Windows
Analysis Report
czcansrv.exe
Overview
General Information
Detection
Score: | 28 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 40% |
Signatures
Classification
- System is w10x64
- czcansrv.exe (PID: 6540 cmdline:
"C:\Users\ user\Deskt op\czcansr v.exe" MD5: 52D32DF86AF95F0844FC3DD43956C997)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Integrated Neural Analysis Model: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: |
Source: | Code function: | 0_2_00E222F3 |
Source: | Code function: | 0_2_00DCE0DA |
Source: | Code function: | 0_2_00DEC41B |
Source: | Code function: | 0_2_00DCC525 |
Source: | Code function: | 0_2_00E101EF | |
Source: | Code function: | 0_2_00E121A6 | |
Source: | Code function: | 0_2_00E2C280 | |
Source: | Code function: | 0_2_00DC4390 | |
Source: | Code function: | 0_2_00E125D6 | |
Source: | Code function: | 0_2_00E2A547 | |
Source: | Code function: | 0_2_00E10546 | |
Source: | Code function: | 0_2_00E346A0 | |
Source: | Code function: | 0_2_00DCC6AE | |
Source: | Code function: | 0_2_00DE674B | |
Source: | Code function: | 0_2_00DF4760 | |
Source: | Code function: | 0_2_00E1088E | |
Source: | Code function: | 0_2_00E2C92F | |
Source: | Code function: | 0_2_00DE2C07 | |
Source: | Code function: | 0_2_00E10C1C | |
Source: | Code function: | 0_2_00DCEDB2 | |
Source: | Code function: | 0_2_00DE8D44 | |
Source: | Code function: | 0_2_00DE4D0E | |
Source: | Code function: | 0_2_00E10FB9 | |
Source: | Code function: | 0_2_00DD8F6C | |
Source: | Code function: | 0_2_00DD30C2 | |
Source: | Code function: | 0_2_00E11347 | |
Source: | Code function: | 0_2_00E116AC | |
Source: | Code function: | 0_2_00E2B930 | |
Source: | Code function: | 0_2_00E11A20 | |
Source: | Code function: | 0_2_00DC3BFE | |
Source: | Code function: | 0_2_00E1FDC5 | |
Source: | Code function: | 0_2_00E11D85 | |
Source: | Code function: | 0_2_00E0FEA7 | |
Source: | Code function: | 0_2_00E2BE40 | |
Source: | Code function: | 0_2_00DE3F48 |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_00DCA4C1 |
Source: | Code function: | 0_2_00DC63EB |
Source: | Code function: | 0_2_00DCB1AF |
Source: | Code function: | 0_2_00DCC41F |
Source: | Code function: | 0_2_00DCC41F |
Source: | Command line argument: | 0_2_00DCCEF1 | |
Source: | Command line argument: | 0_2_00DCCEF1 | |
Source: | Command line argument: | 0_2_00DCCEF1 | |
Source: | Command line argument: | 0_2_00DCCEF1 | |
Source: | Command line argument: | 0_2_00DCCEF1 | |
Source: | Command line argument: | 0_2_00DCCEF1 | |
Source: | Command line argument: | 0_2_00DCCEF1 | |
Source: | Command line argument: | 0_2_00DCCEF1 | |
Source: | Command line argument: | 0_2_00DCCEF1 | |
Source: | Command line argument: | 0_2_00DCCEF1 | |
Source: | Command line argument: | 0_2_00DCCEF1 | |
Source: | Command line argument: | 0_2_00DCCEF1 | |
Source: | Command line argument: | 0_2_00DCCEF1 | |
Source: | Command line argument: | 0_2_00DCCEF1 | |
Source: | Command line argument: | 0_2_00DCCEF1 | |
Source: | Command line argument: | 0_2_00DCCEF1 | |
Source: | Command line argument: | 0_2_00DCCEF1 | |
Source: | Command line argument: | 0_2_00DCCEF1 | |
Source: | Command line argument: | 0_2_00DCCEF1 | |
Source: | Command line argument: | 0_2_00DCCEF1 | |
Source: | Command line argument: | 0_2_00DCCEF1 | |
Source: | Command line argument: | 0_2_00DCCEF1 |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_2_00DEA8DC |
Source: | Code function: | 0_2_00DEE9D3 | |
Source: | Code function: | 0_2_00DEDD52 |
Source: | Code function: | 0_2_00DCC41F |
Source: | Code function: | 0_2_00DC1CED |
Source: | API coverage: |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Code function: | 0_2_00E222F3 |
Source: | Code function: | 0_2_00DFDC97 |
Source: | Code function: | 0_2_00DEE767 |
Source: | Code function: | 0_2_00DFDC97 |
Source: | Code function: | 0_2_00DEA8DC |
Source: | Code function: | 0_2_00E190C2 | |
Source: | Code function: | 0_2_00E21965 | |
Source: | Code function: | 0_2_00E217BC | |
Source: | Code function: | 0_2_00E21779 | |
Source: | Code function: | 0_2_00E21736 | |
Source: | Code function: | 0_2_00E218DD | |
Source: | Code function: | 0_2_00E21817 | |
Source: | Code function: | 0_2_00E21996 | |
Source: | Code function: | 0_2_00E21921 |
Source: | Code function: | 0_2_00E247B4 |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Code function: | 0_2_00DEE767 | |
Source: | Code function: | 0_2_00DEE8FE | |
Source: | Code function: | 0_2_00DFD7E9 | |
Source: | Code function: | 0_2_00DEDF29 |
Source: | Code function: | 0_2_00DEEBA1 |
Source: | Code function: | 0_2_00E1E0C3 | |
Source: | Code function: | 0_2_00E280CC | |
Source: | Code function: | 0_2_00E2819B | |
Source: | Code function: | 0_2_00E1E254 | |
Source: | Code function: | 0_2_00E1E222 | |
Source: | Code function: | 0_2_00E1EB7F | |
Source: | Code function: | 0_2_00E27ABB | |
Source: | Code function: | 0_2_00E27BBF | |
Source: | Code function: | 0_2_00E27B24 | |
Source: | Code function: | 0_2_00E27C4A | |
Source: | Code function: | 0_2_00E27E9D | |
Source: | Code function: | 0_2_00E27FC6 |
Source: | Code function: | 0_2_00DD82B9 |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 2 Command and Scripting Interpreter | 14 Windows Service | 14 Windows Service | 1 Disable or Modify Tools | OS Credential Dumping | 1 System Time Discovery | Remote Services | 1 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 12 Service Execution | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Deobfuscate/Decode Files or Information | LSASS Memory | 2 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Native API | Logon Script (Windows) | Logon Script (Windows) | 2 Obfuscated Files or Information | Security Account Manager | 1 File and Directory Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 DLL Side-Loading | NTDS | 23 System Information Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | ReversingLabs |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1542032 |
Start date and time: | 2024-10-25 13:19:01 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 2m 18s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Run name: | Potential for more IOCs and behavior |
Number of analysed new started processes analysed: | 1 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | czcansrv.exe |
Detection: | SUS |
Classification: | sus28.winEXE@1/0@0/0 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- VT rate limit hit for: czcansrv.exe
File type: | |
Entropy (8bit): | 6.613701793342054 |
TrID: |
|
File name: | czcansrv.exe |
File size: | 672'256 bytes |
MD5: | 52d32df86af95f0844fc3dd43956c997 |
SHA1: | 44789fd469a3164712d00e89e7b2b7d3aa4d02e9 |
SHA256: | 3ad754f08c2f4c4fca7ff66937838429c893e3bceb2b6aa73768c90eb1276664 |
SHA512: | a1b84aaf467086c0430bc4615036d7fdbda4cc710a35429ab65103f1daed80f56a5013f1b73ab0f01509fe37da3bdac61d47353e2954f0034312ccc468248fee |
SSDEEP: | 12288:CWsErQDDhCK0KEeZp44OaVDrQuBLouSWHmSrhm4AwfHfEM8wl1vN:RrKDhCoEeZp44OaV4VSb8wl1vN |
TLSH: | EEE49E12F58180B7CA3225310A66B37556FFA8712E2267CB539C077E6FB45D0AF1623B |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$....... ...d.{.d.{.d.{...x.o.{...~...{.6...u.{.6.x.q.{.6.~.R.{.....r.{...b.f.{.d.z...{...z.k.{...~.z.{.....e.{.d...e.{...y.e.{.Richd.{ |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x42e5dc |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x64ACFA30 [Tue Jul 11 06:44:00 2023 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 6 |
OS Version Minor: | 0 |
File Version Major: | 6 |
File Version Minor: | 0 |
Subsystem Version Major: | 6 |
Subsystem Version Minor: | 0 |
Import Hash: | 7ad32d3ce41e5e74f9073f467044d27c |
Instruction |
---|
call 00007FE35CB50083h |
jmp 00007FE35CB4F6CAh |
retn 0000h |
push ebp |
mov ebp, esp |
mov eax, dword ptr [ebp+08h] |
mov eax, dword ptr [eax] |
pop ebp |
ret |
push ebp |
mov ebp, esp |
mov eax, dword ptr [ebp+08h] |
mov eax, dword ptr [eax] |
pop ebp |
ret |
push ebp |
mov ebp, esp |
mov eax, dword ptr [ebp+08h] |
mov edx, 00488800h |
mov ecx, 004887C4h |
sub eax, edx |
sub ecx, edx |
cmp eax, ecx |
jnbe 00007FE35CB4F893h |
int3 |
pop ebp |
ret |
push ebp |
mov ebp, esp |
mov eax, dword ptr [ebp+08h] |
mov edx, 00488800h |
mov ecx, 004887C4h |
sub eax, edx |
sub ecx, edx |
cmp eax, ecx |
jnbe 00007FE35CB4F897h |
push 00000041h |
pop ecx |
int 29h |
pop ebp |
ret |
retn 0000h |
push ebp |
mov ebp, esp |
mov eax, dword ptr [ebp+08h] |
mov edx, 00488800h |
mov ecx, 004887C4h |
sub eax, edx |
sub ecx, edx |
cmp eax, ecx |
jnbe 00007FE35CB4F8B1h |
cmp dword ptr [0049295Ch], 00000000h |
je 00007FE35CB4F8A8h |
push esi |
mov esi, dword ptr [0049295Ch] |
mov ecx, esi |
push dword ptr [ebp+08h] |
call dword ptr [0047A388h] |
call esi |
pop ecx |
pop esi |
pop ebp |
ret |
push ebp |
mov ebp, esp |
mov eax, dword ptr [ebp+08h] |
mov edx, 00488800h |
mov ecx, 004887C4h |
sub eax, edx |
sub ecx, edx |
cmp ecx, eax |
sbb eax, eax |
inc eax |
pop ebp |
ret |
push ebp |
mov ebp, esp |
mov ecx, dword ptr [ebp+08h] |
mov eax, ecx |
sub eax, dword ptr [ebp+0Ch] |
sub eax, 004887C0h |
sub eax, 40h |
cmp eax, dword ptr [ebp+10h] |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x8eca4 | 0xb4 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x94000 | 0xda18 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0xa2000 | 0x5748 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x8869c | 0x54 | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x887c8 | 0x18 | .rdata |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x886f0 | 0x40 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x7a000 | 0x388 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x78a89 | 0x78c00 | 8fbc8c037f1a2f7d7a18be6f22d31dd7 | False | 0.4512507278726708 | data | 6.644117024573216 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x7a000 | 0x15ed4 | 0x16000 | 644bc625a606202766692e82b5bdca25 | False | 0.3907803622159091 | data | 5.264404162191819 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x90000 | 0x38bc | 0x1e00 | 76fbe0db58c9f57330955d020ef4c8a8 | False | 0.187890625 | data | 4.500306810151821 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x94000 | 0xda18 | 0xdc00 | 1efc546342993356bad798a45c7fa381 | False | 0.314453125 | data | 5.198439058553413 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0xa2000 | 0x5748 | 0x5800 | 565f8c64c105122758dba8c36f2d44c7 | False | 0.7017045454545454 | data | 6.6435449201237065 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
REGISTRY | 0x94530 | 0xb3 | ASCII text, with CRLF line terminators | German | Germany | 0.659217877094972 |
REGISTRY | 0x945e8 | 0x25e | ASCII text, with CRLF line terminators | German | Germany | 0.4900990099009901 |
REGISTRY | 0x94848 | 0x276 | ASCII text, with CRLF line terminators | German | Germany | 0.473015873015873 |
REGISTRY | 0x94ac0 | 0x28e | ASCII text, with CRLF line terminators | German | Germany | 0.4648318042813456 |
TYPELIB | 0x94d50 | 0xcb14 | data | German | Germany | 0.3158421174117104 |
RT_STRING | 0xa1868 | 0x30 | data | German | Germany | 0.6041666666666666 |
RT_VERSION | 0x94230 | 0x2fc | data | German | Germany | 0.4869109947643979 |
RT_MANIFEST | 0xa1898 | 0x17d | XML 1.0 document, ASCII text, with CRLF line terminators | English | United States | 0.5931758530183727 |
DLL | Import |
---|---|
WS2_32.dll | htons, recvfrom, sendto, setsockopt, gethostbyaddr, gethostbyname, WSAStartup, WSASetLastError, WSAGetLastError, WSAConnect, WSAEventSelect, WSAGetOverlappedResult, WSARecv, inet_ntoa, inet_addr, WSACleanup, WSASocketA, WSASend, closesocket |
SETUPAPI.dll | SetupDiGetDeviceInterfaceDetailA, SetupDiGetClassDevsA, SetupDiEnumDeviceInterfaces, SetupDiDestroyDeviceInfoList |
HID.DLL | HidP_GetCaps, HidD_GetHidGuid, HidD_GetPreparsedData, HidD_GetSerialNumberString, HidD_GetAttributes |
KERNEL32.dll | SetEvent, ResetEvent, WaitForSingleObject, CreateEventA, Sleep, WaitForMultipleObjects, GetProcAddress, LoadLibraryA, MultiByteToWideChar, CreateFileA, ReadFile, WriteFile, GetOverlappedResult, CreateThread, GetTickCount, SetupComm, GetCommState, SetCommState, SetCommTimeouts, GetCommandLineA, GetCurrentProcess, GetCurrentThread, GetCurrentThreadId, RaiseException, GetModuleFileNameA, GetModuleHandleA, InitializeCriticalSectionAndSpinCount, LoadLibraryExA, LoadResource, SizeofResource, lstrcmpiA, FindResourceA, WideCharToMultiByte, IsDBCSLeadByte, GetProfileIntA, GetLocalTime, SetPriorityClass, GetPriorityClass, WriteProfileStringA, DeviceIoControl, CancelIo, GetUserDefaultLCID, IsValidLocale, GetLocaleInfoW, LCMapStringW, CompareStringW, GetTimeFormatW, GetDateFormatW, HeapReAlloc, HeapSize, HeapAlloc, HeapFree, CloseHandle, DecodePointer, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, GetModuleHandleW, GetLastError, EnumSystemLocalesW, GetFileType, FindClose, FindFirstFileExW, FindNextFileW, IsValidCodePage, GetACP, GetOEMCP, GetCPInfo, GetCommandLineW, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetEnvironmentVariableW, WriteConsoleW, GetProcessHeap, SetConsoleCtrlHandler, SetStdHandle, GetStringTypeW, GetFileSizeEx, SetFilePointerEx, GetConsoleOutputCP, GetConsoleMode, FlushFileBuffers, ReadConsoleW, CreateFileW, FreeLibrary, GetStdHandle, GetModuleFileNameW, GetModuleHandleExW, ExitProcess, VirtualQuery, VirtualProtect, VirtualAlloc, GetSystemInfo, LoadLibraryExW, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, EncodePointer, SetLastError, InterlockedFlushSList, InterlockedPushEntrySList, RtlUnwind, InitializeSListHead, GetSystemTimeAsFileTime, GetCurrentProcessId, QueryPerformanceCounter, GetStartupInfoW, IsProcessorFeaturePresent, TerminateProcess, SetUnhandledExceptionFilter, UnhandledExceptionFilter, CreateEventW, WaitForSingleObjectEx, OutputDebugStringW, IsDebuggerPresent |
USER32.dll | UnregisterClassA, wsprintfA, LoadStringA, GetMessageA, DispatchMessageA, PostThreadMessageA, CharNextA, MessageBoxA, CharNextW |
ADVAPI32.dll | RegQueryInfoKeyA, StartServiceCtrlDispatcherA, SetServiceStatus, RegisterServiceCtrlHandlerA, OpenServiceA, OpenSCManagerA, DeleteService, CreateServiceA, ControlService, CloseServiceHandle, RegSetValueExA, RegQueryInfoKeyW, RegEnumKeyExA, RegDeleteValueA, RegDeleteKeyA, RegCreateKeyExA, ReportEventA, RegisterEventSourceA, DeregisterEventSource, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, IsValidSid, InitializeSecurityDescriptor, GetTokenInformation, GetLengthSid, CopySid, OpenThreadToken, OpenProcessToken, RegQueryValueExA, RegOpenKeyExA, RegOpenKeyA, RegEnumValueA, RegCloseKey |
ole32.dll | CoInitialize, CoTaskMemFree, CoTaskMemRealloc, CoTaskMemAlloc, StringFromGUID2, CoUninitialize, CoInitializeSecurity, CoRevokeClassObject, CoRegisterClassObject, CoInitializeEx, CoCreateInstance |
OLEAUT32.dll | SysFreeString, VariantClear, VariantInit, SafeArrayUnaccessData, SafeArrayAccessData, SafeArrayDestroy, SafeArrayCreate, VarBstrCmp, VarBstrCat, SysAllocStringByteLen, SysStringByteLen, UnRegisterTypeLib, RegisterTypeLib, LoadRegTypeLib, LoadTypeLib, VarUI4FromStr, SysAllocString, SysStringLen, SysAllocStringLen, VariantCopy |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
German | Germany | |
English | United States |
Target ID: | 0 |
Start time: | 07:19:51 |
Start date: | 25/10/2024 |
Path: | C:\Users\user\Desktop\czcansrv.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xdc0000 |
File size: | 672'256 bytes |
MD5 hash: | 52D32DF86AF95F0844FC3DD43956C997 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Execution Graph
Execution Coverage: | 0.4% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 21.2% |
Total number of Nodes: | 151 |
Total number of Limit Nodes: | 4 |
Graph
Function 00DCCEF1 Relevance: 35.1, APIs: 8, Strings: 12, Instructions: 136stringregistryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E21965 Relevance: .0, Instructions: 22COMMONLIBRARYCODE
Control-flow Graph
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E190C2 Relevance: .0, Instructions: 12COMMONLIBRARYCODE
Control-flow Graph
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E1E5FA Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 74COMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DEE411 Relevance: 7.6, APIs: 5, Instructions: 123COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DC996F Relevance: 3.8, APIs: 3, Instructions: 34COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DCA30B Relevance: 1.5, APIs: 1, Instructions: 31COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DC1CED Relevance: 84.2, APIs: 24, Strings: 24, Instructions: 160libraryloaderCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DE3F48 Relevance: 74.4, APIs: 22, Strings: 20, Instructions: 876registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DF4760 Relevance: 64.1, APIs: 32, Strings: 4, Instructions: 1115COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DCEDB2 Relevance: 55.0, APIs: 28, Strings: 3, Instructions: 751synchronizationCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DC4390 Relevance: 26.8, APIs: 14, Strings: 1, Instructions: 502filesynchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DE8D44 Relevance: 20.1, APIs: 10, Strings: 1, Instructions: 841synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DCC525 Relevance: 19.3, APIs: 8, Strings: 3, Instructions: 74servicewindowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DCA4C1 Relevance: 17.6, APIs: 7, Strings: 3, Instructions: 75windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DEA8DC Relevance: 17.6, APIs: 5, Strings: 5, Instructions: 64libraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E2C92F Relevance: 10.2, APIs: 1, Strings: 4, Instructions: 1436COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DEC41B Relevance: 9.1, APIs: 6, Instructions: 64COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E222F3 Relevance: 6.1, APIs: 4, Instructions: 129fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DFDC97 Relevance: 6.1, APIs: 4, Instructions: 83memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DEE767 Relevance: 6.1, APIs: 4, Instructions: 73COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E27C4A Relevance: 4.7, APIs: 3, Instructions: 205COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E2A547 Relevance: 2.8, APIs: 1, Instructions: 1260COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DD30C2 Relevance: 1.8, APIs: 1, Instructions: 288COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DE2C07 Relevance: 1.8, APIs: 1, Instructions: 278COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DEEBA1 Relevance: 1.6, APIs: 1, Instructions: 144COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E121A6 Relevance: 1.6, Strings: 1, Instructions: 392COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E125D6 Relevance: 1.6, Strings: 1, Instructions: 388COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E11D85 Relevance: 1.6, Strings: 1, Instructions: 388COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E10C1C Relevance: 1.6, Strings: 1, Instructions: 348COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E10FB9 Relevance: 1.6, Strings: 1, Instructions: 344COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E27E9D Relevance: 1.6, APIs: 1, Instructions: 83COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E116AC Relevance: 1.6, Strings: 1, Instructions: 326COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E11347 Relevance: 1.6, Strings: 1, Instructions: 322COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E11A20 Relevance: 1.6, Strings: 1, Instructions: 322COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E101EF Relevance: 1.6, Strings: 1, Instructions: 318COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E0FEA7 Relevance: 1.6, Strings: 1, Instructions: 314COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E27B24 Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DD82B9 Relevance: 1.6, APIs: 1, Instructions: 62timeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E280CC Relevance: 1.5, APIs: 1, Instructions: 45COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E27BBF Relevance: 1.5, APIs: 1, Instructions: 41COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DC63EB Relevance: 1.5, APIs: 1, Instructions: 35comCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E1E0C3 Relevance: 1.5, APIs: 1, Instructions: 33COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E27ABB Relevance: 1.5, APIs: 1, Instructions: 31COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DCC41F Relevance: 1.5, APIs: 1, Instructions: 29COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E1EB7F Relevance: 1.5, APIs: 1, Instructions: 24COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E1E254 Relevance: 1.5, APIs: 1, Instructions: 14COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E1E222 Relevance: 1.5, APIs: 1, Instructions: 11COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DEE8FE Relevance: 1.5, APIs: 1, Instructions: 3COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E21996 Relevance: 1.3, Strings: 1, Instructions: 40COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E217BC Relevance: 1.3, Strings: 1, Instructions: 38COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E21921 Relevance: 1.3, Strings: 1, Instructions: 29COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E21779 Relevance: 1.3, Strings: 1, Instructions: 26COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E247B4 Relevance: 1.3, APIs: 1, Instructions: 5memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E2C280 Relevance: .4, Instructions: 386COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E2BE40 Relevance: .3, Instructions: 259COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E218DD Relevance: .0, Instructions: 29COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E21736 Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E21817 Relevance: .0, Instructions: 18COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DF740A Relevance: 35.3, APIs: 19, Strings: 1, Instructions: 339COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DCB5A4 Relevance: 31.9, APIs: 14, Strings: 4, Instructions: 445stringregistryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DE3B12 Relevance: 31.8, APIs: 11, Strings: 7, Instructions: 274registryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DF88DE Relevance: 28.3, APIs: 13, Strings: 3, Instructions: 301COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DCEA44 Relevance: 28.2, APIs: 8, Strings: 8, Instructions: 166registryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DC498F Relevance: 26.4, APIs: 12, Strings: 3, Instructions: 187registrysleeptimeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DE8BCE Relevance: 24.1, APIs: 16, Instructions: 82synchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDB770 Relevance: 23.0, APIs: 10, Strings: 3, Instructions: 274sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DCE4C3 Relevance: 21.4, APIs: 14, Instructions: 398networksynchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DF5BB7 Relevance: 21.3, APIs: 10, Strings: 2, Instructions: 337COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DD04C2 Relevance: 21.3, APIs: 14, Instructions: 287synchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DF93D0 Relevance: 21.3, APIs: 10, Strings: 2, Instructions: 285COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DC41D3 Relevance: 21.1, APIs: 14, Instructions: 134synchronizationfileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DCB4A1 Relevance: 21.1, APIs: 6, Strings: 6, Instructions: 79registryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DED60F Relevance: 21.1, APIs: 8, Strings: 4, Instructions: 51libraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DCE254 Relevance: 19.7, APIs: 13, Instructions: 182networksleepsynchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DC8B8C Relevance: 19.5, APIs: 8, Strings: 3, Instructions: 288registrycomCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DCC05A Relevance: 19.3, APIs: 8, Strings: 3, Instructions: 97threadwindowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DD4785 Relevance: 18.2, APIs: 12, Instructions: 184COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DD6CDA Relevance: 18.1, APIs: 12, Instructions: 73synchronizationsleepCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDB327 Relevance: 17.7, APIs: 9, Strings: 1, Instructions: 218sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DFA1B2 Relevance: 17.7, APIs: 6, Strings: 4, Instructions: 180COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DC7ED4 Relevance: 16.8, APIs: 11, Instructions: 323COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DEA3FB Relevance: 16.7, APIs: 11, Instructions: 242synchronizationthreadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DE87ED Relevance: 16.7, APIs: 11, Instructions: 202sleepsynchronizationCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DD0DF6 Relevance: 16.6, APIs: 11, Instructions: 122COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DEA701 Relevance: 16.5, APIs: 11, Instructions: 42synchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DF2B1B Relevance: 16.1, APIs: 6, Strings: 3, Instructions: 304COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DC32F9 Relevance: 16.0, APIs: 4, Strings: 5, Instructions: 222registryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DCFDEE Relevance: 15.2, APIs: 10, Instructions: 197synchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DF595C Relevance: 14.2, APIs: 7, Strings: 1, Instructions: 151COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DC8F2E Relevance: 14.1, APIs: 6, Strings: 2, Instructions: 116libraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DF6CBE Relevance: 14.1, APIs: 7, Strings: 1, Instructions: 102COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DF8C90 Relevance: 14.1, APIs: 6, Strings: 2, Instructions: 95COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDBB8E Relevance: 13.7, APIs: 9, Instructions: 218sleepCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DC3ABC Relevance: 12.4, APIs: 6, Strings: 1, Instructions: 103filesleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDA0CC Relevance: 12.1, APIs: 8, Instructions: 122sleepsynchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DE8AB3 Relevance: 12.1, APIs: 8, Instructions: 98synchronizationthreadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DC22FE Relevance: 12.1, APIs: 8, Instructions: 55sleepsynchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDE14A Relevance: 10.7, APIs: 7, Instructions: 238COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDDEA0 Relevance: 10.7, APIs: 7, Instructions: 222COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DF6A54 Relevance: 10.7, APIs: 4, Strings: 2, Instructions: 201COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DF829E Relevance: 10.7, APIs: 4, Strings: 2, Instructions: 178COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DE7896 Relevance: 10.6, APIs: 7, Instructions: 134COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDC873 Relevance: 10.6, APIs: 7, Instructions: 106COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DC40B8 Relevance: 10.6, APIs: 7, Instructions: 87filesynchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DF7316 Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 87COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DD0395 Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 83synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E30B6A Relevance: 9.3, APIs: 6, Instructions: 298COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E329A9 Relevance: 9.2, APIs: 6, Instructions: 248COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDF0D8 Relevance: 9.2, APIs: 6, Instructions: 196COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DC9EA6 Relevance: 9.1, APIs: 6, Instructions: 130COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DD49F0 Relevance: 9.1, APIs: 6, Instructions: 103COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DEAFD0 Relevance: 9.1, APIs: 6, Instructions: 63COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DF70FE Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 144COMMONLIBRARYCODE
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DC90B6 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 66libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DFA90B Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 62COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E190E4 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 42libraryloaderCOMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DC9856 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 40libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E1E7BE Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 35libraryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DC23BE Relevance: 7.9, APIs: 5, Instructions: 448COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DE11C7 Relevance: 7.7, APIs: 5, Instructions: 235COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDFC35 Relevance: 7.7, APIs: 5, Instructions: 206COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDFE93 Relevance: 7.7, APIs: 5, Instructions: 197COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DE3973 Relevance: 7.6, APIs: 5, Instructions: 138COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DE7A73 Relevance: 7.6, APIs: 6, Instructions: 131COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DD6C57 Relevance: 7.6, APIs: 5, Instructions: 53synchronizationthreadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DED6D1 Relevance: 7.5, APIs: 5, Instructions: 37COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DF6E3D Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 125COMMONLIBRARYCODE
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DF84ED Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 113COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DCAE76 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 38libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DCAED9 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 37libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DCAF2B Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 34libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DF9E0A Relevance: 7.0, APIs: 1, Strings: 3, Instructions: 31COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DFAA5F Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 27libraryCOMMONLIBRARYCODE
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DCA94F Relevance: 6.4, APIs: 5, Instructions: 109COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DD85DD Relevance: 6.3, APIs: 4, Instructions: 303COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DE0EA9 Relevance: 6.3, APIs: 4, Instructions: 268COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDE421 Relevance: 6.3, APIs: 4, Instructions: 255COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDDBE7 Relevance: 6.2, APIs: 4, Instructions: 233COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDECB6 Relevance: 6.2, APIs: 4, Instructions: 182COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDEAB6 Relevance: 6.2, APIs: 4, Instructions: 181COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DE33CA Relevance: 6.2, APIs: 4, Instructions: 179COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDC9BE Relevance: 6.2, APIs: 4, Instructions: 172COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDF30A Relevance: 6.2, APIs: 4, Instructions: 167COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDE719 Relevance: 6.2, APIs: 4, Instructions: 164COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDE8ED Relevance: 6.2, APIs: 4, Instructions: 162COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDEEC0 Relevance: 6.2, APIs: 4, Instructions: 162COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DD6A01 Relevance: 6.2, APIs: 4, Instructions: 160COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DCA731 Relevance: 6.1, APIs: 4, Instructions: 133COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDB5C3 Relevance: 6.1, APIs: 4, Instructions: 106COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDBE29 Relevance: 6.1, APIs: 4, Instructions: 106COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DE7E02 Relevance: 6.1, APIs: 4, Instructions: 98COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DEC302 Relevance: 6.1, APIs: 4, Instructions: 95COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DD8E3D Relevance: 6.1, APIs: 4, Instructions: 89memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E21AD4 Relevance: 6.1, APIs: 4, Instructions: 82COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E23DE9 Relevance: 6.1, APIs: 4, Instructions: 74COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DD0AA2 Relevance: 6.1, APIs: 4, Instructions: 57networksynchronizationCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E30178 Relevance: 6.1, APIs: 4, Instructions: 54COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DC2AE7 Relevance: 6.1, APIs: 4, Instructions: 51memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DE16F6 Relevance: 6.0, APIs: 4, Instructions: 45COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DEC0B5 Relevance: 6.0, APIs: 4, Instructions: 44threadCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DEBCE6 Relevance: 6.0, APIs: 4, Instructions: 44threadCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DE3106 Relevance: 6.0, APIs: 4, Instructions: 38memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E3310F Relevance: 6.0, APIs: 4, Instructions: 32COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DCA6CD Relevance: 6.0, APIs: 4, Instructions: 30serviceCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DC1B17 Relevance: 6.0, APIs: 4, Instructions: 28COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DED7BB Relevance: 6.0, APIs: 4, Instructions: 25COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E24B6B Relevance: 5.6, APIs: 2, Strings: 1, Instructions: 306COMMONLIBRARYCODE
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DF2EC5 Relevance: 5.4, APIs: 1, Strings: 2, Instructions: 112COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DF5615 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 93COMMONLIBRARYCODE
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DF5722 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 90COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DF697D Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 72COMMONLIBRARYCODE
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DF81AD Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 66COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DEDD31 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 59COMMONLIBRARYCODE
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DCC17D Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 32registryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DCCCB2 Relevance: 5.0, APIs: 4, Instructions: 45stringCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|