Windows
Analysis Report
IXCbn4ZcdS.exe
Overview
General Information
Sample name: | IXCbn4ZcdS.exerenamed because original name is a hash value |
Original sample name: | 5dcbcb9f5b780bb07e8eb4e98313fc5d0b222823ac94d338b3c3e3fb3efb77e5.exe |
Analysis ID: | 1573905 |
MD5: | b1a62f3fd3a9a4a06c6bbffbb1cbb463 |
SHA1: | f3954f2ddbbe05daa9eeb3e9a9e0bb661f925e76 |
SHA256: | 5dcbcb9f5b780bb07e8eb4e98313fc5d0b222823ac94d338b3c3e3fb3efb77e5 |
Tags: | 181-131-217-244exeuser-JAMESWT_MHT |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- IXCbn4ZcdS.exe (PID: 6244 cmdline:
"C:\Users\ user\Deskt op\IXCbn4Z cdS.exe" MD5: B1A62F3FD3A9A4A06C6BBFFBB1CBB463) - IXCbn4ZcdS.exe (PID: 3348 cmdline:
"C:\Users\ user\Deskt op\IXCbn4Z cdS.exe" MD5: B1A62F3FD3A9A4A06C6BBFFBB1CBB463)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Remcos, RemcosRAT | Remcos (acronym of Remote Control & Surveillance Software) is a commercial Remote Access Tool to remotely control computers.Remcos is advertised as legitimate software which can be used for surveillance and penetration testing purposes, but has been used in numerous hacking campaigns.Remcos, once installed, opens a backdoor on the computer, granting full access to the remote user.Remcos is developed by the cybersecurity company BreakingSecurity. |
{"Host:Port:Password": ["navegacionseguracol24vip.org:30201:0"], "Assigned name": "neptuno", "Connect interval": "1", "Install flag": "Disable", "Setup HKCU\\Run": "Enable", "Setup HKLM\\Run": "Enable", "Install path": "Application path", "Copy file": "remcos.exe", "Startup value": "Enable", "Hide file": "Disable", "Mutex": "mzxbmzmznxbcvzmnxvcnzbcx-T9CO3X", "Keylog flag": "1", "Keylog path": "Application path", "Keylog file": "registros.dat", "Keylog crypt": "Disable", "Hide keylog file": "Disable", "Screenshot flag": "Disable", "Screenshot time": "1", "Take Screenshot option": "Disable", "Take screenshot title": "", "Take screenshot time": "5", "Screenshot path": "AppData", "Screenshot file": "Capturas de pantalla", "Screenshot crypt": "Disable", "Mouse option": "Disable", "Delete file": "Disable", "Audio record time": "5", "Audio folder": "MicRecords", "Connect delay": "0", "Copy folder": "Remcos", "Keylog folder": "registro", "Keylog file max size": ""}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Remcos | Yara detected Remcos RAT | Joe Security | ||
JoeSecurity_Keylogger_Generic | Yara detected Keylogger Generic | Joe Security | ||
JoeSecurity_Remcos | Yara detected Remcos RAT | Joe Security | ||
JoeSecurity_UACBypassusingCMSTP | Yara detected UAC Bypass using CMSTP | Joe Security | ||
Windows_Trojan_Remcos_b296e965 | unknown | unknown |
| |
Click to see the 22 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Keylogger_Generic | Yara detected Keylogger Generic | Joe Security | ||
JoeSecurity_Remcos | Yara detected Remcos RAT | Joe Security | ||
JoeSecurity_UACBypassusingCMSTP | Yara detected UAC Bypass using CMSTP | Joe Security | ||
Windows_Trojan_Remcos_b296e965 | unknown | unknown |
| |
REMCOS_RAT_variants | unknown | unknown |
| |
Click to see the 31 entries |
System Summary |
---|
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-12T17:52:16.783769+0100 | 2032776 | 1 | Malware Command and Control Activity Detected | 192.168.2.9 | 49709 | 181.131.217.244 | 30201 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-12T17:52:27.054987+0100 | 2032777 | 1 | Malware Command and Control Activity Detected | 181.131.217.244 | 30201 | 192.168.2.9 | 49709 | TCP |
2024-12-12T17:54:31.751110+0100 | 2032777 | 1 | Malware Command and Control Activity Detected | 181.131.217.244 | 30201 | 192.168.2.9 | 49709 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-12T17:52:28.865468+0100 | 2803304 | 3 | Unknown Traffic | 192.168.2.9 | 49710 | 178.237.33.50 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira URL Cloud: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Integrated Neural Analysis Model: |
Source: | Code function: | 5_2_006C293A |
Source: | Binary or memory string: | memstr_3e024125-0 |
Exploits |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Privilege Escalation |
---|
Source: | Code function: | 5_2_00696764 |
Source: | Static PE information: |
Source: | Binary string: |
Source: | Code function: | 0_2_0040A0D8 | |
Source: | Code function: | 0_2_0040A0A0 | |
Source: | Code function: | 0_2_004151A0 | |
Source: | Code function: | 0_2_00414290 | |
Source: | Code function: | 0_2_00414340 | |
Source: | Code function: | 0_2_00414380 | |
Source: | Code function: | 0_2_004145D0 | |
Source: | Code function: | 0_2_00415590 | |
Source: | Code function: | 0_2_00414626 | |
Source: | Code function: | 0_2_00414697 | |
Source: | Code function: | 0_2_004156B5 | |
Source: | Code function: | 0_2_00415858 | |
Source: | Code function: | 0_2_00413800 | |
Source: | Code function: | 0_2_004158B9 | |
Source: | Code function: | 0_2_00414A00 | |
Source: | Code function: | 0_2_00414C50 | |
Source: | Code function: | 0_2_00414C5E | |
Source: | Code function: | 0_2_0040AC10 | |
Source: | Code function: | 0_2_00414D36 | |
Source: | Code function: | 0_2_00413E20 | |
Source: | Code function: | 0_2_00417E90 | |
Source: | Code function: | 0_2_00409F71 | |
Source: | Code function: | 0_2_00414F30 | |
Source: | Code function: | 5_2_00413800 | |
Source: | Code function: | 5_2_0040A0A0 | |
Source: | Code function: | 5_2_004158B9 | |
Source: | Code function: | 5_2_0040A12D | |
Source: | Code function: | 5_2_004151A0 | |
Source: | Code function: | 5_2_00414A00 | |
Source: | Code function: | 5_2_00414380 | |
Source: | Code function: | 5_2_00414C50 | |
Source: | Code function: | 5_2_00414C5E | |
Source: | Code function: | 5_2_004145D0 | |
Source: | Code function: | 5_2_00415590 | |
Source: | Code function: | 5_2_00413E20 | |
Source: | Code function: | 5_2_00414F30 | |
Source: | Code function: | 5_2_004157F3 | |
Source: | Code function: | 5_2_0069B335 | |
Source: | Code function: | 5_2_006AB42F | |
Source: | Code function: | 5_2_0069B53A | |
Source: | Code function: | 5_2_006DD5E9 | |
Source: | Code function: | 5_2_006989A9 | |
Source: | Code function: | 5_2_00696AC2 | |
Source: | Code function: | 5_2_00697A8C | |
Source: | Code function: | 5_2_006A8C69 | |
Source: | Code function: | 5_2_00698DA7 |
Source: | Code function: | 5_2_00696F06 |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | URLs: |
Source: | TCP traffic: |
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | Suricata IDS: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | Code function: | 5_2_0069455B |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | Code function: | 5_2_006999E4 |
Source: | Windows user hook set: | Jump to behavior |
Source: | Code function: | 5_2_006A59C6 |
Source: | Code function: | 5_2_006A59C6 |
Source: | Code function: | 5_2_006A59C6 |
Source: | Code function: | 5_2_00699B10 |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
E-Banking Fraud |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | Code function: | 5_2_006ABB77 |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | File dump: | Jump to dropped file |
Source: | Process Stats: |
Source: | Code function: | 0_2_0040A580 | |
Source: | Code function: | 0_2_0041383D | |
Source: | Code function: | 5_2_0041383D | |
Source: | Code function: | 5_2_006A58B9 |
Source: | Code function: | 0_2_0041E100 | |
Source: | Code function: | 0_2_004091A5 | |
Source: | Code function: | 0_2_00424250 | |
Source: | Code function: | 0_2_0040721E | |
Source: | Code function: | 0_2_00408638 | |
Source: | Code function: | 0_2_004076C0 | |
Source: | Code function: | 0_2_004066A6 | |
Source: | Code function: | 0_2_00407754 | |
Source: | Code function: | 0_2_0040977E | |
Source: | Code function: | 0_2_00407728 | |
Source: | Code function: | 0_2_004077D8 | |
Source: | Code function: | 0_2_004077E6 | |
Source: | Code function: | 0_2_00407788 | |
Source: | Code function: | 0_2_004087BD | |
Source: | Code function: | 0_2_00407838 | |
Source: | Code function: | 0_2_0040899B | |
Source: | Code function: | 0_2_00407AB1 | |
Source: | Code function: | 0_2_00407B7D | |
Source: | Code function: | 0_2_00407BE2 | |
Source: | Code function: | 0_2_00407BEF | |
Source: | Code function: | 0_2_00408C69 | |
Source: | Code function: | 0_2_00406C00 | |
Source: | Code function: | 0_2_00406D2E | |
Source: | Code function: | 0_2_00415E70 | |
Source: | Code function: | 0_2_00429E1C | |
Source: | Code function: | 5_2_0040899B | |
Source: | Code function: | 5_2_0041F417 | |
Source: | Code function: | 5_2_006AD071 | |
Source: | Code function: | 5_2_006E20D2 | |
Source: | Code function: | 5_2_006CD098 | |
Source: | Code function: | 5_2_006C7150 | |
Source: | Code function: | 5_2_006C61AA | |
Source: | Code function: | 5_2_006B6254 | |
Source: | Code function: | 5_2_006C1377 | |
Source: | Code function: | 5_2_006C651C | |
Source: | Code function: | 5_2_006AE5DF | |
Source: | Code function: | 5_2_006DC739 | |
Source: | Code function: | 5_2_006B67CB | |
Source: | Code function: | 5_2_006C67C6 | |
Source: | Code function: | 5_2_006CC9DD | |
Source: | Code function: | 5_2_006C2A49 | |
Source: | Code function: | 5_2_006C6A8D | |
Source: | Code function: | 5_2_006CCC0C | |
Source: | Code function: | 5_2_006C6D48 | |
Source: | Code function: | 5_2_006C4D22 | |
Source: | Code function: | 5_2_006B6E73 | |
Source: | Code function: | 5_2_006D0E20 | |
Source: | Code function: | 5_2_006CCE3B | |
Source: | Code function: | 5_2_006A2F45 | |
Source: | Code function: | 5_2_006E2F00 | |
Source: | Code function: | 5_2_006B6FAD |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | Code function: | 0_2_00411010 |
Source: | Code function: | 0_2_0040A580 | |
Source: | Code function: | 0_2_0041383D | |
Source: | Code function: | 5_2_0041383D | |
Source: | Code function: | 5_2_006A6AB7 |
Source: | Code function: | 0_2_0040F650 |
Source: | Code function: | 5_2_0069E219 |
Source: | Code function: | 0_2_0040F900 |
Source: | Code function: | 0_2_004013D0 |
Source: | Code function: | 5_2_006A9BC4 |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Static file information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: |
Source: | Code function: | 0_2_004148D0 |
Source: | Code function: | 0_2_00424374 | |
Source: | Code function: | 0_2_0042439C | |
Source: | Code function: | 0_2_00428B4F | |
Source: | Code function: | 0_2_00427E4E | |
Source: | Code function: | 5_2_00428B4F | |
Source: | Code function: | 5_2_00427E4E | |
Source: | Code function: | 5_2_004096E6 | |
Source: | Code function: | 5_2_006E67FE | |
Source: | Code function: | 5_2_006EB9E6 | |
Source: | Code function: | 5_2_006E5EC2 | |
Source: | Code function: | 5_2_006C4009 |
Source: | Code function: | 5_2_00696128 |
Source: | File created: | Jump to dropped file |
Source: | Code function: | 5_2_006A9BC4 |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Source: | Code function: | 0_2_00422CCA |
Source: | Code function: | 5_2_006ABCE3 |
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Code function: | 5_2_0069E54F |
Source: | Code function: | 5_2_006A98C2 |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Dropped PE file which has not been started: | Jump to dropped file |
Source: | API coverage: | ||
Source: | API coverage: |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Code function: | 0_2_0040A0D8 | |
Source: | Code function: | 0_2_0040A0A0 | |
Source: | Code function: | 0_2_004151A0 | |
Source: | Code function: | 0_2_00414290 | |
Source: | Code function: | 0_2_00414340 | |
Source: | Code function: | 0_2_00414380 | |
Source: | Code function: | 0_2_004145D0 | |
Source: | Code function: | 0_2_00415590 | |
Source: | Code function: | 0_2_00414626 | |
Source: | Code function: | 0_2_00414697 | |
Source: | Code function: | 0_2_004156B5 | |
Source: | Code function: | 0_2_00415858 | |
Source: | Code function: | 0_2_00413800 | |
Source: | Code function: | 0_2_004158B9 | |
Source: | Code function: | 0_2_00414A00 | |
Source: | Code function: | 0_2_00414C50 | |
Source: | Code function: | 0_2_00414C5E | |
Source: | Code function: | 0_2_0040AC10 | |
Source: | Code function: | 0_2_00414D36 | |
Source: | Code function: | 0_2_00413E20 | |
Source: | Code function: | 0_2_00417E90 | |
Source: | Code function: | 0_2_00409F71 | |
Source: | Code function: | 0_2_00414F30 | |
Source: | Code function: | 5_2_00413800 | |
Source: | Code function: | 5_2_0040A0A0 | |
Source: | Code function: | 5_2_004158B9 | |
Source: | Code function: | 5_2_0040A12D | |
Source: | Code function: | 5_2_004151A0 | |
Source: | Code function: | 5_2_00414A00 | |
Source: | Code function: | 5_2_00414380 | |
Source: | Code function: | 5_2_00414C50 | |
Source: | Code function: | 5_2_00414C5E | |
Source: | Code function: | 5_2_004145D0 | |
Source: | Code function: | 5_2_00415590 | |
Source: | Code function: | 5_2_00413E20 | |
Source: | Code function: | 5_2_00414F30 | |
Source: | Code function: | 5_2_004157F3 | |
Source: | Code function: | 5_2_0069B335 | |
Source: | Code function: | 5_2_006AB42F | |
Source: | Code function: | 5_2_0069B53A | |
Source: | Code function: | 5_2_006DD5E9 | |
Source: | Code function: | 5_2_006989A9 | |
Source: | Code function: | 5_2_00696AC2 | |
Source: | Code function: | 5_2_00697A8C | |
Source: | Code function: | 5_2_006A8C69 | |
Source: | Code function: | 5_2_00698DA7 |
Source: | Code function: | 5_2_00696F06 |
Source: | Code function: | 0_2_0042407C |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | API call chain: | graph_5-58909 |
Source: | System information queried: | Jump to behavior |
Source: | Code function: | 5_2_006CA65D |
Source: | Code function: | 0_2_004148D0 |
Source: | Code function: | 5_2_006D2554 |
Source: | Code function: | 5_2_006DE92E |
Source: | Process created: | Jump to behavior |
Source: | Code function: | 5_2_006C4168 | |
Source: | Code function: | 5_2_006CA65D | |
Source: | Code function: | 5_2_006C3B44 | |
Source: | Code function: | 5_2_006C3CD7 |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | NtOpenKeyEx: | Jump to behavior | ||
Source: | NtQuerySystemInformation: | Jump to behavior | ||
Source: | NtNotifyChangeKey: | Jump to behavior | ||
Source: | NtSetInformationProcess: | Jump to behavior | ||
Source: | NtCreateFile: | Jump to behavior | ||
Source: | NtSetInformationProcess: | Jump to behavior | ||
Source: | NtSetValueKey: | Jump to behavior | ||
Source: | NtEnumerateValueKey: | Jump to behavior | ||
Source: | NtOpenKey: | Jump to behavior | ||
Source: | NtSetInformationThread: | Jump to behavior | ||
Source: | NtClose: | |||
Source: | NtQueryValueKey: | Jump to behavior | ||
Source: | NtResumeThread: | Jump to behavior | ||
Source: | NtQueryVolumeInformationFile: | Jump to behavior | ||
Source: | NtAllocateVirtualMemory: | Jump to behavior | ||
Source: | NtMapViewOfSection: | Jump to behavior | ||
Source: | NtCreateThreadEx: | Jump to behavior | ||
Source: | NtCreateMutant: | Jump to behavior | ||
Source: | NtOpenFile: | Jump to behavior | ||
Source: | NtUnmapViewOfSection: | Jump to behavior | ||
Source: | NtQueryInformationProcess: | Jump to behavior | ||
Source: | NtEnumerateKey: | Jump to behavior | ||
Source: | NtQueryInformationToken: | Jump to behavior | ||
Source: | NtQueueApcThread: | Jump to behavior | ||
Source: | NtSetTimerEx: | Jump to behavior | ||
Source: | NtQuerySystemInformation: | Jump to behavior | ||
Source: | NtSetSecurityObject: | Jump to behavior | ||
Source: | NtQuerySystemInformation: | Jump to behavior | ||
Source: | NtQueryAttributesFile: | Jump to behavior | ||
Source: | NtSetInformationFile: | Jump to behavior | ||
Source: | NtSetInformationThread: | Jump to behavior | ||
Source: | NtOpenSection: | Jump to behavior | ||
Source: | NtProtectVirtualMemory: | Jump to behavior | ||
Source: | NtCreateKey: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Code function: | 5_2_006A0F36 |
Source: | Code function: | 5_2_006A8754 |
Source: | Code function: | 0_2_00413910 |
Source: | Code function: | 0_2_00413910 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 5_2_006C3E0A |
Source: | Code function: | 0_2_004300E6 | |
Source: | Code function: | 0_2_00432551 | |
Source: | Code function: | 0_2_00430605 | |
Source: | Code function: | 0_2_0043063C | |
Source: | Code function: | 0_2_004306C2 | |
Source: | Code function: | 0_2_0043469C | |
Source: | Code function: | 0_2_00430717 | |
Source: | Code function: | 0_2_004347CC | |
Source: | Code function: | 0_2_00422895 | |
Source: | Code function: | 5_2_00432551 | |
Source: | Code function: | 5_2_0069E679 | |
Source: | Code function: | 5_2_006D70AE | |
Source: | Code function: | 5_2_006E10BA | |
Source: | Code function: | 5_2_006E11E3 | |
Source: | Code function: | 5_2_006E12EA | |
Source: | Code function: | 5_2_006E13B7 | |
Source: | Code function: | 5_2_006D7597 | |
Source: | Code function: | 5_2_006E0A7F | |
Source: | Code function: | 5_2_006E0CF7 | |
Source: | Code function: | 5_2_006E0D42 | |
Source: | Code function: | 5_2_006E0DDD | |
Source: | Code function: | 5_2_006E0E6A |
Source: | Code function: | 0_2_0042B2AC |
Source: | Code function: | 5_2_006AA7A2 |
Source: | Code function: | 0_2_0042D862 |
Source: | Code function: | 0_2_004135C0 |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Code function: | 5_2_0069B21B |
Source: | Code function: | 5_2_0069B335 | |
Source: | Code function: | 5_2_0069B335 |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Code function: | 5_2_00695042 |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Native API | 1 DLL Side-Loading | 1 Abuse Elevation Control Mechanism | 1 Disable or Modify Tools | 1 OS Credential Dumping | 2 System Time Discovery | Remote Services | 11 Archive Collected Data | 12 Ingress Tool Transfer | Exfiltration Over Other Network Medium | 1 System Shutdown/Reboot |
Credentials | Domains | Default Accounts | 12 Command and Scripting Interpreter | 1 Windows Service | 1 DLL Side-Loading | 1 Deobfuscate/Decode Files or Information | 211 Input Capture | 1 Account Discovery | Remote Desktop Protocol | 211 Input Capture | 2 Encrypted Channel | Exfiltration Over Bluetooth | 1 Defacement |
Email Addresses | DNS Server | Domain Accounts | 2 Service Execution | 1 Registry Run Keys / Startup Folder | 1 Bypass User Account Control | 1 Abuse Elevation Control Mechanism | 2 Credentials In Files | 1 System Service Discovery | SMB/Windows Admin Shares | 3 Clipboard Data | 1 Non-Standard Port | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 1 Access Token Manipulation | 2 Obfuscated Files or Information | NTDS | 2 File and Directory Discovery | Distributed Component Object Model | Input Capture | 2 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | 1 Windows Service | 1 DLL Side-Loading | LSA Secrets | 25 System Information Discovery | SSH | Keylogging | 12 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | 112 Process Injection | 1 Bypass User Account Control | Cached Domain Credentials | 31 Security Software Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | 1 Registry Run Keys / Startup Folder | 1 Masquerading | DCSync | 2 Virtualization/Sandbox Evasion | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 2 Virtualization/Sandbox Evasion | Proc Filesystem | 2 Process Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | 1 Access Token Manipulation | /etc/passwd and /etc/shadow | 11 Application Window Discovery | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
IP Addresses | Compromise Infrastructure | Supply Chain Compromise | PowerShell | Cron | Cron | 112 Process Injection | Network Sniffing | 1 System Owner/User Discovery | Shared Webroot | Local Data Staging | File Transfer Protocols | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol | External Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
42% | ReversingLabs | Win32.Infostealer.Tinba | ||
100% | Avira | TR/Crypt.XPACK.Gen3 |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
navegacionseguracol24vip.org | 181.131.217.244 | true | false | high | |
geoplugin.net | 178.237.33.50 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
181.131.217.244 | navegacionseguracol24vip.org | Colombia | 13489 | EPMTelecomunicacionesSAESPCO | false | |
178.237.33.50 | geoplugin.net | Netherlands | 8455 | ATOM86-ASATOM86NL | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1573905 |
Start date and time: | 2024-12-12 17:50:57 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 9m 1s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 9 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | IXCbn4ZcdS.exerenamed because original name is a hash value |
Original Sample Name: | 5dcbcb9f5b780bb07e8eb4e98313fc5d0b222823ac94d338b3c3e3fb3efb77e5.exe |
Detection: | MAL |
Classification: | mal100.rans.troj.spyw.expl.evad.winEXE@3/3@2/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 4.175.87.197
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing disassembly code.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: IXCbn4ZcdS.exe
Time | Type | Description |
---|---|---|
11:52:49 | API Interceptor | |
16:52:25 | Autostart | |
16:52:34 | Autostart |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
181.131.217.244 | Get hash | malicious | Remcos | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | Unknown | Browse | |||
178.237.33.50 | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos, GuLoader | Browse |
| ||
Get hash | malicious | GuLoader, Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
navegacionseguracol24vip.org | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
geoplugin.net | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos, GuLoader | Browse |
| ||
Get hash | malicious | GuLoader, Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
EPMTelecomunicacionesSAESPCO | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
ATOM86-ASATOM86NL | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos, GuLoader | Browse |
| ||
Get hash | malicious | GuLoader, Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
|
Process: | C:\Users\user\Desktop\IXCbn4ZcdS.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 486 |
Entropy (8bit): | 3.2862379567324242 |
Encrypted: | false |
SSDEEP: | 12:6laDEhecmlaDubWFeglaYla66bWFe5UlablahbW+:6KvcmKqWDHd+WqUkiW+ |
MD5: | 89CD11872C5ABDF3107235FBD199A583 |
SHA1: | 0A137B83D40EC65040EFEE0C52CA29F0EF8CA448 |
SHA-256: | B19983A33E2E415108C7A103EEA65B9EFEC20370226F9CE6C10F6E7BDF2428B4 |
SHA-512: | 59076C818889E6C2895A6B18589F9CE4C724A41E2C0A6936B42F81C64F21B0D78FEFEE249477822B6BFF1A3351AE422C5FA13C328A9C00595F02C3C14883BB58 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\IXCbn4ZcdS.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 963 |
Entropy (8bit): | 5.0088110527764815 |
Encrypted: | false |
SSDEEP: | 12:tkluWJmnd6CsGkMyGWKyGXPVGArwY307f7aZHI7GZArpv/mOAaNO+ao9W7iN5zzz:qlupdRNuKyGX85jvXhNlT3/7CcVKWrZ |
MD5: | BD018C0C5F33B3037C1E9B852C5D9744 |
SHA1: | 69225F65C7D5FF12EF0889811B9CB8CE1C1CF0D1 |
SHA-256: | 29AE4457FFF6A1B0F04A9EC87B161876887D8E827EF06A443D61D78C6BA9330A |
SHA-512: | BE6CF8CDC952A9DE6E1F0769934CFC5A07D93C2A2B341083D79D89CDEF6578D0DDF50D8079962DB3490D76A2738EB01678506C2C8B810BDBABFED567D1977BA3 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\IXCbn4ZcdS.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 979567344 |
Entropy (8bit): | 0.03682041999793769 |
Encrypted: | false |
SSDEEP: | |
MD5: | 17603B8A4D6AAAE374A2D28C0C4CD1CB |
SHA1: | 09342D8C2EE695BA39BA766F34F73EF429562D0D |
SHA-256: | 717C0FC750252817AB984B1D6D2E3E31F39BC22ACB82FF7F27F58798AFC024BC |
SHA-512: | 3394F326969E6B92CD9A8BB703DA77186633D5AEA4FC02F0699634201E5E94F0D0C1582C709263D6AF8147011B0AA7C7AD59F2BE4D3AC998A47BA2B7B5BC6C15 |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 6.352465345748113 |
TrID: |
|
File name: | IXCbn4ZcdS.exe |
File size: | 2'457'600 bytes |
MD5: | b1a62f3fd3a9a4a06c6bbffbb1cbb463 |
SHA1: | f3954f2ddbbe05daa9eeb3e9a9e0bb661f925e76 |
SHA256: | 5dcbcb9f5b780bb07e8eb4e98313fc5d0b222823ac94d338b3c3e3fb3efb77e5 |
SHA512: | a53c1789f2c465809b307a1daabc0b4c10fafe983040ac112f0de0cf5afae3b532630095e62971e0588a7fd17b62caa4ff2f06cb04e6e3799ceca4ce43569528 |
SSDEEP: | 24576:pjmc9/6Am6ls/dcaL9dYx0of9R7iYh0iLnS5vyVJ9dHIliC4:pp/hO/d1xdYx0ir7jTGyVJ9dsR4 |
TLSH: | 9EB5064193E5C013F8F76AB8E8396AF44A2A7E31D83CE11F1A047E6D79329D18935763 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A..j...9...9...9...9...9...9...9...9...9...9...9...9...9...9...9...9...9...9...9...9<..9...9j..9...9...9...9...9Rich...9....... |
Icon Hash: | 83b73111292d65c5 |
Entrypoint: | 0x42567d |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE |
DLL Characteristics: | |
Time Stamp: | 0x43A9E2E6 [Wed Dec 21 23:19:02 2005 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | 1b45e9b30691181342689639e3f2a9ef |
Instruction |
---|
push 00000060h |
push 0044C9D0h |
inc eax |
inc ebx |
mov eax, 00000000h |
inc eax |
add eax, ebx |
mov eax, edi |
call 00007F6D38CF5724h |
mov dword ptr [ebp-18h], esp |
mov esi, esp |
mov dword ptr [esi], edi |
push esi |
call dword ptr [004462D4h] |
mov ecx, dword ptr [esi+10h] |
mov dword ptr [00480954h], ecx |
mov eax, dword ptr [esi+04h] |
mov dword ptr [00480960h], eax |
mov edx, dword ptr [esi+08h] |
mov dword ptr [00480964h], edx |
mov esi, dword ptr [esi+0Ch] |
and esi, 00007FFFh |
mov dword ptr [00480958h], esi |
cmp ecx, 02h |
je 00007F6D38D172BEh |
or esi, 00008000h |
mov dword ptr [00480958h], esi |
shl eax, 08h |
add eax, edx |
mov dword ptr [0048095Ch], eax |
xor esi, esi |
push esi |
mov edi, dword ptr [00446338h] |
call 00007F6D38D18ACFh |
dec ebp |
pop edx |
jne 00007F6D38D172D1h |
mov ecx, dword ptr [eax+3Ch] |
add ecx, eax |
cmp dword ptr [ecx], 00004550h |
jne 00007F6D38D172C4h |
movzx eax, word ptr [ecx+18h] |
cmp eax, 0000010Bh |
je 00007F6D38D172D1h |
cmp eax, 0000020Bh |
je 00007F6D38D172B7h |
mov dword ptr [ebp-1Ch], esi |
jmp 00007F6D38D172D9h |
cmp dword ptr [ecx+00000084h], 0Eh |
jbe 00007F6D38D172A4h |
xor eax, eax |
cmp dword ptr [ecx+000000F8h], esi |
jmp 00007F6D38D172C0h |
cmp dword ptr [ecx+74h], 0Eh |
jbe 00007F6D38D17294h |
xor eax, eax |
cmp dword ptr [ecx+000000E8h], esi |
setne al |
mov dword ptr [ebp-1Ch], eax |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x51b74 | 0x104 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x83000 | 0x1ffa7c | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x46600 | 0x1c | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x4ec80 | 0x48 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x46000 | 0x5f4 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x443a4 | 0x45000 | 2692a1debfa0d53fd0e41574cd59f082 | False | 0.5499249886775363 | data | 6.578648209925144 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x46000 | 0xdc08 | 0xe000 | f035081ac4c7ee86cd6ead176dd1c9bb | False | 0.3834228515625 | data | 5.2366811213048665 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x54000 | 0x2e294 | 0x4000 | 8313c86e1a2ce269f3aa390bb3074e9b | False | 0.2427978515625 | data | 2.963596560441913 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x83000 | 0x1ffa7c | 0x200000 | 03e05ef92389f374ffe1153de5ad83f1 | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_CURSOR | 0x86358 | 0x25ac | data | 0.23828287017834923 | ||
RT_CURSOR | 0x88904 | 0x134 | Targa image data - RGB 64 x 65536 x 1 +32 "\001" | English | United States | 0.4805194805194805 |
RT_CURSOR | 0x88a38 | 0xb4 | Targa image data - Map 32 x 65536 x 1 +16 "\001" | English | United States | 0.7 |
RT_CURSOR | 0x88aec | 0x134 | AmigaOS bitmap font "(", fc_YSize 4294967264, 5120 elements, 2nd "\377\360?\377\377\370\177\377\377\374\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377", 3rd | English | United States | 0.36363636363636365 |
RT_CURSOR | 0x88c20 | 0x134 | Targa image data - RLE 64 x 65536 x 1 +32 "\001" | English | United States | 0.35714285714285715 |
RT_CURSOR | 0x88d54 | 0x134 | data | English | United States | 0.37337662337662336 |
RT_CURSOR | 0x88e88 | 0x134 | data | English | United States | 0.37662337662337664 |
RT_CURSOR | 0x88fbc | 0x134 | Targa image data 64 x 65536 x 1 +32 "\001" | English | United States | 0.36688311688311687 |
RT_CURSOR | 0x890f0 | 0x134 | Targa image data 64 x 65536 x 1 +32 "\001" | English | United States | 0.37662337662337664 |
RT_CURSOR | 0x89224 | 0x134 | Targa image data - Mono - RLE 64 x 65536 x 1 +32 "\001" | English | United States | 0.36688311688311687 |
RT_CURSOR | 0x89358 | 0x134 | Targa image data - RGB - RLE 64 x 65536 x 1 +32 "\001" | English | United States | 0.38636363636363635 |
RT_CURSOR | 0x8948c | 0x134 | data | English | United States | 0.44155844155844154 |
RT_CURSOR | 0x895c0 | 0x134 | data | English | United States | 0.4155844155844156 |
RT_CURSOR | 0x896f4 | 0x134 | AmigaOS bitmap font "(", fc_YSize 4294966847, 3840 elements, 2nd "\377?\374\377\377\300\003\377\377\300\003\377\377\340\007\377\377\360\017\377\377\370\037\377\377\374?\377\377\376\177\377\377\377\377\377\377\377\377\377\377\377\377\377", 3rd | English | United States | 0.5422077922077922 |
RT_CURSOR | 0x89828 | 0x134 | data | English | United States | 0.2662337662337662 |
RT_CURSOR | 0x8995c | 0x134 | data | English | United States | 0.2824675324675325 |
RT_CURSOR | 0x89a90 | 0x134 | data | English | United States | 0.3246753246753247 |
RT_BITMAP | 0x89bc4 | 0x14be8 | Device independent bitmap graphic, 302 x 276 x 8, image size 83904, 256 important colors | 0.2927337350531965 | ||
RT_BITMAP | 0x9e7ac | 0xb8 | Device independent bitmap graphic, 12 x 10 x 4, image size 80 | English | United States | 0.44565217391304346 |
RT_BITMAP | 0x9e864 | 0x144 | Device independent bitmap graphic, 33 x 11 x 4, image size 220 | English | United States | 0.37962962962962965 |
RT_ICON | 0x9e9a8 | 0x13c3b | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | 0.9546538200234699 | ||
RT_ICON | 0xb25e4 | 0xc312 | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | 0.8132884777123633 | ||
RT_ICON | 0xbe8f8 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 128, 16 important colors | English | United States | 0.42567567567567566 |
RT_ICON | 0xbea20 | 0x2e8 | Device independent bitmap graphic, 32 x 64 x 4, image size 512, 16 important colors | English | United States | 0.260752688172043 |
RT_MENU | 0xbed08 | 0xe6 | data | English | United States | 0.6304347826086957 |
RT_DIALOG | 0xbedf0 | 0x134 | data | English | United States | 0.5844155844155844 |
RT_DIALOG | 0xbef24 | 0xe8 | data | English | United States | 0.6336206896551724 |
RT_STRING | 0xbf00c | 0x378 | data | Chinese | Taiwan | 0.49436936936936937 |
RT_STRING | 0xbf384 | 0x896 | data | Czech | Czech Republic | 0.29754322111010006 |
RT_STRING | 0xbfc1c | 0x914 | data | Danish | Denmark | 0.2706540447504303 |
RT_STRING | 0xc0530 | 0x9ec | data | German | Germany | 0.27244094488188975 |
RT_STRING | 0xc0f1c | 0xa74 | data | Greek | Greece | 0.2705530642750374 |
RT_STRING | 0xc1990 | 0x922 | data | Finnish | Finland | 0.2523524379811805 |
RT_STRING | 0xc22b4 | 0x95e | data | French | France | 0.25312760633861553 |
RT_STRING | 0xc2c14 | 0x68a | data | Hebrew | Israel | 0.3279569892473118 |
RT_STRING | 0xc32a0 | 0x8e0 | data | Hungarian | Hungary | 0.2953345070422535 |
RT_STRING | 0xc3b80 | 0x8e4 | data | Italian | Italy | 0.2627416520210896 |
RT_STRING | 0xc4464 | 0x550 | data | Japanese | Japan | 0.35294117647058826 |
RT_STRING | 0xc49b4 | 0x55c | data | Korean | North Korea | 0.39941690962099125 |
RT_STRING | 0xc49b4 | 0x55c | data | Korean | South Korea | 0.39941690962099125 |
RT_STRING | 0xc4f10 | 0x8e6 | data | Dutch | Netherlands | 0.26733977172958734 |
RT_STRING | 0xc57f8 | 0x82a | data | Norwegian | Norway | 0.26842105263157895 |
RT_STRING | 0xc6024 | 0x7ee | data | Polish | Poland | 0.28374384236453204 |
RT_STRING | 0xc6814 | 0xa12 | data | Portuguese | Brazil | 0.24204809930178434 |
RT_STRING | 0xc7228 | 0x7ba | data | Russian | Russia | 0.327098078867543 |
RT_STRING | 0xc79e4 | 0x8fc | data | Swedish | Sweden | 0.25478260869565217 |
RT_STRING | 0xc82e0 | 0x7e8 | data | Thai | Thailand | 0.3102766798418972 |
RT_STRING | 0xc8ac8 | 0x3f6 | data | Chinese | China | 0.48520710059171596 |
RT_STRING | 0xc8ec0 | 0x954 | data | Portuguese | Portugal | 0.26256281407035176 |
RT_STRING | 0xc9814 | 0x8f2 | data | 0.251528384279476 | ||
RT_STRING | 0xca108 | 0x8fa | data | English | Canada | 0.24412532637075718 |
RT_STRING | 0xcaa04 | 0x21c | data | Chinese | Taiwan | 0.6444444444444445 |
RT_STRING | 0xcac20 | 0x3ea | data | Czech | Czech Republic | 0.4431137724550898 |
RT_STRING | 0xcb00c | 0x41e | data | Danish | Denmark | 0.3984819734345351 |
RT_STRING | 0xcb42c | 0x512 | AmigaOS bitmap font "o", fc_YSize 25344, 17920 elements, 2nd " ", 3rd "e" | German | Germany | 0.362095531587057 |
RT_STRING | 0xcb940 | 0x482 | data | Greek | Greece | 0.44280762564991333 |
RT_STRING | 0xcbdc4 | 0x504 | data | Finnish | Finland | 0.3598130841121495 |
RT_STRING | 0xcc2c8 | 0x4b6 | data | French | France | 0.3548922056384743 |
RT_STRING | 0xcc780 | 0x384 | data | Hebrew | Israel | 0.4588888888888889 |
RT_STRING | 0xccb04 | 0x466 | data | Hungarian | Hungary | 0.42362344582593253 |
RT_STRING | 0xccf6c | 0x43c | data | Italian | Italy | 0.3966789667896679 |
RT_STRING | 0xcd3a8 | 0x22e | data | Japanese | Japan | 0.6164874551971327 |
RT_STRING | 0xcd5d8 | 0x240 | data | Korean | North Korea | 0.6388888888888888 |
RT_STRING | 0xcd5d8 | 0x240 | data | Korean | South Korea | 0.6388888888888888 |
RT_STRING | 0xcd818 | 0x4e2 | data | Dutch | Netherlands | 0.3424 |
RT_STRING | 0xcdcfc | 0x3e0 | AmigaOS bitmap font "v", fc_YSize 28416, 16640 elements, 2nd "i", 3rd "e" | Norwegian | Norway | 0.4112903225806452 |
RT_STRING | 0xce0dc | 0x4ac | data | Polish | Poland | 0.4080267558528428 |
RT_STRING | 0xce588 | 0x4b0 | data | Portuguese | Brazil | 0.3858333333333333 |
RT_STRING | 0xcea38 | 0x5c8 | data | Russian | Russia | 0.36824324324324326 |
RT_STRING | 0xcf000 | 0x41e | data | Swedish | Sweden | 0.3776091081593928 |
RT_STRING | 0xcf420 | 0x362 | data | Thai | Thailand | 0.46882217090069284 |
RT_STRING | 0xcf784 | 0x1ea | data | Chinese | China | 0.7306122448979592 |
RT_STRING | 0xcf970 | 0x4a6 | data | Portuguese | Portugal | 0.3815126050420168 |
RT_STRING | 0xcfe18 | 0x4ec | AmigaOS bitmap font "s", fc_YSize 24832, 21760 elements, 2nd "c", 3rd "q" | 0.3753968253968254 | ||
RT_STRING | 0xd0304 | 0x3b0 | data | English | Canada | 0.4014830508474576 |
RT_STRING | 0xd06b4 | 0x2c8 | data | Chinese | Taiwan | 0.7780898876404494 |
RT_STRING | 0xd097c | 0x6c2 | data | Czech | Czech Republic | 0.4028901734104046 |
RT_STRING | 0xd1040 | 0x7ec | data | Danish | Denmark | 0.35552268244575935 |
RT_STRING | 0xd182c | 0x8c8 | data | German | Germany | 0.33629893238434166 |
RT_STRING | 0xd20f4 | 0x926 | AmigaOS bitmap font "\301\003\255\003\307\003\277\003\275\003 ", fc_YSize 4294948611, 41987 elements | Greek | Greece | 0.3736122971818958 |
RT_STRING | 0xd2a1c | 0x6a8 | data | Finnish | Finland | 0.3826291079812207 |
RT_STRING | 0xd30c4 | 0x818 | data | French | France | 0.3359073359073359 |
RT_STRING | 0xd38dc | 0x6e0 | data | Hebrew | Israel | 0.38238636363636364 |
RT_STRING | 0xd3fbc | 0x750 | AmigaOS bitmap font "k", fc_YSize 11520, 16640 elements, 2nd " ", 3rd "l" | Hungarian | Hungary | 0.38514957264957267 |
RT_STRING | 0xd470c | 0x7b6 | data | Italian | Italy | 0.34903748733535966 |
RT_STRING | 0xd4ec4 | 0x3e4 | data | Japanese | Japan | 0.5783132530120482 |
RT_STRING | 0xd52a8 | 0x44c | data | Korean | North Korea | 0.5636363636363636 |
RT_STRING | 0xd52a8 | 0x44c | data | Korean | South Korea | 0.5636363636363636 |
RT_STRING | 0xd56f4 | 0x820 | data | Dutch | Netherlands | 0.33557692307692305 |
RT_STRING | 0xd5f14 | 0x742 | AmigaOS bitmap font "j", fc_YSize 30208, 18176 elements, 2nd "r", 3rd "e" | Norwegian | Norway | 0.34607104413347684 |
RT_STRING | 0xd6658 | 0x728 | data | Polish | Poland | 0.384825327510917 |
RT_STRING | 0xd6d80 | 0x84c | data | Portuguese | Brazil | 0.3422787193973635 |
RT_STRING | 0xd75cc | 0x6f2 | data | Russian | Russia | 0.3914510686164229 |
RT_STRING | 0xd7cc0 | 0x7b6 | AmigaOS bitmap font "u", fc_YSize 8192, 19968 elements, 2nd "v", 3rd "e" | Swedish | Sweden | 0.3601823708206687 |
RT_STRING | 0xd8478 | 0x658 | data | Thai | Thailand | 0.42549261083743845 |
RT_STRING | 0xd8ad0 | 0x2e0 | data | Chinese | China | 0.751358695652174 |
RT_STRING | 0xd8db0 | 0x770 | data | Portuguese | Portugal | 0.34558823529411764 |
RT_STRING | 0xd9520 | 0x7b0 | AmigaOS bitmap font "r", fc_YSize 25856, 16640 elements, 2nd "D", 3rd "e" | 0.3475609756097561 | ||
RT_STRING | 0xd9cd0 | 0x7b6 | data | English | Canada | 0.3454913880445795 |
RT_STRING | 0xda488 | 0x2d6 | data | Chinese | Taiwan | 0.7851239669421488 |
RT_STRING | 0xda760 | 0x64a | data | Czech | Czech Republic | 0.45217391304347826 |
RT_STRING | 0xdadac | 0x66c | data | Danish | Denmark | 0.40450121654501214 |
RT_STRING | 0xdb418 | 0x6e0 | Dyalog APL aplcore version 66.0 | German | Germany | 0.4017045454545455 |
RT_STRING | 0xdbaf8 | 0x718 | OpenPGP Secret Key | Greek | Greece | 0.43061674008810574 |
RT_STRING | 0xdc210 | 0x63e | data | Finnish | Finland | 0.4123904881101377 |
RT_STRING | 0xdc850 | 0x65e | data | French | France | 0.4147239263803681 |
RT_STRING | 0xdceb0 | 0x5c4 | data | Hebrew | Israel | 0.45799457994579945 |
RT_STRING | 0xdd474 | 0x5b0 | data | Hungarian | Hungary | 0.45879120879120877 |
RT_STRING | 0xdda24 | 0x67c | data | Italian | Italy | 0.41566265060240964 |
RT_STRING | 0xde0a0 | 0x36a | data | Japanese | Japan | 0.6601830663615561 |
RT_STRING | 0xde40c | 0x380 | data | Korean | North Korea | 0.6662946428571429 |
RT_STRING | 0xde40c | 0x380 | data | Korean | South Korea | 0.6662946428571429 |
RT_STRING | 0xde78c | 0x6c0 | data | Dutch | Netherlands | 0.3894675925925926 |
RT_STRING | 0xdee4c | 0x63a | data | Norwegian | Norway | 0.397741530740276 |
RT_STRING | 0xdf488 | 0x5d0 | data | Polish | Poland | 0.4536290322580645 |
RT_STRING | 0xdfa58 | 0x66a | data | Portuguese | Brazil | 0.4287454323995128 |
RT_STRING | 0xe00c4 | 0x550 | data | Russian | Russia | 0.4625 |
RT_STRING | 0xe0614 | 0x60e | data | Swedish | Sweden | 0.4096774193548387 |
RT_STRING | 0xe0c24 | 0x500 | data | Thai | Thailand | 0.5046875 |
RT_STRING | 0xe1124 | 0x2c8 | data | Chinese | China | 0.827247191011236 |
RT_STRING | 0xe13ec | 0x608 | OpenPGP Secret Key | Portuguese | Portugal | 0.4216321243523316 |
RT_STRING | 0xe19f4 | 0x664 | OpenPGP Secret Key | 0.41503667481662593 | ||
RT_STRING | 0xe2058 | 0x5da | DOS executable (COM, 0x8C-variant) | English | Canada | 0.4205607476635514 |
RT_STRING | 0xe2634 | 0x340 | AmigaOS bitmap font "~v.zMQ\273\214\013N\011\217\204v", fc_YSize 8192, 2638 elements, 2nd "-\212\356v\004\223\014", 3rd "d" | Chinese | Taiwan | 0.6358173076923077 |
RT_STRING | 0xe2974 | 0x6f8 | data | Czech | Czech Republic | 0.36154708520179374 |
RT_STRING | 0xe306c | 0x74c | data | Danish | Denmark | 0.3329764453961456 |
RT_STRING | 0xe37b8 | 0x802 | data | German | Germany | 0.3326829268292683 |
RT_STRING | 0xe3fbc | 0x908 | data | Greek | Greece | 0.3672145328719723 |
RT_STRING | 0xe48c4 | 0x77e | data | Finnish | Finland | 0.35662148070907196 |
RT_STRING | 0xe5044 | 0x842 | data | French | France | 0.33349101229895933 |
RT_STRING | 0xe5888 | 0x626 | data | Hebrew | Israel | 0.40088945362134687 |
RT_STRING | 0xe5eb0 | 0x72a | data | Hungarian | Hungary | 0.36150490730643403 |
RT_STRING | 0xe65dc | 0x7b8 | data | Italian | Italy | 0.3350202429149798 |
RT_STRING | 0xe6d94 | 0x456 | data | Japanese | Japan | 0.4846846846846847 |
RT_STRING | 0xe71ec | 0x45a | data | Korean | North Korea | 0.5197486535008977 |
RT_STRING | 0xe71ec | 0x45a | data | Korean | South Korea | 0.5197486535008977 |
RT_STRING | 0xe7648 | 0x7ce | data | Dutch | Netherlands | 0.3308308308308308 |
RT_STRING | 0xe7e18 | 0x7a6 | data | Norwegian | Norway | 0.3202247191011236 |
RT_STRING | 0xe85c0 | 0x698 | data | Polish | Poland | 0.36729857819905215 |
RT_STRING | 0xe8c58 | 0x85c | data | Portuguese | Brazil | 0.31822429906542055 |
RT_STRING | 0xe94b4 | 0x6b0 | data | Russian | Russia | 0.3679906542056075 |
RT_STRING | 0xe9b64 | 0x6de | data | Swedish | Sweden | 0.34186575654152446 |
RT_STRING | 0xea244 | 0x636 | data | Thai | Thailand | 0.3855345911949686 |
RT_STRING | 0xea87c | 0x346 | data | Chinese | China | 0.636038186157518 |
RT_STRING | 0xeabc4 | 0x7de | data | Portuguese | Portugal | 0.32621648460774577 |
RT_STRING | 0xeb3a4 | 0x73c | data | 0.3250539956803456 | ||
RT_STRING | 0xebae0 | 0x74c | data | English | Canada | 0.3217344753747323 |
RT_STRING | 0xec22c | 0x46e | data | Chinese | Taiwan | 0.599647266313933 |
RT_STRING | 0xec69c | 0x7b8 | data | Czech | Czech Republic | 0.4185222672064777 |
RT_STRING | 0xece54 | 0x82a | data | Danish | Denmark | 0.3736842105263158 |
RT_STRING | 0xed680 | 0x868 | data | German | Germany | 0.3712825278810409 |
RT_STRING | 0xedee8 | 0x966 | data | Greek | Greece | 0.39276807980049877 |
RT_STRING | 0xee850 | 0x954 | data | Finnish | Finland | 0.36139028475711893 |
RT_STRING | 0xef1a4 | 0x94c | PDP-11 demand-paged pure executable not stripped | French | France | 0.36512605042016805 |
RT_STRING | 0xefaf0 | 0x728 | data | Hebrew | Israel | 0.4170305676855895 |
RT_STRING | 0xf0218 | 0x7f8 | data | Hungarian | Hungary | 0.3877450980392157 |
RT_STRING | 0xf0a10 | 0x86a | data | Italian | Italy | 0.37418755803156917 |
RT_STRING | 0xf127c | 0x53e | data | Japanese | Japan | 0.5104321907600596 |
RT_STRING | 0xf17bc | 0x5ae | data | Korean | North Korea | 0.5281980742778541 |
RT_STRING | 0xf17bc | 0x5ae | data | Korean | South Korea | 0.5281980742778541 |
RT_STRING | 0xf1d6c | 0x878 | data | Dutch | Netherlands | 0.3519372693726937 |
RT_STRING | 0xf25e4 | 0x7a4 | data | Norwegian | Norway | 0.37678936605316976 |
RT_STRING | 0xf2d88 | 0x85a | data | Polish | Poland | 0.3985032740879326 |
RT_STRING | 0xf35e4 | 0x8ee | data | Portuguese | Brazil | 0.36832895888014 |
RT_STRING | 0xf3ed4 | 0x83a | data | Russian | Russia | 0.4107312440645774 |
RT_STRING | 0xf4710 | 0x7fa | data | Swedish | Sweden | 0.38050930460333005 |
RT_STRING | 0xf4f0c | 0x738 | data | Thai | Thailand | 0.42045454545454547 |
RT_STRING | 0xf5644 | 0x482 | data | Chinese | China | 0.6091854419410745 |
RT_STRING | 0xf5ac8 | 0x81a | data | Portuguese | Portugal | 0.3799421407907425 |
RT_STRING | 0xf62e4 | 0x858 | data | 0.38436329588014984 | ||
RT_STRING | 0xf6b3c | 0x7ba | data | English | Canada | 0.3822042467138524 |
RT_STRING | 0xf72f8 | 0x38 | data | Chinese | Taiwan | 0.6428571428571429 |
RT_STRING | 0xf7330 | 0x56 | data | Czech | Czech Republic | 0.6511627906976745 |
RT_STRING | 0xf7388 | 0x5e | data | Danish | Denmark | 0.6382978723404256 |
RT_STRING | 0xf73e8 | 0x56 | data | German | Germany | 0.686046511627907 |
RT_STRING | 0xf7440 | 0x5a | data | Greek | Greece | 0.7222222222222222 |
RT_STRING | 0xf749c | 0x5e | data | Finnish | Finland | 0.6382978723404256 |
RT_STRING | 0xf74fc | 0x5a | data | French | France | 0.6444444444444445 |
RT_STRING | 0xf7558 | 0x46 | data | Hebrew | Israel | 0.7 |
RT_STRING | 0xf75a0 | 0x52 | data | Hungarian | Hungary | 0.6341463414634146 |
RT_STRING | 0xf75f4 | 0x62 | data | Italian | Italy | 0.6122448979591837 |
RT_STRING | 0xf7658 | 0x44 | data | Japanese | Japan | 0.6911764705882353 |
RT_STRING | 0xf769c | 0x3c | data | Korean | North Korea | 0.65 |
RT_STRING | 0xf769c | 0x3c | data | Korean | South Korea | 0.65 |
RT_STRING | 0xf76d8 | 0x56 | data | Dutch | Netherlands | 0.6744186046511628 |
RT_STRING | 0xf7730 | 0x68 | data | Norwegian | Norway | 0.6826923076923077 |
RT_STRING | 0xf7798 | 0x96 | data | Polish | Poland | 0.6466666666666666 |
RT_STRING | 0xf7830 | 0x5c | data | Portuguese | Brazil | 0.6630434782608695 |
RT_STRING | 0xf788c | 0x3c | data | Russian | Russia | 0.6333333333333333 |
RT_STRING | 0xf78c8 | 0x5a | data | Swedish | Sweden | 0.6555555555555556 |
RT_STRING | 0xf7924 | 0x48 | data | Thai | Thailand | 0.6527777777777778 |
RT_STRING | 0xf796c | 0x3a | data | Chinese | China | 0.6551724137931034 |
RT_STRING | 0xf79a8 | 0x52 | data | Portuguese | Portugal | 0.6707317073170732 |
RT_STRING | 0xf79fc | 0x5c | data | 0.6630434782608695 | ||
RT_STRING | 0xf7a58 | 0x4a | data | English | Canada | 0.6621621621621622 |
RT_STRING | 0xf7aa4 | 0x298 | data | Chinese | Taiwan | 0.713855421686747 |
RT_STRING | 0xf7d3c | 0x718 | data | Czech | Czech Republic | 0.3601321585903084 |
RT_STRING | 0xf8454 | 0x7a8 | data | Danish | Denmark | 0.3153061224489796 |
RT_STRING | 0xf8bfc | 0x884 | data | German | Germany | 0.31238532110091743 |
RT_STRING | 0xf9480 | 0x820 | data | Greek | Greece | 0.33028846153846153 |
RT_STRING | 0xf9ca0 | 0x7e0 | data | Finnish | Finland | 0.3060515873015873 |
RT_STRING | 0xfa480 | 0x86a | data | French | France | 0.3138347260909935 |
RT_STRING | 0xfacec | 0x5e0 | data | Hebrew | Israel | 0.3696808510638298 |
RT_STRING | 0xfb2cc | 0x718 | data | Hungarian | Hungary | 0.3419603524229075 |
RT_STRING | 0xfb9e4 | 0x810 | data | Italian | Italy | 0.29651162790697677 |
RT_STRING | 0xfc1f4 | 0x442 | data | Japanese | Japan | 0.5376146788990825 |
RT_STRING | 0xfc638 | 0x456 | data | Korean | North Korea | 0.554954954954955 |
RT_STRING | 0xfc638 | 0x456 | data | Korean | South Korea | 0.554954954954955 |
RT_STRING | 0xfca90 | 0x798 | data | Dutch | Netherlands | 0.3045267489711934 |
RT_STRING | 0xfd228 | 0x6e8 | data | Norwegian | Norway | 0.3173076923076923 |
RT_STRING | 0xfd910 | 0x7b0 | data | Polish | Poland | 0.3429878048780488 |
RT_STRING | 0xfe0c0 | 0x7ea | data | Portuguese | Brazil | 0.31539980256663375 |
RT_STRING | 0xfe8ac | 0x710 | data | Russian | Russia | 0.3495575221238938 |
RT_STRING | 0xfefbc | 0x734 | data | Swedish | Sweden | 0.3297180043383948 |
RT_STRING | 0xff6f0 | 0x5e8 | data | Thai | Thailand | 0.37037037037037035 |
RT_STRING | 0xffcd8 | 0x27c | data | Chinese | China | 0.6965408805031447 |
RT_STRING | 0xfff54 | 0x836 | data | Portuguese | Portugal | 0.30209324452902 |
RT_STRING | 0x10078c | 0x8a0 | data | 0.3016304347826087 | ||
RT_STRING | 0x10102c | 0x77e | data | English | Canada | 0.30552659019812306 |
RT_STRING | 0x1017ac | 0xae | data | Chinese | Taiwan | 0.8908045977011494 |
RT_STRING | 0x10185c | 0x1fe | OpenPGP Public Key | Czech | Czech Republic | 0.515686274509804 |
RT_STRING | 0x101a5c | 0x222 | PGP Secret Sub-key - | Danish | Denmark | 0.43956043956043955 |
RT_STRING | 0x101c80 | 0x278 | data | German | Germany | 0.4272151898734177 |
RT_STRING | 0x101ef8 | 0x244 | data | Greek | Greece | 0.4793103448275862 |
RT_STRING | 0x10213c | 0x1de | data | Finnish | Finland | 0.4707112970711297 |
RT_STRING | 0x10231c | 0x230 | data | French | France | 0.4714285714285714 |
RT_STRING | 0x10254c | 0x170 | data | Hebrew | Israel | 0.5081521739130435 |
RT_STRING | 0x1026bc | 0x248 | data | Hungarian | Hungary | 0.4948630136986301 |
RT_STRING | 0x102904 | 0x24c | data | Italian | Italy | 0.42857142857142855 |
RT_STRING | 0x102b50 | 0x108 | data | Japanese | Japan | 0.8068181818181818 |
RT_STRING | 0x102c58 | 0x122 | data | Korean | North Korea | 0.7344827586206897 |
RT_STRING | 0x102c58 | 0x122 | data | Korean | South Korea | 0.7344827586206897 |
RT_STRING | 0x102d7c | 0x270 | data | Dutch | Netherlands | 0.42788461538461536 |
RT_STRING | 0x102fec | 0x1ec | data | Norwegian | Norway | 0.45934959349593496 |
RT_STRING | 0x1031d8 | 0x208 | OpenPGP Public Key | Polish | Poland | 0.5115384615384615 |
RT_STRING | 0x1033e0 | 0x242 | data | Portuguese | Brazil | 0.4429065743944637 |
RT_STRING | 0x103624 | 0x1e6 | data | Russian | Russia | 0.4876543209876543 |
RT_STRING | 0x10380c | 0x21e | OpenPGP Secret Key | Swedish | Sweden | 0.44280442804428044 |
RT_STRING | 0x103a2c | 0x1b4 | data | Thai | Thailand | 0.5779816513761468 |
RT_STRING | 0x103be0 | 0xa8 | data | Chinese | China | 0.8690476190476191 |
RT_STRING | 0x103c88 | 0x254 | data | Portuguese | Portugal | 0.4513422818791946 |
RT_STRING | 0x103edc | 0x216 | OpenPGP Secret Key | 0.46254681647940077 | ||
RT_STRING | 0x1040f4 | 0x21c | data | English | Canada | 0.45 |
RT_STRING | 0x104310 | 0x3a | data | Chinese | Taiwan | 0.6379310344827587 |
RT_STRING | 0x10434c | 0x3a | data | Czech | Czech Republic | 0.6379310344827587 |
RT_STRING | 0x104388 | 0x3a | data | Danish | Denmark | 0.6379310344827587 |
RT_STRING | 0x1043c4 | 0x3a | data | German | Germany | 0.6379310344827587 |
RT_STRING | 0x104400 | 0x3a | data | Greek | Greece | 0.6379310344827587 |
RT_STRING | 0x10443c | 0x3a | data | Finnish | Finland | 0.6379310344827587 |
RT_STRING | 0x104478 | 0x3a | data | French | France | 0.6379310344827587 |
RT_STRING | 0x1044b4 | 0x3a | data | Hebrew | Israel | 0.6379310344827587 |
RT_STRING | 0x1044f0 | 0x3a | data | Hungarian | Hungary | 0.6379310344827587 |
RT_STRING | 0x10452c | 0x3a | data | Italian | Italy | 0.6379310344827587 |
RT_STRING | 0x104568 | 0x3a | data | Japanese | Japan | 0.6379310344827587 |
RT_STRING | 0x1045a4 | 0x3a | data | Korean | North Korea | 0.6379310344827587 |
RT_STRING | 0x1045a4 | 0x3a | data | Korean | South Korea | 0.6379310344827587 |
RT_STRING | 0x1045e0 | 0x3a | data | Dutch | Netherlands | 0.6379310344827587 |
RT_STRING | 0x10461c | 0x3a | data | Norwegian | Norway | 0.6379310344827587 |
RT_STRING | 0x104658 | 0x3a | data | Polish | Poland | 0.6379310344827587 |
RT_STRING | 0x104694 | 0x3a | data | Portuguese | Brazil | 0.6379310344827587 |
RT_STRING | 0x1046d0 | 0x3a | data | Russian | Russia | 0.6379310344827587 |
RT_STRING | 0x10470c | 0x3a | data | Swedish | Sweden | 0.6379310344827587 |
RT_STRING | 0x104748 | 0x3a | data | Thai | Thailand | 0.6379310344827587 |
RT_STRING | 0x104784 | 0x3a | data | Chinese | China | 0.6379310344827587 |
RT_STRING | 0x1047c0 | 0x3a | data | Portuguese | Portugal | 0.6379310344827587 |
RT_STRING | 0x1047fc | 0x3a | data | 0.6379310344827587 | ||
RT_STRING | 0x104838 | 0x3a | data | English | Canada | 0.6379310344827587 |
RT_STRING | 0x104874 | 0x328 | data | Chinese | Taiwan | 0.34405940594059403 |
RT_STRING | 0x104b9c | 0x328 | data | Czech | Czech Republic | 0.34405940594059403 |
RT_STRING | 0x104ec4 | 0x328 | data | Danish | Denmark | 0.34405940594059403 |
RT_STRING | 0x1051ec | 0x328 | data | German | Germany | 0.34405940594059403 |
RT_STRING | 0x105514 | 0x328 | data | Greek | Greece | 0.34405940594059403 |
RT_STRING | 0x10583c | 0x328 | data | Finnish | Finland | 0.34405940594059403 |
RT_STRING | 0x105b64 | 0x328 | data | French | France | 0.34405940594059403 |
RT_STRING | 0x105e8c | 0x328 | data | Hebrew | Israel | 0.34405940594059403 |
RT_STRING | 0x1061b4 | 0x328 | data | Hungarian | Hungary | 0.34405940594059403 |
RT_STRING | 0x1064dc | 0x328 | data | Italian | Italy | 0.34405940594059403 |
RT_STRING | 0x106804 | 0x328 | data | Japanese | Japan | 0.34405940594059403 |
RT_STRING | 0x106b2c | 0x328 | data | Korean | North Korea | 0.34405940594059403 |
RT_STRING | 0x106b2c | 0x328 | data | Korean | South Korea | 0.34405940594059403 |
RT_STRING | 0x106e54 | 0x328 | data | Dutch | Netherlands | 0.34405940594059403 |
RT_STRING | 0x10717c | 0x328 | data | Norwegian | Norway | 0.34405940594059403 |
RT_STRING | 0x1074a4 | 0x328 | data | Polish | Poland | 0.34405940594059403 |
RT_STRING | 0x1077cc | 0x328 | data | Portuguese | Brazil | 0.34405940594059403 |
RT_STRING | 0x107af4 | 0x328 | data | Russian | Russia | 0.34405940594059403 |
RT_STRING | 0x107e1c | 0x328 | data | Swedish | Sweden | 0.34405940594059403 |
RT_STRING | 0x108144 | 0x328 | data | Thai | Thailand | 0.34405940594059403 |
RT_STRING | 0x10846c | 0x328 | data | Chinese | China | 0.34405940594059403 |
RT_STRING | 0x108794 | 0x328 | data | Portuguese | Portugal | 0.34405940594059403 |
RT_STRING | 0x108abc | 0x328 | data | 0.34405940594059403 | ||
RT_STRING | 0x108de4 | 0x328 | data | English | Canada | 0.34405940594059403 |
RT_STRING | 0x10910c | 0x70 | data | Chinese | Taiwan | 0.625 |
RT_STRING | 0x10917c | 0x70 | data | Czech | Czech Republic | 0.625 |
RT_STRING | 0x1091ec | 0x70 | data | Danish | Denmark | 0.625 |
RT_STRING | 0x10925c | 0x70 | data | German | Germany | 0.625 |
RT_STRING | 0x1092cc | 0x70 | data | Greek | Greece | 0.625 |
RT_STRING | 0x10933c | 0x70 | data | Finnish | Finland | 0.625 |
RT_STRING | 0x1093ac | 0x70 | data | French | France | 0.625 |
RT_STRING | 0x10941c | 0x70 | data | Hebrew | Israel | 0.625 |
RT_STRING | 0x10948c | 0x70 | data | Hungarian | Hungary | 0.625 |
RT_STRING | 0x1094fc | 0x70 | data | Italian | Italy | 0.625 |
RT_STRING | 0x10956c | 0x70 | data | Japanese | Japan | 0.625 |
RT_STRING | 0x1095dc | 0x70 | data | Korean | North Korea | 0.625 |
RT_STRING | 0x1095dc | 0x70 | data | Korean | South Korea | 0.625 |
RT_STRING | 0x10964c | 0x70 | data | Dutch | Netherlands | 0.625 |
RT_STRING | 0x1096bc | 0x70 | data | Norwegian | Norway | 0.625 |
RT_STRING | 0x10972c | 0x70 | data | Polish | Poland | 0.625 |
RT_STRING | 0x10979c | 0x70 | data | Portuguese | Brazil | 0.625 |
RT_STRING | 0x10980c | 0x70 | data | Russian | Russia | 0.625 |
RT_STRING | 0x10987c | 0x70 | data | Swedish | Sweden | 0.625 |
RT_STRING | 0x1098ec | 0x70 | data | Thai | Thailand | 0.625 |
RT_STRING | 0x10995c | 0x70 | data | Chinese | China | 0.625 |
RT_STRING | 0x1099cc | 0x70 | data | Portuguese | Portugal | 0.625 |
RT_STRING | 0x109a3c | 0x70 | data | 0.625 | ||
RT_STRING | 0x109aac | 0x70 | data | English | Canada | 0.625 |
RT_STRING | 0x109b1c | 0x106 | data | Chinese | Taiwan | 0.5763358778625954 |
RT_STRING | 0x109c24 | 0x106 | data | Czech | Czech Republic | 0.5763358778625954 |
RT_STRING | 0x109d2c | 0x106 | data | Danish | Denmark | 0.5763358778625954 |
RT_STRING | 0x109e34 | 0x106 | data | German | Germany | 0.5763358778625954 |
RT_STRING | 0x109f3c | 0x106 | data | Greek | Greece | 0.5763358778625954 |
RT_STRING | 0x10a044 | 0x106 | data | Finnish | Finland | 0.5763358778625954 |
RT_STRING | 0x10a14c | 0x106 | data | French | France | 0.5763358778625954 |
RT_STRING | 0x10a254 | 0x106 | data | Hebrew | Israel | 0.5763358778625954 |
RT_STRING | 0x10a35c | 0x106 | data | Hungarian | Hungary | 0.5763358778625954 |
RT_STRING | 0x10a464 | 0x106 | data | Italian | Italy | 0.5763358778625954 |
RT_STRING | 0x10a56c | 0x106 | data | Japanese | Japan | 0.5763358778625954 |
RT_STRING | 0x10a674 | 0x106 | data | Korean | North Korea | 0.5763358778625954 |
RT_STRING | 0x10a674 | 0x106 | data | Korean | South Korea | 0.5763358778625954 |
RT_STRING | 0x10a77c | 0x106 | data | Dutch | Netherlands | 0.5763358778625954 |
RT_STRING | 0x10a884 | 0x106 | data | Norwegian | Norway | 0.5763358778625954 |
RT_STRING | 0x10a98c | 0x106 | data | Polish | Poland | 0.5763358778625954 |
RT_STRING | 0x10aa94 | 0x106 | data | Portuguese | Brazil | 0.5763358778625954 |
RT_STRING | 0x10ab9c | 0x106 | data | Russian | Russia | 0.5763358778625954 |
RT_STRING | 0x10aca4 | 0x106 | data | Swedish | Sweden | 0.5763358778625954 |
RT_STRING | 0x10adac | 0x106 | data | Thai | Thailand | 0.5763358778625954 |
RT_STRING | 0x10aeb4 | 0x106 | data | Chinese | China | 0.5763358778625954 |
RT_STRING | 0x10afbc | 0x106 | data | Portuguese | Portugal | 0.5763358778625954 |
RT_STRING | 0x10b0c4 | 0x106 | data | 0.5763358778625954 | ||
RT_STRING | 0x10b1cc | 0x106 | data | English | Canada | 0.5763358778625954 |
RT_STRING | 0x10b2d4 | 0xda | data | Chinese | Taiwan | 0.43119266055045874 |
RT_STRING | 0x10b3b0 | 0xda | data | Czech | Czech Republic | 0.43119266055045874 |
RT_STRING | 0x10b48c | 0xda | data | Danish | Denmark | 0.43119266055045874 |
RT_STRING | 0x10b568 | 0xda | data | German | Germany | 0.43119266055045874 |
RT_STRING | 0x10b644 | 0xda | data | Greek | Greece | 0.43119266055045874 |
RT_STRING | 0x10b720 | 0xda | data | Finnish | Finland | 0.43119266055045874 |
RT_STRING | 0x10b7fc | 0xda | data | French | France | 0.43119266055045874 |
RT_STRING | 0x10b8d8 | 0xda | data | Hebrew | Israel | 0.43119266055045874 |
RT_STRING | 0x10b9b4 | 0xda | data | Hungarian | Hungary | 0.43119266055045874 |
RT_STRING | 0x10ba90 | 0xda | data | Italian | Italy | 0.43119266055045874 |
RT_STRING | 0x10bb6c | 0xda | data | Japanese | Japan | 0.43119266055045874 |
RT_STRING | 0x10bc48 | 0xda | data | Korean | North Korea | 0.43119266055045874 |
RT_STRING | 0x10bc48 | 0xda | data | Korean | South Korea | 0.43119266055045874 |
RT_STRING | 0x10bd24 | 0xda | data | Dutch | Netherlands | 0.43119266055045874 |
RT_STRING | 0x10be00 | 0xda | data | Norwegian | Norway | 0.43119266055045874 |
RT_STRING | 0x10bedc | 0xda | data | Polish | Poland | 0.43119266055045874 |
RT_STRING | 0x10bfb8 | 0xda | data | Portuguese | Brazil | 0.43119266055045874 |
RT_STRING | 0x10c094 | 0xda | data | Russian | Russia | 0.43119266055045874 |
RT_STRING | 0x10c170 | 0xda | data | Swedish | Sweden | 0.43119266055045874 |
RT_STRING | 0x10c24c | 0xda | data | Thai | Thailand | 0.43119266055045874 |
RT_STRING | 0x10c328 | 0xda | data | Chinese | China | 0.43119266055045874 |
RT_STRING | 0x10c404 | 0xda | data | Portuguese | Portugal | 0.43119266055045874 |
RT_STRING | 0x10c4e0 | 0xda | data | 0.43119266055045874 | ||
RT_STRING | 0x10c5bc | 0xda | data | English | Canada | 0.43119266055045874 |
RT_STRING | 0x10c698 | 0x46 | data | Chinese | Taiwan | 0.7428571428571429 |
RT_STRING | 0x10c6e0 | 0x46 | data | Czech | Czech Republic | 0.7428571428571429 |
RT_STRING | 0x10c728 | 0x46 | data | Danish | Denmark | 0.7428571428571429 |
RT_STRING | 0x10c770 | 0x46 | data | German | Germany | 0.7428571428571429 |
RT_STRING | 0x10c7b8 | 0x46 | data | Greek | Greece | 0.7428571428571429 |
RT_STRING | 0x10c800 | 0x46 | data | Finnish | Finland | 0.7428571428571429 |
RT_STRING | 0x10c848 | 0x46 | data | French | France | 0.7428571428571429 |
RT_STRING | 0x10c890 | 0x46 | data | Hebrew | Israel | 0.7428571428571429 |
RT_STRING | 0x10c8d8 | 0x46 | data | Hungarian | Hungary | 0.7428571428571429 |
RT_STRING | 0x10c920 | 0x46 | data | Italian | Italy | 0.7428571428571429 |
RT_STRING | 0x10c968 | 0x46 | data | Japanese | Japan | 0.7428571428571429 |
RT_STRING | 0x10c9b0 | 0x46 | data | Korean | North Korea | 0.7428571428571429 |
RT_STRING | 0x10c9b0 | 0x46 | data | Korean | South Korea | 0.7428571428571429 |
RT_STRING | 0x10c9f8 | 0x46 | data | Dutch | Netherlands | 0.7428571428571429 |
RT_STRING | 0x10ca40 | 0x46 | data | Norwegian | Norway | 0.7428571428571429 |
RT_STRING | 0x10ca88 | 0x46 | data | Polish | Poland | 0.7428571428571429 |
RT_STRING | 0x10cad0 | 0x46 | data | Portuguese | Brazil | 0.7428571428571429 |
RT_STRING | 0x10cb18 | 0x46 | data | Russian | Russia | 0.7428571428571429 |
RT_STRING | 0x10cb60 | 0x46 | data | Swedish | Sweden | 0.7428571428571429 |
RT_STRING | 0x10cba8 | 0x46 | data | Thai | Thailand | 0.7428571428571429 |
RT_STRING | 0x10cbf0 | 0x46 | data | Chinese | China | 0.7428571428571429 |
RT_STRING | 0x10cc38 | 0x46 | data | Portuguese | Portugal | 0.7428571428571429 |
RT_STRING | 0x10cc80 | 0x46 | data | 0.7428571428571429 | ||
RT_STRING | 0x10ccc8 | 0x46 | data | English | Canada | 0.7428571428571429 |
RT_STRING | 0x10cd10 | 0x1f8 | data | Chinese | Taiwan | 0.36706349206349204 |
RT_STRING | 0x10cf08 | 0x1f8 | data | Czech | Czech Republic | 0.36706349206349204 |
RT_STRING | 0x10d100 | 0x1f8 | data | Danish | Denmark | 0.36706349206349204 |
RT_STRING | 0x10d2f8 | 0x1f8 | data | German | Germany | 0.36706349206349204 |
RT_STRING | 0x10d4f0 | 0x1f8 | data | Greek | Greece | 0.36706349206349204 |
RT_STRING | 0x10d6e8 | 0x1f8 | data | Finnish | Finland | 0.36706349206349204 |
RT_STRING | 0x10d8e0 | 0x1f8 | data | French | France | 0.36706349206349204 |
RT_STRING | 0x10dad8 | 0x1f8 | data | Hebrew | Israel | 0.36706349206349204 |
RT_STRING | 0x10dcd0 | 0x1f8 | data | Hungarian | Hungary | 0.36706349206349204 |
RT_STRING | 0x10dec8 | 0x1f8 | data | Italian | Italy | 0.36706349206349204 |
RT_STRING | 0x10e0c0 | 0x1f8 | data | Japanese | Japan | 0.36706349206349204 |
RT_STRING | 0x10e2b8 | 0x1f8 | data | Korean | North Korea | 0.36706349206349204 |
RT_STRING | 0x10e2b8 | 0x1f8 | data | Korean | South Korea | 0.36706349206349204 |
RT_STRING | 0x10e4b0 | 0x1f8 | data | Dutch | Netherlands | 0.36706349206349204 |
RT_STRING | 0x10e6a8 | 0x1f8 | data | Norwegian | Norway | 0.36706349206349204 |
RT_STRING | 0x10e8a0 | 0x1f8 | data | Polish | Poland | 0.36706349206349204 |
RT_STRING | 0x10ea98 | 0x1f8 | data | Portuguese | Brazil | 0.36706349206349204 |
RT_STRING | 0x10ec90 | 0x1f8 | data | Russian | Russia | 0.36706349206349204 |
RT_STRING | 0x10ee88 | 0x1f8 | data | Swedish | Sweden | 0.36706349206349204 |
RT_STRING | 0x10f080 | 0x1f8 | data | Thai | Thailand | 0.36706349206349204 |
RT_STRING | 0x10f278 | 0x1f8 | data | Chinese | China | 0.36706349206349204 |
RT_STRING | 0x10f470 | 0x1f8 | data | Portuguese | Portugal | 0.36706349206349204 |
RT_STRING | 0x10f668 | 0x1f8 | data | 0.36706349206349204 | ||
RT_STRING | 0x10f860 | 0x1f8 | data | English | Canada | 0.36706349206349204 |
RT_STRING | 0x10fa58 | 0x86 | data | Chinese | Taiwan | 0.6567164179104478 |
RT_STRING | 0x10fae0 | 0x86 | data | Czech | Czech Republic | 0.6567164179104478 |
RT_STRING | 0x10fb68 | 0x86 | data | Danish | Denmark | 0.6567164179104478 |
RT_STRING | 0x10fbf0 | 0x86 | data | German | Germany | 0.6567164179104478 |
RT_STRING | 0x10fc78 | 0x86 | data | Greek | Greece | 0.6567164179104478 |
RT_STRING | 0x10fd00 | 0x86 | data | Finnish | Finland | 0.6567164179104478 |
RT_STRING | 0x10fd88 | 0x86 | data | French | France | 0.6567164179104478 |
RT_STRING | 0x10fe10 | 0x86 | data | Hebrew | Israel | 0.6567164179104478 |
RT_STRING | 0x10fe98 | 0x86 | data | Hungarian | Hungary | 0.6567164179104478 |
RT_STRING | 0x10ff20 | 0x86 | data | Italian | Italy | 0.6567164179104478 |
RT_STRING | 0x10ffa8 | 0x86 | data | Japanese | Japan | 0.6567164179104478 |
RT_STRING | 0x110030 | 0x86 | data | Korean | North Korea | 0.6567164179104478 |
RT_STRING | 0x110030 | 0x86 | data | Korean | South Korea | 0.6567164179104478 |
RT_STRING | 0x1100b8 | 0x86 | data | Dutch | Netherlands | 0.6567164179104478 |
RT_STRING | 0x110140 | 0x86 | data | Norwegian | Norway | 0.6567164179104478 |
RT_STRING | 0x1101c8 | 0x86 | data | Polish | Poland | 0.6567164179104478 |
RT_STRING | 0x110250 | 0x86 | data | Portuguese | Brazil | 0.6567164179104478 |
RT_STRING | 0x1102d8 | 0x86 | data | Russian | Russia | 0.6567164179104478 |
RT_STRING | 0x110360 | 0x86 | data | Swedish | Sweden | 0.6567164179104478 |
RT_STRING | 0x1103e8 | 0x86 | data | Thai | Thailand | 0.6567164179104478 |
RT_STRING | 0x110470 | 0x86 | data | Chinese | China | 0.6567164179104478 |
RT_STRING | 0x1104f8 | 0x86 | data | Portuguese | Portugal | 0.6567164179104478 |
RT_STRING | 0x110580 | 0x86 | data | 0.6567164179104478 | ||
RT_STRING | 0x110608 | 0x86 | data | English | Canada | 0.6567164179104478 |
RT_STRING | 0x110690 | 0x82 | StarOffice Gallery theme p, 536899072 objects, 1st n | English | United States | 0.7153846153846154 |
RT_STRING | 0x110714 | 0x2a | data | English | United States | 0.5476190476190477 |
RT_STRING | 0x110740 | 0x192 | data | English | United States | 0.48009950248756217 |
RT_STRING | 0x1108d4 | 0x4e2 | data | English | United States | 0.376 |
RT_STRING | 0x110db8 | 0x31a | data | English | United States | 0.2682619647355164 |
RT_STRING | 0x1110d4 | 0x2dc | data | English | United States | 0.36885245901639346 |
RT_STRING | 0x1113b0 | 0x8a | data | English | United States | 0.6594202898550725 |
RT_STRING | 0x11143c | 0xac | data | English | United States | 0.45348837209302323 |
RT_STRING | 0x1114e8 | 0xde | data | English | United States | 0.536036036036036 |
RT_STRING | 0x1115c8 | 0x4c4 | data | English | United States | 0.3221311475409836 |
RT_STRING | 0x111a8c | 0x264 | data | English | United States | 0.3741830065359477 |
RT_STRING | 0x111cf0 | 0x2c | data | English | United States | 0.5227272727272727 |
RT_STRING | 0x111d1c | 0x42 | data | English | United States | 0.6060606060606061 |
RT_ACCELERATOR | 0x111d60 | 0x50 | data | English | United States | 0.8 |
RT_RCDATA | 0x111db0 | 0xf7ece | Delphi compiled form 'TfPNGMessage' | 0.22542053092953043 | ||
RT_GROUP_CURSOR | 0x209c80 | 0x22 | Lotus unknown worksheet or configuration, revision 0x2 | English | United States | 1.0294117647058822 |
RT_GROUP_CURSOR | 0x209ca4 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x209cb8 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x209ccc | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x209ce0 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x209cf4 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x209d08 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x209d1c | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x209d30 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x209d44 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x209d58 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x209d6c | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x209d80 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x209d94 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x209da8 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_ICON | 0x209dbc | 0x22 | data | English | United States | 1.0 |
RT_VERSION | 0x209de0 | 0x32c | data | English | United States | 0.4248768472906404 |
RT_ANIICON | 0x20a10c | 0x2dc73 | PC bitmap, Windows 3.x format, 24050 x 2 x 46, image size 188176, cbSize 187507, bits offset 54 | 0.679739956374962 | ||
RT_ANIICON | 0x237d80 | 0x4acfc | PC bitmap, Windows 3.x format, 39057 x 2 x 32, image size 307263, cbSize 306428, bits offset 54 | 0.7979003224248437 |
DLL | Import |
---|---|
KERNEL32.dll | VirtualQuery, RtlUnwind, ExitProcess, TerminateProcess, GetStartupInfoA, GetCommandLineA, GetSystemTimeAsFileTime, SetEnvironmentVariableA, ExitThread, CreateThread, HeapReAlloc, SetStdHandle, GetFileType, HeapSize, HeapDestroy, HeapCreate, VirtualFree, IsBadWritePtr, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemInfo, GetStringTypeW, GetStdHandle, UnhandledExceptionFilter, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetHandleCount, GetTimeZoneInformation, GetUserDefaultLCID, EnumSystemLocalesA, IsValidLocale, IsValidCodePage, LCMapStringA, LCMapStringW, SetUnhandledExceptionFilter, IsBadReadPtr, IsBadCodePtr, GetLocaleInfoW, VirtualAlloc, VirtualProtect, HeapFree, HeapAlloc, FileTimeToSystemTime, GetOEMCP, GetCPInfo, TlsFree, LocalReAlloc, TlsSetValue, TlsAlloc, TlsGetValue, EnterCriticalSection, GlobalHandle, GlobalReAlloc, LeaveCriticalSection, InterlockedIncrement, WritePrivateProfileStringA, GlobalFlags, DeleteCriticalSection, InitializeCriticalSection, RaiseException, GetFullPathNameA, DuplicateHandle, GetFileSize, SetEndOfFile, UnlockFile, LockFile, FlushFileBuffers, SetFilePointer, WriteFile, ReadFile, InterlockedDecrement, GlobalGetAtomNameA, GlobalFindAtomA, lstrcatA, lstrcmpW, WaitForSingleObject, ResumeThread, GlobalAddAtomA, MulDiv, lstrcpynA, GetCurrentThreadId, GlobalAlloc, GlobalDeleteAtom, lstrcmpA, GetModuleFileNameA, ConvertDefaultLocale, EnumResourceLanguagesA, lstrcpyA, GlobalLock, GlobalUnlock, GlobalFree, FreeResource, GetThreadLocale, GetLocaleInfoA, GetACP, CreateFileA, GetFileTime, DosDateTimeToFileTime, LocalFileTimeToFileTime, SetFileTime, FileTimeToLocalFileTime, SetErrorMode, CreateDirectoryA, RemoveDirectoryA, CreateProcessA, GetExitCodeProcess, GetSystemDirectoryA, GetWindowsDirectoryA, GetTempPathA, LocalAlloc, GetCurrentProcess, GetVersionExA, GetCurrentThread, SetThreadPriority, GetLogicalDrives, GetDriveTypeA, GetShortPathNameA, FormatMessageA, LocalFree, GetDiskFreeSpaceA, SetLastError, GetVolumeInformationA, GetUserDefaultLangID, DeleteFileA, CopyFileA, SetFileAttributesA, GetFileAttributesA, FindFirstFileA, FindNextFileA, FindClose, FindResourceExA, CreateToolhelp32Snapshot, Process32First, Process32Next, CloseHandle, SetCurrentDirectoryA, GetModuleHandleA, GetCurrentDirectoryA, LoadLibraryA, GetProcAddress, FreeLibrary, Sleep, FindResourceA, LoadResource, LockResource, SizeofResource, CompareStringW, CompareStringA, lstrlenA, lstrcmpiA, GetVersion, GetLastError, WideCharToMultiByte, MultiByteToWideChar, GetStringTypeA, InterlockedExchange |
USER32.dll | GetMenuItemInfoA, InflateRect, GetSysColorBrush, LoadMenuA, DestroyMenu, UnpackDDElParam, ReuseDDElParam, ReleaseCapture, LoadAcceleratorsA, InvalidateRect, InsertMenuItemA, CreatePopupMenu, SetRectEmpty, BringWindowToTop, SetMenu, TranslateAcceleratorA, EndPaint, BeginPaint, GetWindowDC, ReleaseDC, GetDC, ClientToScreen, GrayStringA, DrawTextExA, DrawTextA, TabbedTextOutA, FillRect, RegisterWindowMessageA, WinHelpA, GetCapture, CreateWindowExA, GetClassLongA, GetClassInfoExA, GetClassNameA, SetPropA, GetPropA, RemovePropA, GetForegroundWindow, BeginDeferWindowPos, EndDeferWindowPos, GetTopWindow, UnhookWindowsHookEx, GetMessageTime, GetMessagePos, LoadIconA, MapWindowPoints, TrackPopupMenu, SetForegroundWindow, UpdateWindow, GetClientRect, GetMenu, GetSysColor, ScreenToClient, EqualRect, DeferWindowPos, GetClassInfoA, RegisterClassA, UnregisterClassA, CallWindowProcA, OffsetRect, IntersectRect, IsIconic, GetWindowPlacement, GetWindowRect, CopyRect, PtInRect, GetWindow, GetWindowTextA, SetWindowPos, SetFocus, ShowWindow, SetWindowLongA, GetDlgCtrlID, SetWindowTextA, IsDialogMessageA, SendDlgItemMessageA, SetMenuItemBitmaps, GetFocus, ModifyMenuA, EnableMenuItem, CheckMenuItem, GetMenuCheckMarkDimensions, LoadBitmapA, SetWindowsHookExA, CallNextHookEx, GetMessageA, IsWindowVisible, GetKeyState, GetCursorPos, ValidateRect, GetLastActivePopup, ShowOwnedPopups, SetCursor, GetMenuState, GetMenuItemID, GetMenuItemCount, GetSubMenu, PostMessageA, PostQuitMessage, GetDesktopWindow, GetActiveWindow, SetActiveWindow, GetSystemMetrics, CreateDialogIndirectParamA, AdjustWindowRectEx, DestroyWindow, IsWindow, GetWindowLongA, GetDlgItem, IsWindowEnabled, GetParent, GetNextDlgTabItem, SendMessageA, EndDialog, PeekMessageA, TranslateMessage, DispatchMessageA, wsprintfA, ExitWindowsEx, SystemParametersInfoA, DefWindowProcA, LoadImageA, MessageBoxA, LoadCursorA, EnableWindow, CharUpperA |
GDI32.dll | TextOutA, RectVisible, PtVisible, BitBlt, DeleteObject, CreateFontIndirectA, GetTextExtentPoint32A, CreateCompatibleBitmap, CreateSolidBrush, GetStockObject, CreateCompatibleDC, CreatePatternBrush, DeleteDC, ScaleWindowExtEx, SetWindowExtEx, ScaleViewportExtEx, SetViewportExtEx, OffsetViewportOrgEx, SetViewportOrgEx, SelectObject, Escape, GetPixel, GetDeviceCaps, SetMapMode, SetBkMode, RestoreDC, SaveDC, GetObjectA, SetBkColor, SetTextColor, GetClipBox, CreateBitmap, ExtTextOutA |
comdlg32.dll | GetFileTitleA |
WINSPOOL.DRV | OpenPrinterA, DocumentPropertiesA, ClosePrinter |
ADVAPI32.dll | RegEnumKeyExA, LookupPrivilegeValueA, OpenProcessToken, FreeSid, RevertToSelf, AccessCheck, IsValidSecurityDescriptor, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, SetSecurityDescriptorDacl, AddAccessAllowedAce, RegQueryValueA, RegEnumKeyA, RegOpenKeyA, RegCreateKeyExA, RegSetValueExA, AdjustTokenPrivileges, RegDeleteKeyA, RegQueryValueExA, RegCloseKey, RegOpenKeyExA, ImpersonateSelf, OpenThreadToken, AllocateAndInitializeSid, InitializeSecurityDescriptor, GetLengthSid, InitializeAcl |
SHELL32.dll | DragFinish, DragQueryFileA, ShellExecuteA |
COMCTL32.dll | ImageList_Draw, ImageList_GetImageInfo, ImageList_Destroy |
SHLWAPI.dll | PathFindFileNameA, PathStripToRootA, PathFindExtensionA, PathIsUNCA |
ole32.dll | CoUninitialize, CoCreateInstance, CoInitialize |
OLEAUT32.dll | VariantClear, VariantInit, VariantChangeType |
VERSION.dll | GetFileVersionInfoA, VerQueryValueA, GetFileVersionInfoSizeA |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States | |
Chinese | Taiwan | |
Czech | Czech Republic | |
Danish | Denmark | |
German | Germany | |
Greek | Greece | |
Finnish | Finland | |
French | France | |
Hebrew | Israel | |
Hungarian | Hungary | |
Italian | Italy | |
Japanese | Japan | |
Korean | North Korea | |
Korean | South Korea | |
Dutch | Netherlands | |
Norwegian | Norway | |
Polish | Poland | |
Portuguese | Brazil | |
Russian | Russia | |
Swedish | Sweden | |
Thai | Thailand | |
Chinese | China | |
Portuguese | Portugal | |
English | Canada |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-12T17:52:16.783769+0100 | 2032776 | ET MALWARE Remcos 3.x Unencrypted Checkin | 1 | 192.168.2.9 | 49709 | 181.131.217.244 | 30201 | TCP |
2024-12-12T17:52:27.054987+0100 | 2032777 | ET MALWARE Remcos 3.x Unencrypted Server Response | 1 | 181.131.217.244 | 30201 | 192.168.2.9 | 49709 | TCP |
2024-12-12T17:52:28.865468+0100 | 2803304 | ETPRO MALWARE Common Downloader Header Pattern HCa | 3 | 192.168.2.9 | 49710 | 178.237.33.50 | 80 | TCP |
2024-12-12T17:54:31.751110+0100 | 2032777 | ET MALWARE Remcos 3.x Unencrypted Server Response | 1 | 181.131.217.244 | 30201 | 192.168.2.9 | 49709 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 12, 2024 17:52:16.661534071 CET | 49709 | 30201 | 192.168.2.9 | 181.131.217.244 |
Dec 12, 2024 17:52:16.782365084 CET | 30201 | 49709 | 181.131.217.244 | 192.168.2.9 |
Dec 12, 2024 17:52:16.782547951 CET | 49709 | 30201 | 192.168.2.9 | 181.131.217.244 |
Dec 12, 2024 17:52:16.783768892 CET | 49709 | 30201 | 192.168.2.9 | 181.131.217.244 |
Dec 12, 2024 17:52:16.904417038 CET | 30201 | 49709 | 181.131.217.244 | 192.168.2.9 |
Dec 12, 2024 17:52:27.054986954 CET | 30201 | 49709 | 181.131.217.244 | 192.168.2.9 |
Dec 12, 2024 17:52:27.056724072 CET | 49709 | 30201 | 192.168.2.9 | 181.131.217.244 |
Dec 12, 2024 17:52:27.176574945 CET | 30201 | 49709 | 181.131.217.244 | 192.168.2.9 |
Dec 12, 2024 17:52:27.289573908 CET | 30201 | 49709 | 181.131.217.244 | 192.168.2.9 |
Dec 12, 2024 17:52:27.347744942 CET | 49709 | 30201 | 192.168.2.9 | 181.131.217.244 |
Dec 12, 2024 17:52:27.487401009 CET | 49710 | 80 | 192.168.2.9 | 178.237.33.50 |
Dec 12, 2024 17:52:27.607574940 CET | 80 | 49710 | 178.237.33.50 | 192.168.2.9 |
Dec 12, 2024 17:52:27.607657909 CET | 49710 | 80 | 192.168.2.9 | 178.237.33.50 |
Dec 12, 2024 17:52:27.607939005 CET | 49710 | 80 | 192.168.2.9 | 178.237.33.50 |
Dec 12, 2024 17:52:27.749946117 CET | 80 | 49710 | 178.237.33.50 | 192.168.2.9 |
Dec 12, 2024 17:52:28.865305901 CET | 80 | 49710 | 178.237.33.50 | 192.168.2.9 |
Dec 12, 2024 17:52:28.865468025 CET | 49710 | 80 | 192.168.2.9 | 178.237.33.50 |
Dec 12, 2024 17:52:28.996014118 CET | 49709 | 30201 | 192.168.2.9 | 181.131.217.244 |
Dec 12, 2024 17:52:29.118217945 CET | 30201 | 49709 | 181.131.217.244 | 192.168.2.9 |
Dec 12, 2024 17:52:29.872725964 CET | 80 | 49710 | 178.237.33.50 | 192.168.2.9 |
Dec 12, 2024 17:52:29.872833014 CET | 49710 | 80 | 192.168.2.9 | 178.237.33.50 |
Dec 12, 2024 17:52:31.682352066 CET | 30201 | 49709 | 181.131.217.244 | 192.168.2.9 |
Dec 12, 2024 17:52:31.847748995 CET | 49709 | 30201 | 192.168.2.9 | 181.131.217.244 |
Dec 12, 2024 17:52:31.938200951 CET | 49709 | 30201 | 192.168.2.9 | 181.131.217.244 |
Dec 12, 2024 17:52:32.058422089 CET | 30201 | 49709 | 181.131.217.244 | 192.168.2.9 |
Dec 12, 2024 17:53:01.718439102 CET | 30201 | 49709 | 181.131.217.244 | 192.168.2.9 |
Dec 12, 2024 17:53:01.763232946 CET | 49709 | 30201 | 192.168.2.9 | 181.131.217.244 |
Dec 12, 2024 17:53:01.883004904 CET | 30201 | 49709 | 181.131.217.244 | 192.168.2.9 |
Dec 12, 2024 17:53:31.727884054 CET | 30201 | 49709 | 181.131.217.244 | 192.168.2.9 |
Dec 12, 2024 17:53:31.744604111 CET | 49709 | 30201 | 192.168.2.9 | 181.131.217.244 |
Dec 12, 2024 17:53:31.866110086 CET | 30201 | 49709 | 181.131.217.244 | 192.168.2.9 |
Dec 12, 2024 17:54:01.750376940 CET | 30201 | 49709 | 181.131.217.244 | 192.168.2.9 |
Dec 12, 2024 17:54:01.751732111 CET | 49709 | 30201 | 192.168.2.9 | 181.131.217.244 |
Dec 12, 2024 17:54:01.871747971 CET | 30201 | 49709 | 181.131.217.244 | 192.168.2.9 |
Dec 12, 2024 17:54:17.335347891 CET | 49710 | 80 | 192.168.2.9 | 178.237.33.50 |
Dec 12, 2024 17:54:17.769928932 CET | 49710 | 80 | 192.168.2.9 | 178.237.33.50 |
Dec 12, 2024 17:54:18.582324982 CET | 49710 | 80 | 192.168.2.9 | 178.237.33.50 |
Dec 12, 2024 17:54:19.879291058 CET | 49710 | 80 | 192.168.2.9 | 178.237.33.50 |
Dec 12, 2024 17:54:22.514280081 CET | 49710 | 80 | 192.168.2.9 | 178.237.33.50 |
Dec 12, 2024 17:54:27.725935936 CET | 49710 | 80 | 192.168.2.9 | 178.237.33.50 |
Dec 12, 2024 17:54:31.751110077 CET | 30201 | 49709 | 181.131.217.244 | 192.168.2.9 |
Dec 12, 2024 17:54:31.752582073 CET | 49709 | 30201 | 192.168.2.9 | 181.131.217.244 |
Dec 12, 2024 17:54:31.873646021 CET | 30201 | 49709 | 181.131.217.244 | 192.168.2.9 |
Dec 12, 2024 17:54:38.097639084 CET | 49710 | 80 | 192.168.2.9 | 178.237.33.50 |
Dec 12, 2024 17:55:01.775218964 CET | 30201 | 49709 | 181.131.217.244 | 192.168.2.9 |
Dec 12, 2024 17:55:01.776787996 CET | 49709 | 30201 | 192.168.2.9 | 181.131.217.244 |
Dec 12, 2024 17:55:01.897037983 CET | 30201 | 49709 | 181.131.217.244 | 192.168.2.9 |
Dec 12, 2024 17:55:31.770566940 CET | 30201 | 49709 | 181.131.217.244 | 192.168.2.9 |
Dec 12, 2024 17:55:31.774127960 CET | 49709 | 30201 | 192.168.2.9 | 181.131.217.244 |
Dec 12, 2024 17:55:31.894192934 CET | 30201 | 49709 | 181.131.217.244 | 192.168.2.9 |
Dec 12, 2024 17:56:01.751303911 CET | 30201 | 49709 | 181.131.217.244 | 192.168.2.9 |
Dec 12, 2024 17:56:01.751988888 CET | 49709 | 30201 | 192.168.2.9 | 181.131.217.244 |
Dec 12, 2024 17:56:01.871809006 CET | 30201 | 49709 | 181.131.217.244 | 192.168.2.9 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 12, 2024 17:52:16.461904049 CET | 61656 | 53 | 192.168.2.9 | 1.1.1.1 |
Dec 12, 2024 17:52:16.626835108 CET | 53 | 61656 | 1.1.1.1 | 192.168.2.9 |
Dec 12, 2024 17:52:27.345009089 CET | 49222 | 53 | 192.168.2.9 | 1.1.1.1 |
Dec 12, 2024 17:52:27.482811928 CET | 53 | 49222 | 1.1.1.1 | 192.168.2.9 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 12, 2024 17:52:16.461904049 CET | 192.168.2.9 | 1.1.1.1 | 0x6000 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 12, 2024 17:52:27.345009089 CET | 192.168.2.9 | 1.1.1.1 | 0xe2f4 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 12, 2024 17:52:16.626835108 CET | 1.1.1.1 | 192.168.2.9 | 0x6000 | No error (0) | 181.131.217.244 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 17:52:27.482811928 CET | 1.1.1.1 | 192.168.2.9 | 0xe2f4 | No error (0) | 178.237.33.50 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.9 | 49710 | 178.237.33.50 | 80 | 3348 | C:\Users\user\Desktop\IXCbn4ZcdS.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 12, 2024 17:52:27.607939005 CET | 71 | OUT | |
Dec 12, 2024 17:52:28.865305901 CET | 1171 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 11:51:54 |
Start date: | 12/12/2024 |
Path: | C:\Users\user\Desktop\IXCbn4ZcdS.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 2'457'600 bytes |
MD5 hash: | B1A62F3FD3A9A4A06C6BBFFBB1CBB463 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 5 |
Start time: | 11:52:15 |
Start date: | 12/12/2024 |
Path: | C:\Users\user\Desktop\IXCbn4ZcdS.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 2'457'600 bytes |
MD5 hash: | B1A62F3FD3A9A4A06C6BBFFBB1CBB463 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 0.1% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 0% |
Total number of Nodes: | 11 |
Total number of Limit Nodes: | 0 |
Graph
Control-flow Graph
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406D2E Relevance: 23.0, APIs: 1, Strings: 12, Instructions: 218memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040721E Relevance: 21.3, APIs: 1, Strings: 11, Instructions: 288memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004076C0 Relevance: 21.3, APIs: 1, Strings: 11, Instructions: 256memoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407BE2 Relevance: 21.2, APIs: 1, Strings: 11, Instructions: 178memoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407BEF Relevance: 21.1, APIs: 1, Strings: 11, Instructions: 133memoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408C69 Relevance: 1.8, APIs: 1, Instructions: 275COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040899B Relevance: 1.8, APIs: 1, Instructions: 272COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040803F Relevance: 22.9, APIs: 1, Strings: 12, Instructions: 154memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406F87 Relevance: 22.9, APIs: 1, Strings: 12, Instructions: 126memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406C97 Relevance: 22.9, APIs: 1, Strings: 12, Instructions: 119memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406CA8 Relevance: 22.9, APIs: 1, Strings: 12, Instructions: 115memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406D40 Relevance: 22.9, APIs: 1, Strings: 12, Instructions: 113memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407035 Relevance: 22.9, APIs: 1, Strings: 12, Instructions: 107memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407D7D Relevance: 21.2, APIs: 1, Strings: 11, Instructions: 175memoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407223 Relevance: 21.2, APIs: 1, Strings: 11, Instructions: 154memoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407246 Relevance: 21.1, APIs: 1, Strings: 11, Instructions: 144memoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407267 Relevance: 21.1, APIs: 1, Strings: 11, Instructions: 136memoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004071DE Relevance: 21.1, APIs: 1, Strings: 11, Instructions: 134memoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407607 Relevance: 21.1, APIs: 1, Strings: 11, Instructions: 133memoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408106 Relevance: 21.1, APIs: 1, Strings: 11, Instructions: 125memoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408060 Relevance: 21.1, APIs: 1, Strings: 11, Instructions: 113memoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407D9B Relevance: 21.1, APIs: 1, Strings: 11, Instructions: 105memoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407699 Relevance: 21.1, APIs: 1, Strings: 11, Instructions: 105memoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407C71 Relevance: 21.1, APIs: 1, Strings: 11, Instructions: 99memoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407D39 Relevance: 21.1, APIs: 1, Strings: 11, Instructions: 98memoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407D2E Relevance: 21.1, APIs: 1, Strings: 11, Instructions: 97memoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004076B0 Relevance: 21.1, APIs: 1, Strings: 11, Instructions: 96memoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00409ABF Relevance: 1.6, APIs: 1, Instructions: 132COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408BB6 Relevance: 1.6, APIs: 1, Instructions: 124COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408BCF Relevance: 1.6, APIs: 1, Instructions: 115COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408C0A Relevance: 1.6, APIs: 1, Instructions: 102COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408C44 Relevance: 1.6, APIs: 1, Instructions: 86COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408C4E Relevance: 1.6, APIs: 1, Instructions: 85COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00409A09 Relevance: 1.6, APIs: 1, Instructions: 83COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408C58 Relevance: 1.6, APIs: 1, Instructions: 80COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004049B8 Relevance: 1.6, APIs: 1, Instructions: 78COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040942B Relevance: 1.6, APIs: 1, Instructions: 58COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408D29 Relevance: 1.6, APIs: 1, Instructions: 53COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408D7F Relevance: 1.5, APIs: 1, Instructions: 34COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408B1A Relevance: 1.5, APIs: 1, Instructions: 32COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408A96 Relevance: 1.5, APIs: 1, Instructions: 31COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408E30 Relevance: 1.5, APIs: 1, Instructions: 30COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408AA7 Relevance: 1.5, APIs: 1, Instructions: 24COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00409AFF Relevance: 1.5, APIs: 1, Instructions: 18COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00409B0C Relevance: 1.5, APIs: 1, Instructions: 17COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408E71 Relevance: 1.5, APIs: 1, Instructions: 14COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00409F31 Relevance: 1.5, APIs: 1, Instructions: 9COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408E84 Relevance: 1.5, APIs: 1, Instructions: 8COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00413910 Relevance: 36.9, APIs: 20, Strings: 1, Instructions: 166memorythreadCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00409F71 Relevance: 35.3, APIs: 13, Strings: 7, Instructions: 274fileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004151A0 Relevance: 33.5, APIs: 11, Strings: 8, Instructions: 282fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00413E20 Relevance: 30.0, APIs: 13, Strings: 4, Instructions: 242sleepprocessfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00414A00 Relevance: 28.2, APIs: 7, Strings: 9, Instructions: 164sleepfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415E70 Relevance: 25.2, Strings: 20, Instructions: 220COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040A0A0 Relevance: 24.7, APIs: 8, Strings: 6, Instructions: 200filesleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040A0D8 Relevance: 22.9, APIs: 7, Strings: 6, Instructions: 186filesleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00417E90 Relevance: 21.2, APIs: 10, Strings: 2, Instructions: 216fileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00414380 Relevance: 19.4, APIs: 10, Strings: 1, Instructions: 194filesleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00414C50 Relevance: 17.7, APIs: 7, Strings: 3, Instructions: 213fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00414C5E Relevance: 17.7, APIs: 7, Strings: 3, Instructions: 188fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041383D Relevance: 17.6, APIs: 8, Strings: 2, Instructions: 63windowshutdownCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040A580 Relevance: 17.6, APIs: 8, Strings: 2, Instructions: 62windowshutdownCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004087BD Relevance: 15.3, Strings: 12, Instructions: 258COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408638 Relevance: 15.2, Strings: 12, Instructions: 228COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415590 Relevance: 14.4, APIs: 7, Strings: 1, Instructions: 446fileCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004156B5 Relevance: 14.3, APIs: 7, Strings: 1, Instructions: 335fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004158B9 Relevance: 14.3, APIs: 7, Strings: 1, Instructions: 302fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004145D0 Relevance: 12.5, APIs: 6, Strings: 1, Instructions: 243fileCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00414626 Relevance: 12.4, APIs: 6, Strings: 1, Instructions: 185fileCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00411010 Relevance: 12.4, APIs: 3, Strings: 4, Instructions: 137windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00414D36 Relevance: 12.4, APIs: 6, Strings: 1, Instructions: 128fileCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040F650 Relevance: 12.3, APIs: 5, Strings: 2, Instructions: 77libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004148D0 Relevance: 12.3, APIs: 5, Strings: 2, Instructions: 37libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415858 Relevance: 10.7, APIs: 5, Strings: 1, Instructions: 204fileCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00414697 Relevance: 10.7, APIs: 5, Strings: 1, Instructions: 151fileCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040AC10 Relevance: 10.6, APIs: 3, Strings: 3, Instructions: 80fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00414290 Relevance: 10.6, APIs: 3, Strings: 3, Instructions: 61fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004347CC Relevance: 9.1, APIs: 6, Instructions: 102COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0043469C Relevance: 9.1, APIs: 6, Instructions: 97COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042407C Relevance: 7.6, APIs: 5, Instructions: 92memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042D862 Relevance: 6.2, APIs: 4, Instructions: 212timeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040F900 Relevance: 4.6, APIs: 3, Instructions: 102comCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00414F30 Relevance: 4.6, APIs: 3, Instructions: 61fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004013D0 Relevance: 4.5, APIs: 3, Instructions: 46COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00422895 Relevance: 4.5, APIs: 3, Instructions: 37threadCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00422CCA Relevance: 4.5, APIs: 3, Instructions: 37COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00413800 Relevance: 3.0, APIs: 2, Instructions: 19fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00414340 Relevance: 3.0, APIs: 2, Instructions: 19fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004300E6 Relevance: 1.6, APIs: 1, Instructions: 86COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0043063C Relevance: 1.5, APIs: 1, Instructions: 36COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00432551 Relevance: 1.5, APIs: 1, Instructions: 24COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004306C2 Relevance: 1.5, APIs: 1, Instructions: 21COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00430605 Relevance: 1.5, APIs: 1, Instructions: 15COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040977E Relevance: 1.5, Strings: 1, Instructions: 259COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004066A6 Relevance: .2, Instructions: 207COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004091A5 Relevance: .2, Instructions: 162COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041E100 Relevance: .1, Instructions: 102COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00424250 Relevance: .1, Instructions: 98COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406C00 Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00413B40 Relevance: 38.7, APIs: 15, Strings: 7, Instructions: 231registrylibraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415BE0 Relevance: 28.2, APIs: 5, Strings: 11, Instructions: 196registryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00416940 Relevance: 28.1, APIs: 8, Strings: 8, Instructions: 78libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00422B84 Relevance: 28.1, APIs: 8, Strings: 8, Instructions: 78libraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00410610 Relevance: 26.5, APIs: 4, Strings: 11, Instructions: 257windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041BD40 Relevance: 22.9, APIs: 8, Strings: 5, Instructions: 172comCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040C000 Relevance: 21.3, APIs: 8, Strings: 4, Instructions: 318sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00414AC1 Relevance: 21.1, APIs: 5, Strings: 7, Instructions: 111sleepfileCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00417560 Relevance: 19.4, APIs: 10, Strings: 1, Instructions: 153registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042B105 Relevance: 19.3, APIs: 6, Strings: 5, Instructions: 71libraryloaderthreadCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00436495 Relevance: 16.6, APIs: 11, Instructions: 120COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004431A6 Relevance: 15.1, APIs: 10, Instructions: 99memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040A209 Relevance: 14.1, APIs: 4, Strings: 4, Instructions: 103filesleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00410E60 Relevance: 12.4, APIs: 3, Strings: 4, Instructions: 137windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040A590 Relevance: 12.4, APIs: 5, Strings: 2, Instructions: 116sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042CD8E Relevance: 12.4, APIs: 3, Strings: 4, Instructions: 115fileCOMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0044399E Relevance: 12.4, APIs: 4, Strings: 3, Instructions: 105stringCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042B312 Relevance: 12.3, APIs: 1, Strings: 6, Instructions: 97COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00430910 Relevance: 12.2, APIs: 8, Instructions: 196COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042D3D4 Relevance: 12.1, APIs: 8, Instructions: 131COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00411D90 Relevance: 10.7, APIs: 3, Strings: 3, Instructions: 204windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00432594 Relevance: 10.7, APIs: 7, Instructions: 169COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00443492 Relevance: 10.6, APIs: 7, Instructions: 96memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00422D35 Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 62stringCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00414930 Relevance: 10.5, APIs: 2, Strings: 4, Instructions: 46libraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00443AEC Relevance: 10.5, APIs: 4, Strings: 2, Instructions: 38libraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004294D7 Relevance: 9.2, APIs: 6, Instructions: 197COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004336D1 Relevance: 9.2, APIs: 6, Instructions: 181processsynchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004334AC Relevance: 9.2, APIs: 6, Instructions: 168COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042C3B0 Relevance: 9.1, APIs: 6, Instructions: 145COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0043EA5F Relevance: 9.1, APIs: 6, Instructions: 68COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0043BE10 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 115stringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004248C5 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 13libraryloaderCOMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042A412 Relevance: 7.7, APIs: 5, Instructions: 184COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042D4F6 Relevance: 7.7, APIs: 5, Instructions: 172COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042EF95 Relevance: 7.7, APIs: 5, Instructions: 169COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00428338 Relevance: 7.6, APIs: 5, Instructions: 150COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415000 Relevance: 7.6, APIs: 6, Instructions: 138sleepCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004164D0 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 65registryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00416B50 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 56windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042C2D4 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 37libraryloaderCOMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004317FE Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 29libraryloaderCOMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004015E1 Relevance: 6.2, APIs: 2, Strings: 2, Instructions: 150sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004286E3 Relevance: 6.1, APIs: 4, Instructions: 113COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00433DA0 Relevance: 6.0, APIs: 4, Instructions: 38COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042B4E2 Relevance: 5.4, APIs: 1, Strings: 2, Instructions: 105COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00427102 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 22threadCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00429C5F Relevance: 5.1, APIs: 4, Instructions: 57memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 3.2% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 4.8% |
Total number of Nodes: | 1280 |
Total number of Limit Nodes: | 43 |
Graph
Function 006ABCE3 Relevance: 115.6, APIs: 40, Strings: 26, Instructions: 140libraryloaderCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0069E54F Relevance: 12.3, APIs: 2, Strings: 5, Instructions: 88sleepCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006999E4 Relevance: 12.3, APIs: 6, Strings: 1, Instructions: 65windowCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0069455B Relevance: 4.5, APIs: 3, Instructions: 28synchronizationnetworkCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006AA7A2 Relevance: 1.5, APIs: 1, Instructions: 40COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0069E679 Relevance: 1.5, APIs: 1, Instructions: 19COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A3FD4 Relevance: 48.1, APIs: 5, Strings: 22, Instructions: 813sleepnetworkCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00699E48 Relevance: 21.2, APIs: 6, Strings: 6, Instructions: 163sleepCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0069428C Relevance: 19.4, APIs: 4, Strings: 7, Instructions: 147networkCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0069A3F4 Relevance: 17.7, APIs: 6, Strings: 4, Instructions: 158sleepCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006AA51B Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 68networkfileCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00699D97 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 58sleepfileCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00694468 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 92synchronizationnetworkCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006998A5 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 70threadCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00694915 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 60timethreadCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A26D2 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 37registryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A27D5 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 31registryCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00694688 Relevance: 6.1, APIs: 4, Instructions: 121synchronizationthreadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006AB58F Relevance: 6.1, APIs: 4, Instructions: 64fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0069BED7 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 13synchronizationCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006941F1 Relevance: 3.0, APIs: 2, Instructions: 40networkCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006D8706 Relevance: 3.0, APIs: 1, Strings: 1, Instructions: 39memoryCOMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006D6AFF Relevance: 3.0, APIs: 1, Strings: 1, Instructions: 32memoryCOMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006AAC52 Relevance: 3.0, APIs: 2, Instructions: 25COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A3F9A Relevance: 3.0, APIs: 2, Instructions: 21networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00694262 Relevance: 1.5, APIs: 1, Instructions: 15networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00696F06 Relevance: 46.3, APIs: 10, Strings: 16, Instructions: 849filesleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00695042 Relevance: 38.8, APIs: 15, Strings: 7, Instructions: 280pipesleepfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A0F36 Relevance: 33.5, APIs: 7, Strings: 12, Instructions: 238threadCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0069B335 Relevance: 24.6, APIs: 8, Strings: 6, Instructions: 145fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0069B53A Relevance: 21.1, APIs: 7, Strings: 5, Instructions: 130fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0069E219 Relevance: 19.5, APIs: 6, Strings: 5, Instructions: 212processCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A59C6 Relevance: 18.1, APIs: 12, Instructions: 80clipboardmemoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00414C50 Relevance: 17.7, APIs: 7, Strings: 3, Instructions: 213fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00414C5E Relevance: 17.7, APIs: 7, Strings: 3, Instructions: 188fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00699B10 Relevance: 15.9, APIs: 8, Strings: 1, Instructions: 108keyboardthreadCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006E13B7 Relevance: 14.2, APIs: 5, Strings: 3, Instructions: 188COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006AB42F Relevance: 13.6, APIs: 9, Instructions: 105fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A8C69 Relevance: 12.5, APIs: 2, Strings: 5, Instructions: 245fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A2F45 Relevance: 10.9, APIs: 4, Strings: 2, Instructions: 391registrylibraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0069B21B Relevance: 10.5, APIs: 2, Strings: 4, Instructions: 48fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006989A9 Relevance: 9.3, APIs: 6, Instructions: 288fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A9BC4 Relevance: 9.0, APIs: 6, Instructions: 39serviceCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A58B9 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 97libraryloadershutdownCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006E11E3 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 86COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00697A8C Relevance: 7.7, APIs: 5, Instructions: 183fileCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00696128 Relevance: 7.2, APIs: 2, Strings: 2, Instructions: 222filenetworkCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006CA65D Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 78COMMONLIBRARYCODE
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00698DA7 Relevance: 6.2, APIs: 4, Instructions: 206fileCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006C3CD7 Relevance: 1.5, APIs: 1, Instructions: 3COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006DE92E Relevance: 1.3, APIs: 1, Instructions: 5memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A7F9F Relevance: 51.1, APIs: 28, Strings: 1, Instructions: 324windowmemoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A7245 Relevance: 47.5, APIs: 22, Strings: 5, Instructions: 290libraryloaderthreadCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A12B5 Relevance: 43.9, APIs: 17, Strings: 8, Instructions: 189synchronizationsleepfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0069C28E Relevance: 42.3, APIs: 6, Strings: 18, Instructions: 282registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0069BF04 Relevance: 40.5, APIs: 6, Strings: 17, Instructions: 260registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006AA1BB Relevance: 40.4, APIs: 12, Strings: 11, Instructions: 180synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00691BE8 Relevance: 35.2, APIs: 16, Strings: 4, Instructions: 156fileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006964E0 Relevance: 35.1, APIs: 12, Strings: 8, Instructions: 62libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0069BC67 Relevance: 31.7, APIs: 12, Strings: 6, Instructions: 203fileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006AB1BB Relevance: 28.1, APIs: 15, Strings: 1, Instructions: 139stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006DE20E Relevance: 25.9, APIs: 17, Instructions: 419COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A1C81 Relevance: 25.0, APIs: 9, Strings: 5, Instructions: 479sleepfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006E006D Relevance: 24.6, APIs: 13, Strings: 1, Instructions: 114COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A3E37 Relevance: 24.6, APIs: 9, Strings: 5, Instructions: 109libraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006AB824 Relevance: 23.0, APIs: 6, Strings: 7, Instructions: 214registryCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006ACA9E Relevance: 22.8, APIs: 12, Strings: 1, Instructions: 73windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006D4F3D Relevance: 22.8, APIs: 15, Instructions: 296COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00697DEF Relevance: 21.3, APIs: 8, Strings: 4, Instructions: 325fileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A9128 Relevance: 19.4, APIs: 6, Strings: 5, Instructions: 174sleeptimeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006DF3E1 Relevance: 18.4, APIs: 12, Instructions: 376COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006947EB Relevance: 18.1, APIs: 12, Instructions: 66synchronizationCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006E4982 Relevance: 17.8, APIs: 9, Strings: 1, Instructions: 272COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00694E52 Relevance: 15.9, APIs: 6, Strings: 3, Instructions: 155windowmemoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A6E27 Relevance: 15.9, APIs: 4, Strings: 5, Instructions: 107filesynchronizationCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006D6DCB Relevance: 15.1, APIs: 10, Instructions: 54COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006E5139 Relevance: 14.2, APIs: 1, Strings: 7, Instructions: 154COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A65FC Relevance: 14.1, APIs: 3, Strings: 5, Instructions: 103sleepfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006DFCDB Relevance: 14.1, APIs: 7, Strings: 1, Instructions: 65COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006AC96F Relevance: 14.0, APIs: 7, Strings: 1, Instructions: 47windowstringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006E2B2A Relevance: 13.8, APIs: 9, Instructions: 268COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006D43F9 Relevance: 12.5, APIs: 6, Strings: 1, Instructions: 266COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00691768 Relevance: 12.4, APIs: 3, Strings: 4, Instructions: 142threadCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00696BE9 Relevance: 12.3, APIs: 6, Strings: 1, Instructions: 97fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006D7E3A Relevance: 10.9, APIs: 7, Instructions: 370timeCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006DF806 Relevance: 10.7, APIs: 7, Instructions: 204COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006D3F7B Relevance: 10.7, APIs: 5, Strings: 1, Instructions: 187COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006DA0C3 Relevance: 10.7, APIs: 7, Instructions: 152fileCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006E59CA Relevance: 10.7, APIs: 4, Strings: 2, Instructions: 152COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A2C88 Relevance: 10.6, APIs: 2, Strings: 4, Instructions: 135registryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0069B2A8 Relevance: 10.5, APIs: 2, Strings: 4, Instructions: 48fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006ABEB0 Relevance: 10.5, APIs: 3, Strings: 3, Instructions: 47memoryCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006DF79D Relevance: 10.5, APIs: 5, Strings: 1, Instructions: 40COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006C95FC Relevance: 9.3, APIs: 6, Instructions: 284COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006D6159 Relevance: 9.1, APIs: 3, Strings: 2, Instructions: 389COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00693DE7 Relevance: 9.1, APIs: 1, Strings: 5, Instructions: 135sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A9DEC Relevance: 9.1, APIs: 6, Instructions: 66serviceCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A9C20 Relevance: 9.0, APIs: 6, Instructions: 44serviceCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A9D22 Relevance: 9.0, APIs: 6, Instructions: 44serviceCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A9D87 Relevance: 9.0, APIs: 6, Instructions: 44serviceCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A29AA Relevance: 8.9, APIs: 3, Strings: 2, Instructions: 173registryCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006ACA1F Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 54registryCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006D7210 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 52libraryCOMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006969BA Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 42processCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006D25D9 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 38libraryloaderCOMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A2774 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 38registryCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00694AB1 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 35synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A9F32 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 30sleepCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A0B19 Relevance: 7.7, APIs: 5, Instructions: 198memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00415000 Relevance: 7.6, APIs: 6, Instructions: 138sleepCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006DE13B Relevance: 7.6, APIs: 5, Instructions: 68COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006D32E7 Relevance: 7.5, APIs: 5, Instructions: 30COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A6751 Relevance: 7.2, APIs: 3, Strings: 1, Instructions: 182threadwindowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00693A10 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 92sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0069A611 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 64threadCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006DAA73 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 61COMMONLIBRARYCODE
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00694B29 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 47synchronizationCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0069AFBA Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 20threadCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00691430 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 7libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006914D5 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 7libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0042C814 Relevance: 6.1, APIs: 4, Instructions: 145fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 006D1A81 Relevance: 6.1, APIs: 4, Instructions: 133COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0069B806 Relevance: 6.1, APIs: 2, Strings: 2, Instructions: 103sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A1524 Relevance: 6.1, APIs: 1, Strings: 3, Instructions: 93sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00699C4B Relevance: 6.1, APIs: 2, Strings: 2, Instructions: 71sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006D2CD2 Relevance: 6.1, APIs: 4, Instructions: 63COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006D2D51 Relevance: 6.1, APIs: 4, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006AB61A Relevance: 6.0, APIs: 4, Instructions: 50fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A850C Relevance: 6.0, APIs: 4, Instructions: 49COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006AB37D Relevance: 6.0, APIs: 4, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006E08DE Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 88COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 006D7174 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 65libraryloaderCOMMONLIBRARYCODE
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006C3D2C Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 59COMMONLIBRARYCODE
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006C360D Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 38COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006D7790 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 35COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0069AD56 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 32keyboardCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0069ADB0 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 24keyboardCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A297A Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 23registryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006A1699 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 13synchronizationCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|