Windows
Analysis Report
disk-io.exe
Overview
General Information
Detection
Score: | 2 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 60% |
Signatures
Classification
- System is w10x64
- disk-io.exe (PID: 7052 cmdline:
"C:\Users\ user\Deskt op\disk-io .exe" MD5: DEBD16861B6996FEA26C7573FE5F8458) - conhost.exe (PID: 7076 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | Static PE information: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Static PE information: |
Source: | Binary string: |
Source: | Classification label: |
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Last function: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 2 Command and Scripting Interpreter | 1 DLL Side-Loading | 1 Process Injection | 1 Process Injection | OS Credential Dumping | 1 Security Software Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 1 DLL Side-Loading | LSASS Memory | 1 System Information Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1571440 |
Start date and time: | 2024-12-09 11:47:35 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 29s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 6 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | disk-io.exe |
Detection: | CLEAN |
Classification: | clean2.winEXE@2/0@0/0 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: disk-io.exe
File type: | |
Entropy (8bit): | 6.2148293171055515 |
TrID: |
|
File name: | disk-io.exe |
File size: | 30'182'912 bytes |
MD5: | debd16861b6996fea26c7573fe5f8458 |
SHA1: | 30a964aacf1e5b9b2d3a56f7afdad874b8efc0e8 |
SHA256: | 2293ffbbadadb3c8b2657312bd7bb1dbad648663f1b1fc6be41b295756c834a6 |
SHA512: | 347b04e6fac3ca4acb6ad74191564830ffc5ff92ea817348cadc29bef24ec332e2d39c5873b001e6d22d8cf148414a179396cd3d278732134219782da3e9400d |
SSDEEP: | 98304:IywwzwVmAsZkveIz+CVKQDu5fB50nagqCCkObcaPh3S6Gqc+pPNUjJGDDZdJuk+i:P0TNt2zDUQC8nECCURCDSzQ224D |
TLSH: | 50673A47E23211A9E5A5D2754B676963BB30FC5C533476A7B988CB302B82D70E32DB4C |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...9.^f...............)..=......:..%..........@.............................0......F.F...`................................ |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x140001125 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x140000000 |
Subsystem: | windows cui |
Image File Characteristics: | EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, LARGE_ADDRESS_AWARE, DEBUG_STRIPPED |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT |
Time Stamp: | 0x665EFF39 [Tue Jun 4 11:49:13 2024 UTC] |
TLS Callbacks: | 0x413c7e70, 0x1, 0x413c7f30, 0x1 |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | 88e67e1f726189fdea06b4329dc27d3c |
Instruction |
---|
push ebp |
dec eax |
mov ebp, esp |
dec eax |
sub esp, 30h |
mov dword ptr [ebp-04h], 000000FFh |
dec eax |
mov eax, dword ptr [01409155h] |
mov dword ptr [eax], 00000000h |
call 00007FDD31A26FF3h |
mov dword ptr [ebp-04h], eax |
nop |
nop |
mov eax, dword ptr [ebp-04h] |
dec eax |
add esp, 30h |
pop ebp |
ret |
push ebp |
dec eax |
mov ebp, esp |
dec eax |
sub esp, 70h |
dec eax |
mov dword ptr [ebp-10h], 00000000h |
mov dword ptr [ebp-1Ch], 00000030h |
mov eax, dword ptr [ebp-1Ch] |
dec eax |
mov eax, dword ptr [eax] |
dec eax |
mov dword ptr [ebp-28h], eax |
dec eax |
mov eax, dword ptr [ebp-28h] |
dec eax |
mov eax, dword ptr [eax+08h] |
dec eax |
mov dword ptr [ebp-18h], eax |
mov dword ptr [ebp-04h], 00000000h |
jmp 00007FDD31A27003h |
dec eax |
mov eax, dword ptr [ebp-10h] |
dec eax |
cmp eax, dword ptr [ebp-18h] |
jne 00007FDD31A26FEBh |
mov dword ptr [ebp-04h], 00000001h |
jmp 00007FDD31A27027h |
mov ecx, 000003E8h |
dec eax |
mov eax, dword ptr [014CF61Eh] |
call eax |
dec eax |
mov eax, dword ptr [0140912Dh] |
dec eax |
mov dword ptr [ebp-30h], eax |
dec eax |
mov eax, dword ptr [ebp-18h] |
dec eax |
mov dword ptr [ebp-38h], eax |
dec eax |
mov dword ptr [ebp-40h], 00000000h |
dec eax |
mov ecx, dword ptr [ebp-38h] |
dec eax |
mov eax, dword ptr [ebp-40h] |
dec eax |
mov edx, dword ptr [ebp-30h] |
dec eax |
cmpxchg dword ptr [edx], ecx |
dec eax |
mov dword ptr [ebp-10h], eax |
dec eax |
cmp dword ptr [ebp-10h], 00000000h |
jne 00007FDD31A26F8Ah |
dec eax |
mov eax, dword ptr [01409106h] |
mov eax, dword ptr [eax] |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x14cf000 | 0x3c20 | .idata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x14d5000 | 0x86c758 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x1412000 | 0x1d5d4 | .pdata |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x1d42000 | 0xc80 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x1409540 | 0x28 | .rdata |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x14cfd28 | 0xcb0 | .idata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x13d9458 | 0x13d9600 | f757bbc0a9ea67622ed64c318f31ddc9 | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.data | 0x13db000 | 0x8ba0 | 0x8c00 | d796ee37c0f53d42a6e275d6f0101266 | False | 0.20806361607142856 | data | 2.4882446835673684 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rdata | 0x13e4000 | 0x2cbb0 | 0x2cc00 | 68125e1baf519299a06e08b0e5ed2aa4 | False | 0.1629986469972067 | data | 5.251230435521518 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.eh_fram | 0x1411000 | 0x4 | 0x200 | bf619eac0cdf3f68d496ea9344137e8b | False | 0.02734375 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.pdata | 0x1412000 | 0x1d5d4 | 0x1d600 | ae3d7945a450c6de5173c20d72e11322 | False | 0.5768201462765957 | data | 6.622349703647603 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.xdata | 0x1430000 | 0x2ab3c | 0x2ac00 | 62abbb3522c5801f5a293306adc3e0ff | False | 0.07872464364035088 | shared library | 4.734716672862907 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.bss | 0x145b000 | 0x739a0 | 0x0 | d41d8cd98f00b204e9800998ecf8427e | False | 0 | empty | 0.0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.idata | 0x14cf000 | 0x3c20 | 0x3e00 | ccf46f73431659b659951260a8b5d560 | False | 0.2890625 | data | 4.942014326740688 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.CRT | 0x14d3000 | 0x60 | 0x200 | 05f43ba546a40a67b1cf06711ce0371b | False | 0.068359375 | data | 0.3349738039007212 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.tls | 0x14d4000 | 0x10 | 0x200 | bf619eac0cdf3f68d496ea9344137e8b | False | 0.02734375 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x14d5000 | 0x86c758 | 0x86c800 | ffd67f5366f1d03e3eb4796626ba1049 | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x1d42000 | 0xc80 | 0xe00 | 57c2dec2a6606f7246f0bc797334657e | False | 0.3521205357142857 | data | 5.0200783027194635 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_RCDATA | 0x14d50a0 | 0x86c2c0 | little endian ispell 3.1 hash file, | 0.36289310455322266 | ||
RT_MANIFEST | 0x1d41360 | 0x3f8 | ASCII text, with very long lines (1016), with no line terminators | 0.4655511811023622 |
DLL | Import |
---|---|
python311.dll | PyObject_GC_Del, _PyObject_GC_Resize, _PyObject_GC_NewVar, PyIter_Send, PyIter_Next, PyObject_GetIter, PyObject_IsSubclass, PyObject_IsInstance, PyMapping_Size, PyMapping_Check, PySequence_Contains, PySequence_List, PySequence_Tuple, PySequence_InPlaceConcat, PySequence_Check, PyNumber_ToBase, PyNumber_Float, PyNumber_Long, PyNumber_AsSsize_t, PyNumber_Invert, PyNumber_Positive, PyNumber_Negative, PyNumber_InPlaceMultiply, PyNumber_InPlaceAdd, PyNumber_InPlaceLshift, PyNumber_InPlaceOr, PyNumber_FloorDivide, PyNumber_Add, PyNumber_Subtract, PyBuffer_Release, PyObject_GetBuffer, PyObject_DelItem, PyObject_SetItem, PyObject_GetItem, PyObject_LengthHint, PyBool_Type, _Py_FalseStruct, _Py_TrueStruct, _PyByteArray_empty_string, PyByteArray_Type, PyByteArray_FromStringAndSize, PyByteArray_FromObject, PyBytes_Type, _PyBytes_Resize, PyBytes_AsString, PyBytes_FromString, PyBytes_FromStringAndSize, PyObject_CallFunctionObjArgs, PyObject_CallMethodObjArgs, PyObject_CallFunction, PyObject_CallObject, PyObject_Call, PyCapsule_New, PyMethod_Type, PyCode_Type, PyCode_Addr2Line, PyCode_NewWithPosOnlyArgs, PyComplex_Type, PyComplex_FromDoubles, PyProperty_Type, PyDescr_IsData, PyDictItems_Type, PyDictKeys_Type, PyDictValues_Type, PyDict_Type, PyDict_DelItemString, PyDict_SetItemString, PyDict_GetItemString, PyDict_Merge, PyDict_Update, PyDict_MergeFromSeq2, PyDict_Clear, PyDict_DelItem, PyDict_SetItem, PyDict_GetItem, _PyDict_NewPresized, _PyDict_MaybeUntrack, PyDict_New, PyEnum_Type, PyReversed_Type, PyExc_ImportWarning, PyExc_Exception, PyExc_KeyError, PyExc_RuntimeError, PyExc_IOError, PyExc_UnboundLocalError, PyExc_MemoryError, PyExc_TimeoutError, PyExc_WindowsError, PyExc_AttributeError, PyExc_SystemExit, PyExc_ZeroDivisionError, PyExc_ValueError, PyExc_BaseException, PyExc_OverflowError, PyExc_UnicodeError, PyExc_UnicodeDecodeError, PyExc_EnvironmentError, PyExc_StopIteration, PyExc_OSError, PyExc_NotImplementedError, PyExc_StopAsyncIteration, PyExc_TypeError, PyExc_NameError, PyExc_LookupError, PyExc_IndexError, PyExc_UnicodeEncodeError, PyExc_ImportError, PyExc_SystemError, PyExc_AssertionError, PyExc_GeneratorExit, PyException_SetContext, PyException_GetContext, PyException_SetCause, PyFloat_Type, PyFloat_FromString, PyFloat_FromDouble, PyFrame_Type, PyFrame_GetBack, PyFunction_Type, Py_GenericAliasType, Py_GenericAlias, _PyAsyncGenWrappedValue_Type, PyCoro_Type, PyGen_Type, PyAsyncGen_Type, _PyGen_FetchStopIterationValue, PySeqIter_Type, PyCallIter_Type, PyList_Type, PyList_Sort, PyList_Append, PyList_SetItem, PyList_New, PyLong_Type, PyLong_FromUnicodeObject, PyLong_FromString, PyLong_FromSsize_t, PyLong_FromLongLong, PyLong_FromVoidPtr, PyLong_AsSsize_t, PyLong_AsLong, PyLong_AsLongAndOverflow, PyLong_FromUnsignedLongLong, PyLong_FromLong, _PyLong_Copy, _PyLong_New, PyMemoryView_Type, PyCFunction_Type, PyCMethod_New, PyModule_Type, PyModuleDef_Type, PyModule_GetDef, PyModule_GetFilenameObject, PyModule_GetName, PyModule_GetDict, PyModule_ExecDef, PyModule_FromDefAndSpec2, PyModule_NewObject, _Py_NoneStruct, _Py_NotImplementedStruct, _Py_Dealloc, PyObject_Dir, PyCallable_Check, PyObject_IsTrue, PyObject_GenericSetAttr, PyObject_SelfIter, PyObject_SetAttr, _PyObject_LookupAttr, PyObject_GetAttr, PyObject_SetAttrString, PyObject_GetAttrString, PyObject_RichCompareBool, PyObject_RichCompare, _PyObject_FunctionStr, PyObject_Str, PyObject_Repr, _PyObject_New, PyObject_InitVar, PyObject_Free, PyObject_Realloc, PyMem_Free, PyMem_Realloc, PyMem_Malloc, PyMem_GetAllocator, PyRange_Type, PyFrozenSet_Type, PySet_Type, _PySet_NextEntry, PySet_Add, PySet_Contains, PyFrozenSet_New, PySet_New, PySlice_Type, _Py_EllipsisObject, PyEllipsis_Type, PyStructSequence_InitType, PyStructSequence_New, PyTuple_Type, PyTuple_Pack, _PyTuple_MaybeUntrack, PyTuple_New, PyBaseObject_Type, PySuper_Type, PyType_Type, PyType_Ready, _PyType_Lookup, PyType_IsSubtype, PyUnicode_Type, PyUnicode_InternInPlace, PyUnicode_Format, PyUnicode_RPartition, PyUnicode_Partition, PyUnicode_Substring, PyUnicode_Concat, PyUnicode_RichCompare, PyUnicode_Join, PyUnicode_FindChar, PyUnicode_Find, PyUnicode_DecodeUTF8, PyUnicode_GetLength, PyUnicode_AsUTF8, PyUnicode_FromEncodedObject, PyUnicode_FromOrdinal, PyUnicode_AsWideCharString, PyUnicode_FromFormat, PyUnicode_FromString, PyUnicode_FromStringAndSize, PyUnicode_FromWideChar, _PyUnicode_Ready, PyUnicode_New, _PyWeakref_CallableProxyType, _PyWeakref_ProxyType, _PyWeakref_RefType, PyObject_ClearWeakRefs, _PyWeakref_ClearRef, _PyWarnings_Init, PyErr_WarnEx, PyMap_Type, PyFilter_Type, PyZip_Type, PyEval_GetFuncName, PyEval_EvalCodeEx, _PyEval_EvalFrameDefault, Py_MakePendingCalls, PyEval_RestoreThread, PyEval_SaveThread, PyEval_AcquireThread, PyErr_WriteUnraisable, _PyErr_WriteUnraisableMsg, PyErr_Format, PyErr_SetFromErrno, PyErr_NoMemory, PyErr_BadArgument, _PyErr_FormatFromCause, _PyErr_ChainStackItem, _PyErr_NormalizeException, PyErr_ExceptionMatches, PyImport_FrozenModules, _PyArg_NoKeywords, PyArg_UnpackTuple, PyArg_ParseTupleAndKeywords, PyArg_ParseTuple, PyImport_ImportModule, PyImport_ImportFrozenModule, PyImport_ExecCodeModuleEx, PyImport_ExecCodeModule, _PyImport_FixupExtensionObject, PyImport_GetModuleDict, Py_NoSiteFlag, Py_NoUserSiteDirectory, Py_DontWriteBytecodeFlag, Py_DebugFlag, Py_BytesWarningFlag, Py_VerboseFlag, Py_OptimizeFlag, Py_UTF8Mode, Py_InteractiveFlag, Py_InspectFlag, Py_IgnoreEnvironmentFlag, Py_FrozenFlag, PyConfig_SetArgv, PyConfig_SetString, _PyConfig_InitCompatConfig, PyWideStringList_Append, PyStatus_Exception, PyMarshal_ReadObjectFromString, _Py_PackageContext, Py_BuildValue, PyOS_snprintf, Py_SetProgramName, _PyRuntime, Py_Exit, Py_ExitStatusException, Py_InitializeFromConfig, _PyRuntime_Initialize, Py_CompileStringExFlags, PyErr_Print, PyErr_PrintEx, PySys_WriteStderr, PySys_SetArgv, PySys_SetObject, PySys_GetObject, PyTraceBack_Type |
KERNEL32.dll | CloseHandle, CopyFileW, CreateFileMappingW, CreateFileW, DeleteCriticalSection, DeleteFileW, EnterCriticalSection, FindResourceA, FormatMessageA, FreeLibrary, GetCurrentProcessId, GetEnvironmentVariableW, GetFileSize, GetLastError, GetModuleFileNameW, GetModuleHandleA, GetProcAddress, GetShortPathNameW, GetSystemTimeAsFileTime, GetTempPathW, InitializeCriticalSection, IsDBCSLeadByteEx, LeaveCriticalSection, LoadLibraryA, LoadLibraryExW, LoadResource, LockResource, MapViewOfFile, MultiByteToWideChar, ReadFile, SetDllDirectoryW, SetEnvironmentVariableW, SetErrorMode, SetStdHandle, SetUnhandledExceptionFilter, Sleep, TlsGetValue, UnmapViewOfFile, VirtualProtect, VirtualQuery, WideCharToMultiByte, WriteFile |
msvcrt.dll | __C_specific_handler, ___lc_codepage_func, ___mb_cur_max_func, __iob_func, __set_app_type, __setusermatherr, __wgetmainargs, __winitenv, _amsg_exit, _cexit, _commode, _errno, _fmode, _initterm, _lock, _onexit, _unlock, _wcsdup, _wcsicmp, _wrename, _wtoi, abort, calloc, exit, fgetwc, fprintf, fputc, free, fwrite, iswctype, localeconv, malloc, mbstowcs, memcmp, memcpy, memmove, memset, puts, realloc, signal, strchr, strcmp, strerror, strlen, strncmp, strncpy, strrchr, towlower, ungetwc, vfprintf, wcscmp, wcslen, wcsncmp, wcstol, wcstoul |
SHELL32.dll | SHGetFolderPathW |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 05:48:26 |
Start date: | 09/12/2024 |
Path: | C:\Users\user\Desktop\disk-io.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff725c10000 |
File size: | 30'182'912 bytes |
MD5 hash: | DEBD16861B6996FEA26C7573FE5F8458 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 05:48:27 |
Start date: | 09/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |