Windows
Analysis Report
WWAddToLocalAdmins.exe
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- WWAddToLocalAdmins.exe (PID: 2408 cmdline:
"C:\Users\ user\Deskt op\WWAddTo LocalAdmin s.exe" MD5: CD54D0F310489D1CDCEC2692CF9EF236) - conhost.exe (PID: 5384 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - cscript.exe (PID: 1848 cmdline:
"C:\Window s\system32 \CScript.e xe" //noLo go C:\Temp \60875D.vb s MD5: CB601B41D4C8074BE8A84AED564A94DC)
- cleanup
Source: | Author: Michael Haag: |
Click to jump to signature section
AV Detection |
---|
Source: | ReversingLabs: |
Source: | Static PE information: |
Source: | Code function: | 0_2_00401467 |
Source: | Code function: | 0_2_00402757 | |
Source: | Code function: | 0_2_00408917 | |
Source: | Code function: | 0_2_004037C1 | |
Source: | Code function: | 0_2_00404DDD | |
Source: | Code function: | 0_2_00402FBA |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_00401467 |
Source: | Code function: | 0_2_00401467 |
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Process created: |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Code function: | 0_2_00401C42 |
Source: | Code function: | 0_2_004060EE |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Decision node followed by non-executed suspicious API: | graph_0-6040 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 0_2_00407B44 |
Source: | Code function: | 0_2_00401C42 |
Source: | Code function: | 0_2_00401467 |
Source: | Process created: | Jump to behavior |
Source: | Code function: | 0_2_00401467 |
Source: | Key value queried: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | 2 Valid Accounts | 1 Native API | 2 Valid Accounts | 2 Valid Accounts | 2 Valid Accounts | OS Credential Dumping | 1 Security Software Discovery | Remote Services | 1 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Scripting | 2 Access Token Manipulation | 2 Access Token Manipulation | LSASS Memory | 3 System Information Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 1 DLL Side-Loading | 11 Process Injection | 11 Process Injection | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 1 DLL Side-Loading | 1 DLL Side-Loading | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Obfuscated Files or Information | LSA Secrets | Internet Connection Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
17% | ReversingLabs |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1544497 |
Start date and time: | 2024-10-29 14:07:01 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 4s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 6 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | WWAddToLocalAdmins.exe |
Detection: | MAL |
Classification: | mal48.winEXE@4/3@0/0 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: WWAddToLocalAdmins.exe
Process: | C:\Users\user\Desktop\WWAddToLocalAdmins.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2611 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:v//////////////////////////////////////////////////////////////X:P |
MD5: | 7DBE7E58FF8EE7A504F65B2EB0CE7E68 |
SHA1: | A862D6B97147B26F28634606DA26658CF308BFA7 |
SHA-256: | 5048D4CEE2439D67EE5BB920C974A27EC39CEB6F4401BC509114510D85F735E7 |
SHA-512: | 197B4977BE912125FB343C12755E478ACA4E70EDBFAA7E6F472E42E5058927EC18BAF99AC0D973D9AD3B3103941E48488F8CB86CFFE6CD7E605835C8E41ACA16 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\SysWOW64\cscript.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 3.545063206984032 |
Encrypted: | false |
SSDEEP: | 3:5cl115lll55I2Y1AnWSgll//8lLn:Cl11sGWJltMLn |
MD5: | A512AF01F8D61D059A2D7BA9CD9DE5DD |
SHA1: | 14016E22BA3F95C5B981AB14BC7DDE8E9F2F8BED |
SHA-256: | 46BA59EFD5A050C1AE1841E73158FC85D997307553936C1412D212FCD52D1C76 |
SHA-512: | 86548C3C9F6134BFB55F08DA330DEBA82AA35DF5F70BCAFDB3009BEB0608E4C787F7116A68B5CA8C3B844D13D4F97637D02B3F51C0087852229B78BCA15C485A |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\SysWOW64\cscript.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 3.7249034414266404 |
Encrypted: | false |
SSDEEP: | 3:5cl115lll55I2Y1AnJjUSRPlslLn:Cl11sGm1Ln |
MD5: | 435F9258D5A586F18107CD87EE1B3B2E |
SHA1: | 8E1943296338E330E9C8D5D98A93E59025195E37 |
SHA-256: | D18141FAA09D353285AEB932775DF94EC72D4C3F950C057FDB18CE79414DD622 |
SHA-512: | 9EA0505B09A418E50C4FE345E4F7AECCE5760E6E91C74E8186DF746BC0C1252B31B224E315D6FA5129AAD4B998D06FE45347F6D450A357DF8D273CC3CE3E490A |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 5.6126558170625005 |
TrID: |
|
File name: | WWAddToLocalAdmins.exe |
File size: | 90'112 bytes |
MD5: | cd54d0f310489d1cdcec2692cf9ef236 |
SHA1: | 18b7ade73903e3562d3989515e6a5ebdbb21e058 |
SHA256: | 291b83adc7d7d4bc86ddc24c75a26fd2c4d740a432da8d4cbf2b9e2fc4b517c4 |
SHA512: | f5b51b42cf57ccc1dce94739e1f727b16c51e0b29c575ea514e338f2fab8c8f022bbceac261aac5d50e0ccafa57f700b9d6339c230d0aa2b83b2476d9e2de1c2 |
SSDEEP: | 1536:Qpgvvf/afJnTsK8W1tBq5eGWclBjleBKBw/C:vvn/6wwt3hclBhX |
TLSH: | 6F938C13B9D0CA7ED5B04232E8904BF26B79FE31E1695887A7487CC93D32594932739B |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........<..do..do..do..ho..doF.jo..do..no..doF.9o..do..eo..do..oo..do..bo..doRich..do................PE..L...uhNE................... |
Icon Hash: | 49033b1f17170d01 |
Entrypoint: | 0x40689e |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows cui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE |
DLL Characteristics: | |
Time Stamp: | 0x454E6875 [Sun Nov 5 22:40:53 2006 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | 9ee1751483a7b7cb180cbb92cd46f3cc |
Instruction |
---|
push ebp |
mov ebp, esp |
push FFFFFFFFh |
push 0040D950h |
push 00409F30h |
mov eax, dword ptr fs:[00000000h] |
push eax |
mov dword ptr fs:[00000000h], esp |
sub esp, 10h |
push ebx |
push esi |
push edi |
mov dword ptr [ebp-18h], esp |
call dword ptr [0040C0C4h] |
xor edx, edx |
mov dl, ah |
mov dword ptr [00412210h], edx |
mov ecx, eax |
and ecx, 000000FFh |
mov dword ptr [0041220Ch], ecx |
shl ecx, 08h |
add ecx, edx |
mov dword ptr [00412208h], ecx |
shr eax, 10h |
mov dword ptr [00412204h], eax |
push 00000000h |
call 00007F295D0B7B72h |
pop ecx |
test eax, eax |
jne 00007F295D0B640Ah |
push 0000001Ch |
call 00007F295D0B649Fh |
pop ecx |
and dword ptr [ebp-04h], 00000000h |
call 00007F295D0B9780h |
call dword ptr [0040C0C0h] |
mov dword ptr [00413764h], eax |
call 00007F295D0B963Eh |
mov dword ptr [0041226Ch], eax |
call 00007F295D0B93E7h |
call 00007F295D0B9329h |
call 00007F295D0B5916h |
mov eax, dword ptr [00412220h] |
mov dword ptr [00412224h], eax |
push eax |
push dword ptr [00412218h] |
push dword ptr [00412214h] |
call 00007F295D0B0AB3h |
add esp, 0Ch |
mov dword ptr [ebp-1Ch], eax |
push eax |
call 00007F295D0B591Bh |
mov eax, dword ptr [ebp-14h] |
mov ecx, dword ptr [eax] |
mov ecx, dword ptr [ecx] |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xdd78 | 0x50 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x14000 | 0x3fc0 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0xc000 | 0x14c | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0xafc7 | 0xb000 | 5dec2932e9370d540d41369bf4fc5305 | False | 0.6299493963068182 | data | 6.635325183892252 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0xc000 | 0x24c6 | 0x3000 | 0d6280f6031e8522806e3c860459b92f | False | 0.3296712239583333 | data | 3.847678121234383 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0xf000 | 0x477c | 0x3000 | 0ea8fb085d66882d27ec5e633512752c | False | 0.10400390625 | data | 1.3123505764154129 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x14000 | 0x3fc0 | 0x4000 | d8de76a0b21f87ec7f5741ae5ec431c0 | False | 0.42315673828125 | data | 5.058362822093357 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0x14178 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | 0.28921161825726144 | ||
RT_ICON | 0x16720 | 0xca8 | Device independent bitmap graphic, 32 x 64 x 24, image size 3200 | 0.6185185185185185 | ||
RT_ICON | 0x173c8 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | 0.6897163120567376 | ||
RT_RCDATA | 0x17830 | 0x320 | data | 0.0475 | ||
RT_RCDATA | 0x17b50 | 0x43e | data | 1.0101289134438305 | ||
RT_GROUP_ICON | 0x17f90 | 0x30 | data | 0.9166666666666666 |
DLL | Import |
---|---|
KERNEL32.dll | GetWindowsDirectoryA, LockResource, LoadResource, FindResourceA, SizeofResource, CreateProcessA, FormatMessageA, GetLastError, Sleep, GetExitCodeProcess, SetFileAttributesA, GetFileAttributesA, GetTickCount, GetVersionExA, FreeLibrary, MultiByteToWideChar, lstrlenA, GetProcAddress, GetSystemDirectoryA, WinExec, RemoveDirectoryA, DeleteFileA, SetFilePointer, GetFileType, DuplicateHandle, GetCurrentProcess, CreateFileA, CloseHandle, ReadFile, SystemTimeToFileTime, DosDateTimeToFileTime, CreateDirectoryA, SetFileTime, WriteFile, SetEnvironmentVariableA, CompareStringW, GetTempPathA, GetModuleHandleA, SetCurrentDirectoryA, GetCurrentDirectoryA, LoadLibraryA, ExitProcess, TerminateProcess, HeapAlloc, HeapFree, GetCommandLineA, GetVersion, WideCharToMultiByte, LCMapStringA, LCMapStringW, GetFullPathNameA, GetModuleFileNameA, GetEnvironmentVariableA, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, HeapReAlloc, GetCPInfo, GetACP, GetOEMCP, UnhandledExceptionFilter, FreeEnvironmentStringsA, FreeEnvironmentStringsW, GetEnvironmentStrings, GetEnvironmentStringsW, SetHandleCount, GetStdHandle, GetStartupInfoA, RtlUnwind, GetStringTypeA, GetStringTypeW, GetDriveTypeA, SetStdHandle, FlushFileBuffers, CompareStringA, SetEndOfFile |
USER32.dll | PostQuitMessage |
ADVAPI32.dll | LogonUserA, CreateProcessAsUserA |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 09:07:53 |
Start date: | 29/10/2024 |
Path: | C:\Users\user\Desktop\WWAddToLocalAdmins.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 90'112 bytes |
MD5 hash: | CD54D0F310489D1CDCEC2692CF9EF236 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 09:07:53 |
Start date: | 29/10/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 09:07:53 |
Start date: | 29/10/2024 |
Path: | C:\Windows\SysWOW64\cscript.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xc60000 |
File size: | 144'896 bytes |
MD5 hash: | CB601B41D4C8074BE8A84AED564A94DC |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Execution Graph
Execution Coverage: | 11.3% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 8.7% |
Total number of Nodes: | 1121 |
Total number of Limit Nodes: | 9 |
Graph
Function 00401467 Relevance: 74.0, APIs: 27, Strings: 15, Instructions: 475sleepwindowprocessCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407B44 Relevance: 6.1, APIs: 4, Instructions: 139fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040B257 Relevance: 13.7, APIs: 9, Instructions: 221COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040A977 Relevance: 10.7, APIs: 4, Strings: 2, Instructions: 230fileCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00409C8D Relevance: 7.6, APIs: 5, Instructions: 143COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040A1BA Relevance: 3.1, APIs: 2, Instructions: 51COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408069 Relevance: 3.0, APIs: 2, Instructions: 30memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405C25 Relevance: 3.0, APIs: 2, Instructions: 19COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004060EF Relevance: 3.0, APIs: 2, Instructions: 17COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407959 Relevance: 2.6, APIs: 2, Instructions: 66COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004096D1 Relevance: 1.6, APIs: 1, Instructions: 89COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406355 Relevance: 1.6, APIs: 1, Instructions: 72memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406532 Relevance: 1.5, APIs: 1, Instructions: 46memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004010B6 Relevance: 1.5, APIs: 1, Instructions: 8windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401C42 Relevance: 19.3, APIs: 6, Strings: 5, Instructions: 73libraryprocessloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402757 Relevance: .7, Instructions: 681COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402FBA Relevance: .3, Instructions: 333COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408917 Relevance: .3, Instructions: 259COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004037C1 Relevance: .1, Instructions: 104COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401A85 Relevance: 28.2, APIs: 13, Strings: 3, Instructions: 180libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040B1C5 Relevance: 14.0, APIs: 4, Strings: 4, Instructions: 50libraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406CC5 Relevance: 13.7, APIs: 9, Instructions: 177COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040A041 Relevance: 12.4, APIs: 3, Strings: 4, Instructions: 100fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040A2F0 Relevance: 9.1, APIs: 6, Instructions: 117COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403EBF Relevance: 9.1, APIs: 6, Instructions: 104fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040BA81 Relevance: 6.5, APIs: 5, Instructions: 246COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408C0D Relevance: 6.4, APIs: 5, Instructions: 102memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408139 Relevance: 6.3, APIs: 3, Strings: 1, Instructions: 265memoryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040B88B Relevance: 6.2, APIs: 4, Instructions: 174fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040B412 Relevance: 6.1, APIs: 4, Instructions: 67COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040876B Relevance: 5.1, APIs: 4, Instructions: 53memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|