Windows
Analysis Report
Infor IDF Auxiliary Machine.exe
Overview
General Information
Detection
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- Infor IDF Auxiliary Machine.exe (PID: 7316 cmdline:
"C:\Users\ user\Deskt op\Infor I DF Auxilia ry Machine .exe" MD5: 62CDC45806E717F187E2F46780BD6834) - conhost.exe (PID: 7324 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | String found in binary or memory: |
System Summary |
---|
Source: | Static PE information: |
Source: | Code function: | 0_2_004166FC | |
Source: | Code function: | 0_2_0040C8E0 | |
Source: | Code function: | 0_2_0041ACE1 | |
Source: | Code function: | 0_2_00408E5D | |
Source: | Code function: | 0_2_00413F00 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Mutant created: |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Data Obfuscation |
---|
Source: | Unpacked PE file: |
Source: | Code function: | 0_2_0041F805 |
Source: | Code function: | 0_2_0042D0A1 | |
Source: | Code function: | 0_2_00428019 | |
Source: | Code function: | 0_2_004283D9 | |
Source: | Code function: | 0_2_004166FB | |
Source: | Code function: | 0_2_00415746 | |
Source: | Code function: | 0_2_0041C894 | |
Source: | Code function: | 0_2_0041C8BC |
Source: | Static PE information: |
Source: | Evasive API call chain: | graph_0-19947 |
Source: | API coverage: |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Last function: |
Source: | Code function: | 0_2_0041E627 |
Source: | API call chain: | graph_0-19949 |
Source: | Code function: | 0_2_0041F805 |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Code function: | 0_2_0041C9CE | |
Source: | Code function: | 0_2_0041C9BA |
Source: | Code function: | 0_2_0041E70A | |
Source: | Code function: | 0_2_0041F8FE | |
Source: | Code function: | 0_2_0041D992 | |
Source: | Code function: | 0_2_0041F9BA | |
Source: | Code function: | 0_2_0041FA2E | |
Source: | Code function: | 0_2_0041DEE8 | |
Source: | Code function: | 0_2_0041DEB1 | |
Source: | Code function: | 0_2_0041DF6E | |
Source: | Code function: | 0_2_0041DFC3 |
Source: | Code function: | 0_2_0041E429 |
Source: | Code function: | 0_2_00414FC6 |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 2 Native API | 1 DLL Side-Loading | 1 Process Injection | 12 Software Packing | OS Credential Dumping | 1 System Time Discovery | Remote Services | 1 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 1 Process Injection | LSASS Memory | 14 System Information Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Deobfuscate/Decode Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 DLL Side-Loading | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 3 Obfuscated Files or Information | LSA Secrets | Internet Connection Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | ReversingLabs | |||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1500785 |
Start date and time: | 2024-08-28 22:50:16 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 1m 51s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 3 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | Infor IDF Auxiliary Machine.exe |
Detection: | MAL |
Classification: | mal60.evad.winEXE@2/0@0/0 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: Infor IDF Auxiliary Machine.exe
File type: | |
Entropy (8bit): | 7.719974222025018 |
TrID: |
|
File name: | Infor IDF Auxiliary Machine.exe |
File size: | 122'880 bytes |
MD5: | 62cdc45806e717f187e2f46780bd6834 |
SHA1: | c84eb7d4061d8e57a37c493ca28a06403f56501d |
SHA256: | 574bd976108995da86f648aad2403e6780d11bc36d579ce0a6098bd69287769a |
SHA512: | 888edf170ea8dfdf165c6107efd9beff18e80597911b0df29a50aba31f91a5040504c23610492a896f5c04e3c3324e9c27681795304834e94e723038221bb6ae |
SSDEEP: | 3072:YM5y2eLmj6MgLi58xh4V9A/PW/nVaTyVHZdY:KKj6ZLAaHWfVlY |
TLSH: | 7BC3F1D6E6405DBBE06D0572CD3312A02BB0B9093F23968716F36ADB3C71A25258F6DD |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........r8...V...V...V...Y...V...6...V.....*.V.......V...?...V.9.....V.9.....V...W...V...2...V.V.....V.......V.Rich..V.........PE..L.. |
Icon Hash: | 76e9daf4c888b0f0 |
Entrypoint: | 0x414fc6 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows cui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE |
DLL Characteristics: | |
Time Stamp: | 0x4C650145 [Fri Aug 13 08:24:37 2010 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | 09d0478591d4f788cb3e5ea416c25237 |
Instruction |
---|
mov eax, 004438FCh |
push eax |
push dword ptr fs:[00000000h] |
mov dword ptr fs:[00000000h], esp |
xor eax, eax |
mov dword ptr [eax], ecx |
push eax |
inc ebp |
inc ebx |
outsd |
insd |
jo 00007F7010D149E3h |
arpl word ptr [edx+esi+00h], si |
pop ecx |
retf |
aam 16h |
pop es |
pushad |
rcr byte ptr [ecx], 00000022h |
je 00007F7010D149A9h |
in eax, 22h |
dec esp |
mov ebx, 26449820h |
pop esi |
add al, D1h |
imul eax, esp, EEC4E71Eh |
salc |
push FFFFFFA6h |
inc eax |
or eax, dword ptr [esi-6CCA1C66h] |
and dl, byte ptr [edi] |
in al, 68h |
fidiv dword ptr [eax+6303CD78h] |
xor edx, dword ptr [ebx+44h] |
push esp |
mov esp, dword ptr [ebp+72h] |
sbb ch, byte ptr [edi] |
jnl 00007F7010D149F6h |
mov bx, ds |
and dword ptr [edx], A02D8029h |
mov ebx, D0E870ACh |
and cl, ch |
push 00000046h |
sub al, 02h |
push FFFFFF81h |
dec esp |
mov eax, dword ptr [81D5B00Ch] |
xor eax, 1B248E63h |
add esp, dword ptr [esi] |
push eax |
add byte ptr [edx-6Bh], FFFFFFBCh |
dec ebx |
dec ebp |
adc al, 02h |
salc |
pushfd |
cdq |
add ah, byte ptr [ecx] |
mov al, byte ptr [A3B72108h] |
pushad |
test byte ptr [edx], cl |
dec eax |
mov dword ptr [E23DD200h], eax |
sbb dword ptr [ebx+4D488D00h], ebp |
fmul qword ptr [esi+0306AB36h] |
arpl ax, sp |
sbb dword ptr [eax], eax |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x42e94 | 0x8f | .rsrc |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x3c000 | 0x6e55 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x3b000 | 0x16200 | 6b2e13c14c65b20d76c9b766f5db175d | False | 0.9955420197740112 | data | 7.970208954906549 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x3c000 | 0x8000 | 0x7a00 | 7606d67299f301afb8b445c88408d4e6 | False | 0.6684490266393442 | data | 6.468159493452258 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0x3c598 | 0x668 | Device independent bitmap graphic, 48 x 96 x 4, image size 1152 | English | United States | 0.43658536585365854 |
RT_ICON | 0x3cc00 | 0x2e8 | Device independent bitmap graphic, 32 x 64 x 4, image size 512 | English | United States | 0.5376344086021505 |
RT_ICON | 0x3cee8 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 128 | English | United States | 0.597972972972973 |
RT_ICON | 0x3d010 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors | English | United States | 0.6471215351812367 |
RT_ICON | 0x3deb8 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | English | United States | 0.7572202166064982 |
RT_ICON | 0x3e760 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | English | United States | 0.5823699421965318 |
RT_ICON | 0x3ecc8 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9600 | English | United States | 0.7104771784232365 |
RT_ICON | 0x41270 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4224 | English | United States | 0.6843339587242027 |
RT_ICON | 0x42318 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1088 | English | United States | 0.9166666666666666 |
RT_STRING | 0x30000 | 0x2a8 | empty | 0 | ||
RT_STRING | 0x302a8 | 0x2b0 | empty | Catalan | Spain | 0 |
RT_STRING | 0x30558 | 0x142 | empty | Chinese | Taiwan | 0 |
RT_STRING | 0x3069a | 0x1b4 | empty | Czech | Czech Republic | 0 |
RT_STRING | 0x3084e | 0x2b4 | empty | Danish | Denmark | 0 |
RT_STRING | 0x30b02 | 0x274 | empty | German | Germany | 0 |
RT_STRING | 0x30d76 | 0x31c | empty | Greek | Greece | 0 |
RT_STRING | 0x31092 | 0x268 | empty | English | United States | 0 |
RT_STRING | 0x312fa | 0x276 | empty | Finnish | Finland | 0 |
RT_STRING | 0x31570 | 0x28c | empty | French | France | 0 |
RT_STRING | 0x317fc | 0x28c | empty | Hungarian | Hungary | 0 |
RT_STRING | 0x31a88 | 0x29c | empty | Italian | Italy | 0 |
RT_STRING | 0x31d24 | 0x1ce | empty | Japanese | Japan | 0 |
RT_STRING | 0x31ef2 | 0x164 | empty | Korean | North Korea | 0 |
RT_STRING | 0x31ef2 | 0x164 | empty | Korean | South Korea | 0 |
RT_STRING | 0x32056 | 0x2a4 | empty | Dutch | Netherlands | 0 |
RT_STRING | 0x322fa | 0x26a | empty | Norwegian | Norway | 0 |
RT_STRING | 0x32564 | 0x202 | empty | Polish | Poland | 0 |
RT_STRING | 0x32766 | 0x2d4 | empty | Portuguese | Brazil | 0 |
RT_STRING | 0x32a3a | 0x2e4 | empty | Russian | Russia | 0 |
RT_STRING | 0x32d1e | 0x2dc | empty | Slovak | Slovakia | 0 |
RT_STRING | 0x32ffa | 0x262 | empty | Swedish | Sweden | 0 |
RT_STRING | 0x3325c | 0x286 | empty | Thai | Thailand | 0 |
RT_STRING | 0x334e2 | 0x29c | empty | Turkish | Turkey | 0 |
RT_STRING | 0x3377e | 0x29e | empty | Indonesian | Indonesia | 0 |
RT_STRING | 0x33a1c | 0x2d6 | empty | Slovenian | Slovenia | 0 |
RT_STRING | 0x33cf2 | 0x2e8 | empty | Basque | France | 0 |
RT_STRING | 0x33cf2 | 0x2e8 | empty | Basque | Spain | 0 |
RT_STRING | 0x33fda | 0x140 | empty | Chinese | China | 0 |
RT_STRING | 0x3411a | 0x2be | empty | Portuguese | Portugal | 0 |
RT_STRING | 0x343d8 | 0x286 | empty | French | Canada | 0 |
RT_GROUP_ICON | 0x42780 | 0x84 | data | English | United States | 0.6363636363636364 |
RT_VERSION | 0x42808 | 0x348 | data | English | United States | 0.45595238095238094 |
RT_MANIFEST | 0x42b50 | 0x305 | XML 1.0 document, ASCII text | 0.5420439844760673 |
DLL | Import |
---|---|
kernel32.dll | LoadLibraryA, GetProcAddress, VirtualAlloc, VirtualFree |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States | |
Catalan | Spain | |
Chinese | Taiwan | |
Czech | Czech Republic | |
Danish | Denmark | |
German | Germany | |
Greek | Greece | |
Finnish | Finland | |
French | France | |
Hungarian | Hungary | |
Italian | Italy | |
Japanese | Japan | |
Korean | North Korea | |
Korean | South Korea | |
Dutch | Netherlands | |
Norwegian | Norway | |
Polish | Poland | |
Portuguese | Brazil | |
Russian | Russia | |
Slovak | Slovakia | |
Swedish | Sweden | |
Thai | Thailand | |
Turkish | Turkey | |
Indonesian | Indonesia | |
Slovenian | Slovenia | |
Chinese | China | |
Portuguese | Portugal | |
French | Canada |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 16:51:08 |
Start date: | 28/08/2024 |
Path: | C:\Users\user\Desktop\Infor IDF Auxiliary Machine.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 122'880 bytes |
MD5 hash: | 62CDC45806E717F187E2F46780BD6834 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 16:51:08 |
Start date: | 28/08/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Execution Graph
Execution Coverage: | 4% |
Dynamic/Decrypted Code Coverage: | 1.1% |
Signature Coverage: | 3.9% |
Total number of Nodes: | 2000 |
Total number of Limit Nodes: | 62 |
Graph
Function 00414FC6 Relevance: 7.6, APIs: 5, Instructions: 121COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00411F19 Relevance: 24.6, APIs: 10, Strings: 4, Instructions: 119libraryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00417BCA Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 13libraryloaderCOMMONLIBRARYCODE
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402979 Relevance: 6.1, APIs: 4, Instructions: 78stringCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040DA80 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 71keyboardCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415747 Relevance: 3.5, APIs: 1, Strings: 1, Instructions: 24COMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040BC90 Relevance: 3.1, APIs: 2, Instructions: 104COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00570C74 Relevance: 3.0, APIs: 2, Instructions: 30memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041A748 Relevance: 3.0, APIs: 2, Instructions: 26memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00570304 Relevance: 2.7, APIs: 2, Instructions: 165memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040C25F Relevance: 1.6, APIs: 1, Instructions: 108COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406AB8 Relevance: 1.5, APIs: 1, Instructions: 12COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00570C2A Relevance: 1.5, APIs: 1, Instructions: 9libraryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041F805 Relevance: 21.1, APIs: 6, Strings: 6, Instructions: 90libraryloaderCOMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041E627 Relevance: 7.6, APIs: 5, Instructions: 92memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041FA2E Relevance: 4.6, APIs: 3, Instructions: 102COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041DEE8 Relevance: 4.5, APIs: 3, Instructions: 36COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041DF6E Relevance: 3.0, APIs: 2, Instructions: 21COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041DEB1 Relevance: 3.0, APIs: 2, Instructions: 15COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041C9BA Relevance: 1.5, APIs: 1, Instructions: 5COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041C9CE Relevance: 1.5, APIs: 1, Instructions: 3COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004166FC Relevance: .1, Instructions: 77COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00413F00 Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00411C6E Relevance: 31.7, APIs: 11, Strings: 7, Instructions: 214libraryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041C251 Relevance: 26.4, APIs: 11, Strings: 4, Instructions: 115fileCOMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041E48F Relevance: 26.3, APIs: 7, Strings: 8, Instructions: 97COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00418B98 Relevance: 22.8, APIs: 8, Strings: 5, Instructions: 71libraryloadermemoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00410F7E Relevance: 17.6, APIs: 6, Strings: 4, Instructions: 73libraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004171C5 Relevance: 13.7, APIs: 9, Instructions: 196COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041C6D6 Relevance: 12.1, APIs: 8, Instructions: 131COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040C730 Relevance: 10.6, APIs: 2, Strings: 4, Instructions: 85keyboardCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040F0F5 Relevance: 10.6, APIs: 7, Instructions: 66synchronizationthreadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041F57F Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 167fileCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00412265 Relevance: 8.8, APIs: 2, Strings: 3, Instructions: 34COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00413924 Relevance: 8.8, APIs: 2, Strings: 3, Instructions: 25COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00410F3B Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 24libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041E200 Relevance: 7.7, APIs: 5, Instructions: 184COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041F320 Relevance: 7.7, APIs: 5, Instructions: 169COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004189B1 Relevance: 7.5, APIs: 5, Instructions: 37threadCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00413961 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 31COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041B7FF Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 29libraryloaderCOMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042080A Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 13libraryloaderCOMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00411040 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 9libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041637C Relevance: 6.2, APIs: 4, Instructions: 165COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415F91 Relevance: 6.1, APIs: 4, Instructions: 121COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041442D Relevance: 6.1, APIs: 4, Instructions: 113COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004172DF Relevance: 6.1, APIs: 4, Instructions: 93COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041C401 Relevance: 6.1, APIs: 4, Instructions: 74COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00411060 Relevance: 6.1, APIs: 4, Instructions: 69fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00414E1C Relevance: 6.1, APIs: 4, Instructions: 69threadCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041AB24 Relevance: 6.1, APIs: 4, Instructions: 57memoryCOMMONLIBRARYCODE
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00420EF7 Relevance: 6.0, APIs: 4, Instructions: 38COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041ECAD Relevance: 5.4, APIs: 1, Strings: 2, Instructions: 124COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00412904 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 47COMMONLIBRARYCODE
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|