Analysis Report SearchIndexer.exe
Overview
General Information
Detection
Score: | 80 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
Startup |
---|
|
Malware Configuration |
---|
No configs have been found |
---|
Yara Overview |
---|
Memory Dumps |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Xmrig | Yara detected Xmrig cryptocurrency miner | Joe Security | ||
CoinMiner_Strings | Detects mining pool protocol string in Executable | Florian Roth |
| |
JoeSecurity_Xmrig | Yara detected Xmrig cryptocurrency miner | Joe Security |
Unpacked PEs |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
MAL_XMR_Miner_May19_1 | Detects Monero Crypto Coin Miner | Florian Roth |
| |
JoeSecurity_Xmrig | Yara detected Xmrig cryptocurrency miner | Joe Security |
Sigma Overview |
---|
No Sigma rule has matched |
---|
Signature Overview |
---|
Click to jump to signature section
AV Detection: |
---|
Antivirus / Scanner detection for submitted sample | Show sources |
Source: | Avira: |
Multi AV Scanner detection for submitted file | Show sources |
Source: | Virustotal: | Perma Link | ||
Source: | Metadefender: | Perma Link | ||
Source: | ReversingLabs: |
Bitcoin Miner: |
---|
Yara detected Xmrig cryptocurrency miner | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Contains functionality to registers a callback to get notified when the system is suspended or resumed (often done by Miners) | Show sources |
Source: | Code function: | 0_2_00007FF60C6E9BA0 |
Found strings related to Crypto-Mining | Show sources |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Compliance: |
---|
Contains modern PE file flags such as dynamic base (ASLR) or NX | Show sources |
Source: | Static PE information: |
Source: | Code function: | 0_2_00007FF60C6E38C7 | |
Source: | Code function: | 0_2_00007FF60C73A2F0 | |
Source: | Code function: | 0_2_00007FF60C73A4A8 |
Source: | Code function: | 0_2_00007FF60C6E4FC0 |
System Summary: |
---|
Malicious sample detected (through community Yara rule) | Show sources |
Source: | Matched rule: |
Source: | Code function: | 0_2_00007FF60C6E00E0 |
Source: | Code function: | 0_2_00007FF60C717CF0 | |
Source: | Code function: | 0_2_00007FF60C72E5F0 | |
Source: | Code function: | 0_2_00007FF60C72D880 | |
Source: | Code function: | 0_2_00007FF60C67CDB0 | |
Source: | Code function: | 0_2_00007FF60C681DB0 | |
Source: | Code function: | 0_2_00007FF60C71CDD0 | |
Source: | Code function: | 0_2_00007FF60C6C7E30 | |
Source: | Code function: | 0_2_00007FF60C6A1E30 | |
Source: | Code function: | 0_2_00007FF60C699E30 | |
Source: | Code function: | 0_2_00007FF60C6BBE20 | |
Source: | Code function: | 0_2_00007FF60C6C3E20 | |
Source: | Code function: | 0_2_00007FF60C70CD50 | |
Source: | Code function: | 0_2_00007FF60C6ADE00 | |
Source: | Code function: | 0_2_00007FF60C6B3DF0 | |
Source: | Code function: | 0_2_00007FF60C6DDDE0 | |
Source: | Code function: | 0_2_00007FF60C6C9E90 | |
Source: | Code function: | 0_2_00007FF60C67DE50 | |
Source: | Code function: | 0_2_00007FF60C67FF20 | |
Source: | Code function: | 0_2_00007FF60C71AEB0 | |
Source: | Code function: | 0_2_00007FF60C680EC0 | |
Source: | Code function: | 0_2_00007FF60C6D9F90 | |
Source: | Code function: | 0_2_00007FF60C6F6F68 | |
Source: | Code function: | 0_2_00007FF60C6A5F60 | |
Source: | Code function: | 0_2_00007FF60C6E9F50 | |
Source: | Code function: | 0_2_00007FF60C687000 | |
Source: | Code function: | 0_2_00007FF60C71DF80 | |
Source: | Code function: | 0_2_00007FF60C69C080 | |
Source: | Code function: | 0_2_00007FF60C6BE070 | |
Source: | Code function: | 0_2_00007FF60C6F106C | |
Source: | Code function: | 0_2_00007FF60C684060 | |
Source: | Code function: | 0_2_00007FF60C699050 | |
Source: | Code function: | 0_2_00007FF60C6BB040 | |
Source: | Code function: | 0_2_00007FF60C720130 | |
Source: | Code function: | 0_2_00007FF60C680130 | |
Source: | Code function: | 0_2_00007FF60C686110 | |
Source: | Code function: | 0_2_00007FF60C6A00F0 | |
Source: | Code function: | 0_2_00007FF60C6C20E0 | |
Source: | Code function: | 0_2_00007FF60C67B0D0 | |
Source: | Code function: | 0_2_00007FF60C6769A0 | |
Source: | Code function: | 0_2_00007FF60C7209F0 | |
Source: | Code function: | 0_2_00007FF60C704974 | |
Source: | Code function: | 0_2_00007FF60C68A950 | |
Source: | Code function: | 0_2_00007FF60C727A30 | |
Source: | Code function: | 0_2_00007FF60C719950 | |
Source: | Code function: | 0_2_00007FF60C6A0A10 | |
Source: | Code function: | 0_2_00007FF60C701A10 | |
Source: | Code function: | 0_2_00007FF60C6C2A00 | |
Source: | Code function: | 0_2_00007FF60C6CAA00 | |
Source: | Code function: | 0_2_00007FF60C68B9F0 | |
Source: | Code function: | 0_2_00007FF60C6A69F0 | |
Source: | Code function: | 0_2_00007FF60C68F9E0 | |
Source: | Code function: | 0_2_00007FF60C6989E0 | |
Source: | Code function: | 0_2_00007FF60C6BA9D0 | |
Source: | Code function: | 0_2_00007FF60C6949D0 | |
Source: | Code function: | 0_2_00007FF60C7319A0 | |
Source: | Code function: | 0_2_00007FF60C6FDA98 | |
Source: | Code function: | 0_2_00007FF60C6B3A90 | |
Source: | Code function: | 0_2_00007FF60C685A90 | |
Source: | Code function: | 0_2_00007FF60C687A70 | |
Source: | Code function: | 0_2_00007FF60C729A40 | |
Source: | Code function: | 0_2_00007FF60C6EAB1C | |
Source: | Code function: | 0_2_00007FF60C6B5AF0 | |
Source: | Code function: | 0_2_00007FF60C70EAB0 | |
Source: | Code function: | 0_2_00007FF60C6A7BB0 | |
Source: | Code function: | 0_2_00007FF60C6D9B70 | |
Source: | Code function: | 0_2_00007FF60C691B40 | |
Source: | Code function: | 0_2_00007FF60C69FC30 | |
Source: | Code function: | 0_2_00007FF60C6C1C20 | |
Source: | Code function: | 0_2_00007FF60C721B50 | |
Source: | Code function: | 0_2_00007FF60C690C10 | |
Source: | Code function: | 0_2_00007FF60C68FCB0 | |
Source: | Code function: | 0_2_00007FF60C693CB0 | |
Source: | Code function: | 0_2_00007FF60C6ACC90 | |
Source: | Code function: | 0_2_00007FF60C6A2C60 | |
Source: | Code function: | 0_2_00007FF60C6C4C50 | |
Source: | Code function: | 0_2_00007FF60C69CD30 | |
Source: | Code function: | 0_2_00007FF60C6BED20 | |
Source: | Code function: | 0_2_00007FF60C71BC50 | |
Source: | Code function: | 0_2_00007FF60C68ACE0 | |
Source: | Code function: | 0_2_00007FF60C695CE0 | |
Source: | Code function: | 0_2_00007FF60C68CCC0 | |
Source: | Code function: | 0_2_00007FF60C6C8CC0 | |
Source: | Code function: | 0_2_00007FF60C722CB0 | |
Source: | Code function: | 0_2_00007FF60C6C15B0 | |
Source: | Code function: | 0_2_00007FF60C7315C0 | |
Source: | Code function: | 0_2_00007FF60C6935A0 | |
Source: | Code function: | 0_2_00007FF60C6DF584 | |
Source: | Code function: | 0_2_00007FF60C67C570 | |
Source: | Code function: | 0_2_00007FF60C6F1558 | |
Source: | Code function: | 0_2_00007FF60C697550 | |
Source: | Code function: | 0_2_00007FF60C681550 | |
Source: | Code function: | 0_2_00007FF60C692630 | |
Source: | Code function: | 0_2_00007FF60C71F550 | |
Source: | Code function: | 0_2_00007FF60C723560 | |
Source: | Code function: | 0_2_00007FF60C6C95E0 | |
Source: | Code function: | 0_2_00007FF60C68A5D0 | |
Source: | Code function: | 0_2_00007FF60C69F5C0 | |
Source: | Code function: | 0_2_00007FF60C690680 | |
Source: | Code function: | 0_2_00007FF60C698680 | |
Source: | Code function: | 0_2_00007FF60C6BA670 | |
Source: | Code function: | 0_2_00007FF60C71B700 | |
Source: | Code function: | 0_2_00007FF60C6B6660 | |
Source: | Code function: | 0_2_00007FF60C6A9640 | |
Source: | Code function: | 0_2_00007FF60C685700 | |
Source: | Code function: | 0_2_00007FF60C69A6E0 | |
Source: | Code function: | 0_2_00007FF60C6BC6D0 | |
Source: | Code function: | 0_2_00007FF60C7196A0 | |
Source: | Code function: | 0_2_00007FF60C67E6D0 | |
Source: | Code function: | 0_2_00007FF60C71D6B0 | |
Source: | Code function: | 0_2_00007FF60C6E17A0 | |
Source: | Code function: | 0_2_00007FF60C67D7A0 | |
Source: | Code function: | 0_2_00007FF60C6867A0 | |
Source: | Code function: | 0_2_00007FF60C696790 | |
Source: | Code function: | 0_2_00007FF60C6AE780 | |
Source: | Code function: | 0_2_00007FF60C6A8770 | |
Source: | Code function: | 0_2_00007FF60C68D760 | |
Source: | Code function: | 0_2_00007FF60C68F760 | |
Source: | Code function: | 0_2_00007FF60C724810 | |
Source: | Code function: | 0_2_00007FF60C6CB830 | |
Source: | Code function: | 0_2_00007FF60C682820 | |
Source: | Code function: | 0_2_00007FF60C6C8800 | |
Source: | Code function: | 0_2_00007FF60C70E790 | |
Source: | Code function: | 0_2_00007FF60C6F87D0 | |
Source: | Code function: | 0_2_00007FF60C71E7A0 | |
Source: | Code function: | 0_2_00007FF60C71A8F0 | |
Source: | Code function: | 0_2_00007FF60C680840 | |
Source: | Code function: | 0_2_00007FF60C67C840 | |
Source: | Code function: | 0_2_00007FF60C6B4920 | |
Source: | Code function: | 0_2_00007FF60C693920 | |
Source: | Code function: | 0_2_00007FF60C6AC910 | |
Source: | Code function: | 0_2_00007FF60C6A3910 | |
Source: | Code function: | 0_2_00007FF60C6C5900 | |
Source: | Code function: | 0_2_00007FF60C6C8190 | |
Source: | Code function: | 0_2_00007FF60C685170 | |
Source: | Code function: | 0_2_00007FF60C6B8140 | |
Source: | Code function: | 0_2_00007FF60C6B1230 | |
Source: | Code function: | 0_2_00007FF60C719140 | |
Source: | Code function: | 0_2_00007FF60C690220 | |
Source: | Code function: | 0_2_00007FF60C67D210 | |
Source: | Code function: | 0_2_00007FF60C67F1C0 | |
Source: | Code function: | 0_2_00007FF60C6C32B0 | |
Source: | Code function: | 0_2_00007FF60C6892B0 | |
Source: | Code function: | 0_2_00007FF60C6A62B0 | |
Source: | Code function: | 0_2_00007FF60C69F260 | |
Source: | Code function: | 0_2_00007FF60C6C1250 | |
Source: | Code function: | 0_2_00007FF60C695250 | |
Source: | Code function: | 0_2_00007FF60C68C250 | |
Source: | Code function: | 0_2_00007FF60C69B250 | |
Source: | Code function: | 0_2_00007FF60C6B5240 | |
Source: | Code function: | 0_2_00007FF60C6BD240 | |
Source: | Code function: | 0_2_00007FF60C694330 | |
Source: | Code function: | 0_2_00007FF60C6E1320 | |
Source: | Code function: | 0_2_00007FF60C6A72F0 | |
Source: | Code function: | 0_2_00007FF60C6F12F0 | |
Source: | Code function: | 0_2_00007FF60C728280 | |
Source: | Code function: | 0_2_00007FF60C67C2F0 | |
Source: | Code function: | 0_2_00007FF60C6AA2E0 | |
Source: | Code function: | 0_2_00007FF60C6DE2E0 | |
Source: | Code function: | 0_2_00007FF60C7212A0 | |
Source: | Code function: | 0_2_00007FF60C6912C0 | |
Source: | Code function: | 0_2_00007FF60C6A12C0 | |
Source: | Code function: | 0_2_00007FF60C6832C0 | |
Source: | Code function: | 0_2_00007FF60C6DD3A0 | |
Source: | Code function: | 0_2_00007FF60C693390 | |
Source: | Code function: | 0_2_00007FF60C7193F0 | |
Source: | Code function: | 0_2_00007FF60C685380 | |
Source: | Code function: | 0_2_00007FF60C722400 | |
Source: | Code function: | 0_2_00007FF60C68B360 | |
Source: | Code function: | 0_2_00007FF60C6FC3FC | |
Source: | Code function: | 0_2_00007FF60C68A3C0 | |
Source: | Code function: | 0_2_00007FF60C6804B0 | |
Source: | Code function: | 0_2_00007FF60C6B7490 | |
Source: | Code function: | 0_2_00007FF60C6AD480 | |
Source: | Code function: | 0_2_00007FF60C6AF480 | |
Source: | Code function: | 0_2_00007FF60C6B4460 | |
Source: | Code function: | 0_2_00007FF60C71C510 | |
Source: | Code function: | 0_2_00007FF60C688510 | |
Source: | Code function: | 0_2_00007FF60C699510 | |
Source: | Code function: | 0_2_00007FF60C6BB500 | |
Source: | Code function: | 0_2_00007FF60C68E500 | |
Source: | Code function: | 0_2_00007FF60C6CC4E0 | |
Source: | Code function: | 0_2_00007FF60C6B04C0 |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | Code function: | 0_2_00007FF60C73A010 | |
Source: | Code function: | 0_2_00007FF60C72E2D0 |
Source: | Code function: | 0_2_00007FF60C6E2CF0 |
Source: | Mutant created: |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: | ||
Source: | Metadefender: | ||
Source: | ReversingLabs: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Process created: | ||
Source: | Process created: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Code function: | 0_2_00007FF60C6E9BA0 |
Source: | Static PE information: |
Source: | Code function: | 0_2_00007FF60C6D4A22 | |
Source: | Code function: | 0_2_00007FF60C6D4A77 | |
Source: | Code function: | 0_2_00007FF60C6D4B37 | |
Source: | Code function: | 0_2_00007FF60C6D4AD5 | |
Source: | Code function: | 0_2_00007FF60C6D4B95 | |
Source: | Code function: | 0_2_00007FF60C6D4BF5 | |
Source: | Code function: | 0_2_00007FF60C6D4C56 |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_2_00007FF60C6EAB1C |
Source: | Code function: | 0_2_00007FF60C6EA2C4 |
Source: | API coverage: |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Code function: | 0_2_00007FF60C6E38C7 | |
Source: | Code function: | 0_2_00007FF60C73A2F0 | |
Source: | Code function: | 0_2_00007FF60C73A4A8 |
Source: | Code function: | 0_2_00007FF60C72E5F0 |
Source: | Code function: | 0_2_00007FF60C6EA2C4 |
Source: | Code function: | 0_2_00007FF60C6F2A4C |
Source: | Code function: | 0_2_00007FF60C6E9BA0 |
Source: | Code function: | 0_2_00007FF60C73A4E0 |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Code function: | 0_2_00007FF60C6EB610 | |
Source: | Code function: | 0_2_00007FF60C6EBE1C | |
Source: | Code function: | 0_2_00007FF60C6F2A4C | |
Source: | Code function: | 0_2_00007FF60C6EBC74 | |
Source: | Code function: | 0_2_00007FF60C6EB7BC |
Source: | Code function: | 0_2_00007FF60C6EA2A0 |
Source: | Code function: | 0_2_00007FF60C6E7140 |
Source: | Code function: | 0_2_00007FF60C6E0DF0 |
Source: | Code function: | 0_2_00007FF60C73A4A8 |
Source: | Code function: | 0_2_00007FF60C6E4BE0 |
Mitre Att&ck Matrix |
---|
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Command and Scripting Interpreter2 | Application Shimming1 | Access Token Manipulation1 | Access Token Manipulation1 | OS Credential Dumping | System Time Discovery2 | Remote Services | Archive Collected Data1 | Exfiltration Over Other Network Medium | Encrypted Channel1 | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Native API1 | Boot or Logon Initialization Scripts | Process Injection2 | Process Injection2 | LSASS Memory | Security Software Discovery3 | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | Ingress Tool Transfer1 | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Application Shimming1 | Deobfuscate/Decode Files or Information1 | Security Account Manager | File and Directory Discovery1 | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | Steganography | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | Obfuscated Files or Information21 | NTDS | System Information Discovery14 | Distributed Component Object Model | Input Capture | Scheduled Transfer | Protocol Impersonation | SIM Card Swap | Carrier Billing Fraud | |
Cloud Accounts | Cron | Network Logon Script | Network Logon Script | Software Packing1 | LSA Secrets | Remote System Discovery | SSH | Keylogging | Data Transfer Size Limits | Fallback Channels | Manipulate Device Communication | Manipulate App Store Rankings or Ratings |
Behavior Graph |
---|
Screenshots |
---|
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Antivirus, Machine Learning and Genetic Malware Detection |
---|
Initial Sample |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
58% | Virustotal | Browse | ||
22% | Metadefender | Browse | ||
76% | ReversingLabs | Win64.Trojan.Miner | ||
100% | Avira | HEUR/AGEN.1120937 |
Dropped Files |
---|
No Antivirus matches |
---|
Unpacked PE Files |
---|
No Antivirus matches |
---|
Domains |
---|
No Antivirus matches |
---|
URLs |
---|
No Antivirus matches |
---|
Domains and IPs |
---|
General Information |
---|
Joe Sandbox Version: | 31.0.0 Emerald |
Analysis ID: | 364394 |
Start date: | 08.03.2021 |
Start time: | 04:36:30 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 2m 56s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | SearchIndexer.exe |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 3 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal80.mine.winEXE@2/0@0/0 |
EGA Information: |
|
HDC Information: |
|
HCA Information: | Failed |
Cookbook Comments: |
|
Warnings: | Show All
|
Simulations |
---|
Behavior and APIs |
---|
No simulations |
---|
Joe Sandbox View / Context |
---|
Created / dropped Files |
---|
No created / dropped files found |
---|
Static File Info |
---|
General | |
---|---|
File type: | |
Entropy (8bit): | 7.816430515285655 |
TrID: |
|
File name: | SearchIndexer.exe |
File size: | 415744 |
MD5: | 2ed1055a1ae02de09730550c1a1abbbd |
SHA1: | 42871f98dc93635013808b762a6157ddf770226a |
SHA256: | adb64ebd3e30421457e2908995a524885e194182e4deae5b137ccad2d2a05aa3 |
SHA512: | e3828fc4a6215955249f66db8aa35cdbf67e0779e1ea7616b7ac72b4bb73b631a2e28962b127fa2edfef0fac79612486bc0082beffd1a79d15760301970a72df |
SSDEEP: | 6144:N5Wj/bK5hZneFnzOLm1zPqq64/t3fA2Ke3Mhzc6K+rkR10efUK:LW7bKxIzQUbDFvMI+Qztf |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........{....S...S...S...R...S...R...S...R ..S.k.S...S...R...S...R...S...R...S...R...S...S...S3..R...S3..R...S3..S...S...S...S3..R... |
File Icon |
---|
Icon Hash: | 00f070f092ebf830 |
Static PE Info |
---|
General | |
---|---|
Entrypoint: | 0x140397880 |
Entrypoint Section: | UPX1 |
Digitally signed: | false |
Imagebase: | 0x140000000 |
Subsystem: | windows cui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE |
DLL Characteristics: | TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT, HIGH_ENTROPY_VA |
Time Stamp: | 0x6029827B [Sun Feb 14 20:05:15 2021 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 6 |
OS Version Minor: | 0 |
File Version Major: | 6 |
File Version Minor: | 0 |
Subsystem Version Major: | 6 |
Subsystem Version Minor: | 0 |
Import Hash: | e4290fa6afc89d56616f34ebbd0b1f2c |
Entrypoint Preview |
---|
Instruction |
---|
push ebx |
push esi |
push edi |
push ebp |
dec eax |
lea esi, dword ptr [FFFB0775h] |
dec eax |
lea edi, dword ptr [esi-00347000h] |
push edi |
xor ebx, ebx |
xor ecx, ecx |
dec eax |
or ebp, FFFFFFFFh |
call 00007FEDDC466B75h |
add ebx, ebx |
je 00007FEDDC466B24h |
rep ret |
mov ebx, dword ptr [esi] |
dec eax |
sub esi, FFFFFFFCh |
adc ebx, ebx |
mov dl, byte ptr [esi] |
rep ret |
dec eax |
lea eax, dword ptr [edi+ebp] |
cmp ecx, 05h |
mov dl, byte ptr [eax] |
jbe 00007FEDDC466B43h |
dec eax |
cmp ebp, FFFFFFFCh |
jnbe 00007FEDDC466B3Dh |
sub ecx, 04h |
mov edx, dword ptr [eax] |
dec eax |
add eax, 04h |
sub ecx, 04h |
mov dword ptr [edi], edx |
dec eax |
lea edi, dword ptr [edi+04h] |
jnc 00007FEDDC466B11h |
add ecx, 04h |
mov dl, byte ptr [eax] |
je 00007FEDDC466B32h |
dec eax |
inc eax |
mov byte ptr [edi], dl |
sub ecx, 01h |
mov dl, byte ptr [eax] |
dec eax |
lea edi, dword ptr [edi+01h] |
jne 00007FEDDC466B12h |
rep ret |
cld |
inc ecx |
pop ebx |
jmp 00007FEDDC466B2Ah |
dec eax |
inc esi |
mov byte ptr [edi], dl |
dec eax |
inc edi |
mov dl, byte ptr [esi] |
add ebx, ebx |
jne 00007FEDDC466B2Ch |
mov ebx, dword ptr [esi] |
dec eax |
sub esi, FFFFFFFCh |
adc ebx, ebx |
mov dl, byte ptr [esi] |
jc 00007FEDDC466B08h |
lea eax, dword ptr [ecx+01h] |
jmp 00007FEDDC466B29h |
dec eax |
inc ecx |
call ebx |
adc eax, eax |
inc ecx |
call ebx |
adc eax, eax |
add ebx, ebx |
jne 00007FEDDC466B2Ch |
mov ebx, dword ptr [esi] |
dec eax |
sub esi, FFFFFFFCh |
adc ebx, ebx |
mov dl, byte ptr [esi] |
jnc 00007FEDDC466B06h |
sub eax, 03h |
jc 00007FEDDC466B3Bh |
shl eax, 08h |
movzx edx, dl |
or eax, edx |
dec eax |
inc esi |
xor eax, FFFFFFFFh |
je 00007FEDDC466B7Ah |
sar eax, 1 |
Data Directories |
---|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x398000 | 0x140 | UPX2 |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x399000 | 0x15242 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x388000 | 0x5bc8 | UPX1 |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x398140 | 0x14 | UPX2 |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x397af8 | 0x28 | UPX1 |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x397b28 | 0x100 | UPX1 |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Sections |
---|
Name | Virtual Address | Virtual Size | Raw Size | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|
UPX0 | 0x1000 | 0x347000 | 0x0 | unknown | unknown | unknown | unknown | IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ |
UPX1 | 0x348000 | 0x50000 | 0x4fe00 | False | 0.976030663146 | data | 7.92506275506 | IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ |
UPX2 | 0x398000 | 0x1000 | 0x200 | False | 0.388671875 | data | 2.87105394311 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ |
.rsrc | 0x399000 | 0x15242 | 0x15400 | False | 0.788269761029 | data | 7.04582779269 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Resources |
---|
Name | RVA | Size | Type | Language | Country |
---|---|---|---|---|---|
RT_ICON | 0x399370 | 0x668 | data | ||
RT_ICON | 0x3999d8 | 0x2e8 | dBase IV DBT of @.DBF, block length 512, next free block index 40, next free block 28808, next used block 0 | ||
RT_ICON | 0x399cc0 | 0x1e8 | data | ||
RT_ICON | 0x399ea8 | 0x128 | GLS_BINARY_LSB_FIRST | ||
RT_ICON | 0x399fd0 | 0xea8 | data | ||
RT_ICON | 0x39ae78 | 0x8a8 | dBase IV DBT of @.DBF, block length 1024, next free block index 40, next free block 0, next used block 0 | ||
RT_ICON | 0x39b720 | 0x6c8 | data | ||
RT_ICON | 0x39bde8 | 0x568 | GLS_BINARY_LSB_FIRST | ||
RT_ICON | 0x39c350 | 0xd2d5 | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | ||
RT_ICON | 0x3a9628 | 0x25a8 | data | ||
RT_ICON | 0x3abbd0 | 0x10a8 | data | ||
RT_ICON | 0x3acc78 | 0x988 | data | ||
RT_ICON | 0x3ad600 | 0x468 | GLS_BINARY_LSB_FIRST | ||
RT_GROUP_ICON | 0x3ada68 | 0xbc | data | ||
RT_VERSION | 0x3adb24 | 0x38c | PGP symmetric key encrypted data - Plaintext or unencrypted data | English | United States |
RT_MANIFEST | 0x3adeb0 | 0x392 | XML 1.0 document, ASCII text, with CRLF line terminators | English | United States |
Imports |
---|
DLL | Import |
---|---|
ADVAPI32.dll | LsaClose |
KERNEL32.DLL | LoadLibraryA, ExitProcess, GetProcAddress, VirtualProtect |
USER32.dll | ShowWindow |
WS2_32.dll | htons |
Version Infos |
---|
Description | Data |
---|---|
LegalCopyright | Microsoft Corporation. All rights reserved. |
InternalName | SearchIndexer.exe |
FileVersion | 7.0.19041.34 (WinBuild.160101.0800) |
CompanyName | Microsoft Corporation |
ProductName | Windows Search |
ProductVersion | 7.0.19041.34 |
FileDescription | Microsoft Windows Search Indexer |
OriginalFilename | SearchIndexer.exe |
Translation | 0x0409 0x04b0 |
Possible Origin |
---|
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Network Behavior |
---|
No network behavior found |
---|
Code Manipulations |
---|
Statistics |
---|
CPU Usage |
---|
Click to jump to process
Memory Usage |
---|
Click to jump to process
Behavior |
---|
Click to jump to process
System Behavior |
---|
General |
---|
Start time: | 04:37:14 |
Start date: | 08/03/2021 |
Path: | C:\Users\user\Desktop\SearchIndexer.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff60c670000 |
File size: | 415744 bytes |
MD5 hash: | 2ED1055A1AE02DE09730550C1A1ABBBD |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
General |
---|
Start time: | 04:37:15 |
Start date: | 08/03/2021 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6b2800000 |
File size: | 625664 bytes |
MD5 hash: | EA777DEEA782E8B4D7C7C33BBF8A4496 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Disassembly |
---|
Code Analysis |
---|
Execution Graph |
---|
Execution Coverage: | 0.8% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 38.5% |
Total number of Nodes: | 239 |
Total number of Limit Nodes: | 5 |
Graph
Executed Functions |
---|
Function 00007FF60C717CF0, Relevance: 21.3, APIs: 11, Strings: 1, Instructions: 348COMMON
Control-flow Graph |
---|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C72E5F0, Relevance: 20.0, APIs: 1, Strings: 10, Instructions: 708COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C72D880, Relevance: 17.9, APIs: 3, Strings: 7, Instructions: 363COMMON
Control-flow Graph |
---|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph |
---|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph |
---|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6FEAB8, Relevance: 1.5, APIs: 1, Instructions: 36memoryCOMMONLIBRARYCODE
Control-flow Graph |
---|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Non-executed Functions |
---|
Function 00007FF60C6D9F90, Relevance: 40.5, APIs: 21, Strings: 2, Instructions: 299filesynchronizationCOMMON
Control-flow Graph |
---|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6DDDE0, Relevance: 24.8, APIs: 13, Strings: 1, Instructions: 257COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C704974, Relevance: 24.0, APIs: 9, Strings: 4, Instructions: 1207COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6DF584, Relevance: 21.2, APIs: 11, Strings: 1, Instructions: 152synchronizationnetworkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6E7140, Relevance: 14.1, APIs: 6, Strings: 2, Instructions: 85pipeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6E4FC0, Relevance: 13.6, APIs: 9, Instructions: 120networkregistryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6E38C7, Relevance: 12.3, APIs: 4, Strings: 3, Instructions: 97fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6F6F68, Relevance: 7.8, APIs: 5, Instructions: 325fileCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C701A10, Relevance: 3.2, APIs: 2, Instructions: 232COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6B1230, Relevance: .9, Instructions: 947COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C697550, Relevance: .9, Instructions: 884COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6A3910, Relevance: .9, Instructions: 882COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6C5900, Relevance: .9, Instructions: 882COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6B8140, Relevance: .9, Instructions: 882COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C684060, Relevance: .9, Instructions: 873COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6A8770, Relevance: .8, Instructions: 776COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6A1E30, Relevance: .8, Instructions: 767COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6C3E20, Relevance: .8, Instructions: 767COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6B6660, Relevance: .8, Instructions: 767COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6CAA00, Relevance: .8, Instructions: 767COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C696790, Relevance: .7, Instructions: 713COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C71E7A0, Relevance: .7, Instructions: 712COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C68D760, Relevance: .7, Instructions: 703COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C692630, Relevance: .7, Instructions: 701COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C67F1C0, Relevance: .7, Instructions: 701COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6AE780, Relevance: .7, Instructions: 695COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6A9640, Relevance: .7, Instructions: 686COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6CB830, Relevance: .7, Instructions: 682COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C69C080, Relevance: .7, Instructions: 682COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6BE070, Relevance: .7, Instructions: 682COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C69A6E0, Relevance: .6, Instructions: 627COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6C9E90, Relevance: .6, Instructions: 626COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6BC6D0, Relevance: .6, Instructions: 626COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6C32B0, Relevance: .6, Instructions: 626COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C67E6D0, Relevance: .6, Instructions: 577COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C687000, Relevance: .6, Instructions: 551COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C682820, Relevance: .5, Instructions: 546COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C681DB0, Relevance: .5, Instructions: 544COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6ADE00, Relevance: .5, Instructions: 539COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C7319A0, Relevance: .5, Instructions: 535COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C71F550, Relevance: .5, Instructions: 523COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6B4920, Relevance: .5, Instructions: 504COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6A00F0, Relevance: .5, Instructions: 504COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6C20E0, Relevance: .5, Instructions: 504COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6A69F0, Relevance: .5, Instructions: 500COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C699E30, Relevance: .5, Instructions: 489COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6BBE20, Relevance: .5, Instructions: 489COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6A0A10, Relevance: .5, Instructions: 489COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6C2A00, Relevance: .5, Instructions: 489COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6C95E0, Relevance: .5, Instructions: 488COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6949D0, Relevance: .5, Instructions: 454COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C67DE50, Relevance: .4, Instructions: 450COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6867A0, Relevance: .4, Instructions: 447COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C68B9F0, Relevance: .4, Instructions: 447COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C681550, Relevance: .4, Instructions: 445COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C67B0D0, Relevance: .4, Instructions: 439COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6769A0, Relevance: .4, Instructions: 369COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C67D7A0, Relevance: .4, Instructions: 368COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6989E0, Relevance: .4, Instructions: 368COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6C15B0, Relevance: .4, Instructions: 367COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6B3DF0, Relevance: .4, Instructions: 367COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C69F5C0, Relevance: .4, Instructions: 367COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6C8190, Relevance: .4, Instructions: 367COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6BA9D0, Relevance: .4, Instructions: 367COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C680840, Relevance: .4, Instructions: 356COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C686110, Relevance: .3, Instructions: 346COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C680EC0, Relevance: .3, Instructions: 345COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C690680, Relevance: .3, Instructions: 307COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C67D210, Relevance: .3, Instructions: 307COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C67C840, Relevance: .3, Instructions: 299COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C699050, Relevance: .3, Instructions: 266COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6C8800, Relevance: .3, Instructions: 265COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6BB040, Relevance: .3, Instructions: 265COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C71A8F0, Relevance: .3, Instructions: 252COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C724810, Relevance: .2, Instructions: 249COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C67CDB0, Relevance: .2, Instructions: 245COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C690220, Relevance: .2, Instructions: 244COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C71B700, Relevance: .2, Instructions: 226COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6935A0, Relevance: .2, Instructions: 216COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C68A5D0, Relevance: .2, Instructions: 214COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C680130, Relevance: .2, Instructions: 214COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6AC910, Relevance: .2, Instructions: 204COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C698680, Relevance: .2, Instructions: 197COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6C7E30, Relevance: .2, Instructions: 196COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6BA670, Relevance: .2, Instructions: 196COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6A5F60, Relevance: .2, Instructions: 190COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C693920, Relevance: .2, Instructions: 189COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C685700, Relevance: .2, Instructions: 188COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C68A950, Relevance: .2, Instructions: 188COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C7315C0, Relevance: .2, Instructions: 167COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C70E790, Relevance: .2, Instructions: 160COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C68F760, Relevance: .2, Instructions: 158COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C67C570, Relevance: .2, Instructions: 157COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C68F9E0, Relevance: .2, Instructions: 157COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C7196A0, Relevance: .1, Instructions: 145COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C719140, Relevance: .1, Instructions: 145COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C719950, Relevance: .1, Instructions: 145COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C67FF20, Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C685170, Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6EBE1C, Relevance: .1, Instructions: 77COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C73A010, Relevance: .0, Instructions: 14COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6E79F0, Relevance: 36.9, APIs: 20, Strings: 1, Instructions: 162filethreadCOMMON
Control-flow Graph |
---|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C736E34, Relevance: 34.7, APIs: 1, Strings: 22, Instructions: 240stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6E6120, Relevance: 30.0, APIs: 15, Strings: 2, Instructions: 238synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6E2A30, Relevance: 23.0, APIs: 10, Strings: 3, Instructions: 287COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C72E0C0, Relevance: 22.9, APIs: 11, Strings: 2, Instructions: 121memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6E5E00, Relevance: 21.2, APIs: 11, Strings: 1, Instructions: 199COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C7159F0, Relevance: 17.6, APIs: 2, Strings: 8, Instructions: 132libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6E3E80, Relevance: 14.1, APIs: 7, Strings: 1, Instructions: 66memorysynchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6D974B, Relevance: 12.5, APIs: 5, Strings: 2, Instructions: 262COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6E4970, Relevance: 10.7, APIs: 7, Instructions: 154networkCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6DEF70, Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 134sleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6E51A0, Relevance: 9.3, APIs: 6, Instructions: 267networkCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6E7FA0, Relevance: 9.0, APIs: 4, Strings: 1, Instructions: 266filepipeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6DF8C0, Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 114COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6F78C0, Relevance: 7.7, APIs: 5, Instructions: 203COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6E47D0, Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 31networkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6E6F20, Relevance: 6.2, APIs: 2, Strings: 2, Instructions: 154stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6F0740, Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 171COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6FDEE4, Relevance: 5.4, APIs: 1, Strings: 2, Instructions: 134COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6F7664, Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 100fileCOMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6E5A00, Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 86COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6FF098, Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 50COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6DE7A0, Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 47COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6E7DB0, Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 37COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6DF741, Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 37COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6FF034, Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 25COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6FEF98, Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 21COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF60C6FF174, Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 21COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |