Windows
Analysis Report
SHROsQyiAd.exe
Overview
General Information
Sample name: | SHROsQyiAd.exerenamed because original name is a hash value |
Original sample name: | 7119698425e2056d404e97b12ed5ca37.exe |
Analysis ID: | 1578616 |
MD5: | 7119698425e2056d404e97b12ed5ca37 |
SHA1: | 47ebc0744e88fbe12876471b49f4df80195f428a |
SHA256: | f3646ac33546540137231400c43e90525e2bc6fad1ba2c27cb56466c65bd58b3 |
Tags: | exeRATRemcosRATuser-abuse_ch |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- SHROsQyiAd.exe (PID: 2308 cmdline:
"C:\Users\ user\Deskt op\SHROsQy iAd.exe" MD5: 7119698425E2056D404E97B12ED5CA37) - SHROsQyiAd.exe (PID: 3472 cmdline:
"C:\Users\ user\Deskt op\SHROsQy iAd.exe" MD5: 7119698425E2056D404E97B12ED5CA37)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Remcos, RemcosRAT | Remcos (acronym of Remote Control & Surveillance Software) is a commercial Remote Access Tool to remotely control computers.Remcos is advertised as legitimate software which can be used for surveillance and penetration testing purposes, but has been used in numerous hacking campaigns.Remcos, once installed, opens a backdoor on the computer, granting full access to the remote user.Remcos is developed by the cybersecurity company BreakingSecurity. |
{"Host:Port:Password": ["newstaticfreepoint24.ddns-ip.net:3020:0"], "Assigned name": "ROSAS", "Connect interval": "1", "Install flag": "Disable", "Setup HKCU\\Run": "Enable", "Setup HKLM\\Run": "Enable", "Install path": "Application path", "Copy file": "remcos.exe", "Startup value": "Enable", "Hide file": "Disable", "Mutex": "kljjbdlcjbavhbiluiewliuwqerlib-DDZVN3", "Keylog flag": "1", "Keylog path": "Application path", "Keylog file": "registros.dat", "Keylog crypt": "Disable", "Hide keylog file": "Disable", "Screenshot flag": "Disable", "Screenshot time": "1", "Take Screenshot option": "Disable", "Take screenshot title": "", "Take screenshot time": "5", "Screenshot path": "AppData", "Screenshot file": "Capturas de pantalla", "Screenshot crypt": "Disable", "Mouse option": "Disable", "Delete file": "Disable", "Audio record time": "5", "Audio folder": "MicRecords", "Connect delay": "0", "Copy folder": "Remcos", "Keylog folder": "data", "Keylog file max size": ""}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Keylogger_Generic | Yara detected Keylogger Generic | Joe Security | ||
JoeSecurity_Remcos | Yara detected Remcos RAT | Joe Security | ||
JoeSecurity_UACBypassusingCMSTP | Yara detected UAC Bypass using CMSTP | Joe Security | ||
Windows_Trojan_Remcos_b296e965 | unknown | unknown |
| |
REMCOS_RAT_variants | unknown | unknown |
| |
Click to see the 21 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Keylogger_Generic | Yara detected Keylogger Generic | Joe Security | ||
JoeSecurity_Remcos | Yara detected Remcos RAT | Joe Security | ||
JoeSecurity_UACBypassusingCMSTP | Yara detected UAC Bypass using CMSTP | Joe Security | ||
Windows_Trojan_Remcos_b296e965 | unknown | unknown |
| |
REMCOS_RAT_variants | unknown | unknown |
| |
Click to see the 31 entries |
System Summary |
---|
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-19T23:42:33.005441+0100 | 2032776 | 1 | Malware Command and Control Activity Detected | 192.168.2.6 | 49773 | 181.131.217.244 | 3020 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-19T23:42:34.257170+0100 | 2032777 | 1 | Malware Command and Control Activity Detected | 181.131.217.244 | 3020 | 192.168.2.6 | 49773 | TCP |
2024-12-19T23:44:52.538251+0100 | 2032777 | 1 | Malware Command and Control Activity Detected | 181.131.217.244 | 3020 | 192.168.2.6 | 49773 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-19T23:42:36.056369+0100 | 2803304 | 3 | Unknown Traffic | 192.168.2.6 | 49780 | 178.237.33.50 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Integrated Neural Analysis Model: |
Source: | Code function: | 6_2_00CA293A |
Source: | Binary or memory string: | memstr_e7140f15-5 |
Exploits |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Privilege Escalation |
---|
Source: | Code function: | 6_2_00C76764 |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: |
Source: | Code function: | 6_2_00C7B335 | |
Source: | Code function: | 6_2_00C8B42F | |
Source: | Code function: | 6_2_00CBD5E9 | |
Source: | Code function: | 6_2_00C7B53A | |
Source: | Code function: | 6_2_00C789A9 | |
Source: | Code function: | 6_2_00C76AC2 | |
Source: | Code function: | 6_2_00C77A8C | |
Source: | Code function: | 6_2_00C88C69 | |
Source: | Code function: | 6_2_00C78DA7 |
Source: | Code function: | 6_2_00C76F06 |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | URLs: |
Source: | TCP traffic: |
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | Suricata IDS: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | Code function: | 6_2_00C7455B |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | Code function: | 6_2_00C799E4 |
Source: | Windows user hook set: | Jump to behavior |
Source: | Code function: | 6_2_00C859C6 |
Source: | Code function: | 6_2_00C859C6 |
Source: | Code function: | 6_2_00C859C6 |
Source: | Code function: | 6_2_00C79B10 |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
E-Banking Fraud |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | Code function: | 6_2_00C8BB77 |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | File dump: | Jump to dropped file |
Source: | Process Stats: |
Source: | Code function: | 6_2_00C858B9 |
Source: | Code function: | 6_2_00CC20D2 | |
Source: | Code function: | 6_2_00CAD098 | |
Source: | Code function: | 6_2_00C8D071 | |
Source: | Code function: | 6_2_00CA61AA | |
Source: | Code function: | 6_2_00CA7150 | |
Source: | Code function: | 6_2_00C96254 | |
Source: | Code function: | 6_2_00CA1377 | |
Source: | Code function: | 6_2_00C8E5DF | |
Source: | Code function: | 6_2_00C967CB | |
Source: | Code function: | 6_2_00CBC739 | |
Source: | Code function: | 6_2_00CAC9DD | |
Source: | Code function: | 6_2_00CA2A49 | |
Source: | Code function: | 6_2_00CACC0C | |
Source: | Code function: | 6_2_00CA4D22 | |
Source: | Code function: | 6_2_00C96E73 | |
Source: | Code function: | 6_2_00CB0E20 | |
Source: | Code function: | 6_2_00CACE3B | |
Source: | Code function: | 6_2_00C96FAD | |
Source: | Code function: | 6_2_00C82F45 | |
Source: | Code function: | 6_2_00CC2F00 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | Code function: | 6_2_00C86AB7 |
Source: | Code function: | 6_2_00C7E219 |
Source: | Code function: | 6_2_00C8A63F |
Source: | Code function: | 6_2_00C89BC4 |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: |
Source: | Code function: | 6_2_00C8BCE3 |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 6_2_00CC67FE | |
Source: | Code function: | 6_2_00CCB9E6 | |
Source: | Code function: | 6_2_00CC5EC2 | |
Source: | Code function: | 6_2_00CA4009 |
Source: | Code function: | 6_2_00C76128 |
Source: | File created: | Jump to dropped file |
Source: | Code function: | 6_2_00C89BC4 |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Source: | Code function: | 6_2_00C8BCE3 |
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Code function: | 6_2_00C7E54F |
Source: | Code function: | 6_2_00C898C2 |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Dropped PE file which has not been started: | Jump to dropped file |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Code function: | 6_2_00C7B335 | |
Source: | Code function: | 6_2_00C8B42F | |
Source: | Code function: | 6_2_00CBD5E9 | |
Source: | Code function: | 6_2_00C7B53A | |
Source: | Code function: | 6_2_00C789A9 | |
Source: | Code function: | 6_2_00C76AC2 | |
Source: | Code function: | 6_2_00C77A8C | |
Source: | Code function: | 6_2_00C88C69 | |
Source: | Code function: | 6_2_00C78DA7 |
Source: | Code function: | 6_2_00C76F06 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | API call chain: | graph_6-47610 |
Source: | Code function: | 6_2_00CAA65D |
Source: | Code function: | 6_2_00C8BCE3 |
Source: | Code function: | 6_2_00CB2554 |
Source: | Code function: | 6_2_00CBE92E |
Source: | Process created: | Jump to behavior |
Source: | Code function: | 6_2_00CA4168 | |
Source: | Code function: | 6_2_00CAA65D | |
Source: | Code function: | 6_2_00CA3B44 | |
Source: | Code function: | 6_2_00CA3CD7 |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Memory written: | Jump to behavior |
Source: | Code function: | 6_2_00C80F36 |
Source: | Code function: | 6_2_00C88754 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 6_2_00CA3E0A |
Source: | Code function: | 6_2_00C7E679 | |
Source: | Code function: | 6_2_00CB70AE | |
Source: | Code function: | 6_2_00CC10BA | |
Source: | Code function: | 6_2_00CC11E3 | |
Source: | Code function: | 6_2_00CC12EA | |
Source: | Code function: | 6_2_00CC13B7 | |
Source: | Code function: | 6_2_00CB7597 | |
Source: | Code function: | 6_2_00CC0A7F | |
Source: | Code function: | 6_2_00CC0CF7 | |
Source: | Code function: | 6_2_00CC0DDD | |
Source: | Code function: | 6_2_00CC0D42 | |
Source: | Code function: | 6_2_00CC0E6A |
Source: | Code function: | 2_2_00644383 |
Source: | Code function: | 6_2_00C8A7A2 |
Source: | Code function: | 6_2_00CB800F |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Code function: | 6_2_00C7B21B |
Source: | Code function: | 6_2_00C7B335 | |
Source: | Code function: | 6_2_00C7B335 |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Code function: | 6_2_00C75042 |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Disable or Modify Tools | 1 OS Credential Dumping | 2 System Time Discovery | Remote Services | 11 Archive Collected Data | 12 Ingress Tool Transfer | Exfiltration Over Other Network Medium | 1 System Shutdown/Reboot |
Credentials | Domains | Default Accounts | 12 Command and Scripting Interpreter | 1 Windows Service | 1 Bypass User Account Control | 1 Deobfuscate/Decode Files or Information | 211 Input Capture | 1 Account Discovery | Remote Desktop Protocol | 211 Input Capture | 2 Encrypted Channel | Exfiltration Over Bluetooth | 1 Defacement |
Email Addresses | DNS Server | Domain Accounts | 2 Service Execution | 1 Registry Run Keys / Startup Folder | 1 Access Token Manipulation | 2 Obfuscated Files or Information | 2 Credentials In Files | 1 System Service Discovery | SMB/Windows Admin Shares | 3 Clipboard Data | 1 Non-Standard Port | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 1 Windows Service | 1 DLL Side-Loading | NTDS | 2 File and Directory Discovery | Distributed Component Object Model | Input Capture | 2 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | 112 Process Injection | 1 Bypass User Account Control | LSA Secrets | 22 System Information Discovery | SSH | Keylogging | 12 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | 1 Registry Run Keys / Startup Folder | 1 Masquerading | Cached Domain Credentials | 21 Security Software Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 Virtualization/Sandbox Evasion | DCSync | 1 Virtualization/Sandbox Evasion | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 Access Token Manipulation | Proc Filesystem | 2 Process Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | 112 Process Injection | /etc/passwd and /etc/shadow | 1 Application Window Discovery | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
IP Addresses | Compromise Infrastructure | Supply Chain Compromise | PowerShell | Cron | Cron | Dynamic API Resolution | Network Sniffing | 1 System Owner/User Discovery | Shared Webroot | Local Data Staging | File Transfer Protocols | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol | External Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
11% | ReversingLabs |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
geoplugin.net | 178.237.33.50 | true | false | high | |
newstaticfreepoint24.ddns-ip.net | 181.131.217.244 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
true | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | high | |||
false | high | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | high | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | high | |||
false | unknown | |||
false | unknown | |||
false | high | |||
false | unknown | |||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
181.131.217.244 | newstaticfreepoint24.ddns-ip.net | Colombia | 13489 | EPMTelecomunicacionesSAESPCO | false | |
178.237.33.50 | geoplugin.net | Netherlands | 8455 | ATOM86-ASATOM86NL | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1578616 |
Start date and time: | 2024-12-19 23:41:14 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 10m 1s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 13 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | SHROsQyiAd.exerenamed because original name is a hash value |
Original Sample Name: | 7119698425e2056d404e97b12ed5ca37.exe |
Detection: | MAL |
Classification: | mal100.rans.troj.spyw.expl.evad.winEXE@3/3@2/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, BackgroundTransferHost.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 40.126.53.21, 13.107.246.63, 20.223.36.55, 2.16.158.192, 4.175.87.197, 150.171.27.10, 92.122.16.236, 23.218.208.109
- Excluded domains from analysis (whitelisted): www.bing.com, client.wns.windows.com, fs.microsoft.com, otelrules.azureedge.net, slscr.update.microsoft.com, login.live.com, tse1.mm.bing.net, ctldl.windowsupdate.com, g.bing.com, arc.msn.com, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target SHROsQyiAd.exe, PID 2308 because there are no executed function
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: SHROsQyiAd.exe
Time | Type | Description |
---|---|---|
17:43:04 | API Interceptor | |
23:42:40 | Autostart | |
23:42:48 | Autostart |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
181.131.217.244 | Get hash | malicious | Remcos | Browse | ||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | Remcos | Browse | |||
178.237.33.50 | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos, DBatLoader | Browse |
| ||
Get hash | malicious | Cobalt Strike, Remcos, DBatLoader | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos, GuLoader | Browse |
| ||
Get hash | malicious | Remcos, GuLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
newstaticfreepoint24.ddns-ip.net | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
geoplugin.net | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos, DBatLoader | Browse |
| ||
Get hash | malicious | Cobalt Strike, Remcos, DBatLoader | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos, GuLoader | Browse |
| ||
Get hash | malicious | Remcos, GuLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
EPMTelecomunicacionesSAESPCO | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
ATOM86-ASATOM86NL | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos, DBatLoader | Browse |
| ||
Get hash | malicious | Cobalt Strike, Remcos, DBatLoader | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos, GuLoader | Browse |
| ||
Get hash | malicious | Remcos, GuLoader | Browse |
|
Process: | C:\Users\user\Desktop\SHROsQyiAd.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 488 |
Entropy (8bit): | 3.3388163144619414 |
Encrypted: | false |
SSDEEP: | 12:6lJGkKecmlJGlfIbWFe5UlJGGlJGSbWFe5UlJGelJGRqbW+:6jGkTcmjG+WqUjGGjG2WqUjGejG4W+ |
MD5: | 87C1EF97411850B115A267CAB2B9E743 |
SHA1: | 5923EB59F4A1A6719BCDD0DC5CD6D893DB8478A2 |
SHA-256: | C59A93D2D4A70B209154C00EA59861702B6384320AF50B3940A76D3BB5FD389D |
SHA-512: | 3C0A7B88B0B653FB83BE94077DE9E4FC77734A79A978150D71E9A83BF17A874AF5F466D2058376211604FA49E98010D3F1F68F80BA38145DB0A51A56AF6FC1A0 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\SHROsQyiAd.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 963 |
Entropy (8bit): | 5.018384957371898 |
Encrypted: | false |
SSDEEP: | 12:tkluWJmnd6CsGkMyGWKyGXPVGArwY307f7aZHI7GZArpv/mOAaNO+ao9W7iN5zz2:qlupdRNuKyGX85jvXhNlT3/7CcVKWro |
MD5: | C9BB4D5FD5C8A01D20EBF8334B62AE54 |
SHA1: | D38895F4CBB44CB10B6512A19034F14A2FC40359 |
SHA-256: | 767218EC255B7E851971A77B773C0ECC59DC0B179ECA46ABCC29047EEE6216AA |
SHA-512: | 2D412433053610C0229FB3B73A26C8FB684F0A4AB03A53D0533FDC52D4E9882C25037015ACE7D4A411214AA9FAA780A8D950A83B57B200A877E26D7890977157 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\SHROsQyiAd.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 959567331 |
Entropy (8bit): | 0.11874123808649341 |
Encrypted: | false |
SSDEEP: | |
MD5: | D66446D0DCEFEB7DE2A8C3FE7B6C5201 |
SHA1: | 474DF7663BDB1A203A387F9F23F079B0C1641DD6 |
SHA-256: | 540663033BFCEAA7D93AE6D93A4BC58ABFFF2349D1DC0170B391241119048887 |
SHA-512: | E01C5CA852D8D7365AE00E98EF476C00C4DF2B8EF364029A3F406EE6C5F1DECE08A188F503E255EA161DABF6FB864D605F9B4638191A1864D8417F8B3BF031DE |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 6.38784602956759 |
TrID: |
|
File name: | SHROsQyiAd.exe |
File size: | 8'779'776 bytes |
MD5: | 7119698425e2056d404e97b12ed5ca37 |
SHA1: | 47ebc0744e88fbe12876471b49f4df80195f428a |
SHA256: | f3646ac33546540137231400c43e90525e2bc6fad1ba2c27cb56466c65bd58b3 |
SHA512: | 817eb34af541cd6b7b0a67e8d09668014c3fe9e43cb4df355840a2f7529853a8e34ca6d9af3e9b35137c7e13a6de98874dff50b962dc1d10b4e2a3041a9efede |
SSDEEP: | 98304:Gnbgpe4NdaEMybVR/XfJca1tzZdBTXuOMehkf9O:WUpe4qiJdxcg/ |
TLSH: | BB966A72E102C846D92501BFE829EAFC42196F38CB3795CB56C8FE1E3173AE20575A57 |
File Content Preview: | MZ......................@...................................@...........!..L.!This program cannot be run in DOS mode....$..........,..............h........~...............~.......~.......~............'..~....d..~.......~.......~.......~.......~.......~... |
Icon Hash: | 334de0b2926d330e |
Entrypoint: | 0x643e93 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x67600E9F [Mon Dec 16 11:27:27 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 6 |
OS Version Minor: | 0 |
File Version Major: | 6 |
File Version Minor: | 0 |
Subsystem Version Major: | 6 |
Subsystem Version Minor: | 0 |
Import Hash: | d0efa8288bc8fcf1ae384debe93de6ac |
Instruction |
---|
call 00007FF34487C18Dh |
jmp 00007FF34487BACFh |
push 00000010h |
push 006E65C0h |
call 00007FF34487C0DCh |
xor ebx, ebx |
mov dword ptr [ebp-20h], ebx |
mov byte ptr [ebp-19h], bl |
mov dword ptr [ebp-04h], ebx |
cmp ebx, dword ptr [ebp+14h] |
je 00007FF34487BC73h |
push dword ptr [ebp+0Ch] |
mov ecx, dword ptr [ebp+18h] |
call dword ptr [00675B18h] |
mov ecx, dword ptr [ebp+08h] |
call dword ptr [ebp+18h] |
mov eax, dword ptr [ebp+10h] |
add dword ptr [ebp+08h], eax |
add dword ptr [ebp+0Ch], eax |
inc ebx |
mov dword ptr [ebp-20h], ebx |
jmp 00007FF34487BC2Ch |
mov al, 01h |
mov byte ptr [ebp-19h], al |
mov dword ptr [ebp-04h], FFFFFFFEh |
call 00007FF34487BC6Dh |
mov ecx, dword ptr [ebp-10h] |
mov dword ptr fs:[00000000h], ecx |
pop ecx |
pop edi |
pop esi |
pop ebx |
leave |
retn 0018h |
mov ebx, dword ptr [ebp-20h] |
mov al, byte ptr [ebp-19h] |
test al, al |
jne 00007FF34487BC61h |
push dword ptr [ebp+1Ch] |
push ebx |
push dword ptr [ebp+10h] |
push dword ptr [ebp+08h] |
call 00007FF34487B6C4h |
ret |
push ebp |
mov ebp, esp |
sub esp, 0Ch |
lea ecx, dword ptr [ebp-0Ch] |
call 00007FF344644410h |
push 006E66B4h |
lea eax, dword ptr [ebp-0Ch] |
push eax |
call 00007FF34487C35Bh |
int3 |
push ebp |
mov ebp, esp |
sub esp, 0Ch |
lea ecx, dword ptr [ebp-0Ch] |
call 00007FF344643863h |
push 006E6608h |
lea eax, dword ptr [ebp-0Ch] |
push eax |
call 00007FF34487C33Eh |
int3 |
push ebp |
mov ebp, esp |
and dword ptr [00701C04h], 00000000h |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x2e826c | 0x294 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x32e000 | 0x53d400 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x350000 | 0x2c140 | .rsrc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x2a823c | 0x70 | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x2a82c0 | 0x18 | .rdata |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x276d30 | 0x40 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x275000 | 0xb18 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x2e8128 | 0x40 | .rdata |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x274000 | 0x273200 | 4bedbb2e9551e79fae7694bacea5282c | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x275000 | 0x78000 | 0x77600 | 2a4704a587240261914c1de80110ddb1 | False | 0.3565792702879581 | data | 5.125253402867627 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x2ed000 | 0x1e000 | 0x14c00 | 0b15f16cdaeb2ade44ddb62497a9e5fb | False | 0.22939806099397592 | DOS executable (block device driver @\273\) | 5.393205596281875 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
_RDATA | 0x30b000 | 0x23000 | 0x22c00 | 241f50e9d164772437fd3eebd88a3edb | False | 0.16984459307553956 | data | 5.38723924085817 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.rsrc | 0x32e000 | 0x53d400 | 0x53d400 | 61b74e85afa3a3cabfd1c9e29fae61de | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
AFX_DIALOG_LAYOUT | 0x32faf8 | 0x2 | data | English | United States | 5.0 |
AFX_DIALOG_LAYOUT | 0x32fafc | 0x2 | data | English | United States | 5.0 |
AFX_DIALOG_LAYOUT | 0x32fb00 | 0x2 | data | English | United States | 5.0 |
AFX_DIALOG_LAYOUT | 0x32fb04 | 0x2 | data | English | United States | 5.0 |
AFX_DIALOG_LAYOUT | 0x32fb08 | 0x2 | data | English | United States | 5.0 |
AFX_DIALOG_LAYOUT | 0x32fb0c | 0x2 | data | English | United States | 5.0 |
AFX_DIALOG_LAYOUT | 0x32fb10 | 0x2 | data | English | United States | 5.0 |
AFX_DIALOG_LAYOUT | 0x32fb14 | 0x2 | data | English | United States | 5.0 |
AFX_DIALOG_LAYOUT | 0x32fb18 | 0x2 | data | English | United States | 5.0 |
AFX_DIALOG_LAYOUT | 0x32fb1c | 0x2 | data | English | United States | 5.0 |
AFX_DIALOG_LAYOUT | 0x32fb20 | 0x2 | data | English | United States | 5.0 |
AFX_DIALOG_LAYOUT | 0x32fb24 | 0x2 | data | English | United States | 5.0 |
AFX_DIALOG_LAYOUT | 0x32fb28 | 0x2 | data | English | United States | 5.0 |
AFX_DIALOG_LAYOUT | 0x32fb2c | 0x2 | data | English | United States | 5.0 |
AFX_DIALOG_LAYOUT | 0x32fb30 | 0x2 | data | English | United States | 5.0 |
AFX_DIALOG_LAYOUT | 0x32fb34 | 0x2 | data | English | United States | 5.0 |
AFX_DIALOG_LAYOUT | 0x32fb38 | 0x2 | data | English | United States | 5.0 |
AFX_DIALOG_LAYOUT | 0x32fb3c | 0x2 | data | English | United States | 5.0 |
AFX_DIALOG_LAYOUT | 0x32fb40 | 0x2 | data | English | United States | 5.0 |
AFX_DIALOG_LAYOUT | 0x32fb44 | 0x2 | data | English | United States | 5.0 |
AFX_DIALOG_LAYOUT | 0x32fb48 | 0x2 | data | English | United States | 5.0 |
AFX_DIALOG_LAYOUT | 0x32fb4c | 0x2 | data | English | United States | 5.0 |
AFX_DIALOG_LAYOUT | 0x32fb50 | 0x2 | data | English | United States | 5.0 |
PNG | 0x32fb54 | 0x5366 | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | English | United States | 1.0004215456674472 |
RT_BITMAP | 0x334ebc | 0x72a24 | Device independent bitmap graphic, 500 x 313 x 24, image size 469500, resolution 3780 x 3780 px/m | 0.5298930868509605 | ||
RT_BITMAP | 0x3a78e0 | 0x72a24 | Device independent bitmap graphic, 500 x 313 x 24, image size 469500, resolution 3780 x 3780 px/m | 0.6542041146654172 | ||
RT_BITMAP | 0x41a304 | 0x1d4e8 | Device independent bitmap graphic, 200 x 200 x 24, image size 120000, resolution 3780 x 3780 px/m | 0.651882705764745 | ||
RT_BITMAP | 0x4377ec | 0x1d4e8 | Device independent bitmap graphic, 200 x 200 x 24, image size 120000, resolution 3780 x 3780 px/m | 0.5804481839386871 | ||
RT_BITMAP | 0x454cd4 | 0x27a18 | Device independent bitmap graphic, 966 x 42 x 32, image size 162288, resolution 3582 x 3582 px/m | 0.20433936227884283 | ||
RT_BITMAP | 0x47c6ec | 0x242a | Device independent bitmap graphic, 48 x 48 x 32, image size 9218, resolution 2834 x 2834 px/m | 0.3424065672931519 | ||
RT_BITMAP | 0x47eb18 | 0x242a | Device independent bitmap graphic, 48 x 48 x 32, image size 9218, resolution 2834 x 2834 px/m | 0.3844242817023115 | ||
RT_ICON | 0x480f44 | 0xc5c0 | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | 0.8094974715549936 | ||
RT_ICON | 0x48d504 | 0x145a0 | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | 0.8880158349328215 | ||
RT_ICON | 0x4a1aa4 | 0xcce6 | PC bitmap, Windows 3.x format, 6861 x 2 x 35, image size 53283, cbSize 52454, bits offset 54 | 0.5655812712090593 | ||
RT_ICON | 0x4ae78c | 0x44028 | Device independent bitmap graphic, 256 x 512 x 32, image size 262144 | 0.18652178283219897 | ||
RT_ICON | 0x4f27b4 | 0x94a8 | Device independent bitmap graphic, 96 x 192 x 32, image size 38016 | 0.2241696447340761 | ||
RT_ICON | 0x4fbc5c | 0x10828 | Device independent bitmap graphic, 128 x 256 x 32, image size 67584 | 0.0825742339997634 | ||
RT_ICON | 0x50c484 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4224 | English | United States | 0.33630393996247654 |
RT_ICON | 0x50d52c | 0x1a68 | Device independent bitmap graphic, 40 x 80 x 32, image size 6720 | English | United States | 0.29319526627218934 |
RT_ICON | 0x50ef94 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9600 | English | United States | 0.258298755186722 |
RT_ICON | 0x51153c | 0x4228 | Device independent bitmap graphic, 64 x 128 x 32, image size 16896 | English | United States | 0.20896315540859708 |
RT_ICON | 0x515764 | 0x5cd2 | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | English | United States | 0.9988216480094269 |
RT_ICON | 0x51b438 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1088 | English | United States | 0.5301418439716312 |
RT_ICON | 0x51b8a0 | 0x6b8 | Device independent bitmap graphic, 20 x 40 x 32, image size 1680 | English | United States | 0.4511627906976744 |
RT_ICON | 0x51bf58 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2400 | English | United States | 0.41270491803278686 |
RT_MENU | 0x51c8e0 | 0x31a | data | 0.7506297229219143 | ||
RT_DIALOG | 0x51cbfc | 0x35c | data | English | United States | 0.436046511627907 |
RT_DIALOG | 0x51cf58 | 0x502 | data | English | United States | 0.3962558502340094 |
RT_DIALOG | 0x51d45c | 0x248 | data | English | United States | 0.4828767123287671 |
RT_DIALOG | 0x51d6a4 | 0x2c2 | data | English | United States | 0.4730878186968839 |
RT_DIALOG | 0x51d968 | 0x630 | data | English | United States | 0.4116161616161616 |
RT_DIALOG | 0x51df98 | 0x1e8 | data | English | United States | 0.5368852459016393 |
RT_DIALOG | 0x51e180 | 0x828 | data | English | United States | 0.4051724137931034 |
RT_DIALOG | 0x51e9a8 | 0x36c | data | English | United States | 0.45662100456621 |
RT_DIALOG | 0x51ed14 | 0x188 | data | English | United States | 0.5586734693877551 |
RT_DIALOG | 0x51ee9c | 0x1e8 | data | English | United States | 0.5430327868852459 |
RT_DIALOG | 0x51f084 | 0x4a8 | data | English | United States | 0.42533557046979864 |
RT_DIALOG | 0x51f52c | 0x278 | data | English | United States | 0.44936708860759494 |
RT_DIALOG | 0x51f7a4 | 0xc8 | data | English | United States | 0.675 |
RT_DIALOG | 0x51f86c | 0x634 | data | English | United States | 0.4275818639798489 |
RT_DIALOG | 0x51fea0 | 0x4d2 | data | English | United States | 0.3987034035656402 |
RT_DIALOG | 0x520374 | 0x2b0 | data | English | United States | 0.4738372093023256 |
RT_DIALOG | 0x520624 | 0xd0 | data | English | United States | 0.6586538461538461 |
RT_DIALOG | 0x5206f4 | 0x124 | data | English | United States | 0.589041095890411 |
RT_DIALOG | 0x520818 | 0x30e | data | English | United States | 0.4322250639386189 |
RT_DIALOG | 0x520b28 | 0x174 | data | English | United States | 0.5698924731182796 |
RT_DIALOG | 0x520c9c | 0x220 | data | English | United States | 0.48713235294117646 |
RT_DIALOG | 0x520ebc | 0x2d2 | data | English | United States | 0.4695290858725762 |
RT_DIALOG | 0x521190 | 0xec | data | English | United States | 0.673728813559322 |
RT_DIALOG | 0x52127c | 0x1e0 | data | English | United States | 0.5229166666666667 |
RT_DIALOG | 0x52145c | 0x1b0 | data | English | United States | 0.5532407407407407 |
RT_DIALOG | 0x52160c | 0x1a4 | data | English | United States | 0.5333333333333333 |
RT_DIALOG | 0x5217b0 | 0x100 | data | English | United States | 0.62890625 |
RT_DIALOG | 0x5218b0 | 0x60 | data | English | United States | 0.7291666666666666 |
RT_DIALOG | 0x521910 | 0x4ac | data | English | United States | 0.3804347826086957 |
RT_DIALOG | 0x521dbc | 0x326 | data | English | United States | 0.4640198511166253 |
RT_DIALOG | 0x5220e4 | 0x1f8 | data | English | United States | 0.5515873015873016 |
RT_DIALOG | 0x5222dc | 0xe0 | data | English | United States | 0.6607142857142857 |
RT_DIALOG | 0x5223bc | 0xe4 | data | English | United States | 0.6798245614035088 |
RT_DIALOG | 0x5224a0 | 0x1c4 | data | English | United States | 0.5575221238938053 |
RT_DIALOG | 0x522664 | 0x104 | data | English | United States | 0.573076923076923 |
RT_DIALOG | 0x522768 | 0xaa | data | English | United States | 0.7411764705882353 |
RT_DIALOG | 0x522814 | 0x1f4 | data | English | United States | 0.492 |
RT_DIALOG | 0x522a08 | 0x12c | data | English | United States | 0.5966666666666667 |
RT_DIALOG | 0x522b34 | 0x7c | data | English | United States | 0.7903225806451613 |
RT_DIALOG | 0x522bb0 | 0x40 | data | English | United States | 0.765625 |
RT_DIALOG | 0x522bf0 | 0x228 | data | English | United States | 0.519927536231884 |
RT_DIALOG | 0x522e18 | 0xa4 | data | English | United States | 0.6829268292682927 |
RT_DIALOG | 0x522ebc | 0xb8 | data | English | United States | 0.6739130434782609 |
RT_DIALOG | 0x522f74 | 0x228 | data | English | United States | 0.5018115942028986 |
RT_DIALOG | 0x52319c | 0xa8 | data | English | United States | 0.6607142857142857 |
RT_DIALOG | 0x523244 | 0x11c | data | English | United States | 0.5845070422535211 |
RT_DIALOG | 0x523360 | 0x1c8 | data | English | United States | 0.4868421052631579 |
RT_DIALOG | 0x523528 | 0x32c | data | English | United States | 0.45689655172413796 |
RT_DIALOG | 0x523854 | 0x90 | data | English | United States | 0.6944444444444444 |
RT_DIALOG | 0x5238e4 | 0xc6 | data | English | United States | 0.6919191919191919 |
RT_DIALOG | 0x5239ac | 0x224 | data | English | United States | 0.5547445255474452 |
RT_DIALOG | 0x523bd0 | 0x224 | data | English | United States | 0.5602189781021898 |
RT_DIALOG | 0x523df4 | 0x120 | data | English | United States | 0.5972222222222222 |
RT_DIALOG | 0x523f14 | 0x5d4 | data | English | United States | 0.4175603217158177 |
RT_DIALOG | 0x5244e8 | 0x17e | data | English | United States | 0.5837696335078534 |
RT_DIALOG | 0x524668 | 0x19e | data | English | United States | 0.5217391304347826 |
RT_DIALOG | 0x524808 | 0x1e0 | data | English | United States | 0.51875 |
RT_DIALOG | 0x5249e8 | 0x3f8 | data | English | United States | 0.43799212598425197 |
RT_DIALOG | 0x524de0 | 0x6e | data | English | United States | 0.7181818181818181 |
RT_DIALOG | 0x524e50 | 0x7c | data | English | United States | 0.7338709677419355 |
RT_DIALOG | 0x524ecc | 0x3e0 | data | English | United States | 0.4254032258064516 |
RT_DIALOG | 0x5252ac | 0x94 | data | English | United States | 0.7905405405405406 |
RT_DIALOG | 0x525340 | 0x246 | data | English | United States | 0.49140893470790376 |
RT_DIALOG | 0x525588 | 0x1e8 | data | English | United States | 0.4959016393442623 |
RT_DIALOG | 0x525770 | 0xfc | data | English | United States | 0.6626984126984127 |
RT_DIALOG | 0x52586c | 0x160 | data | English | United States | 0.6051136363636364 |
RT_DIALOG | 0x5259cc | 0x4ec | data | English | United States | 0.44047619047619047 |
RT_DIALOG | 0x525eb8 | 0x2f0 | data | English | United States | 0.4654255319148936 |
RT_DIALOG | 0x5261a8 | 0x1ac | data | English | United States | 0.5677570093457944 |
RT_DIALOG | 0x526354 | 0x142 | data | English | United States | 0.5869565217391305 |
RT_DIALOG | 0x526498 | 0x1ae | data | English | United States | 0.5511627906976744 |
RT_ACCELERATOR | 0x526648 | 0x20 | data | English | United States | 0.96875 |
RT_ACCELERATOR | 0x526668 | 0x28 | data | English | United States | 0.95 |
RT_RCDATA | 0x526690 | 0x4e550 | Delphi compiled form 'TBaseFrame' | 0.3885578217723034 | ||
RT_RCDATA | 0x574be0 | 0x7cf06 | Delphi compiled form 'TFilePropertiesForm2' | 0.299847581827064 | ||
RT_RCDATA | 0x5f1ae8 | 0xf7ece | Delphi compiled form 'TfPNGMessage' | 0.09640946054266757 | ||
RT_RCDATA | 0x6e99b8 | 0xf7ece | Delphi compiled form 'TfPNGMessage' | 0.16799277598665488 | ||
RT_RCDATA | 0x7e1888 | 0x1b681 | Delphi compiled form 'TMsgBoxForm' | 0.6012988054197066 | ||
RT_MESSAGETABLE | 0x7fcf0c | 0x2840 | data | 0.3316187888198758 | ||
RT_GROUP_ICON | 0x7ff74c | 0x76 | data | English | United States | 0.7457627118644068 |
RT_VERSION | 0x7ff7c4 | 0x30c | data | English | United States | 0.44358974358974357 |
RT_ANIICON | 0x7ffad0 | 0x6b92e | PC bitmap, Windows 3.x format, 55213 x 2 x 37, image size 441441, cbSize 440622, bits offset 54 | 0.7761573412131033 |
DLL | Import |
---|---|
COMCTL32.dll | ImageList_Destroy, ImageList_Create, ImageList_Add |
WINMM.dll | timeGetTime, timeBeginPeriod, timeEndPeriod |
SHLWAPI.dll | SHAutoComplete, StrCmpLogicalW, SHDeleteKeyW |
UxTheme.dll | IsThemePartDefined, OpenThemeData, GetThemePartSize, SetWindowTheme, DrawThemeBackground, EnableThemeDialogTexture, CloseThemeData |
KERNEL32.dll | GetSystemPowerStatus, VerifyVersionInfoW, VerSetConditionMask, GlobalFree, SystemTimeToFileTime, LocalFileTimeToFileTime, ResumeThread, GetLocaleInfoW, GetNumberFormatW, GlobalSize, DecodePointer, Sleep, SetErrorMode, LoadLibraryW, CreateEventW, FindResourceW, FindResourceExW, LoadResource, LockResource, SizeofResource, SetEndOfFile, GetFileTime, FlushFileBuffers, CreateFileW, GetDiskFreeSpaceExW, FindFirstFileW, DeleteFileW, RemoveDirectoryW, GetFileAttributesW, GetStartupInfoW, SetUnhandledExceptionFilter, UnhandledExceptionFilter, WaitForSingleObjectEx, InitializeCriticalSectionAndSpinCount, LoadLibraryExA, GetCurrentThreadId, VirtualAlloc, IsProcessorFeaturePresent, FlushInstructionCache, InterlockedPushEntrySList, InterlockedPopEntrySList, InitializeSListHead, EncodePointer, InitOnceComplete, InitOnceBeginInitialize, SystemTimeToTzSpecificLocalTime, MoveFileExW, NormalizeString, TryEnterCriticalSection, GetVolumeNameForVolumeMountPointW, GetVolumePathNameW, DeviceIoControl, SetFileTime, SetFilePointer, DosDateTimeToFileTime, GetFileSizeEx, FileTimeToSystemTime, GetSystemTimeAsFileTime, ReadDirectoryChangesW, GetThreadPriority, GetThreadId, GetFileInformationByHandle, TerminateProcess, GetCurrentProcess, DuplicateHandle, WriteFile, CancelIo, GetOverlappedResult, ReadFile, WideCharToMultiByte, MultiByteToWideChar, WaitForMultipleObjects, FormatMessageW, GlobalUnlock, GlobalLock, GlobalAlloc, GetCommandLineW, LoadLibraryExW, lstrlenW, GetNativeSystemInfo, GetVersionExW, PowerCreateRequest, PowerClearRequest, PowerSetRequest, SetLastError, EnterCriticalSection, SetThreadPriority, OutputDebugStringW, LeaveCriticalSection, GetTickCount64, DeleteCriticalSection, GetFileAttributesExW, FindNextFileW, FindClose, GetCurrentThread, SetEvent, ResetEvent, GetExitCodeThread, GetCurrentProcessId, VirtualQuery, VirtualProtect, GetSystemInfo, ReleaseSRWLockExclusive, AcquireSRWLockExclusive, ReleaseSRWLockShared, AcquireSRWLockShared, CopyFileW, IsDebuggerPresent, FreeLibrary, SetDllDirectoryW, CloseHandle, WaitForSingleObject, GetModuleHandleW, GetProcAddress, GetTickCount, GetProcessHeap, HeapAlloc, CreateMutexW, InitializeCriticalSection, QueryPerformanceCounter, QueryPerformanceFrequency, HeapFree, HeapReAlloc, HeapSize, HeapDestroy, MulDiv, InitializeCriticalSectionEx, GetLastError, RaiseException, VirtualFree |
USER32.dll | SetDlgItemTextW, MapVirtualKeyW, GetDlgItem, SendMessageW, ShowWindow, EnableWindow, SetWindowTextW, DestroyWindow, UnregisterClassW, CreateDialogParamW, SetWindowLongW, SendDlgItemMessageW, GetActiveWindow, GetWindowLongW, GetClientRect, ClientToScreen, GetWindowRect, SetWindowPos, SetLayeredWindowAttributes, CharUpperW, GetComboBoxInfo, GetSystemMetrics, EnumThreadWindows, GetWindowPlacement, IsIconic, AdjustWindowRect, DrawEdge, SetClipboardData, CloseClipboard, OpenClipboard, FillRect, AdjustWindowRectEx, GetWindowTextLengthW, GetWindowTextW, NotifyWinEvent, RedrawWindow, IsRectEmpty, DrawTextW, TrackMouseEvent, InflateRect, FrameRect, UnhookWindowsHookEx, SetWindowsHookExW, CallNextHookEx, GetNextDlgTabItem, InvalidateRgn, SystemParametersInfoW, ScrollWindowEx, SetScrollPos, UpdateWindow, SetScrollInfo, SetRectEmpty, SetGestureConfig, CloseGestureInfoHandle, GetGestureInfo, GetScrollInfo, MapDialogRect, IsZoomed, SetMenuItemInfoW, GetMenuItemInfoW, GetMenu, GetWindow, GetDC, BeginPaint, EndPaint, InvalidateRect, IsWindowEnabled, PostMessageW, CreateWindowExW, ScreenToClient, IntersectRect, MonitorFromWindow, LoadIconW, RegisterClipboardFormatW, wsprintfW, AllowSetForegroundWindow, EnumWindows, GetClassNameW, GetWindowThreadProcessId, WindowFromPoint, CheckMenuRadioItem, RegisterShellHookWindow, DeregisterShellHookWindow, RegisterWindowMessageW, RegisterClassW, GetClipboardData, IsCharAlphaW, IsClipboardFormatAvailable, DispatchMessageW, TranslateMessage, LoadImageW, GetDesktopWindow, PostQuitMessage, GetMessageW, MsgWaitForMultipleObjects, OffsetRect, CopyRect, MonitorFromRect, CharLowerW, EndDeferWindowPos, BeginDeferWindowPos, DeferWindowPos, EmptyClipboard, IsWindowVisible, MoveWindow, IsChild, PeekMessageW, SetTimer, DrawTextExW, SetForegroundWindow, PtInRect, DefWindowProcW, GetCursorPos, SetFocus, KillTimer, SetCapture, SetCursor, LoadCursorW, IsDialogMessageW, RegisterClassExW, GetClassInfoExW, CallWindowProcW, GetWindowDC, ReleaseDC, DrawFrameControl, GetParent, GetKeyState, GetMessagePos, AppendMenuW, TrackPopupMenu, CreatePopupMenu, MonitorFromPoint, GetMonitorInfoW, DestroyMenu, MessageBoxW, EndDialog, DialogBoxParamW, MessageBeep, SetActiveWindow, EnumChildWindows, MapWindowPoints, SetMenuDefaultItem, TrackPopupMenuEx, GetDlgCtrlID, GetSysColor, GetFocus, TranslateAcceleratorW, LoadAcceleratorsW, DestroyAcceleratorTable, RegisterHotKey, UnregisterHotKey |
GDI32.dll | GetStockObject, SelectObject, CreateCompatibleDC, CreateCompatibleBitmap, ExtTextOutW, SetBkColor, SetTextColor, DeleteDC, DeleteObject, GetObjectW, CreateFontIndirectW, SetBkMode, CreateRectRgnIndirect, CreateRectRgn, GetTextExtentPoint32W, GetTextColor, GetBkColor, GetCurrentObject, SetDCBrushColor, CreatePen, GetDeviceCaps, GetTextMetricsW, LPtoDP, SaveDC, RestoreDC, OffsetWindowOrgEx, SetWindowOrgEx, IntersectClipRect, CreatePolygonRgn, FrameRgn, FillRgn, SetViewportOrgEx, BitBlt, CombineRgn, SetDCPenColor, LineTo, MoveToEx, OffsetRgn |
ADVAPI32.dll | CryptImportKey, RegQueryValueExW, RegSetValueExW, RegCloseKey, RegOpenKeyW, RegCreateKeyW, RegDeleteValueW, CryptGetHashParam, CryptVerifySignatureW, CryptHashData, CryptCreateHash, RegGetValueW, CryptDestroyKey, CryptDestroyHash, CryptReleaseContext, RegEnumValueW, CryptAcquireContextW, RegOpenKeyExW, RegEnumKeyExW, RegQueryInfoKeyW |
SHELL32.dll | SHOpenFolderAndSelectItems, SHGetFolderPathW, SHCreateItemFromIDList, DragAcceptFiles, ShellExecuteExW, SHGetDesktopFolder, DragFinish |
ole32.dll | CoCreateInstance, OleSetClipboard, OleGetClipboard, CoTaskMemFree, PropVariantClear, CLSIDFromString, CoTaskMemAlloc, ReleaseStgMedium, CoCreateGuid, DoDragDrop, CoUninitialize, RegisterDragDrop, CreateStreamOnHGlobal, OleInitialize, OleUninitialize, CoInitialize, RevokeDragDrop |
OLEAUT32.dll | VariantClear, VariantInit, SysAllocString |
OLEACC.dll | AccessibleObjectFromWindow, LresultFromObject |
CRYPT32.dll | CertVerifyRevocation, CertVerifyCertificateChainPolicy, CertGetCertificateChain, CertVerifyTimeValidity, CertCloseStore, CertFreeCertificateChain, CertFreeCertificateContext |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-19T23:42:33.005441+0100 | 2032776 | ET MALWARE Remcos 3.x Unencrypted Checkin | 1 | 192.168.2.6 | 49773 | 181.131.217.244 | 3020 | TCP |
2024-12-19T23:42:34.257170+0100 | 2032777 | ET MALWARE Remcos 3.x Unencrypted Server Response | 1 | 181.131.217.244 | 3020 | 192.168.2.6 | 49773 | TCP |
2024-12-19T23:42:36.056369+0100 | 2803304 | ETPRO MALWARE Common Downloader Header Pattern HCa | 3 | 192.168.2.6 | 49780 | 178.237.33.50 | 80 | TCP |
2024-12-19T23:44:52.538251+0100 | 2032777 | ET MALWARE Remcos 3.x Unencrypted Server Response | 1 | 181.131.217.244 | 3020 | 192.168.2.6 | 49773 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 19, 2024 23:42:32.861991882 CET | 49773 | 3020 | 192.168.2.6 | 181.131.217.244 |
Dec 19, 2024 23:42:32.981590986 CET | 3020 | 49773 | 181.131.217.244 | 192.168.2.6 |
Dec 19, 2024 23:42:32.982827902 CET | 49773 | 3020 | 192.168.2.6 | 181.131.217.244 |
Dec 19, 2024 23:42:33.005440950 CET | 49773 | 3020 | 192.168.2.6 | 181.131.217.244 |
Dec 19, 2024 23:42:33.125046968 CET | 3020 | 49773 | 181.131.217.244 | 192.168.2.6 |
Dec 19, 2024 23:42:34.257169962 CET | 3020 | 49773 | 181.131.217.244 | 192.168.2.6 |
Dec 19, 2024 23:42:34.303256989 CET | 49773 | 3020 | 192.168.2.6 | 181.131.217.244 |
Dec 19, 2024 23:42:34.425097942 CET | 3020 | 49773 | 181.131.217.244 | 192.168.2.6 |
Dec 19, 2024 23:42:34.492746115 CET | 3020 | 49773 | 181.131.217.244 | 192.168.2.6 |
Dec 19, 2024 23:42:34.612951994 CET | 49773 | 3020 | 192.168.2.6 | 181.131.217.244 |
Dec 19, 2024 23:42:34.692225933 CET | 49780 | 80 | 192.168.2.6 | 178.237.33.50 |
Dec 19, 2024 23:42:34.811904907 CET | 80 | 49780 | 178.237.33.50 | 192.168.2.6 |
Dec 19, 2024 23:42:34.812011003 CET | 49780 | 80 | 192.168.2.6 | 178.237.33.50 |
Dec 19, 2024 23:42:34.812305927 CET | 49780 | 80 | 192.168.2.6 | 178.237.33.50 |
Dec 19, 2024 23:42:34.933470964 CET | 80 | 49780 | 178.237.33.50 | 192.168.2.6 |
Dec 19, 2024 23:42:36.056298018 CET | 80 | 49780 | 178.237.33.50 | 192.168.2.6 |
Dec 19, 2024 23:42:36.056369066 CET | 49780 | 80 | 192.168.2.6 | 178.237.33.50 |
Dec 19, 2024 23:42:36.174133062 CET | 49773 | 3020 | 192.168.2.6 | 181.131.217.244 |
Dec 19, 2024 23:42:36.293732882 CET | 3020 | 49773 | 181.131.217.244 | 192.168.2.6 |
Dec 19, 2024 23:42:37.055639029 CET | 80 | 49780 | 178.237.33.50 | 192.168.2.6 |
Dec 19, 2024 23:42:37.055702925 CET | 49780 | 80 | 192.168.2.6 | 178.237.33.50 |
Dec 19, 2024 23:42:52.276170969 CET | 3020 | 49773 | 181.131.217.244 | 192.168.2.6 |
Dec 19, 2024 23:42:52.277363062 CET | 49773 | 3020 | 192.168.2.6 | 181.131.217.244 |
Dec 19, 2024 23:42:52.397197008 CET | 3020 | 49773 | 181.131.217.244 | 192.168.2.6 |
Dec 19, 2024 23:43:22.367377043 CET | 3020 | 49773 | 181.131.217.244 | 192.168.2.6 |
Dec 19, 2024 23:43:22.368509054 CET | 49773 | 3020 | 192.168.2.6 | 181.131.217.244 |
Dec 19, 2024 23:43:22.488035917 CET | 3020 | 49773 | 181.131.217.244 | 192.168.2.6 |
Dec 19, 2024 23:43:52.398148060 CET | 3020 | 49773 | 181.131.217.244 | 192.168.2.6 |
Dec 19, 2024 23:43:52.402360916 CET | 49773 | 3020 | 192.168.2.6 | 181.131.217.244 |
Dec 19, 2024 23:43:52.522624016 CET | 3020 | 49773 | 181.131.217.244 | 192.168.2.6 |
Dec 19, 2024 23:44:22.447581053 CET | 3020 | 49773 | 181.131.217.244 | 192.168.2.6 |
Dec 19, 2024 23:44:22.453505039 CET | 49773 | 3020 | 192.168.2.6 | 181.131.217.244 |
Dec 19, 2024 23:44:22.573074102 CET | 3020 | 49773 | 181.131.217.244 | 192.168.2.6 |
Dec 19, 2024 23:44:24.535968065 CET | 49780 | 80 | 192.168.2.6 | 178.237.33.50 |
Dec 19, 2024 23:44:24.975891113 CET | 49780 | 80 | 192.168.2.6 | 178.237.33.50 |
Dec 19, 2024 23:44:25.660010099 CET | 49780 | 80 | 192.168.2.6 | 178.237.33.50 |
Dec 19, 2024 23:44:26.972548962 CET | 49780 | 80 | 192.168.2.6 | 178.237.33.50 |
Dec 19, 2024 23:44:29.472493887 CET | 49780 | 80 | 192.168.2.6 | 178.237.33.50 |
Dec 19, 2024 23:44:34.472512007 CET | 49780 | 80 | 192.168.2.6 | 178.237.33.50 |
Dec 19, 2024 23:44:44.175939083 CET | 49780 | 80 | 192.168.2.6 | 178.237.33.50 |
Dec 19, 2024 23:44:52.538250923 CET | 3020 | 49773 | 181.131.217.244 | 192.168.2.6 |
Dec 19, 2024 23:44:52.547180891 CET | 49773 | 3020 | 192.168.2.6 | 181.131.217.244 |
Dec 19, 2024 23:44:52.666826963 CET | 3020 | 49773 | 181.131.217.244 | 192.168.2.6 |
Dec 19, 2024 23:45:22.585927010 CET | 3020 | 49773 | 181.131.217.244 | 192.168.2.6 |
Dec 19, 2024 23:45:22.592022896 CET | 49773 | 3020 | 192.168.2.6 | 181.131.217.244 |
Dec 19, 2024 23:45:22.711642027 CET | 3020 | 49773 | 181.131.217.244 | 192.168.2.6 |
Dec 19, 2024 23:45:52.686440945 CET | 3020 | 49773 | 181.131.217.244 | 192.168.2.6 |
Dec 19, 2024 23:45:52.688266039 CET | 49773 | 3020 | 192.168.2.6 | 181.131.217.244 |
Dec 19, 2024 23:45:52.807832003 CET | 3020 | 49773 | 181.131.217.244 | 192.168.2.6 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 19, 2024 23:42:32.372544050 CET | 56637 | 53 | 192.168.2.6 | 1.1.1.1 |
Dec 19, 2024 23:42:32.779983997 CET | 53 | 56637 | 1.1.1.1 | 192.168.2.6 |
Dec 19, 2024 23:42:34.546252966 CET | 55879 | 53 | 192.168.2.6 | 1.1.1.1 |
Dec 19, 2024 23:42:34.685386896 CET | 53 | 55879 | 1.1.1.1 | 192.168.2.6 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 19, 2024 23:42:32.372544050 CET | 192.168.2.6 | 1.1.1.1 | 0xfcf5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 19, 2024 23:42:34.546252966 CET | 192.168.2.6 | 1.1.1.1 | 0x8321 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 19, 2024 23:42:32.779983997 CET | 1.1.1.1 | 192.168.2.6 | 0xfcf5 | No error (0) | 181.131.217.244 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 23:42:34.685386896 CET | 1.1.1.1 | 192.168.2.6 | 0x8321 | No error (0) | 178.237.33.50 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.6 | 49780 | 178.237.33.50 | 80 | 3472 | C:\Users\user\Desktop\SHROsQyiAd.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 23:42:34.812305927 CET | 71 | OUT | |
Dec 19, 2024 23:42:36.056298018 CET | 1171 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 2 |
Start time: | 17:42:11 |
Start date: | 19/12/2024 |
Path: | C:\Users\user\Desktop\SHROsQyiAd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 8'779'776 bytes |
MD5 hash: | 7119698425E2056D404E97B12ED5CA37 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 6 |
Start time: | 17:42:31 |
Start date: | 19/12/2024 |
Path: | C:\Users\user\Desktop\SHROsQyiAd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 8'779'776 bytes |
MD5 hash: | 7119698425E2056D404E97B12ED5CA37 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 4.2% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 5.8% |
Total number of Nodes: | 1321 |
Total number of Limit Nodes: | 51 |
Graph
Function 00C8BCE3 Relevance: 115.6, APIs: 40, Strings: 26, Instructions: 140libraryloaderCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C799E4 Relevance: 14.1, APIs: 6, Strings: 2, Instructions: 65windowCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C7E54F Relevance: 8.8, APIs: 2, Strings: 3, Instructions: 88sleepCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C7455B Relevance: 4.5, APIs: 3, Instructions: 28synchronizationnetworkCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C8A7A2 Relevance: 1.5, APIs: 1, Instructions: 40COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C7E679 Relevance: 1.5, APIs: 1, Instructions: 19COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C83FD4 Relevance: 32.3, APIs: 5, Strings: 13, Instructions: 813sleepnetworkCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C7428C Relevance: 19.4, APIs: 4, Strings: 7, Instructions: 147networkCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C7A3F4 Relevance: 17.7, APIs: 6, Strings: 4, Instructions: 158sleepCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C8A51B Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 68networkfileCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C79E48 Relevance: 9.2, APIs: 6, Instructions: 163sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C798A5 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 70threadCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C74915 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 60timethreadCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C826D2 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 37registryCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C74688 Relevance: 6.1, APIs: 4, Instructions: 121synchronizationthreadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C8B58F Relevance: 6.1, APIs: 4, Instructions: 64fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C74468 Relevance: 4.6, APIs: 3, Instructions: 92synchronizationnetworkCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C84B9B Relevance: 3.2, APIs: 2, Instructions: 163COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C741F1 Relevance: 3.0, APIs: 2, Instructions: 40networkCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C8AC52 Relevance: 3.0, APIs: 2, Instructions: 25COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C83F9A Relevance: 3.0, APIs: 2, Instructions: 21networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C79517 Relevance: 1.6, APIs: 1, Instructions: 64COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C79A97 Relevance: 1.5, APIs: 1, Instructions: 46COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C74262 Relevance: 1.5, APIs: 1, Instructions: 15networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CB6AFF Relevance: 1.3, APIs: 1, Instructions: 32memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C76F06 Relevance: 34.1, APIs: 10, Strings: 9, Instructions: 849filesleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C75042 Relevance: 30.0, APIs: 15, Strings: 2, Instructions: 280pipesleepfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C80F36 Relevance: 30.0, APIs: 7, Strings: 10, Instructions: 238threadCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C7B335 Relevance: 24.6, APIs: 8, Strings: 6, Instructions: 145fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C7B53A Relevance: 21.1, APIs: 7, Strings: 5, Instructions: 130fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C859C6 Relevance: 18.1, APIs: 12, Instructions: 80clipboardmemoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C7E219 Relevance: 17.7, APIs: 6, Strings: 4, Instructions: 212processCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C8B42F Relevance: 13.6, APIs: 9, Instructions: 105fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C82F45 Relevance: 10.9, APIs: 4, Strings: 2, Instructions: 391registrylibraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C7B21B Relevance: 10.5, APIs: 2, Strings: 4, Instructions: 48fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CC2F00 Relevance: 10.1, APIs: 1, Strings: 4, Instructions: 1381COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C789A9 Relevance: 9.3, APIs: 6, Instructions: 288fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C89BC4 Relevance: 9.0, APIs: 6, Instructions: 39serviceCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C858B9 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 97libraryloadershutdownCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CC11E3 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 86COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C77A8C Relevance: 7.7, APIs: 5, Instructions: 183fileCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C76128 Relevance: 7.2, APIs: 2, Strings: 2, Instructions: 222filenetworkCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C78DA7 Relevance: 6.2, APIs: 4, Instructions: 206fileCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CC0E6A Relevance: 4.7, APIs: 3, Instructions: 205COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CB7597 Relevance: 3.5, APIs: 1, Strings: 1, Instructions: 37COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C88C69 Relevance: 3.2, APIs: 2, Instructions: 245fileCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C76AC2 Relevance: 3.1, APIs: 2, Instructions: 86fileCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CA2A49 Relevance: 1.8, Strings: 1, Instructions: 500COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CC10BA Relevance: 1.6, APIs: 1, Instructions: 83COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CC12EA Relevance: 1.5, APIs: 1, Instructions: 46COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CA3CD7 Relevance: 1.5, APIs: 1, Instructions: 3COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CAC9DD Relevance: 1.5, Strings: 1, Instructions: 214COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C96E73 Relevance: 1.3, Strings: 1, Instructions: 96COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CBE92E Relevance: 1.3, APIs: 1, Instructions: 5memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CBC739 Relevance: .6, Instructions: 637COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C8E5DF Relevance: .6, Instructions: 606COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C967CB Relevance: .4, Instructions: 437COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C96254 Relevance: .4, Instructions: 377COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CA1377 Relevance: .4, Instructions: 371COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C8D071 Relevance: .3, Instructions: 276COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CAD098 Relevance: .2, Instructions: 237COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CACE3B Relevance: .2, Instructions: 237COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C96FAD Relevance: .2, Instructions: 186COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CA7150 Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C87F9F Relevance: 51.1, APIs: 28, Strings: 1, Instructions: 324windowmemoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C87245 Relevance: 49.3, APIs: 22, Strings: 6, Instructions: 290libraryloaderthreadCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C7C28E Relevance: 38.8, APIs: 6, Strings: 16, Instructions: 282registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C812B5 Relevance: 38.7, APIs: 17, Strings: 5, Instructions: 189synchronizationsleepfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C8A1BB Relevance: 38.7, APIs: 12, Strings: 10, Instructions: 180synchronizationCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C7BF04 Relevance: 37.0, APIs: 6, Strings: 15, Instructions: 260registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C71BE8 Relevance: 35.2, APIs: 16, Strings: 4, Instructions: 156fileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C764E0 Relevance: 35.1, APIs: 12, Strings: 8, Instructions: 62libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C7BC67 Relevance: 28.2, APIs: 12, Strings: 4, Instructions: 203fileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C8B1BB Relevance: 28.1, APIs: 15, Strings: 1, Instructions: 139stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CBE20E Relevance: 25.9, APIs: 17, Instructions: 419COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C83E37 Relevance: 24.6, APIs: 9, Strings: 5, Instructions: 109libraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C8B824 Relevance: 23.0, APIs: 6, Strings: 7, Instructions: 214registryCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C8CA9E Relevance: 22.8, APIs: 12, Strings: 1, Instructions: 73windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CB4F3D Relevance: 22.8, APIs: 15, Instructions: 296COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C77DEF Relevance: 19.6, APIs: 8, Strings: 3, Instructions: 325fileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CBF3E1 Relevance: 18.4, APIs: 12, Instructions: 376COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C747EB Relevance: 18.1, APIs: 12, Instructions: 66synchronizationCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C81C81 Relevance: 18.0, APIs: 9, Strings: 1, Instructions: 479sleepfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CC4982 Relevance: 17.8, APIs: 9, Strings: 1, Instructions: 272COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C74E52 Relevance: 15.9, APIs: 6, Strings: 3, Instructions: 155windowmemoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CB6DCB Relevance: 15.1, APIs: 10, Instructions: 54COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C89128 Relevance: 14.2, APIs: 6, Strings: 2, Instructions: 174sleeptimeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CC5139 Relevance: 14.2, APIs: 1, Strings: 7, Instructions: 154COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C865FC Relevance: 14.1, APIs: 3, Strings: 5, Instructions: 103sleepfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C8C96F Relevance: 14.0, APIs: 7, Strings: 1, Instructions: 47windowstringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CC2B2A Relevance: 13.8, APIs: 9, Instructions: 268COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CB43F9 Relevance: 12.5, APIs: 6, Strings: 1, Instructions: 266COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C86E27 Relevance: 12.4, APIs: 4, Strings: 3, Instructions: 107filesynchronizationCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C76BE9 Relevance: 12.3, APIs: 6, Strings: 1, Instructions: 97fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CB7E3A Relevance: 10.9, APIs: 7, Instructions: 370timeCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CBF806 Relevance: 10.7, APIs: 7, Instructions: 204COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CBA0C3 Relevance: 10.7, APIs: 7, Instructions: 152fileCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C7B2A8 Relevance: 10.5, APIs: 2, Strings: 4, Instructions: 48fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C8BEB0 Relevance: 10.5, APIs: 3, Strings: 3, Instructions: 47memoryCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C89F32 Relevance: 10.5, APIs: 4, Strings: 2, Instructions: 30sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CA95FC Relevance: 9.3, APIs: 6, Instructions: 284COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CB6159 Relevance: 9.1, APIs: 3, Strings: 2, Instructions: 389COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C89DEC Relevance: 9.1, APIs: 6, Instructions: 66serviceCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C89C20 Relevance: 9.0, APIs: 6, Instructions: 44serviceCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C89D87 Relevance: 9.0, APIs: 6, Instructions: 44serviceCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C89D22 Relevance: 9.0, APIs: 6, Instructions: 44serviceCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C8CA1F Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 54registryCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C769BA Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 42processCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CB25D9 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 38libraryloaderCOMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C74AB1 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 35synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C71430 Relevance: 8.8, APIs: 2, Strings: 3, Instructions: 7libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C80B19 Relevance: 7.7, APIs: 5, Instructions: 198memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C73DE7 Relevance: 7.6, APIs: 1, Strings: 4, Instructions: 135sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C7196B Relevance: 7.6, APIs: 5, Instructions: 72COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C7FBEF Relevance: 7.6, APIs: 5, Instructions: 71COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CBE13B Relevance: 7.6, APIs: 5, Instructions: 68COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C7FED2 Relevance: 7.6, APIs: 5, Instructions: 59COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CB32E7 Relevance: 7.5, APIs: 5, Instructions: 30COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C829AA Relevance: 7.2, APIs: 3, Strings: 1, Instructions: 173registryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C7A611 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 64threadCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C74B29 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 47synchronizationCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C82774 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 38registryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C7AFBA Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 20threadCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C714D5 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 7libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CB1A81 Relevance: 6.1, APIs: 4, Instructions: 133COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C7B806 Relevance: 6.1, APIs: 2, Strings: 2, Instructions: 103sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C79C4B Relevance: 6.1, APIs: 2, Strings: 2, Instructions: 71sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CB2CD2 Relevance: 6.1, APIs: 4, Instructions: 63COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CB2D51 Relevance: 6.1, APIs: 4, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CB7210 Relevance: 6.1, APIs: 4, Instructions: 52libraryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C8B61A Relevance: 6.0, APIs: 4, Instructions: 50fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C8850C Relevance: 6.0, APIs: 4, Instructions: 49COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C8B37D Relevance: 6.0, APIs: 4, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C73A10 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 92sleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00CC08DE Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 88COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C7AD56 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 32keyboardCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C7ADB0 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 24keyboardCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C8297A Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 23registryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00C81699 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 13synchronizationCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|