Windows
Analysis Report
file.msg.scr.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- file.msg.scr.exe (PID: 5668 cmdline:
C:\Users\u ser\Deskto p\file.msg .scr.exe MD5: 6B7ED3ABDD8484B313948BA83FDE717F) - serv.exe (PID: 7028 cmdline:
C:\Windows \serv.exe s MD5: 6B7ED3ABDD8484B313948BA83FDE717F) - explorer.exe (PID: 3528 cmdline:
C:\Windows \Explorer. EXE MD5: AD5296B280E8F522A8A897C96BAB0E1D) - serv.exe (PID: 5796 cmdline:
"C:\Window s\serv.exe " s MD5: 6B7ED3ABDD8484B313948BA83FDE717F) - WerFault.exe (PID: 808 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -u -p 5 796 -s 128 4 MD5: 9E2B8ACAD48ECCA55C0230D63623661B) - WerFault.exe (PID: 2748 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -u -p 7 028 -s 142 0 MD5: 9E2B8ACAD48ECCA55C0230D63623661B) - WerFault.exe (PID: 5220 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -u -p 2 748 -s 155 6 MD5: 9E2B8ACAD48ECCA55C0230D63623661B) - notepad.exe (PID: 5492 cmdline:
C:\Windows \System32\ notepad.ex e C:\Users \user\Desk top\19F3.t mp MD5: D693F13FE3AA2010B854C4C60671B8E2)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
SUSP_Imphash_Mar23_3 | Detects imphash often found in malware samples (Maximum 0,25% hits with search for \'imphash:x p:0\' on Virustotal) = 99,75% hits | Arnim Rupp (https://github.com/ruppde) | ||
SUSP_Imphash_Mar23_3 | Detects imphash often found in malware samples (Maximum 0,25% hits with search for \'imphash:x p:0\' on Virustotal) = 99,75% hits | Arnim Rupp (https://github.com/ruppde) |
Click to jump to signature section
AV Detection |
---|
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Avira: |
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: |
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: |
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 2_2_0041BF10 |
Source: | IP Address: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | DNS traffic detected: |
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Process created: |
Source: | File created: | Jump to behavior |
Source: | Code function: | 0_2_00413040 | |
Source: | Code function: | 0_2_0040C070 | |
Source: | Code function: | 0_2_00412800 | |
Source: | Code function: | 0_2_004188E0 | |
Source: | Code function: | 0_2_0040D1C0 | |
Source: | Code function: | 0_2_00408980 | |
Source: | Code function: | 0_2_0040F990 | |
Source: | Code function: | 0_2_00424278 | |
Source: | Code function: | 0_2_0042C297 | |
Source: | Code function: | 0_2_00413350 | |
Source: | Code function: | 0_2_00414310 | |
Source: | Code function: | 0_2_0042C39F | |
Source: | Code function: | 0_2_00424C0E | |
Source: | Code function: | 0_2_004184D0 | |
Source: | Code function: | 0_2_00410680 | |
Source: | Code function: | 0_2_00413770 | |
Source: | Code function: | 2_2_00414310 | |
Source: | Code function: | 2_2_00413040 | |
Source: | Code function: | 2_2_0040C070 | |
Source: | Code function: | 2_2_00412800 | |
Source: | Code function: | 2_2_004188E0 | |
Source: | Code function: | 2_2_0040D1C0 | |
Source: | Code function: | 2_2_00408980 | |
Source: | Code function: | 2_2_0040F990 | |
Source: | Code function: | 2_2_00424278 | |
Source: | Code function: | 2_2_0042C297 | |
Source: | Code function: | 2_2_00413350 | |
Source: | Code function: | 2_2_0042C39F | |
Source: | Code function: | 2_2_00424C0E | |
Source: | Code function: | 2_2_004184D0 | |
Source: | Code function: | 2_2_00410680 | |
Source: | Code function: | 2_2_00413770 | |
Source: | Code function: | 2_2_10001470 |
Source: | Code function: | ||
Source: | Code function: |
Source: | Code function: | 2_2_0056184A |
Source: | Code function: | 2_2_0041C400 |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Code function: | 2_2_0041CB80 |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | Code function: | 2_2_0041B4F0 |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 0_2_00422934 | |
Source: | Code function: | 0_2_0042295C | |
Source: | Code function: | 0_2_00424277 | |
Source: | Code function: | 0_2_0042330E | |
Source: | Code function: | 0_2_0043428B | |
Source: | Code function: | 0_2_00434D6A | |
Source: | Code function: | 0_2_0043461A | |
Source: | Code function: | 2_2_00422934 | |
Source: | Code function: | 2_2_0042295C | |
Source: | Code function: | 2_2_00424277 | |
Source: | Code function: | 2_2_0042330E | |
Source: | Code function: | 2_2_0043428B | |
Source: | Code function: | 2_2_00434D6A | |
Source: | Code function: | 2_2_0043461A |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_2_0041F2B0 |
Source: | Static PE information: |
Persistence and Installation Behavior |
---|
Source: | Executable created and started: | Jump to behavior |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Boot Survival |
---|
Source: | Key value created or modified: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | RDTSC instruction interceptor: | ||
Source: | RDTSC instruction interceptor: | ||
Source: | RDTSC instruction interceptor: | ||
Source: | RDTSC instruction interceptor: | ||
Source: | RDTSC instruction interceptor: | ||
Source: | RDTSC instruction interceptor: | ||
Source: | RDTSC instruction interceptor: | ||
Source: | RDTSC instruction interceptor: | ||
Source: | RDTSC instruction interceptor: |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file |
Source: | Code function: | 0_2_0040B470 | |
Source: | Code function: | 2_2_0040B470 |
Source: | Code function: | 0_2_0040D1C0 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Check user administrative privileges: | graph_2-17917 | ||
Source: | Check user administrative privileges: | graph_0-17263 |
Source: | Process information queried: | Jump to behavior |
Source: | Code function: | 0_2_00429AAE |
Source: | Code function: | 2_2_0041BF10 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | API call chain: | graph_2-17716 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 0_2_0041F2B0 |
Source: | Code function: | 0_2_0041AC50 |
Source: | Code function: | 0_2_0040D1C0 |
Source: | Process token adjusted: | Jump to behavior |
Source: | System information queried: | Jump to behavior |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 0_2_00423F8A | |
Source: | Code function: | 0_2_00423F9E | |
Source: | Code function: | 2_2_00423F8A | |
Source: | Code function: | 2_2_00423F9E |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Injected file: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Code function: | 0_2_004215C0 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Code function: | 0_2_004298A2 | |
Source: | Code function: | 2_2_004298A2 |
Source: | Code function: | 0_2_004122F0 |
Source: | Code function: | 0_2_0040B470 |
Source: | Code function: | 0_2_0041B250 |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | 2 Native API | 1 Registry Run Keys / Startup Folder | 1 Access Token Manipulation | 121 Masquerading | 1 Input Capture | 12 System Time Discovery | Remote Services | 1 Input Capture | Exfiltration Over Other Network Medium | 1 Encrypted Channel | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | 1 Shared Modules | Boot or Logon Initialization Scripts | 42 Process Injection | 41 Virtualization/Sandbox Evasion | LSASS Memory | 241 Security Software Discovery | Remote Desktop Protocol | 1 Archive Collected Data | Exfiltration Over Bluetooth | 1 Non-Application Layer Protocol | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | 1 Registry Run Keys / Startup Folder | 1 Access Token Manipulation | Security Account Manager | 41 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 11 Application Layer Protocol | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | 42 Process Injection | NTDS | 3 Process Discovery | Distributed Component Object Model | Input Capture | Scheduled Transfer | Protocol Impersonation | SIM Card Swap | Carrier Billing Fraud | |
Cloud Accounts | Cron | Network Logon Script | Network Logon Script | 1 Deobfuscate/Decode Files or Information | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Data Transfer Size Limits | Fallback Channels | Manipulate Device Communication | Manipulate App Store Rankings or Ratings | |
Replication Through Removable Media | Launchd | Rc.common | Rc.common | 2 Obfuscated Files or Information | Cached Domain Credentials | 1 Remote System Discovery | VNC | GUI Input Capture | Exfiltration Over C2 Channel | Multiband Communication | Jamming or Denial of Service | Abuse Accessibility Features | |
External Remote Services | Scheduled Task | Startup Items | Startup Items | Compile After Delivery | DCSync | 1 File and Directory Discovery | Windows Remote Management | Web Portal Capture | Exfiltration Over Alternative Protocol | Commonly Used Port | Rogue Wi-Fi Access Points | Data Encrypted for Impact | |
Drive-by Compromise | Command and Scripting Interpreter | Scheduled Task/Job | Scheduled Task/Job | Indicator Removal from Tools | Proc Filesystem | 124 System Information Discovery | Shared Webroot | Credential API Hooking | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Application Layer Protocol | Downgrade to Insecure Protocols | Generate Fraudulent Advertising Revenue |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
86% | ReversingLabs | Win32.Worm.Stration | ||
83% | Virustotal | Browse | ||
100% | Avira | WORM/Stration.C | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | TR/Crypt.XPACK.Gen | ||
100% | Avira | TR/Crypt.XPACK.Gen | ||
100% | Avira | TR/PWS.Sinowal.Gen5 | ||
100% | Avira | WORM/Stration.C | ||
100% | Avira | WORM/Stration.Gen | ||
100% | Avira | TR/Crypt.XPACK.Gen | ||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
83% | ReversingLabs | Win32.Worm.Stration | ||
68% | ReversingLabs | Win32.Worm.Stration | ||
76% | ReversingLabs | Win32.Worm.Stration | ||
78% | ReversingLabs | Win32.Worm.Warezov | ||
84% | ReversingLabs | Win32.Worm.Stration | ||
86% | ReversingLabs | Win32.Worm.Stration |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
mta6.am0.yahoodns.net | 67.195.228.106 | true | false |
| unknown |
alt4.gmail-smtp-in.l.google.com | 142.250.157.27 | true | false | high | |
alt3.gmail-smtp-in.l.google.com | 74.125.200.27 | true | false | high | |
mta7.am0.yahoodns.net | 67.195.204.79 | true | false | unknown | |
gmail-smtp-in.l.google.com | 142.250.27.26 | true | false | high | |
mta5.am0.yahoodns.net | 67.195.228.110 | true | false | unknown | |
alt1.gmail-smtp-in.l.google.com | 142.251.9.27 | true | false | high | |
alt2.gmail-smtp-in.l.google.com | 142.250.150.26 | true | false | high | |
hotmail-com.olc.protection.outlook.com | 104.47.18.161 | true | false | high | |
hotmail.com | unknown | unknown | false | high | |
www4.ertinmdesachlion.com | unknown | unknown | false | unknown | |
gmail.com | unknown | unknown | false | high | |
www6.ertinmdesachlion.com | unknown | unknown | false | unknown | |
www3.ertinmdesachlion.com | unknown | unknown | false | unknown | |
yahoo.com | unknown | unknown | false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
104.47.18.161 | hotmail-com.olc.protection.outlook.com | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
142.250.150.26 | alt2.gmail-smtp-in.l.google.com | United States | 15169 | GOOGLEUS | false | |
67.195.204.79 | mta7.am0.yahoodns.net | United States | 26101 | YAHOO-3US | false | |
142.250.27.26 | gmail-smtp-in.l.google.com | United States | 15169 | GOOGLEUS | false | |
67.195.204.74 | unknown | United States | 26101 | YAHOO-3US | false |
Joe Sandbox Version: | 37.1.0 Beryl |
Analysis ID: | 877404 |
Start date and time: | 2023-05-29 12:07:32 +02:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 11m 22s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 14 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 1 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample file name: | file.msg.scr.exe |
Detection: | MAL |
Classification: | mal100.evad.winEXE@10/20@40/5 |
EGA Information: |
|
HDC Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): audiodg.exe, WerFault.exe, svchost.exe
- Excluded domains from analysis (whitelisted): ctldl.windowsupdate.com
- Report creation exceeded maximum time and may have missing disassembly code information.
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtEnumerateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
12:08:47 | Autostart | |
12:08:56 | API Interceptor | |
12:09:00 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
104.47.18.161 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Raccoon RedLine SmokeLoader Tofsee Vidar Xmrig | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Raccoon RedLine SmokeLoader Tofsee Vidar Xmrig | Browse | |||
Get hash | malicious | Tofsee Xmrig | Browse | |||
Get hash | malicious | Tofsee Xmrig | Browse | |||
Get hash | malicious | Tofsee Xmrig | Browse | |||
Get hash | malicious | Tofsee Xmrig | Browse | |||
Get hash | malicious | Tofsee Xmrig | Browse | |||
Get hash | malicious | Tofsee Xmrig | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
mta6.am0.yahoodns.net | Get hash | malicious | Tofsee | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Tofsee | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Raccoon RedLine SmokeLoader Tofsee | Browse |
| ||
Get hash | malicious | Raccoon RedLine SmokeLoader Tofsee | Browse |
| ||
Get hash | malicious | Raccoon RedLine SmokeLoader Tofsee Xmrig | Browse |
| ||
Get hash | malicious | Raccoon RedLine SmokeLoader Tofsee Xmrig | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
MICROSOFT-CORP-MSN-AS-BLOCKUS | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Tofsee | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 141644 |
Entropy (8bit): | 1.9457814315262165 |
Encrypted: | false |
SSDEEP: | 384:bKr9RMa6C1zmmI00Gl7G2NwSpYOvFWx+KA9gXzukEG58sTZFkC:bq6C1zmjOI2jNnzYEG58UQC |
MD5: | 8D4F1D767429957FC73BA90097181CE1 |
SHA1: | A2DA38628B970DCEB6F36051453BB54723C6065E |
SHA-256: | 965ED945CB3453F87CC5BCEAD91877910E45B0291653E4521F94E559FB0625B6 |
SHA-512: | D53FD13A9D9B7DDB341BF0CC540B95179CD64B5795399ED85A74CF40CC6B98C01092F30996D35D24CF92379DC8943A07688606E11A277DA165064556EAB3B867 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6258 |
Entropy (8bit): | 3.7167755787887926 |
Encrypted: | false |
SSDEEP: | 192:Rrl7r3GLNiek6E8YgIStwI+pDZ89bawsfw+m:RrlsNiV6E8YgISNaDfQ |
MD5: | E54ECD38EFC0DA31845DC748690C64D2 |
SHA1: | E60450FE873CD3A20E0333E3592A5783F5C97E44 |
SHA-256: | 048DE83F1AC551059FAE2218C3BA9AC622B40EE8C97A9FAC746967ADDB30C1B6 |
SHA-512: | 9FB781AF6CCCAE0E29342D75CF1683EAEB80855CD3338787E3B5D2CDB484CBFA841C52174C90BA0A758D4F2107DFDFA42E7D45120C648D7B7EF115CCF84A548B |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 326836 |
Entropy (8bit): | 1.5174235239024396 |
Encrypted: | false |
SSDEEP: | 768:FrwUIQvB6BDpeAsX3tl/EAPZSf5YpHP4u7dlukj:zImIBD7sXr/EAcfepv4uDtj |
MD5: | 66F5EC7AF7AB83225F1FE41DDC72EC32 |
SHA1: | 6337BF2D63D3F3002E178E91DF309F936D5DE06B |
SHA-256: | 6FECE78AF9792211FB04B9403BB1A3DCD2D68A62D30AE467B1349A99084B82DB |
SHA-512: | F161BE210EA21FCD4759FCF59A7214DAEE3D6D58F2FD06189A03E2A3C36EAEC7D60780BAEAB49E3A4325F5BCD2D29DF0D2BE57AFE97FD5013B95F0B0F7935F14 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8372 |
Entropy (8bit): | 3.6949145472657356 |
Encrypted: | false |
SSDEEP: | 192:Rrl7r3GLNiCB6Gg6Y+26ccgmf+5ASlO+pDB89bvJsfVsFm:RrlsNi06Gg6Yn6ccgmf+6SmvifVj |
MD5: | 5E2E31121CB671D58B7E8B0D10B028CE |
SHA1: | 9BB3F10E89943CF30D942F2E4164380711B01BEB |
SHA-256: | 2BCC303EB7F28ACDDB7634B41753FD25994B4C8C2DEF12A5B735016644E3A89A |
SHA-512: | 0FA94886D71B216525D62E198799B5A58B8E8A638ACB67F3BE47028BB42310F810EC1A4F2239DFCFCDDF2A7F285DF9BB01B6D5362A6793D9FC1FA6EAC9A9EFEB |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 129382 |
Entropy (8bit): | 1.8442376646649499 |
Encrypted: | false |
SSDEEP: | 384:ClCJzSV8WRkzwPsawwF4qYjq+JZNvI/U3i/iYoml:aChWRkzys5J9lZN5eDl |
MD5: | 7ED40E1C406653AD1606CF7575D863F8 |
SHA1: | C7B1E0F197E6C8AF9B8B6EB6CD728C6E0CBA3743 |
SHA-256: | EBCC9AC4238E25FD43C98D85F2708375BF1B726219ADC1F13134F36977B15FC3 |
SHA-512: | 2E46CC64964164690392890FED455AFAFD4564B65BEA2D1C935BA0D77608666ECF27C557A907B2E03FF535AA0464831C68588BBC4AC895E84F9F5C5882B1BB01 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8278 |
Entropy (8bit): | 3.6938876891401122 |
Encrypted: | false |
SSDEEP: | 192:Rrl7r3GLNiWB6IS6YeZSUjgmfgISAB3Dh+pDw89bevO3sf5Hqm:RrlsNio6X6YQSUjgmfgISqMe1fV |
MD5: | 067E371E1835B896EE1C3315A06A3772 |
SHA1: | C9AC7165DB1F7B88E11228D90BE96FF0074DB139 |
SHA-256: | 52B58007F989C9B94541C77B48FAEE9502074CCAA528219C3F786598864643F1 |
SHA-512: | 0FD5D231720BA21EF24340A4C550663101BBA5D377020C29CB516CEF8E5B3E5557D9114FE636CB581C44AEFBA75434A2FA7B64A92D755B479812A63EBE84AA19 |
Malicious: | false |
Preview: |
Process: | C:\Windows\serv.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 276498 |
Entropy (8bit): | 7.9975652725042785 |
Encrypted: | true |
SSDEEP: | 6144:GHBMAf/u4bsMrM85vTtcK79Ibuwf8twej93OIXumeBi:GHOQu4ntvT579Nwf8tLJ3OIX2Bi |
MD5: | 8C3F3B9C4DC0ACB40834A23BBEAA359D |
SHA1: | E0499EEFDF5428AB47A9A644B6BCF4D5A7E762B6 |
SHA-256: | 9FD510468E5382EE45DCA9E7A75B25BCC4A84FA3C832E236B71DDF62085053D5 |
SHA-512: | 6B197BA92213AB55688BBF5D7B18CB011DA6E59A03418C5BFA477A7765F98EF3856C3A803CCD9EFBBB4074AE7693761783FE5C26FB30940AC7F52356805C2515 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\serv.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 276516 |
Entropy (8bit): | 7.997566441979322 |
Encrypted: | true |
SSDEEP: | 6144:dHBMAf/u4bsMrM85vTtcK79Ibuwf8twej93OIXumeBt:dHOQu4ntvT579Nwf8tLJ3OIX2Bt |
MD5: | 0E49465623E5E4A2A26AD0FEC568E0A9 |
SHA1: | 09C97E6B700CA11FFCD634C491D291E066714094 |
SHA-256: | BB9C12E885EA9A0ACA1A936D00DCD9872AF00071069318A443A5865C2F175E78 |
SHA-512: | E846871BF44DEE4142E3E1E4CA2A0CBAC694293C4FCFC7E7A83F391858DF1746AC203A3AF7EC79FCCF83C805C828A7DF21B2593C41A5549A0CCA6558812DBA5F |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\serv.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 276498 |
Entropy (8bit): | 7.997564568005335 |
Encrypted: | true |
SSDEEP: | 6144:9HBMAf/u4bsMrM85vTtcK79Ibuwf8twej93OIXumeBD:9HOQu4ntvT579Nwf8tLJ3OIX2BD |
MD5: | 532C7902F31D9896DF376634B616E627 |
SHA1: | 8DE7CBEEFB0F8C9EA0A5ACFAE832ACBFCBBAE556 |
SHA-256: | 0D0148245E80C77869B19A9F0F4E8960267D7FC0936EC1160B70C583126D2F08 |
SHA-512: | 6AE828D74CA9995054497CA377D1724B57CB5CEF7EB6D8C764ECBAAAF69D1B9CED8E7E94CB0D725FC9E22C29F1305D76776F0660D17A2B82F80B65015CE457A1 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\serv.exe |
File Type: | |
Category: | modified |
Size (bytes): | 276516 |
Entropy (8bit): | 7.997566274861564 |
Encrypted: | true |
SSDEEP: | 6144:8HBMAf/u4bsMrM85vTtcK79Ibuwf8twej93OIXumeBe:8HOQu4ntvT579Nwf8tLJ3OIX2Be |
MD5: | 83D439D405946C51436F969E8FFB2240 |
SHA1: | 02F6F05A69D25EBB9998969434719306727C3EE8 |
SHA-256: | 6A34AEE57AE1A06A14D7D1E1D5659983A33CF859C80202CC31FAF24E38DF3ABB |
SHA-512: | 78CF1736188DCEC0211B285FBBD84FB619DC1CF043D5CAD151A629B6624EACBF3FB1E4C91D0871D5AFB167B4C7B11EBFC0AAB4D2F922F025ABC8FAEDB5950F1C |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\serv.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1720 |
Entropy (8bit): | 2.9443214183274753 |
Encrypted: | false |
SSDEEP: | 24:PEAoPiVaynbXzfwGDmRfN44EKtZHtvApY4msstHt5hstMDMH:L1xmEKbCsheX |
MD5: | DAF6904E09A281426953488E6F928E38 |
SHA1: | F7393E365155A5766387CE4C001853705597B41D |
SHA-256: | 571779D9E292690080C85B71DBCE49ADF705F4365B633A310470DE39B5DD3EC5 |
SHA-512: | B2F2B42A0A85C2BC268A139E841842C93E7EE23F9576D41E91C87AD496BB7049A206DCFFBDB37AE989EA60622491C4314DBCD937CBBDF748EFEB4C1A57958FEF |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\file.msg.scr.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 63069 |
Entropy (8bit): | 6.642470375761558 |
Encrypted: | false |
SSDEEP: | 1536:36xA6fx7GwbzrhAF9NuCPusA5n5/lt/9/Y06l+veW5NK:n6VGwbzrU/uCPolNP/9C+veWrK |
MD5: | 815DF5397E724F17E251D3C5D9B59F34 |
SHA1: | D26AB6063CAEA15050CFBF618109873854847118 |
SHA-256: | B0B3D443D410716CBFA04AC65106CE8377B56B1B01391396B1D41B54FA72ECD3 |
SHA-512: | 75C9D32F9E952FF806E5C789A12EF3E8B6E252FDB6499AAAED8C5F1968E2D24CBA5FF1DDE81EFFC94E5F2A50B877941675DED86556EC5E61323B66A0902357F0 |
Malicious: | true |
Preview: |
Process: | C:\Windows\serv.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 28672 |
Entropy (8bit): | 3.954945363563141 |
Encrypted: | false |
SSDEEP: | 384:6cUYkTFUBS5rCyg4XnAeeyi+XwdeZgSIANmvsV:6rJTR5RXAn+Xwde2SgS |
MD5: | 7D405426D1269886B6E5A9C2F5AB3D0D |
SHA1: | E08EB10BA21788339C29012B8BCDCDE19ADA9C36 |
SHA-256: | EF7E96EF6888779E7933A50634EF3A549551B169A47D2BE349BC51C42AA20D89 |
SHA-512: | 950E49DD3696C3D16F4F64DD8716C24837EC2B7DB4A4BF6E76AC640193E4C748EE4153F692D9AE6C4FF55B433EAFC7A3870A385C191518147926370A94BEFCA5 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\serv.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 20480 |
Entropy (8bit): | 4.228079937892066 |
Encrypted: | false |
SSDEEP: | 192:Fl3ZPq9/F2YvlLnXDYN11YytrfBtZiJEb2O+uXZzoe6oEQ:b1qFFBbTSYy5RiJkWwZzo5 |
MD5: | B24AB6D11D6C5EDF242C8448B2E6054A |
SHA1: | CE74EB0F0B5A6BC02EE40E40CA366D522B950DE4 |
SHA-256: | E1DE14BDCCCD532FB682AD253151021E56615CC86FD716F638CB6A3F4164F3EC |
SHA-512: | 72BBBE1BA406B4371D3291907B17228CAC42DCC1EBAC00BDD84C04E66482AB5E33D5146FE211AD58310DFA4FA343F9518F43EE65F9ECAC2CC6D6B80CB031BD60 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\serv.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8192 |
Entropy (8bit): | 5.606307481561592 |
Encrypted: | false |
SSDEEP: | 192:Q8mKp+1Rn9Gy25CdalzqKRfPy1dW93ne:QhR1XG/5CwzCS8 |
MD5: | 53D0FF71BEC705351C27389F2A867843 |
SHA1: | 9F92B05AE22F3148E67639BEC3AA7F15BA61E495 |
SHA-256: | E02CB24FBB6CDF0F7181D0071A1FE06A95B924469F44C6ECD67D26097408D0B9 |
SHA-512: | FAA5D93D77964BA16421BDAFD2B45925B9A6DC557CA04437EB42B2EE01AD5399DF2370DD1900A2BC3383FF3DA908D2861D29E3748342B7AB5C004534D2C8935F |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Preview: |
Process: | C:\Windows\serv.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 4.945864297139177 |
Encrypted: | false |
SSDEEP: | 96:fpLp7x39pA7kJpQwea/cXMZnvUhvcu9fPciarvscBITvTmO111tjc1xoEhqhNJLX:fyWpQw2qv0BfP+Bi111taoUsL+ud81I |
MD5: | 02DDF51A3CDE4BADE470C7C03C4545E7 |
SHA1: | C53BD0A77C3A572CF6E9E99F08F919A640299593 |
SHA-256: | 9389FCFAB988A15FCD18D1ABCBBEA5E7EC4DA47E273E21EA1D41818C64B94F2C |
SHA-512: | 48B4E6C21313222B1E6011A8F05935DC1C1E3721317F8073565FE769EB0B1F9CE1A5A327D51856F6FAEF72787B27DB9CCC83A6A634727EAF238245D3B1214D87 |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1572864 |
Entropy (8bit): | 4.3139108916920295 |
Encrypted: | false |
SSDEEP: | 12288:Ar5H8WUzIaQhLjDQyd9E9lyH4rWG8GD4NE4U62ul43VScahZ2S:05H8WUzIaQ1jDQpq4H |
MD5: | 094521B951B122AE766D0A3D6F0848B9 |
SHA1: | 9F9BF28FCDD4554DD3FA8B20A3683B55FCD9F30B |
SHA-256: | 07CFA4DC5FA715A284B6F66B8AD40A09D6CAE30B231E0E20AAE04A6B328686A5 |
SHA-512: | A863E50A7038BE338E1043C7E6805A8CC89CBB647D18EB3CE54D849DEFCDE22F888B5D3AFDE8582149088FC1C2807C469AD1D2F4743EC3DA6C3381999088ABC9 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 32768 |
Entropy (8bit): | 4.2101840580013 |
Encrypted: | false |
SSDEEP: | 768:pHl/bCQiFUz/XgAeeDzegNYtj/HaIsoSw8aMiyqf+WwsfWkchNYd+S:LMyxhDqdY |
MD5: | 63A062AD0E5A8DD12E8B33D6F124321B |
SHA1: | 7B928FB2F2272D16713E850AFA159F83BBD83AD2 |
SHA-256: | FD69C1A2652F2A60E052BAB6227657EB72F878F7D013DFD8B19A2813B7ABA78F |
SHA-512: | 6837EC0FC79EAE6BF2298FF6675F75E44D120E1B8B88EFD6A6B3806147303EC2776B48B1543215D466B99BF04150C1D8A182FA0DE3C58DDAD46750003975F0F9 |
Malicious: | false |
Preview: |
Process: | C:\Windows\serv.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7680 |
Entropy (8bit): | 5.07828909596086 |
Encrypted: | false |
SSDEEP: | 192:VgDu7Z9QTHreZfUFmxhErERC/b9xIyZt:Vgi7ITU2msCCRbZ |
MD5: | 8F1E54E6F9B12FF41298FA92C33F4F02 |
SHA1: | 0C028668D744664F50F3AD38112FD5337F9921A4 |
SHA-256: | 543BB9C3EC687F4D391CE9C179B92510FCAADADFE03C809D0D6DFEC387753569 |
SHA-512: | 8FC0B79526AFC8CE1B4572F1C908FAE3BAD16D8EC06660C9996D02E33925DA58CDF77742A3F3731564AED9731B23EDB4751C9001BA7E27104EC58545259EF404 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\file.msg.scr.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 520196 |
Entropy (8bit): | 6.561025946535229 |
Encrypted: | false |
SSDEEP: | 12288:gYQZsuW9geRWQmkt5nZsCRUTV5nhsf8r1J3OIh8W:gYQZsuW9geETkPZstTV5na8RJ3zhx |
MD5: | 6B7ED3ABDD8484B313948BA83FDE717F |
SHA1: | 2318E1D65CEF538F1CF88E2235A5DD350FF40449 |
SHA-256: | EEE33ED66C2E88E414A5887043DB18EDAFA2FEF889882D751F0448ED360EFC44 |
SHA-512: | A8C063F22768BDE6E0CF6C510867C6EB3B3ADD47AC57B920D44F94485B830089F5318D31D960239C5F5F7F963496D5481F7C1EF4B2291C01ED01D20A86F24C18 |
Malicious: | true |
Antivirus: |
|
Preview: |
File type: | |
Entropy (8bit): | 6.561025946535229 |
TrID: |
|
File name: | file.msg.scr.exe |
File size: | 520196 |
MD5: | 6b7ed3abdd8484b313948ba83fde717f |
SHA1: | 2318e1d65cef538f1cf88e2235a5dd350ff40449 |
SHA256: | eee33ed66c2e88e414a5887043db18edafa2fef889882d751f0448ed360efc44 |
SHA512: | a8c063f22768bde6e0cf6c510867c6eb3b3add47ac57b920d44f94485b830089f5318d31d960239c5f5f7f963496d5481f7c1ef4b2291c01ed01d20a86f24c18 |
SSDEEP: | 12288:gYQZsuW9geRWQmkt5nZsCRUTV5nhsf8r1J3OIh8W:gYQZsuW9geETkPZstTV5na8RJ3zhx |
TLSH: | 71B44A14EE5DD0B1E54B087D076A6A957BA05E7D836856D38F403E6BA2330C2FC3BD4A |
File Content Preview: | MZKERNEL32.DLL..LoadLibraryA....GetProcAddress....Z..ByDwing@...PE..L......................).....0......o,............@.............................................................................<....@...]................................................. |
Icon Hash: | d5c2d29ac2c2f209 |
Entrypoint: | 0x422c6f |
Entrypoint Section: | .Upack |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE |
DLL Characteristics: | |
Time Stamp: | 0x0 [Thu Jan 1 00:00:00 1970 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | 1d1ca12745771ba3c77da58435c9e56a |
Instruction |
---|
push 00000060h |
push 004303A8h |
call 00007F166CCE1896h |
mov edi, 00000094h |
mov eax, edi |
call 00007F166CCDFF7Eh |
mov dword ptr [ebp-18h], esp |
mov esi, esp |
mov dword ptr [esi], edi |
push esi |
call dword ptr [00430060h] |
mov ecx, dword ptr [esi+10h] |
mov dword ptr [00448268h], ecx |
mov eax, dword ptr [esi+04h] |
mov dword ptr [00448274h], eax |
mov edx, dword ptr [esi+08h] |
mov dword ptr [00448278h], edx |
mov esi, dword ptr [esi+0Ch] |
and esi, 00007FFFh |
mov dword ptr [0044826Ch], esi |
cmp ecx, 02h |
je 00007F166CCE02EEh |
or esi, 00008000h |
mov dword ptr [0044826Ch], esi |
shl eax, 08h |
add eax, edx |
mov dword ptr [00448270h], eax |
xor esi, esi |
push esi |
mov edi, dword ptr [00430054h] |
call edi |
cmp word ptr [eax], 5A4Dh |
jne 00007F166CCE0301h |
mov ecx, dword ptr [eax+3Ch] |
add ecx, eax |
cmp dword ptr [ecx], 00004550h |
jne 00007F166CCE02F4h |
movzx eax, word ptr [ecx+18h] |
cmp eax, 0000010Bh |
je 00007F166CCE0301h |
cmp eax, 0000020Bh |
je 00007F166CCE02E7h |
mov dword ptr [ebp-1Ch], esi |
jmp 00007F166CCE0309h |
cmp dword ptr [ecx+00000084h], 0Eh |
jbe 00007F166CCE02D4h |
xor eax, eax |
cmp dword ptr [ecx+000000F8h], esi |
jmp 00007F166CCE02F0h |
cmp dword ptr [ecx+74h], 0Eh |
jbe 00007F166CCE02C4h |
xor eax, eax |
cmp dword ptr [ecx+000000E8h], esi |
setne al |
mov dword ptr [ebp-1Ch], eax |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x7e000 | 0x3c | .rsrc |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x54000 | 0x5de6 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|
.Upack | 0x1000 | 0x53000 | 0x53000 | False | 0.4306317065135542 | data | 6.375705515947977 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x54000 | 0x2b000 | 0x2b000 | False | 0.7129190134447675 | data | 6.7755101512441005 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Name | RVA | Size | Type | Language | Country |
---|---|---|---|---|---|
RT_ICON | 0x54266 | 0x2e8 | Device independent bitmap graphic, 32 x 64 x 4, image size 0 | English | United States |
RT_ICON | 0x5454e | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 0 | English | United States |
RT_ICON | 0x54676 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | English | United States |
RT_ICON | 0x5551e | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | English | United States |
RT_ICON | 0x55dc6 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | English | United States |
RT_ICON | 0x5632e | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | English | United States |
RT_ICON | 0x588d6 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | English | United States |
RT_ICON | 0x5997e | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | English | United States |
RT_GROUP_ICON | 0x541f0 | 0x76 | data | English | United States |
DLL | Import |
---|---|
KERNEL32.DLL | MapViewOfFile, lstrcmpA, GetLastError, lstrcatA, lstrcpyA, GetTickCount, lstrcmpiA, GetLocalTime, Sleep, WaitForSingleObject, ReleaseMutex, LoadLibraryA, GetSystemDirectoryA, lstrlenA, GetTimeZoneInformation, GetProcAddress, RtlUnwind, RaiseException, HeapFree, GetModuleHandleA, GetStartupInfoA, GetCommandLineA, GetVersionExA, HeapAlloc, TlsAlloc, SetLastError, GetCurrentThreadId, TlsFree, TlsSetValue, TlsGetValue, SetUnhandledExceptionFilter, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, HeapReAlloc, IsBadWritePtr, ExitProcess, TerminateProcess, GetCurrentProcess, HeapSize, ReadFile, CloseHandle, WriteFile, GetStdHandle, GetModuleFileNameA, UnhandledExceptionFilter, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, SetHandleCount, GetFileType, IsBadReadPtr, IsBadCodePtr, GetACP, GetOEMCP, GetCPInfo, InitializeCriticalSection, InterlockedExchange, VirtualQuery, GetStringTypeA, MultiByteToWideChar, GetStringTypeW, GetLocaleInfoA, SetFilePointer, SetStdHandle, FlushFileBuffers, CreateFileA, LCMapStringA, LCMapStringW, VirtualProtect, GetSystemInfo, QueryPerformanceCounter, GetCurrentProcessId, GetSystemTimeAsFileTime, SetEndOfFile |
ADVAPI32.DLL | AllocateAndInitializeSid |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
May 29, 2023 12:08:56.577280998 CEST | 49694 | 25 | 192.168.2.4 | 67.195.204.79 |
May 29, 2023 12:08:56.688435078 CEST | 25 | 49694 | 67.195.204.79 | 192.168.2.4 |
May 29, 2023 12:08:56.691210985 CEST | 49694 | 25 | 192.168.2.4 | 67.195.204.79 |
May 29, 2023 12:08:56.701294899 CEST | 49694 | 25 | 192.168.2.4 | 67.195.204.79 |
May 29, 2023 12:08:56.814280987 CEST | 25 | 49694 | 67.195.204.79 | 192.168.2.4 |
May 29, 2023 12:08:56.892046928 CEST | 25 | 49694 | 67.195.204.79 | 192.168.2.4 |
May 29, 2023 12:08:56.892127991 CEST | 25 | 49694 | 67.195.204.79 | 192.168.2.4 |
May 29, 2023 12:08:56.892271996 CEST | 49694 | 25 | 192.168.2.4 | 67.195.204.79 |
May 29, 2023 12:08:56.892271996 CEST | 49694 | 25 | 192.168.2.4 | 67.195.204.79 |
May 29, 2023 12:08:57.027018070 CEST | 49695 | 25 | 192.168.2.4 | 142.250.27.26 |
May 29, 2023 12:08:57.055668116 CEST | 25 | 49695 | 142.250.27.26 | 192.168.2.4 |
May 29, 2023 12:08:57.055819035 CEST | 49695 | 25 | 192.168.2.4 | 142.250.27.26 |
May 29, 2023 12:08:57.056052923 CEST | 49695 | 25 | 192.168.2.4 | 142.250.27.26 |
May 29, 2023 12:08:57.085932970 CEST | 25 | 49695 | 142.250.27.26 | 192.168.2.4 |
May 29, 2023 12:08:57.097206116 CEST | 25 | 49695 | 142.250.27.26 | 192.168.2.4 |
May 29, 2023 12:08:57.100042105 CEST | 49695 | 25 | 192.168.2.4 | 142.250.27.26 |
May 29, 2023 12:08:57.134284019 CEST | 49696 | 25 | 192.168.2.4 | 104.47.18.161 |
May 29, 2023 12:08:57.160191059 CEST | 25 | 49696 | 104.47.18.161 | 192.168.2.4 |
May 29, 2023 12:08:57.160345078 CEST | 49696 | 25 | 192.168.2.4 | 104.47.18.161 |
May 29, 2023 12:08:57.166348934 CEST | 49696 | 25 | 192.168.2.4 | 104.47.18.161 |
May 29, 2023 12:08:57.187882900 CEST | 25 | 49696 | 104.47.18.161 | 192.168.2.4 |
May 29, 2023 12:08:57.187975883 CEST | 49696 | 25 | 192.168.2.4 | 104.47.18.161 |
May 29, 2023 12:08:57.192054033 CEST | 25 | 49696 | 104.47.18.161 | 192.168.2.4 |
May 29, 2023 12:08:57.192157984 CEST | 49696 | 25 | 192.168.2.4 | 104.47.18.161 |
May 29, 2023 12:08:57.192643881 CEST | 25 | 49696 | 104.47.18.161 | 192.168.2.4 |
May 29, 2023 12:08:57.192696095 CEST | 49696 | 25 | 192.168.2.4 | 104.47.18.161 |
May 29, 2023 12:09:07.120112896 CEST | 49697 | 25 | 192.168.2.4 | 67.195.204.74 |
May 29, 2023 12:09:07.231141090 CEST | 25 | 49697 | 67.195.204.74 | 192.168.2.4 |
May 29, 2023 12:09:07.234003067 CEST | 49697 | 25 | 192.168.2.4 | 67.195.204.74 |
May 29, 2023 12:09:07.235549927 CEST | 49697 | 25 | 192.168.2.4 | 67.195.204.74 |
May 29, 2023 12:09:07.348445892 CEST | 25 | 49697 | 67.195.204.74 | 192.168.2.4 |
May 29, 2023 12:09:07.530505896 CEST | 49698 | 25 | 192.168.2.4 | 142.250.150.26 |
May 29, 2023 12:09:07.537208080 CEST | 25 | 49697 | 67.195.204.74 | 192.168.2.4 |
May 29, 2023 12:09:07.537247896 CEST | 25 | 49697 | 67.195.204.74 | 192.168.2.4 |
May 29, 2023 12:09:07.537481070 CEST | 49697 | 25 | 192.168.2.4 | 67.195.204.74 |
May 29, 2023 12:09:07.537858963 CEST | 49697 | 25 | 192.168.2.4 | 67.195.204.74 |
May 29, 2023 12:09:07.580784082 CEST | 25 | 49698 | 142.250.150.26 | 192.168.2.4 |
May 29, 2023 12:09:07.581012964 CEST | 49698 | 25 | 192.168.2.4 | 142.250.150.26 |
May 29, 2023 12:09:07.581238985 CEST | 49698 | 25 | 192.168.2.4 | 142.250.150.26 |
May 29, 2023 12:09:07.631963015 CEST | 25 | 49698 | 142.250.150.26 | 192.168.2.4 |
May 29, 2023 12:09:07.632051945 CEST | 49698 | 25 | 192.168.2.4 | 142.250.150.26 |
May 29, 2023 12:09:07.632909060 CEST | 49699 | 25 | 192.168.2.4 | 104.47.18.161 |
May 29, 2023 12:09:07.658512115 CEST | 25 | 49699 | 104.47.18.161 | 192.168.2.4 |
May 29, 2023 12:09:07.658665895 CEST | 49699 | 25 | 192.168.2.4 | 104.47.18.161 |
May 29, 2023 12:09:07.662638903 CEST | 49699 | 25 | 192.168.2.4 | 104.47.18.161 |
May 29, 2023 12:09:07.685729980 CEST | 25 | 49699 | 104.47.18.161 | 192.168.2.4 |
May 29, 2023 12:09:07.685832024 CEST | 49699 | 25 | 192.168.2.4 | 104.47.18.161 |
May 29, 2023 12:09:07.688389063 CEST | 25 | 49699 | 104.47.18.161 | 192.168.2.4 |
May 29, 2023 12:09:07.688512087 CEST | 49699 | 25 | 192.168.2.4 | 104.47.18.161 |
May 29, 2023 12:09:07.688798904 CEST | 25 | 49699 | 104.47.18.161 | 192.168.2.4 |
May 29, 2023 12:09:07.688863039 CEST | 49699 | 25 | 192.168.2.4 | 104.47.18.161 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
May 29, 2023 12:08:56.446839094 CEST | 59683 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:08:56.469856024 CEST | 53 | 59683 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:08:56.488616943 CEST | 64167 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:08:56.517162085 CEST | 53 | 64167 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:08:56.530642986 CEST | 58565 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:08:56.545115948 CEST | 53 | 58565 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:08:56.558708906 CEST | 52239 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:08:56.565623999 CEST | 56807 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:08:56.573407888 CEST | 53 | 52239 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:08:56.595958948 CEST | 53 | 56807 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:08:56.704440117 CEST | 61007 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:08:56.719270945 CEST | 53 | 61007 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:08:56.770046949 CEST | 60686 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:08:56.772181988 CEST | 61124 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:08:56.813844919 CEST | 53 | 61124 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:08:56.818828106 CEST | 53 | 60686 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:08:56.819009066 CEST | 59444 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:08:56.851736069 CEST | 53 | 59444 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:08:56.858681917 CEST | 55570 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:08:56.891666889 CEST | 53 | 55570 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:08:56.895817995 CEST | 64906 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:08:56.936825991 CEST | 53 | 64906 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:08:56.991333008 CEST | 59446 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:08:56.991942883 CEST | 50861 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:08:57.024194002 CEST | 53 | 50861 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:08:57.027148008 CEST | 53 | 59446 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:08:57.058486938 CEST | 61088 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:08:57.072884083 CEST | 53 | 61088 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:08:57.099978924 CEST | 58729 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:08:57.131136894 CEST | 53 | 58729 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:08:57.207417011 CEST | 64700 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:08:57.209470987 CEST | 56022 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:08:57.216517925 CEST | 60822 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:08:57.234597921 CEST | 53 | 64700 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:08:57.236496925 CEST | 53 | 56022 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:08:57.266289949 CEST | 53 | 60822 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:08:57.545277119 CEST | 49750 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:08:57.567842007 CEST | 53 | 49750 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:08:57.737387896 CEST | 60550 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:08:57.764712095 CEST | 53 | 60550 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:09:06.883358955 CEST | 54851 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:09:06.906258106 CEST | 53 | 54851 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:09:06.936913013 CEST | 57300 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:09:06.951689959 CEST | 53 | 57300 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:09:06.994626999 CEST | 54521 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:09:07.014516115 CEST | 53 | 54521 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:09:07.025388956 CEST | 58914 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:09:07.048424006 CEST | 53 | 58914 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:09:07.115349054 CEST | 51419 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:09:07.146219969 CEST | 53 | 51419 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:09:07.238343954 CEST | 51054 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:09:07.261553049 CEST | 53 | 51054 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:09:07.287853956 CEST | 55673 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:09:07.294683933 CEST | 49735 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:09:07.317189932 CEST | 53 | 55673 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:09:07.325964928 CEST | 53 | 49735 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:09:07.326173067 CEST | 52437 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:09:07.354629040 CEST | 53 | 52437 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:09:07.383367062 CEST | 52825 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:09:07.416253090 CEST | 53 | 52825 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:09:07.445856094 CEST | 58530 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:09:07.474673033 CEST | 64959 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:09:07.487732887 CEST | 53 | 58530 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:09:07.495090008 CEST | 63093 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:09:07.509610891 CEST | 53 | 64959 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:09:07.528597116 CEST | 53 | 63093 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:09:07.583739996 CEST | 50433 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:09:07.606775045 CEST | 53 | 50433 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:09:07.610234976 CEST | 53498 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:09:07.630606890 CEST | 53 | 53498 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:09:07.678050995 CEST | 61460 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:09:07.683275938 CEST | 63001 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:09:07.696145058 CEST | 65133 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:09:07.708158016 CEST | 53 | 61460 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:09:07.723443985 CEST | 53 | 65133 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:09:07.725240946 CEST | 53 | 63001 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:09:07.914297104 CEST | 60998 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:09:07.944766998 CEST | 53 | 60998 | 8.8.8.8 | 192.168.2.4 |
May 29, 2023 12:09:08.182660103 CEST | 61733 | 53 | 192.168.2.4 | 8.8.8.8 |
May 29, 2023 12:09:08.217622995 CEST | 53 | 61733 | 8.8.8.8 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
May 29, 2023 12:08:56.446839094 CEST | 192.168.2.4 | 8.8.8.8 | 0x8db | Standard query (0) | MX (Mail exchange) | IN (0x0001) | false | |
May 29, 2023 12:08:56.488616943 CEST | 192.168.2.4 | 8.8.8.8 | 0x80d4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:08:56.530642986 CEST | 192.168.2.4 | 8.8.8.8 | 0x5569 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:08:56.558708906 CEST | 192.168.2.4 | 8.8.8.8 | 0x5e33 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:08:56.565623999 CEST | 192.168.2.4 | 8.8.8.8 | 0x8b5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:08:56.704440117 CEST | 192.168.2.4 | 8.8.8.8 | 0x7087 | Standard query (0) | MX (Mail exchange) | IN (0x0001) | false | |
May 29, 2023 12:08:56.770046949 CEST | 192.168.2.4 | 8.8.8.8 | 0xc867 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:08:56.772181988 CEST | 192.168.2.4 | 8.8.8.8 | 0xede6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:08:56.819009066 CEST | 192.168.2.4 | 8.8.8.8 | 0x2573 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:08:56.858681917 CEST | 192.168.2.4 | 8.8.8.8 | 0x65ad | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:08:56.895817995 CEST | 192.168.2.4 | 8.8.8.8 | 0xc828 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:08:56.991333008 CEST | 192.168.2.4 | 8.8.8.8 | 0x538a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:08:56.991942883 CEST | 192.168.2.4 | 8.8.8.8 | 0xc5c7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:08:57.058486938 CEST | 192.168.2.4 | 8.8.8.8 | 0x7849 | Standard query (0) | MX (Mail exchange) | IN (0x0001) | false | |
May 29, 2023 12:08:57.099978924 CEST | 192.168.2.4 | 8.8.8.8 | 0x61 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:08:57.207417011 CEST | 192.168.2.4 | 8.8.8.8 | 0x1bcd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:08:57.209470987 CEST | 192.168.2.4 | 8.8.8.8 | 0x1206 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:08:57.216517925 CEST | 192.168.2.4 | 8.8.8.8 | 0x65b3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:08:57.545277119 CEST | 192.168.2.4 | 8.8.8.8 | 0x2846 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:08:57.737387896 CEST | 192.168.2.4 | 8.8.8.8 | 0x95bf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:06.883358955 CEST | 192.168.2.4 | 8.8.8.8 | 0x8b19 | Standard query (0) | MX (Mail exchange) | IN (0x0001) | false | |
May 29, 2023 12:09:06.936913013 CEST | 192.168.2.4 | 8.8.8.8 | 0x864a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:06.994626999 CEST | 192.168.2.4 | 8.8.8.8 | 0x24ab | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:07.025388956 CEST | 192.168.2.4 | 8.8.8.8 | 0x1f7f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:07.115349054 CEST | 192.168.2.4 | 8.8.8.8 | 0x1cd2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:07.238343954 CEST | 192.168.2.4 | 8.8.8.8 | 0x4113 | Standard query (0) | MX (Mail exchange) | IN (0x0001) | false | |
May 29, 2023 12:09:07.287853956 CEST | 192.168.2.4 | 8.8.8.8 | 0xa6a1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:07.294683933 CEST | 192.168.2.4 | 8.8.8.8 | 0x26e6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:07.326173067 CEST | 192.168.2.4 | 8.8.8.8 | 0x5db0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:07.383367062 CEST | 192.168.2.4 | 8.8.8.8 | 0xe333 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:07.445856094 CEST | 192.168.2.4 | 8.8.8.8 | 0x81f2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:07.474673033 CEST | 192.168.2.4 | 8.8.8.8 | 0x1872 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:07.495090008 CEST | 192.168.2.4 | 8.8.8.8 | 0x2b70 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:07.583739996 CEST | 192.168.2.4 | 8.8.8.8 | 0xef9f | Standard query (0) | MX (Mail exchange) | IN (0x0001) | false | |
May 29, 2023 12:09:07.610234976 CEST | 192.168.2.4 | 8.8.8.8 | 0xf139 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:07.678050995 CEST | 192.168.2.4 | 8.8.8.8 | 0xb3e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:07.683275938 CEST | 192.168.2.4 | 8.8.8.8 | 0x9015 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:07.696145058 CEST | 192.168.2.4 | 8.8.8.8 | 0x196e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:07.914297104 CEST | 192.168.2.4 | 8.8.8.8 | 0x2e11 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:08.182660103 CEST | 192.168.2.4 | 8.8.8.8 | 0x89b2 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
May 29, 2023 12:08:56.469856024 CEST | 8.8.8.8 | 192.168.2.4 | 0x8db | No error (0) | MX (Mail exchange) | IN (0x0001) | false | |||
May 29, 2023 12:08:56.469856024 CEST | 8.8.8.8 | 192.168.2.4 | 0x8db | No error (0) | MX (Mail exchange) | IN (0x0001) | false | |||
May 29, 2023 12:08:56.469856024 CEST | 8.8.8.8 | 192.168.2.4 | 0x8db | No error (0) | MX (Mail exchange) | IN (0x0001) | false | |||
May 29, 2023 12:08:56.517162085 CEST | 8.8.8.8 | 192.168.2.4 | 0x80d4 | No error (0) | 67.195.228.110 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.517162085 CEST | 8.8.8.8 | 192.168.2.4 | 0x80d4 | No error (0) | 67.195.228.94 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.517162085 CEST | 8.8.8.8 | 192.168.2.4 | 0x80d4 | No error (0) | 67.195.228.109 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.517162085 CEST | 8.8.8.8 | 192.168.2.4 | 0x80d4 | No error (0) | 67.195.204.74 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.517162085 CEST | 8.8.8.8 | 192.168.2.4 | 0x80d4 | No error (0) | 67.195.204.72 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.517162085 CEST | 8.8.8.8 | 192.168.2.4 | 0x80d4 | No error (0) | 67.195.228.111 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.517162085 CEST | 8.8.8.8 | 192.168.2.4 | 0x80d4 | No error (0) | 98.136.96.77 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.517162085 CEST | 8.8.8.8 | 192.168.2.4 | 0x80d4 | No error (0) | 67.195.204.73 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.545115948 CEST | 8.8.8.8 | 192.168.2.4 | 0x5569 | No error (0) | 67.195.228.106 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.545115948 CEST | 8.8.8.8 | 192.168.2.4 | 0x5569 | No error (0) | 67.195.204.73 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.545115948 CEST | 8.8.8.8 | 192.168.2.4 | 0x5569 | No error (0) | 67.195.228.110 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.545115948 CEST | 8.8.8.8 | 192.168.2.4 | 0x5569 | No error (0) | 67.195.204.79 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.545115948 CEST | 8.8.8.8 | 192.168.2.4 | 0x5569 | No error (0) | 67.195.204.77 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.545115948 CEST | 8.8.8.8 | 192.168.2.4 | 0x5569 | No error (0) | 98.136.96.74 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.545115948 CEST | 8.8.8.8 | 192.168.2.4 | 0x5569 | No error (0) | 67.195.204.72 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.545115948 CEST | 8.8.8.8 | 192.168.2.4 | 0x5569 | No error (0) | 67.195.228.109 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.573407888 CEST | 8.8.8.8 | 192.168.2.4 | 0x5e33 | No error (0) | 67.195.204.79 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.573407888 CEST | 8.8.8.8 | 192.168.2.4 | 0x5e33 | No error (0) | 98.136.96.91 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.573407888 CEST | 8.8.8.8 | 192.168.2.4 | 0x5e33 | No error (0) | 98.136.96.74 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.573407888 CEST | 8.8.8.8 | 192.168.2.4 | 0x5e33 | No error (0) | 67.195.228.111 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.573407888 CEST | 8.8.8.8 | 192.168.2.4 | 0x5e33 | No error (0) | 98.136.96.76 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.573407888 CEST | 8.8.8.8 | 192.168.2.4 | 0x5e33 | No error (0) | 67.195.228.106 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.573407888 CEST | 8.8.8.8 | 192.168.2.4 | 0x5e33 | No error (0) | 67.195.228.94 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.573407888 CEST | 8.8.8.8 | 192.168.2.4 | 0x5e33 | No error (0) | 67.195.228.110 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.595958948 CEST | 8.8.8.8 | 192.168.2.4 | 0x8b5 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:08:56.719270945 CEST | 8.8.8.8 | 192.168.2.4 | 0x7087 | No error (0) | MX (Mail exchange) | IN (0x0001) | false | |||
May 29, 2023 12:08:56.719270945 CEST | 8.8.8.8 | 192.168.2.4 | 0x7087 | No error (0) | MX (Mail exchange) | IN (0x0001) | false | |||
May 29, 2023 12:08:56.719270945 CEST | 8.8.8.8 | 192.168.2.4 | 0x7087 | No error (0) | MX (Mail exchange) | IN (0x0001) | false | |||
May 29, 2023 12:08:56.719270945 CEST | 8.8.8.8 | 192.168.2.4 | 0x7087 | No error (0) | MX (Mail exchange) | IN (0x0001) | false | |||
May 29, 2023 12:08:56.719270945 CEST | 8.8.8.8 | 192.168.2.4 | 0x7087 | No error (0) | MX (Mail exchange) | IN (0x0001) | false | |||
May 29, 2023 12:08:56.813844919 CEST | 8.8.8.8 | 192.168.2.4 | 0xede6 | No error (0) | 142.250.157.27 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.818828106 CEST | 8.8.8.8 | 192.168.2.4 | 0xc867 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:08:56.851736069 CEST | 8.8.8.8 | 192.168.2.4 | 0x2573 | No error (0) | 142.251.9.27 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.891666889 CEST | 8.8.8.8 | 192.168.2.4 | 0x65ad | No error (0) | 142.250.27.26 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:56.936825991 CEST | 8.8.8.8 | 192.168.2.4 | 0xc828 | No error (0) | 74.125.200.27 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:57.024194002 CEST | 8.8.8.8 | 192.168.2.4 | 0xc5c7 | No error (0) | 142.250.150.26 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:57.027148008 CEST | 8.8.8.8 | 192.168.2.4 | 0x538a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:08:57.072884083 CEST | 8.8.8.8 | 192.168.2.4 | 0x7849 | No error (0) | MX (Mail exchange) | IN (0x0001) | false | |||
May 29, 2023 12:08:57.131136894 CEST | 8.8.8.8 | 192.168.2.4 | 0x61 | No error (0) | 104.47.18.161 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:57.131136894 CEST | 8.8.8.8 | 192.168.2.4 | 0x61 | No error (0) | 104.47.18.225 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:08:57.234597921 CEST | 8.8.8.8 | 192.168.2.4 | 0x1bcd | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:08:57.236496925 CEST | 8.8.8.8 | 192.168.2.4 | 0x1206 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:08:57.266289949 CEST | 8.8.8.8 | 192.168.2.4 | 0x65b3 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:08:57.567842007 CEST | 8.8.8.8 | 192.168.2.4 | 0x2846 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:08:57.764712095 CEST | 8.8.8.8 | 192.168.2.4 | 0x95bf | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:06.906258106 CEST | 8.8.8.8 | 192.168.2.4 | 0x8b19 | No error (0) | MX (Mail exchange) | IN (0x0001) | false | |||
May 29, 2023 12:09:06.906258106 CEST | 8.8.8.8 | 192.168.2.4 | 0x8b19 | No error (0) | MX (Mail exchange) | IN (0x0001) | false | |||
May 29, 2023 12:09:06.906258106 CEST | 8.8.8.8 | 192.168.2.4 | 0x8b19 | No error (0) | MX (Mail exchange) | IN (0x0001) | false | |||
May 29, 2023 12:09:06.951689959 CEST | 8.8.8.8 | 192.168.2.4 | 0x864a | No error (0) | 67.195.228.111 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:06.951689959 CEST | 8.8.8.8 | 192.168.2.4 | 0x864a | No error (0) | 98.136.96.77 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:06.951689959 CEST | 8.8.8.8 | 192.168.2.4 | 0x864a | No error (0) | 98.136.96.74 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:06.951689959 CEST | 8.8.8.8 | 192.168.2.4 | 0x864a | No error (0) | 67.195.228.109 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:06.951689959 CEST | 8.8.8.8 | 192.168.2.4 | 0x864a | No error (0) | 98.136.96.75 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:06.951689959 CEST | 8.8.8.8 | 192.168.2.4 | 0x864a | No error (0) | 67.195.228.106 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:06.951689959 CEST | 8.8.8.8 | 192.168.2.4 | 0x864a | No error (0) | 67.195.228.94 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:06.951689959 CEST | 8.8.8.8 | 192.168.2.4 | 0x864a | No error (0) | 98.136.96.91 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.014516115 CEST | 8.8.8.8 | 192.168.2.4 | 0x24ab | No error (0) | 67.195.204.74 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.014516115 CEST | 8.8.8.8 | 192.168.2.4 | 0x24ab | No error (0) | 67.195.204.73 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.014516115 CEST | 8.8.8.8 | 192.168.2.4 | 0x24ab | No error (0) | 98.136.96.77 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.014516115 CEST | 8.8.8.8 | 192.168.2.4 | 0x24ab | No error (0) | 67.195.228.110 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.014516115 CEST | 8.8.8.8 | 192.168.2.4 | 0x24ab | No error (0) | 98.136.96.76 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.014516115 CEST | 8.8.8.8 | 192.168.2.4 | 0x24ab | No error (0) | 98.136.96.75 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.014516115 CEST | 8.8.8.8 | 192.168.2.4 | 0x24ab | No error (0) | 67.195.228.111 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.014516115 CEST | 8.8.8.8 | 192.168.2.4 | 0x24ab | No error (0) | 67.195.204.79 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.048424006 CEST | 8.8.8.8 | 192.168.2.4 | 0x1f7f | No error (0) | 67.195.228.94 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.048424006 CEST | 8.8.8.8 | 192.168.2.4 | 0x1f7f | No error (0) | 67.195.228.111 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.048424006 CEST | 8.8.8.8 | 192.168.2.4 | 0x1f7f | No error (0) | 67.195.204.79 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.048424006 CEST | 8.8.8.8 | 192.168.2.4 | 0x1f7f | No error (0) | 67.195.204.73 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.048424006 CEST | 8.8.8.8 | 192.168.2.4 | 0x1f7f | No error (0) | 98.136.96.77 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.048424006 CEST | 8.8.8.8 | 192.168.2.4 | 0x1f7f | No error (0) | 67.195.204.77 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.048424006 CEST | 8.8.8.8 | 192.168.2.4 | 0x1f7f | No error (0) | 98.136.96.74 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.048424006 CEST | 8.8.8.8 | 192.168.2.4 | 0x1f7f | No error (0) | 67.195.228.110 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.146219969 CEST | 8.8.8.8 | 192.168.2.4 | 0x1cd2 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:07.261553049 CEST | 8.8.8.8 | 192.168.2.4 | 0x4113 | No error (0) | MX (Mail exchange) | IN (0x0001) | false | |||
May 29, 2023 12:09:07.261553049 CEST | 8.8.8.8 | 192.168.2.4 | 0x4113 | No error (0) | MX (Mail exchange) | IN (0x0001) | false | |||
May 29, 2023 12:09:07.261553049 CEST | 8.8.8.8 | 192.168.2.4 | 0x4113 | No error (0) | MX (Mail exchange) | IN (0x0001) | false | |||
May 29, 2023 12:09:07.261553049 CEST | 8.8.8.8 | 192.168.2.4 | 0x4113 | No error (0) | MX (Mail exchange) | IN (0x0001) | false | |||
May 29, 2023 12:09:07.261553049 CEST | 8.8.8.8 | 192.168.2.4 | 0x4113 | No error (0) | MX (Mail exchange) | IN (0x0001) | false | |||
May 29, 2023 12:09:07.317189932 CEST | 8.8.8.8 | 192.168.2.4 | 0xa6a1 | No error (0) | 142.250.157.27 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.325964928 CEST | 8.8.8.8 | 192.168.2.4 | 0x26e6 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:07.354629040 CEST | 8.8.8.8 | 192.168.2.4 | 0x5db0 | No error (0) | 142.251.9.27 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.416253090 CEST | 8.8.8.8 | 192.168.2.4 | 0xe333 | No error (0) | 142.250.27.27 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.487732887 CEST | 8.8.8.8 | 192.168.2.4 | 0x81f2 | No error (0) | 74.125.200.26 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.509610891 CEST | 8.8.8.8 | 192.168.2.4 | 0x1872 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:07.528597116 CEST | 8.8.8.8 | 192.168.2.4 | 0x2b70 | No error (0) | 142.250.150.26 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.606775045 CEST | 8.8.8.8 | 192.168.2.4 | 0xef9f | No error (0) | MX (Mail exchange) | IN (0x0001) | false | |||
May 29, 2023 12:09:07.630606890 CEST | 8.8.8.8 | 192.168.2.4 | 0xf139 | No error (0) | 104.47.18.161 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.630606890 CEST | 8.8.8.8 | 192.168.2.4 | 0xf139 | No error (0) | 104.47.18.225 | A (IP address) | IN (0x0001) | false | ||
May 29, 2023 12:09:07.708158016 CEST | 8.8.8.8 | 192.168.2.4 | 0xb3e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:07.723443985 CEST | 8.8.8.8 | 192.168.2.4 | 0x196e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:07.725240946 CEST | 8.8.8.8 | 192.168.2.4 | 0x9015 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:07.944766998 CEST | 8.8.8.8 | 192.168.2.4 | 0x2e11 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
May 29, 2023 12:09:08.217622995 CEST | 8.8.8.8 | 192.168.2.4 | 0x89b2 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false |
Timestamp | Source Port | Dest Port | Source IP | Dest IP | Commands |
---|---|---|---|---|---|
May 29, 2023 12:08:56.892046928 CEST | 25 | 49694 | 67.195.204.79 | 192.168.2.4 | 220 mtaproxy212.free.mail.bf1.yahoo.com ESMTP ready |
May 29, 2023 12:08:57.187882900 CEST | 25 | 49696 | 104.47.18.161 | 192.168.2.4 | 220 AM7EUR06FT057.mail.protection.outlook.com Microsoft ESMTP MAIL Service ready at Mon, 29 May 2023 10:08:56 +0000 |
May 29, 2023 12:09:07.537208080 CEST | 25 | 49697 | 67.195.204.74 | 192.168.2.4 | 220 mtaproxy512.free.mail.bf1.yahoo.com ESMTP ready |
May 29, 2023 12:09:07.685729980 CEST | 25 | 49699 | 104.47.18.161 | 192.168.2.4 | 220 AM7EUR06FT036.mail.protection.outlook.com Microsoft ESMTP MAIL Service ready at Mon, 29 May 2023 10:09:07 +0000 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 12:08:29 |
Start date: | 29/05/2023 |
Path: | C:\Users\user\Desktop\file.msg.scr.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 520196 bytes |
MD5 hash: | 6B7ED3ABDD8484B313948BA83FDE717F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Target ID: | 2 |
Start time: | 12:08:35 |
Start date: | 29/05/2023 |
Path: | C:\Windows\serv.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 520196 bytes |
MD5 hash: | 6B7ED3ABDD8484B313948BA83FDE717F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | low |
Target ID: | 3 |
Start time: | 12:08:35 |
Start date: | 29/05/2023 |
Path: | C:\Windows\SysWOW64\notepad.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xa90000 |
File size: | 236032 bytes |
MD5 hash: | D693F13FE3AA2010B854C4C60671B8E2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Target ID: | 4 |
Start time: | 12:08:45 |
Start date: | 29/05/2023 |
Path: | C:\Windows\explorer.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff618f60000 |
File size: | 3933184 bytes |
MD5 hash: | AD5296B280E8F522A8A897C96BAB0E1D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Target ID: | 5 |
Start time: | 12:08:55 |
Start date: | 29/05/2023 |
Path: | C:\Windows\serv.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 520196 bytes |
MD5 hash: | 6B7ED3ABDD8484B313948BA83FDE717F |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Target ID: | 8 |
Start time: | 12:08:57 |
Start date: | 29/05/2023 |
Path: | C:\Windows\SysWOW64\WerFault.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xe50000 |
File size: | 434592 bytes |
MD5 hash: | 9E2B8ACAD48ECCA55C0230D63623661B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Target ID: | 10 |
Start time: | 12:08:59 |
Start date: | 29/05/2023 |
Path: | C:\Windows\SysWOW64\WerFault.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xe50000 |
File size: | 434592 bytes |
MD5 hash: | 9E2B8ACAD48ECCA55C0230D63623661B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Target ID: | 13 |
Start time: | 12:09:08 |
Start date: | 29/05/2023 |
Path: | C:\Windows\SysWOW64\WerFault.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xe50000 |
File size: | 434592 bytes |
MD5 hash: | 9E2B8ACAD48ECCA55C0230D63623661B |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Execution Graph
Execution Coverage: | 1.9% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 10.2% |
Total number of Nodes: | 1464 |
Total number of Limit Nodes: | 45 |
Graph
Function 0041F2B0 Relevance: 10.6, APIs: 2, Strings: 4, Instructions: 79libraryloaderCOMMON
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00423F8A Relevance: 1.5, APIs: 1, Instructions: 5COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00423F9E Relevance: 1.5, APIs: 1, Instructions: 3COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041B2D0 Relevance: 14.0, APIs: 1, Strings: 7, Instructions: 44fileCOMMON
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 93% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041B070 Relevance: 12.3, APIs: 1, Strings: 6, Instructions: 55processCOMMON
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041ACD0 Relevance: 12.3, APIs: 1, Strings: 6, Instructions: 35memoryCOMMON
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041B470 Relevance: 10.5, APIs: 1, Strings: 5, Instructions: 40fileCOMMON
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00425396 Relevance: 10.5, APIs: 3, Strings: 3, Instructions: 13libraryloaderCOMMONLIBRARYCODE
Control-flow Graph
C-Code - Quality: 68% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041AD50 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 34memoryCOMMON
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00427472 Relevance: 3.1, APIs: 2, Instructions: 59memoryCOMMONLIBRARYCODE
Control-flow Graph
C-Code - Quality: 76% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00422E44 Relevance: 3.0, APIs: 2, Instructions: 34memoryCOMMONLIBRARYCODE
Control-flow Graph
C-Code - Quality: 61% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00424675 Relevance: 3.0, APIs: 2, Instructions: 26memoryCOMMON
C-Code - Quality: 91% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041C090 Relevance: 1.5, APIs: 1, Instructions: 43COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041D130 Relevance: 1.5, APIs: 1, Instructions: 38serviceCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041A8E0 Relevance: 1.5, APIs: 1, Instructions: 34COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00408980 Relevance: 236.3, APIs: 1, Strings: 133, Instructions: 1751COMMONCrypto
C-Code - Quality: 99% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 99% |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 81% |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00414310 Relevance: 32.0, APIs: 2, Strings: 19, Instructions: 486COMMONCrypto
C-Code - Quality: 51% |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00413040 Relevance: 26.5, APIs: 1, Strings: 14, Instructions: 253COMMONCrypto
C-Code - Quality: 89% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004184D0 Relevance: 19.7, APIs: 2, Strings: 11, Instructions: 244stringCOMMONCrypto
C-Code - Quality: 64% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 95% |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00429AAE Relevance: 7.6, APIs: 5, Instructions: 92memoryCOMMON
C-Code - Quality: 86% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040D1C0 Relevance: 6.0, APIs: 4, Instructions: 36COMMONCrypto
C-Code - Quality: 72% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004215C0 Relevance: 5.0, APIs: 3, Instructions: 482COMMON
C-Code - Quality: 100% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004122F0 Relevance: 1.6, APIs: 1, Instructions: 73timeCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 67% |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 96% |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004188E0 Relevance: .6, Instructions: 563COMMONCrypto
C-Code - Quality: 91% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00413770 Relevance: .4, Instructions: 357COMMONCrypto
C-Code - Quality: 94% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0042C297 Relevance: .1, Instructions: 94COMMONCrypto
C-Code - Quality: 100% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00424278 Relevance: .1, Instructions: 77COMMONCrypto
C-Code - Quality: 71% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041B250 Relevance: .0, Instructions: 34COMMON
C-Code - Quality: 37% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041AC50 Relevance: .0, Instructions: 34COMMON
C-Code - Quality: 37% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00426A34 Relevance: 26.4, APIs: 11, Strings: 4, Instructions: 115fileCOMMONLIBRARYCODE
C-Code - Quality: 71% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404920 Relevance: 26.4, APIs: 2, Strings: 13, Instructions: 112librarystringloaderCOMMON
C-Code - Quality: 79% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00429C54 Relevance: 26.3, APIs: 7, Strings: 8, Instructions: 97COMMONLIBRARYCODE
C-Code - Quality: 57% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00423D97 Relevance: 24.6, APIs: 8, Strings: 6, Instructions: 71libraryloadermemoryCOMMON
C-Code - Quality: 76% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00406820 Relevance: 22.7, APIs: 10, Strings: 5, Instructions: 232stringCOMMON
C-Code - Quality: 36% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00429202 Relevance: 21.1, APIs: 6, Strings: 6, Instructions: 90libraryloaderCOMMONLIBRARYCODE
C-Code - Quality: 29% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041E5F0 Relevance: 21.1, APIs: 2, Strings: 10, Instructions: 55libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041C580 Relevance: 17.6, APIs: 2, Strings: 8, Instructions: 85libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 75% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041DA50 Relevance: 14.1, APIs: 2, Strings: 6, Instructions: 66libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041E6C0 Relevance: 14.1, APIs: 2, Strings: 6, Instructions: 59libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041D870 Relevance: 14.1, APIs: 2, Strings: 6, Instructions: 51libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041A600 Relevance: 12.3, APIs: 2, Strings: 5, Instructions: 92libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 86% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0042707A Relevance: 12.1, APIs: 8, Instructions: 131COMMON
C-Code - Quality: 98% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004181F0 Relevance: 12.1, APIs: 2, Strings: 6, Instructions: 105stringCOMMON
C-Code - Quality: 53% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 80% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00428EC6 Relevance: 9.0, APIs: 4, Strings: 1, Instructions: 247fileCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 85% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00427A37 Relevance: 8.8, APIs: 2, Strings: 3, Instructions: 29libraryloaderCOMMONLIBRARYCODE
C-Code - Quality: 62% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00427AC2 Relevance: 7.7, APIs: 5, Instructions: 184COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0042719C Relevance: 7.7, APIs: 5, Instructions: 172COMMON
C-Code - Quality: 97% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004251E9 Relevance: 7.6, APIs: 5, Instructions: 150COMMON
C-Code - Quality: 54% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00423BDF Relevance: 7.5, APIs: 5, Instructions: 37threadCOMMONLIBRARYCODE
C-Code - Quality: 75% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 87% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00426055 Relevance: 6.2, APIs: 4, Instructions: 167fileCOMMON
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00428BF3 Relevance: 6.1, APIs: 4, Instructions: 113COMMON
C-Code - Quality: 73% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00426DA5 Relevance: 6.1, APIs: 4, Instructions: 74COMMON
C-Code - Quality: 95% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00424A51 Relevance: 6.1, APIs: 4, Instructions: 57memoryCOMMONLIBRARYCODE
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00418330 Relevance: 6.0, APIs: 1, Strings: 3, Instructions: 40stringCOMMON
C-Code - Quality: 37% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00416ED0 Relevance: 5.6, APIs: 2, Strings: 1, Instructions: 344sleepCOMMON
C-Code - Quality: 92% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 96% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00427585 Relevance: 5.4, APIs: 1, Strings: 2, Instructions: 124COMMONLIBRARYCODE
C-Code - Quality: 65% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 95% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 69% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 86% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 11.2% |
Dynamic/Decrypted Code Coverage: | 3.3% |
Signature Coverage: | 0.9% |
Total number of Nodes: | 2000 |
Total number of Limit Nodes: | 77 |
Graph
Function 00414310 Relevance: 39.5, APIs: 7, Strings: 19, Instructions: 486COMMONCrypto
Control-flow Graph
C-Code - Quality: 82% |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041B4F0 Relevance: 24.6, APIs: 1, Strings: 13, Instructions: 51processCOMMON
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041BF10 Relevance: 15.8, APIs: 1, Strings: 8, Instructions: 38fileCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041CB80 Relevance: 1.6, APIs: 1, Instructions: 55COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041C400 Relevance: 1.6, APIs: 1, Instructions: 52COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0056184A Relevance: 1.5, APIs: 1, Instructions: 34nativeCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00423F8A Relevance: 1.5, APIs: 1, Instructions: 5COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005618AB Relevance: 50.8, APIs: 2, Strings: 27, Instructions: 76libraryloaderCOMMON
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00406820 Relevance: 22.7, APIs: 10, Strings: 5, Instructions: 232stringCOMMON
Control-flow Graph
C-Code - Quality: 36% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041C720 Relevance: 19.3, APIs: 1, Strings: 10, Instructions: 48registryCOMMON
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041C7D0 Relevance: 19.3, APIs: 1, Strings: 10, Instructions: 45registryCOMMON
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041BE50 Relevance: 17.6, APIs: 1, Strings: 9, Instructions: 54threadinjectionCOMMON
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041D320 Relevance: 15.8, APIs: 1, Strings: 8, Instructions: 50registryCOMMON
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041BD10 Relevance: 15.8, APIs: 1, Strings: 8, Instructions: 50injectionCOMMON
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041D680 Relevance: 15.8, APIs: 1, Strings: 8, Instructions: 49networkCOMMON
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041C870 Relevance: 15.8, APIs: 1, Strings: 8, Instructions: 32registryCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041DA50 Relevance: 14.1, APIs: 2, Strings: 6, Instructions: 66libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041E6C0 Relevance: 14.1, APIs: 2, Strings: 6, Instructions: 59libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041D870 Relevance: 14.1, APIs: 2, Strings: 6, Instructions: 51libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041B2D0 Relevance: 14.0, APIs: 1, Strings: 7, Instructions: 44fileCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041D920 Relevance: 14.0, APIs: 1, Strings: 7, Instructions: 39networkCOMMON
C-Code - Quality: 37% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 37% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 93% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041E150 Relevance: 12.3, APIs: 1, Strings: 6, Instructions: 41networkCOMMON
C-Code - Quality: 37% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041BFA0 Relevance: 12.3, APIs: 1, Strings: 6, Instructions: 38fileCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041ACD0 Relevance: 12.3, APIs: 1, Strings: 6, Instructions: 35memoryCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041DB30 Relevance: 12.3, APIs: 1, Strings: 6, Instructions: 34networkCOMMON
C-Code - Quality: 37% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 95% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041F2B0 Relevance: 10.6, APIs: 2, Strings: 4, Instructions: 79libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041B1B0 Relevance: 10.5, APIs: 1, Strings: 5, Instructions: 46threadCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041B470 Relevance: 10.5, APIs: 1, Strings: 5, Instructions: 40fileCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00428EC6 Relevance: 9.0, APIs: 4, Strings: 1, Instructions: 247fileCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00426055 Relevance: 6.2, APIs: 4, Instructions: 167fileCOMMON
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00561647 Relevance: 6.2, APIs: 2, Strings: 2, Instructions: 161stringCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 96% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 93% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041B960 Relevance: 4.5, APIs: 1, Strings: 2, Instructions: 27sleepCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041DC80 Relevance: 3.5, APIs: 1, Strings: 1, Instructions: 35networkCOMMON
C-Code - Quality: 37% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 94% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00427472 Relevance: 3.1, APIs: 2, Instructions: 59memoryCOMMONLIBRARYCODE
C-Code - Quality: 76% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0042275E Relevance: 3.0, APIs: 2, Instructions: 35memoryCOMMONLIBRARYCODE
C-Code - Quality: 18% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00422E44 Relevance: 3.0, APIs: 2, Instructions: 34memoryCOMMONLIBRARYCODE
C-Code - Quality: 61% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00424675 Relevance: 3.0, APIs: 2, Instructions: 26memoryCOMMON
C-Code - Quality: 91% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00406680 Relevance: 1.7, APIs: 1, Instructions: 153fileCOMMON
C-Code - Quality: 93% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00425F74 Relevance: 1.6, APIs: 1, Instructions: 79COMMON
C-Code - Quality: 90% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041D510 Relevance: 1.6, APIs: 1, Instructions: 57networkCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041CAC0 Relevance: 1.6, APIs: 1, Instructions: 51COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041E270 Relevance: 1.5, APIs: 1, Instructions: 48networkCOMMON
C-Code - Quality: 37% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041B6C0 Relevance: 1.5, APIs: 1, Instructions: 45COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041D5F0 Relevance: 1.5, APIs: 1, Instructions: 44networkCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041C090 Relevance: 1.5, APIs: 1, Instructions: 43COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041E1E0 Relevance: 1.5, APIs: 1, Instructions: 43networkCOMMON
C-Code - Quality: 37% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041BC70 Relevance: 1.5, APIs: 1, Instructions: 43memoryCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041DFB0 Relevance: 1.5, APIs: 1, Instructions: 42networkCOMMON
C-Code - Quality: 37% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041D130 Relevance: 1.5, APIs: 1, Instructions: 38serviceCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00561D1B Relevance: 1.5, APIs: 1, Instructions: 37memoryCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041A8E0 Relevance: 1.5, APIs: 1, Instructions: 34COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041AEE0 Relevance: 1.5, APIs: 1, Instructions: 33fileCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 10001470 Relevance: 49.4, APIs: 6, Strings: 22, Instructions: 375libraryCOMMONCrypto
C-Code - Quality: 100% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 86% |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00413040 Relevance: 28.3, APIs: 2, Strings: 14, Instructions: 253COMMONCrypto
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004184D0 Relevance: 22.7, APIs: 4, Strings: 11, Instructions: 244stringCOMMONCrypto
C-Code - Quality: 81% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040D1C0 Relevance: 6.0, APIs: 4, Instructions: 36COMMONCrypto
C-Code - Quality: 72% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 94% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00426A34 Relevance: 26.4, APIs: 11, Strings: 4, Instructions: 115fileCOMMONLIBRARYCODE
C-Code - Quality: 71% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404920 Relevance: 26.4, APIs: 2, Strings: 13, Instructions: 112librarystringloaderCOMMON
C-Code - Quality: 79% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00429C54 Relevance: 26.3, APIs: 7, Strings: 8, Instructions: 97COMMONLIBRARYCODE
C-Code - Quality: 57% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00423D97 Relevance: 24.6, APIs: 8, Strings: 6, Instructions: 71libraryloadermemoryCOMMON
C-Code - Quality: 76% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00429202 Relevance: 21.1, APIs: 6, Strings: 6, Instructions: 90libraryloaderCOMMONLIBRARYCODE
C-Code - Quality: 29% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041E5F0 Relevance: 21.1, APIs: 2, Strings: 10, Instructions: 55libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00561A0E Relevance: 21.0, APIs: 2, Strings: 10, Instructions: 48libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041C580 Relevance: 17.6, APIs: 2, Strings: 8, Instructions: 85libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00561E4A Relevance: 17.5, APIs: 2, Strings: 8, Instructions: 46libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 75% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 10002500 Relevance: 14.1, APIs: 2, Strings: 6, Instructions: 59libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0041A600 Relevance: 12.3, APIs: 2, Strings: 5, Instructions: 92libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 10002070 Relevance: 12.3, APIs: 2, Strings: 5, Instructions: 92libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 86% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0042707A Relevance: 12.1, APIs: 8, Instructions: 131COMMON
C-Code - Quality: 98% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004181F0 Relevance: 12.1, APIs: 2, Strings: 6, Instructions: 105stringCOMMON
C-Code - Quality: 53% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00425396 Relevance: 10.5, APIs: 3, Strings: 3, Instructions: 13libraryloaderCOMMONLIBRARYCODE
C-Code - Quality: 68% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 80% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 85% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00561D92 Relevance: 8.8, APIs: 2, Strings: 3, Instructions: 55libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00427A37 Relevance: 8.8, APIs: 2, Strings: 3, Instructions: 29libraryloaderCOMMONLIBRARYCODE
C-Code - Quality: 62% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 97% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00427AC2 Relevance: 7.7, APIs: 5, Instructions: 184COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0042719C Relevance: 7.7, APIs: 5, Instructions: 172COMMON
C-Code - Quality: 97% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004251E9 Relevance: 7.6, APIs: 5, Instructions: 150COMMON
C-Code - Quality: 54% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00429AAE Relevance: 7.6, APIs: 5, Instructions: 92memoryCOMMON
C-Code - Quality: 86% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00423BDF Relevance: 7.5, APIs: 5, Instructions: 37threadCOMMONLIBRARYCODE
C-Code - Quality: 75% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 87% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00428BF3 Relevance: 6.1, APIs: 4, Instructions: 113COMMON
C-Code - Quality: 73% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00426DA5 Relevance: 6.1, APIs: 4, Instructions: 74COMMON
C-Code - Quality: 95% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00424A51 Relevance: 6.1, APIs: 4, Instructions: 57memoryCOMMONLIBRARYCODE
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00418330 Relevance: 6.0, APIs: 1, Strings: 3, Instructions: 40stringCOMMON
C-Code - Quality: 37% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00416ED0 Relevance: 5.6, APIs: 2, Strings: 1, Instructions: 344sleepCOMMON
C-Code - Quality: 92% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00427585 Relevance: 5.4, APIs: 1, Strings: 2, Instructions: 124COMMONLIBRARYCODE
C-Code - Quality: 65% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 95% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 69% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 86% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |