Windows
Analysis Report
1734388385543fca13ccf5614dc71c1922a5cd8cddeb80fc9e4bce55f618d2232c3744cd06117.dat-decoded.exe
Overview
General Information
Sample name: | 1734388385543fca13ccf5614dc71c1922a5cd8cddeb80fc9e4bce55f618d2232c3744cd06117.dat-decoded.exe |
Analysis ID: | 1576397 |
MD5: | f14e833c2b69a9637a7c7d7af31aadea |
SHA1: | 3cee372cff015aa08ff4d085d8d7c8eefb0d1a78 |
SHA256: | 5294488f02dcfa41ad7b603ad9658346c028c5855781e5f41c6a2c94030ba96f |
Tags: | base64-decodedexeuser-abuse_ch |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- 1734388385543fca13ccf5614dc71c1922a5cd8cddeb80fc9e4bce55f618d2232c3744cd06117.dat-decoded.exe (PID: 7360 cmdline:
"C:\Users\ user\Deskt op\1734388 385543fca1 3ccf5614dc 71c1922a5c d8cddeb80f c9e4bce55f 618d2232c3 744cd06117 .dat-decod ed.exe" MD5: F14E833C2B69A9637A7C7D7AF31AADEA)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Remcos, RemcosRAT | Remcos (acronym of Remote Control & Surveillance Software) is a commercial Remote Access Tool to remotely control computers.Remcos is advertised as legitimate software which can be used for surveillance and penetration testing purposes, but has been used in numerous hacking campaigns.Remcos, once installed, opens a backdoor on the computer, granting full access to the remote user.Remcos is developed by the cybersecurity company BreakingSecurity. |
{"Host:Port:Password": ["newglobalfucntioninside.duckdns.org:14646:1"], "Assigned name": "RemoteHost", "Connect interval": "1", "Install flag": "Disable", "Setup HKCU\\Run": "Enable", "Setup HKLM\\Run": "Enable", "Install path": "Application path", "Copy file": "remcos.exe", "Startup value": "Disable", "Hide file": "Disable", "Mutex": "Rmc-PVMSPM", "Keylog flag": "0", "Keylog path": "Application path", "Keylog file": "logs.dat", "Keylog crypt": "Disable", "Hide keylog file": "Disable", "Screenshot flag": "Disable", "Screenshot time": "1", "Take Screenshot option": "Disable", "Take screenshot title": "", "Take screenshot time": "5", "Screenshot path": "AppData", "Screenshot file": "Screenshots", "Screenshot crypt": "Disable", "Mouse option": "Disable", "Delete file": "Disable", "Audio record time": "5", "Audio folder": "MicRecords", "Connect delay": "0", "Copy folder": "Remcos", "Keylog folder": "remcos"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Keylogger_Generic | Yara detected Keylogger Generic | Joe Security | ||
JoeSecurity_Remcos | Yara detected Remcos RAT | Joe Security | ||
JoeSecurity_UACBypassusingCMSTP | Yara detected UAC Bypass using CMSTP | Joe Security | ||
Windows_Trojan_Remcos_b296e965 | unknown | unknown |
| |
REMCOS_RAT_variants | unknown | unknown |
| |
Click to see the 1 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Keylogger_Generic | Yara detected Keylogger Generic | Joe Security | ||
JoeSecurity_Remcos | Yara detected Remcos RAT | Joe Security | ||
JoeSecurity_UACBypassusingCMSTP | Yara detected UAC Bypass using CMSTP | Joe Security | ||
Windows_Trojan_Remcos_b296e965 | unknown | unknown |
| |
JoeSecurity_Keylogger_Generic | Yara detected Keylogger Generic | Joe Security | ||
Click to see the 8 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Keylogger_Generic | Yara detected Keylogger Generic | Joe Security | ||
JoeSecurity_Remcos | Yara detected Remcos RAT | Joe Security | ||
JoeSecurity_UACBypassusingCMSTP | Yara detected UAC Bypass using CMSTP | Joe Security | ||
Windows_Trojan_Remcos_b296e965 | unknown | unknown |
| |
REMCOS_RAT_variants | unknown | unknown |
| |
Click to see the 7 entries |
Stealing of Sensitive Information |
---|
Source: | Author: Joe Security: |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-16T23:34:59.728051+0100 | 2036594 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50023 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:35:10.541700+0100 | 2036594 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49730 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:35:21.980788+0100 | 2036594 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:35:33.478010+0100 | 2036594 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49737 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:35:44.945189+0100 | 2036594 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49739 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:35:56.455423+0100 | 2036594 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49740 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:36:07.827823+0100 | 2036594 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49743 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:36:19.602424+0100 | 2036594 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49769 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:36:31.037042+0100 | 2036594 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49795 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:36:42.483509+0100 | 2036594 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49825 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:36:53.957750+0100 | 2036594 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49852 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:37:05.443437+0100 | 2036594 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49878 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:37:16.917244+0100 | 2036594 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49904 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:37:28.703412+0100 | 2036594 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49930 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:37:40.238135+0100 | 2036594 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49959 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:37:51.699789+0100 | 2036594 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49986 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:38:03.227367+0100 | 2036594 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50013 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:38:14.717369+0100 | 2036594 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50018 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:38:26.201373+0100 | 2036594 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50019 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:38:38.525519+0100 | 2036594 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50020 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:38:50.017441+0100 | 2036594 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50021 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:39:01.461561+0100 | 2036594 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50022 | 192.169.69.26 | 14646 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira URL Cloud: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Code function: | 0_2_0043294A |
Source: | Binary or memory string: | memstr_fa68f948-e |
Exploits |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Privilege Escalation |
---|
Source: | Code function: | 0_2_00406764 |
Source: | Static PE information: |
Source: | Code function: | 0_2_0040B335 | |
Source: | Code function: | 0_2_0041B43F | |
Source: | Code function: | 0_2_0040B53A | |
Source: | Code function: | 0_2_004089A9 | |
Source: | Code function: | 0_2_00406AC2 | |
Source: | Code function: | 0_2_00407A8C | |
Source: | Code function: | 0_2_00418C79 | |
Source: | Code function: | 0_2_00408DA7 |
Source: | Code function: | 0_2_00406F06 |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | URLs: |
Source: | DNS query: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | Code function: | 0_2_00426107 |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | Code function: | 0_2_004099E4 |
Source: | Code function: | 0_2_004159C6 |
Source: | Code function: | 0_2_004159C6 |
Source: | Code function: | 0_2_004159C6 |
Source: | Code function: | 0_2_00409B10 |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
E-Banking Fraud |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | Code function: | 0_2_0041BB81 | |
Source: | Code function: | 0_2_0041BB87 |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 0_2_0041ACD1 | |
Source: | Code function: | 0_2_0041ACFD |
Source: | Code function: | 0_2_004158B9 |
Source: | Code function: | 0_2_004520E2 | |
Source: | Code function: | 0_2_0041D081 | |
Source: | Code function: | 0_2_0043D0A8 | |
Source: | Code function: | 0_2_00437160 | |
Source: | Code function: | 0_2_004361BA | |
Source: | Code function: | 0_2_00426264 | |
Source: | Code function: | 0_2_00431387 | |
Source: | Code function: | 0_2_0043652C | |
Source: | Code function: | 0_2_0041E5EF | |
Source: | Code function: | 0_2_0044C749 | |
Source: | Code function: | 0_2_004367D6 | |
Source: | Code function: | 0_2_004267DB | |
Source: | Code function: | 0_2_0043C9ED | |
Source: | Code function: | 0_2_00432A59 | |
Source: | Code function: | 0_2_00436A9D | |
Source: | Code function: | 0_2_0043CC1C | |
Source: | Code function: | 0_2_00436D58 | |
Source: | Code function: | 0_2_00434D32 | |
Source: | Code function: | 0_2_0043CE4B | |
Source: | Code function: | 0_2_00440E30 | |
Source: | Code function: | 0_2_00426E83 | |
Source: | Code function: | 0_2_00412F45 | |
Source: | Code function: | 0_2_00452F10 | |
Source: | Code function: | 0_2_00426FBD |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | Code function: | 0_2_00416AB7 |
Source: | Code function: | 0_2_0040E219 |
Source: | Code function: | 0_2_0041A64F |
Source: | Code function: | 0_2_00419BD4 |
Source: | Mutant created: |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 | |
Source: | Command line argument: | 0_2_0040D767 |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_2_0041BCF3 |
Source: | Code function: | 0_2_00434019 | |
Source: | Code function: | 0_2_0045680E | |
Source: | Code function: | 0_2_00455ED2 |
Source: | Code function: | 0_2_00406128 |
Source: | Code function: | 0_2_00419BD4 |
Source: | Code function: | 0_2_0041BCF3 |
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Code function: | 0_2_0040E54F |
Source: | Code function: | 0_2_004198D2 |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | API coverage: |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Code function: | 0_2_0040B335 | |
Source: | Code function: | 0_2_0041B43F | |
Source: | Code function: | 0_2_0040B53A | |
Source: | Code function: | 0_2_004089A9 | |
Source: | Code function: | 0_2_00406AC2 | |
Source: | Code function: | 0_2_00407A8C | |
Source: | Code function: | 0_2_00418C79 | |
Source: | Code function: | 0_2_00408DA7 |
Source: | Code function: | 0_2_00406F06 |
Source: | Binary or memory string: |
Source: | API call chain: | graph_0-46918 |
Source: | Code function: | 0_2_0043A66D |
Source: | Code function: | 0_2_0041BCF3 |
Source: | Code function: | 0_2_00442564 |
Source: | Code function: | 0_2_0044E93E |
Source: | Code function: | 0_2_00434178 | |
Source: | Code function: | 0_2_0043A66D | |
Source: | Code function: | 0_2_00433B54 | |
Source: | Code function: | 0_2_00433CE7 |
Source: | Code function: | 0_2_00410F36 |
Source: | Code function: | 0_2_00418764 |
Source: | Code function: | 0_2_00433E1A |
Source: | Code function: | 0_2_004510CA | |
Source: | Code function: | 0_2_004470BE | |
Source: | Code function: | 0_2_004511F3 | |
Source: | Code function: | 0_2_004512FA | |
Source: | Code function: | 0_2_004513C7 | |
Source: | Code function: | 0_2_004475A7 | |
Source: | Code function: | 0_2_0040E679 | |
Source: | Code function: | 0_2_00450A8F | |
Source: | Code function: | 0_2_00450D52 | |
Source: | Code function: | 0_2_00450D07 | |
Source: | Code function: | 0_2_00450DED | |
Source: | Code function: | 0_2_00450E7A |
Source: | Code function: | 0_2_00404915 |
Source: | Code function: | 0_2_0041A7B2 |
Source: | Code function: | 0_2_00448067 |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Code function: | 0_2_0040B21B |
Source: | Code function: | 0_2_0040B335 | |
Source: | Code function: | 0_2_0040B335 |
Remote Access Functionality |
---|
Source: | Mutex created: | Jump to behavior |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Code function: | 0_2_00405042 |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Deobfuscate/Decode Files or Information | 1 OS Credential Dumping | 2 System Time Discovery | Remote Services | 11 Archive Collected Data | 11 Ingress Tool Transfer | Exfiltration Over Other Network Medium | 1 System Shutdown/Reboot |
Credentials | Domains | Default Accounts | 12 Command and Scripting Interpreter | 1 Windows Service | 1 Bypass User Account Control | 2 Obfuscated Files or Information | 111 Input Capture | 1 Account Discovery | Remote Desktop Protocol | 111 Input Capture | 2 Encrypted Channel | Exfiltration Over Bluetooth | 1 Defacement |
Email Addresses | DNS Server | Domain Accounts | 2 Service Execution | Logon Script (Windows) | 1 Access Token Manipulation | 1 DLL Side-Loading | 2 Credentials In Files | 1 System Service Discovery | SMB/Windows Admin Shares | 3 Clipboard Data | 1 Remote Access Software | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 1 Windows Service | 1 Bypass User Account Control | NTDS | 2 File and Directory Discovery | Distributed Component Object Model | Input Capture | 1 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | 1 Process Injection | 1 Virtualization/Sandbox Evasion | LSA Secrets | 23 System Information Discovery | SSH | Keylogging | 21 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Access Token Manipulation | Cached Domain Credentials | 21 Security Software Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 Process Injection | DCSync | 1 Virtualization/Sandbox Evasion | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | Indicator Removal from Tools | Proc Filesystem | 1 Process Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | HTML Smuggling | /etc/passwd and /etc/shadow | 1 Application Window Discovery | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
IP Addresses | Compromise Infrastructure | Supply Chain Compromise | PowerShell | Cron | Cron | Dynamic API Resolution | Network Sniffing | 1 System Owner/User Discovery | Shared Webroot | Local Data Staging | File Transfer Protocols | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol | External Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
74% | ReversingLabs | Win32.Backdoor.Remcos | ||
100% | Avira | BDS/Backdoor.Gen | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
newglobalfucntioninside.duckdns.org | 192.169.69.26 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
192.169.69.26 | newglobalfucntioninside.duckdns.org | United States | 23033 | WOWUS | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1576397 |
Start date and time: | 2024-12-16 23:34:06 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 26s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 5 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 1734388385543fca13ccf5614dc71c1922a5cd8cddeb80fc9e4bce55f618d2232c3744cd06117.dat-decoded.exe |
Detection: | MAL |
Classification: | mal100.rans.troj.spyw.expl.evad.winEXE@1/0@4/1 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 20.12.23.50, 13.107.246.63
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: 1734388385543fca13ccf5614dc71c1922a5cd8cddeb80fc9e4bce55f618d2232c3744cd06117.dat-decoded.exe
Time | Type | Description |
---|---|---|
17:35:35 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
192.169.69.26 | Get hash | malicious | RedLine, XWorm | Browse |
| |
Get hash | malicious | VjW0rm, AsyncRAT, RATDispenser | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
newglobalfucntioninside.duckdns.org | Get hash | malicious | Cobalt Strike, Remcos | Browse |
| |
Get hash | malicious | Remcos | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
WOWUS | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | AsyncRAT | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Cobalt Strike, Remcos | Browse |
| ||
Get hash | malicious | AsyncRAT, DcRat | Browse |
| ||
Get hash | malicious | RedLine, XWorm | Browse |
| ||
Get hash | malicious | Nanocore | Browse |
| ||
Get hash | malicious | AsyncRAT | Browse |
| ||
Get hash | malicious | AsyncRAT | Browse |
| ||
Get hash | malicious | AsyncRAT, PureLog Stealer | Browse |
|
File type: | |
Entropy (8bit): | 6.586446051281027 |
TrID: |
|
File name: | 1734388385543fca13ccf5614dc71c1922a5cd8cddeb80fc9e4bce55f618d2232c3744cd06117.dat-decoded.exe |
File size: | 493'056 bytes |
MD5: | f14e833c2b69a9637a7c7d7af31aadea |
SHA1: | 3cee372cff015aa08ff4d085d8d7c8eefb0d1a78 |
SHA256: | 5294488f02dcfa41ad7b603ad9658346c028c5855781e5f41c6a2c94030ba96f |
SHA512: | 6fad90820cade81e24049b6bdeca8df1946ac76aae0806a186e896bc43179328529f3fb9d19ea81329be9de499dd7a9104765b163988c1813f0e1a5a35a8aaaf |
SSDEEP: | 12288:L9PgP3HAMwIGjY4vce6lnBthn5HSRVMf139F5woxr+IwtHwBtFhCsvZD5S+P32:Z43HfwIGYMcn5PJrZM+ |
TLSH: | A2A4BE01B6D2C072D57625300D26E775DEBDBD212835897BB3DA1D67FE30180E63AAB2 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........)...H...H...H....(..H....*..H....+..H...0]..H..&....H... ...H... ...H... ...H...0J..H...H...I...!...H...!&..H...!...H..Rich.H. |
Icon Hash: | 95694d05214c1b33 |
Entrypoint: | 0x433b4a |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | TERMINAL_SERVER_AWARE |
Time Stamp: | 0x6752B172 [Fri Dec 6 08:10:26 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 1 |
File Version Major: | 5 |
File Version Minor: | 1 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 1 |
Import Hash: | e77512f955eaf60ccff45e02d69234de |
Instruction |
---|
call 00007FAB8C9D3A33h |
jmp 00007FAB8C9D338Fh |
push ebp |
mov ebp, esp |
sub esp, 00000324h |
push ebx |
push 00000017h |
call 00007FAB8C9F5869h |
test eax, eax |
je 00007FAB8C9D3517h |
mov ecx, dword ptr [ebp+08h] |
int 29h |
push 00000003h |
call 00007FAB8C9D36D4h |
mov dword ptr [esp], 000002CCh |
lea eax, dword ptr [ebp-00000324h] |
push 00000000h |
push eax |
call 00007FAB8C9D59EBh |
add esp, 0Ch |
mov dword ptr [ebp-00000274h], eax |
mov dword ptr [ebp-00000278h], ecx |
mov dword ptr [ebp-0000027Ch], edx |
mov dword ptr [ebp-00000280h], ebx |
mov dword ptr [ebp-00000284h], esi |
mov dword ptr [ebp-00000288h], edi |
mov word ptr [ebp-0000025Ch], ss |
mov word ptr [ebp-00000268h], cs |
mov word ptr [ebp-0000028Ch], ds |
mov word ptr [ebp-00000290h], es |
mov word ptr [ebp-00000294h], fs |
mov word ptr [ebp-00000298h], gs |
pushfd |
pop dword ptr [ebp-00000264h] |
mov eax, dword ptr [ebp+04h] |
mov dword ptr [ebp-0000026Ch], eax |
lea eax, dword ptr [ebp+04h] |
mov dword ptr [ebp-00000260h], eax |
mov dword ptr [ebp-00000324h], 00010001h |
mov eax, dword ptr [eax-04h] |
push 00000050h |
mov dword ptr [ebp-00000270h], eax |
lea eax, dword ptr [ebp-58h] |
push 00000000h |
push eax |
call 00007FAB8C9D5961h |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x6e020 | 0x104 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x76000 | 0x4a9c | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x7b000 | 0x3b88 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x6c510 | 0x38 | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x6c5e8 | 0x18 | .rdata |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x6c548 | 0x40 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x57000 | 0x4f4 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x55f2d | 0x56000 | c9fb1fecb5f01a3c88e2bc00eccd57c4 | False | 0.5739377043968024 | data | 6.621523378040251 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x57000 | 0x18b00 | 0x18c00 | 0ba285a9a28b1dec254a7539ab18f8d0 | False | 0.4981455176767677 | OpenPGP Secret Key Version 6 | 5.75873851406894 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x70000 | 0x5d8c | 0xe00 | 06414e748130e7e668ba2ba172d63448 | False | 0.22684151785714285 | data | 3.093339598098017 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x76000 | 0x4a9c | 0x4c00 | 3e83db102941549e2f72fe75f1340133 | False | 0.27420847039473684 | data | 3.9788779818289983 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x7b000 | 0x3b88 | 0x3c00 | b875bbd60cc90da8a22f40034fe9606e | False | 0.7575520833333333 | data | 6.702930468027394 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0x7618c | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1088 | English | United States | 0.3421985815602837 |
RT_ICON | 0x765f4 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2400 | English | United States | 0.27704918032786885 |
RT_ICON | 0x76f7c | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4224 | English | United States | 0.23686679174484052 |
RT_ICON | 0x78024 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9600 | English | United States | 0.22977178423236513 |
RT_RCDATA | 0x7a5cc | 0x490 | data | 1.009417808219178 | ||
RT_GROUP_ICON | 0x7aa5c | 0x3e | data | English | United States | 0.8064516129032258 |
DLL | Import |
---|---|
KERNEL32.dll | ExpandEnvironmentStringsA, GetLongPathNameW, CopyFileW, GetLocaleInfoA, CreateToolhelp32Snapshot, Process32NextW, Process32FirstW, VirtualProtect, SetLastError, VirtualFree, VirtualAlloc, LoadLibraryA, GetNativeSystemInfo, HeapAlloc, GetProcessHeap, FreeLibrary, IsBadReadPtr, GetTempPathW, OpenProcess, OpenMutexA, lstrcatW, GetCurrentProcessId, GetTempFileNameW, GetSystemDirectoryA, GlobalAlloc, GlobalLock, GetTickCount, GlobalUnlock, WriteProcessMemory, ResumeThread, GetThreadContext, ReadProcessMemory, CreateProcessW, SetThreadContext, LocalAlloc, GlobalFree, MulDiv, SizeofResource, QueryDosDeviceW, FindFirstVolumeW, GetConsoleScreenBufferInfo, SetConsoleTextAttribute, lstrlenW, GetStdHandle, SetFilePointer, FindResourceA, LockResource, LoadResource, LocalFree, FindVolumeClose, GetVolumePathNamesForVolumeNameW, lstrcpyW, SetConsoleOutputCP, FormatMessageA, FindFirstFileA, AllocConsole, lstrcmpW, GetModuleFileNameA, lstrcpynA, QueryPerformanceFrequency, QueryPerformanceCounter, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, DeleteCriticalSection, HeapSize, WriteConsoleW, SetStdHandle, SetEnvironmentVariableW, SetEnvironmentVariableA, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineW, GetCommandLineA, GetOEMCP, IsValidCodePage, FindFirstFileExA, HeapReAlloc, ReadConsoleW, GetConsoleMode, GetConsoleCP, FlushFileBuffers, GetFileType, GetTimeZoneInformation, EnumSystemLocalesW, GetUserDefaultLCID, IsValidLocale, GetTimeFormatW, GetDateFormatW, GetACP, GetModuleHandleExW, MoveFileExW, LoadLibraryExW, RaiseException, RtlUnwind, GetCPInfo, GetStringTypeW, GetLocaleInfoW, LCMapStringW, CompareStringW, MultiByteToWideChar, DecodePointer, EncodePointer, TlsFree, TlsSetValue, GetFileSize, TerminateThread, GetLastError, GetModuleHandleA, RemoveDirectoryW, MoveFileW, SetFilePointerEx, CreateDirectoryW, GetLogicalDriveStringsA, DeleteFileW, FindNextFileA, DeleteFileA, SetFileAttributesW, GetFileAttributesW, FindClose, lstrlenA, GetDriveTypeA, FindNextFileW, GetFileSizeEx, FindFirstFileW, GetModuleHandleW, ExitProcess, GetProcAddress, CreateMutexA, GetCurrentProcess, CreateProcessA, PeekNamedPipe, CreatePipe, TerminateProcess, ReadFile, HeapFree, HeapCreate, CreateEventA, GetLocalTime, CreateThread, SetEvent, CreateEventW, WaitForSingleObject, Sleep, GetModuleFileNameW, CloseHandle, ExitThread, CreateFileW, WriteFile, FindNextVolumeW, TlsGetValue, TlsAlloc, SwitchToThread, WideCharToMultiByte, InitializeSListHead, GetSystemTimeAsFileTime, GetCurrentThreadId, IsProcessorFeaturePresent, GetStartupInfoW, SetUnhandledExceptionFilter, UnhandledExceptionFilter, IsDebuggerPresent, WaitForSingleObjectEx, ResetEvent, InitializeCriticalSectionAndSpinCount, SetEndOfFile |
USER32.dll | DefWindowProcA, TranslateMessage, DispatchMessageA, GetMessageA, GetWindowTextW, wsprintfW, GetClipboardData, UnhookWindowsHookEx, GetForegroundWindow, ToUnicodeEx, GetKeyboardLayout, SetWindowsHookExA, CloseClipboard, OpenClipboard, GetKeyboardState, CallNextHookEx, GetKeyboardLayoutNameA, GetKeyState, GetWindowTextLengthW, GetWindowThreadProcessId, SetForegroundWindow, SetClipboardData, EnumWindows, ExitWindowsEx, EmptyClipboard, ShowWindow, SetWindowTextW, MessageBoxW, IsWindowVisible, CreateWindowExA, SendInput, EnumDisplaySettingsW, mouse_event, MapVirtualKeyA, TrackPopupMenu, CreatePopupMenu, AppendMenuA, RegisterClassExA, GetCursorPos, SystemParametersInfoW, GetIconInfo, GetSystemMetrics, CloseWindow, DrawIcon |
GDI32.dll | BitBlt, CreateCompatibleBitmap, CreateCompatibleDC, StretchBlt, GetDIBits, DeleteDC, DeleteObject, CreateDCA, GetObjectA, SelectObject |
ADVAPI32.dll | LookupPrivilegeValueA, CryptAcquireContextA, CryptGenRandom, CryptReleaseContext, GetUserNameW, RegEnumKeyExA, QueryServiceStatus, CloseServiceHandle, OpenSCManagerW, OpenSCManagerA, ControlService, StartServiceW, QueryServiceConfigW, ChangeServiceConfigW, OpenServiceW, EnumServicesStatusW, AdjustTokenPrivileges, RegDeleteKeyA, OpenProcessToken, RegCreateKeyA, RegCloseKey, RegQueryInfoKeyW, RegQueryValueExA, RegCreateKeyExW, RegEnumKeyExW, RegSetValueExW, RegSetValueExA, RegOpenKeyExA, RegOpenKeyExW, RegCreateKeyW, RegDeleteValueW, RegEnumValueW, RegQueryValueExW |
SHELL32.dll | ShellExecuteExA, Shell_NotifyIconA, ExtractIconA, ShellExecuteW |
ole32.dll | CoInitializeEx, CoGetObject, CoUninitialize |
SHLWAPI.dll | StrToIntA, PathFileExistsW, PathFileExistsA |
WINMM.dll | mciSendStringA, mciSendStringW, waveInClose, waveInStop, waveInStart, waveInUnprepareHeader, waveInOpen, waveInAddBuffer, waveInPrepareHeader, PlaySoundW |
WS2_32.dll | send, WSAStartup, socket, connect, WSAGetLastError, recv, closesocket, inet_ntoa, htons, htonl, getservbyname, ntohs, getservbyport, gethostbyaddr, inet_addr, WSASetLastError, gethostbyname |
urlmon.dll | URLOpenBlockingStreamW, URLDownloadToFileW |
gdiplus.dll | GdipAlloc, GdiplusStartup, GdipGetImageEncoders, GdipLoadImageFromStream, GdipSaveImageToStream, GdipGetImageEncodersSize, GdipFree, GdipDisposeImage, GdipCloneImage |
WININET.dll | InternetOpenUrlW, InternetOpenW, InternetCloseHandle, InternetReadFile |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-16T23:34:59.728051+0100 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | 1 | 192.168.2.4 | 50023 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:35:10.541700+0100 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | 1 | 192.168.2.4 | 49730 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:35:21.980788+0100 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | 1 | 192.168.2.4 | 49731 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:35:33.478010+0100 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | 1 | 192.168.2.4 | 49737 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:35:44.945189+0100 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | 1 | 192.168.2.4 | 49739 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:35:56.455423+0100 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | 1 | 192.168.2.4 | 49740 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:36:07.827823+0100 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | 1 | 192.168.2.4 | 49743 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:36:19.602424+0100 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | 1 | 192.168.2.4 | 49769 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:36:31.037042+0100 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | 1 | 192.168.2.4 | 49795 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:36:42.483509+0100 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | 1 | 192.168.2.4 | 49825 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:36:53.957750+0100 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | 1 | 192.168.2.4 | 49852 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:37:05.443437+0100 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | 1 | 192.168.2.4 | 49878 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:37:16.917244+0100 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | 1 | 192.168.2.4 | 49904 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:37:28.703412+0100 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | 1 | 192.168.2.4 | 49930 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:37:40.238135+0100 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | 1 | 192.168.2.4 | 49959 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:37:51.699789+0100 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | 1 | 192.168.2.4 | 49986 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:38:03.227367+0100 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | 1 | 192.168.2.4 | 50013 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:38:14.717369+0100 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | 1 | 192.168.2.4 | 50018 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:38:26.201373+0100 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | 1 | 192.168.2.4 | 50019 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:38:38.525519+0100 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | 1 | 192.168.2.4 | 50020 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:38:50.017441+0100 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | 1 | 192.168.2.4 | 50021 | 192.169.69.26 | 14646 | TCP |
2024-12-16T23:39:01.461561+0100 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | 1 | 192.168.2.4 | 50022 | 192.169.69.26 | 14646 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 16, 2024 23:35:00.069895983 CET | 49730 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:00.189613104 CET | 14646 | 49730 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:35:00.189735889 CET | 49730 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:00.194421053 CET | 49730 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:00.315485954 CET | 14646 | 49730 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:35:10.541568041 CET | 14646 | 49730 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:35:10.541699886 CET | 49730 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:10.541779995 CET | 49730 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:10.661842108 CET | 14646 | 49730 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:35:11.555198908 CET | 49731 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:11.675441027 CET | 14646 | 49731 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:35:11.675595999 CET | 49731 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:11.678735018 CET | 49731 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:11.799860001 CET | 14646 | 49731 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:35:21.980729103 CET | 14646 | 49731 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:35:21.980787992 CET | 49731 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:21.980971098 CET | 49731 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:22.100925922 CET | 14646 | 49731 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:35:22.996350050 CET | 49737 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:23.137305021 CET | 14646 | 49737 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:35:23.137398005 CET | 49737 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:23.140866995 CET | 49737 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:23.260603905 CET | 14646 | 49737 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:35:33.477809906 CET | 14646 | 49737 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:35:33.478009939 CET | 49737 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:33.478009939 CET | 49737 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:33.597918034 CET | 14646 | 49737 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:35:34.492765903 CET | 49739 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:34.612858057 CET | 14646 | 49739 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:35:34.612967014 CET | 49739 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:34.617969990 CET | 49739 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:34.737855911 CET | 14646 | 49739 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:35:44.945012093 CET | 14646 | 49739 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:35:44.945188999 CET | 49739 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:44.945277929 CET | 49739 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:45.066606045 CET | 14646 | 49739 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:35:45.961556911 CET | 49740 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:46.081537008 CET | 14646 | 49740 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:35:46.081738949 CET | 49740 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:46.085565090 CET | 49740 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:46.205385923 CET | 14646 | 49740 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:35:56.455290079 CET | 14646 | 49740 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:35:56.455423117 CET | 49740 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:56.456093073 CET | 49740 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:56.575819969 CET | 14646 | 49740 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:35:57.461739063 CET | 49743 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:57.581729889 CET | 14646 | 49743 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:35:57.581935883 CET | 49743 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:57.587028027 CET | 49743 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:35:57.706911087 CET | 14646 | 49743 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:36:07.827518940 CET | 14646 | 49743 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:36:07.827822924 CET | 49743 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:07.827822924 CET | 49743 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:07.947679996 CET | 14646 | 49743 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:36:09.148009062 CET | 49769 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:09.267987013 CET | 14646 | 49769 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:36:09.269136906 CET | 49769 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:09.272789001 CET | 49769 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:09.392657042 CET | 14646 | 49769 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:36:19.602325916 CET | 14646 | 49769 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:36:19.602423906 CET | 49769 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:19.602581024 CET | 49769 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:19.722265959 CET | 14646 | 49769 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:36:20.618010044 CET | 49795 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:20.737893105 CET | 14646 | 49795 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:36:20.738008976 CET | 49795 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:20.742134094 CET | 49795 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:20.861824036 CET | 14646 | 49795 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:36:31.036921978 CET | 14646 | 49795 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:36:31.037041903 CET | 49795 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:31.039776087 CET | 49795 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:31.159502029 CET | 14646 | 49795 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:36:32.055402040 CET | 49825 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:32.175128937 CET | 14646 | 49825 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:36:32.175234079 CET | 49825 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:32.178745031 CET | 49825 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:32.298397064 CET | 14646 | 49825 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:36:42.483402967 CET | 14646 | 49825 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:36:42.483509064 CET | 49825 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:42.485572100 CET | 49825 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:42.608803034 CET | 14646 | 49825 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:36:43.493015051 CET | 49852 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:43.612848043 CET | 14646 | 49852 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:36:43.615428925 CET | 49852 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:43.624509096 CET | 49852 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:43.745066881 CET | 14646 | 49852 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:36:53.957681894 CET | 14646 | 49852 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:36:53.957750082 CET | 49852 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:53.957832098 CET | 49852 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:54.077555895 CET | 14646 | 49852 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:36:54.967267990 CET | 49878 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:55.087193012 CET | 14646 | 49878 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:36:55.087348938 CET | 49878 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:55.090802908 CET | 49878 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:36:55.210530996 CET | 14646 | 49878 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:37:05.440063000 CET | 14646 | 49878 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:37:05.443437099 CET | 49878 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:05.443506956 CET | 49878 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:05.563374996 CET | 14646 | 49878 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:37:06.479156971 CET | 49904 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:06.599205017 CET | 14646 | 49904 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:37:06.599318981 CET | 49904 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:06.603951931 CET | 49904 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:06.723790884 CET | 14646 | 49904 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:37:16.915462971 CET | 14646 | 49904 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:37:16.917243958 CET | 49904 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:16.917315960 CET | 49904 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:17.037074089 CET | 14646 | 49904 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:37:18.258764982 CET | 49930 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:18.378926992 CET | 14646 | 49930 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:37:18.379014969 CET | 49930 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:18.386099100 CET | 49930 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:18.505908012 CET | 14646 | 49930 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:37:28.701270103 CET | 14646 | 49930 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:37:28.703412056 CET | 49930 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:28.703573942 CET | 49930 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:28.823539019 CET | 14646 | 49930 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:37:29.711756945 CET | 49959 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:29.831669092 CET | 14646 | 49959 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:37:29.832391977 CET | 49959 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:29.836122990 CET | 49959 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:29.955833912 CET | 14646 | 49959 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:37:40.238059998 CET | 14646 | 49959 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:37:40.238135099 CET | 49959 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:40.238178015 CET | 49959 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:40.358269930 CET | 14646 | 49959 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:37:41.243082047 CET | 49986 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:41.362853050 CET | 14646 | 49986 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:37:41.362977028 CET | 49986 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:41.366837978 CET | 49986 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:41.486624002 CET | 14646 | 49986 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:37:51.699698925 CET | 14646 | 49986 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:37:51.699789047 CET | 49986 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:51.699908972 CET | 49986 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:51.819612026 CET | 14646 | 49986 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:37:52.712044001 CET | 50013 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:52.831929922 CET | 14646 | 50013 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:37:52.832027912 CET | 50013 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:52.835532904 CET | 50013 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:37:52.955415964 CET | 14646 | 50013 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:38:03.225106955 CET | 14646 | 50013 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:38:03.227366924 CET | 50013 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:03.227366924 CET | 50013 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:03.348191023 CET | 14646 | 50013 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:38:04.243444920 CET | 50018 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:04.363281012 CET | 14646 | 50018 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:38:04.363363028 CET | 50018 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:04.368105888 CET | 50018 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:04.488177061 CET | 14646 | 50018 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:38:14.715523958 CET | 14646 | 50018 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:38:14.717369080 CET | 50018 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:14.717426062 CET | 50018 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:14.837532043 CET | 14646 | 50018 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:38:15.727456093 CET | 50019 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:15.847266912 CET | 14646 | 50019 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:38:15.847372055 CET | 50019 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:15.851722002 CET | 50019 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:15.971554995 CET | 14646 | 50019 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:38:26.200761080 CET | 14646 | 50019 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:38:26.201373100 CET | 50019 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:26.201436996 CET | 50019 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:26.323872089 CET | 14646 | 50019 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:38:28.057590008 CET | 50020 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:28.177654982 CET | 14646 | 50020 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:38:28.177759886 CET | 50020 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:28.182014942 CET | 50020 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:28.301817894 CET | 14646 | 50020 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:38:38.525048971 CET | 14646 | 50020 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:38:38.525518894 CET | 50020 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:38.525518894 CET | 50020 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:38.645359039 CET | 14646 | 50020 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:38:39.540003061 CET | 50021 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:39.659912109 CET | 14646 | 50021 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:38:39.659986019 CET | 50021 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:39.664271116 CET | 50021 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:39.784291983 CET | 14646 | 50021 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:38:50.011595964 CET | 14646 | 50021 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:38:50.017441034 CET | 50021 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:50.017482042 CET | 50021 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:50.137507915 CET | 14646 | 50021 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:38:51.024811029 CET | 50022 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:51.144778967 CET | 14646 | 50022 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:38:51.144860983 CET | 50022 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:51.150491953 CET | 50022 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:38:51.270299911 CET | 14646 | 50022 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:39:01.455451012 CET | 14646 | 50022 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:39:01.461560965 CET | 50022 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:39:01.461561918 CET | 50022 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:39:01.581563950 CET | 14646 | 50022 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:39:02.477582932 CET | 50023 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:39:02.597795010 CET | 14646 | 50023 | 192.169.69.26 | 192.168.2.4 |
Dec 16, 2024 23:39:02.597899914 CET | 50023 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:39:02.601207972 CET | 50023 | 14646 | 192.168.2.4 | 192.169.69.26 |
Dec 16, 2024 23:39:02.721370935 CET | 14646 | 50023 | 192.169.69.26 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 16, 2024 23:34:59.728050947 CET | 63934 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 16, 2024 23:35:00.066431999 CET | 53 | 63934 | 1.1.1.1 | 192.168.2.4 |
Dec 16, 2024 23:36:08.837424994 CET | 62312 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 16, 2024 23:36:09.144421101 CET | 53 | 62312 | 1.1.1.1 | 192.168.2.4 |
Dec 16, 2024 23:37:17.940093994 CET | 54509 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 16, 2024 23:37:18.253760099 CET | 53 | 54509 | 1.1.1.1 | 192.168.2.4 |
Dec 16, 2024 23:38:27.211405993 CET | 55347 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 16, 2024 23:38:28.055337906 CET | 53 | 55347 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 16, 2024 23:34:59.728050947 CET | 192.168.2.4 | 1.1.1.1 | 0x5cd0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 16, 2024 23:36:08.837424994 CET | 192.168.2.4 | 1.1.1.1 | 0x1549 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 16, 2024 23:37:17.940093994 CET | 192.168.2.4 | 1.1.1.1 | 0xc373 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 16, 2024 23:38:27.211405993 CET | 192.168.2.4 | 1.1.1.1 | 0xd36 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 16, 2024 23:35:00.066431999 CET | 1.1.1.1 | 192.168.2.4 | 0x5cd0 | No error (0) | 192.169.69.26 | A (IP address) | IN (0x0001) | false | ||
Dec 16, 2024 23:36:09.144421101 CET | 1.1.1.1 | 192.168.2.4 | 0x1549 | No error (0) | 192.169.69.26 | A (IP address) | IN (0x0001) | false | ||
Dec 16, 2024 23:37:18.253760099 CET | 1.1.1.1 | 192.168.2.4 | 0xc373 | No error (0) | 192.169.69.26 | A (IP address) | IN (0x0001) | false | ||
Dec 16, 2024 23:38:28.055337906 CET | 1.1.1.1 | 192.168.2.4 | 0xd36 | No error (0) | 192.169.69.26 | A (IP address) | IN (0x0001) | false |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Target ID: | 0 |
Start time: | 17:34:58 |
Start date: | 16/12/2024 |
Path: | C:\Users\user\Desktop\1734388385543fca13ccf5614dc71c1922a5cd8cddeb80fc9e4bce55f618d2232c3744cd06117.dat-decoded.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 493'056 bytes |
MD5 hash: | F14E833C2B69A9637A7C7D7AF31AADEA |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 3% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 27.9% |
Total number of Nodes: | 1006 |
Total number of Limit Nodes: | 54 |
Graph
Function 0041BCF3 Relevance: 115.6, APIs: 40, Strings: 26, Instructions: 140libraryloaderCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040E54F Relevance: 10.6, APIs: 2, Strings: 4, Instructions: 88sleepCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00404915 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 60timethreadCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041A7B2 Relevance: 3.0, APIs: 2, Instructions: 40COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00426107 Relevance: 1.5, APIs: 1, Instructions: 7networkCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00413FD4 Relevance: 53.3, APIs: 5, Strings: 25, Instructions: 813sleepnetworkCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040428C Relevance: 19.4, APIs: 4, Strings: 7, Instructions: 147networkCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004047EB Relevance: 18.1, APIs: 12, Instructions: 66synchronizationCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004126D2 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 37registryCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004127D5 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 31registryCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040BED7 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 13synchronizationCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0044B9CE Relevance: 3.0, APIs: 2, Instructions: 44memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004041F1 Relevance: 3.0, APIs: 2, Instructions: 40networkCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00413F9A Relevance: 3.0, APIs: 2, Instructions: 21networkCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00446B0F Relevance: 1.5, APIs: 1, Instructions: 32memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00404262 Relevance: 1.5, APIs: 1, Instructions: 15networkCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0042611E Relevance: 1.5, APIs: 1, Instructions: 7networkCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00406F06 Relevance: 48.1, APIs: 10, Strings: 17, Instructions: 849filesleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00405042 Relevance: 40.5, APIs: 15, Strings: 8, Instructions: 280pipesleepfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00410F36 Relevance: 35.2, APIs: 7, Strings: 13, Instructions: 238threadCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040B335 Relevance: 24.6, APIs: 8, Strings: 6, Instructions: 145fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040B53A Relevance: 21.1, APIs: 7, Strings: 5, Instructions: 130fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040E219 Relevance: 19.5, APIs: 6, Strings: 5, Instructions: 212processCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004159C6 Relevance: 18.1, APIs: 12, Instructions: 80clipboardmemoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041B43F Relevance: 17.6, APIs: 9, Strings: 1, Instructions: 105fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00409B10 Relevance: 15.9, APIs: 8, Strings: 1, Instructions: 108keyboardthreadCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004099E4 Relevance: 12.3, APIs: 6, Strings: 1, Instructions: 65windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00412F45 Relevance: 10.9, APIs: 4, Strings: 2, Instructions: 391registrylibraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040B21B Relevance: 10.5, APIs: 2, Strings: 4, Instructions: 48fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00452F10 Relevance: 10.1, APIs: 1, Strings: 4, Instructions: 1381COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004089A9 Relevance: 9.3, APIs: 6, Instructions: 288fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00419BD4 Relevance: 9.0, APIs: 6, Instructions: 39serviceCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00418C79 Relevance: 9.0, APIs: 2, Strings: 3, Instructions: 245fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004158B9 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 97libraryloadershutdownCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004513C7 Relevance: 7.7, APIs: 5, Instructions: 188COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00407A8C Relevance: 7.7, APIs: 5, Instructions: 183fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00406128 Relevance: 7.2, APIs: 2, Strings: 2, Instructions: 222filenetworkCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00450A8F Relevance: 6.2, APIs: 4, Instructions: 236COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00408DA7 Relevance: 6.2, APIs: 4, Instructions: 206fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00448067 Relevance: 6.1, APIs: 4, Instructions: 90timeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00450E7A Relevance: 4.7, APIs: 3, Instructions: 205COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041ACD1 Relevance: 4.5, APIs: 3, Instructions: 19nativeCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041ACFD Relevance: 4.5, APIs: 3, Instructions: 19nativeCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00432A59 Relevance: 1.8, Strings: 1, Instructions: 500COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004510CA Relevance: 1.6, APIs: 1, Instructions: 83COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00450D52 Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004512FA Relevance: 1.5, APIs: 1, Instructions: 46COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00450DED Relevance: 1.5, APIs: 1, Instructions: 42COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004470BE Relevance: 1.5, APIs: 1, Instructions: 34COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00450D07 Relevance: 1.5, APIs: 1, Instructions: 31COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040E679 Relevance: 1.5, APIs: 1, Instructions: 19COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00433CE7 Relevance: 1.5, APIs: 1, Instructions: 3COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00426E83 Relevance: 1.3, Strings: 1, Instructions: 96COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0044E93E Relevance: 1.3, APIs: 1, Instructions: 5memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0044C749 Relevance: .6, Instructions: 637COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041E5EF Relevance: .6, Instructions: 606COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004267DB Relevance: .4, Instructions: 437COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00426264 Relevance: .4, Instructions: 377COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00431387 Relevance: .4, Instructions: 371COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041D081 Relevance: .3, Instructions: 276COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00436A9D Relevance: .3, Instructions: 254COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00436D58 Relevance: .2, Instructions: 244COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004367D6 Relevance: .2, Instructions: 240COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0043D0A8 Relevance: .2, Instructions: 237COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0043CE4B Relevance: .2, Instructions: 237COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0043652C Relevance: .2, Instructions: 232COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0043C9ED Relevance: .2, Instructions: 214COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00426FBD Relevance: .2, Instructions: 186COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00437160 Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00417FAF Relevance: 52.8, APIs: 29, Strings: 1, Instructions: 324windowmemoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00417245 Relevance: 47.5, APIs: 22, Strings: 5, Instructions: 290libraryloaderthreadCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004112B5 Relevance: 43.9, APIs: 17, Strings: 8, Instructions: 189synchronizationsleepfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040BF04 Relevance: 42.3, APIs: 6, Strings: 18, Instructions: 260registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041A1CB Relevance: 42.2, APIs: 12, Strings: 12, Instructions: 180synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401BE8 Relevance: 35.2, APIs: 16, Strings: 4, Instructions: 156fileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004064E0 Relevance: 35.1, APIs: 12, Strings: 8, Instructions: 62libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040BC67 Relevance: 30.0, APIs: 12, Strings: 5, Instructions: 203fileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041B1CB Relevance: 28.1, APIs: 15, Strings: 1, Instructions: 139stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00411C81 Relevance: 25.0, APIs: 9, Strings: 5, Instructions: 479sleepfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040A3F4 Relevance: 22.9, APIs: 6, Strings: 7, Instructions: 158sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041CAAE Relevance: 22.8, APIs: 12, Strings: 1, Instructions: 73windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00444F4D Relevance: 22.8, APIs: 15, Instructions: 296COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00407DEF Relevance: 21.3, APIs: 8, Strings: 4, Instructions: 325fileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00409E48 Relevance: 21.2, APIs: 6, Strings: 6, Instructions: 163sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00413E37 Relevance: 21.1, APIs: 9, Strings: 3, Instructions: 109libraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00419138 Relevance: 19.4, APIs: 6, Strings: 5, Instructions: 174sleeptimeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0044F3F1 Relevance: 18.4, APIs: 12, Instructions: 376COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00454992 Relevance: 17.8, APIs: 9, Strings: 1, Instructions: 272COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00416E27 Relevance: 17.6, APIs: 4, Strings: 6, Instructions: 107filesynchronizationCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00404E52 Relevance: 15.9, APIs: 6, Strings: 3, Instructions: 155windowmemoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00446DDB Relevance: 15.1, APIs: 10, Instructions: 54COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004165FC Relevance: 14.1, APIs: 3, Strings: 5, Instructions: 103sleepfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041C97F Relevance: 14.0, APIs: 7, Strings: 1, Instructions: 47windowstringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00452B3A Relevance: 13.8, APIs: 9, Instructions: 268COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00444409 Relevance: 12.5, APIs: 6, Strings: 1, Instructions: 266COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00412C88 Relevance: 12.4, APIs: 2, Strings: 5, Instructions: 135registryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00406BE9 Relevance: 12.3, APIs: 6, Strings: 1, Instructions: 97fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041BEC0 Relevance: 12.3, APIs: 4, Strings: 3, Instructions: 47memoryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00446169 Relevance: 10.9, APIs: 3, Strings: 3, Instructions: 389COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0044F816 Relevance: 10.7, APIs: 7, Instructions: 204COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00443F8B Relevance: 10.7, APIs: 5, Strings: 1, Instructions: 187COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0044A0D3 Relevance: 10.7, APIs: 7, Instructions: 152fileCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401768 Relevance: 10.6, APIs: 3, Strings: 3, Instructions: 142threadCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040E6A3 Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 132processCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041A52B Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 68networkfileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040B2A8 Relevance: 10.5, APIs: 2, Strings: 4, Instructions: 48fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0043960C Relevance: 9.3, APIs: 6, Instructions: 284COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00403DE7 Relevance: 9.1, APIs: 1, Strings: 5, Instructions: 135sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00419DFC Relevance: 9.1, APIs: 6, Instructions: 66serviceCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00419C30 Relevance: 9.0, APIs: 6, Instructions: 44serviceCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00419D32 Relevance: 9.0, APIs: 6, Instructions: 44serviceCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00419D97 Relevance: 9.0, APIs: 6, Instructions: 44serviceCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004129AA Relevance: 8.9, APIs: 3, Strings: 2, Instructions: 173registryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004559DA Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 152COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0044AA83 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 61COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00409D97 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 58sleepfileCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041CA2F Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 54registryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004069BA Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 42processCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004425E9 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 38libraryloaderCOMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00404AB1 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 35synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00419F42 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 30sleepCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00410B19 Relevance: 7.7, APIs: 5, Instructions: 198memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0044E14B Relevance: 7.6, APIs: 5, Instructions: 68COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041B38D Relevance: 7.5, APIs: 5, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00416751 Relevance: 7.2, APIs: 3, Strings: 1, Instructions: 182threadwindowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00403A10 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 92sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004098A5 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 70threadCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040A611 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 64threadCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00404B29 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 47synchronizationCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00412774 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 38registryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040AFBA Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 20threadCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00441A91 Relevance: 6.1, APIs: 4, Instructions: 133COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00404688 Relevance: 6.1, APIs: 4, Instructions: 121synchronizationthreadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040B806 Relevance: 6.1, APIs: 2, Strings: 2, Instructions: 103sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00411524 Relevance: 6.1, APIs: 1, Strings: 3, Instructions: 93sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00409C4B Relevance: 6.1, APIs: 2, Strings: 2, Instructions: 71sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041B59F Relevance: 6.1, APIs: 4, Instructions: 64fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00442D61 Relevance: 6.1, APIs: 4, Instructions: 59COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00447220 Relevance: 6.1, APIs: 4, Instructions: 52libraryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041B62A Relevance: 6.0, APIs: 4, Instructions: 50fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041851C Relevance: 6.0, APIs: 4, Instructions: 49COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004125EE Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 51registryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0044DDF7 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 45COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040AD56 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 32keyboardCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040ADB0 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 24keyboardCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041297A Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 23registryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00411699 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 13synchronizationCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|