Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
60Zxcx88Uv.exe

Overview

General Information

Sample name:60Zxcx88Uv.exe
renamed because original name is a hash value
Original sample name:0ee9a86828935f4ee448a66aaf0bfb42.exe
Analysis ID:1581231
MD5:0ee9a86828935f4ee448a66aaf0bfb42
SHA1:2b718d65a24f8bed4d37456a3fd05e054e90e550
SHA256:f47d5e2b2aa8746022bdcfba52a8604be13d0e8b260e2d05ad959f1a2cc8c507
Tags:exeuser-abuse_ch
Errors
  • No process behavior to analyse as no analysis process or sample was found
  • Corrupt sample or wrongly selected analyzer. Details: %1 is not a valid Win32 application.

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
PE file contains more sections than normal
PE file contains sections with non-standard names
PE file overlay found

Classification

No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: 60Zxcx88Uv.exeReversingLabs: Detection: 34%
Source: 60Zxcx88Uv.exeVirustotal: Detection: 36%Perma Link
Source: 60Zxcx88Uv.exeString found in binary or memory: http://digitalbush.com/projects/masked-input-plugin/#license)
Source: 60Zxcx88Uv.exeStatic PE information: Number of sections : 11 > 10
Source: 60Zxcx88Uv.exeStatic PE information: Data appended to the last section found
Source: classification engineClassification label: mal48.winEXE@0/0@0/0
Source: 60Zxcx88Uv.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: 60Zxcx88Uv.exeReversingLabs: Detection: 34%
Source: 60Zxcx88Uv.exeVirustotal: Detection: 36%
Source: 60Zxcx88Uv.exeString found in binary or memory: gfx/loading.gif">
Source: 60Zxcx88Uv.exeString found in binary or memory: /gfx/loading.gif
Source: 60Zxcx88Uv.exeString found in binary or memory: gfx/loading.gif
Source: 60Zxcx88Uv.exeString found in binary or memory: Execute via &Default browser/Launch default browser and execute application.
Source: 60Zxcx88Uv.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
Source: 60Zxcx88Uv.exeStatic file information: File size 7618431 > 1048576
Source: 60Zxcx88Uv.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x48f600
Source: 60Zxcx88Uv.exeStatic PE information: Raw size of .rsrc is bigger than: 0x100000 < 0x283e00
Source: 60Zxcx88Uv.exeStatic PE information: section name: .didata
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
Command and Scripting Interpreter
Path InterceptionPath InterceptionDirect Volume AccessOS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
SourceDetectionScannerLabelLink
60Zxcx88Uv.exe34%ReversingLabsWin64.Trojan.Ulise
60Zxcx88Uv.exe37%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
s-part-0035.t-0009.t-msedge.net
13.107.246.63
truefalse
    high
    NameSourceMaliciousAntivirus DetectionReputation
    http://digitalbush.com/projects/masked-input-plugin/#license)60Zxcx88Uv.exefalse
      high
      No contacted IP infos
      Joe Sandbox version:41.0.0 Charoite
      Analysis ID:1581231
      Start date and time:2024-12-27 08:52:08 +01:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 1m 56s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:default.jbs
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:1
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Sample name:60Zxcx88Uv.exe
      renamed because original name is a hash value
      Original Sample Name:0ee9a86828935f4ee448a66aaf0bfb42.exe
      Detection:MAL
      Classification:mal48.winEXE@0/0@0/0
      Cookbook Comments:
      • Found application associated with file extension: .exe
      • Unable to launch sample, stop analysis
      • No process behavior to analyse as no analysis process or sample was found
      • Corrupt sample or wrongly selected analyzer. Details: %1 is not a valid Win32 application.
      • Exclude process from analysis (whitelisted): dllhost.exe
      • Excluded IPs from analysis (whitelisted): 13.107.246.63
      • Excluded domains from analysis (whitelisted): otelrules.azureedge.net, otelrules.afd.azureedge.net, azureedge-t-prod.trafficmanager.net
      No simulations
      No context
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      s-part-0035.t-0009.t-msedge.net7jKx8dPOEs.exeGet hashmaliciousLummaCBrowse
      • 13.107.246.63
      1fi2LiofgW.exeGet hashmaliciousUnknownBrowse
      • 13.107.246.63
      zi042476Iv.exeGet hashmaliciousLummaCBrowse
      • 13.107.246.63
      54861 Proforma Invoice AMC2273745.xlam.xlsxGet hashmaliciousUnknownBrowse
      • 13.107.246.63
      TAX INVOICE - NBO2506000632.xlam.xlsxGet hashmaliciousUnknownBrowse
      • 13.107.246.63
      installer.batGet hashmaliciousVidarBrowse
      • 13.107.246.63
      din.exeGet hashmaliciousVidarBrowse
      • 13.107.246.63
      lem.exeGet hashmaliciousVidarBrowse
      • 13.107.246.63
      atw3.dllGet hashmaliciousGozi, UrsnifBrowse
      • 13.107.246.63
      WRD1792.docx.docGet hashmaliciousDynamerBrowse
      • 13.107.246.63
      No context
      No context
      No context
      No created / dropped files found
      File type:PE32+ executable (GUI) x86-64, for MS Windows
      Entropy (8bit):6.40904898608761
      TrID:
      • Win64 Executable GUI (202006/5) 92.64%
      • Win64 Executable (generic) (12005/4) 5.51%
      • Generic Win/DOS Executable (2004/3) 0.92%
      • DOS Executable Generic (2002/1) 0.92%
      • VXD Driver (31/22) 0.01%
      File name:60Zxcx88Uv.exe
      File size:7'618'431 bytes
      MD5:0ee9a86828935f4ee448a66aaf0bfb42
      SHA1:2b718d65a24f8bed4d37456a3fd05e054e90e550
      SHA256:f47d5e2b2aa8746022bdcfba52a8604be13d0e8b260e2d05ad959f1a2cc8c507
      SHA512:042a117ba45f731d1cf8fcf53f812ac65e56ee1276796c4c84c901429925ab2979c34f84515cc8e06e8f9e3a740403e53ce3ab53a756b88d2f365a72bcb5d110
      SSDEEP:49152:sExHcWioiCm3XEyP3605RYCXXLwsSXLJK3quO6xVzsoeoe17qRhm6PpdTTCWZ4ib:cNtfmToeoeKSWew5OkKc
      TLSH:DE765B7B62B59279C25DC13FC0A38F02E433B4791B37CAEB929042595F159C4AE3BB25
      File Content Preview:MZP.....................@...............................................!..L.!..This program must be run under Win64..$7.......................................................................................................................................
      Icon Hash:00928e8e8686b000
      Entrypoint:0x8904a0
      Entrypoint Section:.text
      Digitally signed:false
      Imagebase:0x400000
      Subsystem:windows gui
      Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
      DLL Characteristics:
      Time Stamp:0x66C36C30 [Mon Aug 19 16:00:48 2024 UTC]
      TLS Callbacks:
      CLR (.Net) Version:
      OS Version Major:5
      OS Version Minor:2
      File Version Major:5
      File Version Minor:2
      Subsystem Version Major:5
      Subsystem Version Minor:2
      Import Hash:73c7e572536ce3b598c7740cf9a09ab5
      Instruction
      push ebp
      dec eax
      sub esp, 20h
      dec eax
      mov ebp, esp
      nop
      dec eax
      lea ecx, dword ptr [FFFE92A8h]
      call 00007FA358675720h
      dec eax
      mov eax, dword ptr [00066574h]
      dec eax
      mov ecx, dword ptr [eax]
      call 00007FA35892A3F1h
      dec eax
      mov eax, dword ptr [00066565h]
      dec eax
      mov ecx, dword ptr [eax]
      mov dl, 01h
      call 00007FA35892D0A0h
      dec eax
      mov eax, dword ptr [00066554h]
      dec eax
      mov ecx, dword ptr [eax]
      dec eax
      mov edx, dword ptr [FFFE8BFAh]
      dec esp
      mov eax, dword ptr [0006624Bh]
      call 00007FA35892A3F3h
      dec eax
      mov eax, dword ptr [00066537h]
      dec eax
      mov ecx, dword ptr [eax]
      call 00007FA35892A604h
      call 00007FA35866D14Fh
      jmp 00007FA358AEEB5Ah
      nop
      nop
      call 00007FA35866D346h
      nop
      dec eax
      lea esp, dword ptr [ebp+20h]
      pop ebp
      ret
      dec eax
      nop
      dec eax
      lea eax, dword ptr [00000000h+eax]
      dec eax
      sub esp, 28h
      call 00007FA35866C8DCh
      dec eax
      add esp, 28h
      ret
      int3
      int3
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      add byte ptr [eax], al
      NameVirtual AddressVirtual Size Is in Section
      IMAGE_DIRECTORY_ENTRY_EXPORT0x50a0000x9c.edata
      IMAGE_DIRECTORY_ENTRY_IMPORT0x5040000x4e36.idata
      IMAGE_DIRECTORY_ENTRY_RESOURCE0x5850000x283e00.rsrc
      IMAGE_DIRECTORY_ENTRY_EXCEPTION0x5460000x3e754.pdata
      IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
      IMAGE_DIRECTORY_ENTRY_BASERELOC0x50d0000x38314.reloc
      IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
      IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
      IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
      IMAGE_DIRECTORY_ENTRY_TLS0x50c0000x28.rdata
      IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
      IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
      IMAGE_DIRECTORY_ENTRY_IAT0x5054280x1258.idata
      IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x5090000xed8.didata
      IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
      IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
      NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
      .text0x10000x48f5300x48f60045b0d17e9c8caac916608d2d25f852c3unknownunknownunknownunknownIMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
      .data0x4910000x663780x66400b94e35a0a016d96b2d8b4b49acb21d4cFalse0.2696983878361858data4.880729534270984IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
      .bss0x4f80000xb7d40x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
      .idata0x5040000x4e360x50003531e19eda29b47c89c335efc173829cFalse0.240673828125data4.208258046171773IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
      .didata0x5090000xed80x1000938a440fea59562ad3c6086f335c8fbdFalse0.248046875data3.128860257762936IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
      .edata0x50a0000x9c0x200b0e12af7e0ba2bb16811f2a082fe87ccFalse0.26171875data1.9231601644709146IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
      .tls0x50b0000x1e40x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
      .rdata0x50c0000x6d0x20068e9a6e686447975f28feec93489aa94False0.1953125data1.3902637598484393IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
      .reloc0x50d0000x383140x384000dd6aa7ec5ee4e6e625f993b6657a20dFalse0.4608072916666667data6.4452844954118484IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
      .pdata0x5460000x3e7540x3e8003a7d70695ace71dd0889878956e0fe47False0.49669921875data6.397376454331368IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
      .rsrc0x5850000x283e000x283e0039c45a21837b30d0e7e33283ff3cefeeunknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
      NameRVASizeTypeLanguageCountryZLIB Complexity
      RT_CURSOR0x587d040x134Targa image data - Map 64 x 65536 x 1 +32 "\001"EnglishUnited States0.38636363636363635
      RT_CURSOR0x587e380x134dataEnglishUnited States0.4642857142857143
      RT_CURSOR0x587f6c0x134dataEnglishUnited States0.4805194805194805
      RT_CURSOR0x5880a00x134dataEnglishUnited States0.38311688311688313
      RT_CURSOR0x5881d40x134dataEnglishUnited States0.36038961038961037
      RT_CURSOR0x5883080x134dataEnglishUnited States0.4090909090909091
      RT_CURSOR0x58843c0x134Targa image data - RGB 64 x 65536 x 1 +32 "\001"EnglishUnited States0.4967532467532468
      RT_ICON0x5885700x468Device independent bitmap graphic, 16 x 32 x 32, image size 1024, resolution 2835 x 2835 px/m0.6613475177304965
      RT_ICON0x5889d80x988Device independent bitmap graphic, 24 x 48 x 32, image size 2304, resolution 2835 x 2835 px/m0.42745901639344264
      RT_ICON0x5893600x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4096, resolution 2835 x 2835 px/m0.3224671669793621
      RT_ICON0x58a4080x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9216, resolution 2835 x 2835 px/m0.229149377593361
      RT_ICON0x58c9b00x4228Device independent bitmap graphic, 64 x 128 x 32, image size 16384, resolution 2835 x 2835 px/m0.16456069910250354
      RT_ICON0x590bd80x5488Device independent bitmap graphic, 72 x 144 x 32, image size 20736, resolution 2835 x 2835 px/m0.14755083179297598
      RT_ICON0x5960600x94a8Device independent bitmap graphic, 96 x 192 x 32, image size 36864, resolution 2835 x 2835 px/m0.056154088711372716
      RT_ICON0x59f5080x10828Device independent bitmap graphic, 128 x 256 x 32, image size 65536, resolution 2835 x 2835 px/m0.09265941086004968
      RT_ICON0x5afd300x3694PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced0.9870455196106499
      RT_STRING0x5b33c40x818data0.30984555984555984
      RT_STRING0x5b3bdc0x924data0.25427350427350426
      RT_STRING0x5b45000x330data0.4178921568627451
      RT_STRING0x5b48300x45cdata0.3673835125448029
      RT_STRING0x5b4c8c0x438data0.3537037037037037
      RT_STRING0x5b50c40x444data0.29945054945054944
      RT_STRING0x5b55080x388data0.4358407079646018
      RT_STRING0x5b58900x358data0.39602803738317754
      RT_STRING0x5b5be80x394data0.3307860262008734
      RT_STRING0x5b5f7c0x5d8data0.3830213903743315
      RT_STRING0x5b65540x24cdata0.477891156462585
      RT_STRING0x5b67a00x2a0data0.34672619047619047
      RT_STRING0x5b6a400x3d8data0.35060975609756095
      RT_STRING0x5b6e180x398data0.4489130434782609
      RT_STRING0x5b71b00x298StarOffice Gallery theme o, 151022848 objects, 1st e0.4743975903614458
      RT_STRING0x5b74480x54cdata0.3635693215339233
      RT_STRING0x5b79940x200data0.52734375
      RT_STRING0x5b7b940x280data0.503125
      RT_STRING0x5b7e140x588data0.3637005649717514
      RT_STRING0x5b839c0x36cdata0.3664383561643836
      RT_STRING0x5b87080x3c4data0.4118257261410788
      RT_STRING0x5b8acc0x3a0data0.4267241379310345
      RT_STRING0x5b8e6c0x410data0.39903846153846156
      RT_STRING0x5b927c0x43cdata0.4059040590405904
      RT_STRING0x5b96b80x34cdata0.40165876777251186
      RT_STRING0x5b9a040x390data0.3355263157894737
      RT_STRING0x5b9d940x288data0.4737654320987654
      RT_STRING0x5ba01c0x4ecdata0.37222222222222223
      RT_STRING0x5ba5080x3dcdata0.3248987854251012
      RT_STRING0x5ba8e40x364data0.4216589861751152
      RT_STRING0x5bac480x290data0.4695121951219512
      RT_STRING0x5baed80xc0data0.6666666666666666
      RT_STRING0x5baf980x100data0.625
      RT_STRING0x5bb0980x3f0data0.37797619047619047
      RT_STRING0x5bb4880x414data0.3726053639846743
      RT_STRING0x5bb89c0x444data0.3983516483516483
      RT_STRING0x5bbce00x418data0.2862595419847328
      RT_STRING0x5bc0f80x3bcdata0.41422594142259417
      RT_STRING0x5bc4b40x3f8data0.3838582677165354
      RT_STRING0x5bc8ac0x59cdata0.31963788300835655
      RT_STRING0x5bce480x458AmigaOS bitmap font "t", fc_YSize 29184, 21248 elements, 2nd "r", 3rd " "0.33363309352517984
      RT_STRING0x5bd2a00x36cdata0.3915525114155251
      RT_STRING0x5bd60c0x360data0.35532407407407407
      RT_STRING0x5bd96c0x3fcdata0.3764705882352941
      RT_STRING0x5bdd680xd0data0.5288461538461539
      RT_STRING0x5bde380xb8data0.6467391304347826
      RT_STRING0x5bdef00x2c0data0.46732954545454547
      RT_STRING0x5be1b00x434data0.3308550185873606
      RT_STRING0x5be5e40x360data0.38425925925925924
      RT_STRING0x5be9440x2ecdata0.37566844919786097
      RT_STRING0x5bec300x31cdata0.34296482412060303
      RT_RCDATA0x5bef4c0x10data1.5
      RT_RCDATA0x5bef5c0x1536MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixelEnglishUnited States0.6550644567219153
      RT_RCDATA0x5c04940x359GIF image data, version 89a, 16 x 16EnglishUnited States0.15635939323220538
      RT_RCDATA0x5c07f00x378GIF image data, version 89a, 21 x 21EnglishUnited States0.5529279279279279
      RT_RCDATA0x5c0b680x12cGIF image data, version 89a, 10 x 12EnglishUnited States0.83
      RT_RCDATA0x5c0c940x129GIF image data, version 89a, 10 x 12EnglishUnited States0.7575757575757576
      RT_RCDATA0x5c0dc00x4c8GIF image data, version 89a, 24 x 24EnglishUnited States0.6282679738562091
      RT_RCDATA0x5c12880x4b5GIF image data, version 89a, 24 x 24EnglishUnited States0.5526970954356847
      RT_RCDATA0x5c17400x42eGIF image data, version 89a, 24 x 24EnglishUnited States0.5112149532710281
      RT_RCDATA0x5c1b700x42eGIF image data, version 89a, 24 x 24EnglishUnited States0.4766355140186916
      RT_RCDATA0x5c1fa00x432GIF image data, version 89a, 24 x 24EnglishUnited States0.5027932960893855
      RT_RCDATA0x5c23d40x434GIF image data, version 89a, 24 x 24EnglishUnited States0.4758364312267658
      RT_RCDATA0x5c28080x4daGIF image data, version 89a, 24 x 24EnglishUnited States0.6191626409017713
      RT_RCDATA0x5c2ce40x4c1GIF image data, version 89a, 24 x 24EnglishUnited States0.5825801150369762
      RT_RCDATA0x5c31a80x449GIF image data, version 89a, 24 x 24EnglishUnited States0.5077484047402006
      RT_RCDATA0x5c35f40x455GIF image data, version 89a, 24 x 24EnglishUnited States0.5067628494138864
      RT_RCDATA0x5c3a4c0x4ceGIF image data, version 89a, 24 x 24EnglishUnited States0.6699186991869919
      RT_RCDATA0x5c3f1c0x4b9GIF image data, version 89a, 24 x 24EnglishUnited States0.5665839536807279
      RT_RCDATA0x5c43d80x32eGIF image data, version 89a, 24 x 24EnglishUnited States0.9582309582309583
      RT_RCDATA0x5c47080x30eGIF image data, version 89a, 24 x 24EnglishUnited States0.8491048593350383
      RT_RCDATA0x5c4a180x444GIF image data, version 89a, 24 x 24EnglishUnited States0.5265567765567766
      RT_RCDATA0x5c4e5c0x44fGIF image data, version 89a, 24 x 24EnglishUnited States0.4877606527651859
      RT_RCDATA0x5c52ac0x4b5GIF image data, version 89a, 24 x 24EnglishUnited States0.6182572614107884
      RT_RCDATA0x5c57640x4abGIF image data, version 89a, 24 x 24EnglishUnited States0.5581589958158996
      RT_RCDATA0x5c5c100x480GIF image data, version 89a, 24 x 24EnglishUnited States0.5815972222222222
      RT_RCDATA0x5c60900x46aGIF image data, version 89a, 24 x 24EnglishUnited States0.5389380530973451
      RT_RCDATA0x5c64fc0x679HTML document, ASCII text, with CRLF, LF line terminatorsEnglishUnited States0.46107423053711527
      RT_RCDATA0x5c6b780xacfGIF image data, version 89a, 32 x 32EnglishUnited States0.6841344416335381
      RT_RCDATA0x5c76480xe34GIF image data, version 89a, 105 x 141EnglishUnited States1.0030253025302531
      RT_RCDATA0x5c847c0xa25GIF image data, version 89a, 171 x 75EnglishUnited States1.0042356565267616
      RT_RCDATA0x5c8ea40x4bGIF image data, version 89a, 16 x 16EnglishUnited States0.9733333333333334
      RT_RCDATA0x5c8ef00x3fGIF image data, version 89a, 12 x 16EnglishUnited States1.0317460317460319
      RT_RCDATA0x5c8f300x6eGIF image data, version 89a, 16 x 16EnglishUnited States1.009090909090909
      RT_RCDATA0x5c8fa00x50GIF image data, version 89a, 16 x 16EnglishUnited States1.025
      RT_RCDATA0x5c8ff00x6cGIF image data, version 89a, 16 x 16EnglishUnited States1.0092592592592593
      RT_RCDATA0x5c905c0x4fGIF image data, version 89a, 16 x 16EnglishUnited States1.0253164556962024
      RT_RCDATA0x5c90ac0x6fGIF image data, version 89a, 17 x 16EnglishUnited States1.018018018018018
      RT_RCDATA0x5c911c0x41GIF image data, version 89a, 15 x 15EnglishUnited States0.9846153846153847
      RT_RCDATA0x5c91600x3cGIF image data, version 89a, 16 x 12EnglishUnited States1.0333333333333334
      RT_RCDATA0x5c919c0x69GIF image data, version 89a, 16 x 16EnglishUnited States1.019047619047619
      RT_RCDATA0x5c92080x4dGIF image data, version 89a, 16 x 16EnglishUnited States1.025974025974026
      RT_RCDATA0x5c92580x71GIF image data, version 89a, 16 x 17EnglishUnited States1.079646017699115
      RT_RCDATA0x5c92cc0x69GIF image data, version 89a, 16 x 16EnglishUnited States1.0095238095238095
      RT_RCDATA0x5c93380x4dGIF image data, version 89a, 16 x 16EnglishUnited States1.025974025974026
      RT_RCDATA0x5c93880x45aHTML document, ASCII text, with CRLF line terminatorsEnglishUnited States0.47217235188509876
      RT_RCDATA0x5c97e40x36GIF image data, version 89a, 1 x 1EnglishUnited States1.037037037037037
      RT_RCDATA0x5c981c0x91GIF image data, version 89a, 16 x 16EnglishUnited States0.8137931034482758
      RT_RCDATA0x5c98b00x82GIF image data, version 89a, 16 x 16EnglishUnited States0.7769230769230769
      RT_RCDATA0x5c99340x6cGIF image data, version 89a, 11 x 9EnglishUnited States0.6944444444444444
      RT_RCDATA0x5c99a00x9eGIF image data, version 89a, 16 x 16EnglishUnited States0.8354430379746836
      RT_RCDATA0x5c9a400x6fGIF image data, version 89a, 11 x 9EnglishUnited States0.7027027027027027
      RT_RCDATA0x5c9ab00x356GIF image data, version 89a, 16 x 16EnglishUnited States0.12295081967213115
      RT_RCDATA0x5c9e080x355GIF image data, version 89a, 16 x 16EnglishUnited States0.123094958968347
      RT_RCDATA0x5ca1600x355GIF image data, version 89a, 16 x 16EnglishUnited States0.12192262602579132
      RT_RCDATA0x5ca4b80x361GIF image data, version 89a, 16 x 16EnglishUnited States0.13179190751445086
      RT_RCDATA0x5ca81c0x3aeGIF image data, version 89a, 16 x 16EnglishUnited States0.25796178343949044
      RT_RCDATA0x5cabcc0x3b5GIF image data, version 89a, 16 x 16EnglishUnited States0.291886195995785
      RT_RCDATA0x5caf840x38cGIF image data, version 89a, 16 x 16EnglishUnited States0.21585903083700442
      RT_RCDATA0x5cb3100x41aGIF image data, version 89a, 16 x 16EnglishUnited States0.6266666666666667
      RT_RCDATA0x5cb72c0x36eGIF image data, version 89a, 16 x 16EnglishUnited States0.15945330296127563
      RT_RCDATA0x5cba9c0x36dGIF image data, version 89a, 16 x 16EnglishUnited States0.1573546180159635
      RT_RCDATA0x5cbe0c0x354GIF image data, version 89a, 16 x 16EnglishUnited States0.11854460093896714
      RT_RCDATA0x5cc1600x394GIF image data, version 89a, 16 x 16EnglishUnited States0.1965065502183406
      RT_RCDATA0x5cc4f40x3b0GIF image data, version 89a, 16 x 16EnglishUnited States0.2552966101694915
      RT_RCDATA0x5cc8a40x3e7GIF image data, version 89a, 16 x 16EnglishUnited States0.42842842842842843
      RT_RCDATA0x5ccc8c0x3eeGIF image data, version 89a, 16 x 16EnglishUnited States0.6272365805168986
      RT_RCDATA0x5cd07c0x368GIF image data, version 89a, 16 x 16EnglishUnited States0.13876146788990826
      RT_RCDATA0x5cd3e40x37fGIF image data, version 89a, 16 x 16EnglishUnited States0.28044692737430166
      RT_RCDATA0x5cd7640x37fGIF image data, version 89a, 16 x 16EnglishUnited States0.27932960893854747
      RT_RCDATA0x5cdae40x362GIF image data, version 89a, 16 x 16EnglishUnited States0.13279445727482678
      RT_RCDATA0x5cde480x531bASCII text, with very long lines (16079)EnglishUnited States0.2575323149236193
      RT_RCDATA0x5d31640x3457ASCII text, with very long lines (13399), with no line terminatorsEnglishUnited States0.27718486454213
      RT_RCDATA0x5d65bc0x38c1ASCII text, with very long lines (14529), with no line terminatorsEnglishUnited States0.2771697983343657
      RT_RCDATA0x5d9e800xa64ASCII text, with very long lines (2660), with no line terminatorsEnglishUnited States0.3669172932330827
      RT_RCDATA0x5da8e40xbe1ASCII text, with very long lines (3041), with no line terminatorsEnglishUnited States0.3909898059848734
      RT_RCDATA0x5db4c80x134aASCII text, with very long lines (4938), with no line terminatorsEnglishUnited States0.24807614418793034
      RT_RCDATA0x5dc8140x677ASCII text, with very long lines (1655), with no line terminatorsEnglishUnited States0.313595166163142
      RT_RCDATA0x5dce8c0x4cdHTML document, ASCII text, with very long lines (1229), with no line terminatorsEnglishUnited States0.49308380797396256
      RT_RCDATA0x5dd35c0x1775ASCII text, with very long lines (6005), with no line terminatorsEnglishUnited States0.24196502914238135
      RT_RCDATA0x5dead40xdcdASCII text, with very long lines (3533), with no line terminatorsEnglishUnited States0.3014435324087178
      RT_RCDATA0x5df8a40x17278HTML document, Unicode text, UTF-8 text, with very long lines (32769)EnglishUnited States0.354924082665542
      RT_RCDATA0x5f6b1c0xd0fASCII text, with very long lines (3142)EnglishUnited States0.4552796889021837
      RT_RCDATA0x5f782c0x6eccASCII text, with very long lines (28364), with no line terminatorsEnglishUnited States0.2744676350303201
      RT_RCDATA0x5fe6f80xc9c7ASCII text, with very long lines (51655), with no line terminatorsEnglishUnited States0.24799148194753654
      RT_RCDATA0x60b0c00x1e82ASCII text, with very long lines (7146), with CRLF line terminatorsEnglishUnited States0.3613316261203585
      RT_RCDATA0x60cf440xdb2ASCII text, with CRLF line terminatorsEnglishUnited States0.32857957786651454
      RT_RCDATA0x60dcf80x1448data0.48112480739599384
      RT_RCDATA0x60f1400x1f6304dataEnglishUnited States0.8600749969482422
      RT_RCDATA0x8054440x33c2emptyDutchBelgium0
      RT_RCDATA0x8088080x15fempty0
      RT_GROUP_CURSOR0x8089680x14emptyEnglishUnited States0
      RT_GROUP_CURSOR0x80897c0x14emptyEnglishUnited States0
      RT_GROUP_CURSOR0x8089900x14emptyEnglishUnited States0
      RT_GROUP_CURSOR0x8089a40x14emptyEnglishUnited States0
      RT_GROUP_CURSOR0x8089b80x14emptyEnglishUnited States0
      RT_GROUP_CURSOR0x8089cc0x14emptyEnglishUnited States0
      RT_GROUP_CURSOR0x8089e00x14emptyEnglishUnited States0
      RT_GROUP_ICON0x8089f40x84empty0
      RT_VERSION0x808a780x2e4empty0
      DLLImport
      oleaut32.dllSysFreeString, SysReAllocStringLen, SysAllocStringLen
      advapi32.dllRegQueryValueExW, RegOpenKeyExW, RegCloseKey
      user32.dllCharNextW, LoadStringW
      kernel32.dllSleep, VirtualFree, VirtualAlloc, lstrlenW, VirtualQuery, QueryPerformanceCounter, GetTickCount, GetSystemInfo, GetVersion, CompareStringW, IsValidLocale, SetThreadLocale, GetSystemDefaultUILanguage, GetUserDefaultUILanguage, GetLocaleInfoW, WideCharToMultiByte, MultiByteToWideChar, GetACP, LoadLibraryExW, GetStartupInfoW, GetProcAddress, GetModuleHandleW, GetModuleFileNameW, GetCommandLineW, FreeLibrary, GetLastError, UnhandledExceptionFilter, RtlUnwindEx, RtlUnwind, RaiseException, ExitProcess, ExitThread, SwitchToThread, GetCurrentThreadId, CreateThread, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, FindFirstFileW, FindClose, WriteFile, GetStdHandle, CloseHandle
      kernel32.dllGetProcAddress, RaiseException, LoadLibraryA, GetLastError, TlsSetValue, TlsGetValue, LocalFree, LocalAlloc, GetModuleHandleW, FreeLibrary
      user32.dllSetClassLongPtrW, GetClassLongPtrW, SetWindowLongPtrW, GetWindowLongPtrW, CreateWindowExW, WindowFromPoint, WaitMessage, UpdateWindow, UnregisterClassW, UnhookWindowsHookEx, TranslateMessage, TranslateMDISysAccel, TrackPopupMenu, SystemParametersInfoW, ShowWindow, ShowScrollBar, ShowOwnedPopups, ShowCaret, SetWindowRgn, SetWindowsHookExW, SetWindowTextW, SetWindowPos, SetWindowPlacement, SetTimer, SetScrollRange, SetScrollPos, SetScrollInfo, SetRect, SetPropW, SetParent, SetMenuItemInfoW, SetMenu, SetForegroundWindow, SetFocus, SetCursorPos, SetCursor, SetClipboardData, SetCapture, SetActiveWindow, SendMessageA, SendMessageW, ScrollWindow, ScreenToClient, RemovePropW, RemoveMenu, ReleaseDC, ReleaseCapture, RegisterWindowMessageW, RegisterClipboardFormatW, RegisterClassW, RedrawWindow, PostQuitMessage, PostMessageW, PeekMessageA, PeekMessageW, OpenClipboard, MsgWaitForMultipleObjectsEx, MsgWaitForMultipleObjects, MessageBoxW, MessageBeep, MapWindowPoints, MapVirtualKeyW, LoadStringW, LoadKeyboardLayoutW, LoadIconW, LoadCursorW, LoadBitmapW, KillTimer, IsZoomed, IsWindowVisible, IsWindowUnicode, IsWindowEnabled, IsWindow, IsIconic, IsDialogMessageA, IsDialogMessageW, IsClipboardFormatAvailable, IsChild, InvalidateRect, InsertMenuItemW, InsertMenuW, InflateRect, HideCaret, GetWindowThreadProcessId, GetWindowTextW, GetWindowRect, GetWindowPlacement, GetWindowDC, GetTopWindow, GetSystemMetrics, GetSystemMenu, GetSysColorBrush, GetSysColor, GetSubMenu, GetScrollRange, GetScrollPos, GetScrollInfo, GetScrollBarInfo, GetPropW, GetParent, GetWindow, GetMessageTime, GetMessagePos, GetMessageExtraInfo, GetMenuStringW, GetMenuState, GetMenuItemInfoW, GetMenuItemID, GetMenuItemCount, GetMenu, GetLastActivePopup, GetKeyboardState, GetKeyboardLayoutNameW, GetKeyboardLayoutList, GetKeyboardLayout, GetKeyState, GetKeyNameTextW, GetIconInfo, GetForegroundWindow, GetFocus, GetDlgCtrlID, GetDesktopWindow, GetDCEx, GetDC, GetCursorPos, GetCursor, GetClipboardData, GetClientRect, GetClassNameW, GetClassInfoExW, GetClassInfoW, GetCapture, GetActiveWindow, FrameRect, FindWindowExW, FindWindowW, FillRect, EnumWindows, EnumThreadWindows, EnumClipboardFormats, EnumChildWindows, EndPaint, EndMenu, EnableWindow, EnableScrollBar, EnableMenuItem, EmptyClipboard, DrawTextExW, DrawTextW, DrawMenuBar, DrawIconEx, DrawIcon, DrawFrameControl, DrawFocusRect, DrawEdge, DispatchMessageA, DispatchMessageW, DestroyWindow, DestroyMenu, DestroyIcon, DestroyCursor, DeleteMenu, DefWindowProcW, DefMDIChildProcW, DefFrameProcW, CreatePopupMenu, CreateMenu, CreateIcon, CreateAcceleratorTableW, CountClipboardFormats, CopyImage, CopyIcon, CloseClipboard, ClientToScreen, CheckMenuItem, CharUpperBuffW, CharUpperW, CharNextW, CharLowerBuffW, CharLowerW, CallWindowProcW, CallNextHookEx, BeginPaint, AdjustWindowRectEx, ActivateKeyboardLayout
      gdi32.dllUnrealizeObject, StretchDIBits, StretchBlt, StartPage, StartDocW, SetWindowOrgEx, SetWinMetaFileBits, SetViewportOrgEx, SetTextColor, SetStretchBltMode, SetRectRgn, SetROP2, SetPixel, SetMapMode, SetEnhMetaFileBits, SetDIBits, SetDIBColorTable, SetBrushOrgEx, SetBkMode, SetBkColor, SetAbortProc, SelectPalette, SelectObject, SaveDC, RoundRect, RestoreDC, ResizePalette, Rectangle, RectVisible, RealizePalette, Polyline, Polygon, PolyBezierTo, PolyBezier, PlayEnhMetaFile, Pie, PatBlt, MoveToEx, MaskBlt, LineTo, LPtoDP, IntersectClipRect, GetWindowOrgEx, GetWinMetaFileBits, GetTextMetricsW, GetTextExtentPointW, GetTextExtentPoint32W, GetTextAlign, GetSystemPaletteEntries, GetStockObject, GetRgnBox, GetPixel, GetPaletteEntries, GetObjectW, GetNearestPaletteIndex, GetEnhMetaFilePaletteEntries, GetEnhMetaFileHeader, GetEnhMetaFileDescriptionW, GetEnhMetaFileBits, GetDeviceCaps, GetDIBits, GetDIBColorTable, GetCurrentPositionEx, GetClipBox, GetBrushOrgEx, GetBitmapBits, GdiFlush, FrameRgn, ExtTextOutW, ExtFloodFill, ExcludeClipRect, EnumFontsW, EnumFontFamiliesExW, EndPage, EndDoc, Ellipse, DeleteObject, DeleteEnhMetaFile, DeleteDC, CreateSolidBrush, CreateRectRgn, CreatePenIndirect, CreatePalette, CreateICW, CreateHalftonePalette, CreateFontIndirectW, CreateEnhMetaFileW, CreateDIBitmap, CreateDIBSection, CreateDCW, CreateCompatibleDC, CreateCompatibleBitmap, CreateBrushIndirect, CreateBitmap, CopyEnhMetaFileW, CloseEnhMetaFile, Chord, BitBlt, ArcTo, Arc, AngleArc, AbortDoc
      version.dllVerQueryValueW, GetFileVersionInfoSizeW, GetFileVersionInfoW
      kernel32.dllWritePrivateProfileStringW, WriteFile, WideCharToMultiByte, WaitForSingleObject, WaitForMultipleObjectsEx, VirtualQueryEx, VirtualQuery, VirtualProtect, VirtualFree, VirtualAlloc, VerSetConditionMask, VerifyVersionInfoW, UnmapViewOfFile, TryEnterCriticalSection, SwitchToThread, SuspendThread, Sleep, SizeofResource, SetThreadPriority, SetThreadLocale, SetLastError, SetFilePointer, SetEvent, SetErrorMode, SetEndOfFile, ResumeThread, ResetEvent, RemoveDirectoryW, ReadFile, RaiseException, QueryPerformanceFrequency, QueryPerformanceCounter, QueryDosDeviceW, IsDebuggerPresent, MulDiv, MapViewOfFile, LockResource, LocalFree, LoadResource, LoadLibraryW, LeaveCriticalSection, IsValidLocale, InitializeCriticalSection, HeapSize, HeapFree, HeapDestroy, HeapCreate, HeapAlloc, GlobalUnlock, GlobalSize, GlobalHandle, GlobalLock, GlobalFree, GlobalFindAtomW, GlobalDeleteAtom, GlobalAlloc, GlobalAddAtomW, GetVolumeInformationW, GetVersionExW, GetVersion, GetUserDefaultLCID, GetTimeZoneInformation, GetTickCount, GetThreadPriority, GetThreadLocale, GetTempPathW, GetTempFileNameW, GetSystemDirectoryW, GetStdHandle, GetProcAddress, GetPrivateProfileStringW, GetModuleHandleW, GetModuleFileNameW, GetLogicalDriveStringsW, GetLocaleInfoW, GetLocalTime, GetLastError, GetFullPathNameW, GetFileSize, GetFileAttributesExW, GetFileAttributesW, GetExitCodeThread, GetDriveTypeW, GetDiskFreeSpaceW, GetDateFormatW, GetCurrentThreadId, GetCurrentThread, GetCurrentProcessId, GetCurrentProcess, GetComputerNameW, GetCPInfoExW, GetCPInfo, GetACP, FreeResource, FreeLibrary, FormatMessageW, FindResourceW, FindNextFileW, FindFirstFileW, FindClose, FileTimeToSystemTime, FileTimeToLocalFileTime, FileTimeToDosDateTime, EnumSystemLocalesW, EnumResourceNamesW, EnumCalendarInfoW, EnterCriticalSection, DeleteFileW, DeleteCriticalSection, CreateThread, CreateFileMappingW, CreateFileW, CreateEventW, CreateDirectoryW, CopyFileW, CompareStringA, CompareStringW, CloseHandle
      advapi32.dllRegUnLoadKeyW, RegSetValueExW, RegSaveKeyW, RegRestoreKeyW, RegReplaceKeyW, RegQueryValueExW, RegQueryInfoKeyW, RegOpenKeyExW, RegLoadKeyW, RegFlushKey, RegEnumValueW, RegEnumKeyExW, RegDeleteValueW, RegDeleteKeyW, RegCreateKeyExW, RegConnectRegistryW, RegCloseKey
      kernel32.dllSleep
      oleaut32.dllSafeArrayPtrOfIndex, SafeArrayGetUBound, SafeArrayGetLBound, SafeArrayCreate, VariantChangeType, VariantCopy, VariantClear, VariantInit
      oleaut32.dllGetErrorInfo, GetActiveObject, SysFreeString
      ole32.dllCreateStreamOnHGlobal, OleRegEnumVerbs, IsAccelerator, OleDraw, OleSetMenuDescriptor, OleUninitialize, OleInitialize, CoTaskMemFree, CoTaskMemAlloc, ProgIDFromCLSID, StringFromCLSID, CoCreateInstance, CoGetClassObject, CoUninitialize, CoInitialize, IsEqualGUID
      comctl32.dllInitializeFlatSB, FlatSB_SetScrollProp, FlatSB_SetScrollPos, FlatSB_SetScrollInfo, FlatSB_GetScrollPos, FlatSB_GetScrollInfo, _TrackMouseEvent, ImageList_GetImageInfo, ImageList_SetIconSize, ImageList_GetIconSize, ImageList_Write, ImageList_Read, ImageList_GetDragImage, ImageList_DragShowNolock, ImageList_DragMove, ImageList_DragLeave, ImageList_DragEnter, ImageList_EndDrag, ImageList_BeginDrag, ImageList_Copy, ImageList_LoadImageW, ImageList_GetIcon, ImageList_Remove, ImageList_DrawEx, ImageList_Replace, ImageList_Draw, ImageList_SetOverlayImage, ImageList_GetBkColor, ImageList_SetBkColor, ImageList_ReplaceIcon, ImageList_Add, ImageList_SetImageCount, ImageList_GetImageCount, ImageList_Destroy, ImageList_Create
      user32.dllEnumDisplayMonitors, GetMonitorInfoW, MonitorFromPoint, MonitorFromRect, MonitorFromWindow
      msvcrt.dllmemset, memcpy
      shell32.dllShell_NotifyIconW
      shell32.dllSHGetSpecialFolderPathW
      winspool.drvOpenPrinterW, EnumPrintersW, DocumentPropertiesW, ClosePrinter
      winspool.drvGetDefaultPrinterW
      winmm.dlltimeGetTime
      NameOrdinalAddress
      TMethodImplementationIntercept30x4985c0
      __dbk_fcall_wrapper20x416d30
      dbkFCallWrapperAddr10x8fcf58
      Language of compilation systemCountry where language is spokenMap
      EnglishUnited States
      DutchBelgium
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Dec 27, 2024 08:53:00.116209984 CET1.1.1.1192.168.2.90x8509No error (0)shed.dual-low.s-part-0035.t-0009.t-msedge.nets-part-0035.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
      Dec 27, 2024 08:53:00.116209984 CET1.1.1.1192.168.2.90x8509No error (0)s-part-0035.t-0009.t-msedge.net13.107.246.63A (IP address)IN (0x0001)false
      No statistics
      No system behavior
      No disassembly