Windows
Analysis Report
Y5kEUsYDFr.exe
Overview
General Information
Sample name: | Y5kEUsYDFr.exerenamed because original name is a hash value |
Original sample name: | ec773998b0078cc58100fdb4d27dc3f4.exe |
Analysis ID: | 1571211 |
MD5: | ec773998b0078cc58100fdb4d27dc3f4 |
SHA1: | 491a3d8d31c9eabcd8f6236203c54daa12031aab |
SHA256: | ff4fd58c1db6e88c768665983b2212e53204d7a07b3769883882179d34258933 |
Tags: | exeuser-abuse_ch |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- Y5kEUsYDFr.exe (PID: 7012 cmdline:
"C:\Users\ user\Deskt op\Y5kEUsY DFr.exe" MD5: EC773998B0078CC58100FDB4D27DC3F4) - black.exe (PID: 6360 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\RarSFX 0\black.ex e" MD5: 09929B04B0C29E2722009F49FAF7183C) - cmd.exe (PID: 1308 cmdline:
"C:\Window s\System32 \cmd.exe" /c ping va stgm.ru MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 5356 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - PING.EXE (PID: 1460 cmdline:
ping vastg m.ru MD5: B3624DD758CCECF93A1226CEF252CA12) - cmd.exe (PID: 2600 cmdline:
"C:\Window s\System32 \cmd.exe" /c ping va stgm.ru MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 2284 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - PING.EXE (PID: 3168 cmdline:
ping vastg m.ru MD5: B3624DD758CCECF93A1226CEF252CA12)
- black.exe (PID: 5492 cmdline:
"C:\Users\ user\AppDa ta\Roaming \black.exe " MD5: 09929B04B0C29E2722009F49FAF7183C) - cmd.exe (PID: 5848 cmdline:
"C:\Window s\System32 \cmd.exe" /c ping va stgm.ru MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 496 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - PING.EXE (PID: 3064 cmdline:
ping vastg m.ru MD5: B3624DD758CCECF93A1226CEF252CA12) - cmd.exe (PID: 5688 cmdline:
"C:\Window s\System32 \cmd.exe" /c ping va stgm.ru MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 4448 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - PING.EXE (PID: 1168 cmdline:
ping vastg m.ru MD5: B3624DD758CCECF93A1226CEF252CA12)
- Acrobat.exe (PID: 4936 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 2208 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 3844 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=20 96 --field -trial-han dle=1644,i ,112278778 2678695715 5,36095801 8279179380 6,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- cleanup
System Summary |
---|
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Source: | Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research): |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: |
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | Binary string: |
Source: | Code function: | 0_2_00007FF6CA9D40BC | |
Source: | Code function: | 0_2_00007FF6CA9EB190 | |
Source: | Code function: | 0_2_00007FF6CA9FFCA0 |
Source: | Code function: | 1_2_023D9A58 | |
Source: | Code function: | 1_2_023D28F1 | |
Source: | Code function: | 1_2_023D2908 | |
Source: | Code function: | 1_2_023D9A4C | |
Source: | Code function: | 1_2_02501288 | |
Source: | Code function: | 1_2_02500740 | |
Source: | Code function: | 1_2_02500B18 | |
Source: | Code function: | 1_2_02500818 | |
Source: | Code function: | 1_2_025010A0 | |
Source: | Code function: | 1_2_02500A74 | |
Source: | Code function: | 1_2_02500A78 | |
Source: | Code function: | 1_2_02501620 | |
Source: | Code function: | 1_2_025012E0 | |
Source: | Code function: | 1_2_02500318 | |
Source: | Code function: | 1_2_02501700 | |
Source: | Code function: | 1_2_02500B01 | |
Source: | Code function: | 1_2_02500F28 | |
Source: | Code function: | 1_2_025013D0 | |
Source: | Code function: | 1_2_02500BFD | |
Source: | Code function: | 1_2_02500F9E | |
Source: | Code function: | 1_2_02500FB0 | |
Source: | Code function: | 1_2_025003A0 | |
Source: | Code function: | 1_2_02500C00 | |
Source: | Code function: | 1_2_025014F8 | |
Source: | Code function: | 1_2_02501085 | |
Source: | Code function: | 1_2_025004A0 | |
Source: | Code function: | 7_2_046C0870 | |
Source: | Code function: | 7_2_046C1298 | |
Source: | Code function: | 7_2_046C0740 | |
Source: | Code function: | 7_2_046C0F38 | |
Source: | Code function: | 7_2_046C0868 | |
Source: | Code function: | 7_2_046C0C65 | |
Source: | Code function: | 7_2_046C1065 | |
Source: | Code function: | 7_2_046C127D | |
Source: | Code function: | 7_2_046C1440 | |
Source: | Code function: | 7_2_046C1421 | |
Source: | Code function: | 7_2_046C0CED | |
Source: | Code function: | 7_2_046C02F9 | |
Source: | Code function: | 7_2_046C04A0 | |
Source: | Code function: | 7_2_046C0C80 | |
Source: | Code function: | 7_2_046C1080 | |
Source: | Code function: | 7_2_046C0481 | |
Source: | Code function: | 7_2_046C1360 | |
Source: | Code function: | 7_2_046C0F75 | |
Source: | Code function: | 7_2_046C1341 | |
Source: | Code function: | 7_2_046C0958 | |
Source: | Code function: | 7_2_046C0725 | |
Source: | Code function: | 7_2_046C0F27 | |
Source: | Code function: | 7_2_046C0939 | |
Source: | Code function: | 7_2_046C0D08 | |
Source: | Code function: | 7_2_046C0318 | |
Source: | Code function: | 7_2_046C07D0 | |
Source: | Code function: | 7_2_046C11A8 | |
Source: | Code function: | 7_2_046C03A0 | |
Source: | Code function: | 7_2_046C07B5 | |
Source: | Code function: | 7_2_046C118D | |
Source: | Code function: | 7_2_046C0385 | |
Source: | Code function: | 7_2_046C0F90 | |
Source: | Code function: | 7_2_04BD8C90 | |
Source: | Code function: | 7_2_04BD8C84 | |
Source: | Code function: | 7_2_04BD28F1 | |
Source: | Code function: | 7_2_04BD2908 |
Networking |
---|
Source: | Process created: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Operating System Destruction |
---|
Source: | Process information set: | Jump to behavior |
System Summary |
---|
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Process Stats: | ||
Source: | Process Stats: |
Source: | Code function: | 1_2_023AC270 | |
Source: | Code function: | 1_2_023AB660 | |
Source: | Code function: | 1_2_023AC660 | |
Source: | Code function: | 1_2_023AB750 | |
Source: | Code function: | 1_2_023AC3B8 | |
Source: | Code function: | 1_2_023AC788 | |
Source: | Code function: | 1_2_023AB420 | |
Source: | Code function: | 1_2_023ABC80 | |
Source: | Code function: | 1_2_023AC4D0 | |
Source: | Code function: | 1_2_023AC138 | |
Source: | Code function: | 1_2_023AB548 | |
Source: | Code function: | 1_2_023AC268 | |
Source: | Code function: | 1_2_023AB658 | |
Source: | Code function: | 1_2_023AC659 | |
Source: | Code function: | 1_2_023AB74A | |
Source: | Code function: | 1_2_023AC3B0 | |
Source: | Code function: | 1_2_023AC780 | |
Source: | Code function: | 1_2_023AB418 | |
Source: | Code function: | 1_2_023ABC79 | |
Source: | Code function: | 1_2_023AC4C8 | |
Source: | Code function: | 1_2_023AC130 | |
Source: | Code function: | 1_2_023AB546 | |
Source: | Code function: | 1_2_023D6D68 | |
Source: | Code function: | 1_2_023D7290 | |
Source: | Code function: | 1_2_023D7309 | |
Source: | Code function: | 7_2_04BABC80 | |
Source: | Code function: | 7_2_04BAC4D0 | |
Source: | Code function: | 7_2_04BAB420 | |
Source: | Code function: | 7_2_04BAC138 | |
Source: | Code function: | 7_2_04BAB548 | |
Source: | Code function: | 7_2_04BAC270 | |
Source: | Code function: | 7_2_04BAB660 | |
Source: | Code function: | 7_2_04BAC660 | |
Source: | Code function: | 7_2_04BAC3B8 | |
Source: | Code function: | 7_2_04BAC788 | |
Source: | Code function: | 7_2_04BAB750 | |
Source: | Code function: | 7_2_04BAC4C8 | |
Source: | Code function: | 7_2_04BAB418 | |
Source: | Code function: | 7_2_04BABC79 | |
Source: | Code function: | 7_2_04BAC130 | |
Source: | Code function: | 7_2_04BAB540 | |
Source: | Code function: | 7_2_04BAC268 | |
Source: | Code function: | 7_2_04BAB658 | |
Source: | Code function: | 7_2_04BAC659 | |
Source: | Code function: | 7_2_04BAC3B0 | |
Source: | Code function: | 7_2_04BAC780 | |
Source: | Code function: | 7_2_04BAB749 |
Source: | Code function: | 0_2_00007FF6CA9CC2F0 |
Source: | File created: | Jump to behavior |
Source: | File deleted: | Jump to behavior |
Source: | Code function: | 0_2_00007FF6CA9C5E24 | |
Source: | Code function: | 0_2_00007FF6CA9E1F20 | |
Source: | Code function: | 0_2_00007FF6CA9ECE88 | |
Source: | Code function: | 0_2_00007FF6CA9DA4AC | |
Source: | Code function: | 0_2_00007FF6CA9E3484 | |
Source: | Code function: | 0_2_00007FF6CA9EB190 | |
Source: | Code function: | 0_2_00007FF6CA9F0754 | |
Source: | Code function: | 0_2_00007FF6CA9CF930 | |
Source: | Code function: | 0_2_00007FF6CA9D4928 | |
Source: | Code function: | 0_2_00007FF6CA9F8C1C | |
Source: | Code function: | 0_2_00007FF6CA9D5B60 | |
Source: | Code function: | 0_2_00007FF6CA9E4B98 | |
Source: | Code function: | 0_2_00007FF6CA9DBB90 | |
Source: | Code function: | 0_2_00007FF6CA9E3964 | |
Source: | Code function: | 0_2_00007FF6CA9DC96C | |
Source: | Code function: | 0_2_00007FF6CA9F89A0 | |
Source: | Code function: | 0_2_00007FF6CAA05AF8 | |
Source: | Code function: | 0_2_00007FF6CA9D1A48 | |
Source: | Code function: | 0_2_00007FF6CA9C1AA4 | |
Source: | Code function: | 0_2_00007FF6CA9E2AB0 | |
Source: | Code function: | 0_2_00007FF6CA9FFA94 | |
Source: | Code function: | 0_2_00007FF6CAA02080 | |
Source: | Code function: | 0_2_00007FF6CA9E8DF4 | |
Source: | Code function: | 0_2_00007FF6CA9F0754 | |
Source: | Code function: | 0_2_00007FF6CA9E2D58 | |
Source: | Code function: | 0_2_00007FF6CA9DAF18 | |
Source: | Code function: | 0_2_00007FF6CA9E53F0 | |
Source: | Code function: | 0_2_00007FF6CA9DB534 | |
Source: | Code function: | 0_2_00007FF6CA9E21D0 | |
Source: | Code function: | 0_2_00007FF6CA9DF180 | |
Source: | Code function: | 0_2_00007FF6CA9CC2F0 | |
Source: | Code function: | 0_2_00007FF6CA9CA310 | |
Source: | Code function: | 0_2_00007FF6CA9D126C | |
Source: | Code function: | 0_2_00007FF6CA9C7288 | |
Source: | Code function: | 0_2_00007FF6CA9C4840 | |
Source: | Code function: | 0_2_00007FF6CA9FC838 | |
Source: | Code function: | 0_2_00007FF6CAA02550 | |
Source: | Code function: | 0_2_00007FF6CA9C76C0 | |
Source: | Code function: | 1_2_00CDADD8 | |
Source: | Code function: | 1_2_00CDA188 | |
Source: | Code function: | 1_2_00CDBD00 | |
Source: | Code function: | 1_2_00CDC6E0 | |
Source: | Code function: | 1_2_00CDA6A8 | |
Source: | Code function: | 1_2_00CDAA50 | |
Source: | Code function: | 1_2_00CDEA00 | |
Source: | Code function: | 1_2_00CDE628 | |
Source: | Code function: | 1_2_00CDB7D0 | |
Source: | Code function: | 1_2_00CDD3A8 | |
Source: | Code function: | 1_2_00CD6301 | |
Source: | Code function: | 1_2_00CDBB20 | |
Source: | Code function: | 1_2_00CDE098 | |
Source: | Code function: | 1_2_00CDADC8 | |
Source: | Code function: | 1_2_00CDC5E8 | |
Source: | Code function: | 1_2_00CDA178 | |
Source: | Code function: | 1_2_00CDA698 | |
Source: | Code function: | 1_2_00CDE618 | |
Source: | Code function: | 1_2_023A1B18 | |
Source: | Code function: | 1_2_023A1310 | |
Source: | Code function: | 1_2_023ACBA8 | |
Source: | Code function: | 1_2_023A53A0 | |
Source: | Code function: | 1_2_023A0F98 | |
Source: | Code function: | 1_2_023A7BC0 | |
Source: | Code function: | 1_2_023A5830 | |
Source: | Code function: | 1_2_023A7420 | |
Source: | Code function: | 1_2_023AA408 | |
Source: | Code function: | 1_2_023AD050 | |
Source: | Code function: | 1_2_023A0850 | |
Source: | Code function: | 1_2_023A704A | |
Source: | Code function: | 1_2_023A78B0 | |
Source: | Code function: | 1_2_023A6500 | |
Source: | Code function: | 1_2_023A1D70 | |
Source: | Code function: | 1_2_023AD5B0 | |
Source: | Code function: | 1_2_023A21F0 | |
Source: | Code function: | 1_2_023A8688 | |
Source: | Code function: | 1_2_023AE308 | |
Source: | Code function: | 1_2_023A7F01 | |
Source: | Code function: | 1_2_023A8F78 | |
Source: | Code function: | 1_2_023ACB98 | |
Source: | Code function: | 1_2_023AA3F9 | |
Source: | Code function: | 1_2_023A7BD0 | |
Source: | Code function: | 1_2_023A083F | |
Source: | Code function: | 1_2_023A7430 | |
Source: | Code function: | 1_2_023AAC31 | |
Source: | Code function: | 1_2_023A9810 | |
Source: | Code function: | 1_2_023A7058 | |
Source: | Code function: | 1_2_023AE050 | |
Source: | Code function: | 1_2_023A9CA0 | |
Source: | Code function: | 1_2_023AE8E2 | |
Source: | Code function: | 1_2_023A21E0 | |
Source: | Code function: | 1_2_023D34C8 | |
Source: | Code function: | 1_2_023D01D0 | |
Source: | Code function: | 1_2_023D01C3 | |
Source: | Code function: | 1_2_023D4430 | |
Source: | Code function: | 1_2_023D4440 | |
Source: | Code function: | 1_2_023D8C38 | |
Source: | Code function: | 1_2_023D8C48 | |
Source: | Code function: | 1_2_023D5318 | |
Source: | Code function: | 1_2_023D5188 | |
Source: | Code function: | 1_2_023D36B0 | |
Source: | Code function: | 1_2_023D36A0 | |
Source: | Code function: | 1_2_023D7729 | |
Source: | Code function: | 1_2_023D1FB0 | |
Source: | Code function: | 7_2_0253AA50 | |
Source: | Code function: | 7_2_0253EA00 | |
Source: | Code function: | 7_2_0253BB20 | |
Source: | Code function: | 7_2_0253A188 | |
Source: | Code function: | 7_2_025311B8 | |
Source: | Code function: | 7_2_0253E628 | |
Source: | Code function: | 7_2_0253C6E0 | |
Source: | Code function: | 7_2_0253A6A8 | |
Source: | Code function: | 7_2_0253B7D0 | |
Source: | Code function: | 7_2_0253BD00 | |
Source: | Code function: | 7_2_0253ADD8 | |
Source: | Code function: | 7_2_0253E098 | |
Source: | Code function: | 7_2_0253A178 | |
Source: | Code function: | 7_2_025311A8 | |
Source: | Code function: | 7_2_0253E618 | |
Source: | Code function: | 7_2_0253A698 | |
Source: | Code function: | 7_2_0253ADC8 | |
Source: | Code function: | 7_2_0253C5E8 | |
Source: | Code function: | 7_2_04BA5830 | |
Source: | Code function: | 7_2_04BA7420 | |
Source: | Code function: | 7_2_04BAA408 | |
Source: | Code function: | 7_2_04BAD050 | |
Source: | Code function: | 7_2_04BA0850 | |
Source: | Code function: | 7_2_04BA704A | |
Source: | Code function: | 7_2_04BAD5B0 | |
Source: | Code function: | 7_2_04BA21F0 | |
Source: | Code function: | 7_2_04BA6500 | |
Source: | Code function: | 7_2_04BA1D70 | |
Source: | Code function: | 7_2_04BACBA8 | |
Source: | Code function: | 7_2_04BA53A0 | |
Source: | Code function: | 7_2_04BA0F98 | |
Source: | Code function: | 7_2_04BA7BC0 | |
Source: | Code function: | 7_2_04BA1B18 | |
Source: | Code function: | 7_2_04BA1310 | |
Source: | Code function: | 7_2_04BA78B0 | |
Source: | Code function: | 7_2_04BA9CA0 | |
Source: | Code function: | 7_2_04BAE8E2 | |
Source: | Code function: | 7_2_04BA083F | |
Source: | Code function: | 7_2_04BA7430 | |
Source: | Code function: | 7_2_04BAAC31 | |
Source: | Code function: | 7_2_04BA5820 | |
Source: | Code function: | 7_2_04BA9810 | |
Source: | Code function: | 7_2_04BA7058 | |
Source: | Code function: | 7_2_04BAE050 | |
Source: | Code function: | 7_2_04BAD5A1 | |
Source: | Code function: | 7_2_04BA21E0 | |
Source: | Code function: | 7_2_04BA8688 | |
Source: | Code function: | 7_2_04BACB98 | |
Source: | Code function: | 7_2_04BA5392 | |
Source: | Code function: | 7_2_04BAA3F9 | |
Source: | Code function: | 7_2_04BA7BD0 | |
Source: | Code function: | 7_2_04BAE308 | |
Source: | Code function: | 7_2_04BA7F01 | |
Source: | Code function: | 7_2_04BA8F78 | |
Source: | Code function: | 7_2_04BD34C8 | |
Source: | Code function: | 7_2_04BD4430 | |
Source: | Code function: | 7_2_04BD4440 | |
Source: | Code function: | 7_2_04BD01D0 | |
Source: | Code function: | 7_2_04BD01C0 | |
Source: | Code function: | 7_2_04BD36B0 | |
Source: | Code function: | 7_2_04BD36A0 | |
Source: | Code function: | 7_2_04BD5188 | |
Source: | Code function: | 7_2_04BD71E1 | |
Source: | Code function: | 7_2_04BD5318 | |
Source: | Code function: | 7_2_04BD7E88 | |
Source: | Code function: | 7_2_04BD1FB0 |
Source: | Binary or memory string: |
Source: | Classification label: |
Source: | Code function: | 0_2_00007FF6CA9CB6D8 |
Source: | Code function: | 0_2_00007FF6CA9E8624 |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_2_00007FF6CAA05157 | |
Source: | Code function: | 0_2_00007FF6CAA05167 | |
Source: | Code function: | 1_2_023A8220 | |
Source: | Code function: | 7_2_046C0DD9 |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Boot Survival |
---|
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Source: | Registry key monitored for changes: | Jump to behavior | ||
Source: | Registry key monitored for changes: | Jump to behavior | ||
Source: | Registry key monitored for changes: | Jump to behavior | ||
Source: | Registry key monitored for changes: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: |
Malware Analysis System Evasion |
---|
Source: | System information queried: | Jump to behavior | ||
Source: | System information queried: | Jump to behavior | ||
Source: | System information queried: | Jump to behavior | ||
Source: | System information queried: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: |
Source: | Check user administrative privileges: | graph_0-25992 |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: |
Source: | Code function: | 0_2_00007FF6CA9D40BC | |
Source: | Code function: | 0_2_00007FF6CA9EB190 | |
Source: | Code function: | 0_2_00007FF6CA9FFCA0 |
Source: | Code function: | 0_2_00007FF6CA9F16A4 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Anti Debugging |
---|
Source: | Thread information set: | Jump to behavior | ||
Source: | Thread information set: | Jump to behavior | ||
Source: | Thread information set: | Jump to behavior | ||
Source: | Thread information set: | Jump to behavior |
Source: | System information queried: | Jump to behavior |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 0_2_00007FF6CA9F3170 |
Source: | Code function: | 0_2_00007FF6CAA00D20 |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
Source: | Code function: | 0_2_00007FF6CA9F3354 | |
Source: | Code function: | 0_2_00007FF6CA9F2510 | |
Source: | Code function: | 0_2_00007FF6CA9F3170 | |
Source: | Code function: | 0_2_00007FF6CA9F76D8 |
Source: | Memory allocated: | Jump to behavior |
Source: | Code function: | 0_2_00007FF6CA9EB190 |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: |
Source: | Code function: | 0_2_00007FF6CA9E9D90 |
Source: | Code function: | 0_2_00007FF6CA9DDC70 |
Source: | Code function: | 0_2_00007FF6CA9EA2CC |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Code function: | 0_2_00007FF6CA9F0754 |
Source: | Code function: | 0_2_00007FF6CA9D4EB0 |
Source: | Key value queried: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Native API | 1 DLL Side-Loading | 1 Exploitation for Privilege Escalation | 1 Disable or Modify Tools | OS Credential Dumping | 1 System Time Discovery | Remote Services | 1 Archive Collected Data | 3 Ingress Tool Transfer | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 121 Registry Run Keys / Startup Folder | 1 DLL Side-Loading | 3 Obfuscated Files or Information | LSASS Memory | 2 File and Directory Discovery | Remote Desktop Protocol | Data from Removable Media | 11 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 11 Process Injection | 2 Software Packing | Security Account Manager | 35 System Information Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 121 Registry Run Keys / Startup Folder | 1 Timestomp | NTDS | 1 Query Registry | Distributed Component Object Model | Input Capture | 4 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 341 Security Software Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 File Deletion | Cached Domain Credentials | 1 Process Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 11 Masquerading | DCSync | 251 Virtualization/Sandbox Evasion | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 251 Virtualization/Sandbox Evasion | Proc Filesystem | 1 Application Window Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | 11 Process Injection | /etc/passwd and /etc/shadow | 1 Remote System Discovery | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
IP Addresses | Compromise Infrastructure | Supply Chain Compromise | PowerShell | Cron | Cron | Dynamic API Resolution | Network Sniffing | 1 System Network Configuration Discovery | Shared Webroot | Local Data Staging | File Transfer Protocols | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol | External Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
47% | ReversingLabs | Win32.Exploit.Generic | ||
61% | Virustotal | Browse | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | HEUR/AGEN.1310014 | ||
100% | Avira | HEUR/AGEN.1310014 | ||
100% | Avira | HEUR/AGEN.1310014 | ||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
34% | ReversingLabs | ByteCode-MSIL.Trojan.Generic | ||
34% | ReversingLabs | ByteCode-MSIL.Trojan.Generic | ||
34% | ReversingLabs | ByteCode-MSIL.Trojan.Generic |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
github.com | 20.233.83.145 | true | false | high | |
vastgm.ru | 185.178.208.190 | true | true |
| unknown |
x1.i.lencr.org | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
69.192.108.223 | unknown | United States | 16625 | AKAMAI-ASUS | false | |
20.233.83.145 | github.com | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
185.178.208.190 | vastgm.ru | Russian Federation | 57724 | DDOS-GUARDRU | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1571211 |
Start date and time: | 2024-12-09 07:02:47 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 8m 44s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 44 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | Y5kEUsYDFr.exerenamed because original name is a hash value |
Original Sample Name: | ec773998b0078cc58100fdb4d27dc3f4.exe |
Detection: | MAL |
Classification: | mal100.troj.adwa.evad.winEXE@42/41@3/3 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, WmiPrvSE.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 23.32.238.137, 23.32.238.128, 23.32.238.98, 23.32.238.106, 23.32.238.138, 23.32.238.113, 23.32.238.107, 23.32.238.123, 23.32.238.129, 162.159.61.3, 172.64.41.3, 23.32.238.155, 23.32.238.162, 2.19.198.49, 23.32.238.161, 23.32.238.131, 23.32.238.146, 2.19.198.43, 2.20.40.170, 23.218.208.137, 23.195.39.65, 50.16.47.176, 18.213.11.84, 34.237.241.83, 54.224.241.105, 23.32.238.122, 23.32.238.147, 23.32.238.153, 23.32.238.145, 23.32.238.115, 23.32.238.154, 2.16.188.171, 23.32.238.97, 23.32.238.112, 23.32.238.114, 23.32.238.99, 2.19.198.57, 2.19.198.41, 2.19.198.50, 2.19.198.58, 23.32.238.163, 2.19.198.40, 2.19.198.72, 23.32.238.160, 23.32.238.90, 23.32.238.96, 23.32.238.130, 2.19.198.73
- Excluded domains from analysis (whitelisted): chrome.cloudflare-dns.com, e4578.dscg.akamaiedge.net, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, otelrules.azureedge.net, acroipm2.adobe.com.edgesuite.net, e4578.dscb.akamaiedge.net, ctldl.windowsupdate.com, p13n.adobe.io, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ssl.adobe.com.edgekey.net, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, geo2.adobe.com, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size exceeded maximum capacity and may have missing disassembly code.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Time | Type | Description |
---|---|---|
01:04:16 | API Interceptor | |
01:05:11 | API Interceptor | |
06:03:42 | Autostart | |
06:03:51 | Autostart | |
06:04:18 | Autostart |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
69.192.108.223 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HTMLPhisher, ReCaptcha Phish | Browse | |||
Get hash | malicious | Unknown | Browse | |||
20.233.83.145 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | MicroClip | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Babadeda, Blank Grabber | Browse | |||
Get hash | malicious | Havoc, RUSTDESK | Browse | |||
Get hash | malicious | Vidar | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Stealc, Vidar | Browse | |||
185.178.208.190 | Get hash | malicious | Cyberduck Djvu SmokeLoader Vidar | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
github.com | Get hash | malicious | MicroClip | Browse |
| |
Get hash | malicious | Babadeda, Blank Grabber | Browse |
| ||
Get hash | malicious | Havoc, RUSTDESK | Browse |
| ||
Get hash | malicious | Vidar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Caesium Obfuscator, STRRAT | Browse |
| ||
Get hash | malicious | Stealc, Vidar | Browse |
| ||
Get hash | malicious | Stealc, Vidar | Browse |
| ||
Get hash | malicious | Stealc, Vidar | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
DDOS-GUARDRU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
AKAMAI-ASUS | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Lokibot | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
MICROSOFT-CORP-MSN-AS-BLOCKUS | Get hash | malicious | XenoRAT | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | XenoRAT | Browse |
| ||
Get hash | malicious | XenoRAT | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
54328bd36c14bd82ddaa0c04b25ed9ad | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
|
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.158849390404121 |
Encrypted: | false |
SSDEEP: | 6:juRcq2Pwkn2nKuAl9OmbnIFUt8WuRfXZmw+WuRfFkwOwkn2nKuAl9OmbjLJ:ju+vYfHAahFUt8WupX/+WupF5JfHAaSJ |
MD5: | 24820C395FDB62B7FA224ADFFF0CD1A1 |
SHA1: | B68ED3162860A4385EBCDBD94E13E0B6924E1748 |
SHA-256: | 2A71D9DC773CEDD2C42500CF91DB73DBDCB27A56263B39A1BE4BFAE3DD33CB72 |
SHA-512: | 2DDD89849084CDD2B60DB27988974C51E848D9605AE45F762A293A24A20362B665103D59C110358A4931877D30EE6C5DC13BB76868E01ECB12F836538C629E80 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.158849390404121 |
Encrypted: | false |
SSDEEP: | 6:juRcq2Pwkn2nKuAl9OmbnIFUt8WuRfXZmw+WuRfFkwOwkn2nKuAl9OmbjLJ:ju+vYfHAahFUt8WupX/+WupF5JfHAaSJ |
MD5: | 24820C395FDB62B7FA224ADFFF0CD1A1 |
SHA1: | B68ED3162860A4385EBCDBD94E13E0B6924E1748 |
SHA-256: | 2A71D9DC773CEDD2C42500CF91DB73DBDCB27A56263B39A1BE4BFAE3DD33CB72 |
SHA-512: | 2DDD89849084CDD2B60DB27988974C51E848D9605AE45F762A293A24A20362B665103D59C110358A4931877D30EE6C5DC13BB76868E01ECB12F836538C629E80 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 333 |
Entropy (8bit): | 5.163052101733533 |
Encrypted: | false |
SSDEEP: | 6:ju+q2Pwkn2nKuAl9Ombzo2jMGIFUt8WuJKXZmw+WuZFzkwOwkn2nKuAl9Ombzo23:ju+vYfHAa8uFUt8WuJ6/+Wun5JfHAa8z |
MD5: | 47F56480CBC018B56B319005ADAF033A |
SHA1: | E3B3620E073FB4EED636EADDE4B886998AB13277 |
SHA-256: | 5542A9B8BE4C4733440F71CE7EB23029663685BC353B263A5F6A83A87FCFE453 |
SHA-512: | E1FAA0BCEB6D79E22393F526642E94CF63B597CC93DB0E1FFCD542F63622CFD1ED8F29A8F69EEF5E2CA7A01B21BCE3424AD170F03BB0FA1D2EB6AF6A0AF0E4E4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 333 |
Entropy (8bit): | 5.163052101733533 |
Encrypted: | false |
SSDEEP: | 6:ju+q2Pwkn2nKuAl9Ombzo2jMGIFUt8WuJKXZmw+WuZFzkwOwkn2nKuAl9Ombzo23:ju+vYfHAa8uFUt8WuJ6/+Wun5JfHAa8z |
MD5: | 47F56480CBC018B56B319005ADAF033A |
SHA1: | E3B3620E073FB4EED636EADDE4B886998AB13277 |
SHA-256: | 5542A9B8BE4C4733440F71CE7EB23029663685BC353B263A5F6A83A87FCFE453 |
SHA-512: | E1FAA0BCEB6D79E22393F526642E94CF63B597CC93DB0E1FFCD542F63622CFD1ED8F29A8F69EEF5E2CA7A01B21BCE3424AD170F03BB0FA1D2EB6AF6A0AF0E4E4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.967403857886107 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqLsBdOg2HHfcaq3QYiubInP7E4TX:Y2sRdsVdMHO3QYhbG7n7 |
MD5: | B7761633048D74E3C02F61AD04E00147 |
SHA1: | 72A2D446DF757BAEA2C7A58C050925976E4C9372 |
SHA-256: | 1A468796D744FCA806D1F828C07E0064AB6A1FA0E31DA3A403F12B9B89868B67 |
SHA-512: | 397A10C510FAA048E4AAB08A11B2AE14A09EE47EC4F5A2B47CE1A9580C2874ADE0F9F8FC287B9358C0FFEA4C89F8AB9270B9CA00064EA90CD2EF0EAD0A59369F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State~RF6d2e70.TMP (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.967403857886107 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqLsBdOg2HHfcaq3QYiubInP7E4TX:Y2sRdsVdMHO3QYhbG7n7 |
MD5: | B7761633048D74E3C02F61AD04E00147 |
SHA1: | 72A2D446DF757BAEA2C7A58C050925976E4C9372 |
SHA-256: | 1A468796D744FCA806D1F828C07E0064AB6A1FA0E31DA3A403F12B9B89868B67 |
SHA-512: | 397A10C510FAA048E4AAB08A11B2AE14A09EE47EC4F5A2B47CE1A9580C2874ADE0F9F8FC287B9358C0FFEA4C89F8AB9270B9CA00064EA90CD2EF0EAD0A59369F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\d1e8fdc2-5a27-4dd7-955d-2c2d0c2005af.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 546 |
Entropy (8bit): | 4.949867576032391 |
Encrypted: | false |
SSDEEP: | 12:YHgLdvI1oqBWsB6um3RA8sqJ2gsBd2caq3QH7E4TX:YALtIPB7JsRdsZdJ3QH7n7 |
MD5: | 624EA1F42B72404E6A5BD12EA495EA67 |
SHA1: | F3C694F276938BF5C9830C4C1F0616E3404BDAED |
SHA-256: | 217F03962EB39AB353704367748A38B1B15B84CF4A8DA17685D98F9A0F0130EA |
SHA-512: | C316787F369603F9260930B30E159FB8ADC19F60C1ABE24C8C2182C685A93BC540131B48D4F9C108E7886424B4373E75FC16B972607AC76AE7B2A17F02333E0E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\dcddf736-09ed-4644-94da-a6ed343af90a.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.967403857886107 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqLsBdOg2HHfcaq3QYiubInP7E4TX:Y2sRdsVdMHO3QYhbG7n7 |
MD5: | B7761633048D74E3C02F61AD04E00147 |
SHA1: | 72A2D446DF757BAEA2C7A58C050925976E4C9372 |
SHA-256: | 1A468796D744FCA806D1F828C07E0064AB6A1FA0E31DA3A403F12B9B89868B67 |
SHA-512: | 397A10C510FAA048E4AAB08A11B2AE14A09EE47EC4F5A2B47CE1A9580C2874ADE0F9F8FC287B9358C0FFEA4C89F8AB9270B9CA00064EA90CD2EF0EAD0A59369F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4812 |
Entropy (8bit): | 5.2607929979267825 |
Encrypted: | false |
SSDEEP: | 96:etJCV4FAsszrNamjTN/2rjYMta02fDtehgO7BtTgo73c/c0YBjH:etJCV4FiN/jTN/2r8Mta02fEhgO73gov |
MD5: | 9E3947FA773E7A3D28AC26D823AC3597 |
SHA1: | BAC1FC7A5EAA23612FAF7DD13F2EA1544BBF1E3B |
SHA-256: | 01D2E2DCCF62A7EDD280D48C64749356D14D80F55CBDAE7581563F96D0F637D6 |
SHA-512: | D294A46BE16786E191B2C32F36FE2AAF4C6341518DB7157647650D33849925D2E5A81B4403EA0E1BA8F58F2A07A1F34386AF4B53347F119AF14D2D10BFFB1E49 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 321 |
Entropy (8bit): | 5.151007476450527 |
Encrypted: | false |
SSDEEP: | 6:jOQeIq2Pwkn2nKuAl9OmbzNMxIFUt8WOKJZmw+WEGkwOwkn2nKuAl9OmbzNMFLJ:jNXvYfHAa8jFUt8WT/+WEG5JfHAa84J |
MD5: | B9BF243A6C1458C4C0DDF30471ED1AC9 |
SHA1: | 0734065638611C7E6E21115B17E9C7313F008926 |
SHA-256: | 7EC7FD71BAC83B6EF1373FD4AFB7E3D7660E5468CB1F82A770E0AAD2DB08CDA9 |
SHA-512: | 97C177F28AEAA1E058CB23557244FC60A4A3E0119B0124DE10247E8398AFD870DD732A7DE1126EB9459E78E7143A60CDD077F21695622A5DD8722646C3BB6250 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 321 |
Entropy (8bit): | 5.151007476450527 |
Encrypted: | false |
SSDEEP: | 6:jOQeIq2Pwkn2nKuAl9OmbzNMxIFUt8WOKJZmw+WEGkwOwkn2nKuAl9OmbzNMFLJ:jNXvYfHAa8jFUt8WT/+WEG5JfHAa84J |
MD5: | B9BF243A6C1458C4C0DDF30471ED1AC9 |
SHA1: | 0734065638611C7E6E21115B17E9C7313F008926 |
SHA-256: | 7EC7FD71BAC83B6EF1373FD4AFB7E3D7660E5468CB1F82A770E0AAD2DB08CDA9 |
SHA-512: | 97C177F28AEAA1E058CB23557244FC60A4A3E0119B0124DE10247E8398AFD870DD732A7DE1126EB9459E78E7143A60CDD077F21695622A5DD8722646C3BB6250 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.444630649917991 |
Encrypted: | false |
SSDEEP: | 384:yezci5t7iBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:r4s3OazzU89UTTgUL |
MD5: | D29FC24683F57AEE770CCC10BBE10145 |
SHA1: | FD39A81AEAF28A09C451AC4B5DAA737961E91208 |
SHA-256: | 3CF860E12D12737619F91078019729DBE643094EFC1C76C287637B72D7FDEE23 |
SHA-512: | 5C50ACDC4AB8FCB20D322E987048FDC66DE90CD62EDDDE804B31F3CEA12A41D9DDDC3E741EB825417049DAF76B03E5B7B3396206A61DFC62D3B237B0EBC1BC02 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 3.770470275674103 |
Encrypted: | false |
SSDEEP: | 48:7MRsUpA2ioyVTioyloWoy1Cwoy1PKOioy1noy1AYoy1Wioy11ioyeioyBoy1noyW:78sUpfuTR2X2jicb9IVXEBodRBkp |
MD5: | 4BBD2CB0C97061FDC4AF0E5D8547744F |
SHA1: | AE0A149F226CF332DC0D6968BA7D09D7B2C1B008 |
SHA-256: | 5AC1C3F4B933A564ABE687CDD0883083AE75CA292D47D4AA3E2154470A54BE34 |
SHA-512: | 91B204B0FCBAF1D4FE0C66BFC3C68AF6AB3808293023AE93D8CE7F7B4BC9CA469D15A0D2073BC287F462558B289631D94AC57AC44310FEB9C0A52302375F9F3C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7130774337030337 |
Encrypted: | false |
SSDEEP: | 3:kkFkl5Vwlv+stfllXlE/HT8ku77l1NNX8RolJuRdxLlGB9lQRYwpDdt:kKDlLeT8/l7NMa8RdWBwRd |
MD5: | 4A6053066C7A84833BB925BCF001D2EC |
SHA1: | 3678320A5C9A09780B73446523B59BC42363B421 |
SHA-256: | 0D13E7ABE62371CC91A3DA757A89AA7744A913F615AB51E69076D79146480750 |
SHA-512: | 10A8F610DA4B8157A150BAC77728A52E9013385E14609781D3060749817DF55090509C92AAEB2C326ED9C87016F0E924590245CBFBDD0627D9DC327F2240589C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1969 |
Entropy (8bit): | 5.0470967544303305 |
Encrypted: | false |
SSDEEP: | 48:Y62sSbMSlMtCM5mMOpiMAW0MretMSMmkaMY:4tYtt55V6AWLre6JmkhY |
MD5: | C01BB431919B73D0FCE5A4504275F362 |
SHA1: | 756C37C8CE49A33BF70B5EAFDF0BA1E348FC87D9 |
SHA-256: | 8B6B36A674CEF60FB0EC1C3A0FC580DA44AA9949F8D376BF6013FCECE82E60EA |
SHA-512: | BFC69A412273E5B05DD240EECD4C478B5409A6054C6C8C34A46E71A82F2F18BEDCE771C272DD3896A28C10081D4B39EDE3510629D041F8EE173E4779619B190C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.187441781567585 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msEHUUUUUUUU5nSvR9H9vxFGiDIAEkGVvpFH:lNVmswUUUUUUUU5n+FGSIt5H |
MD5: | 5E4D192D65909E747EF421EECF485240 |
SHA1: | 804B55FFB3E10948A484D3E0E19C53D9B5CF9079 |
SHA-256: | 31DBA3FB532827B6D37AB6C23D62FAB2307F40347CB31FD5D06F579D3849D375 |
SHA-512: | D584D8AF944B723FB55B9545AE6D8F991752CBF2BB7BFAFE495AD5C555B178907087093C73C098B70D5F1B7C5F242D2411D1CBD922BF4661FB083DC1CFDE3DC6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.6074402971898196 |
Encrypted: | false |
SSDEEP: | 48:7McKUUUUUUUUUU57vR9H9vxFGiDIAEkGVvEfqFl2GL7msB:74UUUUUUUUUU5LFGSItSfKVmsB |
MD5: | 8B0C23872C81F71BB58538AA44A7D06A |
SHA1: | D44A036A5816A3FB82D595540484B112C84F5B83 |
SHA-256: | 1F9D183D853AE6ECFC74EF1DEAB32628F5DE3D8891A51403671F6F35F711E3A7 |
SHA-512: | CB806951E97F24E3EF4DBBD5F006F86AF76D74E7138408151775F50E2A809AAFB1EB75251957CDD6A24ED9C8F711A9C9259020FAE6CB7B7AFCC7B294A7817559 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgablQ9WY0oQhFZ7EdOKnYBenlvYyu:6a6TZ44ADEabO9WYohFZzelvK |
MD5: | BAE2A73B3683EEAA3FCAAA9915A73C2E |
SHA1: | 68327FE03B11F9FE7F217308B3531F03074F2367 |
SHA-256: | 6CDDFBAAA66947E798D6FFEF3B5BFD050FE6F9DE7C6ABEA74B87EA905AD71F75 |
SHA-512: | B33647324966FD41B75AE89FFE918EE76605C93B251E347E8CF9CC22BA2D1EAF49BF96629C871528069F66EE7C40E33D31203290E748ABEB94D1BE20C63AA79C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5193370621730837 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K88hlAiwlN1rCH:Qw946cPbiOxDlbYnuRKrYf1U |
MD5: | 13B87891961A07A9CD5AEDD6069D3728 |
SHA1: | 81FDDEF7F5BE87DEAAD29500C6DE28D81658C6B2 |
SHA-256: | 34A1D9C7DD52EDECC90991688A56BCBD376C51E87C6CAB14AE9ACADC6AD127FC |
SHA-512: | 689D72EAA2EEB1A1AB3CCD0FF0797549FA6B43F547EBBC153DDB2794359AF66353A5E315D740102163C270149A3EE66546DAD137D09F538C21B846449CBFC754 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\Y5kEUsYDFr.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 305 |
Entropy (8bit): | 4.857483719766813 |
Encrypted: | false |
SSDEEP: | 6:JiMVBdDmUifoPWzcJ7RexJOG0XIQsJyLAxJmJBJ4lpAxJuhwc:MMHdD6fY4cufsXIQslfEgAfHc |
MD5: | B9C3AE0E82195B170FEA8976D2EAFF22 |
SHA1: | 4EBC61D576E45E7FA118EB909189B34FEE42791D |
SHA-256: | 14DEC7D1C20FC426AD5463D1B658F87A22F7E576BA4A08905CAF399551813A72 |
SHA-512: | AD82F54D5DBD951CC7F9B24D90A87DFDF1E1E839AA0C92DE7A813BA09BFF66F309274384275D0F38C7990A511EC2363341C516556230ED81D97EA62569A326EB |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\Y5kEUsYDFr.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 550912 |
Entropy (8bit): | 7.713690387908805 |
Encrypted: | false |
SSDEEP: | 6144:eVtna0OB1sZqP+jPVtSfj+Bv/pvteHwxBBBvYfrZcE0X+VkV/M0wZSca7ForfYEd:E5f0+B3pUHwpJYTcOSV5suQeEFHncyQ |
MD5: | 09929B04B0C29E2722009F49FAF7183C |
SHA1: | 8FBACCD01E2F6E3213140402766B90E0409C92BE |
SHA-256: | 2AA22D6CD757C6E46D10FD8DB264481C299FF4646F2698C7A1976384D7C20EE2 |
SHA-512: | CC9728AF886B748119AE2BEDE4B7E9FF5F2245EEA3D1B9034E943D33A060D78E0191B8DF1B80E5E01F666B0DE6473C5D846CB446D7F83925BD83FBA5BE9D091B |
Malicious: | true |
Antivirus: |
|
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2024-12-09 01-04-36-988.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.345946398610936 |
Encrypted: | false |
SSDEEP: | 384:zHIq8qrq0qoq/qUILImCIrImI9IWdFdDdoPtPTPtP7ygyAydy0yGV///X/J/VokV:nNW |
MD5: | 8947C10F5AB6CFFFAE64BCA79B5A0BE3 |
SHA1: | 70F87EEB71BA1BE43D2ABAB7563F94C73AB5F778 |
SHA-256: | 4F3449101521DA7DF6B58A2C856592E1359BA8BD1ACD0688ECF4292BA5388485 |
SHA-512: | B76DB9EF3AE758F00CAF0C1705105C875838C7801F7265B17396466EECDA4BCD915DA4611155C5F2AD1C82A800C1BEC855E52E2203421815F915B77AA7331CA0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15110 |
Entropy (8bit): | 5.34439448979523 |
Encrypted: | false |
SSDEEP: | 384:fr96lrQRCzOY6dGj1bxYgyzKmlcN7S29bMFJDnTCvRl9/PjOuphT8b8hAjBf4JR8:BRx |
MD5: | 2F0D5120C157C3D04020BAE9EBB40621 |
SHA1: | 3FFBC800F05811ADADDFF800841CDB0FB0CF1AFD |
SHA-256: | 3920A3D7F87EBA513DD1F689356B237C70EA58118EED19BB8AAAAA7E73EC937D |
SHA-512: | D53C6EEBE3AD6709F782C71E2528D439BD869EBC0AD6FC307C4C82DF4427BF55BBF877D118EBFC6EA1EA4C9D5FC264625044A2181BA7928A201D038942E52321 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.388982408897857 |
Encrypted: | false |
SSDEEP: | 768:anddBuBYZwcfCnwZCnR8Bu5hx18HoCnLlAY+iCBuzhLCnx1CnPrRRFS10l8gT2rR:a3p4AmaaUv9iZ |
MD5: | 55EF1E942BC78C7EE02194EE61DF929D |
SHA1: | 3B82E0670B2CCD4D7AB5217C33B7F98F0487AE5D |
SHA-256: | 91401E30B1B884272C4AD007517ABF96D8D7A0A0DCAAB5A981202F981A344996 |
SHA-512: | 69F92EF43A8A56105639188AD6F23821308F20812169DC3C050D9F5E4095D030AD9584124EBEA4C5065CB030DD3074C153D8A337C4D5FD3A45C50DD625E8CDCD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:eIowYIGNPnbdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07WWL07oBGZd:UwZGNb3mlind9i4ufFXpAXkrfUs0qWLa |
MD5: | DD5E646E5A339DEA766F301A1768A03D |
SHA1: | C2FC502E4D0563D50F3A32F583C4E353F504FDC9 |
SHA-256: | 2EEE2EE4A1201AEC0D19B1B961BFFA3AF0BE80D9A8320684847DDA4451AFF5F7 |
SHA-512: | E2A03E11E27C3CBC3E186FB29175A6F037CDEDBE17CAEA38F13575A5EE7A18574152A77E2E4A4AFD53613001035A1B76BB7194F292E4B8B5BE4275981480D408 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:rBgI81ReWQ53+sQ3POSTJJJJEQ6T9UkRm1XX/FLYVbxrr/IxktOQZ1mau4yBwsOo:r+Tegs6lTJJJJv+9UZd1ybxrr/IxkB1m |
MD5: | 774036904FF86EB19FCE18B796528E1E |
SHA1: | 2BA0EBF3FC7BEF9EF5BFAD32070BD3C785904E16 |
SHA-256: | D2FC8EA3DDD3F095F7A469927179B408102471627C91275EDB4D7356F8E453AD |
SHA-512: | 9E9662EA15AE3345166C1E51235CDCE3123B27848E4A4651CC4D2173BDD973E4AD2F8994EFF34A221A9F07AA676F52BEB6D90FF374F6CCB0D06FA39C3EFE6B31 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:ZtwYIGNP4mOWL07oBGZ1dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:fwZG6bWLxBGZN3mlind9i4ufFXpAXkru |
MD5: | 971F33F2204A29A9601BD391856AD580 |
SHA1: | EFDE508CA80123F69E881A0CDEDEFC4B4713B04F |
SHA-256: | 06390D0A44CF3C02ED7D30A7985F83CC6059CC0302F02DC30E78FD711A2C7119 |
SHA-512: | CA3B3FABE111B201ECF4B23596BE7EACCB2405ECA3415658293CE8B0AF97286E4FEDE85E8511679D49124DCCF9D5C020B05A4E6C20C281ED1D8BEC0EABDF620F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\RarSFX0\black.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 550912 |
Entropy (8bit): | 7.713690387908805 |
Encrypted: | false |
SSDEEP: | 6144:eVtna0OB1sZqP+jPVtSfj+Bv/pvteHwxBBBvYfrZcE0X+VkV/M0wZSca7ForfYEd:E5f0+B3pUHwpJYTcOSV5suQeEFHncyQ |
MD5: | 09929B04B0C29E2722009F49FAF7183C |
SHA1: | 8FBACCD01E2F6E3213140402766B90E0409C92BE |
SHA-256: | 2AA22D6CD757C6E46D10FD8DB264481C299FF4646F2698C7A1976384D7C20EE2 |
SHA-512: | CC9728AF886B748119AE2BEDE4B7E9FF5F2245EEA3D1B9034E943D33A060D78E0191B8DF1B80E5E01F666B0DE6473C5D846CB446D7F83925BD83FBA5BE9D091B |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\RarSFX0\black.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 550912 |
Entropy (8bit): | 7.713690387908805 |
Encrypted: | false |
SSDEEP: | 6144:eVtna0OB1sZqP+jPVtSfj+Bv/pvteHwxBBBvYfrZcE0X+VkV/M0wZSca7ForfYEd:E5f0+B3pUHwpJYTcOSV5suQeEFHncyQ |
MD5: | 09929B04B0C29E2722009F49FAF7183C |
SHA1: | 8FBACCD01E2F6E3213140402766B90E0409C92BE |
SHA-256: | 2AA22D6CD757C6E46D10FD8DB264481C299FF4646F2698C7A1976384D7C20EE2 |
SHA-512: | CC9728AF886B748119AE2BEDE4B7E9FF5F2245EEA3D1B9034E943D33A060D78E0191B8DF1B80E5E01F666B0DE6473C5D846CB446D7F83925BD83FBA5BE9D091B |
Malicious: | true |
Antivirus: |
|
Preview: |
File type: | |
Entropy (8bit): | 7.509626966343186 |
TrID: |
|
File name: | Y5kEUsYDFr.exe |
File size: | 912'111 bytes |
MD5: | ec773998b0078cc58100fdb4d27dc3f4 |
SHA1: | 491a3d8d31c9eabcd8f6236203c54daa12031aab |
SHA256: | ff4fd58c1db6e88c768665983b2212e53204d7a07b3769883882179d34258933 |
SHA512: | 00c01a72b8dc6254629cf942d30c05015ef44b90ad65da59b07019de3fee14f23d20f4611123308937c46f256e654e054447f42d1132f89dc1cf0af1f1b8bd60 |
SSDEEP: | 24576:yuDXTIGaPhEYzUzA0JZtduqcudFpYePc+98dhK:1Djlabwz97ZdvJydU |
TLSH: | 7115D00AF7E805F8E077E538C9574946F77A7C4903709A8F13A5166B2F673A09E3A321 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......$.2.`.\.`.\.`.\..y..h.\..y....\..y..m.\.....b.\...X.r.\..._.j.\...Y.Y.\.i...i.\.i...b.\.i...g.\.`.].C.\...Y.R.\...\.a.\.....a.\ |
Icon Hash: | 1515d4d4442f2d2d |
Entrypoint: | 0x140032ee0 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x140000000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x66409723 [Sun May 12 10:17:07 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 2 |
File Version Major: | 5 |
File Version Minor: | 2 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 2 |
Import Hash: | b1c5b1beabd90d9fdabd1df0779ea832 |
Instruction |
---|
dec eax |
sub esp, 28h |
call 00007F5EECB80A78h |
dec eax |
add esp, 28h |
jmp 00007F5EECB8040Fh |
int3 |
int3 |
dec eax |
mov eax, esp |
dec eax |
mov dword ptr [eax+08h], ebx |
dec eax |
mov dword ptr [eax+10h], ebp |
dec eax |
mov dword ptr [eax+18h], esi |
dec eax |
mov dword ptr [eax+20h], edi |
inc ecx |
push esi |
dec eax |
sub esp, 20h |
dec ebp |
mov edx, dword ptr [ecx+38h] |
dec eax |
mov esi, edx |
dec ebp |
mov esi, eax |
dec eax |
mov ebp, ecx |
dec ecx |
mov edx, ecx |
dec eax |
mov ecx, esi |
dec ecx |
mov edi, ecx |
inc ecx |
mov ebx, dword ptr [edx] |
dec eax |
shl ebx, 04h |
dec ecx |
add ebx, edx |
dec esp |
lea eax, dword ptr [ebx+04h] |
call 00007F5EECB7F893h |
mov eax, dword ptr [ebp+04h] |
and al, 66h |
neg al |
mov eax, 00000001h |
sbb edx, edx |
neg edx |
add edx, eax |
test dword ptr [ebx+04h], edx |
je 00007F5EECB805A3h |
dec esp |
mov ecx, edi |
dec ebp |
mov eax, esi |
dec eax |
mov edx, esi |
dec eax |
mov ecx, ebp |
call 00007F5EECB825B7h |
dec eax |
mov ebx, dword ptr [esp+30h] |
dec eax |
mov ebp, dword ptr [esp+38h] |
dec eax |
mov esi, dword ptr [esp+40h] |
dec eax |
mov edi, dword ptr [esp+48h] |
dec eax |
add esp, 20h |
inc ecx |
pop esi |
ret |
int3 |
int3 |
int3 |
dec eax |
sub esp, 48h |
dec eax |
lea ecx, dword ptr [esp+20h] |
call 00007F5EECB6EE23h |
dec eax |
lea edx, dword ptr [00025747h] |
dec eax |
lea ecx, dword ptr [esp+20h] |
call 00007F5EECB81672h |
int3 |
jmp 00007F5EECB87854h |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x597a0 | 0x34 | .rdata |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x597d4 | 0x50 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x70000 | 0xe3bc | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x6a000 | 0x306c | .pdata |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x7f000 | 0x970 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x536c0 | 0x54 | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x53780 | 0x28 | .rdata |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x4b3f0 | 0x140 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x48000 | 0x508 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x588bc | 0x120 | .rdata |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x4676e | 0x46800 | f06bb06e02377ae8b223122e53be35c2 | False | 0.5372340425531915 | data | 6.47079645411382 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x48000 | 0x128c4 | 0x12a00 | 2de06d4a6920a6911e64ff20000ea72f | False | 0.4499003775167785 | data | 5.273999097784603 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x5b000 | 0xe75c | 0x1a00 | 0dbdb901a7d477980097e42e511a94fb | False | 0.28275240384615385 | data | 3.2571023907881185 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.pdata | 0x6a000 | 0x306c | 0x3200 | b0ce0f057741ad2a4ef4717079fa34e9 | False | 0.483359375 | data | 5.501810413666288 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.didat | 0x6e000 | 0x360 | 0x400 | 1fcc7b1d7a02443319f8fcc2be4ca936 | False | 0.2578125 | data | 3.0459938492946015 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
_RDATA | 0x6f000 | 0x15c | 0x200 | 3f331ec50f09ba861beaf955b33712d5 | False | 0.408203125 | data | 3.3356393424384843 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.rsrc | 0x70000 | 0xe3bc | 0xe400 | bc9f91a29304eb418a66064e8181fb64 | False | 0.6335149396929824 | data | 6.778689555051379 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x7f000 | 0x970 | 0xa00 | 77a9ddfc47a5650d6eebbcc823e39532 | False | 0.52421875 | data | 5.336289720085303 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
PNG | 0x70674 | 0xb45 | PNG image data, 93 x 302, 8-bit/color RGB, non-interlaced | 1.0027729636048528 | ||
PNG | 0x711bc | 0x15a9 | PNG image data, 186 x 604, 8-bit/color RGB, non-interlaced | 0.9363390441839495 | ||
RT_ICON | 0x72768 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, resolution 2834 x 2834 px/m, 256 important colors | 0.47832369942196534 | ||
RT_ICON | 0x72cd0 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, resolution 2834 x 2834 px/m, 256 important colors | 0.5410649819494585 | ||
RT_ICON | 0x73578 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, resolution 2834 x 2834 px/m, 256 important colors | 0.4933368869936034 | ||
RT_ICON | 0x74420 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1024, resolution 2834 x 2834 px/m | 0.5390070921985816 | ||
RT_ICON | 0x74888 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4096, resolution 2834 x 2834 px/m | 0.41393058161350843 | ||
RT_ICON | 0x75930 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9216, resolution 2834 x 2834 px/m | 0.3479253112033195 | ||
RT_ICON | 0x77ed8 | 0x3d71 | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | 0.9809269502193401 | ||
RT_DIALOG | 0x7bc4c | 0x2ba | data | 0.5286532951289399 | ||
RT_DIALOG | 0x7bf08 | 0x13a | data | 0.6560509554140127 | ||
RT_DIALOG | 0x7c044 | 0xf2 | data | 0.71900826446281 | ||
RT_DIALOG | 0x7c138 | 0x14a | data | 0.6 | ||
RT_DIALOG | 0x7c284 | 0x314 | data | 0.47588832487309646 | ||
RT_DIALOG | 0x7c598 | 0x24a | data | 0.6279863481228669 | ||
RT_STRING | 0x7c7e4 | 0x1fc | data | 0.421259842519685 | ||
RT_STRING | 0x7c9e0 | 0x246 | data | 0.41924398625429554 | ||
RT_STRING | 0x7cc28 | 0x1a6 | data | 0.514218009478673 | ||
RT_STRING | 0x7cdd0 | 0xdc | data | 0.65 | ||
RT_STRING | 0x7ceac | 0x470 | data | 0.3873239436619718 | ||
RT_STRING | 0x7d31c | 0x164 | data | 0.5056179775280899 | ||
RT_STRING | 0x7d480 | 0x110 | data | 0.5772058823529411 | ||
RT_STRING | 0x7d590 | 0x158 | data | 0.4563953488372093 | ||
RT_STRING | 0x7d6e8 | 0xe8 | data | 0.5948275862068966 | ||
RT_STRING | 0x7d7d0 | 0x1c6 | data | 0.5242290748898678 | ||
RT_STRING | 0x7d998 | 0x268 | data | 0.4837662337662338 | ||
RT_GROUP_ICON | 0x7dc00 | 0x68 | data | 0.7019230769230769 | ||
RT_MANIFEST | 0x7dc68 | 0x753 | XML 1.0 document, ASCII text, with CRLF line terminators | 0.39786666666666665 |
DLL | Import |
---|---|
KERNEL32.dll | LocalFree, GetLastError, SetLastError, FormatMessageW, GetCurrentProcess, DeviceIoControl, SetFileTime, CloseHandle, RemoveDirectoryW, CreateFileW, DeleteFileW, CreateHardLinkW, GetShortPathNameW, GetLongPathNameW, MoveFileW, GetFileType, GetStdHandle, WriteFile, ReadFile, FlushFileBuffers, SetEndOfFile, SetFilePointer, GetCurrentProcessId, CreateDirectoryW, SetFileAttributesW, GetFileAttributesW, FindClose, FindFirstFileW, FindNextFileW, GetVersionExW, GetModuleFileNameW, SetCurrentDirectoryW, GetCurrentDirectoryW, GetFullPathNameW, FoldStringW, GetModuleHandleW, FindResourceW, FreeLibrary, GetProcAddress, ExpandEnvironmentStringsW, ExitProcess, SetThreadExecutionState, Sleep, LoadLibraryW, GetSystemDirectoryW, CompareStringW, AllocConsole, FreeConsole, AttachConsole, WriteConsoleW, GetProcessAffinityMask, CreateThread, SetThreadPriority, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, SetEvent, ResetEvent, ReleaseSemaphore, WaitForSingleObject, CreateEventW, CreateSemaphoreW, GetSystemTime, SystemTimeToTzSpecificLocalTime, TzSpecificLocalTimeToSystemTime, SystemTimeToFileTime, FileTimeToLocalFileTime, LocalFileTimeToFileTime, FileTimeToSystemTime, GetCPInfo, IsDBCSLeadByte, MultiByteToWideChar, WideCharToMultiByte, GlobalAlloc, LockResource, GlobalLock, GlobalUnlock, GlobalFree, GlobalMemoryStatusEx, LoadResource, SizeofResource, GetTimeFormatW, GetDateFormatW, GetExitCodeProcess, GetLocalTime, GetTickCount, MapViewOfFile, UnmapViewOfFile, CreateFileMappingW, OpenFileMappingW, GetCommandLineW, SetEnvironmentVariableW, GetTempPathW, MoveFileExW, GetLocaleInfoW, GetNumberFormatW, SetFilePointerEx, GetConsoleMode, GetConsoleCP, HeapSize, SetStdHandle, GetProcessHeap, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineA, GetOEMCP, IsValidCodePage, FindNextFileA, RaiseException, GetSystemInfo, VirtualProtect, VirtualQuery, LoadLibraryExA, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, TerminateProcess, IsProcessorFeaturePresent, InitializeCriticalSectionAndSpinCount, WaitForSingleObjectEx, IsDebuggerPresent, GetStartupInfoW, QueryPerformanceCounter, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, RtlPcToFileHeader, RtlUnwindEx, EncodePointer, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, LoadLibraryExW, QueryPerformanceFrequency, GetModuleHandleExW, GetModuleFileNameA, GetACP, HeapFree, HeapAlloc, GetStringTypeW, HeapReAlloc, LCMapStringW, FindFirstFileExA |
OLEAUT32.dll | SysAllocString, SysFreeString, VariantClear |
gdiplus.dll | GdipCloneImage, GdipFree, GdipDisposeImage, GdipCreateBitmapFromStream, GdipCreateHBITMAPFromBitmap, GdiplusStartup, GdiplusShutdown, GdipAlloc |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 9, 2024 07:03:43.521142006 CET | 49730 | 80 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:43.640774012 CET | 80 | 49730 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:43.640857935 CET | 49730 | 80 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:43.643467903 CET | 49730 | 80 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:43.762876987 CET | 80 | 49730 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:45.094494104 CET | 80 | 49730 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:45.096118927 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:45.096172094 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:45.096326113 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:45.106193066 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:45.106208086 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:45.139740944 CET | 49730 | 80 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:46.733144045 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:46.733297110 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:46.738733053 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:46.738739967 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:46.739100933 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:46.795588017 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:46.843327045 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.694281101 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.694374084 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.694412947 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.694434881 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.694458961 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:47.694475889 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.694493055 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:47.694515944 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:47.699702024 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.712928057 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.712969065 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.713015079 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:47.713030100 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.713071108 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:47.721209049 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.764744997 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:47.878501892 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.882263899 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.882317066 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.882417917 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:47.882433891 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.882488966 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:47.890928030 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.901038885 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.901109934 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:47.901124954 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.908914089 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.908992052 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:47.908999920 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.916821003 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.916902065 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:47.916909933 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.924841881 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.924870968 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.924945116 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:47.924954891 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.925007105 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:47.932635069 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.940484047 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.940562963 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.940578938 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:47.940593004 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.940637112 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:47.948374987 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.956238031 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.956317902 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:47.956335068 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.964076996 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:47.964162111 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:47.964171886 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.014769077 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:48.062341928 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.070310116 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.070391893 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:48.070411921 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.073375940 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.073470116 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:48.073478937 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.079513073 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.079593897 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:48.079601049 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.088835955 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.088932037 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.088948965 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:48.088958025 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.089004993 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:48.094599962 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.100436926 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.100513935 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:48.100521088 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.106491089 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.106559038 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:48.106570959 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.111939907 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.112004042 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:48.112015963 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.117692947 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.117744923 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:48.117758989 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.123473883 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.123549938 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:48.123562098 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.129244089 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.129292965 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:48.129301071 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.140568018 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.140640974 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:03:48.140647888 CET | 443 | 49731 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:03:48.141205072 CET | 49731 | 443 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:04:00.095634937 CET | 80 | 49730 | 20.233.83.145 | 192.168.2.4 |
Dec 9, 2024 07:04:00.095794916 CET | 49730 | 80 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:05:07.047285080 CET | 49785 | 443 | 192.168.2.4 | 69.192.108.223 |
Dec 9, 2024 07:05:07.047305107 CET | 443 | 49785 | 69.192.108.223 | 192.168.2.4 |
Dec 9, 2024 07:05:07.047379017 CET | 49785 | 443 | 192.168.2.4 | 69.192.108.223 |
Dec 9, 2024 07:05:07.047559023 CET | 49785 | 443 | 192.168.2.4 | 69.192.108.223 |
Dec 9, 2024 07:05:07.047569990 CET | 443 | 49785 | 69.192.108.223 | 192.168.2.4 |
Dec 9, 2024 07:05:08.260246992 CET | 443 | 49785 | 69.192.108.223 | 192.168.2.4 |
Dec 9, 2024 07:05:08.362853050 CET | 49785 | 443 | 192.168.2.4 | 69.192.108.223 |
Dec 9, 2024 07:05:08.362884998 CET | 443 | 49785 | 69.192.108.223 | 192.168.2.4 |
Dec 9, 2024 07:05:08.364104033 CET | 443 | 49785 | 69.192.108.223 | 192.168.2.4 |
Dec 9, 2024 07:05:08.364120007 CET | 443 | 49785 | 69.192.108.223 | 192.168.2.4 |
Dec 9, 2024 07:05:08.364187956 CET | 49785 | 443 | 192.168.2.4 | 69.192.108.223 |
Dec 9, 2024 07:05:08.484380007 CET | 49785 | 443 | 192.168.2.4 | 69.192.108.223 |
Dec 9, 2024 07:05:08.484555006 CET | 443 | 49785 | 69.192.108.223 | 192.168.2.4 |
Dec 9, 2024 07:05:08.573370934 CET | 49785 | 443 | 192.168.2.4 | 69.192.108.223 |
Dec 9, 2024 07:05:08.573399067 CET | 443 | 49785 | 69.192.108.223 | 192.168.2.4 |
Dec 9, 2024 07:05:08.776489019 CET | 49785 | 443 | 192.168.2.4 | 69.192.108.223 |
Dec 9, 2024 07:05:23.184171915 CET | 49730 | 80 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:05:23.526534081 CET | 49730 | 80 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:05:24.229654074 CET | 49730 | 80 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:05:25.526705027 CET | 49730 | 80 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:05:27.574373007 CET | 443 | 49785 | 69.192.108.223 | 192.168.2.4 |
Dec 9, 2024 07:05:27.574461937 CET | 443 | 49785 | 69.192.108.223 | 192.168.2.4 |
Dec 9, 2024 07:05:27.574558020 CET | 49785 | 443 | 192.168.2.4 | 69.192.108.223 |
Dec 9, 2024 07:05:28.026695967 CET | 49730 | 80 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:05:33.026599884 CET | 49730 | 80 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:05:43.026597977 CET | 49730 | 80 | 192.168.2.4 | 20.233.83.145 |
Dec 9, 2024 07:06:12.776721001 CET | 49785 | 443 | 192.168.2.4 | 69.192.108.223 |
Dec 9, 2024 07:06:12.776751041 CET | 443 | 49785 | 69.192.108.223 | 192.168.2.4 |
Dec 9, 2024 07:06:57.870714903 CET | 49785 | 443 | 192.168.2.4 | 69.192.108.223 |
Dec 9, 2024 07:06:57.870780945 CET | 443 | 49785 | 69.192.108.223 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 9, 2024 07:03:43.373780012 CET | 62332 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 9, 2024 07:03:43.510727882 CET | 53 | 62332 | 1.1.1.1 | 192.168.2.4 |
Dec 9, 2024 07:03:43.536669970 CET | 59154 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 9, 2024 07:03:44.108558893 CET | 53 | 59154 | 1.1.1.1 | 192.168.2.4 |
Dec 9, 2024 07:05:08.934978962 CET | 52689 | 53 | 192.168.2.4 | 1.1.1.1 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Dec 9, 2024 07:03:44.119338989 CET | 192.168.2.4 | 185.178.208.190 | 4d5a | Echo | |
Dec 9, 2024 07:03:48.770092010 CET | 192.168.2.4 | 185.178.208.190 | 4d59 | Echo | |
Dec 9, 2024 07:03:56.160629034 CET | 192.168.2.4 | 185.178.208.190 | 4d58 | Echo | |
Dec 9, 2024 07:04:00.977262020 CET | 192.168.2.4 | 185.178.208.190 | 4d57 | Echo | |
Dec 9, 2024 07:04:09.862446070 CET | 192.168.2.4 | 185.178.208.190 | 4d56 | Echo | |
Dec 9, 2024 07:04:15.073781013 CET | 192.168.2.4 | 185.178.208.190 | 4d55 | Echo | |
Dec 9, 2024 07:04:23.524650097 CET | 192.168.2.4 | 185.178.208.190 | 4d54 | Echo | |
Dec 9, 2024 07:04:32.318049908 CET | 192.168.2.4 | 185.178.208.190 | 4d53 | Echo | |
Dec 9, 2024 07:07:03.209980011 CET | 192.168.2.4 | 185.178.208.190 | 4d52 | Echo | |
Dec 9, 2024 07:07:12.915436983 CET | 192.168.2.4 | 185.178.208.190 | 4d51 | Echo | |
Dec 9, 2024 07:07:15.993057966 CET | 192.168.2.4 | 185.178.208.190 | 4d50 | Echo | |
Dec 9, 2024 07:07:21.276700020 CET | 192.168.2.4 | 185.178.208.190 | 4d4f | Echo | |
Dec 9, 2024 07:07:24.274765968 CET | 192.168.2.4 | 185.178.208.190 | 4d4e | Echo | |
Dec 9, 2024 07:07:29.749423027 CET | 192.168.2.4 | 185.178.208.190 | 4d4d | Echo | |
Dec 9, 2024 07:07:32.258939028 CET | 192.168.2.4 | 185.178.208.190 | 4d4c | Echo | |
Dec 9, 2024 07:07:41.130366087 CET | 192.168.2.4 | 185.178.208.190 | 4d4b | Echo | |
Dec 9, 2024 07:07:48.962646961 CET | 192.168.2.4 | 185.178.208.190 | 4d4a | Echo |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 9, 2024 07:03:43.373780012 CET | 192.168.2.4 | 1.1.1.1 | 0xc323 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 9, 2024 07:03:43.536669970 CET | 192.168.2.4 | 1.1.1.1 | 0x8745 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 9, 2024 07:05:08.934978962 CET | 192.168.2.4 | 1.1.1.1 | 0x8e2f | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 9, 2024 07:03:43.510727882 CET | 1.1.1.1 | 192.168.2.4 | 0xc323 | No error (0) | 20.233.83.145 | A (IP address) | IN (0x0001) | false | ||
Dec 9, 2024 07:03:44.108558893 CET | 1.1.1.1 | 192.168.2.4 | 0x8745 | No error (0) | 185.178.208.190 | A (IP address) | IN (0x0001) | false | ||
Dec 9, 2024 07:05:09.151154995 CET | 1.1.1.1 | 192.168.2.4 | 0x8e2f | No error (0) | crl.root-x1.letsencrypt.org.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49730 | 20.233.83.145 | 80 | 6360 | C:\Users\user\AppData\Local\Temp\RarSFX0\black.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 9, 2024 07:03:43.643467903 CET | 126 | OUT | |
Dec 9, 2024 07:03:45.094494104 CET | 150 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49731 | 20.233.83.145 | 443 | 6360 | C:\Users\user\AppData\Local\Temp\RarSFX0\black.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-09 06:03:46 UTC | 126 | OUT | |
2024-12-09 06:03:47 UTC | 442 | IN | |
2024-12-09 06:03:47 UTC | 3388 | IN | |
2024-12-09 06:03:47 UTC | 280 | IN | |
2024-12-09 06:03:47 UTC | 1370 | IN | |
2024-12-09 06:03:47 UTC | 884 | IN | |
2024-12-09 06:03:47 UTC | 1370 | IN | |
2024-12-09 06:03:47 UTC | 1370 | IN | |
2024-12-09 06:03:47 UTC | 1370 | IN | |
2024-12-09 06:03:47 UTC | 1370 | IN | |
2024-12-09 06:03:47 UTC | 1370 | IN | |
2024-12-09 06:03:47 UTC | 140 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 01:03:37 |
Start date: | 09/12/2024 |
Path: | C:\Users\user\Desktop\Y5kEUsYDFr.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6ca9c0000 |
File size: | 912'111 bytes |
MD5 hash: | EC773998B0078CC58100FDB4D27DC3F4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 01:03:37 |
Start date: | 09/12/2024 |
Path: | C:\Users\user\AppData\Local\Temp\RarSFX0\black.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x120000 |
File size: | 550'912 bytes |
MD5 hash: | 09929B04B0C29E2722009F49FAF7183C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 01:03:42 |
Start date: | 09/12/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x240000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 01:03:42 |
Start date: | 09/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 01:03:42 |
Start date: | 09/12/2024 |
Path: | C:\Windows\SysWOW64\PING.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xe40000 |
File size: | 18'944 bytes |
MD5 hash: | B3624DD758CCECF93A1226CEF252CA12 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 01:03:50 |
Start date: | 09/12/2024 |
Path: | C:\Users\user\AppData\Roaming\black.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x300000 |
File size: | 550'912 bytes |
MD5 hash: | 09929B04B0C29E2722009F49FAF7183C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | low |
Has exited: | false |
Target ID: | 9 |
Start time: | 01:03:53 |
Start date: | 09/12/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x240000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 10 |
Start time: | 01:03:53 |
Start date: | 09/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 12 |
Start time: | 01:03:56 |
Start date: | 09/12/2024 |
Path: | C:\Windows\SysWOW64\PING.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xe40000 |
File size: | 18'944 bytes |
MD5 hash: | B3624DD758CCECF93A1226CEF252CA12 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 18 |
Start time: | 01:04:18 |
Start date: | 09/12/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6bc1b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 23 |
Start time: | 01:04:39 |
Start date: | 09/12/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 26 |
Start time: | 01:04:43 |
Start date: | 09/12/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 36 |
Start time: | 01:06:42 |
Start date: | 09/12/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x240000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | false |
Target ID: | 37 |
Start time: | 01:06:42 |
Start date: | 09/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | false |
Target ID: | 38 |
Start time: | 01:06:47 |
Start date: | 09/12/2024 |
Path: | C:\Windows\SysWOW64\PING.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xe40000 |
File size: | 18'944 bytes |
MD5 hash: | B3624DD758CCECF93A1226CEF252CA12 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | false |
Target ID: | 39 |
Start time: | 01:06:54 |
Start date: | 09/12/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x240000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Target ID: | 40 |
Start time: | 01:06:54 |
Start date: | 09/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Target ID: | 41 |
Start time: | 01:06:59 |
Start date: | 09/12/2024 |
Path: | C:\Windows\SysWOW64\PING.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xe40000 |
File size: | 18'944 bytes |
MD5 hash: | B3624DD758CCECF93A1226CEF252CA12 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Execution Graph
Execution Coverage: | 11.9% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 28% |
Total number of Nodes: | 2000 |
Total number of Limit Nodes: | 26 |
Graph
Function 00007FF6CA9EB190 Relevance: 118.7, APIs: 57, Strings: 10, Instructions: 1421windowfilesleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9ECE88 Relevance: 63.2, APIs: 25, Strings: 10, Instructions: 1963windowfileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9F0754 Relevance: 42.4, APIs: 19, Strings: 5, Instructions: 380filesleeptimeCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9DA4AC Relevance: 23.0, APIs: 11, Strings: 2, Instructions: 250COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9E8624 Relevance: 21.1, APIs: 11, Strings: 1, Instructions: 101memorywindowCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9CF930 Relevance: 17.2, APIs: 8, Strings: 1, Instructions: 1417COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9C4840 Relevance: 12.1, APIs: 5, Strings: 1, Instructions: 1624COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9C5E24 Relevance: 7.6, APIs: 3, Strings: 1, Instructions: 586COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9E1F20 Relevance: .3, Instructions: 337COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9E3484 Relevance: .3, Instructions: 302COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9D4928 Relevance: .1, Instructions: 136COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9DDFD0 Relevance: 143.9, APIs: 16, Strings: 66, Instructions: 440libraryfileloaderCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9D98DC Relevance: 25.2, APIs: 3, Strings: 11, Instructions: 702COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9F1900 Relevance: 22.9, APIs: 12, Strings: 1, Instructions: 195libraryCOMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9EF4E0 Relevance: 21.3, APIs: 8, Strings: 4, Instructions: 285windowCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9EF0A4 Relevance: 16.6, APIs: 11, Instructions: 102windowCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9D24C0 Relevance: 9.2, APIs: 6, Instructions: 164filetimeCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9EFE24 Relevance: 7.5, APIs: 5, Instructions: 29windowsynchronizationCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9E91E8 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 33COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9EB014 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 54windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9DEAA4 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 42threadCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9E946C Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 26comCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9FD90C Relevance: 3.0, APIs: 2, Instructions: 19memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9F1558 Relevance: 1.5, APIs: 1, Instructions: 38COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9D7FC4 Relevance: 1.5, APIs: 1, Instructions: 9COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9FFA04 Relevance: 1.3, APIs: 1, Instructions: 36memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9FD94C Relevance: 1.3, APIs: 1, Instructions: 29memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9CC2F0 Relevance: 49.8, APIs: 24, Strings: 4, Instructions: 754fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9DF180 Relevance: 43.2, APIs: 22, Strings: 2, Instructions: 1205COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CAA02550 Relevance: 22.3, APIs: 8, Strings: 4, Instructions: 1310COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9D1A48 Relevance: 17.9, APIs: 9, Strings: 1, Instructions: 375fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9F76D8 Relevance: 9.1, APIs: 6, Instructions: 83COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9FFA94 Relevance: 5.4, APIs: 1, Strings: 2, Instructions: 164COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CAA02080 Relevance: 4.8, APIs: 3, Instructions: 340COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9FFCA0 Relevance: 3.6, APIs: 1, Strings: 1, Instructions: 97COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CAA05AF8 Relevance: 3.2, APIs: 2, Instructions: 227COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9F8C1C Relevance: 1.5, Strings: 1, Instructions: 219COMMONLIBRARYCODE
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9F89A0 Relevance: 1.4, Strings: 1, Instructions: 199COMMONLIBRARYCODE
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9E3964 Relevance: .9, Instructions: 931COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9C76C0 Relevance: .9, Instructions: 893COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9E53F0 Relevance: .9, Instructions: 891COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9DBB90 Relevance: .6, Instructions: 587COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9E4B98 Relevance: .6, Instructions: 578COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9C7288 Relevance: .3, Instructions: 294COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9E2D58 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9DAF18 Relevance: .2, Instructions: 244COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9CA310 Relevance: .2, Instructions: 230COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9DB534 Relevance: .2, Instructions: 181COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9E21D0 Relevance: .1, Instructions: 137COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9E2AB0 Relevance: .1, Instructions: 112COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9DDC70 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9F3354 Relevance: .0, Instructions: 2COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9CD7D0 Relevance: 26.3, APIs: 1, Strings: 14, Instructions: 98COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9F2A10 Relevance: 21.1, APIs: 8, Strings: 4, Instructions: 61libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9D6A0C Relevance: 16.2, APIs: 6, Strings: 3, Instructions: 444COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9E6E80 Relevance: 16.0, APIs: 5, Strings: 4, Instructions: 204memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9FE650 Relevance: 15.9, APIs: 1, Strings: 8, Instructions: 117COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9EA440 Relevance: 14.3, APIs: 6, Strings: 2, Instructions: 257COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9EF390 Relevance: 14.1, APIs: 7, Strings: 1, Instructions: 85windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9DB9B4 Relevance: 14.1, APIs: 3, Strings: 5, Instructions: 84libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9E87D8 Relevance: 12.7, APIs: 5, Strings: 2, Instructions: 415COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9F57EC Relevance: 10.8, APIs: 3, Strings: 3, Instructions: 317COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9D4F38 Relevance: 10.7, APIs: 1, Strings: 5, Instructions: 158COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9EAE90 Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 94COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9F72EC Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 88libraryloaderCOMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9F1604 Relevance: 10.5, APIs: 3, Strings: 3, Instructions: 43libraryloaderCOMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9D7918 Relevance: 9.0, APIs: 1, Strings: 4, Instructions: 233COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9F5CE8 Relevance: 8.9, APIs: 3, Strings: 2, Instructions: 191COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9F4F80 Relevance: 8.9, APIs: 3, Strings: 2, Instructions: 144COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9CCEE0 Relevance: 8.9, APIs: 3, Strings: 2, Instructions: 139COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9E7B28 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 122COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9EFD0C Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 76COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9EFED4 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 52COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9FBFB0 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 29libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9D3AF8 Relevance: 7.7, APIs: 5, Instructions: 164filetimeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9FF414 Relevance: 7.6, APIs: 5, Instructions: 114libraryloaderCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CAA056D8 Relevance: 7.6, APIs: 5, Instructions: 56COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9F625C Relevance: 7.2, APIs: 2, Strings: 2, Instructions: 163COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9F80F4 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 145COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CAA01758 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 126COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9F66A0 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 117COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CAA04360 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 100fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9E90B0 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 83COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9DE870 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 53COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9E85E0 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 19COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9FDB5C Relevance: 6.1, APIs: 4, Instructions: 104COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9FD440 Relevance: 6.0, APIs: 4, Instructions: 43COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9CE34C Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 176COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9FE1F4 Relevance: 5.4, APIs: 1, Strings: 2, Instructions: 138COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9D9408 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 108COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9FC2C0 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 107COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9D9638 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 84COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9F0204 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 75windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9FEB04 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 70COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9F4078 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 42COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9DEA5C Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 16synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF6CA9DA43C Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 15COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 21.5% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 92.3% |
Total number of Nodes: | 39 |
Total number of Limit Nodes: | 0 |
Graph
Function 00CD6301 Relevance: 28.7, Strings: 17, Instructions: 7481COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDC6E0 Relevance: 3.9, Strings: 3, Instructions: 158COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02500B18 Relevance: 3.8, Strings: 3, Instructions: 71COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 023D7290 Relevance: 3.6, APIs: 1, Strings: 1, Instructions: 106nativeCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDADD8 Relevance: 3.0, Strings: 2, Instructions: 487COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDADC8 Relevance: 2.8, Strings: 2, Instructions: 332COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02500B01 Relevance: 2.6, Strings: 2, Instructions: 74COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02500818 Relevance: 2.6, Strings: 2, Instructions: 56COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDEA00 Relevance: 1.8, Strings: 1, Instructions: 558COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDD3A8 Relevance: 1.8, Strings: 1, Instructions: 547COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 023AC4C8 Relevance: 1.6, APIs: 1, Instructions: 148nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 023AC4D0 Relevance: 1.6, APIs: 1, Instructions: 144nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 023AC268 Relevance: 1.6, APIs: 1, Instructions: 123nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 023AC270 Relevance: 1.6, APIs: 1, Instructions: 119nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 023AB418 Relevance: 1.6, APIs: 1, Instructions: 106nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 023AB750 Relevance: 1.6, APIs: 1, Instructions: 105nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 023AB74A Relevance: 1.6, APIs: 1, Instructions: 105nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 023AB420 Relevance: 1.6, APIs: 1, Instructions: 103nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 023D7309 Relevance: 1.6, APIs: 1, Instructions: 97nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 023AC3B0 Relevance: 1.6, APIs: 1, Instructions: 97nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 023AC3B8 Relevance: 1.6, APIs: 1, Instructions: 96nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 023AB658 Relevance: 1.6, APIs: 1, Instructions: 74nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 023AB660 Relevance: 1.6, APIs: 1, Instructions: 73nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDBD00 Relevance: 1.5, Strings: 1, Instructions: 293COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDE618 Relevance: 1.5, Strings: 1, Instructions: 212COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDE628 Relevance: 1.5, Strings: 1, Instructions: 207COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDA188 Relevance: .3, Instructions: 327COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDA178 Relevance: .3, Instructions: 294COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDA6A8 Relevance: .2, Instructions: 199COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDBB20 Relevance: .1, Instructions: 135COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDA698 Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDB7D0 Relevance: .1, Instructions: 107COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDAA50 Relevance: .1, Instructions: 106COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 023D9A4C Relevance: .1, Instructions: 66COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 023D9A58 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02501085 Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02500740 Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 025010A0 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02501288 Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02500CB0 Relevance: 5.1, Strings: 4, Instructions: 58COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDDE38 Relevance: 2.6, Strings: 2, Instructions: 64COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 023D9938 Relevance: 1.6, APIs: 1, Instructions: 92COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 023D9940 Relevance: 1.6, APIs: 1, Instructions: 88COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CD9A90 Relevance: 1.4, Strings: 1, Instructions: 176COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDF908 Relevance: 1.3, Strings: 1, Instructions: 67COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDDE28 Relevance: 1.3, Strings: 1, Instructions: 67COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDACF0 Relevance: 1.3, Strings: 1, Instructions: 64COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDF918 Relevance: 1.3, Strings: 1, Instructions: 60COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CD0839 Relevance: 1.3, Strings: 1, Instructions: 29COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CD0848 Relevance: 1.3, Strings: 1, Instructions: 24COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDFA01 Relevance: .1, Instructions: 135COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDB970 Relevance: .1, Instructions: 127COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDC9C0 Relevance: .1, Instructions: 122COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDCA10 Relevance: .1, Instructions: 119COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDCA20 Relevance: .1, Instructions: 96COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDD9C9 Relevance: .1, Instructions: 92COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDA048 Relevance: .1, Instructions: 91COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDF440 Relevance: .1, Instructions: 87COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDF6F0 Relevance: .1, Instructions: 82COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDE8F0 Relevance: .1, Instructions: 81COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDFE70 Relevance: .1, Instructions: 74COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDC4E8 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0069D104 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0069D030 Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDC1E8 Relevance: .1, Instructions: 65COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDDFC9 Relevance: .1, Instructions: 65COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDDFD8 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDF618 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDF628 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDDF18 Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0069D0FF Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0069D02B Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CD99D8 Relevance: .0, Instructions: 48COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDA9A8 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0068D8B9 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDC1F8 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CD99E8 Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CD9878 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDABC0 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDCB47 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0068D8B8 Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDABD0 Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDDDCC Relevance: .0, Instructions: 33COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CD9BE7 Relevance: .0, Instructions: 32COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CD9F98 Relevance: .0, Instructions: 32COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CD9888 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02500428 Relevance: .0, Instructions: 30COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02500A00 Relevance: .0, Instructions: 29COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02501038 Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02501580 Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CD9EE8 Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CDDDE8 Relevance: .0, Instructions: 21COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00CD9EF8 Relevance: .0, Instructions: 18COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02500C60 Relevance: .0, Instructions: 17COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 025000A0 Relevance: .0, Instructions: 17COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02501700 Relevance: 5.1, Strings: 4, Instructions: 56COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02500A78 Relevance: 2.5, Strings: 2, Instructions: 43COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 025013D0 Relevance: 2.5, Strings: 2, Instructions: 43COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 025012E0 Relevance: 2.5, Strings: 2, Instructions: 43COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 025004A0 Relevance: 1.3, Strings: 1, Instructions: 50COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02500A74 Relevance: 1.3, Strings: 1, Instructions: 39COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02501620 Relevance: 1.3, Strings: 1, Instructions: 27COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 023D28F1 Relevance: .1, Instructions: 87COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 023D2908 Relevance: .1, Instructions: 79COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02500F9E Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02500318 Relevance: .0, Instructions: 40COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 025003A0 Relevance: .0, Instructions: 40COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02500F28 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 025014F8 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02500FB0 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02500BFD Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02500C00 Relevance: .0, Instructions: 25COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 025008E0 Relevance: 5.1, Strings: 4, Instructions: 57COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 31.1% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 36 |
Total number of Limit Nodes: | 0 |
Graph
Function 046C0870 Relevance: 3.8, Strings: 3, Instructions: 71COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 046C0868 Relevance: 2.6, Strings: 2, Instructions: 65COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04BAC4C8 Relevance: 1.6, APIs: 1, Instructions: 146nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04BAC4D0 Relevance: 1.6, APIs: 1, Instructions: 144nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04BAC268 Relevance: 1.6, APIs: 1, Instructions: 121nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04BAC270 Relevance: 1.6, APIs: 1, Instructions: 119nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04BAB418 Relevance: 1.6, APIs: 1, Instructions: 105nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04BAB420 Relevance: 1.6, APIs: 1, Instructions: 103nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 046C0725 Relevance: .0, Instructions: 48COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 046C127D Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 046C0740 Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 046C1298 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 046C0F27 Relevance: .0, Instructions: 32COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 046C0F38 Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 046C0A08 Relevance: 5.1, Strings: 4, Instructions: 58COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 046C09ED Relevance: 2.6, Strings: 2, Instructions: 55COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 046C040D Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 046C0428 Relevance: .0, Instructions: 30COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 046C0085 Relevance: .0, Instructions: 28COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 046C1230 Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 046C1508 Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 046C0999 Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 046C122A Relevance: .0, Instructions: 23COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 046C1502 Relevance: .0, Instructions: 22COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 046C00A0 Relevance: .0, Instructions: 17COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 046C09B8 Relevance: .0, Instructions: 17COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|