Analysis Report c541a313a0492231a3_wmiprvse.exe
Overview
General Information
Detection
Score: | 5 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
Startup |
---|
|
Malware Configuration |
---|
No configs have been found |
---|
Yara Overview |
---|
No yara matches |
---|
Sigma Overview |
---|
No Sigma rule has matched |
---|
Signature Overview |
---|
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | Code function: | 0_2_00007FF6EE69F110 | |
Source: | Code function: | 0_2_00007FF6EE698490 |
Source: | Code function: | 0_2_00007FF6EE69AC50 | |
Source: | Code function: | 0_2_00007FF6EE69C334 | |
Source: | Code function: | 0_2_00007FF6EE6AFF50 | |
Source: | Code function: | 0_2_00007FF6EE6BDFD0 | |
Source: | Code function: | 0_2_00007FF6EE6B1E60 | |
Source: | Code function: | 0_2_00007FF6EE6D5F00 | |
Source: | Code function: | 0_2_00007FF6EE6AFC40 | |
Source: | Code function: | 0_2_00007FF6EE6CE9E8 | |
Source: | Code function: | 0_2_00007FF6EE6AEA6C | |
Source: | Code function: | 0_2_00007FF6EE6C9B00 | |
Source: | Code function: | 0_2_00007FF6EE6D0AC4 | |
Source: | Code function: | 0_2_00007FF6EE69775C | |
Source: | Code function: | 0_2_00007FF6EE6AF868 | |
Source: | Code function: | 0_2_00007FF6EE69B8FC | |
Source: | Code function: | 0_2_00007FF6EE6938C4 | |
Source: | Code function: | 0_2_00007FF6EE6BD580 | |
Source: | Code function: | 0_2_00007FF6EE6B34EC | |
Source: | Code function: | 0_2_00007FF6EE6C728C | |
Source: | Code function: | 0_2_00007FF6EE6B1264 | |
Source: | Code function: | 0_2_00007FF6EE6922D0 |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Classification label: |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Code function: | 0_2_00007FF6EE698490 |
Source: | API coverage: |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Process information queried: | Jump to behavior |
Source: | Code function: | 0_2_00007FF6EE69F260 |
Source: | Code function: | 0_2_00007FF6EE698490 |
Source: | Code function: | 0_2_00007FF6EE699E60 |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Code function: | 0_2_00007FF6EE6A2CC0 | |
Source: | Code function: | 0_2_00007FF6EE6A293C |
Source: | Code function: | 0_2_00007FF6EE69C334 |
Source: | Code function: | 0_2_00007FF6EE69C334 |
Source: | Code function: | 0_2_00007FF6EE6A2E94 |
Mitre Att&ck Matrix |
---|
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | Direct Volume Access | OS Credential Dumping | System Time Discovery1 | Remote Services | Archive Collected Data1 | Exfiltration Over Other Network Medium | Encrypted Channel1 | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Security Software Discovery2 | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | Junk Data | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Process Discovery1 | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | Steganography | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | Binary Padding | NTDS | System Information Discovery2 | Distributed Component Object Model | Input Capture | Scheduled Transfer | Protocol Impersonation | SIM Card Swap | Carrier Billing Fraud |
Behavior Graph |
---|
Screenshots |
---|
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Antivirus, Machine Learning and Genetic Malware Detection |
---|
Initial Sample |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse | ||
0% | Metadefender | Browse | ||
0% | ReversingLabs |
Dropped Files |
---|
No Antivirus matches |
---|
Unpacked PE Files |
---|
No Antivirus matches |
---|
Domains |
---|
No Antivirus matches |
---|
URLs |
---|
No Antivirus matches |
---|
Domains and IPs |
---|
General Information |
---|
Joe Sandbox Version: | 31.0.0 Red Diamond |
Analysis ID: | 328714 |
Start date: | 09.12.2020 |
Start time: | 16:20:11 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 14m 14s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | c541a313a0492231a3_wmiprvse.exe |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 29 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean5.winEXE@1/0@0/0 |
EGA Information: |
|
HDC Information: |
|
HCA Information: | Failed |
Cookbook Comments: |
|
Warnings: | Show All
|
Simulations |
---|
Behavior and APIs |
---|
No simulations |
---|
Joe Sandbox View / Context |
---|
Created / dropped Files |
---|
No created / dropped files found |
---|
Static File Info |
---|
General | |
---|---|
File type: | |
Entropy (8bit): | 6.2141826593596825 |
TrID: |
|
File name: | c541a313a0492231a3_wmiprvse.exe |
File size: | 496640 |
MD5: | 60ff40cfd7fb8fe41ee4fe9ae5fe1c51 |
SHA1: | 3ea7cc066317ac45f963c2227c4c7c50aa16eb7c |
SHA256: | 2198a7b58bccb758036b969ddae6cc2ece07565e2659a7c541a313a0492231a3 |
SHA512: | 991e38e2b480ffc58ec5ade9dcc8747a57b29fbc9b12397a8010e73143c4dfb420e5248a0c3acf0832812c0e804080ed5a83952b9c05419d93763372ece775c3 |
SSDEEP: | 12288:ahBzXzR4mnIu0CWQjONc3XmvzjnyBEIl/t8:qumnGDjnyBll/ |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........9.8.X.k.X.k.X.k. .k.X.k.3.j.X.k.3.j.X.k.X.k.Y.k.3.j.X.k.3.j.X.k.3.j.X.k.3wk.X.k.3.j.X.kRich.X.k........................PE..d.. |
File Icon |
---|
Icon Hash: | a4e0a6beb8aea0a0 |
Static PE Info |
---|
General | |
---|---|
Entrypoint: | 0x140012580 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x140000000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE |
DLL Characteristics: | GUARD_CF, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT, HIGH_ENTROPY_VA |
Time Stamp: | 0x5DA7AB91 [Wed Oct 16 23:45:21 2019 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 10 |
OS Version Minor: | 0 |
File Version Major: | 10 |
File Version Minor: | 0 |
Subsystem Version Major: | 10 |
Subsystem Version Minor: | 0 |
Import Hash: | b71cb3ac5c352bec857c940cbc95f0f3 |
Entrypoint Preview |
---|
Instruction |
---|
dec eax |
sub esp, 28h |
call 00007F0828F0D950h |
dec eax |
add esp, 28h |
jmp 00007F0828F0D04Bh |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
dec eax |
mov dword ptr [esp+08h], ebx |
dec eax |
mov dword ptr [esp+10h], edi |
inc ecx |
push esi |
dec eax |
sub esp, 000000B0h |
and dword ptr [esp+20h], 00000000h |
dec eax |
lea ecx, dword ptr [esp+40h] |
call dword ptr [00039F7Dh] |
nop |
dec eax |
mov eax, dword ptr [00000030h] |
dec eax |
mov ebx, dword ptr [eax+08h] |
xor edi, edi |
xor eax, eax |
dec eax |
cmpxchg dword ptr [00054AD2h], ebx |
je 00007F0828F0D04Ch |
dec eax |
cmp eax, ebx |
jne 00007F0828F0D05Ch |
mov edi, 00000001h |
mov eax, dword ptr [00054AC8h] |
cmp eax, 01h |
jne 00007F0828F0D059h |
lea ecx, dword ptr [eax+1Eh] |
call 00007F0828F0D7E3h |
jmp 00007F0828F0D0BCh |
mov ecx, 000003E8h |
call dword ptr [0003A006h] |
jmp 00007F0828F0D009h |
mov eax, dword ptr [00054AA6h] |
test eax, eax |
jne 00007F0828F0D09Bh |
mov dword ptr [00054A98h], 00000001h |
dec esp |
lea esi, dword ptr [0003A359h] |
dec eax |
lea ebx, dword ptr [0003A33Ah] |
dec eax |
mov dword ptr [esp+30h], ebx |
mov dword ptr [esp+24h], eax |
dec ecx |
cmp ebx, esi |
jnc 00007F0828F0D067h |
test eax, eax |
jne 00007F0828F0D067h |
dec eax |
cmp dword ptr [ebx], 00000000h |
je 00007F0828F0D052h |
dec eax |
mov eax, dword ptr [ebx] |
dec eax |
mov ecx, dword ptr [0003A2B0h] |
Rich Headers |
---|
Programming Language: |
|
Data Directories |
---|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x63420 | 0x21c | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x6d000 | 0xfa48 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x68000 | 0x36cc | .pdata |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x7d000 | 0xd00 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x51e80 | 0x54 | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x4af70 | 0x118 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x4c358 | 0x598 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x62bbc | 0x1a0 | .rdata |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Sections |
---|
Name | Virtual Address | Virtual Size | Raw Size | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x4711c | 0x47200 | False | 0.406775181239 | data | 6.24353319739 | IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ |
.rdata | 0x49000 | 0x1bc4c | 0x1be00 | False | 0.296559697309 | data | 4.38560302658 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x65000 | 0x2588 | 0x1c00 | False | 0.1787109375 | data | 4.17250851172 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ |
.pdata | 0x68000 | 0x36cc | 0x3800 | False | 0.505929129464 | data | 5.64407195399 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.didat | 0x6c000 | 0x1d8 | 0x200 | False | 0.3125 | data | 2.60351504795 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ |
.rsrc | 0x6d000 | 0xfa48 | 0xfc00 | False | 0.70372953869 | data | 6.8321114608 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x7d000 | 0xd00 | 0xe00 | False | 0.344308035714 | data | 5.31711045203 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Resources |
---|
Name | RVA | Size | Type | Language | Country |
---|---|---|---|---|---|
RT_ICON | 0x6d9c0 | 0x668 | data | English | United States |
RT_ICON | 0x6e028 | 0x2e8 | dBase IV DBT of @.DBF, block length 512, next free block index 40, next free block 2298443911, next used block 8849520 | English | United States |
RT_ICON | 0x6e310 | 0x1e8 | data | English | United States |
RT_ICON | 0x6e4f8 | 0x128 | GLS_BINARY_LSB_FIRST | English | United States |
RT_ICON | 0x6e620 | 0xea8 | data | English | United States |
RT_ICON | 0x6f4c8 | 0x8a8 | dBase IV DBT of @.DBF, block length 1024, next free block index 40, next free block 0, next used block 0 | English | United States |
RT_ICON | 0x6fd70 | 0x6c8 | data | English | United States |
RT_ICON | 0x70438 | 0x568 | GLS_BINARY_LSB_FIRST | English | United States |
RT_ICON | 0x709a0 | 0x7ba8 | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | English | United States |
RT_ICON | 0x78548 | 0x25a8 | data | English | United States |
RT_ICON | 0x7aaf0 | 0x10a8 | data | English | United States |
RT_ICON | 0x7bb98 | 0x988 | data | English | United States |
RT_ICON | 0x7c520 | 0x468 | GLS_BINARY_LSB_FIRST | English | United States |
RT_GROUP_ICON | 0x7c988 | 0xbc | data | English | United States |
RT_VERSION | 0x6d628 | 0x398 | data | English | United States |
RT_MANIFEST | 0x6d390 | 0x296 | XML 1.0 document, ASCII text, with CRLF line terminators | English | United States |
Imports |
---|
DLL | Import |
---|---|
msvcrt.dll | _cexit, _exit, _ismbblead, __set_app_type, memcmp, __setusermatherr, _initterm, _acmdln, __getmainargs, _onexit, __dllonexit, _amsg_exit, _fmode, _XcptFilter, ??8type_info@@QEBAHAEBV0@@Z, ?what@exception@@UEBAPEBDXZ, ??1exception@@UEAA@XZ, ??0exception@@QEAA@AEBV0@@Z, ??0exception@@QEAA@AEBQEBDH@Z, __CxxFrameHandler3, _unlock, _lock, ??1type_info@@UEAA@XZ, ?terminate@@YAXXZ, ??0exception@@QEAA@AEBQEBD@Z, memmove, memcpy, _commode, _CxxThrowException, __C_specific_handler, _purecall, _itow, wcstok, _vsnwprintf, exit, memset |
ntdll.dll | RtlNtStatusToDosError, RtlAddAccessAllowedAce, RtlLengthSid, EtwGetTraceLoggerHandle, EtwGetTraceEnableLevel, EtwGetTraceEnableFlags, NtQuerySystemInformation, RtlCreateAcl, EtwRegisterTraceGuidsW, EtwUnregisterTraceGuids, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, EtwTraceMessage |
api-ms-win-core-synch-l1-1-0.dll | SetEvent, EnterCriticalSection, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, CreateEventW, WaitForSingleObject, LeaveCriticalSection, WaitForMultipleObjectsEx |
api-ms-win-core-heap-l2-1-0.dll | LocalAlloc, LocalFree |
api-ms-win-security-base-l1-1-0.dll | MakeSelfRelativeSD, GetSecurityDescriptorLength, AddAce, MakeAbsoluteSD, CopySid, GetLengthSid, InitializeSecurityDescriptor, AccessCheck, MapGenericMask, AllocateAndInitializeSid, FreeSid, GetTokenInformation, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, InitializeAcl, SetSecurityDescriptorDacl, GetAclInformation, RevertToSelf, ImpersonateLoggedOnUser |
api-ms-win-core-errorhandling-l1-1-0.dll | GetLastError, UnhandledExceptionFilter, SetUnhandledExceptionFilter |
api-ms-win-core-libraryloader-l1-2-0.dll | FreeLibrary, GetModuleHandleExW, GetProcAddress, GetModuleFileNameW, GetModuleHandleW |
api-ms-win-core-handle-l1-1-0.dll | DuplicateHandle, CloseHandle |
api-ms-win-core-processthreads-l1-1-0.dll | GetCurrentThreadId, GetCurrentThread, TlsFree, CreateThread, OpenThreadToken, SetThreadToken, GetCurrentProcess, SwitchToThread, TlsAlloc, GetStartupInfoW, TerminateProcess, GetCurrentProcessId, OpenProcessToken |
api-ms-win-core-processenvironment-l1-1-0.dll | GetCommandLineW |
api-ms-win-core-string-l1-1-0.dll | CompareStringW, GetStringTypeExW |
api-ms-win-core-heap-l1-1-0.dll | GetProcessHeap, HeapAlloc, HeapFree, HeapCreate, HeapDestroy, HeapSetInformation |
api-ms-win-core-registry-l1-1-0.dll | RegCloseKey, RegSetValueExW, RegQueryValueExW, RegDeleteKeyExW, RegCreateKeyExW, RegOpenKeyExW |
api-ms-win-eventing-provider-l1-1-0.dll | EventRegister, EventWrite, EventUnregister |
api-ms-win-core-synch-l1-2-0.dll | Sleep |
api-ms-win-core-memory-l1-1-0.dll | MapViewOfFile, CreateFileMappingW, OpenFileMappingW, UnmapViewOfFile |
api-ms-win-core-sysinfo-l1-1-0.dll | GetSystemTimeAsFileTime, GetTickCount |
api-ms-win-core-localization-l1-2-0.dll | LCMapStringW |
api-ms-win-core-threadpool-legacy-l1-1-0.dll | ChangeTimerQueueTimer |
api-ms-win-core-profile-l1-1-0.dll | QueryPerformanceCounter |
api-ms-win-core-apiquery-l1-1-0.dll | ApiSetQueryApiSetPresence |
FastProx.dll | ?Release@CWbemCallSecurity@@UEAAKXZ, ?QueryInterface@CWbemCallSecurity@@UEAAJAEBU_GUID@@PEAPEAX@Z, ?SetThreadSecurity@CWbemCallSecurity@@UEAAJPEAU_IWmiThreadSecHandle@@@Z, ?GetThreadSecurity@CWbemCallSecurity@@UEAAJW4tag_WMI_THREAD_SECURITY_ORIGIN@@PEAPEAU_IWmiThreadSecHandle@@@Z, ?AddRef@CWbemCallSecurity@@UEAAKXZ, ?New@CWbemCallSecurity@@SAPEAV1@XZ |
NCObjAPI.DLL | WmiCreateObjectWithFormat, WmiDestroyObject, WmiEventSourceDisconnect, WmiSetAndCommitObject, WmiEventSourceConnect |
wbemcomn.dll | BreakOnDbgAndRenterLoop, GetMemLogObject, ?Write@CMemoryLog@@QEAAXJ@Z, _ThrowMemoryException_, ?GetPreferredLanguages@CMUILocale@@SAJKPEAPEAGPEAK@Z, ?_Free@CMUILocale@@SAHPEAX@Z, ?SetPreferredLanguages@CMUILocale@@SAJKPEBGPEAK@Z, ?PublishProviderStarted@CPublishWMIOperationEvent@@SAJPEAGJ0K0@Z, ?Init@CPublishWMIOperationEvent@@SAJXZ |
api-ms-win-core-delayload-l1-1-1.dll | ResolveDelayLoadedAPI |
api-ms-win-core-delayload-l1-1-0.dll | DelayLoadFailureHook |
Version Infos |
---|
Description | Data |
---|---|
LegalCopyright | Microsoft Corporation. All rights reserved. |
InternalName | Wmiprvse.exe |
FileVersion | 10.0.19041.546 (WinBuild.160101.0800) |
CompanyName | Microsoft Corporation |
ProductName | Microsoft Windows Operating System |
ProductVersion | 10.0.19041.546 |
FileDescription | WMI Provider Host |
OriginalFilename | Wmiprvse.exe |
Translation | 0x0409 0x04b0 |
Possible Origin |
---|
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Network Behavior |
---|
No network behavior found |
---|
Code Manipulations |
---|
Statistics |
---|
CPU Usage |
---|
Click to jump to process
Memory Usage |
---|
Click to jump to process
System Behavior |
---|
General |
---|
Start time: | 16:21:02 |
Start date: | 09/12/2020 |
Path: | C:\Users\user\Desktop\c541a313a0492231a3_wmiprvse.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6ee690000 |
File size: | 496640 bytes |
MD5 hash: | 60FF40CFD7FB8FE41EE4FE9AE5FE1C51 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Disassembly |
---|
Code Analysis |
---|
Execution Graph |
---|
Execution Coverage: | 3.3% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 24.1% |
Total number of Nodes: | 630 |
Total number of Limit Nodes: | 15 |
Graph
Executed Functions |
---|
Function 00007FF6EE69C334, Relevance: 96.8, APIs: 54, Strings: 1, Instructions: 556memoryCOMMON
Control-flow Graph |
---|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE69AC50, Relevance: 18.2, APIs: 12, Instructions: 238sleepCOMMON
Control-flow Graph |
---|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE698490, Relevance: 10.6, APIs: 3, Strings: 3, Instructions: 139nativeCOMMON
Control-flow Graph |
---|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE69F110, Relevance: 3.0, APIs: 2, Instructions: 18nativewindowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE69B4D0, Relevance: 19.5, APIs: 10, Strings: 1, Instructions: 248memorysynchronizationCOMMON
Control-flow Graph |
---|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE69C890, Relevance: 15.8, APIs: 8, Strings: 1, Instructions: 66windowregistryCOMMON
Control-flow Graph |
---|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph |
---|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE69C260, Relevance: 14.1, APIs: 7, Strings: 1, Instructions: 105fileCOMMON
Control-flow Graph |
---|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph |
---|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE697C2C, Relevance: 10.9, APIs: 7, Instructions: 361memoryCOMMON
Control-flow Graph |
---|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE69DBEC, Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 101memoryCOMMON
Control-flow Graph |
---|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE69DA94, Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 84memoryCOMMON
Control-flow Graph |
---|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE69C69C, Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 80registrymemoryCOMMON
Control-flow Graph |
---|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE69C174, Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 71COMMON
Control-flow Graph |
---|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE69F884, Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 39registryCOMMON
Control-flow Graph |
---|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE69F978, Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 31registryCOMMON
Control-flow Graph |
---|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE69B320, Relevance: 1.5, APIs: 1, Instructions: 29synchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Non-executed Functions |
---|
Function 00007FF6EE6922D0, Relevance: 160.6, APIs: 66, Strings: 25, Instructions: 1398memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6D0AC4, Relevance: 120.0, APIs: 48, Strings: 20, Instructions: 961COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6B1264, Relevance: 65.2, APIs: 35, Strings: 2, Instructions: 493memoryregistryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6BDFD0, Relevance: 63.5, APIs: 9, Strings: 27, Instructions: 475memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6BD580, Relevance: 63.5, APIs: 9, Strings: 27, Instructions: 475memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6B34EC, Relevance: 45.9, APIs: 25, Strings: 1, Instructions: 383memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6B1E60, Relevance: 40.7, APIs: 14, Strings: 9, Instructions: 488registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6938C4, Relevance: 33.4, APIs: 15, Strings: 4, Instructions: 200registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6D5F00, Relevance: 26.9, APIs: 13, Strings: 2, Instructions: 609COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6AEA6C, Relevance: 17.7, APIs: 9, Strings: 1, Instructions: 162windowsleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE69775C, Relevance: 12.8, APIs: 8, Instructions: 770synchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6C9B00, Relevance: 12.6, APIs: 8, Instructions: 594synchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6AF868, Relevance: 12.1, APIs: 8, Instructions: 135sleepwindowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6AFF50, Relevance: 12.1, APIs: 8, Instructions: 109sleepwindowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6AFC40, Relevance: 12.1, APIs: 8, Instructions: 105windowsleepCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6C728C, Relevance: 9.6, APIs: 6, Instructions: 550synchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6A2E94, Relevance: 9.0, APIs: 6, Instructions: 49timethreadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE694E10, Relevance: 42.5, APIs: 16, Strings: 8, Instructions: 466memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE69BCD4, Relevance: 30.3, APIs: 20, Instructions: 259memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6A0A50, Relevance: 28.3, APIs: 11, Strings: 5, Instructions: 344memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6933F0, Relevance: 24.9, APIs: 4, Strings: 10, Instructions: 390COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6A12B0, Relevance: 24.8, APIs: 9, Strings: 5, Instructions: 312memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6A02F0, Relevance: 24.8, APIs: 9, Strings: 5, Instructions: 311memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE694028, Relevance: 22.9, APIs: 11, Strings: 2, Instructions: 158registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6CF1F4, Relevance: 22.6, APIs: 15, Instructions: 139threadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6D3C60, Relevance: 21.4, APIs: 8, Strings: 4, Instructions: 351COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE694D54, Relevance: 21.3, APIs: 11, Strings: 1, Instructions: 342registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE69539C, Relevance: 21.1, APIs: 10, Strings: 2, Instructions: 134COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6D00B0, Relevance: 19.6, APIs: 6, Strings: 5, Instructions: 326COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6911B8, Relevance: 19.5, APIs: 6, Strings: 5, Instructions: 210COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE691940, Relevance: 17.9, APIs: 9, Strings: 1, Instructions: 352COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE69517C, Relevance: 17.8, APIs: 9, Strings: 1, Instructions: 285registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE69C9DC, Relevance: 17.6, APIs: 7, Strings: 3, Instructions: 83COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE693998, Relevance: 15.9, APIs: 8, Strings: 1, Instructions: 118registrymemoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6B262C, Relevance: 15.8, APIs: 4, Strings: 5, Instructions: 81registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6BF6E0, Relevance: 15.4, APIs: 10, Instructions: 365memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE695788, Relevance: 14.3, APIs: 7, Strings: 1, Instructions: 310COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6C54FC, Relevance: 14.1, APIs: 4, Strings: 4, Instructions: 133memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE69D300, Relevance: 14.1, APIs: 5, Strings: 3, Instructions: 57libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6D19F0, Relevance: 12.3, APIs: 4, Strings: 3, Instructions: 96COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE699800, Relevance: 12.3, APIs: 6, Strings: 1, Instructions: 88COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6BB990, Relevance: 12.3, APIs: 3, Strings: 4, Instructions: 62COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6B2818, Relevance: 12.1, APIs: 8, Instructions: 112threadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6AB08F, Relevance: 10.7, APIs: 5, Strings: 1, Instructions: 211memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6C5930, Relevance: 9.1, APIs: 6, Instructions: 96synchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6BEC94, Relevance: 9.0, APIs: 4, Strings: 1, Instructions: 214memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6BF00C, Relevance: 9.0, APIs: 4, Strings: 1, Instructions: 210memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6BF374, Relevance: 9.0, APIs: 4, Strings: 1, Instructions: 210memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6AF324, Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 120registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6AF4CE, Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 87registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE693CDC, Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 64registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE693DFC, Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 56registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6B1CF0, Relevance: 8.8, APIs: 2, Strings: 3, Instructions: 44COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6B1A14, Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 110registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE693B40, Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 44registrymemoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE693844, Relevance: 7.0, APIs: 1, Strings: 3, Instructions: 37memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6C7BD0, Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 35COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE69806C, Relevance: 6.3, APIs: 4, Instructions: 298synchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6A921A, Relevance: 6.3, APIs: 4, Instructions: 269synchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6A9136, Relevance: 6.3, APIs: 4, Instructions: 256synchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6C0058, Relevance: 5.5, APIs: 2, Strings: 1, Instructions: 205COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE6BFD0C, Relevance: 5.5, APIs: 2, Strings: 1, Instructions: 205COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6EE691100, Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 45memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |