Windows
Analysis Report
EDownloader.exe
Overview
General Information
Detection
Score: | 6 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 40% |
Signatures
Classification
Analysis Advice
Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior |
Sample may offer command line options, please run it with the 'Execute binary with arguments' cookbook (it's possible that the command line switches require additional characters like: "-", "/", "--") |
Sample searches for specific file, try point organization specific fake files to the analysis machine |
- System is w10x64
- EDownloader.exe (PID: 3008 cmdline:
"C:\Users\ user\Deskt op\EDownlo ader.exe" MD5: 3D92268FEC3C1CF2E0E29A47D22A79FB)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | Code function: | 0_2_005E6300 | |
Source: | Code function: | 0_2_005EA450 | |
Source: | Code function: | 0_2_005CE400 | |
Source: | Code function: | 0_2_005CE490 | |
Source: | Code function: | 0_2_005EA580 | |
Source: | Code function: | 0_2_005CF760 | |
Source: | Code function: | 0_2_005D17C0 | |
Source: | Code function: | 0_2_005D1800 | |
Source: | Code function: | 0_2_005D1820 | |
Source: | Code function: | 0_2_00525CD0 |
Source: | Code function: | 0_2_005B83A0 | |
Source: | Binary or memory string: |
Source: | Code function: | 0_2_005DCDB0 |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: |
Source: | Code function: | 0_2_006119B2 |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Code function: | 0_2_005BED70 |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Code function: | 0_2_005584C0 | |
Source: | Code function: | 0_2_00558FB0 |
Source: | Code function: | 0_2_005EA580 |
Source: | Code function: | 0_2_005382B0 |
Source: | Code function: | 0_2_005F6065 | |
Source: | Code function: | 0_2_005D0060 | |
Source: | Code function: | 0_2_00610179 | |
Source: | Code function: | 0_2_005F21F1 | |
Source: | Code function: | 0_2_005BE200 | |
Source: | Code function: | 0_2_005F6299 | |
Source: | Code function: | 0_2_0057C280 | |
Source: | Code function: | 0_2_00608326 | |
Source: | Code function: | 0_2_005A8310 | |
Source: | Code function: | 0_2_005B03D0 | |
Source: | Code function: | 0_2_0059C3F0 | |
Source: | Code function: | 0_2_005C23F0 | |
Source: | Code function: | 0_2_005A8440 | |
Source: | Code function: | 0_2_005F64CD | |
Source: | Code function: | 0_2_005F24AC | |
Source: | Code function: | 0_2_005724A0 | |
Source: | Code function: | 0_2_0056E550 | |
Source: | Code function: | 0_2_005A0540 | |
Source: | Code function: | 0_2_005E4500 | |
Source: | Code function: | 0_2_005EC500 | |
Source: | Code function: | 0_2_005A25B0 | |
Source: | Code function: | 0_2_005947D0 | |
Source: | Code function: | 0_2_005E2860 | |
Source: | Code function: | 0_2_00560820 | |
Source: | Code function: | 0_2_005FC8EA | |
Source: | Code function: | 0_2_005FE8E0 | |
Source: | Code function: | 0_2_0059E950 | |
Source: | Code function: | 0_2_005369D0 | |
Source: | Code function: | 0_2_00574AD0 | |
Source: | Code function: | 0_2_00584AB0 | |
Source: | Code function: | 0_2_005ECB00 | |
Source: | Code function: | 0_2_0059EC80 | |
Source: | Code function: | 0_2_00572DB0 | |
Source: | Code function: | 0_2_0059CE50 | |
Source: | Code function: | 0_2_00618EE0 | |
Source: | Code function: | 0_2_005CCF40 | |
Source: | Code function: | 0_2_0053F03F | |
Source: | Code function: | 0_2_00577150 | |
Source: | Code function: | 0_2_0057D11F | |
Source: | Code function: | 0_2_005591B0 | |
Source: | Code function: | 0_2_00573270 | |
Source: | Code function: | 0_2_006172EC | |
Source: | Code function: | 0_2_005A9370 | |
Source: | Code function: | 0_2_00521380 | |
Source: | Code function: | 0_2_005A1380 | |
Source: | Code function: | 0_2_005A33B0 | |
Source: | Code function: | 0_2_00617410 | |
Source: | Code function: | 0_2_00533570 | |
Source: | Code function: | 0_2_00559520 | |
Source: | Code function: | 0_2_006156CA | |
Source: | Code function: | 0_2_005CF760 | |
Source: | Code function: | 0_2_005F17E0 | |
Source: | Code function: | 0_2_00571910 | |
Source: | Code function: | 0_2_005F190E | |
Source: | Code function: | 0_2_00521A70 | |
Source: | Code function: | 0_2_0055FAF0 | |
Source: | Code function: | 0_2_00613B67 | |
Source: | Code function: | 0_2_0055DB10 | |
Source: | Code function: | 0_2_0059BB10 | |
Source: | Code function: | 0_2_005DDB30 | |
Source: | Code function: | 0_2_0057BBF0 | |
Source: | Code function: | 0_2_005E1C60 | |
Source: | Code function: | 0_2_005F1C80 | |
Source: | Code function: | 0_2_005EDDDB | |
Source: | Code function: | 0_2_00591E70 | |
Source: | Code function: | 0_2_0052BF70 | |
Source: | Code function: | 0_2_0056FF70 | |
Source: | Code function: | 0_2_005F1F2A | |
Source: | Code function: | 0_2_00585F90 |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_005E3590 |
Source: | Code function: | 0_2_005382B0 |
Source: | Code function: | 0_2_00554FA0 |
Source: | Code function: | 0_2_0058F650 |
Source: | Code function: | 0_2_005639E0 |
Source: | File created: | Jump to behavior |
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | String found in binary or memory: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_2_005287D0 |
Source: | Code function: | 0_2_005EF5E8 | |
Source: | Code function: | 0_2_005EF779 | |
Source: | Code function: | 0_2_005FB94F |
Source: | Code function: | 0_2_005581C0 | |
Source: | Code function: | 0_2_005591B0 | |
Source: | Code function: | 0_2_005591B0 | |
Source: | Code function: | 0_2_005591B0 | |
Source: | Code function: | 0_2_00563400 | |
Source: | Code function: | 0_2_00525500 | |
Source: | Code function: | 0_2_00525500 | |
Source: | Code function: | 0_2_00563820 |
Source: | Code function: | 0_2_005EDDDB |
Source: | API coverage: |
Source: | Code function: | 0_2_006119B2 |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Code function: | 0_2_005EF77B |
Source: | Code function: | 0_2_005287D0 |
Source: | Code function: | 0_2_0060FAEA | |
Source: | Code function: | 0_2_0060FB30 | |
Source: | Code function: | 0_2_00605E63 |
Source: | Code function: | 0_2_005EEB22 | |
Source: | Code function: | 0_2_005EF77B | |
Source: | Code function: | 0_2_005EF90E | |
Source: | Code function: | 0_2_005F3FEE |
Source: | Code function: | 0_2_0059E130 |
Source: | Code function: | 0_2_006140C0 | |
Source: | Code function: | 0_2_0060C26F | |
Source: | Code function: | 0_2_0054C350 | |
Source: | Code function: | 0_2_00614366 | |
Source: | Code function: | 0_2_006143B1 | |
Source: | Code function: | 0_2_0061444C | |
Source: | Code function: | 0_2_006144D7 | |
Source: | Code function: | 0_2_0061472C | |
Source: | Code function: | 0_2_00614854 | |
Source: | Code function: | 0_2_0060C822 | |
Source: | Code function: | 0_2_0061495C | |
Source: | Code function: | 0_2_00614A2F | |
Source: | Code function: | 0_2_005394D0 |
Source: | Code function: | 0_2_0060C861 |
Source: | Code function: | 0_2_00526920 |
Source: | Code function: | 0_2_0060EC7B |
Source: | Code function: | 0_2_0054C350 |
Source: | Code function: | 0_2_005C0240 | |
Source: | Code function: | 0_2_005DF6C0 |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 2 Command and Scripting Interpreter | 1 DLL Side-Loading | 1 Access Token Manipulation | 1 Masquerading | 1 Input Capture | 2 System Time Discovery | 1 Exploitation of Remote Services | 1 Input Capture | 2 Encrypted Channel | Exfiltration Over Other Network Medium | 1 Data Encrypted for Impact |
Credentials | Domains | Default Accounts | 1 Native API | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 1 Access Token Manipulation | LSASS Memory | 1 Security Software Discovery | Remote Desktop Protocol | 12 Archive Collected Data | 1 Ingress Tool Transfer | Exfiltration Over Bluetooth | 1 System Shutdown/Reboot |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Deobfuscate/Decode Files or Information | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 2 Obfuscated Files or Information | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Account Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 System Owner/User Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 2 File and Directory Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | Indicator Removal from Tools | Proc Filesystem | 23 System Information Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs | |||
0% | Virustotal | Browse |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1431754 |
Start date and time: | 2024-04-25 18:17:19 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 2m 47s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 2 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | EDownloader.exe |
Detection: | CLEAN |
Classification: | clean6.winEXE@2/1@0/0 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe
- Report size exceeded maximum capacity and may have missing disassembly code.
Process: | C:\Users\user\Desktop\EDownloader.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 113 |
Entropy (8bit): | 4.9697947247990175 |
Encrypted: | false |
SSDEEP: | 3:bRAv+OwnvQNOo2yjEQdVMcLvQNOo2yn:bb34jT7HL4jX |
MD5: | FF0DA2AA2413F1F278FFD795A4293747 |
SHA1: | 2E10D553A646C21CFA8F0F07BDB54423F6A724DC |
SHA-256: | EA9DF83AB19A8C46D7E6604C2DC87511F99044A2B0161D547CA68FD2D3EF680E |
SHA-512: | D18960256B89CF86759F2EF96CD95A8A8AFC4EC3F9FE6D7DCAC220ED6C4BEFB733BA730BFD5A86C96C1D4C892384FB07E0FD4119173850548E663E0867761977 |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 6.591503398666959 |
TrID: |
|
File name: | EDownloader.exe |
File size: | 1'327'952 bytes |
MD5: | 3d92268fec3c1cf2e0e29a47d22a79fb |
SHA1: | 445c634e78ec63ccb3a39ee5f6e81a7b46f3a7e5 |
SHA256: | 20475e541ca6a061eb5dc587784b9a3910bda519ccfd8d009dfcb4fd60fff0b6 |
SHA512: | d378a3def28412392e4b7426e53d6c2154c1b59c85815559843084d8381f91761cf0d7fd58b88014c69ee3ef215402217249b82e4a64c00dd5dce9674beabc31 |
SSDEEP: | 24576:95ZO2T67qsf6EbDOt20wjgrccMT8wGo20zd:927UdrccNwGo20zd |
TLSH: | 69558E617D42C172E1910170AEBFAFB6996DB5380B3540DBA7C00D3E9530AD2BA35B7B |
File Content Preview: | MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$........".;.C.h.C.h.C.h.%.i.C.h.%.i C.h.%.i.C.ht..h.C.h.+.i.C.h.+.i.C.h.+.i.C.h.%.i.C.h.%.i.C.h.C.hPB.h.%.i.C.hO*.i.C.hO*9h.C.h.CQh.C. |
Icon Hash: | 00928e8e8686b000 |
Entrypoint: | 0x4cef5e |
Entrypoint Section: | .text |
Digitally signed: | true |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x657FECEB [Mon Dec 18 06:55:39 2023 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 6 |
OS Version Minor: | 0 |
File Version Major: | 6 |
File Version Minor: | 0 |
Subsystem Version Major: | 6 |
Subsystem Version Minor: | 0 |
Import Hash: | 83b999c43d5940cad2066ca37770b561 |
Signature Valid: | true |
Signature Issuer: | CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US |
Signature Validation Error: | The operation completed successfully |
Error Number: | 0 |
Not Before, Not After |
|
Subject Chain |
|
Version: | 3 |
Thumbprint MD5: | A9CA0963936C7546B2348E650C8D8514 |
Thumbprint SHA-1: | 8F5F832BA07AE78DC635886D20042C21300D5DB9 |
Thumbprint SHA-256: | 8A6407872F4E2E95BB570B1751BED91D0B9D0BC90643F8F9E505374BF77519AB |
Serial: | 0AB53526DD9E3F80814952E212FFB1C4 |
Instruction |
---|
call 00007F616CE8BC39h |
jmp 00007F616CE8AEBFh |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
push edi |
push esi |
push ebx |
xor edi, edi |
mov eax, dword ptr [esp+14h] |
or eax, eax |
jnl 00007F616CE8B056h |
inc edi |
mov edx, dword ptr [esp+10h] |
neg eax |
neg edx |
sbb eax, 00000000h |
mov dword ptr [esp+14h], eax |
mov dword ptr [esp+10h], edx |
mov eax, dword ptr [esp+1Ch] |
or eax, eax |
jnl 00007F616CE8B056h |
inc edi |
mov edx, dword ptr [esp+18h] |
neg eax |
neg edx |
sbb eax, 00000000h |
mov dword ptr [esp+1Ch], eax |
mov dword ptr [esp+18h], edx |
or eax, eax |
jne 00007F616CE8B05Ah |
mov ecx, dword ptr [esp+18h] |
mov eax, dword ptr [esp+14h] |
xor edx, edx |
div ecx |
mov ebx, eax |
mov eax, dword ptr [esp+10h] |
div ecx |
mov edx, ebx |
jmp 00007F616CE8B083h |
mov ebx, eax |
mov ecx, dword ptr [esp+18h] |
mov edx, dword ptr [esp+14h] |
mov eax, dword ptr [esp+10h] |
shr ebx, 1 |
rcr ecx, 1 |
shr edx, 1 |
rcr eax, 1 |
or ebx, ebx |
jne 00007F616CE8B036h |
div ecx |
mov esi, eax |
mul dword ptr [esp+1Ch] |
mov ecx, eax |
mov eax, dword ptr [esp+18h] |
mul esi |
add edx, ecx |
jc 00007F616CE8B050h |
cmp edx, dword ptr [esp+14h] |
jnbe 00007F616CE8B04Ah |
jc 00007F616CE8B049h |
cmp eax, dword ptr [esp+10h] |
jbe 00007F616CE8B043h |
dec esi |
xor edx, edx |
mov eax, esi |
dec edi |
jne 00007F616CE8B049h |
neg edx |
neg eax |
sbb edx, 00000000h |
pop ebx |
pop esi |
pop edi |
retn 0010h |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
push ecx |
lea ecx, dword ptr [esp+04h] |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x13186c | 0x118 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x138000 | 0x5f0 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x141a00 | 0x2950 | .reloc |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x139000 | 0xc230 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x126f30 | 0x70 | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x127040 | 0x18 | .rdata |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x126fa0 | 0x40 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x101000 | 0x6c0 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0xffb3b | 0xffc00 | 800a547f152deb58dcc7637bebfe7b21 | False | 0.48263761608015643 | data | 6.521448412368595 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x101000 | 0x32bde | 0x32c00 | 8f7afa3ae6070acb034335b4e2bae657 | False | 0.3848041102216749 | DIY-Thermocam raw data (Lepton 2.x), scale 0-0, spot sensor temperature 0.000000, unit celsius, color scheme 0, calibration: offset 0.000000, slope 8589934592.000000 | 5.367310260450011 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x134000 | 0x39a4 | 0x2400 | 4b0958377ef3c5000d2a7ace9f05b544 | False | 0.19813368055555555 | data | 3.9789298039521968 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x138000 | 0x5f0 | 0x600 | 1752197a1bbfd2bf6b2ae489af36291f | False | 0.4765625 | data | 4.544009189321645 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x139000 | 0xc230 | 0xc400 | 8822af14128603b305d1eb503da79d4f | False | 0.5656688456632653 | data | 6.587363980280129 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_MENU | 0x138180 | 0x50 | data | Chinese | China | 0.8375 |
RT_DIALOG | 0x1381e0 | 0x12c | data | Chinese | China | 0.61 |
RT_STRING | 0x138310 | 0x4c | data | Chinese | China | 0.6710526315789473 |
RT_ACCELERATOR | 0x1381d0 | 0x10 | data | Chinese | China | 1.25 |
RT_MANIFEST | 0x138360 | 0x28b | XML 1.0 document, ASCII text, with CRLF line terminators | English | United States | 0.5529953917050692 |
DLL | Import |
---|---|
KERNEL32.dll | IsValidCodePage, FindNextFileW, FindFirstFileExW, FindClose, SetStdHandle, GetFullPathNameW, HeapReAlloc, GetFileAttributesExW, FlushFileBuffers, EnumSystemLocalesW, GetUserDefaultLCID, IsValidLocale, GetTimeFormatW, GetDateFormatW, HeapAlloc, HeapFree, GetConsoleCP, ReadConsoleW, GetConsoleMode, GetModuleHandleExW, FreeLibraryAndExitThread, ExitThread, FileTimeToSystemTime, SystemTimeToTzSpecificLocalTime, GetFileInformationByHandle, GetDriveTypeW, GetModuleFileNameA, SetEnvironmentVariableW, RtlUnwind, InitializeSListHead, GetCommandLineA, GetCurrentProcessId, QueryPerformanceCounter, GetStartupInfoW, IsDebuggerPresent, IsProcessorFeaturePresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, ResetEvent, SetEvent, GetCPInfo, LCMapStringW, CompareStringW, GetSystemTimeAsFileTime, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, SwitchToThread, CreateEventW, EncodePointer, GetStringTypeW, GetProcessHeap, HeapSize, GetFileSizeEx, CreateFileA, FormatMessageA, SetLastError, PeekNamedPipe, GetStdHandle, ExpandEnvironmentStringsA, VerifyVersionInfoA, GetModuleHandleA, GetSystemDirectoryA, VerSetConditionMask, GetOEMCP, GetCommandLineW, GetEnvironmentStringsW, GetCurrentThreadId, FreeEnvironmentStringsW, WaitForSingleObjectEx, GetTickCount64, SleepEx, LeaveCriticalSection, LoadLibraryW, GetPrivateProfileStringA, GetLocaleInfoW, Sleep, EnterCriticalSection, WaitForMultipleObjects, DecodePointer, DeleteCriticalSection, InitializeCriticalSectionEx, RaiseException, WaitForSingleObject, SetEndOfFile, SetFilePointerEx, OutputDebugStringW, GlobalUnlock, GlobalLock, GlobalAlloc, MulDiv, DosDateTimeToFileTime, GetFileType, SystemTimeToFileTime, DuplicateHandle, WriteFile, InitializeCriticalSectionAndSpinCount, ExitProcess, LockResource, SizeofResource, FreeResource, LoadResource, FindResourceW, GetACP, GetTickCount, GetCurrentDirectoryW, GetUserDefaultUILanguage, CreateMutexW, TerminateProcess, OpenProcess, Process32NextW, Process32FirstW, CreateToolhelp32Snapshot, ReleaseMutex, GetModuleHandleW, OutputDebugStringA, LoadLibraryExW, GetLocalTime, CreateDirectoryW, GetEnvironmentVariableW, SetFilePointer, DeleteFileW, GetTempPathW, MultiByteToWideChar, GetSystemInfo, GetTimeZoneInformation, CreateThread, FreeLibrary, GetProcAddress, LoadLibraryA, GetVersionExW, GetCurrentProcess, GetExitCodeProcess, GetLastError, CreateProcessW, ReadFile, GetFileSize, CloseHandle, CreateFileW, GetModuleFileNameW, WideCharToMultiByte, MoveFileExW, WriteConsoleW |
USER32.dll | GetWindowLongW, SetWindowLongW, IsIconic, ScreenToClient, SendMessageW, LoadImageW, GetParent, DestroyWindow, InvalidateRgn, GetClientRect, GetWindowRect, SetWindowRgn, MsgWaitForMultipleObjects, PeekMessageW, TranslateMessage, DispatchMessageW, ExitWindowsEx, GetSystemMetrics, KillTimer, CreateAcceleratorTableW, ClientToScreen, PtInRect, SetTimer, PostQuitMessage, MoveWindow, GetWindowDC, ReleaseDC, FindWindowW, IsWindow, SetForegroundWindow, SetFocus, GetDC, DefWindowProcW, CreateWindowExW, ShowWindow, GetWindow, EnableWindow, GetMessageW, GetMonitorInfoW, MonitorFromWindow, SetWindowPos, LoadCursorW, RegisterClassW, GetClassInfoExW, RegisterClassExW, CallWindowProcW, SetPropW, GetPropW, PostMessageW, AdjustWindowRectEx, GetGUIThreadInfo, IsZoomed, GetWindowTextW, GetWindowTextLengthW, SetWindowTextW, GetCaretBlinkTime, GetSysColor, SetCaretPos, GetCaretPos, HideCaret, ShowCaret, CreateCaret, CharPrevW, SetRect, DrawTextW, FillRect, MessageBoxW, SetCursor, wvsprintfW, OffsetRect, CharNextW, ReleaseCapture, GetMenu, GetKeyState, GetActiveWindow, BeginPaint, EndPaint, IsRectEmpty, GetUpdateRect, IsWindowVisible, IntersectRect, MapWindowPoints, GetCursorPos, GetFocus, InvalidateRect, UnionRect, SetCapture |
GDI32.dll | CombineRgn, ExtSelectClipRgn, CreateRectRgnIndirect, GetClipBox, SelectClipRgn, GetObjectA, GetTextMetricsW, SetWindowOrgEx, Rectangle, RestoreDC, BitBlt, SaveDC, CreateDIBSection, CreateCompatibleDC, DeleteDC, CreatePen, CreateFontIndirectW, GetStockObject, GetObjectW, GetTextExtentPoint32W, CreateFontW, GetTextExtentPointW, SelectObject, DeleteObject, CreateRoundRectRgn, StretchBlt, SetStretchBltMode, SetBkColor, ExtTextOutW, CreateSolidBrush, CreatePenIndirect, MoveToEx, LineTo, RoundRect, SetBkMode, SetTextColor, GetCharABCWidthsW, TextOutW, GdiFlush, GetDeviceCaps, CreateCompatibleBitmap, CreatePatternBrush |
ADVAPI32.dll | RegOpenKeyExW, RegEnumKeyExW, RegSetValueExA, RegCreateKeyExA, AdjustTokenPrivileges, LookupPrivilegeValueW, OpenProcessToken, GetSidSubAuthority, GetSidSubAuthorityCount, GetSidIdentifierAuthority, IsValidSid, LookupAccountNameW, GetUserNameW, RegCloseKey, RegQueryValueExW, CryptReleaseContext, CryptDestroyHash, CryptGetHashParam, CryptHashData, CryptCreateHash, CryptAcquireContextW, CryptGenRandom, CryptDestroyKey, CryptImportKey, CryptEncrypt, CryptAcquireContextA |
SHELL32.dll | SHBrowseForFolderW, ShellExecuteW, SHGetSpecialFolderPathW, SHGetSpecialFolderLocation, SHGetPathFromIDListW |
ole32.dll | CreateStreamOnHGlobal, CoCreateInstance, CLSIDFromProgID, CLSIDFromString, CoUninitialize, CoInitialize, OleLockRunning, CoCreateGuid |
OLEAUT32.dll | VariantClear, VariantInit, SysAllocString, SysFreeString |
gdiplus.dll | GdipAlloc, GdipLoadImageFromStream, GdipImageSelectActiveFrame, GdipGetImageHeight, GdipGetImageWidth, GdipGetPropertyItem, GdipGetPropertyItemSize, GdipImageGetFrameCount, GdipImageGetFrameDimensionsList, GdipImageGetFrameDimensionsCount, GdipDrawImage, GdipGraphicsClear, GdipDrawImageRectI, GdipDrawString, GdipGetFamily, GdipDeleteFontFamily, GdipSetPixelOffsetMode, GdipSetInterpolationMode, GdipSetCompositingQuality, GdipSetSmoothingMode, GdipGetImageGraphicsContext, GdipDisposeImage, GdipCloneImage, GdipCreateBitmapFromScan0, GdipFree, GdipDeleteBrush, GdipCreateLineBrushI, GdipSetStringFormatAlign, GdipSetStringFormatLineAlign, GdipDeleteStringFormat, GdipCreateStringFormat, GdipSetTextRenderingHint, GdipDeleteGraphics, GdipCreateFromHDC, GdipDeleteFont, GdipCreateFontFromLogfontA, GdipCreateFontFromDC, GdiplusShutdown, GdiplusStartup |
COMCTL32.dll | _TrackMouseEvent |
IMM32.dll | ImmGetContext, ImmSetCompositionFontW, ImmReleaseContext, ImmSetCompositionWindow |
CRYPT32.dll | CryptQueryObject, CertGetNameStringA, CertAddCertificateContextToStore, CertFreeCertificateChainEngine, CertFreeCertificateContext, CertFindCertificateInStore, CertCloseStore, CertOpenStore, CertCreateCertificateChainEngine, CertGetCertificateChain, CryptStringToBinaryA, CertFreeCertificateChain |
WS2_32.dll | connect, ntohl, htonl, ioctlsocket, sendto, recvfrom, listen, accept, freeaddrinfo, getaddrinfo, WSAIoctl, socket, setsockopt, ntohs, htons, getsockopt, getsockname, getpeername, closesocket, bind, send, recv, WSASetLastError, select, __WSAFDIsSet, WSAGetLastError, WSACleanup, gethostname, WSAStartup |
WLDAP32.dll |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
Chinese | China | |
English | United States |
Target ID: | 0 |
Start time: | 18:18:05 |
Start date: | 25/04/2024 |
Path: | C:\Users\user\Desktop\EDownloader.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x520000 |
File size: | 1'327'952 bytes |
MD5 hash: | 3D92268FEC3C1CF2E0E29A47D22A79FB |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Execution Graph
Execution Coverage: | 2.2% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 15.2% |
Total number of Nodes: | 2000 |
Total number of Limit Nodes: | 37 |
Graph
Function 005639E0 Relevance: 35.5, APIs: 14, Strings: 6, Instructions: 472windowCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060EC7B Relevance: 14.4, APIs: 5, Strings: 3, Instructions: 376timeCOMMONLIBRARYCODE
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060A524 Relevance: 17.8, APIs: 9, Strings: 1, Instructions: 274COMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00526110 Relevance: 15.9, APIs: 6, Strings: 3, Instructions: 163processCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00557EC0 Relevance: 15.9, APIs: 8, Strings: 1, Instructions: 131registryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005586B0 Relevance: 14.2, APIs: 6, Strings: 2, Instructions: 219libraryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00574920 Relevance: 12.2, APIs: 8, Instructions: 156fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060EE58 Relevance: 10.7, APIs: 3, Strings: 3, Instructions: 173timeCOMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00600F6D Relevance: 9.3, APIs: 6, Instructions: 285COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005A8100 Relevance: 9.1, APIs: 6, Instructions: 119COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00558330 Relevance: 7.6, APIs: 5, Instructions: 73COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060EFB5 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 80COMMONLIBRARYCODE
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00545670 Relevance: 3.2, APIs: 2, Instructions: 204COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00523A90 Relevance: 3.1, APIs: 2, Instructions: 67COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00564070 Relevance: 1.8, APIs: 1, Instructions: 250COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00553D60 Relevance: 1.6, APIs: 1, Instructions: 99COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060DFDE Relevance: 1.6, APIs: 1, Instructions: 54COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060B17A Relevance: 1.5, APIs: 1, Instructions: 32memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005C23F0 Relevance: 120.8, APIs: 5, Strings: 63, Instructions: 1808COMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005591B0 Relevance: 95.6, APIs: 53, Strings: 1, Instructions: 1113windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0054C350 Relevance: 62.9, APIs: 5, Strings: 30, Instructions: 1601windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005E6300 Relevance: 49.3, APIs: 15, Strings: 13, Instructions: 254fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005E2860 Relevance: 42.0, Strings: 33, Instructions: 726COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00584AB0 Relevance: 31.8, APIs: 17, Strings: 1, Instructions: 336timewindowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005369D0 Relevance: 30.9, APIs: 3, Strings: 14, Instructions: 1118sleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00560820 Relevance: 30.9, Strings: 24, Instructions: 864COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005A8310 Relevance: 28.7, APIs: 8, Strings: 8, Instructions: 720synchronizationthreadCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005382B0 Relevance: 28.5, APIs: 5, Strings: 11, Instructions: 453shutdownCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005C0240 Relevance: 28.4, APIs: 8, Strings: 8, Instructions: 356networkCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005A8440 Relevance: 26.9, APIs: 7, Strings: 8, Instructions: 631sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00554FA0 Relevance: 21.4, APIs: 5, Strings: 7, Instructions: 361processCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005D0060 Relevance: 20.5, Strings: 16, Instructions: 509COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005287D0 Relevance: 17.7, APIs: 6, Strings: 4, Instructions: 151registrylibraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00558FB0 Relevance: 15.9, APIs: 8, Strings: 1, Instructions: 162keyboardCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005581C0 Relevance: 15.9, APIs: 8, Strings: 1, Instructions: 123windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005EC500 Relevance: 12.9, Strings: 10, Instructions: 382COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006140C0 Relevance: 12.5, APIs: 5, Strings: 2, Instructions: 253COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00614A2F Relevance: 10.7, APIs: 5, Strings: 1, Instructions: 184COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00614854 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 86COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005A0540 Relevance: 8.4, Strings: 6, Instructions: 861COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005CCF40 Relevance: 6.6, Strings: 5, Instructions: 386COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006144D7 Relevance: 4.7, APIs: 3, Instructions: 206COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005FE8E0 Relevance: 3.5, APIs: 2, Instructions: 452COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00574AD0 Relevance: 3.4, APIs: 2, Instructions: 377COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005DCDB0 Relevance: 3.0, APIs: 2, Instructions: 38networkCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005E4500 Relevance: 3.0, Strings: 2, Instructions: 528COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005BED70 Relevance: 3.0, APIs: 2, Instructions: 23networkCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0061472C Relevance: 1.6, APIs: 1, Instructions: 84COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0061495C Relevance: 1.5, APIs: 1, Instructions: 46COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005F6299 Relevance: 1.5, Strings: 1, Instructions: 217COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060C861 Relevance: 1.3, Strings: 1, Instructions: 23COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005A25B0 Relevance: .7, Instructions: 677COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00618EE0 Relevance: .7, Instructions: 651COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00610179 Relevance: .6, Instructions: 637COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0059C3F0 Relevance: .5, Instructions: 465COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0059CE50 Relevance: .4, Instructions: 419COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005724A0 Relevance: .4, Instructions: 366COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0059EC80 Relevance: .4, Instructions: 352COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0059E950 Relevance: .3, Instructions: 305COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005B03D0 Relevance: .3, Instructions: 286COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005F21F1 Relevance: .3, Instructions: 254COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005F24AC Relevance: .2, Instructions: 244COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005F64CD Relevance: .2, Instructions: 240COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005F6065 Relevance: .2, Instructions: 217COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005947D0 Relevance: .2, Instructions: 217COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005FC8EA Relevance: .2, Instructions: 160COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00572DB0 Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005ECB00 Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0059E130 Relevance: .0, Instructions: 32COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00534700 Relevance: 49.1, APIs: 4, Strings: 24, Instructions: 147fileCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005E6630 Relevance: 38.8, APIs: 10, Strings: 12, Instructions: 280encryptionCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005D06E0 Relevance: 28.3, APIs: 1, Strings: 15, Instructions: 286encryptionCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00588880 Relevance: 26.7, APIs: 12, Strings: 3, Instructions: 442windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00590170 Relevance: 26.5, APIs: 14, Strings: 1, Instructions: 262filememoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005DF040 Relevance: 24.7, APIs: 8, Strings: 6, Instructions: 198networkCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0057F0A0 Relevance: 24.6, APIs: 13, Strings: 1, Instructions: 149windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00526340 Relevance: 23.0, APIs: 10, Strings: 3, Instructions: 205processCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005A8880 Relevance: 21.3, APIs: 3, Strings: 9, Instructions: 312synchronizationthreadCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005821E0 Relevance: 21.3, APIs: 11, Strings: 1, Instructions: 276windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005625D0 Relevance: 21.2, APIs: 4, Strings: 8, Instructions: 211fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0056EBA0 Relevance: 21.1, APIs: 6, Strings: 6, Instructions: 140memoryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00546270 Relevance: 19.5, APIs: 5, Strings: 6, Instructions: 228memorythreadCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0054A910 Relevance: 17.9, APIs: 5, Strings: 5, Instructions: 444libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0053C3E0 Relevance: 17.9, APIs: 6, Strings: 4, Instructions: 382windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00532BAB Relevance: 16.1, APIs: 2, Strings: 7, Instructions: 313threadCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005348F0 Relevance: 16.0, APIs: 6, Strings: 3, Instructions: 244fileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0057CCDB Relevance: 15.3, APIs: 10, Instructions: 294COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00578830 Relevance: 15.2, APIs: 10, Instructions: 153COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060AB37 Relevance: 15.1, APIs: 10, Instructions: 70COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005C0030 Relevance: 14.2, APIs: 4, Strings: 4, Instructions: 169networkCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005E69D0 Relevance: 14.1, APIs: 2, Strings: 6, Instructions: 119encryptionCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0055CE20 Relevance: 13.7, APIs: 9, Instructions: 217COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005AAC2A Relevance: 12.6, APIs: 3, Strings: 4, Instructions: 303threadCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005643B0 Relevance: 12.4, APIs: 3, Strings: 4, Instructions: 138windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005DED90 Relevance: 12.4, APIs: 6, Strings: 1, Instructions: 129networkCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00612518 Relevance: 12.2, APIs: 8, Instructions: 204COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0058EEF0 Relevance: 12.1, APIs: 8, Instructions: 123COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005281C0 Relevance: 10.9, APIs: 2, Strings: 4, Instructions: 392libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005AA430 Relevance: 10.8, APIs: 2, Strings: 4, Instructions: 310sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00558BC0 Relevance: 10.8, APIs: 7, Instructions: 266COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00585100 Relevance: 10.8, APIs: 7, Instructions: 257COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005A8F80 Relevance: 10.7, APIs: 5, Strings: 1, Instructions: 244threadsynchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00591110 Relevance: 10.7, APIs: 7, Instructions: 166COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0052E7E0 Relevance: 10.6, APIs: 7, Instructions: 130COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060C42E Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 78COMMONLIBRARYCODE
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0057C0D0 Relevance: 10.6, APIs: 7, Instructions: 56COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0057C040 Relevance: 10.6, APIs: 7, Instructions: 54COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00606368 Relevance: 9.2, APIs: 6, Instructions: 223COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005B44B0 Relevance: 9.1, APIs: 6, Instructions: 66networkCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00544280 Relevance: 8.9, APIs: 3, Strings: 2, Instructions: 116windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005D6DA0 Relevance: 8.9, APIs: 2, Strings: 3, Instructions: 101networkCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005C0AA0 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 77networkCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00546670 Relevance: 7.7, APIs: 5, Instructions: 232COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005C80D0 Relevance: 7.7, APIs: 5, Instructions: 181COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006025AA Relevance: 7.6, APIs: 5, Instructions: 144pipeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0052E3D0 Relevance: 7.6, APIs: 5, Instructions: 110COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0052E290 Relevance: 7.6, APIs: 5, Instructions: 102COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0057C160 Relevance: 7.6, APIs: 5, Instructions: 85COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00554C60 Relevance: 7.3, APIs: 2, Strings: 2, Instructions: 276synchronizationCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00538020 Relevance: 7.2, APIs: 1, Strings: 3, Instructions: 188windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005DE340 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 54networkCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005DEC20 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 37networkCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005B7070 Relevance: 7.0, APIs: 1, Strings: 3, Instructions: 30libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00586990 Relevance: 6.4, APIs: 4, Instructions: 352COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005BA240 Relevance: 6.1, APIs: 4, Instructions: 138COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005FEE1E Relevance: 6.1, APIs: 4, Instructions: 133COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060F26E Relevance: 6.0, APIs: 4, Instructions: 44COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00578E80 Relevance: 6.0, APIs: 4, Instructions: 41COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006121FD Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 167COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005D6F70 Relevance: 5.4, APIs: 1, Strings: 2, Instructions: 135networkCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00528A20 Relevance: 5.4, APIs: 1, Strings: 2, Instructions: 120timeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0055C080 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 72windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00580470 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 67windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005BEDF0 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 64networkCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 005BEEA0 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 52networkCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |