Windows
Analysis Report
bfsvc.exe
Overview
General Information
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- bfsvc.exe (PID: 1424 cmdline:
"C:\Users\ user\Deskt op\bfsvc.e xe" MD5: 60A339532F6A5290D435ACBD30CB1992)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Code function: | 6_2_0000000140145940 |
Source: | Code function: | 6_2_0000000140145940 |
Source: | Code function: | 6_2_00000001400E00A4 |
Source: | Code function: | 6_2_000000014005098C | |
Source: | Code function: | 6_2_0000000140114F8C | |
Source: | Code function: | 6_2_00000001400159A4 | |
Source: | Code function: | 6_2_000000014009E3C0 | |
Source: | Code function: | 6_2_000000014013EA78 |
Source: | Code function: | 6_2_0000000140054054 | |
Source: | Code function: | 6_2_0000000140080090 | |
Source: | Code function: | 6_2_00000001400D8088 | |
Source: | Code function: | 6_2_00000001400400EC | |
Source: | Code function: | 6_2_00000001400380F4 | |
Source: | Code function: | 6_2_0000000140124158 | |
Source: | Code function: | 6_2_0000000140100148 | |
Source: | Code function: | 6_2_000000014001C178 | |
Source: | Code function: | 6_2_00000001400A8198 | |
Source: | Code function: | 6_2_00000001400481D8 | |
Source: | Code function: | 6_2_00000001401981D0 | |
Source: | Code function: | 6_2_00000001401742B8 | |
Source: | Code function: | 6_2_000000014013C2B0 | |
Source: | Code function: | 6_2_000000014012C33C | |
Source: | Code function: | 6_2_00000001400D4340 | |
Source: | Code function: | 6_2_000000014009035C | |
Source: | Code function: | 6_2_000000014019844C | |
Source: | Code function: | 6_2_00000001400A4464 | |
Source: | Code function: | 6_2_00000001401745E4 | |
Source: | Code function: | 6_2_00000001401A05F0 | |
Source: | Code function: | 6_2_000000014011C638 | |
Source: | Code function: | 6_2_000000014007C650 | |
Source: | Code function: | 6_2_00000001401606C0 | |
Source: | Code function: | 6_2_00000001400A06F8 | |
Source: | Code function: | 6_2_00000001401007D8 | |
Source: | Code function: | 6_2_0000000140118838 | |
Source: | Code function: | 6_2_0000000140104874 | |
Source: | Code function: | 6_2_000000014013C8CC | |
Source: | Code function: | 6_2_00000001400DC8D4 | |
Source: | Code function: | 6_2_000000014008CA04 | |
Source: | Code function: | 6_2_0000000140124AA0 | |
Source: | Code function: | 6_2_0000000140054B9C | |
Source: | Code function: | 6_2_0000000140140BFC | |
Source: | Code function: | 6_2_00000001400E8C04 | |
Source: | Code function: | 6_2_00000001401A0C4C | |
Source: | Code function: | 6_2_0000000140174C9C | |
Source: | Code function: | 6_2_0000000140158C9C | |
Source: | Code function: | 6_2_0000000140078CA0 | |
Source: | Code function: | 6_2_0000000140068CB4 | |
Source: | Code function: | 6_2_00000001400BCCC4 | |
Source: | Code function: | 6_2_00000001400FCCD4 | |
Source: | Code function: | 6_2_0000000140134D48 | |
Source: | Code function: | 6_2_00000001400ACD60 | |
Source: | Code function: | 6_2_0000000140090DE4 | |
Source: | Code function: | 6_2_00000001400ECE24 | |
Source: | Code function: | 6_2_00000001400A8E58 | |
Source: | Code function: | 6_2_00000001400E4E64 | |
Source: | Code function: | 6_2_000000014010CF78 | |
Source: | Code function: | 6_2_00000001401310A0 | |
Source: | Code function: | 6_2_0000000140115184 | |
Source: | Code function: | 6_2_00000001400351AC | |
Source: | Code function: | 6_2_00000001401451AC | |
Source: | Code function: | 6_2_0000000140169268 | |
Source: | Code function: | 6_2_00000001400692F0 | |
Source: | Code function: | 6_2_00000001400792EC | |
Source: | Code function: | 6_2_000000014011D340 | |
Source: | Code function: | 6_2_00000001400C5348 | |
Source: | Code function: | 6_2_00000001400F53C8 | |
Source: | Code function: | 6_2_000000014005943C | |
Source: | Code function: | 6_2_000000014003944C | |
Source: | Code function: | 6_2_00000001400514CC | |
Source: | Code function: | 6_2_00000001400A94D8 | |
Source: | Code function: | 6_2_00000001401314FC | |
Source: | Code function: | 6_2_00000001401254E8 | |
Source: | Code function: | 6_2_0000000140105510 | |
Source: | Code function: | 6_2_00000001400F162C | |
Source: | Code function: | 6_2_0000000140139680 | |
Source: | Code function: | 6_2_000000014008D694 | |
Source: | Code function: | 6_2_00000001400B1714 | |
Source: | Code function: | 6_2_00000001400A1748 | |
Source: | Code function: | 6_2_00000001400E1754 | |
Source: | Code function: | 6_2_0000000140149780 | |
Source: | Code function: | 6_2_000000014013D788 | |
Source: | Code function: | 6_2_00000001400457C0 | |
Source: | Code function: | 6_2_00000001400317E0 | |
Source: | Code function: | 6_2_000000014005980C | |
Source: | Code function: | 6_2_00000001400B58DC | |
Source: | Code function: | 6_2_00000001401418CC | |
Source: | Code function: | 6_2_00000001400A58E8 | |
Source: | Code function: | 6_2_0000000140105924 | |
Source: | Code function: | 6_2_0000000140021938 | |
Source: | Code function: | 6_2_00000001401A5984 | |
Source: | Code function: | 6_2_00000001401699D0 | |
Source: | Code function: | 6_2_00000001400E5A0C | |
Source: | Code function: | 6_2_000000014005DA4C | |
Source: | Code function: | 6_2_000000014013DA9C | |
Source: | Code function: | 6_2_000000014012DA84 | |
Source: | Code function: | 6_2_00000001400D5AE0 | |
Source: | Code function: | 6_2_0000000140065AF0 | |
Source: | Code function: | 6_2_00000001400D5C1C | |
Source: | Code function: | 6_2_0000000140171C2C | |
Source: | Code function: | 6_2_0000000140115CDC | |
Source: | Code function: | 6_2_0000000140085CF8 | |
Source: | Code function: | 6_2_00000001400F1D10 | |
Source: | Code function: | 6_2_0000000140095D80 | |
Source: | Code function: | 6_2_0000000140139DEC | |
Source: | Code function: | 6_2_0000000140131E48 | |
Source: | Code function: | 6_2_00000001400B5E90 | |
Source: | Code function: | 6_2_000000014010DED4 | |
Source: | Code function: | 6_2_0000000140121F04 | |
Source: | Code function: | 6_2_0000000140039F48 | |
Source: | Code function: | 6_2_00000001400B1F5C | |
Source: | Code function: | 6_2_00000001400C5F8C | |
Source: | Code function: | 6_2_0000000140142110 | |
Source: | Code function: | 6_2_00000001400AE170 | |
Source: | Code function: | 6_2_000000014013A1C4 | |
Source: | Code function: | 6_2_00000001400821FC | |
Source: | Code function: | 6_2_000000014009A1F8 | |
Source: | Code function: | 6_2_00000001400D6210 | |
Source: | Code function: | 6_2_000000014007A2D8 | |
Source: | Code function: | 6_2_00000001400DA2EC | |
Source: | Code function: | 6_2_00000001400A6304 | |
Source: | Code function: | 6_2_000000014009E3C0 | |
Source: | Code function: | 6_2_0000000140162420 | |
Source: | Code function: | 6_2_00000001401AE40C | |
Source: | Code function: | 6_2_0000000140086488 | |
Source: | Code function: | 6_2_000000014000E4E0 | |
Source: | Code function: | 6_2_00000001401264F4 | |
Source: | Code function: | 6_2_00000001400F6524 | |
Source: | Code function: | 6_2_0000000140062578 | |
Source: | Code function: | 6_2_00000001400525FC | |
Source: | Code function: | 6_2_000000014015A6A0 | |
Source: | Code function: | 6_2_000000014002A6E8 | |
Source: | Code function: | 6_2_000000014010675C | |
Source: | Code function: | 6_2_00000001400B2758 | |
Source: | Code function: | 6_2_000000014019E774 | |
Source: | Code function: | 6_2_00000001401427A8 | |
Source: | Code function: | 6_2_000000014016E7C4 | |
Source: | Code function: | 6_2_0000000140066824 | |
Source: | Code function: | 6_2_000000014008E858 | |
Source: | Code function: | 6_2_00000001400D2868 | |
Source: | Code function: | 6_2_0000000140152868 | |
Source: | Code function: | 6_2_0000000140146894 | |
Source: | Code function: | 6_2_00000001401768D4 | |
Source: | Code function: | 6_2_00000001400968DC | |
Source: | Code function: | 6_2_00000001400A68E8 | |
Source: | Code function: | 6_2_00000001400F2A80 | |
Source: | Code function: | 6_2_0000000140136AA8 | |
Source: | Code function: | 6_2_000000014014AB1C | |
Source: | Code function: | 6_2_0000000140122B40 | |
Source: | Code function: | 6_2_00000001400EAB50 | |
Source: | Code function: | 6_2_0000000140126B98 | |
Source: | Code function: | 6_2_00000001400AAB88 | |
Source: | Code function: | 6_2_0000000140116BC0 | |
Source: | Code function: | 6_2_0000000140082C0C | |
Source: | Code function: | 6_2_000000014012AC4C | |
Source: | Code function: | 6_2_000000014012ECB8 | |
Source: | Code function: | 6_2_00000001400F6CE4 | |
Source: | Code function: | 6_2_0000000140146D0C | |
Source: | Code function: | 6_2_000000014010AD60 | |
Source: | Code function: | 6_2_000000014007ED88 |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 6_2_000000014003CAC0 |
Source: | Code function: | 6_2_0000000140014264 |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | File read: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Code function: | 6_2_0000000140039024 |
Source: | Code function: | 6_2_004D3544 | |
Source: | Code function: | 6_2_004D1B7A | |
Source: | Code function: | 6_2_004D0A3A | |
Source: | Code function: | 6_2_004D283F | |
Source: | Code function: | 6_2_004D30E3 | |
Source: | Code function: | 6_2_004D15FD | |
Source: | Code function: | 6_2_000000014010D542 |
Source: | Code function: | 6_2_0000000140094878 | |
Source: | Code function: | 6_2_0000000140114B5C | |
Source: | Code function: | 6_2_0000000140114B5C | |
Source: | Code function: | 6_2_0000000140114B5C | |
Source: | Code function: | 6_2_000000014011562C | |
Source: | Code function: | 6_2_0000000140115954 | |
Source: | Code function: | 6_2_000000014011609C | |
Source: | Code function: | 6_2_00000001401168BC | |
Source: | Code function: | 6_2_0000000140116BC0 | |
Source: | Code function: | 6_2_0000000140002E00 |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | API coverage: |
Source: | Code function: | 6_2_000000014019A694 |
Source: | Code function: | 6_2_0000000140196A38 |
Source: | Code function: | 6_2_000000014006C43C |
Source: | Code function: | 6_2_0000000140039024 |
Source: | Code function: | 6_2_0000000140196A38 | |
Source: | Code function: | 6_2_0000000140192D94 |
Source: | Code function: | 6_2_000000014001E3DC |
Source: | Code function: | 6_2_000000014003CAC0 |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Deobfuscate/Decode Files or Information | 21 Input Capture | 2 Security Software Discovery | Remote Services | 21 Input Capture | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | LSASS Memory | 1 Application Window Discovery | Remote Desktop Protocol | 1 Archive Collected Data | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 2 Obfuscated Files or Information | Security Account Manager | 13 System Information Discovery | SMB/Windows Admin Shares | 2 Clipboard Data | Steganography | Automated Exfiltration | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
39% | ReversingLabs | Win64.Trojan.SpywareX | ||
58% | Virustotal | Browse | ||
100% | Avira | TR/Spy.Bobik.fivkh |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1525467 |
Start date and time: | 2024-10-04 09:18:10 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 27s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 14 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | bfsvc.exe |
Detection: | MAL |
Classification: | mal56.winEXE@1/1@0/0 |
EGA Information: |
|
HCA Information: | Failed |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, ctldl.windowsupdate.com, time.windows.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing disassembly code.
Process: | C:\Users\user\Desktop\bfsvc.exe |
File Type: | |
Category: | modified |
Size (bytes): | 174548 |
Entropy (8bit): | 7.9989319921201245 |
Encrypted: | true |
SSDEEP: | 3072:UmHqdQxxy7SdsuzoCJbpYiUxOuTT5N+6N3/51Qg+b3TYtTJYkGVE+z4i2OqJI+y:UeqexM7SdooUxOy7Nh1Qg+HYtTWkMVcI |
MD5: | 92400F38A0E86B23DB1E64358ACEBCED |
SHA1: | 4991C69B137ECDFEC978FBA643DC6CB2DBC7D2B5 |
SHA-256: | 65325DF0FB8678FAE5022869D45643558DAAF8766EA36CD23BECD3B6BDDA32B8 |
SHA-512: | 5405BCC84520A06AE08EFCBA1A11F8C0683B7BD798A6915DB9549056471434EE62B32E672DB7A6D065A9ADBC4C8428BFA02000AC6A246A301350D59C385A5ECE |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 6.35497393259666 |
TrID: |
|
File name: | bfsvc.exe |
File size: | 2'789'712 bytes |
MD5: | 60a339532f6a5290d435acbd30cb1992 |
SHA1: | 49ac28641a0448d4179eb870c1af4327a1799650 |
SHA256: | ee7926b30c734b49f373b88b3f0d73a761b832585ac235eda68cf9435c931269 |
SHA512: | 5fe71e5f3df06c257da11fdc9186188ec021df67be86ec4a7286156f3a5f27fd1bc7a9a3e42672a7c92b1c8ca291f110d8b08c6282a4dd25afae890c97c1fe08 |
SSDEEP: | 49152:SWloiaXmVQDg/xrTYp3Rp8Z7iOOSaIOzd9nLgUvSSP88O5Z2Cfz8kIL+hlaDOjiH:SWv0yOSQbnLLSSP8L5IzY8FkT8 |
TLSH: | 1CD57D5F67B851D9C5A7C178C5268A8FE7F3B8A10930C38F40A54B9E5FB32628D1B721 |
File Content Preview: | MZ......................@...................................(...........!..L.!This program cannot be run in DOS mode....$........o..E...E...E.....+.J.....).......(.S.......H.......D.......G.......f...E...e....W..S....W..L....W..#....W..A....W%.D...E.M.D.. |
Icon Hash: | 00928e8e8686b000 |
Entrypoint: | 0x140192ac4 |
Entrypoint Section: | .text |
Digitally signed: | true |
Imagebase: | 0x140000000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE |
DLL Characteristics: | HIGH_ENTROPY_VA, NX_COMPAT, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x65D698E7 [Thu Feb 22 00:44:23 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 6 |
OS Version Minor: | 0 |
File Version Major: | 6 |
File Version Minor: | 0 |
Subsystem Version Major: | 6 |
Subsystem Version Minor: | 0 |
Import Hash: | e99b1acfe7b35844f0584357831f0665 |
Signature Valid: | false |
Signature Issuer: | CN=Tableau Software Inc. |
Signature Validation Error: | A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider |
Error Number: | -2146762487 |
Not Before, Not After |
|
Subject Chain |
|
Version: | 3 |
Thumbprint MD5: | 1DC7895A0C06936950D50A29047999BE |
Thumbprint SHA-1: | 6624C7B8FAAC176D1C1CB10B03E7EE58A4853F91 |
Thumbprint SHA-256: | F76D6AE999702C40C74D2575A2923F571359B90743A80BB5445C442C7C558EF6 |
Serial: | 76CB5D1E6C2B6895428115705D9AC765 |
Instruction |
---|
dec eax |
sub esp, 28h |
call 00007FBBB8B0E02Ch |
dec eax |
add esp, 28h |
jmp 00007FBBB8B0D537h |
int3 |
int3 |
dec eax |
sub esp, 28h |
dec ebp |
mov eax, dword ptr [ecx+38h] |
dec eax |
mov ecx, edx |
dec ecx |
mov edx, ecx |
call 00007FBBB8B0D6D2h |
mov eax, 00000001h |
dec eax |
add esp, 28h |
ret |
int3 |
int3 |
int3 |
inc eax |
push ebx |
inc ebp |
mov ebx, dword ptr [eax] |
dec eax |
mov ebx, edx |
inc ecx |
and ebx, FFFFFFF8h |
dec esp |
mov ecx, ecx |
inc ecx |
test byte ptr [eax], 00000004h |
dec esp |
mov edx, ecx |
je 00007FBBB8B0D6D5h |
inc ecx |
mov eax, dword ptr [eax+08h] |
dec ebp |
arpl word ptr [eax+04h], dx |
neg eax |
dec esp |
add edx, ecx |
dec eax |
arpl ax, cx |
dec esp |
and edx, ecx |
dec ecx |
arpl bx, ax |
dec edx |
mov edx, dword ptr [eax+edx] |
dec eax |
mov eax, dword ptr [ebx+10h] |
mov ecx, dword ptr [eax+08h] |
dec eax |
add ecx, dword ptr [ebx+08h] |
test byte ptr [ecx+03h], 0000000Fh |
je 00007FBBB8B0D6CEh |
movzx eax, byte ptr [ecx+03h] |
and eax, FFFFFFF0h |
dec eax |
cwde |
dec esp |
add ecx, eax |
dec esp |
xor ecx, edx |
dec ecx |
mov ecx, ecx |
pop ebx |
jmp 00007FBBB8B0D0B2h |
int3 |
dec eax |
mov eax, esp |
dec eax |
mov dword ptr [eax+08h], ebx |
dec eax |
mov dword ptr [eax+10h], ebp |
dec eax |
mov dword ptr [eax+18h], esi |
dec eax |
mov dword ptr [eax+20h], edi |
inc ecx |
push esi |
dec eax |
sub esp, 20h |
dec ebp |
mov edx, dword ptr [ecx+38h] |
dec eax |
mov esi, edx |
dec ebp |
mov esi, eax |
dec eax |
mov ebp, ecx |
dec ecx |
mov edx, ecx |
dec eax |
mov ecx, esi |
dec ecx |
mov edi, ecx |
inc ecx |
mov ebx, dword ptr [edx] |
dec eax |
shl ebx, 04h |
dec ecx |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x25da00 | 0x17c | |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x288000 | 0x5350 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x271000 | 0x15c60 | .pdata |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x2a8c00 | 0x550 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x28e000 | 0xef3c | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x2211f0 | 0x1c | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x2212a8 | 0x28 | .rdata |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x221210 | 0x94 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x1bc2e0 | 0x1bc400 | b51bb458f4da03b2ac05d7bfdb2988ac | False | 0.5279119917698368 | zlib compressed data | 6.4274818862709555 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x1be000 | 0x9f926 | 0x9fc00 | 221966d18488fc88b46efbcdb39d5a14 | False | 0.2700187671165884 | data | 4.542617662939858 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.data | 0x25e000 | 0x127b4 | 0x7800 | df3e929c55c7972dbff0d4164cdad5e7 | False | 0.19547526041666666 | data | 4.147628436363404 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.pdata | 0x271000 | 0x15c60 | 0x15e00 | 37f832ba1a326f736003396574f5ffd9 | False | 0.5044084821428572 | data | 6.16397692708684 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.tls | 0x287000 | 0x9 | 0x200 | 1f354d76203061bfdd5a53dae48d5435 | False | 0.033203125 | data | 0.020393135236084953 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x288000 | 0x5350 | 0x5400 | 76a6e84e7298c02c76385d01d614bc32 | False | 0.23939732142857142 | data | 3.665069544682688 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x28e000 | 0xef3c | 0xf000 | af5c9342690516674eda0363f0bd45c9 | False | 0.10154622395833333 | data | 5.444310130802154 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_CURSOR | 0x288ac0 | 0x134 | Targa image data - RGB 64 x 65536 x 1 +32 "\001" | English | United States | 0.4805194805194805 |
RT_CURSOR | 0x288bf4 | 0xb4 | Targa image data - Map 32 x 65536 x 1 +16 "\001" | English | United States | 0.7 |
RT_CURSOR | 0x288ca8 | 0x134 | AmigaOS bitmap font "(", fc_YSize 4294967264, 5120 elements, 2nd "\377\360?\377\377\370\177\377\377\374\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377", 3rd | English | United States | 0.36363636363636365 |
RT_CURSOR | 0x288ddc | 0x134 | Targa image data - RLE 64 x 65536 x 1 +32 "\001" | English | United States | 0.35714285714285715 |
RT_CURSOR | 0x288f10 | 0x134 | data | English | United States | 0.37337662337662336 |
RT_CURSOR | 0x289044 | 0x134 | data | English | United States | 0.37662337662337664 |
RT_CURSOR | 0x289178 | 0x134 | Targa image data 64 x 65536 x 1 +32 "\001" | English | United States | 0.36688311688311687 |
RT_CURSOR | 0x2892ac | 0x134 | Targa image data 64 x 65536 x 1 +32 "\001" | English | United States | 0.37662337662337664 |
RT_CURSOR | 0x2893e0 | 0x134 | Targa image data - Mono - RLE 64 x 65536 x 1 +32 "\001" | English | United States | 0.36688311688311687 |
RT_CURSOR | 0x289514 | 0x134 | Targa image data - RGB - RLE 64 x 65536 x 1 +32 "\001" | English | United States | 0.38636363636363635 |
RT_CURSOR | 0x289648 | 0x134 | data | English | United States | 0.44155844155844154 |
RT_CURSOR | 0x28977c | 0x134 | data | English | United States | 0.4155844155844156 |
RT_CURSOR | 0x2898b0 | 0x134 | AmigaOS bitmap font "(", fc_YSize 4294966847, 3840 elements, 2nd "\377?\374\377\377\300\003\377\377\300\003\377\377\340\007\377\377\360\017\377\377\370\037\377\377\374?\377\377\376\177\377\377\377\377\377\377\377\377\377\377\377\377\377", 3rd | English | United States | 0.5422077922077922 |
RT_CURSOR | 0x2899e4 | 0x134 | data | English | United States | 0.2662337662337662 |
RT_CURSOR | 0x289b18 | 0x134 | data | English | United States | 0.2824675324675325 |
RT_CURSOR | 0x289c4c | 0x134 | data | English | United States | 0.3246753246753247 |
RT_BITMAP | 0x289d80 | 0x220 | Device independent bitmap graphic, 85 x 10 x 4, image size 440 | Portuguese | Brazil | 0.15441176470588236 |
RT_BITMAP | 0x289fa0 | 0xe8 | Device independent bitmap graphic, 28 x 8 x 4, image size 128 | Portuguese | Brazil | 0.3706896551724138 |
RT_BITMAP | 0x28a088 | 0xb8 | Device independent bitmap graphic, 12 x 10 x 4, image size 80 | English | United States | 0.44565217391304346 |
RT_BITMAP | 0x28a140 | 0x144 | Device independent bitmap graphic, 33 x 11 x 4, image size 220 | English | United States | 0.37962962962962965 |
RT_DIALOG | 0x28a284 | 0x33e | data | English | United States | 0.4072289156626506 |
RT_DIALOG | 0x28a5c4 | 0xe8 | data | English | United States | 0.6336206896551724 |
RT_DIALOG | 0x28a6ac | 0x34 | data | English | United States | 0.9038461538461539 |
RT_STRING | 0x28a6e0 | 0x82 | StarOffice Gallery theme p, 536899072 objects, 1st n | English | United States | 0.7153846153846154 |
RT_STRING | 0x28a764 | 0x2a | data | English | United States | 0.5476190476190477 |
RT_STRING | 0x28a790 | 0x184 | data | English | United States | 0.48711340206185566 |
RT_STRING | 0x28a914 | 0x4ee | data | English | United States | 0.375594294770206 |
RT_STRING | 0x28ae04 | 0x264 | data | English | United States | 0.3333333333333333 |
RT_STRING | 0x28b068 | 0x2da | data | English | United States | 0.3698630136986301 |
RT_STRING | 0x28b344 | 0x8a | data | English | United States | 0.6594202898550725 |
RT_STRING | 0x28b3d0 | 0xac | data | English | United States | 0.45348837209302323 |
RT_STRING | 0x28b47c | 0xde | data | English | United States | 0.536036036036036 |
RT_STRING | 0x28b55c | 0x4a8 | data | English | United States | 0.3221476510067114 |
RT_STRING | 0x28ba04 | 0x228 | data | English | United States | 0.4003623188405797 |
RT_STRING | 0x28bc2c | 0x2c | data | English | United States | 0.5227272727272727 |
RT_STRING | 0x28bc58 | 0x53e | data | English | United States | 0.2965722801788376 |
RT_GROUP_CURSOR | 0x28c198 | 0x22 | Lotus unknown worksheet or configuration, revision 0x2 | English | United States | 0.9705882352941176 |
RT_GROUP_CURSOR | 0x28c1bc | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x28c1d0 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x28c1e4 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x28c1f8 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x28c20c | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x28c220 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x28c234 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x28c248 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x28c25c | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x28c270 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x28c284 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x28c298 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x28c2ac | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x28c2c0 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_VERSION | 0x28c2d4 | 0x72c | OpenPGP Secret Key | 0.3044662309368192 | ||
RT_VERSION | 0x28ca00 | 0x72c | OpenPGP Secret Key | English | United States | 0.3044662309368192 |
RT_MANIFEST | 0x28d12c | 0x224 | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (488), with CRLF line terminators | English | United States | 0.531021897810219 |
DLL | Import |
---|---|
KERNEL32.dll | SetEnvironmentVariableA, FreeEnvironmentStringsW, GetEnvironmentStringsW, IsValidCodePage, SetFilePointerEx, GetConsoleMode, GetConsoleCP, GetTimeZoneInformation, GetStringTypeW, LCMapStringW, FindFirstFileExA, ExitProcess, GetFileType, SetStdHandle, QueryPerformanceFrequency, HeapQueryInformation, VirtualQuery, VirtualAlloc, GetSystemInfo, GetCommandLineW, GetCommandLineA, FreeLibraryAndExitThread, ExitThread, CreateThread, RtlPcToFileHeader, RtlUnwindEx, OutputDebugStringW, FindNextFileA, WriteConsoleW, CreateFileW, InitializeSListHead, GetSystemTimeAsFileTime, QueryPerformanceCounter, GetStartupInfoW, IsDebuggerPresent, IsProcessorFeaturePresent, TerminateProcess, SetUnhandledExceptionFilter, UnhandledExceptionFilter, RtlVirtualUnwind, RtlLookupFunctionEntry, RtlCaptureContext, CreateEventW, WaitForSingleObjectEx, ResetEvent, SearchPathA, GetProfileIntA, GetTempFileNameA, GetTempPathA, FindResourceExW, VerifyVersionInfoA, VerSetConditionMask, GetTickCount, SystemTimeToTzSpecificLocalTime, GetFileTime, GetFileSizeEx, GetFileAttributesExA, GetFileAttributesA, FileTimeToLocalFileTime, SetErrorMode, GetWindowsDirectoryA, GetCPInfo, GetOEMCP, VirtualProtect, lstrcpyA, FileTimeToSystemTime, GetThreadLocale, GetVolumeInformationA, lstrcmpiA, GetCurrentProcess, DuplicateHandle, WriteFile, UnlockFile, SetFilePointer, SetEndOfFile, ReadFile, LockFile, GetFullPathNameA, GetFileSize, FlushFileBuffers, FindFirstFileA, FindClose, CreateFileA, DeleteFileA, GetUserDefaultUILanguage, GetSystemDefaultUILanguage, GetLocaleInfoW, CompareStringW, GetCurrentDirectoryA, LocalReAlloc, LocalAlloc, GlobalHandle, GlobalReAlloc, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, GetACP, InitializeCriticalSection, GlobalFlags, GlobalGetAtomNameA, GlobalFindAtomA, lstrcmpW, GetSystemDirectoryW, EncodePointer, InitializeCriticalSectionAndSpinCount, LeaveCriticalSection, EnterCriticalSection, CopyFileA, FormatMessageA, MulDiv, LocalFree, GlobalSize, GetCurrentProcessId, GlobalAddAtomA, WritePrivateProfileStringA, GetPrivateProfileStringA, GetPrivateProfileIntA, GetProcAddress, GetModuleHandleW, GetModuleHandleA, CompareStringA, WideCharToMultiByte, MultiByteToWideChar, FindResourceW, lstrcmpA, GlobalDeleteAtom, GlobalAlloc, SizeofResource, LoadLibraryExW, GetModuleFileNameA, FreeLibrary, GetVersionExA, GetCurrentThread, ResumeThread, SuspendThread, SetThreadPriority, GetCurrentThreadId, CreateEventA, CloseHandle, QueryActCtxW, FindActCtxSectionStringW, DeactivateActCtx, ActivateActCtx, CreateActCtxW, FindResourceA, LoadLibraryW, GlobalFree, GlobalUnlock, GlobalLock, LockResource, LoadResource, GetModuleHandleExW, GetModuleFileNameW, FreeResource, SetLastError, OutputDebugStringA, Sleep, WaitForSingleObject, SetEvent, DeleteCriticalSection, InitializeCriticalSectionEx, GetProcessHeap, HeapSize, HeapFree, HeapReAlloc, HeapAlloc, GetLastError, RaiseException, GetStdHandle, DecodePointer |
USER32.dll | GetAsyncKeyState, GetMenuItemInfoA, DestroyMenu, LoadImageW, TrackMouseEvent, InflateRect, MessageBeep, GetNextDlgGroupItem, IsRectEmpty, IntersectRect, SetRect, InvalidateRgn, CopyAcceleratorTableA, CharNextA, LoadCursorW, WindowFromPoint, ReleaseCapture, SetCapture, WaitMessage, CharUpperA, DestroyIcon, KillTimer, SetTimer, DeleteMenu, SystemParametersInfoA, CopyImage, GetSysColorBrush, RealChildWindowFromPoint, IsDialogMessageA, SetWindowTextA, CheckDlgButton, MoveWindow, ShowWindow, GetMonitorInfoA, MonitorFromWindow, WinHelpA, GetScrollInfo, SetScrollInfo, LoadIconW, LoadIconA, GetTopWindow, GetClassNameA, GetClassLongPtrA, GetClassLongA, SetWindowLongPtrA, GetWindowLongPtrA, SetWindowLongA, PtInRect, EqualRect, MapWindowPoints, AdjustWindowRectEx, GetWindowTextLengthA, GetWindowTextA, RemovePropA, GetPropA, SetPropA, ShowScrollBar, GetScrollRange, SetScrollRange, CreatePopupMenu, SetScrollPos, ScrollWindow, RedrawWindow, SetForegroundWindow, GetForegroundWindow, UpdateWindow, TrackPopupMenu, SetMenu, GetMenu, GetCapture, SetFocus, GetDlgCtrlID, EndDeferWindowPos, DeferWindowPos, BeginDeferWindowPos, SetWindowPlacement, GetWindowPlacement, SetWindowRgn, IsMenu, CreateWindowExA, GetClassInfoExA, RegisterClassA, CallWindowProcA, GetMessageTime, GetMessagePos, RegisterWindowMessageA, OffsetRect, SetRectEmpty, SendDlgItemMessageA, FillRect, ScreenToClient, ClientToScreen, EndPaint, BeginPaint, GetWindowDC, TabbedTextOutA, GrayStringA, DrawTextExA, DrawTextA, UnhookWindowsHookEx, RemoveMenu, SetParent, OpenClipboard, CloseClipboard, SendMessageA, IsIconic, EnableWindow, GetSystemMetrics, DrawIcon, AppendMenuA, InsertMenuA, GetMenuItemCount, GetMenuItemID, GetSubMenu, GetMenuState, GetMenuStringA, CopyRect, MapVirtualKeyA, GetKeyNameTextA, MapDialogRect, GetWindow, SetWindowContextHelpId, SetWindowPos, GetLastActivePopup, GetWindowThreadProcessId, GetMenuDefaultItem, BringWindowToTop, LoadAcceleratorsA, TranslateAcceleratorA, LoadMenuA, InsertMenuItemA, LoadImageA, UnpackDDElParam, ReuseDDElParam, RegisterClipboardFormatA, DrawFocusRect, DrawIconEx, GetIconInfo, MessageBoxA, SetCursor, ShowOwnedPopups, EnableScrollBar, HideCaret, InvertRect, NotifyWinEvent, SetLayeredWindowAttributes, EnumDisplayMonitors, GetScrollPos, SetClassLongPtrA, GetClientRect, UnregisterClassA, DefWindowProcA, GetClassInfoA, IsWindow, GetDC, ReleaseDC, InvalidateRect, GetWindowRect, GetSysColor, LoadCursorA, GetFocus, CheckMenuItem, EnableMenuItem, SetMenuItemBitmaps, GetMenuCheckMarkDimensions, SetMenuItemInfoA, GetParent, LoadBitmapW, DestroyWindow, CreateDialogIndirectParamA, EndDialog, GetDlgItem, GetNextDlgTabItem, GetActiveWindow, IsWindowEnabled, SetActiveWindow, GetWindowLongA, GetDesktopWindow, GetMessageA, TranslateMessage, DispatchMessageA, PeekMessageA, IsWindowVisible, GetKeyState, ValidateRect, GetCursorPos, SetWindowsHookExA, CallNextHookEx, PostMessageA, PostQuitMessage, SetClipboardData, EmptyClipboard, DrawStateA, DrawEdge, DrawFrameControl, IsZoomed, LoadMenuW, DestroyCursor, GetWindowRgn, CreateMenu, SubtractRect, TranslateMDISysAccel, DefMDIChildProcA, DefFrameProcA, DrawMenuBar, GetUpdateRect, IsClipboardFormatAvailable, CharUpperBuffA, ModifyMenuA, GetDoubleClickTime, SetMenuDefaultItem, LockWindowUpdate, DestroyAcceleratorTable, CreateAcceleratorTableA, LoadAcceleratorsW, ToAsciiEx, GetKeyboardState, MapVirtualKeyExA, IsCharLowerA, GetKeyboardLayout, GetComboBoxInfo, MonitorFromPoint, UpdateLayeredWindow, PostThreadMessageA, UnionRect, FrameRect, CopyIcon, SetCursorPos, IsChild, GetSystemMenu |
GDI32.dll | GetObjectType, GetPixel, GetStockObject, GetViewportExtEx, GetWindowExtEx, IntersectClipRect, LineTo, PtVisible, RectVisible, RestoreDC, SaveDC, SelectClipRgn, ExtSelectClipRgn, SelectObject, SelectPalette, SetBkColor, SetBkMode, SetMapMode, SetLayout, GetLayout, SetPolyFillMode, SetROP2, SetTextColor, SetTextAlign, GetObjectA, MoveToEx, TextOutA, ExtTextOutA, SetViewportExtEx, SetViewportOrgEx, SetWindowExtEx, SetWindowOrgEx, OffsetViewportOrgEx, OffsetWindowOrgEx, ScaleViewportExtEx, ScaleWindowExtEx, CreateFontIndirectA, GetTextExtentPoint32A, GetTextMetricsA, GetClipBox, GetTextColor, GetRgnBox, CombineRgn, GetMapMode, SetRectRgn, DPtoLP, CreateCompatibleBitmap, CreatePalette, GetNearestPaletteIndex, GetPaletteEntries, GetSystemPaletteEntries, RealizePalette, CreateDIBitmap, EnumFontFamiliesA, GetTextCharsetInfo, SetPixel, StretchBlt, CreateDIBSection, SetDIBColorTable, CreateEllipticRgn, Ellipse, CreatePolygonRgn, Polygon, Polyline, CreateRoundRectRgn, LPtoDP, EnumFontFamiliesExA, OffsetRgn, RoundRect, FillRgn, FrameRgn, GetBoundsRect, PtInRegion, ExtFloodFill, SetPaletteEntries, SetPixelV, GetWindowOrgEx, GetViewportOrgEx, GetTextFaceA, ExcludeClipRect, Escape, DeleteObject, DeleteDC, CreateSolidBrush, CreateRectRgn, CreatePatternBrush, CreatePen, CreateHatchBrush, CreateCompatibleDC, BitBlt, GetDeviceCaps, CreateDCA, CopyMetaFileA, PatBlt, CreateRectRgnIndirect, CreateBitmap, GetBkColor, Rectangle |
MSIMG32.dll | AlphaBlend, TransparentBlt |
WINSPOOL.DRV | DocumentPropertiesA, OpenPrinterA, ClosePrinter |
ADVAPI32.dll | SystemFunction036, RegOpenKeyExA, RegQueryValueExA, RegEnumKeyExA, RegEnumValueA, RegQueryValueA, RegEnumKeyA, RegSetValueExA, RegDeleteValueA, RegDeleteKeyA, RegCreateKeyExA, RegCloseKey |
SHELL32.dll | SHBrowseForFolderA, SHGetFileInfoA, SHGetPathFromIDListA, SHGetSpecialFolderLocation, SHGetDesktopFolder, DragQueryFileA, SHAppBarMessage, ShellExecuteA, DragFinish |
COMCTL32.dll | ImageList_Draw, ImageList_GetImageCount |
SHLWAPI.dll | PathFindFileNameA, PathIsUNCA, PathStripToRootA, StrFormatKBSizeA, PathFindExtensionA, PathRemoveFileSpecW |
UxTheme.dll | GetThemeSysColor, GetWindowTheme, IsAppThemed, GetThemePartSize, DrawThemeText, DrawThemeParentBackground, OpenThemeData, CloseThemeData, DrawThemeBackground, GetThemeColor, GetCurrentThemeName, IsThemeBackgroundPartiallyTransparent |
ole32.dll | CoGetClassObject, CoRevokeClassObject, OleFlushClipboard, OleIsCurrentClipboard, CoRegisterMessageFilter, DoDragDrop, OleGetClipboard, CoLockObjectExternal, RegisterDragDrop, RevokeDragDrop, OleLockRunning, OleCreateMenuDescriptor, OleDestroyMenuDescriptor, OleTranslateAccelerator, IsAccelerator, CreateStreamOnHGlobal, OleUninitialize, OleInitialize, CoFreeUnusedLibraries, CoInitializeEx, CreateILockBytesOnHGlobal, StgOpenStorageOnILockBytes, StgCreateDocfileOnILockBytes, CoDisconnectObject, ReleaseStgMedium, OleDuplicateData, CoTaskMemFree, CoTaskMemAlloc, CLSIDFromProgID, CLSIDFromString, CoInitialize, CoCreateInstance, CoCreateGuid, CoUninitialize |
OLEAUT32.dll | SysAllocString, SysStringLen, SystemTimeToVariantTime, VariantTimeToSystemTime, SafeArrayDestroy, LoadTypeLib, OleCreateFontIndirect, VariantCopy, VarBstrFromDate, VariantChangeType, VariantClear, SysAllocStringByteLen, VariantInit, SysAllocStringLen, SysFreeString |
oledlg.dll | |
gdiplus.dll | GdipDrawImageRectI, GdipSetInterpolationMode, GdipCreateFromHDC, GdipCreateBitmapFromHBITMAP, GdipDrawImageI, GdipDeleteGraphics, GdipBitmapUnlockBits, GdipBitmapLockBits, GdipCreateBitmapFromScan0, GdipCreateBitmapFromStream, GdipGetImagePaletteSize, GdipGetImagePalette, GdipGetImagePixelFormat, GdipGetImageHeight, GdipGetImageWidth, GdipGetImageGraphicsContext, GdipDisposeImage, GdipCloneImage, GdiplusStartup, GdipFree, GdipAlloc, GdiplusShutdown |
OLEACC.dll | AccessibleObjectFromWindow, LresultFromObject, CreateStdAccessibleObject |
IMM32.dll | ImmGetContext, ImmGetOpenStatus, ImmReleaseContext |
WINMM.dll | PlaySoundA |
kernel32.dll | VirtualFree, LoadLibraryA |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States | |
Portuguese | Brazil |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Target ID: | 6 |
Start time: | 03:19:06 |
Start date: | 04/10/2024 |
Path: | C:\Users\user\Desktop\bfsvc.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x140000000 |
File size: | 2'789'712 bytes |
MD5 hash: | 60A339532F6A5290D435ACBD30CB1992 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Execution Graph
Execution Coverage: | 0% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 0% |
Total number of Nodes: | 3 |
Total number of Limit Nodes: | 0 |
Graph
Function 00000001401AFA10 Relevance: 1.5, APIs: 1, Instructions: 45COMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014015A6A0 Relevance: 83.1, APIs: 46, Strings: 1, Instructions: 850COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014013A1C4 Relevance: 50.0, APIs: 27, Strings: 1, Instructions: 969windowsleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400400EC Relevance: 33.8, APIs: 17, Strings: 2, Instructions: 580windowCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014019E774 Relevance: 31.9, APIs: 20, Instructions: 1857COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014009E3C0 Relevance: 31.8, APIs: 16, Strings: 2, Instructions: 330windowkeyboardCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400A06F8 Relevance: 28.6, APIs: 15, Strings: 1, Instructions: 615windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400380F4 Relevance: 28.2, APIs: 15, Strings: 1, Instructions: 179COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400D8088 Relevance: 27.5, APIs: 18, Instructions: 487windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400D6210 Relevance: 25.7, APIs: 17, Instructions: 243windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014001C178 Relevance: 24.7, APIs: 12, Strings: 2, Instructions: 219COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400A6304 Relevance: 23.1, APIs: 10, Strings: 3, Instructions: 383windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001401AE40C Relevance: 22.3, APIs: 8, Strings: 4, Instructions: 1310COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014008E858 Relevance: 20.0, APIs: 10, Strings: 1, Instructions: 767windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001401264F4 Relevance: 19.7, APIs: 10, Strings: 1, Instructions: 407windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400481D8 Relevance: 19.6, APIs: 1, Strings: 10, Instructions: 395windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014009035C Relevance: 18.6, APIs: 12, Instructions: 630windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140086488 Relevance: 18.3, APIs: 12, Instructions: 346windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140062578 Relevance: 18.3, APIs: 12, Instructions: 314windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001401168BC Relevance: 16.7, APIs: 11, Instructions: 211windowkeyboardCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140142110 Relevance: 15.2, APIs: 10, Instructions: 189windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014000E4E0 Relevance: 13.8, APIs: 9, Instructions: 251filecommemoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140066824 Relevance: 13.7, APIs: 9, Instructions: 180windowclipboardCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014006C43C Relevance: 12.3, APIs: 5, Strings: 2, Instructions: 68COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014001E3DC Relevance: 12.3, APIs: 5, Strings: 2, Instructions: 62libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014012C33C Relevance: 10.7, APIs: 5, Strings: 1, Instructions: 202COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400E00A4 Relevance: 9.1, APIs: 6, Instructions: 145keyboardwindowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400A8198 Relevance: 6.3, APIs: 4, Instructions: 287keyboardCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001401606C0 Relevance: 5.5, APIs: 2, Strings: 1, Instructions: 221COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001401A05F0 Relevance: 4.8, APIs: 3, Instructions: 340COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400DA2EC Relevance: 4.8, APIs: 3, Instructions: 265keyboardCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400D4340 Relevance: 3.8, APIs: 1, Strings: 1, Instructions: 315COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014009A1F8 Relevance: .4, Instructions: 412COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001401768D4 Relevance: .2, Instructions: 205COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014007C650 Relevance: .2, Instructions: 185COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014005E090 Relevance: 63.3, APIs: 42, Instructions: 315COMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140066264 Relevance: 44.0, APIs: 24, Strings: 1, Instructions: 248windowCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014003017C Relevance: 31.9, APIs: 21, Instructions: 387windowkeyboardCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400184D8 Relevance: 31.7, APIs: 15, Strings: 3, Instructions: 181COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001401628AC Relevance: 30.1, APIs: 20, Instructions: 133windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014012E5D8 Relevance: 30.0, APIs: 16, Strings: 1, Instructions: 271windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400547F4 Relevance: 26.5, APIs: 7, Strings: 8, Instructions: 257windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140068560 Relevance: 24.8, APIs: 13, Strings: 1, Instructions: 312windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140024298 Relevance: 24.2, APIs: 16, Instructions: 157windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140096230 Relevance: 22.9, APIs: 12, Strings: 1, Instructions: 182timeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140092244 Relevance: 21.2, APIs: 14, Instructions: 234windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400887AC Relevance: 21.2, APIs: 14, Instructions: 189windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140006554 Relevance: 21.1, APIs: 10, Strings: 2, Instructions: 92libraryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014006A0D4 Relevance: 19.4, APIs: 10, Strings: 1, Instructions: 189COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400647E8 Relevance: 19.4, APIs: 1, Strings: 10, Instructions: 176COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400BE86C Relevance: 18.3, APIs: 12, Instructions: 255windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400E8394 Relevance: 18.2, APIs: 12, Instructions: 247timewindowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400B6654 Relevance: 15.9, APIs: 8, Strings: 1, Instructions: 183COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140176100 Relevance: 15.9, APIs: 8, Strings: 1, Instructions: 114COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014004A4B8 Relevance: 15.3, APIs: 10, Instructions: 310windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400B08C4 Relevance: 15.2, APIs: 10, Instructions: 230windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014001C728 Relevance: 15.1, APIs: 10, Instructions: 115memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400A26FC Relevance: 14.3, APIs: 7, Strings: 1, Instructions: 271windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014001E4B8 Relevance: 14.1, APIs: 6, Strings: 2, Instructions: 135libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140072114 Relevance: 14.1, APIs: 7, Strings: 1, Instructions: 121COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140018310 Relevance: 14.1, APIs: 7, Strings: 1, Instructions: 113COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014001C374 Relevance: 14.1, APIs: 7, Strings: 1, Instructions: 66COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014001A040 Relevance: 14.1, APIs: 6, Strings: 2, Instructions: 56libraryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014013E67C Relevance: 13.6, APIs: 9, Instructions: 136timekeyboardCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400A201C Relevance: 12.5, APIs: 6, Strings: 1, Instructions: 295COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014014E7D8 Relevance: 12.4, APIs: 6, Strings: 1, Instructions: 196windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400A2474 Relevance: 12.4, APIs: 6, Strings: 1, Instructions: 178windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014005A534 Relevance: 12.4, APIs: 6, Strings: 1, Instructions: 168windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400AA598 Relevance: 12.3, APIs: 6, Strings: 1, Instructions: 79windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140034878 Relevance: 12.3, APIs: 5, Strings: 2, Instructions: 76COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140006404 Relevance: 12.3, APIs: 6, Strings: 1, Instructions: 68COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014003E864 Relevance: 12.3, APIs: 5, Strings: 2, Instructions: 68COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014001A104 Relevance: 12.3, APIs: 6, Strings: 1, Instructions: 59registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400488B8 Relevance: 12.1, APIs: 8, Instructions: 98windowtimeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400285B8 Relevance: 10.7, APIs: 7, Instructions: 249COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400823E0 Relevance: 10.7, APIs: 1, Strings: 5, Instructions: 204COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014009C820 Relevance: 10.7, APIs: 5, Strings: 1, Instructions: 185windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400160D4 Relevance: 10.6, APIs: 3, Strings: 3, Instructions: 130libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400082BC Relevance: 10.6, APIs: 7, Instructions: 56memorystringCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014001E6A0 Relevance: 10.5, APIs: 4, Strings: 2, Instructions: 44libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014001E7CC Relevance: 10.5, APIs: 4, Strings: 2, Instructions: 44libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014001E874 Relevance: 10.5, APIs: 4, Strings: 2, Instructions: 44libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014001E358 Relevance: 10.5, APIs: 4, Strings: 2, Instructions: 35libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014001E748 Relevance: 10.5, APIs: 4, Strings: 2, Instructions: 35libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400487D4 Relevance: 9.1, APIs: 6, Instructions: 54windowtimeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014008C3EC Relevance: 9.0, APIs: 1, Strings: 4, Instructions: 285COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400B83F0 Relevance: 9.0, APIs: 4, Strings: 1, Instructions: 206fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140052090 Relevance: 8.9, APIs: 3, Strings: 2, Instructions: 149COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400125AC Relevance: 8.9, APIs: 3, Strings: 2, Instructions: 137COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014000A814 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 135registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014009671C Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 113COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140142604 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 96windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014000A114 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 66registrylibraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140006324 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 56COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014000A248 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 48registrylibraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014001DFE4 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 46libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014001E178 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 44libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014001E2B4 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 44libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014011A624 Relevance: 8.8, APIs: 2, Strings: 3, Instructions: 40COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014001E220 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 39libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014001E104 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 32libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014001E090 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 31libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001401AA458 Relevance: 7.8, APIs: 5, Instructions: 265COMMONLIBRARYCODE
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400AC0B0 Relevance: 7.6, APIs: 5, Instructions: 109keyboardCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014006A6B4 Relevance: 7.2, APIs: 3, Strings: 1, Instructions: 196COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140042118 Relevance: 7.2, APIs: 3, Strings: 1, Instructions: 152COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001401081A4 Relevance: 7.1, APIs: 1, Strings: 3, Instructions: 126COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400EA700 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 120COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001401282D8 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 107COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014008009C Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 103windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001401722E8 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 90COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140036398 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 89COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001401662A4 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 65timeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140012424 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 56libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140176044 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 44COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400D8804 Relevance: 6.2, APIs: 4, Instructions: 218keyboardCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140168098 Relevance: 6.0, APIs: 4, Instructions: 42timewindowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400C2598 Relevance: 5.6, APIs: 2, Strings: 1, Instructions: 365COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400D4014 Relevance: 5.5, APIs: 2, Strings: 1, Instructions: 208COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400F8728 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 169windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400F62A8 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 112COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400E8754 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 78COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001401905CC Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 50windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000140004480 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 33COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001400064F8 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 25COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000014013E618 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 24COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|