Windows
Analysis Report
RUMMY.EXE
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- RUMMY.EXE (PID: 7092 cmdline:
"C:\Users\ user\Deskt op\RUMMY.E XE" MD5: D228499E249B66190ED130B1D27790EC)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Static PE information: |
Source: | String found in binary or memory: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 DLL Side-Loading | OS Credential Dumping | 1 System Information Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
19% | ReversingLabs | Win32.Trojan.Generic | ||
22% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1528654 |
Start date and time: | 2024-10-08 07:42:45 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 47s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 4 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | RUMMY.EXE |
Detection: | MAL |
Classification: | mal48.winEXE@1/0@0/0 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, dns.msftncsi.com, fe3cr.delivery.mp.microsoft.com
File type: | |
Entropy (8bit): | 4.383599727985923 |
TrID: |
|
File name: | RUMMY.EXE |
File size: | 151'552 bytes |
MD5: | d228499e249b66190ed130b1d27790ec |
SHA1: | 9f6d842edacd83dabc8a548d7d8eb47d5df66f3f |
SHA256: | 77032f475fe4d87f065ae038ebbd230e4281884040a28f8745dde73e4d33c067 |
SHA512: | 0b536da26e1dc87356f697be96d2a3a7c25d472259fb5cc3274e2fb8abf184b34ddbc3700879dd3af23b15da34d5c45504ad7ba19cd0c01f4209472c115ced60 |
SSDEEP: | 768:qCYcoX561rQJDbsQxgvcqgA4JswkXpTFMWCQrvTace+0PhnMKT7cd:qE6pRVgcwwkXpTFMWCQK6mVc |
TLSH: | 3EE3A833F025C84AF56999728CD099F8E2D3BD309E141523B644FBAEFAB7A409B14375 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........M...M...M...6...L.../...K.......L.......F.......H...M...........E.......L...RichM...........................PE..L......8... |
Icon Hash: | b21edeb8b5cecdff |
Entrypoint: | 0x4033de |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE |
DLL Characteristics: | |
Time Stamp: | 0x38F296E3 [Tue Apr 11 03:07:15 2000 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | 8f11bca1acc579591031ff47d7ad4c47 |
Instruction |
---|
push ebp |
mov ebp, esp |
push FFFFFFFFh |
push 00404A90h |
push 00403564h |
mov eax, dword ptr fs:[00000000h] |
push eax |
mov dword ptr fs:[00000000h], esp |
sub esp, 68h |
push ebx |
push esi |
push edi |
mov dword ptr [ebp-18h], esp |
xor ebx, ebx |
mov dword ptr [ebp-04h], ebx |
push 00000002h |
call dword ptr [00404394h] |
pop ecx |
or dword ptr [0040616Ch], FFFFFFFFh |
or dword ptr [00406170h], FFFFFFFFh |
call dword ptr [00404390h] |
mov ecx, dword ptr [00406160h] |
mov dword ptr [eax], ecx |
call dword ptr [00404388h] |
mov ecx, dword ptr [0040615Ch] |
mov dword ptr [eax], ecx |
mov eax, dword ptr [00404384h] |
mov eax, dword ptr [eax] |
mov dword ptr [00406168h], eax |
call 00007F11D52C519Bh |
cmp dword ptr [00406080h], ebx |
jne 00007F11D52C508Eh |
push 00403560h |
call dword ptr [00404380h] |
pop ecx |
call 00007F11D52C516Dh |
push 00406014h |
push 00406010h |
call 00007F11D52C5158h |
mov eax, dword ptr [00406158h] |
mov dword ptr [ebp-6Ch], eax |
lea eax, dword ptr [ebp-6Ch] |
push eax |
push dword ptr [00406154h] |
lea eax, dword ptr [ebp-64h] |
push eax |
lea eax, dword ptr [ebp-70h] |
push eax |
lea eax, dword ptr [ebp-60h] |
push eax |
call dword ptr [00404378h] |
push 0040600Ch |
push 00406000h |
call 00007F11D52C5125h |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x4d58 | 0x78 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x7000 | 0x1d5c0 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x4000 | 0x3ec | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x27d2 | 0x3000 | 468532419e1cd526c2644200ff28280f | False | 0.4298502604166667 | data | 5.273158969972959 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x4000 | 0x13c2 | 0x2000 | 6831063698e3b0bf2ed903fd016cbb98 | False | 0.2271728515625 | data | 3.389820039460895 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x6000 | 0x174 | 0x1000 | 106642e33387622d7775bbb8b97d547c | False | 0.029541015625 | data | 0.21884890496450699 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x7000 | 0x1d5c0 | 0x1e000 | 7bb5b156ce988e592517c9c788051fbf | False | 0.21956380208333334 | data | 4.230447840036496 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_BITMAP | 0x13310 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.32 |
RT_BITMAP | 0x10d90 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.3 |
RT_BITMAP | 0x11240 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.37416666666666665 |
RT_BITMAP | 0x116f0 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.3825 |
RT_BITMAP | 0x11ba0 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.41 |
RT_BITMAP | 0x12050 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.4 |
RT_BITMAP | 0x12500 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.41583333333333333 |
RT_BITMAP | 0x129b0 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.4141666666666667 |
RT_BITMAP | 0x12e60 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.4483333333333333 |
RT_BITMAP | 0x108e0 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.3925 |
RT_BITMAP | 0x137c0 | 0xde8 | Device independent bitmap graphic, 71 x 96 x 4, image size 3456 | English | United States | 0.275561797752809 |
RT_BITMAP | 0x15390 | 0xde8 | Device independent bitmap graphic, 71 x 96 x 4, image size 3456 | English | United States | 0.29943820224719103 |
RT_BITMAP | 0x145a8 | 0xde8 | Device independent bitmap graphic, 71 x 96 x 4, image size 3456 | English | United States | 0.2581460674157303 |
RT_BITMAP | 0x1e440 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.43833333333333335 |
RT_BITMAP | 0x1bec0 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.3416666666666667 |
RT_BITMAP | 0x1c370 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.38 |
RT_BITMAP | 0x1c820 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.38416666666666666 |
RT_BITMAP | 0x1ccd0 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.4041666666666667 |
RT_BITMAP | 0x1d180 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.3975 |
RT_BITMAP | 0x1d630 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.36833333333333335 |
RT_BITMAP | 0x1dae0 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.4058333333333333 |
RT_BITMAP | 0x1df90 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.4375 |
RT_BITMAP | 0x1ba10 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.4483333333333333 |
RT_BITMAP | 0x1e8f0 | 0xde8 | Device independent bitmap graphic, 71 x 96 x 4, image size 3456 | English | United States | 0.273876404494382 |
RT_BITMAP | 0x86b8 | 0xde8 | Device independent bitmap graphic, 71 x 96 x 4, image size 3456 | English | United States | 0.30168539325842697 |
RT_BITMAP | 0x1f6d8 | 0xde8 | Device independent bitmap graphic, 71 x 96 x 4, image size 3456 | English | United States | 0.26825842696629215 |
RT_BITMAP | 0xb0c0 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.32416666666666666 |
RT_BITMAP | 0x229f0 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.4075 |
RT_BITMAP | 0x204c0 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.35833333333333334 |
RT_BITMAP | 0x94a0 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.3175 |
RT_BITMAP | 0x9950 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.38916666666666666 |
RT_BITMAP | 0x9e00 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.3641666666666667 |
RT_BITMAP | 0xa2b0 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.37666666666666665 |
RT_BITMAP | 0xa760 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.36333333333333334 |
RT_BITMAP | 0xac10 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.3925 |
RT_BITMAP | 0x22ea0 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.49166666666666664 |
RT_BITMAP | 0xb570 | 0xde8 | Device independent bitmap graphic, 71 x 96 x 4, image size 3456 | English | United States | 0.2800561797752809 |
RT_BITMAP | 0xd140 | 0xde8 | Device independent bitmap graphic, 71 x 96 x 4, image size 3456 | English | United States | 0.30786516853932583 |
RT_BITMAP | 0xc358 | 0xde8 | Device independent bitmap graphic, 71 x 96 x 4, image size 3456 | English | United States | 0.31573033707865167 |
RT_BITMAP | 0x18ba8 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.29333333333333333 |
RT_BITMAP | 0x16628 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.3516666666666667 |
RT_BITMAP | 0x16ad8 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.36583333333333334 |
RT_BITMAP | 0x16f88 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.3616666666666667 |
RT_BITMAP | 0x17438 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.3825 |
RT_BITMAP | 0x178e8 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.37416666666666665 |
RT_BITMAP | 0x17d98 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.38916666666666666 |
RT_BITMAP | 0x18248 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.4191666666666667 |
RT_BITMAP | 0x186f8 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.4225 |
RT_BITMAP | 0x16178 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.43333333333333335 |
RT_BITMAP | 0x19058 | 0xde8 | Device independent bitmap graphic, 71 x 96 x 4, image size 3456 | English | United States | 0.2648876404494382 |
RT_BITMAP | 0x1ac28 | 0xde8 | Device independent bitmap graphic, 71 x 96 x 4, image size 3456 | English | United States | 0.2941011235955056 |
RT_BITMAP | 0x19e40 | 0xde8 | Device independent bitmap graphic, 71 x 96 x 4, image size 3456 | English | United States | 0.2859550561797753 |
RT_BITMAP | 0x8290 | 0x428 | Device independent bitmap graphic, 128 x 15 x 4, image size 960 | English | United States | 0.3618421052631579 |
RT_BITMAP | 0xdf28 | 0xde8 | Device independent bitmap graphic, 71 x 96 x 4, image size 3456 | English | United States | 0.04522471910112359 |
RT_BITMAP | 0xed10 | 0xde8 | Device independent bitmap graphic, 71 x 96 x 4, image size 3456 | English | United States | 0.10056179775280899 |
RT_BITMAP | 0xfaf8 | 0xde8 | Device independent bitmap graphic, 71 x 96 x 4, image size 3456 | English | United States | 0.0550561797752809 |
RT_BITMAP | 0x20970 | 0xde8 | Device independent bitmap graphic, 71 x 96 x 4, image size 3456 | English | United States | 0.2606741573033708 |
RT_BITMAP | 0x21758 | 0x4b0 | Device independent bitmap graphic, 71 x 96 x 1, image size 1152 | English | United States | 0.29583333333333334 |
RT_BITMAP | 0x21c08 | 0xde8 | Device independent bitmap graphic, 71 x 96 x 4, image size 3456 | English | United States | 0.04719101123595506 |
RT_ICON | 0x7f90 | 0x2e8 | Device independent bitmap graphic, 32 x 64 x 4, image size 512 | English | United States | 0.36693548387096775 |
RT_MENU | 0x23370 | 0x9a | data | English | United States | 0.7402597402597403 |
RT_DIALOG | 0x23420 | 0x172 | data | English | United States | 0.5864864864864865 |
RT_STRING | 0x23840 | 0x6c | data | English | United States | 0.4444444444444444 |
RT_STRING | 0x238b0 | 0x34 | data | English | United States | 0.5576923076923077 |
RT_STRING | 0x23930 | 0x166 | data | English | United States | 0.37988826815642457 |
RT_STRING | 0x23ba0 | 0x260 | data | English | United States | 0.0805921052631579 |
RT_STRING | 0x23f50 | 0x328 | data | English | United States | 0.34405940594059403 |
RT_STRING | 0x23ee0 | 0x70 | data | English | United States | 0.625 |
RT_STRING | 0x23a98 | 0x106 | data | English | United States | 0.5763358778625954 |
RT_STRING | 0x23e00 | 0xda | data | English | United States | 0.43119266055045874 |
RT_STRING | 0x238e8 | 0x46 | data | English | United States | 0.7428571428571429 |
RT_STRING | 0x24278 | 0xc6 | data | English | United States | 0.41919191919191917 |
RT_STRING | 0x24340 | 0x1f8 | data | English | United States | 0.36706349206349204 |
RT_STRING | 0x24538 | 0x86 | data | English | United States | 0.6567164179104478 |
RT_ACCELERATOR | 0x23410 | 0x10 | data | English | United States | 1.3125 |
RT_GROUP_ICON | 0x8278 | 0x14 | data | English | United States | 1.2 |
RT_VERSION | 0x23598 | 0x2a8 | data | English | United States | 0.4808823529411765 |
None | 0x23350 | 0x1c | data | English | United States | 1.25 |
DLL | Import |
---|---|
MFC42.DLL | |
MSVCRT.dll | _acmdln, __getmainargs, _initterm, __setusermatherr, _adjust_fdiv, __p__commode, exit, __p__fmode, __set_app_type, _except_handler3, _controlfp, _exit, _onexit, _XcptFilter, __dllonexit, rand, _setmbcp, _itoa, srand, time, __CxxFrameHandler |
KERNEL32.dll | GetModuleHandleA, GetStartupInfoA |
USER32.dll | SetTimer, GetClientRect, KillTimer, FillRect, LoadBitmapA, LoadCursorA, EnableWindow |
GDI32.dll | CreateSolidBrush, BitBlt, CreateCompatibleDC |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 8, 2024 07:43:55.673548937 CEST | 53 | 50997 | 1.1.1.1 | 192.168.2.5 |
Target ID: | 0 |
Start time: | 01:43:34 |
Start date: | 08/10/2024 |
Path: | C:\Users\user\Desktop\RUMMY.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 151'552 bytes |
MD5 hash: | D228499E249B66190ED130B1D27790EC |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 11% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 0% |
Total number of Nodes: | 179 |
Total number of Limit Nodes: | 10 |
Graph
Callgraph
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401190 Relevance: 15.1, APIs: 10, Instructions: 67COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402690 Relevance: 6.2, APIs: 4, Instructions: 210COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403570 Relevance: 1.5, APIs: 1, Instructions: 6COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401B30 Relevance: 17.7, APIs: 9, Strings: 1, Instructions: 206timeCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004033DE Relevance: 16.6, APIs: 11, Instructions: 111COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004019E0 Relevance: 6.0, APIs: 4, Instructions: 29COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401AE0 Relevance: 6.0, APIs: 4, Instructions: 25COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|