Windows
Analysis Report
64.exe
Overview
General Information
Detection
Score: | 68 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- 64.exe (PID: 3852 cmdline:
"C:\Users\ user\Deskt op\64.exe" MD5: 43F0B9F0058030153D6114309D953FB3)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
OlympicDestroyer_1 | OlympicDestroyer Payload | kevoreilly |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
OlympicDestroyer_1 | OlympicDestroyer Payload | kevoreilly |
| |
OlympicDestroyer_1 | OlympicDestroyer Payload | kevoreilly |
|
Click to jump to signature section
AV Detection |
---|
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Integrated Neural Analysis Model: |
Source: | Code function: | 0_2_00007FF763E2A4A0 | |
Source: | Code function: | 0_2_00007FF763E252D0 | |
Source: | Code function: | 0_2_00007FF763E2A7A0 | |
Source: | Code function: | 0_2_00007FF763E26640 | |
Source: | Code function: | 0_2_00007FF763E255D0 | |
Source: | Code function: | 0_2_00007FF763E24CD0 | |
Source: | Code function: | 0_2_00007FF763E249D0 | |
Source: | Code function: | 0_2_00007FF763E24FD0 | |
Source: | Code function: | 0_2_00007FF763E23E70 | |
Source: | Code function: | 0_2_00007FF763E26E70 | |
Source: | Code function: | 0_2_00007FF763E25E10 |
Source: | Static PE information: |
Source: | Code function: | 0_2_00007FF763E27FB0 |
Source: | Binary or memory string: | memstr_2bef3a66-8 |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 0_2_00007FF763E21000 | |
Source: | Code function: | 0_2_00007FF763EA6510 | |
Source: | Code function: | 0_2_00007FF763EC84C0 | |
Source: | Code function: | 0_2_00007FF763E234B0 | |
Source: | Code function: | 0_2_00007FF763EE1480 | |
Source: | Code function: | 0_2_00007FF763EAA410 | |
Source: | Code function: | 0_2_00007FF763E293C0 | |
Source: | Code function: | 0_2_00007FF763EE02A0 | |
Source: | Code function: | 0_2_00007FF763E36290 | |
Source: | Code function: | 0_2_00007FF763EB81A0 | |
Source: | Code function: | 0_2_00007FF763EE0900 | |
Source: | Code function: | 0_2_00007FF763EEB84C | |
Source: | Code function: | 0_2_00007FF763EB282A | |
Source: | Code function: | 0_2_00007FF763E2A7A0 | |
Source: | Code function: | 0_2_00007FF763EED6B8 | |
Source: | Code function: | 0_2_00007FF763EEA674 | |
Source: | Code function: | 0_2_00007FF763E26640 | |
Source: | Code function: | 0_2_00007FF763E255D0 | |
Source: | Code function: | 0_2_00007FF763E505A0 | |
Source: | Code function: | 0_2_00007FF763E3DC50 | |
Source: | Code function: | 0_2_00007FF763EEAAF4 | |
Source: | Code function: | 0_2_00007FF763EE1A90 | |
Source: | Code function: | 0_2_00007FF763EEB0E0 | |
Source: | Code function: | 0_2_00007FF763EE0FC0 | |
Source: | Code function: | 0_2_00007FF763EB1F8F | |
Source: | Code function: | 0_2_00007FF763E2AF00 | |
Source: | Code function: | 0_2_00007FF763EAEEC0 | |
Source: | Code function: | 0_2_00007FF763E53EC0 | |
Source: | Code function: | 0_2_00007FF763EE3EB0 | |
Source: | Code function: | 0_2_00007FF763EBFE70 | |
Source: | Code function: | 0_2_00007FF763E26E70 | |
Source: | Code function: | 0_2_00007FF763E25E10 | |
Source: | Code function: | 0_2_00007FF763EE5DF0 | |
Source: | Code function: | 0_2_00007FF763EDFDF0 | |
Source: | Code function: | 0_2_00007FF763EE4D94 |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | Evasive API call chain: | graph_0-61287 |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Code function: | 0_2_00007FF763EE439C |
Source: | Code function: | 0_2_00007FF763E8D151 |
Source: | Code function: | 0_2_00007FF763E234B0 | |
Source: | Code function: | 0_2_00007FF763E2AF00 |
Source: | Code function: | 0_2_00007FF763E2C960 |
Source: | API coverage: |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Code function: | 0_2_00007FF763E27FB0 |
Source: | API call chain: | graph_0-61293 | ||
Source: | API call chain: | graph_0-61294 |
Source: | Code function: | 0_2_00007FF763EE5890 |
Source: | Code function: | 0_2_00007FF763EE439C |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Code function: | 0_2_00007FF763EE5890 | |
Source: | Code function: | 0_2_00007FF763EE2A80 |
Source: | Code function: | 0_2_00007FF763EED488 |
Source: | Code function: | 0_2_00007FF763EEA674 |
Stealing of Sensitive Information |
---|
Source: | Code function: | 0_2_00007FF763E240D0 |
Source: | Code function: | 0_2_00007FF763E2AF00 | |
Source: | Code function: | 0_2_00007FF763E2AF00 | |
Source: | Code function: | 0_2_00007FF763E2AF00 |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 2 Command and Scripting Interpreter | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Deobfuscate/Decode Files or Information | 1 OS Credential Dumping | 2 System Time Discovery | Remote Services | 11 Input Capture | 2 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 11 Native API | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 2 Obfuscated Files or Information | 11 Input Capture | 1 Security Software Discovery | Remote Desktop Protocol | 1 Archive Collected Data | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 DLL Side-Loading | 2 Credentials In Files | 1 File and Directory Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | 2 System Information Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
32% | ReversingLabs | Win64.Trojan.Generic | ||
43% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
s-part-0017.t-0009.t-msedge.net | 13.107.246.45 | true | false | high |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1585179 |
Start date and time: | 2025-01-07 09:12:08 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 2m 31s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 2 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 64.exe |
Detection: | MAL |
Classification: | mal68.spyw.winEXE@1/0@0/0 |
EGA Information: |
|
HCA Information: | Failed |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe
- Excluded IPs from analysis (whitelisted): 20.12.23.50, 13.107.246.45
- Excluded domains from analysis (whitelisted): otelrules.azureedge.net, slscr.update.microsoft.com, otelrules.afd.azureedge.net, sls.update.microsoft.com, azureedge-t-prod.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
s-part-0017.t-0009.t-msedge.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Bdaejec | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
File type: | |
Entropy (8bit): | 5.772282846568756 |
TrID: |
|
File name: | 64.exe |
File size: | 1'021'952 bytes |
MD5: | 43f0b9f0058030153d6114309d953fb3 |
SHA1: | cd093efca6d56f51a28b6b32d0c492aa655671ae |
SHA256: | cf30c55ec1f1083d8cc3fb4204e29ec50b39788a3c7c561d8d0ab2a9cba86336 |
SHA512: | 3009e1054373b876f5542d84c784a50440c69c1555182cc405b1e9395e0b928f26ad408cb627eb8f0b663ad124f979b6677a89b5eb73d04a13c981a5e93106e0 |
SSDEEP: | 12288:fEUEK/alBxScnB04n9Cf8gzLRrtB25JsGW2EEYGVp3Am:OK/alBxFB0FUgzLRrtUJFW |
TLSH: | 14259257E6B691E4D8B6D0389662722BBC713859833897D79B809B074B71FF0E93E340 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........H.u.).&.).&.).&..w&.).&.Qn&.).&.Qz&.).&.).&O).&..B&.).&..C&.).&..t&.).&Rich.).&................PE..d.....6g.........."......F. |
Icon Hash: | 00928e8e8686b000 |
Entrypoint: | 0x1400c4ac8 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x140000000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x6736E3EA [Fri Nov 15 06:02:18 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 2 |
File Version Major: | 5 |
File Version Minor: | 2 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 2 |
Import Hash: | e84d11c378c8e8f83080cc0f510539d2 |
Instruction |
---|
dec eax |
sub esp, 28h |
call 00007FA1546E93CCh |
dec eax |
add esp, 28h |
jmp 00007FA1546E0867h |
int3 |
int3 |
dec eax |
mov eax, esp |
dec eax |
mov dword ptr [eax+10h], ebx |
dec eax |
mov dword ptr [eax+18h], ebp |
dec eax |
mov dword ptr [eax+20h], esi |
mov dword ptr [eax+08h], ecx |
push edi |
dec eax |
sub esp, 20h |
dec eax |
mov ecx, edx |
dec eax |
mov ebx, edx |
call 00007FA1546EA0D7h |
mov ecx, dword ptr [ebx+18h] |
dec eax |
arpl ax, si |
test cl, FFFFFF82h |
jne 00007FA1546E0A29h |
call 00007FA1546E19EFh |
mov dword ptr [eax], 00000009h |
or dword ptr [ebx+18h], 20h |
or eax, FFFFFFFFh |
jmp 00007FA1546E0B49h |
test cl, 00000040h |
je 00007FA1546E0A1Fh |
call 00007FA1546E19D3h |
mov dword ptr [eax], 00000022h |
jmp 00007FA1546E09F4h |
xor edi, edi |
test cl, 00000001h |
je 00007FA1546E0A2Bh |
mov dword ptr [ebx+08h], edi |
test cl, 00000010h |
je 00007FA1546E0A9Fh |
dec eax |
mov eax, dword ptr [ebx+10h] |
and ecx, FFFFFFFEh |
dec eax |
mov dword ptr [ebx], eax |
mov dword ptr [ebx+18h], ecx |
mov eax, dword ptr [ebx+18h] |
mov dword ptr [ebx+08h], edi |
and eax, FFFFFFEFh |
or eax, 02h |
mov dword ptr [ebx+18h], eax |
test eax, 0000010Ch |
jne 00007FA1546E0A41h |
call 00007FA1546E9E54h |
dec eax |
add eax, 30h |
dec eax |
cmp ebx, eax |
je 00007FA1546E0A20h |
call 00007FA1546E9E46h |
dec eax |
add eax, 60h |
dec eax |
cmp ebx, eax |
jne 00007FA1546E0A1Dh |
mov ecx, esi |
call 00007FA1546E9DD6h |
test eax, eax |
jne 00007FA1546E0A1Ah |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xe6f04 | 0xb4 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0xfa000 | 0x654c | .pdata |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x101000 | 0x1004 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0xd6000 | 0x510 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0xd440a | 0xd4600 | 0368dfd044ab2d5f4fa05e78905b0888 | False | 0.3942714464390818 | data | 5.61843896377423 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0xd6000 | 0x11fec | 0x12000 | 981389091fb9f8c2e50ddf1acdc046b4 | False | 0.3441297743055556 | DIY-Thermocam raw data (Lepton 2.x), scale 9472-29440, spot sensor temperature 0.000000, unit celsius, color scheme 0, calibration: offset 39614081257132168796771975168.000000, slope 4503583248285072024404605534208.000000 | 5.271103778790476 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0xe8000 | 0x11310 | 0xac00 | 4dbbdef79fd7f1aa21fe58aae2582295 | False | 0.31018350290697677 | COM executable for DOS | 4.703260377877969 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.pdata | 0xfa000 | 0x654c | 0x6600 | bb52357a3ae264208681dde94b3157f8 | False | 0.5178079044117647 | data | 5.937374784127747 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x101000 | 0x1a9a | 0x1c00 | 51773b5929950467e765aea61a578906 | False | 0.21819196428571427 | data | 3.975109668791781 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
DLL | Import |
---|---|
KERNEL32.dll | CreateFileW, FreeLibrary, GetProcAddress, LoadLibraryW, SetCurrentDirectoryW, GetCurrentDirectoryW, lstrlenA, MultiByteToWideChar, GetFileSize, CreateFileA, GetPrivateProfileStringW, CopyFileW, GetTempPathW, lstrlenW, lstrcmpiW, FindClose, FindNextFileW, DeleteFileW, FindFirstFileW, lstrcpyW, lstrcpyA, FlushViewOfFile, GetProcessHeap, OutputDebugStringW, OutputDebugStringA, WaitForSingleObjectEx, WaitForSingleObject, WriteFile, WideCharToMultiByte, UnmapViewOfFile, UnlockFileEx, UnlockFile, SystemTimeToFileTime, Sleep, SetFilePointer, SetEndOfFile, QueryPerformanceCounter, MapViewOfFile, LockFileEx, LockFile, LoadLibraryA, HeapCompact, HeapValidate, HeapSize, HeapReAlloc, HeapFree, ReadFile, HeapCreate, HeapAlloc, GetVersionExW, GetVersionExA, GetTickCount, GetTempPathA, GetSystemTimeAsFileTime, GetSystemTime, GetSystemInfo, GetLastError, GetFullPathNameW, GetFullPathNameA, GetFileAttributesExW, GetFileAttributesW, GetFileAttributesA, GetDiskFreeSpaceW, GetDiskFreeSpaceA, GetCurrentProcessId, FormatMessageW, FormatMessageA, FlushFileBuffers, DeleteFileA, CreateMutexW, CreateFileMappingW, CreateFileMappingA, AreFileApisANSI, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, TryEnterCriticalSection, LeaveCriticalSection, GetCurrentThreadId, CompareStringW, WriteConsoleW, SetStdHandle, LCMapStringW, GetStringTypeW, GetConsoleMode, GetConsoleCP, LocalAlloc, LocalFree, GetCommandLineW, ExitProcess, OpenEventW, SetEvent, HeapDestroy, CloseHandle, GetFileType, InitializeCriticalSectionAndSpinCount, SetHandleCount, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetModuleFileNameA, RtlLookupFunctionEntry, RtlUnwindEx, RaiseException, RtlPcToFileHeader, EncodePointer, DecodePointer, ExitThread, CreateThread, GetCommandLineA, GetStartupInfoW, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, RtlVirtualUnwind, RtlCaptureContext, TerminateProcess, GetCurrentProcess, HeapSetInformation, GetVersion, FlsGetValue, FlsSetValue, FlsFree, SetLastError, FlsAlloc, GetTimeZoneInformation, GetModuleHandleW, GetStdHandle, GetModuleFileNameW, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, SetEnvironmentVariableA |
USER32.dll | wsprintfW |
SHELL32.dll | SHGetKnownFolderPath, CommandLineToArgvW |
SHLWAPI.dll | StrCmpNIW, StrStrIW |
ole32.dll | StringFromGUID2, CoCreateGuid, CoInitialize, CoUninitialize, CoTaskMemFree |
ADVAPI32.dll | RegCloseKey, RegCreateKeyExW, RegSetValueExW, RegGetValueW |
CRYPT32.dll | CryptStringToBinaryA, CryptUnprotectData |
Wlanapi.dll | WlanGetProfileList, WlanEnumInterfaces, WlanOpenHandle, WlanGetProfile, WlanCloseHandle |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 7, 2025 09:13:09.204920053 CET | 1.1.1.1 | 192.168.2.6 | 0x9b7d | No error (0) | s-part-0017.t-0009.t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 7, 2025 09:13:09.204920053 CET | 1.1.1.1 | 192.168.2.6 | 0x9b7d | No error (0) | 13.107.246.45 | A (IP address) | IN (0x0001) | false |
Target ID: | 0 |
Start time: | 03:13:10 |
Start date: | 07/01/2025 |
Path: | C:\Users\user\Desktop\64.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff763e20000 |
File size: | 1'021'952 bytes |
MD5 hash: | 43F0B9F0058030153D6114309D953FB3 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Execution Graph
Execution Coverage: | 0% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 95.2% |
Total number of Nodes: | 21 |
Total number of Limit Nodes: | 1 |
Graph
Function 00007FF763E21000 Relevance: 28.1, APIs: 15, Strings: 1, Instructions: 129registryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E2C960 Relevance: 127.0, APIs: 54, Strings: 18, Instructions: 968libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E2AF00 Relevance: 93.1, APIs: 37, Strings: 16, Instructions: 327memoryfileCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E234B0 Relevance: 82.6, APIs: 37, Strings: 10, Instructions: 392memoryfileCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E27FB0 Relevance: 63.2, APIs: 29, Strings: 7, Instructions: 222memoryfilestringCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E255D0 Relevance: 47.6, APIs: 19, Strings: 8, Instructions: 369memoryencryptionstringCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E26640 Relevance: 47.6, APIs: 19, Strings: 8, Instructions: 365memoryencryptionstringCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E25E10 Relevance: 47.6, APIs: 19, Strings: 8, Instructions: 365memoryencryptionstringCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E26E70 Relevance: 47.6, APIs: 19, Strings: 8, Instructions: 363memoryencryptionstringCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E2A7A0 Relevance: 45.8, APIs: 18, Strings: 8, Instructions: 333memoryencryptionCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EED6B8 Relevance: 40.7, APIs: 22, Strings: 1, Instructions: 465COMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E252D0 Relevance: 38.6, APIs: 18, Strings: 4, Instructions: 134memoryfileencryptionCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E24CD0 Relevance: 38.6, APIs: 18, Strings: 4, Instructions: 134memoryfileencryptionCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E249D0 Relevance: 38.6, APIs: 18, Strings: 4, Instructions: 134memoryfileencryptionCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E24FD0 Relevance: 38.6, APIs: 18, Strings: 4, Instructions: 134memoryfileencryptionCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E2A4A0 Relevance: 36.9, APIs: 17, Strings: 4, Instructions: 134memoryfileencryptionCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EE5DF0 Relevance: 34.0, APIs: 17, Strings: 2, Instructions: 723COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E240D0 Relevance: 28.1, APIs: 13, Strings: 3, Instructions: 102memoryfileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EE439C Relevance: 26.3, APIs: 13, Strings: 2, Instructions: 68libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EE4D94 Relevance: 23.5, APIs: 12, Strings: 1, Instructions: 731COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EEB84C Relevance: 15.9, APIs: 5, Strings: 4, Instructions: 159fileCOMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EEA674 Relevance: 15.3, APIs: 10, Instructions: 292timeCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EE3EB0 Relevance: 13.7, APIs: 9, Instructions: 234COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EC84C0 Relevance: 12.6, APIs: 2, Strings: 4, Instructions: 2063COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E293C0 Relevance: 12.3, APIs: 2, Strings: 6, Instructions: 300COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EE2A80 Relevance: 12.1, APIs: 8, Instructions: 67COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E3DC50 Relevance: 9.2, APIs: 4, Strings: 1, Instructions: 452memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EE5890 Relevance: 9.1, APIs: 6, Instructions: 80COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EED488 Relevance: 7.5, APIs: 5, Instructions: 39timethreadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E23E70 Relevance: 7.1, APIs: 1, Strings: 3, Instructions: 77encryptionCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EEB0E0 Relevance: 4.7, APIs: 3, Instructions: 207COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EEAAF4 Relevance: 3.2, APIs: 2, Instructions: 235COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EE1A90 Relevance: .7, Instructions: 695COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EBFE70 Relevance: .6, Instructions: 646COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E36290 Relevance: .5, Instructions: 468COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EE1480 Relevance: .3, Instructions: 345COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E505A0 Relevance: .3, Instructions: 310COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EDFDF0 Relevance: .2, Instructions: 229COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EE0FC0 Relevance: .2, Instructions: 215COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EE02A0 Relevance: .2, Instructions: 175COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EE0900 Relevance: .1, Instructions: 145COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EF0528 Relevance: 107.7, APIs: 86, Instructions: 180COMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E224F0 Relevance: 42.2, APIs: 17, Strings: 7, Instructions: 178memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EEFA98 Relevance: 38.6, APIs: 16, Strings: 6, Instructions: 136libraryloaderCOMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E24350 Relevance: 33.4, APIs: 13, Strings: 6, Instructions: 153memoryfileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E284F0 Relevance: 31.8, APIs: 9, Strings: 9, Instructions: 333COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E2A330 Relevance: 28.1, APIs: 13, Strings: 3, Instructions: 71memoryfileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E24860 Relevance: 28.1, APIs: 13, Strings: 3, Instructions: 71memoryfileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E246F0 Relevance: 28.1, APIs: 13, Strings: 3, Instructions: 71memoryfileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E213F0 Relevance: 24.9, APIs: 3, Strings: 11, Instructions: 405COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E222A0 Relevance: 24.6, APIs: 7, Strings: 7, Instructions: 85libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EEC84C Relevance: 19.6, APIs: 13, Instructions: 90COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E21FC0 Relevance: 19.4, APIs: 8, Strings: 3, Instructions: 115memoryfileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EEE1E8 Relevance: 18.1, APIs: 12, Instructions: 149COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E29FE0 Relevance: 17.6, APIs: 8, Strings: 2, Instructions: 115memoryfileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EF4750 Relevance: 16.8, APIs: 11, Instructions: 254COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E277E0 Relevance: 15.9, APIs: 5, Strings: 4, Instructions: 197memorystringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E27E30 Relevance: 15.8, APIs: 6, Strings: 3, Instructions: 49stringregistrymemoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EEE618 Relevance: 15.1, APIs: 10, Instructions: 123COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E52800 Relevance: 14.4, APIs: 3, Strings: 5, Instructions: 382COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E30374 Relevance: 14.3, APIs: 2, Strings: 6, Instructions: 330COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E22B90 Relevance: 14.1, APIs: 4, Strings: 4, Instructions: 100memorystringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E22DF0 Relevance: 14.1, APIs: 4, Strings: 4, Instructions: 100memorystringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E22940 Relevance: 14.1, APIs: 4, Strings: 4, Instructions: 97memorystringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E23280 Relevance: 14.1, APIs: 4, Strings: 4, Instructions: 92memorystringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E23050 Relevance: 14.1, APIs: 4, Strings: 4, Instructions: 92memorystringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E212E0 Relevance: 14.1, APIs: 4, Strings: 4, Instructions: 54registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EEB630 Relevance: 13.6, APIs: 9, Instructions: 98COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E27CD0 Relevance: 13.6, APIs: 5, Strings: 4, Instructions: 75COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E95360 Relevance: 12.7, APIs: 1, Strings: 6, Instructions: 413COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EEED74 Relevance: 12.1, APIs: 8, Instructions: 59COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EDD060 Relevance: 10.8, APIs: 1, Strings: 5, Instructions: 345COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EED5D4 Relevance: 10.6, APIs: 7, Instructions: 67COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EEDE18 Relevance: 10.6, APIs: 7, Instructions: 67COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EE4570 Relevance: 9.1, APIs: 6, Instructions: 63threadCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EE7E50 Relevance: 9.0, APIs: 6, Instructions: 37threadCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E90700 Relevance: 9.0, APIs: 3, Strings: 2, Instructions: 269COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E495F0 Relevance: 9.0, APIs: 3, Strings: 2, Instructions: 268COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E6EDD0 Relevance: 8.9, APIs: 1, Strings: 4, Instructions: 160COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EE3ABC Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 56COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E21E70 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 56registrymemoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E27F20 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 27registrymemoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E2AE70 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 27registrymemoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EF0FD8 Relevance: 7.6, APIs: 5, Instructions: 116COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EE4ADC Relevance: 7.6, APIs: 5, Instructions: 115COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EF0348 Relevance: 7.6, APIs: 5, Instructions: 102COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EE970C Relevance: 7.6, APIs: 5, Instructions: 72COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EF0BCC Relevance: 7.5, APIs: 5, Instructions: 31COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E312B0 Relevance: 7.2, APIs: 1, Strings: 3, Instructions: 180COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EEB460 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 17libraryloaderCOMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E2E1B0 Relevance: 6.4, APIs: 5, Instructions: 179stringmemoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E2E6A0 Relevance: 6.4, APIs: 5, Instructions: 175stringmemoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EEC150 Relevance: 6.0, APIs: 4, Instructions: 45COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EECA20 Relevance: 6.0, APIs: 4, Instructions: 29COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E28D90 Relevance: 5.6, APIs: 1, Strings: 2, Instructions: 314COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763E6FAA9 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 71memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EE2880 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 70COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF763EE31EC Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 44COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|