Windows
Analysis Report
file.exe
Overview
General Information
Detection
Score: | 84 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- file.exe (PID: 2872 cmdline:
"C:\Users\ user\Deskt op\file.ex e" MD5: E2F4A20BF1778DDB6396F48F6F4A9A32)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Lumma Stealer, LummaC2 Stealer | Lumma Stealer (aka LummaC2 Stealer) is an information stealer written in C language that has been available through a Malware-as-a-Service (MaaS) model on Russian-speaking forums since at least August 2022. It is believed to have been developed by the threat actor "Shamel", who goes by the alias "Lumma". Lumma Stealer primarily targets cryptocurrency wallets and two-factor authentication (2FA) browser extensions, before ultimately stealing sensitive information from the victim's machine. Once the targeted data is obtained, it is exfiltrated to a C2 server via HTTP POST requests using the user agent "TeslaBrowser/5.5"." The stealer also features a non-resident loader that is capable of delivering additional payloads via EXE, DLL, and PowerShell. | No Attribution |
{"C2 url": ["contemteny.site", "goalyfeastz.site", "servicedny.site", "seallysl.site", "opposezmny.site", "authorisev.site", "dilemmadu.site", "faulteyotk.site"], "Build id": "2Zo0RN--PRIVATE"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_LummaCStealer_2 | Yara detected LummaC Stealer | Joe Security |
Click to jump to signature section
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Code function: | 0_2_005941F0 | |
Source: | Code function: | 0_2_0059137E | |
Source: | Code function: | 0_2_005913D5 | |
Source: | Code function: | 0_2_0057E870 | |
Source: | Code function: | 0_2_00555820 | |
Source: | Code function: | 0_2_0055E8DE | |
Source: | Code function: | 0_2_0056C8CE | |
Source: | Code function: | 0_2_0058A97E | |
Source: | Code function: | 0_2_0058A97E | |
Source: | Code function: | 0_2_0058A97E | |
Source: | Code function: | 0_2_0058B170 | |
Source: | Code function: | 0_2_0055C960 | |
Source: | Code function: | 0_2_00560118 | |
Source: | Code function: | 0_2_00560118 | |
Source: | Code function: | 0_2_00560118 | |
Source: | Code function: | 0_2_00560118 | |
Source: | Code function: | 0_2_00560118 | |
Source: | Code function: | 0_2_00560130 | |
Source: | Code function: | 0_2_00560130 | |
Source: | Code function: | 0_2_00560130 | |
Source: | Code function: | 0_2_00560130 | |
Source: | Code function: | 0_2_00560130 | |
Source: | Code function: | 0_2_005931D0 | |
Source: | Code function: | 0_2_005931D0 | |
Source: | Code function: | 0_2_005741E0 | |
Source: | Code function: | 0_2_0055E996 | |
Source: | Code function: | 0_2_0057AA40 | |
Source: | Code function: | 0_2_0057CA72 | |
Source: | Code function: | 0_2_0057CA72 | |
Source: | Code function: | 0_2_0057AA60 | |
Source: | Code function: | 0_2_005512D5 | |
Source: | Code function: | 0_2_0058FAD0 | |
Source: | Code function: | 0_2_005932C0 | |
Source: | Code function: | 0_2_005932C0 | |
Source: | Code function: | 0_2_00571B40 | |
Source: | Code function: | 0_2_0057EB60 | |
Source: | Code function: | 0_2_0057EB60 | |
Source: | Code function: | 0_2_0057EB60 | |
Source: | Code function: | 0_2_0057EB60 | |
Source: | Code function: | 0_2_0057EB60 | |
Source: | Code function: | 0_2_0057EB60 | |
Source: | Code function: | 0_2_0057EB60 | |
Source: | Code function: | 0_2_00571333 | |
Source: | Code function: | 0_2_00594380 | |
Source: | Code function: | 0_2_005933B0 | |
Source: | Code function: | 0_2_005933B0 | |
Source: | Code function: | 0_2_0057AC04 | |
Source: | Code function: | 0_2_0057E400 | |
Source: | Code function: | 0_2_0056ECDE | |
Source: | Code function: | 0_2_00587CA0 | |
Source: | Code function: | 0_2_0056F510 | |
Source: | Code function: | 0_2_0056F510 | |
Source: | Code function: | 0_2_0055D500 | |
Source: | Code function: | 0_2_0056D5AF | |
Source: | Code function: | 0_2_00591648 | |
Source: | Code function: | 0_2_0057DE70 | |
Source: | Code function: | 0_2_00590E3A | |
Source: | Code function: | 0_2_0058C6D0 | |
Source: | Code function: | 0_2_0057CEDA | |
Source: | Code function: | 0_2_0056C6E0 | |
Source: | Code function: | 0_2_00592EB0 | |
Source: | Code function: | 0_2_00592EB0 | |
Source: | Code function: | 0_2_00575F00 | |
Source: | Code function: | 0_2_00578F00 | |
Source: | Code function: | 0_2_00593720 | |
Source: | Code function: | 0_2_00591720 | |
Source: | Code function: | 0_2_0058F7E0 |
Networking |
---|
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: |
Source: | Code function: | 0_2_00585210 |
Source: | Code function: | 0_2_00585210 |
Source: | Code function: | 0_2_005859B7 |
Source: | Code function: | 0_2_005886FE | |
Source: | Code function: | 0_2_00592850 | |
Source: | Code function: | 0_2_00551000 | |
Source: | Code function: | 0_2_00576800 | |
Source: | Code function: | 0_2_0056482A | |
Source: | Code function: | 0_2_005600C5 | |
Source: | Code function: | 0_2_005538E0 | |
Source: | Code function: | 0_2_0057509D | |
Source: | Code function: | 0_2_00589940 | |
Source: | Code function: | 0_2_0055F970 | |
Source: | Code function: | 0_2_0058A97E | |
Source: | Code function: | 0_2_00557960 | |
Source: | Code function: | 0_2_00560118 | |
Source: | Code function: | 0_2_00560130 | |
Source: | Code function: | 0_2_00594920 | |
Source: | Code function: | 0_2_005831DE | |
Source: | Code function: | 0_2_005931D0 | |
Source: | Code function: | 0_2_005741E0 | |
Source: | Code function: | 0_2_005791E0 | |
Source: | Code function: | 0_2_00581980 | |
Source: | Code function: | 0_2_0055F250 | |
Source: | Code function: | 0_2_0057AA40 | |
Source: | Code function: | 0_2_0055A270 | |
Source: | Code function: | 0_2_0057CA72 | |
Source: | Code function: | 0_2_0055B260 | |
Source: | Code function: | 0_2_0058E230 | |
Source: | Code function: | 0_2_00570A24 | |
Source: | Code function: | 0_2_005512D5 | |
Source: | Code function: | 0_2_005932C0 | |
Source: | Code function: | 0_2_0058A2E0 | |
Source: | Code function: | 0_2_0056E298 | |
Source: | Code function: | 0_2_00571B40 | |
Source: | Code function: | 0_2_0057EB60 | |
Source: | Code function: | 0_2_0055DB20 | |
Source: | Code function: | 0_2_0055132D | |
Source: | Code function: | 0_2_00565BD8 | |
Source: | Code function: | 0_2_0057C3E0 | |
Source: | Code function: | 0_2_00592380 | |
Source: | Code function: | 0_2_005933B0 | |
Source: | Code function: | 0_2_00589BA0 | |
Source: | Code function: | 0_2_00594C50 | |
Source: | Code function: | 0_2_00584C60 | |
Source: | Code function: | 0_2_0057AC04 | |
Source: | Code function: | 0_2_0058EC20 | |
Source: | Code function: | 0_2_00577CD2 | |
Source: | Code function: | 0_2_0056ECDE | |
Source: | Code function: | 0_2_0055ECC0 | |
Source: | Code function: | 0_2_00579494 | |
Source: | Code function: | 0_2_005594BF | |
Source: | Code function: | 0_2_0055BD70 | |
Source: | Code function: | 0_2_0056F510 | |
Source: | Code function: | 0_2_00579D00 | |
Source: | Code function: | 0_2_0055ADD0 | |
Source: | Code function: | 0_2_00582D80 | |
Source: | Code function: | 0_2_005835B0 | |
Source: | Code function: | 0_2_005755A4 | |
Source: | Code function: | 0_2_00558DA0 | |
Source: | Code function: | 0_2_0056D5AF | |
Source: | Code function: | 0_2_00572E50 | |
Source: | Code function: | 0_2_0057D642 | |
Source: | Code function: | 0_2_0057BE10 | |
Source: | Code function: | 0_2_00594620 | |
Source: | Code function: | 0_2_0057762D | |
Source: | Code function: | 0_2_0057A6D0 | |
Source: | Code function: | 0_2_00592EB0 | |
Source: | Code function: | 0_2_005726A0 | |
Source: | Code function: | 0_2_0057762D | |
Source: | Code function: | 0_2_0055D760 | |
Source: | Code function: | 0_2_00556F60 | |
Source: | Code function: | 0_2_00578F00 | |
Source: | Code function: | 0_2_00579494 | |
Source: | Code function: | 0_2_00593720 | |
Source: | Code function: | 0_2_00591720 | |
Source: | Code function: | 0_2_00558DA0 | |
Source: | Code function: | 0_2_0057B7D9 | |
Source: | Code function: | 0_2_0057B7FE | |
Source: | Code function: | 0_2_00559F9C | |
Source: | Code function: | 0_2_00576F82 | |
Source: | Code function: | 0_2_00584F80 | |
Source: | Code function: | 0_2_00591F80 | |
Source: | Code function: | 0_2_00554FA0 | |
Source: | Code function: | 0_2_00559FA8 |
Source: | Code function: | ||
Source: | Code function: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_00582088 |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Section loaded: | Jump to behavior |
Source: | Static PE information: |
Source: | API coverage: |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | API call chain: | graph_0-15582 |
Source: | Code function: | 0_2_00590D90 |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Stealing of Sensitive Information |
---|
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 PowerShell | 1 DLL Side-Loading | 1 DLL Side-Loading | 11 Deobfuscate/Decode Files or Information | OS Credential Dumping | 2 System Information Discovery | Remote Services | 1 Screen Capture | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | 1 Archive Collected Data | 1 Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 2 Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | 2 Clipboard Data | Steganography | Automated Exfiltration | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
45% | ReversingLabs | Win32.Trojan.MintZard | ||
100% | Joe Sandbox ML |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown | ||
true | unknown | ||
true | unknown | ||
true | unknown | ||
true | unknown | ||
true | unknown | ||
true | unknown | ||
true | unknown |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1545304 |
Start date and time: | 2024-10-30 11:46:06 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 3s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 5 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | file.exe |
Detection: | MAL |
Classification: | mal84.troj.evad.winEXE@1/0@0/0 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, d.4.1.9.1.6.7.1.0.0.0.0.0.0.0.0.1.0.0.9.0.0.1.f.1.1.1.0.1.0.a.2.ip6.arpa, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: file.exe
File type: | |
Entropy (8bit): | 6.7615707075 |
TrID: |
|
File name: | file.exe |
File size: | 334'848 bytes |
MD5: | e2f4a20bf1778ddb6396f48f6f4a9a32 |
SHA1: | 75d402e0a8645b0a33f93ed6a66f76fe22496987 |
SHA256: | a76920b863ff403f08436950963f30333e7b9297d36f2cec8e26bd94d66c8f1a |
SHA512: | 13fd064e04d302471ab5ad28ed9e3a07ead4429046054ae4f7931bd2d24678857e0ae3a48ab0888da313e9ba320d3e73fe358cfc8c82796fceba7b31440c4126 |
SSDEEP: | 6144:+tWC7xvtddofKKrybbuMY88Jc/oZ3ipoOvYcOCL7E6tt7t2lp4:+RZtddofKKrzHPJ3ii0bL7E6t7S2 |
TLSH: | E2649D09EB7381B1CC46847871DEB37F8A386B1547389FD7DB90DF8429636D2583AA06 |
File Content Preview: | MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L......g.................D........................@.......................................@.................................R...... |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x40d0b0 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x6715CDA7 [Mon Oct 21 03:42:31 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 6 |
OS Version Minor: | 0 |
File Version Major: | 6 |
File Version Minor: | 0 |
Subsystem Version Major: | 6 |
Subsystem Version Minor: | 0 |
Import Hash: | f5ad7569262698fb9eae9f54a4af280c |
Instruction |
---|
push edi |
push esi |
sub esp, 2Ch |
mov dword ptr [esp], 710E3123h |
xor eax, eax |
nop |
nop |
mov ecx, eax |
add cl, 0000003Dh |
xor cl, byte ptr [esp+eax] |
add cl, FFFFFFCFh |
mov byte ptr [esp+eax], cl |
inc eax |
cmp eax, 04h |
jne 00007FB2D881972Eh |
mov esi, dword ptr [esp] |
call 00007FB2D884C139h |
test al, al |
je 00007FB2D88198D9h |
call 00007FB2D884438Ch |
test al, al |
je 00007FB2D88198C7h |
mov ecx, esi |
and ecx, 34A7AD07h |
mov edx, esi |
mov eax, esi |
or esi, 34A7AD07h |
imul esi, ecx |
xor ecx, 34A7AD07h |
and edx, CB5852F8h |
lea edi, dword ptr [00000002h+edx*2] |
sub edi, edx |
add edi, FFFFFFFEh |
or eax, CB5852F8h |
mov edx, edi |
and edx, eax |
or eax, edi |
not eax |
imul eax, edx |
mov edx, edi |
and edx, ecx |
or edi, ecx |
imul edi, edx |
add esi, edi |
add esi, eax |
mov edi, esi |
shr edi, 07h |
xor edi, esi |
mov eax, edi |
and eax, F5AE3701h |
mov ecx, edi |
and ecx, 0A51C8FEh |
or edi, 0A51C8FEh |
imul edi, ecx |
xor ecx, 0A51C8FEh |
imul ecx, eax |
add edi, ecx |
call dword ptr [004481ACh] |
mov dword ptr [esp], F9814689h |
mov word ptr [esp+04h], 0000h |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x48052 | 0x8c | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x59000 | 0x4b80 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x4819c | 0xbc | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x442b8 | 0x44400 | 44608c6e2848810b5efa0e9a7b922cd9 | False | 0.5487315418956044 | data | 6.601624760368542 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x46000 | 0x2527 | 0x2600 | f56a63840f9b0722ee007c6b90252d24 | False | 0.4369860197368421 | data | 6.454837802198663 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x49000 | 0xf518 | 0x6200 | b0266cc045a35151394b57109c20c9e2 | False | 0.49960140306122447 | data | 6.15803565276463 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.reloc | 0x59000 | 0x4b80 | 0x4c00 | 1a6e4bcb7a19a779e696996fffb94813 | False | 0.43770559210526316 | data | 6.457467952497308 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
DLL | Import |
---|---|
KERNEL32.dll | CopyFileW, ExitProcess, GetCommandLineW, GetCurrentProcessId, GetCurrentThreadId, GetLogicalDrives, GetSystemDirectoryW, GlobalLock, GlobalUnlock |
SHELL32.dll | ShellExecuteW |
USER32.dll | CloseClipboard, FindWindowExW, GetClipboardData, GetDC, GetForegroundWindow, GetSystemMetrics, GetWindowLongW, GetWindowThreadProcessId, IsWindowEnabled, IsWindowVisible, OpenClipboard, ReleaseDC |
ole32.dll | CoCreateInstance, CoInitialize, CoInitializeSecurity, CoSetProxyBlanket, CoUninitialize |
OLEAUT32.dll | SysAllocString, SysFreeString, VariantClear, VariantInit |
GDI32.dll | BitBlt, CreateCompatibleBitmap, CreateCompatibleDC, DeleteDC, DeleteObject, GetCurrentObject, GetDIBits, GetObjectW, SelectObject, StretchBlt |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 30, 2024 11:47:44.279051065 CET | 53 | 59007 | 162.159.36.2 | 192.168.2.4 |
Oct 30, 2024 11:47:44.918107986 CET | 53 | 60915 | 1.1.1.1 | 192.168.2.4 |
Target ID: | 0 |
Start time: | 06:46:56 |
Start date: | 30/10/2024 |
Path: | C:\Users\user\Desktop\file.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x550000 |
File size: | 334'848 bytes |
MD5 hash: | E2F4A20BF1778DDB6396F48F6F4A9A32 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 1.1% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 36.7% |
Total number of Nodes: | 49 |
Total number of Limit Nodes: | 3 |
Graph
Function 005886FE Relevance: 66.6, Strings: 53, Instructions: 390COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00590D90 Relevance: 1.5, APIs: 1, Instructions: 14libraryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005941F0 Relevance: .2, Instructions: 157COMMON
Control-flow Graph
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005913D5 Relevance: .1, Instructions: 102COMMON
Control-flow Graph
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0059137E Relevance: .1, Instructions: 57COMMON
Control-flow Graph
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0055D0B0 Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 142threadCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00590F68 Relevance: 1.5, APIs: 1, Instructions: 18COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0058DC18 Relevance: 1.5, APIs: 1, Instructions: 11memoryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00585210 Relevance: 31.6, APIs: 6, Strings: 12, Instructions: 120clipboardCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00577CD2 Relevance: 30.7, Strings: 24, Instructions: 728COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0056F510 Relevance: 24.0, Strings: 18, Instructions: 1543COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0058A97E Relevance: 19.8, APIs: 9, Strings: 2, Instructions: 587memoryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00589BA0 Relevance: 17.8, Strings: 14, Instructions: 304COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005512D5 Relevance: 16.0, Strings: 12, Instructions: 987COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0055F970 Relevance: 15.3, Strings: 12, Instructions: 280COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00551000 Relevance: 13.2, Strings: 10, Instructions: 702COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0058A2E0 Relevance: 11.6, Strings: 9, Instructions: 302COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0055D760 Relevance: 10.3, Strings: 8, Instructions: 302COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0055D500 Relevance: 10.2, Strings: 8, Instructions: 218COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0055F250 Relevance: 9.2, Strings: 7, Instructions: 471COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00570A24 Relevance: 8.0, Strings: 6, Instructions: 505COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0055DB20 Relevance: 7.9, Strings: 6, Instructions: 361COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0058EC20 Relevance: 7.0, Strings: 5, Instructions: 723COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005741E0 Relevance: 6.7, Strings: 5, Instructions: 461COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0055ECC0 Relevance: 6.7, Strings: 5, Instructions: 426COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00579D00 Relevance: 6.7, Strings: 5, Instructions: 405COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0057509D Relevance: 6.4, Strings: 5, Instructions: 163COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005755A4 Relevance: 6.4, Strings: 5, Instructions: 157COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0056E298 Relevance: 6.3, APIs: 4, Instructions: 347COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00578F00 Relevance: 5.5, Strings: 4, Instructions: 489COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0055132D Relevance: 5.4, Strings: 4, Instructions: 388COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0057D642 Relevance: 5.3, Strings: 4, Instructions: 333COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00592EB0 Relevance: 4.8, Strings: 3, Instructions: 1010COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005931D0 Relevance: 4.4, Strings: 3, Instructions: 680COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00571B40 Relevance: 4.4, Strings: 3, Instructions: 657COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005932C0 Relevance: 4.4, Strings: 3, Instructions: 637COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0057AC04 Relevance: 4.3, Strings: 3, Instructions: 578COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00592850 Relevance: 4.2, Strings: 3, Instructions: 475COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0056D5AF Relevance: 4.2, Strings: 3, Instructions: 404COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0057C3E0 Relevance: 4.0, Strings: 3, Instructions: 221COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0055E8DE Relevance: 3.8, Strings: 3, Instructions: 51COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0055E996 Relevance: 3.8, Strings: 3, Instructions: 25COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0057B7D9 Relevance: 3.2, Strings: 2, Instructions: 674COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0057B7FE Relevance: 3.1, Strings: 2, Instructions: 613COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005726A0 Relevance: 3.0, Strings: 2, Instructions: 480COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005538E0 Relevance: 2.9, Strings: 2, Instructions: 404COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0057A6D0 Relevance: 2.8, Strings: 2, Instructions: 324COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005594BF Relevance: 2.8, Strings: 2, Instructions: 305COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005600C5 Relevance: 2.7, Strings: 2, Instructions: 198COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005933B0 Relevance: 1.8, Strings: 1, Instructions: 572COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00554FA0 Relevance: 1.8, Strings: 1, Instructions: 514COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00575F00 Relevance: 1.8, APIs: 1, Instructions: 251comCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0057E400 Relevance: 1.6, Strings: 1, Instructions: 382COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00592380 Relevance: 1.6, Strings: 1, Instructions: 344COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005835B0 Relevance: 1.6, Strings: 1, Instructions: 320COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00571333 Relevance: 1.5, Strings: 1, Instructions: 288COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0058F7E0 Relevance: 1.5, Strings: 1, Instructions: 259COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0057E870 Relevance: 1.5, Strings: 1, Instructions: 236COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0058E230 Relevance: 1.5, Strings: 1, Instructions: 231COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0056482A Relevance: 1.4, Strings: 1, Instructions: 140COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0057CEDA Relevance: 1.3, Strings: 1, Instructions: 67COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0055BD70 Relevance: .8, Instructions: 830COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0055B260 Relevance: .7, Instructions: 670COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00556F60 Relevance: .7, Instructions: 657COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00572E50 Relevance: .7, Instructions: 655COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00557960 Relevance: .6, Instructions: 611COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00591720 Relevance: .5, Instructions: 497COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0055A270 Relevance: .4, Instructions: 399COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00579494 Relevance: .4, Instructions: 390COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00593720 Relevance: .3, Instructions: 334COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00591F80 Relevance: .3, Instructions: 334COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0057CA72 Relevance: .3, Instructions: 318COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00594C50 Relevance: .3, Instructions: 311COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0055ADD0 Relevance: .3, Instructions: 303COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00594920 Relevance: .3, Instructions: 301COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00594620 Relevance: .3, Instructions: 298COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00584C60 Relevance: .3, Instructions: 283COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00581980 Relevance: .3, Instructions: 277COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00582D80 Relevance: .3, Instructions: 259COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005831DE Relevance: .3, Instructions: 258COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00565BD8 Relevance: .2, Instructions: 234COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00584F80 Relevance: .2, Instructions: 230COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00558DA0 Relevance: .2, Instructions: 223COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0057BE10 Relevance: .2, Instructions: 208COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00589940 Relevance: .2, Instructions: 189COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0057762D Relevance: .2, Instructions: 170COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00555820 Relevance: .2, Instructions: 163COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005791E0 Relevance: .2, Instructions: 159COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00594380 Relevance: .2, Instructions: 154COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0058B170 Relevance: .1, Instructions: 142COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0056C6E0 Relevance: .1, Instructions: 128COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0055C960 Relevance: .1, Instructions: 106COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0056C8CE Relevance: .1, Instructions: 94COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00559F9C Relevance: .1, Instructions: 66COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00587CA0 Relevance: .1, Instructions: 64COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00590E3A Relevance: .1, Instructions: 64COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00559FA8 Relevance: .1, Instructions: 64COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0057DE70 Relevance: .1, Instructions: 63COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0058FAD0 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00582088 Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0057AA60 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00591648 Relevance: .0, Instructions: 25COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0058C6D0 Relevance: .0, Instructions: 21COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005844AC Relevance: 52.7, APIs: 1, Strings: 29, Instructions: 163memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0056CBE6 Relevance: 5.5, APIs: 1, Strings: 2, Instructions: 273threadCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|