Loading ...

Play interactive tourEdit tour

Analysis Report aISbFyk4Lj.exe

Overview

General Information

Sample Name:aISbFyk4Lj.exe
Analysis ID:412223
MD5:167f0a829df709cc4107369ed23fbdfb
SHA1:a66caacf3bd0390912ab789b7e773e805172ba4c
SHA256:12279e26650d5826758ae344bc6ffef54a438d4782a42f0d369403ae41f3914b
Tags:exeNanoCoreRAT
Infos:

Most interesting Screenshot:

Detection

NanoCore
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: NanoCore
Yara detected AntiVM3
Yara detected Nanocore RAT
Allocates memory in foreign processes
C2 URLs / IPs found in malware configuration
Hides that the sample has been downloaded from the Internet (zone.identifier)
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Uses schtasks.exe or at.exe to add and modify task schedules
Writes to foreign memory regions
Contains capabilities to detect virtual machines
Contains functionality to call native functions
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains strange resources
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

Startup

  • System is w10x64
  • aISbFyk4Lj.exe (PID: 3288 cmdline: 'C:\Users\user\Desktop\aISbFyk4Lj.exe' MD5: 167F0A829DF709CC4107369ED23FBDFB)
    • schtasks.exe (PID: 2200 cmdline: 'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\QxHKzIlUxTf' /XML 'C:\Users\user\AppData\Local\Temp\tmp8EF.tmp' MD5: 15FF7D8324231381BAD48A052F85DF04)
      • conhost.exe (PID: 5232 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • RegSvcs.exe (PID: 1724 cmdline: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe MD5: 71369277D09DA0830C8C59F9E22BB23A)
    • RegSvcs.exe (PID: 5884 cmdline: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe MD5: 71369277D09DA0830C8C59F9E22BB23A)
  • cleanup

Malware Configuration

Threatname: NanoCore

{"Version": ".0.0.0,", "Mutex": "a7fa722b-7dae-45b1-afa6-302155a5", "Group": "Default", "Domain1": "wespeaktruthtoman.sytes.net", "Domain2": "wespeaktruthtoman12.sytes.net", "Port": 5600, "KeyboardLogging": "Enable", "RunOnStartup": "Disable", "RequestElevation": "Disable", "BypassUAC": "Disable", "ClearZoneIdentifier": "Enable", "ClearAccessControl": "Disable", "SetCriticalProcess": "Disable", "PreventSystemSleep": "Enable", "ActivateAwayMode": "Disable", "EnableDebugMode": "Disable", "RunDelay": 0, "ConnectDelay": 4000, "RestartDelay": 5000, "TimeoutInterval": 5000, "KeepAliveTimeout": 30000, "MutexTimeout": 5000, "LanTimeout": 2500, "WanTimeout": 8000, "BufferSize": "ffff0000", "MaxPacketSize": "0000a000", "GCThreshold": "0000a000", "UseCustomDNS": "Enable", "PrimaryDNSServer": "8.8.8.8"}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmpJoeSecurity_AntiVM_3Yara detected AntiVM_3Joe Security
    00000000.00000002.227998353.00000000045E1000.00000004.00000001.sdmpNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
    • 0x279b45:$x1: NanoCore.ClientPluginHost
    • 0x2feb65:$x1: NanoCore.ClientPluginHost
    • 0x279b82:$x2: IClientNetworkHost
    • 0x2feba2:$x2: IClientNetworkHost
    • 0x27d6b5:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
    • 0x3026d5:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
    00000000.00000002.227998353.00000000045E1000.00000004.00000001.sdmpJoeSecurity_NanocoreYara detected Nanocore RATJoe Security
      00000000.00000002.227998353.00000000045E1000.00000004.00000001.sdmpNanoCoreunknown Kevin Breen <kevin@techanarchy.net>
      • 0x2798ad:$a: NanoCore
      • 0x2798bd:$a: NanoCore
      • 0x279af1:$a: NanoCore
      • 0x279b05:$a: NanoCore
      • 0x279b45:$a: NanoCore
      • 0x2fe8cd:$a: NanoCore
      • 0x2fe8dd:$a: NanoCore
      • 0x2feb11:$a: NanoCore
      • 0x2feb25:$a: NanoCore
      • 0x2feb65:$a: NanoCore
      • 0x27990c:$b: ClientPlugin
      • 0x279b0e:$b: ClientPlugin
      • 0x279b4e:$b: ClientPlugin
      • 0x2fe92c:$b: ClientPlugin
      • 0x2feb2e:$b: ClientPlugin
      • 0x2feb6e:$b: ClientPlugin
      • 0x279a33:$c: ProjectData
      • 0x2fea53:$c: ProjectData
      • 0x447ba0:$c: ProjectData
      • 0x27a43a:$d: DESCrypto
      • 0x2ff45a:$d: DESCrypto
      Process Memory Space: aISbFyk4Lj.exe PID: 3288JoeSecurity_AntiVM_3Yara detected AntiVM_3Joe Security

        Unpacked PEs

        SourceRuleDescriptionAuthorStrings
        0.2.aISbFyk4Lj.exe.484a9b8.2.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
        • 0xe38d:$x1: NanoCore.ClientPluginHost
        • 0xe3ca:$x2: IClientNetworkHost
        • 0x11efd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
        0.2.aISbFyk4Lj.exe.484a9b8.2.unpackNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
        • 0xe105:$x1: NanoCore Client.exe
        • 0xe38d:$x2: NanoCore.ClientPluginHost
        • 0xf9c6:$s1: PluginCommand
        • 0xf9ba:$s2: FileCommand
        • 0x1086b:$s3: PipeExists
        • 0x16622:$s4: PipeCreated
        • 0xe3b7:$s5: IClientLoggingHost
        0.2.aISbFyk4Lj.exe.484a9b8.2.unpackJoeSecurity_NanocoreYara detected Nanocore RATJoe Security
          0.2.aISbFyk4Lj.exe.484a9b8.2.unpackNanoCoreunknown Kevin Breen <kevin@techanarchy.net>
          • 0xe0f5:$a: NanoCore
          • 0xe105:$a: NanoCore
          • 0xe339:$a: NanoCore
          • 0xe34d:$a: NanoCore
          • 0xe38d:$a: NanoCore
          • 0xe154:$b: ClientPlugin
          • 0xe356:$b: ClientPlugin
          • 0xe396:$b: ClientPlugin
          • 0xe27b:$c: ProjectData
          • 0xec82:$d: DESCrypto
          • 0x1664e:$e: KeepAlive
          • 0x1463c:$g: LogClientMessage
          • 0x10837:$i: get_Connected
          • 0xefb8:$j: #=q
          • 0xefe8:$j: #=q
          • 0xf004:$j: #=q
          • 0xf034:$j: #=q
          • 0xf050:$j: #=q
          • 0xf06c:$j: #=q
          • 0xf09c:$j: #=q
          • 0xf0b8:$j: #=q
          0.2.aISbFyk4Lj.exe.484a9b8.2.raw.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
          • 0x1018d:$x1: NanoCore.ClientPluginHost
          • 0x951ad:$x1: NanoCore.ClientPluginHost
          • 0x101ca:$x2: IClientNetworkHost
          • 0x951ea:$x2: IClientNetworkHost
          • 0x13cfd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
          • 0x98d1d:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
          Click to see the 2 entries

          Sigma Overview

          AV Detection:

          barindex
          Sigma detected: NanoCoreShow sources
          Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe, ProcessId: 5884, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

          E-Banking Fraud:

          barindex
          Sigma detected: NanoCoreShow sources
          Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe, ProcessId: 5884, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

          System Summary:

          barindex
          Sigma detected: Possible Applocker BypassShow sources
          Source: Process startedAuthor: juju4: Data: Command: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe, CommandLine: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe, CommandLine|base64offset|contains: , Image: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe, NewProcessName: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe, OriginalFileName: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe, ParentCommandLine: 'C:\Users\user\Desktop\aISbFyk4Lj.exe' , ParentImage: C:\Users\user\Desktop\aISbFyk4Lj.exe, ParentProcessId: 3288, ProcessCommandLine: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe, ProcessId: 1724

          Stealing of Sensitive Information:

          barindex
          Sigma detected: NanoCoreShow sources
          Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe, ProcessId: 5884, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

          Remote Access Functionality:

          barindex
          Sigma detected: NanoCoreShow sources
          Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe, ProcessId: 5884, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

          Signature Overview

          Click to jump to signature section

          Show All Signature Results

          AV Detection:

          barindex
          Found malware configurationShow sources
          Source: 0.2.aISbFyk4Lj.exe.484a9b8.2.raw.unpackMalware Configuration Extractor: NanoCore {"Version": ".0.0.0,", "Mutex": "a7fa722b-7dae-45b1-afa6-302155a5", "Group": "Default", "Domain1": "wespeaktruthtoman.sytes.net", "Domain2": "wespeaktruthtoman12.sytes.net", "Port": 5600, "KeyboardLogging": "Enable", "RunOnStartup": "Disable", "RequestElevation": "Disable", "BypassUAC": "Disable", "ClearZoneIdentifier": "Enable", "ClearAccessControl": "Disable", "SetCriticalProcess": "Disable", "PreventSystemSleep": "Enable", "ActivateAwayMode": "Disable", "EnableDebugMode": "Disable", "RunDelay": 0, "ConnectDelay": 4000, "RestartDelay": 5000, "TimeoutInterval": 5000, "KeepAliveTimeout": 30000, "MutexTimeout": 5000, "LanTimeout": 2500, "WanTimeout": 8000, "BufferSize": "ffff0000", "MaxPacketSize": "0000a000", "GCThreshold": "0000a000", "UseCustomDNS": "Enable", "PrimaryDNSServer": "8.8.8.8"}
          Multi AV Scanner detection for domain / URLShow sources
          Source: wespeaktruthtoman.sytes.netVirustotal: Detection: 8%Perma Link
          Source: wespeaktruthtoman.sytes.netVirustotal: Detection: 8%Perma Link
          Multi AV Scanner detection for dropped fileShow sources
          Source: C:\Users\user\AppData\Roaming\QxHKzIlUxTf.exeReversingLabs: Detection: 27%
          Multi AV Scanner detection for submitted fileShow sources
          Source: aISbFyk4Lj.exeVirustotal: Detection: 23%Perma Link
          Source: aISbFyk4Lj.exeReversingLabs: Detection: 27%
          Yara detected Nanocore RATShow sources
          Source: Yara matchFile source: 00000000.00000002.227998353.00000000045E1000.00000004.00000001.sdmp, type: MEMORY
          Source: Yara matchFile source: 0.2.aISbFyk4Lj.exe.484a9b8.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.aISbFyk4Lj.exe.484a9b8.2.raw.unpack, type: UNPACKEDPE
          Machine Learning detection for dropped fileShow sources
          Source: C:\Users\user\AppData\Roaming\QxHKzIlUxTf.exeJoe Sandbox ML: detected
          Machine Learning detection for sampleShow sources
          Source: aISbFyk4Lj.exeJoe Sandbox ML: detected
          Source: aISbFyk4Lj.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeFile opened: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9445_none_d08c58b4442ba54f\MSVCR80.dllJump to behavior
          Source: aISbFyk4Lj.exeStatic PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
          Source: Binary string: C:\Users\Administrator\Desktop\Client\Temp\aJUqyHKjYG\src\obj\Debug\getClaimsd95.pdbT source: aISbFyk4Lj.exe
          Source: Binary string: C:\Users\Administrator\Desktop\Client\Temp\aJUqyHKjYG\src\obj\Debug\getClaimsd95.pdb source: aISbFyk4Lj.exe
          Source: Binary string: \??\C:\Windows\symbols\dll\System.pdb source: RegSvcs.exe, 00000004.00000003.370702724.0000000000AF9000.00000004.00000001.sdmp
          Source: Binary string: mscorrc.pdb source: aISbFyk4Lj.exe, 00000000.00000002.230993463.0000000005880000.00000002.00000001.sdmp
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 4x nop then mov dword ptr [ebp-1Ch], 00000000h0_2_055E25B8
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 4x nop then mov dword ptr [ebp-1Ch], 00000000h0_2_055E25A8

          Networking:

          barindex
          C2 URLs / IPs found in malware configurationShow sources
          Source: Malware configuration extractorURLs: wespeaktruthtoman.sytes.net
          Source: Malware configuration extractorURLs: wespeaktruthtoman12.sytes.net
          Source: global trafficTCP traffic: 192.168.2.3:49694 -> 105.112.208.19:5600
          Source: Joe Sandbox ViewASN Name: VNL1-ASNG VNL1-ASNG
          Source: unknownDNS traffic detected: queries for: wespeaktruthtoman.sytes.net
          Source: aISbFyk4Lj.exeString found in binary or memory: http://checkip.dyndns.org/
          Source: aISbFyk4Lj.exeString found in binary or memory: http://servermanager.miixit.org/
          Source: aISbFyk4Lj.exeString found in binary or memory: http://servermanager.miixit.org/E
          Source: aISbFyk4Lj.exeString found in binary or memory: http://servermanager.miixit.org/downloads/
          Source: aISbFyk4Lj.exeString found in binary or memory: http://servermanager.miixit.org/hits/hit_index.php?k=
          Source: aISbFyk4Lj.exeString found in binary or memory: http://servermanager.miixit.org/hits/hit_index.php?k=1
          Source: aISbFyk4Lj.exeString found in binary or memory: http://servermanager.miixit.org/index_ru.html
          Source: aISbFyk4Lj.exeString found in binary or memory: http://servermanager.miixit.org/index_ru.htmlk
          Source: aISbFyk4Lj.exeString found in binary or memory: http://servermanager.miixit.org/report/reporter_index.php?name=
          Source: aISbFyk4Lj.exe, 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmpString found in binary or memory: https://stackpath.bootstrapcdn.com/bootstrap/4.5.0/css/bootstrap.min.css
          Source: aISbFyk4Lj.exeString found in binary or memory: https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=CJU3DBQXBUQPC

          E-Banking Fraud:

          barindex
          Yara detected Nanocore RATShow sources
          Source: Yara matchFile source: 00000000.00000002.227998353.00000000045E1000.00000004.00000001.sdmp, type: MEMORY
          Source: Yara matchFile source: 0.2.aISbFyk4Lj.exe.484a9b8.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.aISbFyk4Lj.exe.484a9b8.2.raw.unpack, type: UNPACKEDPE

          System Summary:

          barindex
          Malicious sample detected (through community Yara rule)Show sources
          Source: 00000000.00000002.227998353.00000000045E1000.00000004.00000001.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
          Source: 00000000.00000002.227998353.00000000045E1000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
          Source: 0.2.aISbFyk4Lj.exe.484a9b8.2.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
          Source: 0.2.aISbFyk4Lj.exe.484a9b8.2.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
          Source: 0.2.aISbFyk4Lj.exe.484a9b8.2.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
          Source: 0.2.aISbFyk4Lj.exe.484a9b8.2.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_0597184E NtQuerySystemInformation,0_2_0597184E
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_05971821 NtQuerySystemInformation,0_2_05971821
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_00EC93F10_2_00EC93F1
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_055E21B90_2_055E21B9
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_055E04400_2_055E0440
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_055E22C40_2_055E22C4
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_055E08880_2_055E0888
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C0D400_2_057C0D40
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C412B0_2_057C412B
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C29180_2_057C2918
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C39080_2_057C3908
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C20100_2_057C2010
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C58E80_2_057C58E8
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C24E00_2_057C24E0
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C17D70_2_057C17D7
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057CEFB80_2_057CEFB8
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C4A600_2_057C4A60
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057CFA200_2_057CFA20
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C0D300_2_057C0D30
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057CC5200_2_057CC520
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C29090_2_057C2909
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C39030_2_057C3903
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057CC9C00_2_057CC9C0
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C2DA00_2_057C2DA0
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C75880_2_057C7588
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057CD8780_2_057CD878
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057CCC680_2_057CCC68
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C70680_2_057C7068
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C705B0_2_057C705B
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C18300_2_057C1830
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C78200_2_057C7820
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C78100_2_057C7810
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C7C100_2_057C7C10
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C5CFB0_2_057C5CFB
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057CBCE80_2_057CBCE8
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C24D00_2_057C24D0
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C68D00_2_057C68D0
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057CB7180_2_057CB718
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C23100_2_057C2310
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C73080_2_057C7308
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C23010_2_057C2301
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C57F10_2_057C57F1
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C6FE80_2_057C6FE8
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C57B20_2_057C57B2
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C66780_2_057C6678
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C66680_2_057C6668
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C7A500_2_057C7A50
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C7A400_2_057C7A40
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C76200_2_057C7620
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C62C80_2_057C62C8
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057CD2A80_2_057CD2A8
          Source: aISbFyk4Lj.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
          Source: QxHKzIlUxTf.exe.0.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
          Source: aISbFyk4Lj.exeBinary or memory string: OriginalFilename vs aISbFyk4Lj.exe
          Source: aISbFyk4Lj.exe, 00000000.00000002.231389678.0000000005F80000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameDSASignature.dll@ vs aISbFyk4Lj.exe
          Source: aISbFyk4Lj.exe, 00000000.00000000.215774542.0000000000EC2000.00000002.00020000.sdmpBinary or memory string: OriginalFilenamegetClaimsd95.exeF vs aISbFyk4Lj.exe
          Source: aISbFyk4Lj.exe, 00000000.00000002.230993463.0000000005880000.00000002.00000001.sdmpBinary or memory string: OriginalFilenamemscorrc.dllT vs aISbFyk4Lj.exe
          Source: aISbFyk4Lj.exe, 00000000.00000002.227522713.0000000003698000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameSimpleUI.dll( vs aISbFyk4Lj.exe
          Source: aISbFyk4Lj.exe, 00000000.00000002.231733663.0000000006710000.00000002.00000001.sdmpBinary or memory string: originalfilename vs aISbFyk4Lj.exe
          Source: aISbFyk4Lj.exe, 00000000.00000002.231733663.0000000006710000.00000002.00000001.sdmpBinary or memory string: OriginalFilenamepropsys.dll.mui@ vs aISbFyk4Lj.exe
          Source: aISbFyk4Lj.exe, 00000000.00000002.230861005.00000000057F0000.00000002.00000001.sdmpBinary or memory string: OriginalFilenamenlsbres.dllj% vs aISbFyk4Lj.exe
          Source: aISbFyk4Lj.exe, 00000000.00000002.231565418.0000000006620000.00000002.00000001.sdmpBinary or memory string: System.OriginalFileName vs aISbFyk4Lj.exe
          Source: aISbFyk4Lj.exe, 00000000.00000002.230866914.0000000005800000.00000002.00000001.sdmpBinary or memory string: OriginalFilenamenlsbres.dll.muij% vs aISbFyk4Lj.exe
          Source: aISbFyk4Lj.exeBinary or memory string: OriginalFilenamegetClaimsd95.exeF vs aISbFyk4Lj.exe
          Source: aISbFyk4Lj.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
          Source: 00000000.00000002.227998353.00000000045E1000.00000004.00000001.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = https://creativecommons.org/licenses/by-nc/4.0/, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
          Source: 00000000.00000002.227998353.00000000045E1000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
          Source: 0.2.aISbFyk4Lj.exe.484a9b8.2.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = https://creativecommons.org/licenses/by-nc/4.0/, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
          Source: 0.2.aISbFyk4Lj.exe.484a9b8.2.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = https://creativecommons.org/licenses/by-nc/4.0/
          Source: 0.2.aISbFyk4Lj.exe.484a9b8.2.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
          Source: 0.2.aISbFyk4Lj.exe.484a9b8.2.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = https://creativecommons.org/licenses/by-nc/4.0/, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
          Source: 0.2.aISbFyk4Lj.exe.484a9b8.2.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
          Source: aISbFyk4Lj.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
          Source: QxHKzIlUxTf.exe.0.drStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
          Source: classification engineClassification label: mal100.troj.evad.winEXE@8/5@15/1
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_0597143A AdjustTokenPrivileges,0_2_0597143A
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_05971403 AdjustTokenPrivileges,0_2_05971403
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeFile created: C:\Users\user\AppData\Roaming\QxHKzIlUxTf.exeJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeMutant created: \Sessions\1\BaseNamedObjects\LiNEoHrmAt
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeMutant created: \Sessions\1\BaseNamedObjects\Global\.net clr networking
          Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5232:120:WilError_01
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeMutant created: \Sessions\1\BaseNamedObjects\Global\{a7fa722b-7dae-45b1-afa6-302155a56210}
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeFile created: C:\Users\user\AppData\Local\Temp\tmp8EF.tmpJump to behavior
          Source: aISbFyk4Lj.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeSection loaded: C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9603718106bd57ecfbb18fefd769cab4\mscorlib.ni.dllJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeSection loaded: C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlpJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeSection loaded: C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlpJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeSection loaded: C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9603718106bd57ecfbb18fefd769cab4\mscorlib.ni.dllJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeSection loaded: C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlpJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeSection loaded: C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlpJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
          Source: aISbFyk4Lj.exe, 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmpBinary or memory string: Select * from Clientes WHERE id=@id;;
          Source: aISbFyk4Lj.exe, 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmpBinary or memory string: Select * from Aluguel Erro ao listar Banco sql-Aluguel.INSERT INTO Aluguel VALUES(@clienteID, @data);
          Source: aISbFyk4Lj.exe, 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmpBinary or memory string: Select * from SecurityLogonType WHERE id=@id;
          Source: aISbFyk4Lj.exe, 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmpBinary or memory string: Select * from SecurityLogonType WHERE modelo=@modelo;
          Source: aISbFyk4Lj.exe, 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmpBinary or memory string: INSERT INTO Itens_Aluguel VALUES(@aluguelID, @aviaoID, @validade);
          Source: aISbFyk4Lj.exe, 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmpBinary or memory string: Insert into Clientes values (@nome, @cpf, @rg, @cidade, @endereco, @uf, @telefone);
          Source: aISbFyk4Lj.exe, 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmpBinary or memory string: INSERT INTO Aluguel VALUES(@clienteID, @data);
          Source: aISbFyk4Lj.exe, 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmpBinary or memory string: INSERT INTO SecurityLogonType VALUES(@modelo, @fabricante, @ano, @cor);
          Source: aISbFyk4Lj.exe, 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmpBinary or memory string: Select * from SecurityLogonType*Erro ao listar Banco sql-SecurityLogonType,Select * from SecurityLogonType WHERE id=@id;Select * from SecurityLogonType WHERE (modelo LIKE @modelo)
          Source: aISbFyk4Lj.exeVirustotal: Detection: 23%
          Source: aISbFyk4Lj.exeReversingLabs: Detection: 27%
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeFile read: C:\Users\user\Desktop\aISbFyk4Lj.exeJump to behavior
          Source: unknownProcess created: C:\Users\user\Desktop\aISbFyk4Lj.exe 'C:\Users\user\Desktop\aISbFyk4Lj.exe'
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess created: C:\Windows\SysWOW64\schtasks.exe 'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\QxHKzIlUxTf' /XML 'C:\Users\user\AppData\Local\Temp\tmp8EF.tmp'
          Source: C:\Windows\SysWOW64\schtasks.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess created: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess created: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess created: C:\Windows\SysWOW64\schtasks.exe 'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\QxHKzIlUxTf' /XML 'C:\Users\user\AppData\Local\Temp\tmp8EF.tmp'Jump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess created: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess created: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32Jump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeFile opened: C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dllJump to behavior
          Source: aISbFyk4Lj.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
          Source: aISbFyk4Lj.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
          Source: aISbFyk4Lj.exeStatic file information: File size 1476608 > 1048576
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeFile opened: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9445_none_d08c58b4442ba54f\MSVCR80.dllJump to behavior
          Source: aISbFyk4Lj.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x14d800
          Source: aISbFyk4Lj.exeStatic PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
          Source: aISbFyk4Lj.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
          Source: Binary string: C:\Users\Administrator\Desktop\Client\Temp\aJUqyHKjYG\src\obj\Debug\getClaimsd95.pdbT source: aISbFyk4Lj.exe
          Source: Binary string: C:\Users\Administrator\Desktop\Client\Temp\aJUqyHKjYG\src\obj\Debug\getClaimsd95.pdb source: aISbFyk4Lj.exe
          Source: Binary string: \??\C:\Windows\symbols\dll\System.pdb source: RegSvcs.exe, 00000004.00000003.370702724.0000000000AF9000.00000004.00000001.sdmp
          Source: Binary string: mscorrc.pdb source: aISbFyk4Lj.exe, 00000000.00000002.230993463.0000000005880000.00000002.00000001.sdmp
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C9838 push dword ptr [eax-67h]; ret 0_2_057C984E
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_057C842C push esp; iretd 0_2_057C842D
          Source: initial sampleStatic PE information: section name: .text entropy: 7.93424696113
          Source: initial sampleStatic PE information: section name: .text entropy: 7.93424696113
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeFile created: C:\Users\user\AppData\Roaming\QxHKzIlUxTf.exeJump to dropped file

          Boot Survival:

          barindex
          Uses schtasks.exe or at.exe to add and modify task schedulesShow sources
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess created: C:\Windows\SysWOW64\schtasks.exe 'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\QxHKzIlUxTf' /XML 'C:\Users\user\AppData\Local\Temp\tmp8EF.tmp'

          Hooking and other Techniques for Hiding and Protection:

          barindex
          Hides that the sample has been downloaded from the Internet (zone.identifier)Show sources
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeFile opened: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe:Zone.Identifier read attributes | deleteJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

          Malware Analysis System Evasion:

          barindex
          Yara detected AntiVM3Show sources
          Source: Yara matchFile source: 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: aISbFyk4Lj.exe PID: 3288, type: MEMORY
          Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)Show sources
          Source: aISbFyk4Lj.exe, 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmpBinary or memory string: WINE_GET_UNIX_FILE_NAME
          Source: aISbFyk4Lj.exe, 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmpBinary or memory string: SBIEDLL.DLL
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeFile opened / queried: SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}Jump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeThread delayed: delay time: 922337203685477Jump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeThread delayed: delay time: 922337203685477Jump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeWindow / User API: threadDelayed 649Jump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeWindow / User API: foregroundWindowGot 645Jump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeWindow / User API: foregroundWindowGot 734Jump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exe TID: 3704Thread sleep time: -103557s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exe TID: 3508Thread sleep time: -922337203685477s >= -30000sJump to behavior
          Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeThread delayed: delay time: 103557Jump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeThread delayed: delay time: 922337203685477Jump to behavior
          Source: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeThread delayed: delay time: 922337203685477Jump to behavior
          Source: aISbFyk4Lj.exe, 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmpBinary or memory string: vmware
          Source: aISbFyk4Lj.exe, 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmpBinary or memory string: C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\
          Source: aISbFyk4Lj.exe, 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmpBinary or memory string: SOFTWARE\VMware, Inc.\VMware Tools
          Source: aISbFyk4Lj.exe, 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmpBinary or memory string: VMware SVGA II!Add-MpPreference -ExclusionPath "
          Source: aISbFyk4Lj.exe, 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmpBinary or memory string: VMWARE
          Source: aISbFyk4Lj.exe, 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmpBinary or memory string: InstallPath%C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\
          Source: aISbFyk4Lj.exe, 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmpBinary or memory string: VMWARE"SOFTWARE\VMware, Inc.\VMware ToolsLHARDWARE\DEVICEMAP\Scsi\Scsi Port 1\Scsi Bus 0\Target Id 0\Logical Unit Id 0LHARDWARE\DEVICEMAP\Scsi\Scsi Port 2\Scsi Bus 0\Target Id 0\Logical Unit Id 0'SYSTEM\ControlSet001\Services\Disk\Enum
          Source: aISbFyk4Lj.exe, 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmpBinary or memory string: VMware SVGA II
          Source: aISbFyk4Lj.exe, 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmpBinary or memory string: vmwareNSYSTEM\ControlSet001\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess information queried: ProcessInformationJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess token adjusted: DebugJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeMemory allocated: page read and write | page guardJump to behavior

          HIPS / PFW / Operating System Protection Evasion:

          barindex
          Allocates memory in foreign processesShow sources
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeMemory allocated: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe base: 400000 protect: page execute and read and writeJump to behavior
          Injects a PE file into a foreign processesShow sources
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeMemory written: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe base: 400000 value starts with: 4D5AJump to behavior
          Writes to foreign memory regionsShow sources
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeMemory written: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe base: 400000Jump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeMemory written: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe base: 402000Jump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeMemory written: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe base: 420000Jump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeMemory written: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe base: 422000Jump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeMemory written: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe base: 664008Jump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess created: C:\Windows\SysWOW64\schtasks.exe 'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\QxHKzIlUxTf' /XML 'C:\Users\user\AppData\Local\Temp\tmp8EF.tmp'Jump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess created: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeJump to behavior
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeProcess created: C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeJump to behavior
          Source: RegSvcs.exe, 00000004.00000003.295080067.0000000000ABB000.00000004.00000001.sdmpBinary or memory string: Program Manager
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeCode function: 0_2_018FB0BE GetUserNameW,0_2_018FB0BE
          Source: C:\Users\user\Desktop\aISbFyk4Lj.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

          Stealing of Sensitive Information:

          barindex
          Yara detected Nanocore RATShow sources
          Source: Yara matchFile source: 00000000.00000002.227998353.00000000045E1000.00000004.00000001.sdmp, type: MEMORY
          Source: Yara matchFile source: 0.2.aISbFyk4Lj.exe.484a9b8.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.aISbFyk4Lj.exe.484a9b8.2.raw.unpack, type: UNPACKEDPE

          Remote Access Functionality:

          barindex
          Yara detected Nanocore RATShow sources
          Source: Yara matchFile source: 00000000.00000002.227998353.00000000045E1000.00000004.00000001.sdmp, type: MEMORY
          Source: Yara matchFile source: 0.2.aISbFyk4Lj.exe.484a9b8.2.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.aISbFyk4Lj.exe.484a9b8.2.raw.unpack, type: UNPACKEDPE

          Mitre Att&ck Matrix

          Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
          Valid AccountsScheduled Task/Job1Scheduled Task/Job1Access Token Manipulation1Masquerading1OS Credential DumpingSecurity Software Discovery211Remote ServicesArchive Collected Data1Exfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
          Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsProcess Injection312Disable or Modify Tools1LSASS MemoryProcess Discovery2Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
          Domain AccountsAt (Linux)Logon Script (Windows)Scheduled Task/Job1Virtualization/Sandbox Evasion31Security Account ManagerVirtualization/Sandbox Evasion31SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationNon-Application Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
          Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Access Token Manipulation1NTDSApplication Window Discovery1Distributed Component Object ModelInput CaptureScheduled TransferApplication Layer Protocol11SIM Card SwapCarrier Billing Fraud
          Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptProcess Injection312LSA SecretsAccount Discovery1SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
          Replication Through Removable MediaLaunchdRc.commonRc.commonHidden Files and Directories1Cached Domain CredentialsSystem Owner/User Discovery1VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
          External Remote ServicesScheduled TaskStartup ItemsStartup ItemsObfuscated Files or Information3DCSyncFile and Directory Discovery1Windows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
          Drive-by CompromiseCommand and Scripting InterpreterScheduled Task/JobScheduled Task/JobSoftware Packing2Proc FilesystemSystem Information Discovery2Shared WebrootCredential API HookingExfiltration Over Symmetric Encrypted Non-C2 ProtocolApplication Layer ProtocolDowngrade to Insecure ProtocolsGenerate Fraudulent Advertising Revenue

          Behavior Graph

          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Is Windows Process
          • Number of created Registry Values
          • Number of created Files
          • Visual Basic
          • Delphi
          • Java
          • .Net C# or VB.NET
          • C, C++ or other language
          • Is malicious
          • Internet

          Screenshots

          Thumbnails

          This section contains all screenshots as thumbnails, including those not shown in the slideshow.

          windows-stand

          Antivirus, Machine Learning and Genetic Malware Detection

          Initial Sample

          SourceDetectionScannerLabelLink
          aISbFyk4Lj.exe24%VirustotalBrowse
          aISbFyk4Lj.exe28%ReversingLabsWin32.Trojan.Wacatac
          aISbFyk4Lj.exe100%Joe Sandbox ML

          Dropped Files

          SourceDetectionScannerLabelLink
          C:\Users\user\AppData\Roaming\QxHKzIlUxTf.exe100%Joe Sandbox ML
          C:\Users\user\AppData\Roaming\QxHKzIlUxTf.exe28%ReversingLabsWin32.Trojan.Wacatac

          Unpacked PE Files

          No Antivirus matches

          Domains

          SourceDetectionScannerLabelLink
          wespeaktruthtoman.sytes.net8%VirustotalBrowse

          URLs

          SourceDetectionScannerLabelLink
          http://checkip.dyndns.org/0%VirustotalBrowse
          http://checkip.dyndns.org/0%Avira URL Cloudsafe
          wespeaktruthtoman.sytes.net8%VirustotalBrowse
          wespeaktruthtoman.sytes.net0%Avira URL Cloudsafe
          http://servermanager.miixit.org/hits/hit_index.php?k=10%Avira URL Cloudsafe
          wespeaktruthtoman12.sytes.net0%Avira URL Cloudsafe
          http://servermanager.miixit.org/E0%Avira URL Cloudsafe
          http://servermanager.miixit.org/index_ru.html0%Avira URL Cloudsafe
          http://servermanager.miixit.org/report/reporter_index.php?name=0%Avira URL Cloudsafe
          http://servermanager.miixit.org/0%Avira URL Cloudsafe
          http://servermanager.miixit.org/index_ru.htmlk0%Avira URL Cloudsafe
          http://servermanager.miixit.org/downloads/0%Avira URL Cloudsafe
          http://servermanager.miixit.org/hits/hit_index.php?k=0%Avira URL Cloudsafe

          Domains and IPs

          Contacted Domains

          NameIPActiveMaliciousAntivirus DetectionReputation
          wespeaktruthtoman.sytes.net
          105.112.208.19
          truetrueunknown
          wespeaktruthtoman12.sytes.net
          unknown
          unknowntrue
            unknown

            Contacted URLs

            NameMaliciousAntivirus DetectionReputation
            wespeaktruthtoman.sytes.nettrue
            • 8%, Virustotal, Browse
            • Avira URL Cloud: safe
            unknown
            wespeaktruthtoman12.sytes.nettrue
            • Avira URL Cloud: safe
            unknown

            URLs from Memory and Binaries

            NameSourceMaliciousAntivirus DetectionReputation
            http://checkip.dyndns.org/aISbFyk4Lj.exefalse
            • 0%, Virustotal, Browse
            • Avira URL Cloud: safe
            unknown
            http://servermanager.miixit.org/hits/hit_index.php?k=1aISbFyk4Lj.exefalse
            • Avira URL Cloud: safe
            unknown
            https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=CJU3DBQXBUQPCaISbFyk4Lj.exefalse
              high
              http://servermanager.miixit.org/EaISbFyk4Lj.exefalse
              • Avira URL Cloud: safe
              unknown
              http://servermanager.miixit.org/index_ru.htmlaISbFyk4Lj.exefalse
              • Avira URL Cloud: safe
              unknown
              http://servermanager.miixit.org/report/reporter_index.php?name=aISbFyk4Lj.exefalse
              • Avira URL Cloud: safe
              unknown
              http://servermanager.miixit.org/aISbFyk4Lj.exefalse
              • Avira URL Cloud: safe
              unknown
              http://servermanager.miixit.org/index_ru.htmlkaISbFyk4Lj.exefalse
              • Avira URL Cloud: safe
              unknown
              https://stackpath.bootstrapcdn.com/bootstrap/4.5.0/css/bootstrap.min.cssaISbFyk4Lj.exe, 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmpfalse
                high
                http://servermanager.miixit.org/downloads/aISbFyk4Lj.exefalse
                • Avira URL Cloud: safe
                unknown
                http://servermanager.miixit.org/hits/hit_index.php?k=aISbFyk4Lj.exefalse
                • Avira URL Cloud: safe
                unknown

                Contacted IPs

                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs

                Public

                IPDomainCountryFlagASNASN NameMalicious
                105.112.208.19
                wespeaktruthtoman.sytes.netNigeria
                36873VNL1-ASNGtrue

                General Information

                Joe Sandbox Version:32.0.0 Black Diamond
                Analysis ID:412223
                Start date:12.05.2021
                Start time:14:09:05
                Joe Sandbox Product:CloudBasic
                Overall analysis duration:0h 8m 0s
                Hypervisor based Inspection enabled:false
                Report type:full
                Sample file name:aISbFyk4Lj.exe
                Cookbook file name:default.jbs
                Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                Number of analysed new started processes analysed:17
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • HDC enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:MAL
                Classification:mal100.troj.evad.winEXE@8/5@15/1
                EGA Information:Failed
                HDC Information:Failed
                HCA Information:
                • Successful, ratio: 90%
                • Number of executed functions: 209
                • Number of non-executed functions: 30
                Cookbook Comments:
                • Adjust boot time
                • Enable AMSI
                • Found application associated with file extension: .exe
                Warnings:
                Show All
                • Behavior information exceeds normal sizes, reducing to normal. Report will have missing behavior information.
                • Excluded IPs from analysis (whitelisted): 168.61.161.212, 52.147.198.201, 13.88.21.125, 184.30.20.56, 2.20.143.16, 2.20.142.209
                • Excluded domains from analysis (whitelisted): au.download.windowsupdate.com.edgesuite.net, fs.microsoft.com, skypedataprdcolcus17.cloudapp.net, e1723.g.akamaiedge.net, ctldl.windowsupdate.com, a767.dscg3.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, skypedataprdcoleus16.cloudapp.net, blobcollector.events.data.trafficmanager.net, audownload.windowsupdate.nsatc.net, watson.telemetry.microsoft.com, prod.fs.microsoft.com.akadns.net, skypedataprdcolwus15.cloudapp.net, au-bg-shim.trafficmanager.net
                • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                • Report size getting too big, too many NtOpenKeyEx calls found.
                • Report size getting too big, too many NtProtectVirtualMemory calls found.
                • Report size getting too big, too many NtQueryValueKey calls found.

                Simulations

                Behavior and APIs

                TimeTypeDescription
                14:10:00API Interceptor1x Sleep call for process: aISbFyk4Lj.exe modified
                14:10:05API Interceptor967x Sleep call for process: RegSvcs.exe modified

                Joe Sandbox View / Context

                IPs

                No context

                Domains

                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                wespeaktruthtoman.sytes.netcXyHZtgrFS.exeGet hashmaliciousBrowse
                • 79.134.225.47
                13efMb6ayq.exeGet hashmaliciousBrowse
                • 79.134.225.47
                s65eJyjKga.exeGet hashmaliciousBrowse
                • 79.134.225.47
                new order.xlsxGet hashmaliciousBrowse
                • 79.134.225.47
                Ot3srIM10B.exeGet hashmaliciousBrowse
                • 79.134.225.47
                kwK4iGa9DL.exeGet hashmaliciousBrowse
                • 79.134.225.47
                4z9Saf2vu3.exeGet hashmaliciousBrowse
                • 79.134.225.47
                ORDER 4553241.xlsxGet hashmaliciousBrowse
                • 105.112.101.86
                Pu5UMH4fWK.exeGet hashmaliciousBrowse
                • 79.134.225.14

                ASN

                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                VNL1-ASNGw85rzxid7y.exeGet hashmaliciousBrowse
                • 105.112.102.199
                ORDER 4553241.xlsxGet hashmaliciousBrowse
                • 105.112.101.86
                akclienttues.exeGet hashmaliciousBrowse
                • 105.112.53.147
                Spec_PDF.vbsGet hashmaliciousBrowse
                • 105.112.11.245
                6GCAm7DuOd.exeGet hashmaliciousBrowse
                • 105.112.36.184
                Scan.Invoice0909206606.exeGet hashmaliciousBrowse
                • 105.112.39.176
                kYXjS6Oc3S.exeGet hashmaliciousBrowse
                • 105.112.99.190
                eK1KiJlz3l.exeGet hashmaliciousBrowse
                • 105.112.99.190
                80tzo8FG3d.exeGet hashmaliciousBrowse
                • 105.112.98.238
                Stub.exeGet hashmaliciousBrowse
                • 105.112.78.3
                nyrXbOodFH.exeGet hashmaliciousBrowse
                • 105.112.37.156
                3aDHivUqWtumbXb.exeGet hashmaliciousBrowse
                • 105.112.99.199
                ld7EYHHTT6.exeGet hashmaliciousBrowse
                • 105.112.148.62
                SecuriteInfo.com.Variant.Bulz.394792.29952.exeGet hashmaliciousBrowse
                • 105.112.98.171
                SecuriteInfo.com.Trojan.PackedNET.578.18498.exeGet hashmaliciousBrowse
                • 105.112.98.171
                yPLbA6JwCR.exeGet hashmaliciousBrowse
                • 105.112.156.57
                m1UDslBq6j.exeGet hashmaliciousBrowse
                • 105.112.107.123
                hjCQmeI243.exeGet hashmaliciousBrowse
                • 105.112.36.173
                Ixli7b5j6A.exeGet hashmaliciousBrowse
                • 105.112.106.26
                Ircg423Akc.exeGet hashmaliciousBrowse
                • 105.112.97.251

                JA3 Fingerprints

                No context

                Dropped Files

                No context

                Created / dropped Files

                C:\Users\user\AppData\Local\Microsoft\CLR_v2.0_32\UsageLogs\aISbFyk4Lj.exe.log
                Process:C:\Users\user\Desktop\aISbFyk4Lj.exe
                File Type:ASCII text, with CRLF line terminators
                Category:modified
                Size (bytes):916
                Entropy (8bit):5.282390836641403
                Encrypted:false
                SSDEEP:24:MLF20NaL3z2p29hJ5g522rW2xAi3AP26K95rKoO2+g2+:MwLLD2Y9h3go2rxxAcAO6ox+g2+
                MD5:5AD8E7ABEADADAC4CE06FF693476581A
                SHA1:81E42A97BBE3D7DE8B1E8B54C2B03C48594D761E
                SHA-256:BAA1A28262BA27D51C3A1FA7FB0811AD1128297ABB2EDCCC785DC52667D2A6FD
                SHA-512:7793E78E84AD36CE65B5B1C015364E340FB9110FAF199BC0234108CE9BCB1AEDACBD25C6A012AC99740E08BEA5E5C373A88E553E47016304D8AE6AEEAB58EBFF
                Malicious:true
                Reputation:moderate, very likely benign file
                Preview: 1,"fusion","GAC",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System\1ffc437de59fb69ba2b865ffdc98ffd1\System.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\cd7c74fce2a0eab72cd25cbe4bb61614\Microsoft.VisualBasic.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\54d944b3ca0ea1188d700fbd8089726b\System.Drawing.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\bd8d59c984c9f5f2695f64341115cdf0\System.Windows.Forms.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\35774dc3cd31b4550ab06c3354cf4ba5\System.Runtime.Remoting.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\de460308a9099237864d2ec2328fc958\System.Configuration.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\527c933194f3a99a816d83c619a3e1d3\System.Xml.ni.dll",0..
                C:\Users\user\AppData\Local\Temp\tmp8EF.tmp
                Process:C:\Users\user\Desktop\aISbFyk4Lj.exe
                File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):1644
                Entropy (8bit):5.1944478973860955
                Encrypted:false
                SSDEEP:24:2dH4+SEqC/Q7hxlNMFp1/rlMhEMjnGpwjpIgUYODOLD9RJh7h8gKBPtn:cbh47TlNQ//rydbz9I3YODOLNdq3n
                MD5:E38027EBC37002B1FE092464B6C50B95
                SHA1:69AA7795D3B11A6A00287E52B32922D8E709A90E
                SHA-256:1E9883662C67947499313FE57C066D600B86E342D05E38D3BBCA11D18057178B
                SHA-512:510EA110A11A2FCC43DEC5D7949AF1D521DE0E90312F9B85A2F599368670357D100D5F581E76B6345458E44DFA02094A3F9A604F755743199DBF63AFDBA5E1ED
                Malicious:true
                Reputation:low
                Preview: <?xml version="1.0" encoding="UTF-16"?>..<Task version="1.2" xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task">.. <RegistrationInfo>.. <Date>2014-10-25T14:27:44.8929027</Date>.. <Author>computer\user</Author>.. </RegistrationInfo>.. <Triggers>.. <LogonTrigger>.. <Enabled>true</Enabled>.. <UserId>computer\user</UserId>.. </LogonTrigger>.. <RegistrationTrigger>.. <Enabled>false</Enabled>.. </RegistrationTrigger>.. </Triggers>.. <Principals>.. <Principal id="Author">.. <UserId>computer\user</UserId>.. <LogonType>InteractiveToken</LogonType>.. <RunLevel>LeastPrivilege</RunLevel>.. </Principal>.. </Principals>.. <Settings>.. <MultipleInstancesPolicy>StopExisting</MultipleInstancesPolicy>.. <DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>.. <StopIfGoingOnBatteries>true</StopIfGoingOnBatteries>.. <AllowHardTerminate>false</AllowHardTerminate>.. <StartWhenAvailable>true
                C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat
                Process:C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
                File Type:International EBCDIC text, with NEL line terminators
                Category:dropped
                Size (bytes):8
                Entropy (8bit):3.0
                Encrypted:false
                SSDEEP:3:KlN:KT
                MD5:E53DF14406EA51F6AD5310C94FEA9653
                SHA1:5BD800A65855F236146D932FBD4770D50E73F469
                SHA-256:5B4ECA88318B72851EFEE98C61006C852B7F468802C1D12D6B4FB0E611BEEA49
                SHA-512:BF9F3C5062392F727ACA1E3B1A277131F840AAAA6E398F16E6C8A717BA04D1B72296B92E9662EBAB399807BEF7C2A0F02024231BF306FDA4BA0D33F00A3BBD54
                Malicious:true
                Reputation:low
                Preview: ..P...H
                C:\Users\user\AppData\Roaming\QxHKzIlUxTf.exe
                Process:C:\Users\user\Desktop\aISbFyk4Lj.exe
                File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                Category:dropped
                Size (bytes):1476608
                Entropy (8bit):7.772479880770275
                Encrypted:false
                SSDEEP:24576:MvI4jwLI3Z/kneMTMoiKc4MUVLUFJ6VAsqbuQjrFQLIrH:MAa3Z/keMs5UUwWsqb/jr5
                MD5:167F0A829DF709CC4107369ED23FBDFB
                SHA1:A66CAACF3BD0390912AB789B7E773E805172BA4C
                SHA-256:12279E26650D5826758AE344BC6FFEF54A438D4782A42F0D369403AE41F3914B
                SHA-512:BFE66CD5BE80F3912041B504BF20A05EFE510C7ABB3CB653E03E1F25F5CF193BA5338A007A688C718A6AE97F51886C020ABB853A39A020DA7C880AA81C4C7E23
                Malicious:true
                Antivirus:
                • Antivirus: Joe Sandbox ML, Detection: 100%
                • Antivirus: ReversingLabs, Detection: 28%
                Reputation:low
                Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......`..............P.............~.... ........@.. ....................................@.................................,...O.................................................................................... ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B................`.......H.......pr..,...............X............................................0............(....(..........(.....o ....*.....................(!......("......(#......($......(%....*N..(....o....(&....*&..('....*.s(........s)........s*........s+........s,........*....0...........~....o-....+..*.0...........~....o.....+..*.0...........~....o/....+..*.0...........~....o0....+..*.0...........~....o1....+..*.0..<........~.....(2.....,!r...p.....(3...o4...s5............~.....+..*.0......
                C:\Users\user\AppData\Roaming\QxHKzIlUxTf.exe:Zone.Identifier
                Process:C:\Users\user\Desktop\aISbFyk4Lj.exe
                File Type:ASCII text, with CRLF line terminators
                Category:dropped
                Size (bytes):26
                Entropy (8bit):3.95006375643621
                Encrypted:false
                SSDEEP:3:ggPYV:rPYV
                MD5:187F488E27DB4AF347237FE461A079AD
                SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
                SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
                SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
                Malicious:true
                Reputation:high, very likely benign file
                Preview: [ZoneTransfer]....ZoneId=0

                Static File Info

                General

                File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                Entropy (8bit):7.772479880770275
                TrID:
                • Win32 Executable (generic) Net Framework (10011505/4) 49.83%
                • Win32 Executable (generic) a (10002005/4) 49.78%
                • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
                • Generic Win/DOS Executable (2004/3) 0.01%
                • DOS Executable Generic (2002/1) 0.01%
                File name:aISbFyk4Lj.exe
                File size:1476608
                MD5:167f0a829df709cc4107369ed23fbdfb
                SHA1:a66caacf3bd0390912ab789b7e773e805172ba4c
                SHA256:12279e26650d5826758ae344bc6ffef54a438d4782a42f0d369403ae41f3914b
                SHA512:bfe66cd5be80f3912041b504bf20a05efe510c7abb3cb653e03e1f25f5cf193ba5338a007a688c718a6ae97f51886c020abb853a39a020da7c880aa81c4c7e23
                SSDEEP:24576:MvI4jwLI3Z/kneMTMoiKc4MUVLUFJ6VAsqbuQjrFQLIrH:MAa3Z/keMs5UUwWsqb/jr5
                File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......`..............P.............~.... ........@.. ....................................@................................

                File Icon

                Icon Hash:cc92316d713396e8

                Static PE Info

                General

                Entrypoint:0x54f67e
                Entrypoint Section:.text
                Digitally signed:false
                Imagebase:0x400000
                Subsystem:windows gui
                Image File Characteristics:32BIT_MACHINE, EXECUTABLE_IMAGE
                DLL Characteristics:NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
                Time Stamp:0x609BBDAF [Wed May 12 11:36:15 2021 UTC]
                TLS Callbacks:
                CLR (.Net) Version:v2.0.50727
                OS Version Major:4
                OS Version Minor:0
                File Version Major:4
                File Version Minor:0
                Subsystem Version Major:4
                Subsystem Version Minor:0
                Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744

                Entrypoint Preview

                Instruction
                jmp dword ptr [00402000h]
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al

                Data Directories

                NameVirtual AddressVirtual Size Is in Section
                IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                IMAGE_DIRECTORY_ENTRY_IMPORT0x14f62c0x4f.text
                IMAGE_DIRECTORY_ENTRY_RESOURCE0x1500000x1abb0.rsrc
                IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                IMAGE_DIRECTORY_ENTRY_BASERELOC0x16c0000xc.reloc
                IMAGE_DIRECTORY_ENTRY_DEBUG0x14f4f40x1c.text
                IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
                IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
                IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0

                Sections

                NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                .text0x20000x14d6840x14d800False0.937049053598data7.93424696113IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                .rsrc0x1500000x1abb00x1ac00False0.146274459696data3.15106465863IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                .reloc0x16c0000xc0x200False0.044921875data0.101910425663IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ

                Resources

                NameRVASizeTypeLanguageCountry
                RT_ICON0x1502500x468GLS_BINARY_LSB_FIRST
                RT_ICON0x1506b80x162aPNG image data, 256 x 256, 8-bit colormap, non-interlaced
                RT_ICON0x151ce40x25a8dBase IV DBT of `.DBF, block length 9216, next free block index 40, next free block 0, next used block 0
                RT_ICON0x15428c0x10a8dBase IV DBT of @.DBF, block length 4096, next free block index 40, next free block 0, next used block 0
                RT_ICON0x1553340x10828dBase III DBT, version number 0, next free block index 40
                RT_ICON0x165b5c0x4228dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
                RT_GROUP_ICON0x169d840x5adata
                RT_GROUP_ICON0x169de00x14data
                RT_VERSION0x169df40x354data
                RT_MANIFEST0x16a1480xa65XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

                Imports

                DLLImport
                mscoree.dll_CorExeMain

                Version Infos

                DescriptionData
                Translation0x0000 0x04b0
                LegalCopyrightCopyright 2013
                Assembly Version3.0.0.0
                InternalNamegetClaimsd95.exe
                FileVersion3.0.0.0
                CompanyName
                LegalTrademarks
                Comments
                ProductNameServerManager_Core
                ProductVersion3.0.0.0
                FileDescriptionServerManager_Core
                OriginalFilenamegetClaimsd95.exe

                Network Behavior

                Network Port Distribution

                TCP Packets

                TimestampSource PortDest PortSource IPDest IP
                May 12, 2021 14:10:07.926372051 CEST496945600192.168.2.3105.112.208.19
                May 12, 2021 14:10:10.927815914 CEST496945600192.168.2.3105.112.208.19
                May 12, 2021 14:10:16.928287029 CEST496945600192.168.2.3105.112.208.19
                May 12, 2021 14:10:27.812267065 CEST497055600192.168.2.3105.112.208.19
                May 12, 2021 14:10:30.820108891 CEST497055600192.168.2.3105.112.208.19
                May 12, 2021 14:10:36.867598057 CEST497055600192.168.2.3105.112.208.19
                May 12, 2021 14:10:47.904078007 CEST497065600192.168.2.3105.112.208.19
                May 12, 2021 14:10:50.899920940 CEST497065600192.168.2.3105.112.208.19
                May 12, 2021 14:10:57.072427034 CEST497065600192.168.2.3105.112.208.19
                May 12, 2021 14:11:22.187241077 CEST497085600192.168.2.3105.112.208.19
                May 12, 2021 14:11:25.199759007 CEST497085600192.168.2.3105.112.208.19
                May 12, 2021 14:11:31.200397968 CEST497085600192.168.2.3105.112.208.19
                May 12, 2021 14:11:40.734610081 CEST497095600192.168.2.3105.112.208.19
                May 12, 2021 14:11:43.748296976 CEST497095600192.168.2.3105.112.208.19
                May 12, 2021 14:11:49.764352083 CEST497095600192.168.2.3105.112.208.19
                May 12, 2021 14:11:57.417399883 CEST497105600192.168.2.3105.112.208.19
                May 12, 2021 14:12:00.421408892 CEST497105600192.168.2.3105.112.208.19
                May 12, 2021 14:12:06.422015905 CEST497105600192.168.2.3105.112.208.19

                UDP Packets

                TimestampSource PortDest PortSource IPDest IP
                May 12, 2021 14:09:52.197921038 CEST5696153192.168.2.38.8.8.8
                May 12, 2021 14:09:52.249525070 CEST53569618.8.8.8192.168.2.3
                May 12, 2021 14:09:53.094300985 CEST5935353192.168.2.38.8.8.8
                May 12, 2021 14:09:53.151433945 CEST53593538.8.8.8192.168.2.3
                May 12, 2021 14:09:54.402956009 CEST5223853192.168.2.38.8.8.8
                May 12, 2021 14:09:54.454456091 CEST53522388.8.8.8192.168.2.3
                May 12, 2021 14:09:55.308458090 CEST4987353192.168.2.38.8.8.8
                May 12, 2021 14:09:55.362652063 CEST53498738.8.8.8192.168.2.3
                May 12, 2021 14:10:01.325623035 CEST5319653192.168.2.38.8.8.8
                May 12, 2021 14:10:01.377830982 CEST53531968.8.8.8192.168.2.3
                May 12, 2021 14:10:02.353259087 CEST5677753192.168.2.38.8.8.8
                May 12, 2021 14:10:02.402128935 CEST53567778.8.8.8192.168.2.3
                May 12, 2021 14:10:04.487103939 CEST5864353192.168.2.38.8.8.8
                May 12, 2021 14:10:04.538048983 CEST53586438.8.8.8192.168.2.3
                May 12, 2021 14:10:05.972115040 CEST6098553192.168.2.38.8.8.8
                May 12, 2021 14:10:06.020780087 CEST53609858.8.8.8192.168.2.3
                May 12, 2021 14:10:06.890644073 CEST5020053192.168.2.38.8.8.8
                May 12, 2021 14:10:06.939263105 CEST53502008.8.8.8192.168.2.3
                May 12, 2021 14:10:07.797035933 CEST5128153192.168.2.38.8.8.8
                May 12, 2021 14:10:07.856506109 CEST53512818.8.8.8192.168.2.3
                May 12, 2021 14:10:08.141349077 CEST4919953192.168.2.38.8.8.8
                May 12, 2021 14:10:08.191653967 CEST53491998.8.8.8192.168.2.3
                May 12, 2021 14:10:08.925841093 CEST5062053192.168.2.38.8.8.8
                May 12, 2021 14:10:08.977776051 CEST53506208.8.8.8192.168.2.3
                May 12, 2021 14:10:09.719042063 CEST6493853192.168.2.38.8.8.8
                May 12, 2021 14:10:09.769270897 CEST53649388.8.8.8192.168.2.3
                May 12, 2021 14:10:10.492587090 CEST6015253192.168.2.38.8.8.8
                May 12, 2021 14:10:10.541302919 CEST53601528.8.8.8192.168.2.3
                May 12, 2021 14:10:11.335540056 CEST5754453192.168.2.38.8.8.8
                May 12, 2021 14:10:11.395431995 CEST53575448.8.8.8192.168.2.3
                May 12, 2021 14:10:12.158965111 CEST5598453192.168.2.38.8.8.8
                May 12, 2021 14:10:12.220136881 CEST53559848.8.8.8192.168.2.3
                May 12, 2021 14:10:13.261647940 CEST6418553192.168.2.38.8.8.8
                May 12, 2021 14:10:13.311885118 CEST53641858.8.8.8192.168.2.3
                May 12, 2021 14:10:22.907243967 CEST6511053192.168.2.38.8.8.8
                May 12, 2021 14:10:22.969291925 CEST53651108.8.8.8192.168.2.3
                May 12, 2021 14:10:27.748070955 CEST5836153192.168.2.38.8.8.8
                May 12, 2021 14:10:27.810220003 CEST53583618.8.8.8192.168.2.3
                May 12, 2021 14:10:47.850631952 CEST6349253192.168.2.38.8.8.8
                May 12, 2021 14:10:47.862081051 CEST6083153192.168.2.38.8.8.8
                May 12, 2021 14:10:47.902456999 CEST53634928.8.8.8192.168.2.3
                May 12, 2021 14:10:47.922029972 CEST53608318.8.8.8192.168.2.3
                May 12, 2021 14:11:07.928497076 CEST6010053192.168.2.38.8.8.8
                May 12, 2021 14:11:07.985506058 CEST53601008.8.8.8192.168.2.3
                May 12, 2021 14:11:08.167423010 CEST5319553192.168.2.38.8.4.4
                May 12, 2021 14:11:08.228714943 CEST53531958.8.4.4192.168.2.3
                May 12, 2021 14:11:08.287180901 CEST5014153192.168.2.38.8.8.8
                May 12, 2021 14:11:08.348562002 CEST53501418.8.8.8192.168.2.3
                May 12, 2021 14:11:12.555984974 CEST5302353192.168.2.38.8.8.8
                May 12, 2021 14:11:12.613117933 CEST53530238.8.8.8192.168.2.3
                May 12, 2021 14:11:13.215193987 CEST4956353192.168.2.38.8.4.4
                May 12, 2021 14:11:13.272510052 CEST53495638.8.4.4192.168.2.3
                May 12, 2021 14:11:13.365533113 CEST5135253192.168.2.38.8.8.8
                May 12, 2021 14:11:13.422804117 CEST53513528.8.8.8192.168.2.3
                May 12, 2021 14:11:17.661933899 CEST5934953192.168.2.38.8.8.8
                May 12, 2021 14:11:17.719084978 CEST53593498.8.8.8192.168.2.3
                May 12, 2021 14:11:17.753895044 CEST5708453192.168.2.38.8.4.4
                May 12, 2021 14:11:17.815638065 CEST53570848.8.4.4192.168.2.3
                May 12, 2021 14:11:17.981719017 CEST5882353192.168.2.38.8.8.8
                May 12, 2021 14:11:18.042107105 CEST53588238.8.8.8192.168.2.3
                May 12, 2021 14:11:22.121907949 CEST5756853192.168.2.38.8.8.8
                May 12, 2021 14:11:22.185769081 CEST53575688.8.8.8192.168.2.3
                May 12, 2021 14:11:40.674099922 CEST5054053192.168.2.38.8.8.8
                May 12, 2021 14:11:40.733225107 CEST53505408.8.8.8192.168.2.3
                May 12, 2021 14:11:57.362112999 CEST5436653192.168.2.38.8.8.8
                May 12, 2021 14:11:57.415962934 CEST53543668.8.8.8192.168.2.3

                DNS Queries

                TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                May 12, 2021 14:10:07.797035933 CEST192.168.2.38.8.8.80xee82Standard query (0)wespeaktruthtoman.sytes.netA (IP address)IN (0x0001)
                May 12, 2021 14:10:27.748070955 CEST192.168.2.38.8.8.80x9d3cStandard query (0)wespeaktruthtoman.sytes.netA (IP address)IN (0x0001)
                May 12, 2021 14:10:47.850631952 CEST192.168.2.38.8.8.80xb13bStandard query (0)wespeaktruthtoman.sytes.netA (IP address)IN (0x0001)
                May 12, 2021 14:11:07.928497076 CEST192.168.2.38.8.8.80x187eStandard query (0)wespeaktruthtoman12.sytes.netA (IP address)IN (0x0001)
                May 12, 2021 14:11:08.167423010 CEST192.168.2.38.8.4.40x7021Standard query (0)wespeaktruthtoman12.sytes.netA (IP address)IN (0x0001)
                May 12, 2021 14:11:08.287180901 CEST192.168.2.38.8.8.80x8e6aStandard query (0)wespeaktruthtoman12.sytes.netA (IP address)IN (0x0001)
                May 12, 2021 14:11:12.555984974 CEST192.168.2.38.8.8.80xd0aeStandard query (0)wespeaktruthtoman12.sytes.netA (IP address)IN (0x0001)
                May 12, 2021 14:11:13.215193987 CEST192.168.2.38.8.4.40x4bf6Standard query (0)wespeaktruthtoman12.sytes.netA (IP address)IN (0x0001)
                May 12, 2021 14:11:13.365533113 CEST192.168.2.38.8.8.80x757bStandard query (0)wespeaktruthtoman12.sytes.netA (IP address)IN (0x0001)
                May 12, 2021 14:11:17.661933899 CEST192.168.2.38.8.8.80xca1aStandard query (0)wespeaktruthtoman12.sytes.netA (IP address)IN (0x0001)
                May 12, 2021 14:11:17.753895044 CEST192.168.2.38.8.4.40xa13fStandard query (0)wespeaktruthtoman12.sytes.netA (IP address)IN (0x0001)
                May 12, 2021 14:11:17.981719017 CEST192.168.2.38.8.8.80xa420Standard query (0)wespeaktruthtoman12.sytes.netA (IP address)IN (0x0001)
                May 12, 2021 14:11:22.121907949 CEST192.168.2.38.8.8.80x6731Standard query (0)wespeaktruthtoman.sytes.netA (IP address)IN (0x0001)
                May 12, 2021 14:11:40.674099922 CEST192.168.2.38.8.8.80x3e28Standard query (0)wespeaktruthtoman.sytes.netA (IP address)IN (0x0001)
                May 12, 2021 14:11:57.362112999 CEST192.168.2.38.8.8.80x4eb1Standard query (0)wespeaktruthtoman.sytes.netA (IP address)IN (0x0001)

                DNS Answers

                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                May 12, 2021 14:10:07.856506109 CEST8.8.8.8192.168.2.30xee82No error (0)wespeaktruthtoman.sytes.net105.112.208.19A (IP address)IN (0x0001)
                May 12, 2021 14:10:27.810220003 CEST8.8.8.8192.168.2.30x9d3cNo error (0)wespeaktruthtoman.sytes.net105.112.208.19A (IP address)IN (0x0001)
                May 12, 2021 14:10:47.902456999 CEST8.8.8.8192.168.2.30xb13bNo error (0)wespeaktruthtoman.sytes.net105.112.208.19A (IP address)IN (0x0001)
                May 12, 2021 14:11:22.185769081 CEST8.8.8.8192.168.2.30x6731No error (0)wespeaktruthtoman.sytes.net105.112.208.19A (IP address)IN (0x0001)
                May 12, 2021 14:11:40.733225107 CEST8.8.8.8192.168.2.30x3e28No error (0)wespeaktruthtoman.sytes.net105.112.208.19A (IP address)IN (0x0001)
                May 12, 2021 14:11:57.415962934 CEST8.8.8.8192.168.2.30x4eb1No error (0)wespeaktruthtoman.sytes.net105.112.208.19A (IP address)IN (0x0001)

                Code Manipulations

                Statistics

                CPU Usage

                Click to jump to process

                Memory Usage

                Click to jump to process

                High Level Behavior Distribution

                Click to dive into process behavior distribution

                Behavior

                Click to jump to process

                System Behavior

                General

                Start time:14:09:59
                Start date:12/05/2021
                Path:C:\Users\user\Desktop\aISbFyk4Lj.exe
                Wow64 process (32bit):true
                Commandline:'C:\Users\user\Desktop\aISbFyk4Lj.exe'
                Imagebase:0xec0000
                File size:1476608 bytes
                MD5 hash:167F0A829DF709CC4107369ED23FBDFB
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:.Net C# or VB.NET
                Yara matches:
                • Rule: JoeSecurity_AntiVM_3, Description: Yara detected AntiVM_3, Source: 00000000.00000002.227476170.000000000362D000.00000004.00000001.sdmp, Author: Joe Security
                • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000000.00000002.227998353.00000000045E1000.00000004.00000001.sdmp, Author: Florian Roth
                • Rule: JoeSecurity_Nanocore, Description: Yara detected Nanocore RAT, Source: 00000000.00000002.227998353.00000000045E1000.00000004.00000001.sdmp, Author: Joe Security
                • Rule: NanoCore, Description: unknown, Source: 00000000.00000002.227998353.00000000045E1000.00000004.00000001.sdmp, Author: Kevin Breen <kevin@techanarchy.net>
                Reputation:low

                General

                Start time:14:10:02
                Start date:12/05/2021
                Path:C:\Windows\SysWOW64\schtasks.exe
                Wow64 process (32bit):true
                Commandline:'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\QxHKzIlUxTf' /XML 'C:\Users\user\AppData\Local\Temp\tmp8EF.tmp'
                Imagebase:0xc70000
                File size:185856 bytes
                MD5 hash:15FF7D8324231381BAD48A052F85DF04
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:high

                General

                Start time:14:10:02
                Start date:12/05/2021
                Path:C:\Windows\System32\conhost.exe
                Wow64 process (32bit):false
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:0x7ff6b2800000
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:high

                General

                Start time:14:10:03
                Start date:12/05/2021
                Path:C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
                Wow64 process (32bit):false
                Commandline:C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
                Imagebase:0x1e0000
                File size:32768 bytes
                MD5 hash:71369277D09DA0830C8C59F9E22BB23A
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:moderate

                General

                Start time:14:10:03
                Start date:12/05/2021
                Path:C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
                Wow64 process (32bit):true
                Commandline:C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
                Imagebase:0x4d0000
                File size:32768 bytes
                MD5 hash:71369277D09DA0830C8C59F9E22BB23A
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:.Net C# or VB.NET
                Reputation:moderate

                Disassembly

                Code Analysis

                Reset < >

                  Executed Functions

                  APIs
                  • AdjustTokenPrivileges.KERNELBASE(?,?,?,?,?,?), ref: 05971483
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: AdjustPrivilegesToken
                  • String ID:
                  • API String ID: 2874748243-0
                  • Opcode ID: 6f4a6e56af4f9de1f536a5cb1ecd9f49cdac9ed49225de535c3f013ded631e49
                  • Instruction ID: fa03a01fce70f1a9987338e35c8d8d5541e335b798ed4fe4a696255144adf5b5
                  • Opcode Fuzzy Hash: 6f4a6e56af4f9de1f536a5cb1ecd9f49cdac9ed49225de535c3f013ded631e49
                  • Instruction Fuzzy Hash: 10219175509784AFDB228F25DC40B62BFF8AF06310F0885DBE9858F563D2759908DB61
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • NtQuerySystemInformation.NTDLL(?,?,?,?), ref: 05971889
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: InformationQuerySystem
                  • String ID:
                  • API String ID: 3562636166-0
                  • Opcode ID: f596ce138e3d89dce1433194de395394d103d524973882ede55c31bec7cac28a
                  • Instruction ID: 7e47ce736979ccfd431bce62959e7c0ab9eccc8dab2a3973706a8db7f03f9d05
                  • Opcode Fuzzy Hash: f596ce138e3d89dce1433194de395394d103d524973882ede55c31bec7cac28a
                  • Instruction Fuzzy Hash: CB119D71409784AFDB228F21DC44A62FFB4FF06310F0885DBEE854B662D275A858DB62
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • AdjustTokenPrivileges.KERNELBASE(?,?,?,?,?,?), ref: 05971483
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: AdjustPrivilegesToken
                  • String ID:
                  • API String ID: 2874748243-0
                  • Opcode ID: 6989a4b4f5b6292859fae41546111bdc988863a42dcd47cebf200fa28e84826a
                  • Instruction ID: b017a57be9c4a4304f9b7d5966019286e5cb3ee19cf6ce7b03d4e725e500eb58
                  • Opcode Fuzzy Hash: 6989a4b4f5b6292859fae41546111bdc988863a42dcd47cebf200fa28e84826a
                  • Instruction Fuzzy Hash: 79115A755006049FDB20CF65D884B66FFE9FF44320F0899ABEE8A8B612D275E418DB71
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetUserNameW.ADVAPI32(?,00000E2C,?,?), ref: 018FB10E
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: NameUser
                  • String ID:
                  • API String ID: 2645101109-0
                  • Opcode ID: 75f6bb60e7b0ad99f1c1fb5bcfeb14db13c1b5c0ad092e2b0375ec8c81d3cf9c
                  • Instruction ID: f057d3337917751fce66f8e685643ef695060124b23e3aae78ed81b590f56caa
                  • Opcode Fuzzy Hash: 75f6bb60e7b0ad99f1c1fb5bcfeb14db13c1b5c0ad092e2b0375ec8c81d3cf9c
                  • Instruction Fuzzy Hash: 9C016275500600ABD650DF16DC86F36FBA8FB88B20F14815AED085BB41E375F515CBE5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • NtQuerySystemInformation.NTDLL(?,?,?,?), ref: 05971889
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: InformationQuerySystem
                  • String ID:
                  • API String ID: 3562636166-0
                  • Opcode ID: a6daeea6096e39bf8effd7c812e9f10464ff509f819454a076ab928539ce07fe
                  • Instruction ID: a22f74acec12ec22c0cb7d799b0ff9ed0d153eb5ed05da9f16c273d2b63e6cde
                  • Opcode Fuzzy Hash: a6daeea6096e39bf8effd7c812e9f10464ff509f819454a076ab928539ce07fe
                  • Instruction Fuzzy Hash: 40018B31800608DFEB20DF55D885B62FFA4FF08320F18C59BDE490B616D2B9A418DB72
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID: k8y^
                  • API String ID: 0-2503320954
                  • Opcode ID: a7b45931cb7e5cf4207a7a0ad5b0012d7af87c6f8ceef89e59364d06b2139806
                  • Instruction ID: ebe85accea51d4644f705ee21646f7324b8f4a2c6f2c8505a18090426bbaaa90
                  • Opcode Fuzzy Hash: a7b45931cb7e5cf4207a7a0ad5b0012d7af87c6f8ceef89e59364d06b2139806
                  • Instruction Fuzzy Hash: B4815D78D19219CFCB18CFE5C9849ADFBBAFB4A301F10A91AD016BB248D7349942CF55
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID: :@Dr
                  • API String ID: 0-3830894600
                  • Opcode ID: da1d1ae9ecfd594d5779d1a6fd863b698067439b14ebb1c7b7b4e3034b105ec6
                  • Instruction ID: 82e136c50edfb9af521421f455d51402293fb5f50bb4b62a0915a81ca4151757
                  • Opcode Fuzzy Hash: da1d1ae9ecfd594d5779d1a6fd863b698067439b14ebb1c7b7b4e3034b105ec6
                  • Instruction Fuzzy Hash: D761BF74E15208DFDB04DFA4D5859ADBFB2FF89300F609069E80AAB358DB345A41DB64
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID: k8y^
                  • API String ID: 0-2503320954
                  • Opcode ID: d3c780e7dc134b4a1f6d74169e95c73b0e1c832e6949e15fedc511136ebe96ac
                  • Instruction ID: 01602a5b9556e78372933a9e4a7320437567e613781279339161989670a8f903
                  • Opcode Fuzzy Hash: d3c780e7dc134b4a1f6d74169e95c73b0e1c832e6949e15fedc511136ebe96ac
                  • Instruction Fuzzy Hash: C9411B78D18319CFCB58CFA6C4445ADFBBAFB4A302F00991AD066BB248D7349902CF55
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: f4e3486e233353b6d01ebc552ec3cfe2b6db57c4ef7204dbb80e6354a96811f4
                  • Instruction ID: 524e8a0ad466ad22c553b5bd728b3e59bcdbd87ff798da4cbc5b41c8400feef8
                  • Opcode Fuzzy Hash: f4e3486e233353b6d01ebc552ec3cfe2b6db57c4ef7204dbb80e6354a96811f4
                  • Instruction Fuzzy Hash: E042B434A01218CFDB14DF64C994BADBBB2FF8A301F5181A9D50AAB361DB31AD85CF51
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: b6c806b13b7f8c51e95203fb20b46a84d16d7748ba9ff7b97f099142ecd30f39
                  • Instruction ID: ba68f2fadd0247ab9fa335f0c473c909ede04ad77de38d5bec92bb1ea6b0e9f7
                  • Opcode Fuzzy Hash: b6c806b13b7f8c51e95203fb20b46a84d16d7748ba9ff7b97f099142ecd30f39
                  • Instruction Fuzzy Hash: 5342B334A01218CFDB14DF64C894BADBBB2FF8A311F5181A9D50AAB361DB31AD85CF11
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 771f38ca2295718f4f29f7218df59a6c1bd0edd9ea88b13983c18a7d67aff95d
                  • Instruction ID: b75d5b14af6c9c7dff7f940dfb225fc096eb294f34e838a80ed47fc5d6f2f957
                  • Opcode Fuzzy Hash: 771f38ca2295718f4f29f7218df59a6c1bd0edd9ea88b13983c18a7d67aff95d
                  • Instruction Fuzzy Hash: 51E16D7490920ADFCB14CFA4C9889AEBFF2FB48310B1495DDD411AB255D732BA81EF61
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 80abbe5f7adb22a949e5a76408b6a3df470bb62f81f469af04303dae1a3ae5b7
                  • Instruction ID: e8945e6809c40ae2848fdbc57e179992d58d444a7730345a73becf4a53f964cd
                  • Opcode Fuzzy Hash: 80abbe5f7adb22a949e5a76408b6a3df470bb62f81f469af04303dae1a3ae5b7
                  • Instruction Fuzzy Hash: D1E16C7490920ADFCB14CFA4C9889AEBFF2FB45310B1495DDD411AB255D332BA81EFA1
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 2a51f67664ece757bf3dc3e512dfcd3cc384f42d128e1053781474657f4622cd
                  • Instruction ID: 04d7bced425cc80dbf352b21ee43bdd98c7cea24b786fbad910df408b9bee927
                  • Opcode Fuzzy Hash: 2a51f67664ece757bf3dc3e512dfcd3cc384f42d128e1053781474657f4622cd
                  • Instruction Fuzzy Hash: 6FB15AB4D052099FCB08CFAAC5409EDFBF2FF49320B60A59ED455BB256E7349901DB24
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 05b0c9e9dcee11bce133c934d49ba93d4717e6628989f841614effddc004c61a
                  • Instruction ID: c62813327b44151e096fab0cb06db75548705d61bb87e163f1887334dbe8d830
                  • Opcode Fuzzy Hash: 05b0c9e9dcee11bce133c934d49ba93d4717e6628989f841614effddc004c61a
                  • Instruction Fuzzy Hash: 74B16378D06219CBCF08CFE6D9519AEBBB2FF85310F5085AED015BB256DB309A028F14
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 1795937338e2e8b136a7bb13efa4cda094a55ea6e10381bf9d457dae6120e318
                  • Instruction ID: 92bdafccd0d585864409c72aba70e5ab27a334fe77d614667035f9705bb77f87
                  • Opcode Fuzzy Hash: 1795937338e2e8b136a7bb13efa4cda094a55ea6e10381bf9d457dae6120e318
                  • Instruction Fuzzy Hash: 9CB16478D06219CBDF04CFE6D9509AEFBB2BF85310F5089AED055BB256DB309A028F14
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: ee9ece19d9d8a6ad4a00fee1a66baca26e2d48b0d0ce86c9601d256ab1de5d47
                  • Instruction ID: 283e2c801fb51620a4ba8c681a299ec803b3143b547be2b3cfb301c9203836a6
                  • Opcode Fuzzy Hash: ee9ece19d9d8a6ad4a00fee1a66baca26e2d48b0d0ce86c9601d256ab1de5d47
                  • Instruction Fuzzy Hash: 5CB148B8C052099FCB08CFA6C5409EDFBF2BF49320F60A69ED455BB256E7309901DB64
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 3996c5f3c6f4ea62f7a00a11e00605cbedd8ef4d29bb7979392426fc82031ab0
                  • Instruction ID: 38dbe3f7ded67c8479acf1c6e1a8bc2d6e42d32d741b7bce405481e10246d153
                  • Opcode Fuzzy Hash: 3996c5f3c6f4ea62f7a00a11e00605cbedd8ef4d29bb7979392426fc82031ab0
                  • Instruction Fuzzy Hash: 02C13C7490920ADFCB14CFA5C5848AEFBB2FF49310B25A59DD402BB215C731EA81DFA1
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 388ce646aa4b23d9361f6f797aba638eabf5d2a9ba800091a962e51f5ced4eb6
                  • Instruction ID: c0bceb8b319b3a297f121bf7025fd633dab8045fffbd1066b561cb0495e627eb
                  • Opcode Fuzzy Hash: 388ce646aa4b23d9361f6f797aba638eabf5d2a9ba800091a962e51f5ced4eb6
                  • Instruction Fuzzy Hash: 38A1F670E0921ADFCB48CFE5D5855AEBFF2BF49300F10992AD505BB264E7709A42CB94
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: de5abf690d074cc2705d2c78b0c23933d787d892b0d1112a20549fa40c4d2e31
                  • Instruction ID: b3cc5367b5e004609aee5fe2ba5aa011b6975b7527f0f05bf26bcbf5cd38df9d
                  • Opcode Fuzzy Hash: de5abf690d074cc2705d2c78b0c23933d787d892b0d1112a20549fa40c4d2e31
                  • Instruction Fuzzy Hash: 8E91D3B4E05209DFCB04DFA9D5909ADBFB2FF89300F2095AAD406AB365DB309A41DF54
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 7b675451ba934798b02ed5ebe7b177ed33babd09011a3d7e2c298f8d87f2ccd3
                  • Instruction ID: a3f5e8c26205563220a02868e58fe3d85915b1caf5e329b80a945fb257a31272
                  • Opcode Fuzzy Hash: 7b675451ba934798b02ed5ebe7b177ed33babd09011a3d7e2c298f8d87f2ccd3
                  • Instruction Fuzzy Hash: C181EFB4D05219DFCB08CFA9C984AAEFBB2BF88304F10846ED416BB254DB349A41DF55
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: c705d2feb98c452c54498194691fcfb7d131cf59f50e1c97ff5699906374395b
                  • Instruction ID: a48079ab38cd30cce2f93c5bba248436e70ee1e3644139f94a8c739e04a5cd99
                  • Opcode Fuzzy Hash: c705d2feb98c452c54498194691fcfb7d131cf59f50e1c97ff5699906374395b
                  • Instruction Fuzzy Hash: CE71CEB4D05209DFCB08CFA9C984AAEFBB2BF88304F10856ED416BB254DB359A41DF55
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 8b7f2ed40f5b1824b9c907c4083eed0c373228c3a492575aea0042e096328d95
                  • Instruction ID: f072459d4fa82bb26979b5969306ef0d264e0db78e899ce80677b5762caf2ce1
                  • Opcode Fuzzy Hash: 8b7f2ed40f5b1824b9c907c4083eed0c373228c3a492575aea0042e096328d95
                  • Instruction Fuzzy Hash: 7D5127B0D1A209DFDB44CFA5D5815EDBFF2EB8D310F20A46ED005B6254DA3499409F68
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 8b887c6c7bef4e4c486b69744ef0b4d0377231dd8d922171c1f0b487490ce7f6
                  • Instruction ID: 2c9aa447fc54e40970f3fe0d02412ace7b5c0ba8f445b22922e7432e71609178
                  • Opcode Fuzzy Hash: 8b887c6c7bef4e4c486b69744ef0b4d0377231dd8d922171c1f0b487490ce7f6
                  • Instruction Fuzzy Hash: 67516471E142198FDF08CFA5C850AAEFBF2FB88302F24916ED405B7210D7349A41DBA4
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 776d4de5b25078580ad974993c9f72fe34c3c4c4e3f58f9599027d101a042b10
                  • Instruction ID: f8a9dd9de2af1592317bbaef782497f932444473db8170e7642798930bbb25ff
                  • Opcode Fuzzy Hash: 776d4de5b25078580ad974993c9f72fe34c3c4c4e3f58f9599027d101a042b10
                  • Instruction Fuzzy Hash: 0641F570D056098FDB09DFAAC8446AEFFF2AF85300F14C17EC804AB255DB741A46DB40
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 2bcb45b3b7af519a3e3157d9b97ea47f574b81e554794ce7ff7363b92a6eecb0
                  • Instruction ID: 2b8df71224fc7872cdc072fbdbe7bfb9f4ab13676be8fa5db7a2fd5b4cf51ec4
                  • Opcode Fuzzy Hash: 2bcb45b3b7af519a3e3157d9b97ea47f574b81e554794ce7ff7363b92a6eecb0
                  • Instruction Fuzzy Hash: 7131B271D056199BEB09CFAAC8446AEFBF7AF89300F14C02ED414AB255DB751946DF80
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 74efae4aa527667b4ce87d06480eeaae46b8377fb7ae41ec694ee88cb22a2ab8
                  • Instruction ID: 9c67a45835a9ebeb052bca315fdb33966644f750bdf2662f8c6cb90759747285
                  • Opcode Fuzzy Hash: 74efae4aa527667b4ce87d06480eeaae46b8377fb7ae41ec694ee88cb22a2ab8
                  • Instruction Fuzzy Hash: DA21EA71E006588BDB19CFAA98406EEFBF3AFC9310F14C06AD409A7254DA355A469B50
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID: X$kr$X$kr$X$kr
                  • API String ID: 0-1229313103
                  • Opcode ID: b50a0dbefc37a40d3300a52f9725ca915e3cc4a31f37999bb3c3b7dfc2848524
                  • Instruction ID: cdb672f024c4bcf2b87f8fee88c52828a4cb1a5f170e99dd2e867304b7e9d337
                  • Opcode Fuzzy Hash: b50a0dbefc37a40d3300a52f9725ca915e3cc4a31f37999bb3c3b7dfc2848524
                  • Instruction Fuzzy Hash: 11518F74E00248DFDB58DFAAC584AADFBF2BF88300F24806AE815AB355DB749941DF51
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID: :@Dr$`5kr
                  • API String ID: 0-2548079215
                  • Opcode ID: b1d151c26d9c34529458789e2dd97b01ec841f03d451b1d7b7340c0a821263f0
                  • Instruction ID: 4d570a262e0fe60c62b6264de3ebbe8f94d1e461ead1638aab2ad1083d01cf14
                  • Opcode Fuzzy Hash: b1d151c26d9c34529458789e2dd97b01ec841f03d451b1d7b7340c0a821263f0
                  • Instruction Fuzzy Hash: AA91C174E01218CFDB54CFA9C898BADBBF2BF88310F1050A9D509AB390DB719985DF50
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID: X$kr$X$kr
                  • API String ID: 0-2690305392
                  • Opcode ID: 05a4a4c27a9b961c87979ba51c665ef1bb74b82f5901a964abb092f7f503a035
                  • Instruction ID: 86e223f4822b23fb8495a061964ff2c7431088ece17ebdab7f592e1a04d3fb97
                  • Opcode Fuzzy Hash: 05a4a4c27a9b961c87979ba51c665ef1bb74b82f5901a964abb092f7f503a035
                  • Instruction Fuzzy Hash: 1B51D2B4E00248DFDB14DFA9C840AADBBF2FF88300F2481AAE815AB355DB349945DF51
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID: 54;$54;
                  • API String ID: 0-2105295863
                  • Opcode ID: 1bf3fed0060abc9e3f91933c0ee9d9798c6953cedf4d3c1d5ccdc5d93a9df33e
                  • Instruction ID: 075911873bc28061174838d35f05a0b21e1b6a7d7c5294c974db64fdcc2515f3
                  • Opcode Fuzzy Hash: 1bf3fed0060abc9e3f91933c0ee9d9798c6953cedf4d3c1d5ccdc5d93a9df33e
                  • Instruction Fuzzy Hash: AC0116789816A8DFDB64CF64CD8ABD9B7B0BB48305F5044D9A109BB691C7B46AC5CF00
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetTempFileNameW.KERNELBASE(?,00000E2C,?,?), ref: 05970F2A
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: FileNameTemp
                  • String ID:
                  • API String ID: 745986568-0
                  • Opcode ID: c3de3b5257fdb611064b7766a9cbd99b96e9cf1d66697eef15a6c3440d4e98e9
                  • Instruction ID: 761e76178234f2098348f7c46666e7c790cd717dac25d3857bd0bdcc5d7933bc
                  • Opcode Fuzzy Hash: c3de3b5257fdb611064b7766a9cbd99b96e9cf1d66697eef15a6c3440d4e98e9
                  • Instruction Fuzzy Hash: 27416E6240E3C05FD7038B358C65A61BFB4AF47610F0E85DBD8C49F5A3D2646919C7B2
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • DuplicateHandle.KERNELBASE(?,00000E2C), ref: 0597115B
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: DuplicateHandle
                  • String ID:
                  • API String ID: 3793708945-0
                  • Opcode ID: 1e8d033fa0184a885b639e1d9126b83fb9a1e27124e071388f474fa930589d63
                  • Instruction ID: b282549eb4b536870b2608d538ccfc448634c86ee6a42d7abe3fdf5895fb10b9
                  • Opcode Fuzzy Hash: 1e8d033fa0184a885b639e1d9126b83fb9a1e27124e071388f474fa930589d63
                  • Instruction Fuzzy Hash: 8931B471404384AFEB228B65DC45F67BFBCEF46310F04859BE985DB152D224A909DB71
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • VerLanguageNameW.KERNELBASE(?,00000E2C,?,?), ref: 018FB692
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: LanguageName
                  • String ID:
                  • API String ID: 2060303382-0
                  • Opcode ID: 13bcb1dc85a6664ee823e6e84d45ee6c565d73f82ed088917a5bcf4ac552dc1c
                  • Instruction ID: 70ad1d3e2caa771ce545874f79ed38b2223f4af2fe91154d0a849ae7823400de
                  • Opcode Fuzzy Hash: 13bcb1dc85a6664ee823e6e84d45ee6c565d73f82ed088917a5bcf4ac552dc1c
                  • Instruction Fuzzy Hash: 4E316CA540E3C06FD7138B259C61A62BF74EF87B10B0A81DBE8848B5A3D624690DC772
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • RegOpenKeyExW.KERNELBASE(?,00000E2C), ref: 018FABD5
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: Open
                  • String ID:
                  • API String ID: 71445658-0
                  • Opcode ID: 11e3936c14d67889c8751f4014d84309d34c4763d12f8c86e9460441c759b64d
                  • Instruction ID: e6c5c096d25fd1c8e198ce7c709e680750fab7488eb50047fb7e2fcd7a7f7f8c
                  • Opcode Fuzzy Hash: 11e3936c14d67889c8751f4014d84309d34c4763d12f8c86e9460441c759b64d
                  • Instruction Fuzzy Hash: E531C5B2504384AFE7228B25CC45F67BFBCEF06720F08859BEE85DB152D264A549CB71
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • CreateFileW.KERNELBASE(?,?,?,?,?,?), ref: 018FB821
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: CreateFile
                  • String ID:
                  • API String ID: 823142352-0
                  • Opcode ID: 9f61fe900ab36b365233039d06f3e88538a5f157493336bb4b6ccaf578f9b22b
                  • Instruction ID: b0c9f53be76f2e46c2008ecdf2b899d489d6bd13121e361c5e1351a391de18fc
                  • Opcode Fuzzy Hash: 9f61fe900ab36b365233039d06f3e88538a5f157493336bb4b6ccaf578f9b22b
                  • Instruction Fuzzy Hash: E2316D71505340AFE722CF65DC44F66BFE8EF45610F0884AEEA858B252D365E909CB71
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • CreateMutexW.KERNELBASE(?,?), ref: 05970429
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: CreateMutex
                  • String ID:
                  • API String ID: 1964310414-0
                  • Opcode ID: 58d9d509c8ce373e187e614c742aa3570318ee3b53a57f578a4ef255c2143876
                  • Instruction ID: 8f5a0e097782a16b16abda4f0cf6fbec6dfaeb9070f0df63f32ed7cea0e22193
                  • Opcode Fuzzy Hash: 58d9d509c8ce373e187e614c742aa3570318ee3b53a57f578a4ef255c2143876
                  • Instruction Fuzzy Hash: BD3193B1509784AFE712CB25CC84F56FFE8EF46310F18849BE984CB292D365A909CB71
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • CopyFileW.KERNELBASE(?,?,?), ref: 059706E6
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: CopyFile
                  • String ID:
                  • API String ID: 1304948518-0
                  • Opcode ID: ab45728ff0ee1ee2b2c2779d332590ba7d71dbbd9479dabaf916a2d3d687b753
                  • Instruction ID: e74f1dff0033c19b25619ae7c63f3e1f160018c4822ebd3ab5155fee7a6c5cb2
                  • Opcode Fuzzy Hash: ab45728ff0ee1ee2b2c2779d332590ba7d71dbbd9479dabaf916a2d3d687b753
                  • Instruction Fuzzy Hash: 9031907150E3C49FD7138B259C68A62BFB8AF03210F1D85DFD984CF1A3D225A808CB62
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • RegQueryValueExW.KERNELBASE(?,00000E2C,BBAEEA50,00000000,00000000,00000000,00000000), ref: 018FACD8
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: QueryValue
                  • String ID:
                  • API String ID: 3660427363-0
                  • Opcode ID: 07400df998d6d2a9b4b5455fb071f700ef3f9ea062187c157556414c3ae7a3a1
                  • Instruction ID: e72026423da6fe6c9d8be1c585608b54dcfee6629dc2252a184827aaf9f03e13
                  • Opcode Fuzzy Hash: 07400df998d6d2a9b4b5455fb071f700ef3f9ea062187c157556414c3ae7a3a1
                  • Instruction Fuzzy Hash: BF319375105384AFE722CB25CC84F62BFF8EF06320F18849AEA85DB153D264E549CB71
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • TerminateProcess.KERNELBASE(?,00000E2C,BBAEEA50,00000000,00000000,00000000,00000000), ref: 059717C8
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: ProcessTerminate
                  • String ID:
                  • API String ID: 560597551-0
                  • Opcode ID: 5ec93e17389c3b71bee0f727761d4c971cbf749d49532b566749f56f272d5d48
                  • Instruction ID: c9061c2e7da7a2c47dc8fb0ff12d45a3f11eb05903c10d3f4874993a96730c44
                  • Opcode Fuzzy Hash: 5ec93e17389c3b71bee0f727761d4c971cbf749d49532b566749f56f272d5d48
                  • Instruction Fuzzy Hash: EE21E472409384AFE7128B24DC85F96BFB8EF42320F0884DBE944DF192D264A909C761
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • LsaOpenPolicy.ADVAPI32(?,00000E2C), ref: 059708AF
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: OpenPolicy
                  • String ID:
                  • API String ID: 2030686058-0
                  • Opcode ID: 1ec2f0cc60e1d778a5eca537f1a91bac30c170f086d8f956d2107c433ac41609
                  • Instruction ID: afeb1bde0da94ec0d3fcd66cc9427e85d67a8e6559286aba2d97759f36baf40d
                  • Opcode Fuzzy Hash: 1ec2f0cc60e1d778a5eca537f1a91bac30c170f086d8f956d2107c433ac41609
                  • Instruction Fuzzy Hash: B3219E72504344AFE721CB24DC45FA7FFACEF45310F18849BEE449B152D225A808CB61
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetTokenInformation.KERNELBASE(?,00000E2C,BBAEEA50,00000000,00000000,00000000,00000000), ref: 05970B40
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: InformationToken
                  • String ID:
                  • API String ID: 4114910276-0
                  • Opcode ID: 1e4ccda7812d07af5b152f48405e2e1172447dd72fdc5bc4291286c5bed3c0ba
                  • Instruction ID: 60f6e1d1224e2a3c0884d5235281b9eef66e520e3338767d8863709927897cee
                  • Opcode Fuzzy Hash: 1e4ccda7812d07af5b152f48405e2e1172447dd72fdc5bc4291286c5bed3c0ba
                  • Instruction Fuzzy Hash: 1821A571104344AFEB21CF65DC85FA7BFBCEF06310F04849BE9459B152D224A544CB71
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • DuplicateHandle.KERNELBASE(?,00000E2C), ref: 0597115B
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: DuplicateHandle
                  • String ID:
                  • API String ID: 3793708945-0
                  • Opcode ID: 537f5e6f76bb5728e72b3a47b2d46848f3ea4efa24360c9938d9a4370399ae01
                  • Instruction ID: 0f7d8bdcc96b9161254bc6b05c9f068ef147600ec861369ed981d7c43c6583ec
                  • Opcode Fuzzy Hash: 537f5e6f76bb5728e72b3a47b2d46848f3ea4efa24360c9938d9a4370399ae01
                  • Instruction Fuzzy Hash: 8E21CF72500208AFEB21DF64DC84F6BFBACEF44320F14896BEE459B251D670A408DB71
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetFileType.KERNELBASE(?,00000E2C,BBAEEA50,00000000,00000000,00000000,00000000), ref: 018FB90D
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: FileType
                  • String ID:
                  • API String ID: 3081899298-0
                  • Opcode ID: 792ad40b2f49a466b768c132b2f5edac5f30c65f92195329478a892f95340fda
                  • Instruction ID: c22520ad7e93036adeb6f57efd6a640383e312a7fa3f39ee44389a0ffcc26f1e
                  • Opcode Fuzzy Hash: 792ad40b2f49a466b768c132b2f5edac5f30c65f92195329478a892f95340fda
                  • Instruction Fuzzy Hash: 1421D8B55093806FE7138B25DC41B62BFA8EF47720F1884DBEE849B193D2646909C771
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetUserNameW.ADVAPI32(?,00000E2C,?,?), ref: 018FB10E
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: NameUser
                  • String ID:
                  • API String ID: 2645101109-0
                  • Opcode ID: 6e38915abd81c6dda921587fff6489ef2531d8150b0f1469b1c4ad14e6e3e4f6
                  • Instruction ID: 5a5acfea5574456acccf9096e680a900bc02092f2135561496843aa6f8a2c58f
                  • Opcode Fuzzy Hash: 6e38915abd81c6dda921587fff6489ef2531d8150b0f1469b1c4ad14e6e3e4f6
                  • Instruction Fuzzy Hash: C521A4714497C06FD3138B259C51B22BFB8EF87610F0A81DBE884CB653D225A919C7B2
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • CreateFileW.KERNELBASE(?,?,?,?,?,?), ref: 018FB821
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: CreateFile
                  • String ID:
                  • API String ID: 823142352-0
                  • Opcode ID: 41360f40beacbb777e058b1cfe8d5eade9dedc963382037d40699d198e920d53
                  • Instruction ID: 0281c06e73fe1e2a780a9cfacb123fb9e32d5adfffb105e41901f8a80f4e1112
                  • Opcode Fuzzy Hash: 41360f40beacbb777e058b1cfe8d5eade9dedc963382037d40699d198e920d53
                  • Instruction Fuzzy Hash: 43219C75500204AFEB21DF29CC84B66FFE8EF44710F14886EEA858B652D371E504CB71
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • DeleteFileW.KERNELBASE(?), ref: 05971240
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: DeleteFile
                  • String ID:
                  • API String ID: 4033686569-0
                  • Opcode ID: 157e761d7203be71321995061a6005f735a60cec774a69d1599af4f8ee132f1e
                  • Instruction ID: baa504f50ddb1149b9aea54d93142598ae498f0036b30eceb9dd6bc56d82962b
                  • Opcode Fuzzy Hash: 157e761d7203be71321995061a6005f735a60cec774a69d1599af4f8ee132f1e
                  • Instruction Fuzzy Hash: 9821B0725093849FDB128B25DC91A92BFB8EF06250F0984DBDC85CF263D225A908CB61
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • RegOpenKeyExW.KERNELBASE(?,00000E2C), ref: 018FABD5
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: Open
                  • String ID:
                  • API String ID: 71445658-0
                  • Opcode ID: c952c37271d842ce5252da4954dd4f4af2a8f3363171b8f0e592cdb997ace77c
                  • Instruction ID: 013c406920415e148ddb110789663164665ea56523034e1500f6717424e54e16
                  • Opcode Fuzzy Hash: c952c37271d842ce5252da4954dd4f4af2a8f3363171b8f0e592cdb997ace77c
                  • Instruction Fuzzy Hash: A521AEB2500708AFE7219B29CC84F6BFBECEF04720F14895BEE45DB241D664E5088BB1
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • CreateMutexW.KERNELBASE(?,?), ref: 05970429
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: CreateMutex
                  • String ID:
                  • API String ID: 1964310414-0
                  • Opcode ID: 48abca7c4649aab7226ff8f471ffe7d2105f37ab7e3bc7444fb5f07acd993e1e
                  • Instruction ID: 35c9b4d23078cc44a07a667e5286304d116196678d72f4be71ca58ed8b26128e
                  • Opcode Fuzzy Hash: 48abca7c4649aab7226ff8f471ffe7d2105f37ab7e3bc7444fb5f07acd993e1e
                  • Instruction Fuzzy Hash: 3A21CFB1604204AFE720DF25CC88F66FBE8EF44310F14846AED898B241E770E805CB71
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • LsaOpenPolicy.ADVAPI32(?,00000E2C), ref: 059708AF
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: OpenPolicy
                  • String ID:
                  • API String ID: 2030686058-0
                  • Opcode ID: 81af2dd2e775cda6597320efddd2038ef2cc4fef4e04693f08471002026a1b63
                  • Instruction ID: 4356a18e65c1a6727dce7867dc80b192a933b374ee30e3add2e26d97db92f41b
                  • Opcode Fuzzy Hash: 81af2dd2e775cda6597320efddd2038ef2cc4fef4e04693f08471002026a1b63
                  • Instruction Fuzzy Hash: 2821C071500308AFEB20DF29DC45FABFBACEF44710F14886BEE459B241D675A4098BB5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • WriteFile.KERNELBASE(?,00000E2C,BBAEEA50,00000000,00000000,00000000,00000000), ref: 018FBBD9
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: FileWrite
                  • String ID:
                  • API String ID: 3934441357-0
                  • Opcode ID: ce9de4fdd98c1d3dcc48dbfc4736458805e618350e308a7abe9b0396ddcacbdd
                  • Instruction ID: 60dc25b8acf471819ec6acbf1be6993a4803d3bf9a47c05953c644eb13f93726
                  • Opcode Fuzzy Hash: ce9de4fdd98c1d3dcc48dbfc4736458805e618350e308a7abe9b0396ddcacbdd
                  • Instruction Fuzzy Hash: 05219F72405380AFEB22CF65DC84F57FFB8EF46310F18849BEA459B152C264A508CB71
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetTokenInformation.KERNELBASE(?,00000E2C,BBAEEA50,00000000,00000000,00000000,00000000), ref: 05970B40
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: InformationToken
                  • String ID:
                  • API String ID: 4114910276-0
                  • Opcode ID: d3e9aaf3aabab0d2228047d33ea9837f14bd16eee3fad35e9fc6a3a0bf878444
                  • Instruction ID: b2b0e149767eddd90966cc822cc904ee53ebe7773eb79360a9d4c5f63bf37de0
                  • Opcode Fuzzy Hash: d3e9aaf3aabab0d2228047d33ea9837f14bd16eee3fad35e9fc6a3a0bf878444
                  • Instruction Fuzzy Hash: 68119D71500204AFEB21CF65DC85FABFBACEF05324F14886BEA459B251D674A5088BB1
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • RegQueryValueExW.KERNELBASE(?,00000E2C,BBAEEA50,00000000,00000000,00000000,00000000), ref: 018FACD8
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: QueryValue
                  • String ID:
                  • API String ID: 3660427363-0
                  • Opcode ID: 1500497c535b5803c5f3189f5247608c11146d33f5401836926aa90f5914d73f
                  • Instruction ID: 5f592e32fc417987fb5ecea7dbd37893baddded020e40790bfd9da8c5c171a2f
                  • Opcode Fuzzy Hash: 1500497c535b5803c5f3189f5247608c11146d33f5401836926aa90f5914d73f
                  • Instruction Fuzzy Hash: 96215C75600604AFEB21DF19DC84F67BBECEF04720F14846AEA49DB651D660E509CA71
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • FindCloseChangeNotification.KERNELBASE(?), ref: 0597153C
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: ChangeCloseFindNotification
                  • String ID:
                  • API String ID: 2591292051-0
                  • Opcode ID: e982e34596c6d217618af529b804fcfce592970bd4e5c95bc1855bafb6e20789
                  • Instruction ID: 924c6e0aeba899b795437e8ef2ea5245b3592086c220d817190a62a4b598bb56
                  • Opcode Fuzzy Hash: e982e34596c6d217618af529b804fcfce592970bd4e5c95bc1855bafb6e20789
                  • Instruction Fuzzy Hash: 5021D1725093C05FDB028B25DC94B92BFB4AF43224F0880DBED858F663D274A908CB62
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • K32EnumProcesses.KERNEL32(?,?,?,BBAEEA50,00000000,?,?,?,?,?,?,?,?,72F43C38), ref: 059715F6
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: EnumProcesses
                  • String ID:
                  • API String ID: 84517404-0
                  • Opcode ID: a002f53ae1027432ac45a798ee72922af2885d35f583aa332637926701da7fcc
                  • Instruction ID: 7713e025c7848b1eb9dd480db31f75fa348fb9bd30167be2ad8589594da3c85c
                  • Opcode Fuzzy Hash: a002f53ae1027432ac45a798ee72922af2885d35f583aa332637926701da7fcc
                  • Instruction Fuzzy Hash: 0C215E715093849FD712CB65DC85B96BFF8AF06220F0984EBE985CF162D274A908DB61
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • VirtualProtect.KERNELBASE(?,?,?,?), ref: 05970125
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: ProtectVirtual
                  • String ID:
                  • API String ID: 544645111-0
                  • Opcode ID: 4a5ba302d7b367b16a025f801469e36d2a8948e75fc6f88fb87cbd6bd839daf3
                  • Instruction ID: 041b8bfb1a392936d1ad97db178c7175fd9645496ef59662bf896bc3e9b954d6
                  • Opcode Fuzzy Hash: 4a5ba302d7b367b16a025f801469e36d2a8948e75fc6f88fb87cbd6bd839daf3
                  • Instruction Fuzzy Hash: 12219076509384AFDB228F25DC54BA2FFB4EF06310F0884DEED858F662D265A418DB61
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • LoadLibraryShim.MSCOREE(?,?,?,?), ref: 018FBD55
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: LibraryLoadShim
                  • String ID:
                  • API String ID: 1475914169-0
                  • Opcode ID: 8c27af4459d099bcc4df807f442fb8b8f1ca457482a7a74fe6b1215db2a8b219
                  • Instruction ID: 78778840c73e4fe5d416c5195a56322abafda122fbe04fe588b78f465bc252dd
                  • Opcode Fuzzy Hash: 8c27af4459d099bcc4df807f442fb8b8f1ca457482a7a74fe6b1215db2a8b219
                  • Instruction Fuzzy Hash: 432193755093809FD7228E15DC44B62BFF8EF06314F18808EEE85CB293D265E508CB72
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetFileVersionInfoSizeW.KERNELBASE(?,?), ref: 018FB417
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: FileInfoSizeVersion
                  • String ID:
                  • API String ID: 1661704012-0
                  • Opcode ID: b35648ee2b4aea040a918e7d6c9e1de3d248d9a254cd2cfa1816e81a8291ce30
                  • Instruction ID: 7444d01a877ffb63f03ddef0a6647c124b1411dbd4e3ec1e27a35e6a1b047d3e
                  • Opcode Fuzzy Hash: b35648ee2b4aea040a918e7d6c9e1de3d248d9a254cd2cfa1816e81a8291ce30
                  • Instruction Fuzzy Hash: 192181B14093849FD712CF25DC85B52BFA4EF56314F0984DAED849F163D274A909CB61
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • PostMessageW.USER32(?,?,?,?), ref: 059719D5
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: MessagePost
                  • String ID:
                  • API String ID: 410705778-0
                  • Opcode ID: f4a0c30040d1c8774fbd3acd3e1a66e7760e57e3ccb22c1ea9d81ca958ad2b31
                  • Instruction ID: 3566499888d03c944954be53f4926079282de6eb2467cc3eed0c186a27b8ec0e
                  • Opcode Fuzzy Hash: f4a0c30040d1c8774fbd3acd3e1a66e7760e57e3ccb22c1ea9d81ca958ad2b31
                  • Instruction Fuzzy Hash: 24218C714097C0AFDB138B25DC44A62BFB4EF07210F0985DBE9858F563D265A858DB62
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • TerminateProcess.KERNELBASE(?,00000E2C,BBAEEA50,00000000,00000000,00000000,00000000), ref: 059717C8
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: ProcessTerminate
                  • String ID:
                  • API String ID: 560597551-0
                  • Opcode ID: 93089b7cad16f41ae2e098cd01e2d2bc8c14b83c07c7d6c70445f116da34859c
                  • Instruction ID: a1ee0f382c499c83ea2706116911f86b0155595468860f3b05c952ce09b9efe2
                  • Opcode Fuzzy Hash: 93089b7cad16f41ae2e098cd01e2d2bc8c14b83c07c7d6c70445f116da34859c
                  • Instruction Fuzzy Hash: 06119E71500604AFEB10DF29DC85FAABBACEF45720F1884ABEE05DB241D674A909DB71
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 018FA61A
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: DuplicateHandle
                  • String ID:
                  • API String ID: 3793708945-0
                  • Opcode ID: 300fbfa50cd36c294b2fed3b3a02562083b1a774ad08d9eb4924f3f790df8bb7
                  • Instruction ID: 73f5210002868c44e731a5b368e791ba620335d3690c3990621890735cdc7c63
                  • Opcode Fuzzy Hash: 300fbfa50cd36c294b2fed3b3a02562083b1a774ad08d9eb4924f3f790df8bb7
                  • Instruction Fuzzy Hash: 42117271409380AFDB228F55DC44A62FFF4EF4A720F08859EEE898B562C275A518DB61
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • SetFileAttributesW.KERNELBASE(?,?), ref: 059707C3
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: AttributesFile
                  • String ID:
                  • API String ID: 3188754299-0
                  • Opcode ID: 8c033309090da4b6e709bb3c05c9beeb19bfb007795834456995d15ca7b7bed7
                  • Instruction ID: e5fe3589afe91485a6a09380cadbb06fb6dd59e794548ee8b3487e1bd655ed66
                  • Opcode Fuzzy Hash: 8c033309090da4b6e709bb3c05c9beeb19bfb007795834456995d15ca7b7bed7
                  • Instruction Fuzzy Hash: 4811D0B5509384AFDB11CF25DC89B52BFE8EF06220F0884AAED45CB252D275E849CB61
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • SetErrorMode.KERNELBASE(?), ref: 018FA6CC
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: ErrorMode
                  • String ID:
                  • API String ID: 2340568224-0
                  • Opcode ID: b6916e99568a890f38b840e1f5d60990e8edb2e4d53be4fad4bc94b6930d5257
                  • Instruction ID: 3135a54b0433e7ab22af16b983f59b7d51f96fc37f4d7b50c70a853db4974fc0
                  • Opcode Fuzzy Hash: b6916e99568a890f38b840e1f5d60990e8edb2e4d53be4fad4bc94b6930d5257
                  • Instruction Fuzzy Hash: 13115C714093C4AFDB138B25DC94762BFB4EF47620F0980DAED849B153D2695908D772
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • WriteFile.KERNELBASE(?,00000E2C,BBAEEA50,00000000,00000000,00000000,00000000), ref: 018FBBD9
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: FileWrite
                  • String ID:
                  • API String ID: 3934441357-0
                  • Opcode ID: ab427363c4a9b059354f56b0a82a5a870c37df866accd7b979a51f4f757486c4
                  • Instruction ID: baa9441c9e24b34f6a1ff2c058e7e26808cbbb552d0fa96456eb962517f955f0
                  • Opcode Fuzzy Hash: ab427363c4a9b059354f56b0a82a5a870c37df866accd7b979a51f4f757486c4
                  • Instruction Fuzzy Hash: 5011BF71400204EFEB21DF55DC80F67FFA8EF44320F14846BEE459B252C674A5098B71
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetFileVersionInfoW.KERNELBASE(?,?,?,?), ref: 018FB4CD
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: FileInfoVersion
                  • String ID:
                  • API String ID: 2427832333-0
                  • Opcode ID: 5cb8ed65d813c7101ad072e9565606af5b9c7044a193ad335b95ea84cdcf9c16
                  • Instruction ID: d690b451a098d1904bdaa863ee3be2abed1c96918e17c36e90b6f7c8752349d8
                  • Opcode Fuzzy Hash: 5cb8ed65d813c7101ad072e9565606af5b9c7044a193ad335b95ea84cdcf9c16
                  • Instruction Fuzzy Hash: 72119371505380AFDB228F19DC85F62FFF8EF56710F08809EEE858B653D265A508CB61
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • FindCloseChangeNotification.KERNELBASE(?), ref: 018FA32C
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: ChangeCloseFindNotification
                  • String ID:
                  • API String ID: 2591292051-0
                  • Opcode ID: a1194928c72c7c3b45598df5705a05c0d399ff5a8ed0170a7033923fb2e0f142
                  • Instruction ID: ccc3f28f65841727ea5f47162098522e85eb7cb8f3353189418c963fbb86106a
                  • Opcode Fuzzy Hash: a1194928c72c7c3b45598df5705a05c0d399ff5a8ed0170a7033923fb2e0f142
                  • Instruction Fuzzy Hash: 64119871509380AFDB128F25DC94B56BFB8EF46220F0884DBED858F653D2759908C761
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • CopyFileW.KERNELBASE(?,?,?), ref: 059706E6
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: CopyFile
                  • String ID:
                  • API String ID: 1304948518-0
                  • Opcode ID: 94870480cdec18d420aaa652c07b3daa4936617218a97ab85d173f90b4321dd1
                  • Instruction ID: 0138e73bf3c0ee1ffdd4ef00b5394864f9a1dad66a505c68d690ebe16edb11e7
                  • Opcode Fuzzy Hash: 94870480cdec18d420aaa652c07b3daa4936617218a97ab85d173f90b4321dd1
                  • Instruction Fuzzy Hash: CC117C716012049FEB50DF2ADC89B66FBE8FB44220F1889ABDD49DB642D671E404CE71
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetFileType.KERNELBASE(?,00000E2C,BBAEEA50,00000000,00000000,00000000,00000000), ref: 018FB90D
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: FileType
                  • String ID:
                  • API String ID: 3081899298-0
                  • Opcode ID: 909493a0c86058a627930334c16969432d1e91779923bd63a2eb03af53da16b1
                  • Instruction ID: 26909fb6baa9f0efa326737e067ffaf92976c6238b435742cc26e26b44e800d1
                  • Opcode Fuzzy Hash: 909493a0c86058a627930334c16969432d1e91779923bd63a2eb03af53da16b1
                  • Instruction Fuzzy Hash: 2901D271500604EEEB11DB19DC85F66FFA8EF05720F14C09BEF459B241D6B4A5098A71
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • K32EnumProcesses.KERNEL32(?,?,?,BBAEEA50,00000000,?,?,?,?,?,?,?,?,72F43C38), ref: 059715F6
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: EnumProcesses
                  • String ID:
                  • API String ID: 84517404-0
                  • Opcode ID: 8b3a0c6aa58601310600a8b651e46effa38a11afb6142c6a7b38a5392dcec012
                  • Instruction ID: 12d89fff6a447482b96525b0d5b1005426ddba1c08ffb39fac8a62c6bdfc33c6
                  • Opcode Fuzzy Hash: 8b3a0c6aa58601310600a8b651e46effa38a11afb6142c6a7b38a5392dcec012
                  • Instruction Fuzzy Hash: C511AD715002089FDB20CF69D884B66FBE8EF04320F18C4ABDE0A8B651D270E408DB61
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • SetFileAttributesW.KERNELBASE(?,?), ref: 059707C3
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: AttributesFile
                  • String ID:
                  • API String ID: 3188754299-0
                  • Opcode ID: 1218306d8262ec71fc2cd830a2adb2df096ef6d42fb1ada1e820c25a431c92cb
                  • Instruction ID: 0d7f1c88434431dbab11944aa4bded2f2cf2f81d9966eba23046a88a879b71f7
                  • Opcode Fuzzy Hash: 1218306d8262ec71fc2cd830a2adb2df096ef6d42fb1ada1e820c25a431c92cb
                  • Instruction Fuzzy Hash: 24018C719002449FDB10CF29DC88766FFE8EF04220F1884ABDD09DB656E675E808CF61
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: LongWindow
                  • String ID:
                  • API String ID: 1378638983-0
                  • Opcode ID: 13f6bd1bc9fac6fe4e44e24247c90b0b0e09187b7b137b329219d21dd153563a
                  • Instruction ID: 7cea48b8f1eed6db1c8a9e61d143efbb95e57181ab202b91391419e8c917aac4
                  • Opcode Fuzzy Hash: 13f6bd1bc9fac6fe4e44e24247c90b0b0e09187b7b137b329219d21dd153563a
                  • Instruction Fuzzy Hash: 66117071409784AFD7228F15DC84B52FFF4EF06320F08C49AEE894B262D275A518CB62
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • DeleteFileW.KERNELBASE(?), ref: 05971240
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: DeleteFile
                  • String ID:
                  • API String ID: 4033686569-0
                  • Opcode ID: 355b2137bb11eef0f5ae8808c22740b925fbfa9f0b5502447ae575dc79cff072
                  • Instruction ID: ea879fdcbd279a99149e6d07d75afc14e685a2a2d8bfd1300874cbfceec1a4c6
                  • Opcode Fuzzy Hash: 355b2137bb11eef0f5ae8808c22740b925fbfa9f0b5502447ae575dc79cff072
                  • Instruction Fuzzy Hash: 73019A71A00208DFDB50CF2AE885766FFE8EF44220F18C4ABDD09CB652D674E808DB61
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetTempFileNameW.KERNELBASE(?,00000E2C,?,?), ref: 05970F2A
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: FileNameTemp
                  • String ID:
                  • API String ID: 745986568-0
                  • Opcode ID: 3516997af0458968458a3aaf307984dba94916715d3d2ecf4b5f5e14951fc6a7
                  • Instruction ID: ffb250a4e067ddff9001471dac03bc1bb6be2cf3e3d8506f0fb8a9e015e8e212
                  • Opcode Fuzzy Hash: 3516997af0458968458a3aaf307984dba94916715d3d2ecf4b5f5e14951fc6a7
                  • Instruction Fuzzy Hash: 9C0171B2900600ABD750DF16DC85F36FBA8FB88B20F14856AED089B741E331B915CBA5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetFileVersionInfoW.KERNELBASE(?,?,?,?), ref: 018FB4CD
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: FileInfoVersion
                  • String ID:
                  • API String ID: 2427832333-0
                  • Opcode ID: 60a2c79421c112e067cfc7f4fc2220096b94f89c364b8cbb22b95363535fda06
                  • Instruction ID: d4070692d85ec472e71d5b6e30072840e48c920b6379343a196aa23e8024fdd4
                  • Opcode Fuzzy Hash: 60a2c79421c112e067cfc7f4fc2220096b94f89c364b8cbb22b95363535fda06
                  • Instruction Fuzzy Hash: 75016D755006449FDB20DE19D985B66FFE4EF14720F08809EDE4A8B652D275E508CB61
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • LoadLibraryShim.MSCOREE(?,?,?,?), ref: 018FBD55
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: LibraryLoadShim
                  • String ID:
                  • API String ID: 1475914169-0
                  • Opcode ID: e10f64f3d65457d0eac0377dd287da383823a03d0fff3969661e4091fc319f67
                  • Instruction ID: 364c4c8d224665e26842e45ceb644986e1bb81cb6db544114e198917a0aff0e5
                  • Opcode Fuzzy Hash: e10f64f3d65457d0eac0377dd287da383823a03d0fff3969661e4091fc319f67
                  • Instruction Fuzzy Hash: 14016D71500604DFDB60EE19D885B62FFE8EF04720F18845EDE49CB652D265E508CA73
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 018FA61A
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: DuplicateHandle
                  • String ID:
                  • API String ID: 3793708945-0
                  • Opcode ID: b817cbd29e5dd069673fd8f28b5a45f2a5e2bb7c3a6b09ff7dd356223974d4d1
                  • Instruction ID: bf070d6cfdfc86a274a0d54b54e3ca119539de0793edc1d5e67c8ff4967294a4
                  • Opcode Fuzzy Hash: b817cbd29e5dd069673fd8f28b5a45f2a5e2bb7c3a6b09ff7dd356223974d4d1
                  • Instruction Fuzzy Hash: 98016D71400604EFDB218F55D844B56FFE0EF48720F18C9AEDE498B612C276E518DF61
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetFileVersionInfoSizeW.KERNELBASE(?,?), ref: 018FB417
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: FileInfoSizeVersion
                  • String ID:
                  • API String ID: 1661704012-0
                  • Opcode ID: a27afb743737ad8884d5e42f5216eab008538f3d6e7f0974fbe202df2c636e1a
                  • Instruction ID: a3463ee9838dc74ab7f4bd1514a67c9f3e9f84ab2d071301a5b2917f13b45b4d
                  • Opcode Fuzzy Hash: a27afb743737ad8884d5e42f5216eab008538f3d6e7f0974fbe202df2c636e1a
                  • Instruction Fuzzy Hash: 77019A71900244DFEB10CF29D984766FFE4EF04320F1884AADE09CB602D274A508CBA2
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • FindCloseChangeNotification.KERNELBASE(?), ref: 0597153C
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: ChangeCloseFindNotification
                  • String ID:
                  • API String ID: 2591292051-0
                  • Opcode ID: 7c2f1908400f24b61379db69515e4d21c6ba5620f47e79c811cf7e29973a5e44
                  • Instruction ID: 3be87134bc04b3c638ead20d26b610dd47adea8d9c7f785d905abf3db1e448a8
                  • Opcode Fuzzy Hash: 7c2f1908400f24b61379db69515e4d21c6ba5620f47e79c811cf7e29973a5e44
                  • Instruction Fuzzy Hash: 5401DF719002449FDB14CF29E885B66FFE4EF40220F18C4ABDE4A8F612C274E408DB72
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • VerLanguageNameW.KERNELBASE(?,00000E2C,?,?), ref: 018FB692
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: LanguageName
                  • String ID:
                  • API String ID: 2060303382-0
                  • Opcode ID: 961f77382806b6ad32d77339ee95e92c98d2cfc38ff9005cbc9442195caa2283
                  • Instruction ID: 2a611ea97bc1efe73bd5f41d62d8df8d10716ee4c5822270170afed74d102877
                  • Opcode Fuzzy Hash: 961f77382806b6ad32d77339ee95e92c98d2cfc38ff9005cbc9442195caa2283
                  • Instruction Fuzzy Hash: 65016276500600ABD650DF16DC86F36FBA8FB88B20F14815AED085BB41E371F515CBE5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • FindCloseChangeNotification.KERNELBASE(?), ref: 018FA32C
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: ChangeCloseFindNotification
                  • String ID:
                  • API String ID: 2591292051-0
                  • Opcode ID: 200c371bd6cb53e67d5cf943152c7c8ca1364823d966776516518438710c8193
                  • Instruction ID: 1c41d87dacf7d9da0af4012ddb9e22eb4f12322cfa9dd46649914cf99924aaca
                  • Opcode Fuzzy Hash: 200c371bd6cb53e67d5cf943152c7c8ca1364823d966776516518438710c8193
                  • Instruction Fuzzy Hash: 5E0178719042449FDB148F29D884766FFE8EF44720F18C4AADE09CB656D6B5A908CA62
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • VirtualProtect.KERNELBASE(?,?,?,?), ref: 05970125
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: ProtectVirtual
                  • String ID:
                  • API String ID: 544645111-0
                  • Opcode ID: fa87f014466557234ef4dada74df98aa4f2e39c2484696e2653b0e6dfdef2473
                  • Instruction ID: 9fc6f6f6cefb970e6fdff8e617de1d7c9f77328dc21740cac2efa886b6773b1b
                  • Opcode Fuzzy Hash: fa87f014466557234ef4dada74df98aa4f2e39c2484696e2653b0e6dfdef2473
                  • Instruction Fuzzy Hash: A5015A359006449FDB218F19D989B66FFA4EF04320F18C4ABDE4A4B651D2B5A418DF62
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • PostMessageW.USER32(?,?,?,?), ref: 059719D5
                  Memory Dump Source
                  • Source File: 00000000.00000002.231077313.0000000005970000.00000040.00000001.sdmp, Offset: 05970000, based on PE: false
                  Similarity
                  • API ID: MessagePost
                  • String ID:
                  • API String ID: 410705778-0
                  • Opcode ID: 076a36322801574a4205e06d6bb1d8a3ba94e4ff9067ff6530991fbe7dd7e0cc
                  • Instruction ID: 6b0b0f8a2e10f8916996080d3ff49214682fec3d16906cd422fc02f780e45d33
                  • Opcode Fuzzy Hash: 076a36322801574a4205e06d6bb1d8a3ba94e4ff9067ff6530991fbe7dd7e0cc
                  • Instruction Fuzzy Hash: D701BC31400644DFDB20CF15D884B62FFA4EF04320F18C49ADE494B612D2B1A008DB62
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: LongWindow
                  • String ID:
                  • API String ID: 1378638983-0
                  • Opcode ID: 3bae8dc773cc58ebef0addda3ee8d00a0fe160a8df917856caf324daf4151f64
                  • Instruction ID: 06076ee2c2537297c16435e6af5e6111384fd796f63aebd63a69287f5798b47a
                  • Opcode Fuzzy Hash: 3bae8dc773cc58ebef0addda3ee8d00a0fe160a8df917856caf324daf4151f64
                  • Instruction Fuzzy Hash: FB01AD35400604DFDB208F19D984722FFA0EF04720F18C09ADE494B616D2B5A51CCF72
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • SetErrorMode.KERNELBASE(?), ref: 018FA6CC
                  Memory Dump Source
                  • Source File: 00000000.00000002.226893181.00000000018FA000.00000040.00000001.sdmp, Offset: 018FA000, based on PE: false
                  Similarity
                  • API ID: ErrorMode
                  • String ID:
                  • API String ID: 2340568224-0
                  • Opcode ID: 8fccf9a50dbbbce795e37da59631f37d36bfe8c0b1b358de364a47f335cba662
                  • Instruction ID: 470e33bfdaf1b2fd82435c3b8371913e586905441e5ca9211637637b498d7ac9
                  • Opcode Fuzzy Hash: 8fccf9a50dbbbce795e37da59631f37d36bfe8c0b1b358de364a47f335cba662
                  • Instruction Fuzzy Hash: 3FF0A934804644DFDB20DF19D884762FFA4EF44331F18C0AADE498B616E2B9E548CEB2
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID: :@Dr
                  • API String ID: 0-3830894600
                  • Opcode ID: d6038ec0c6f54ceaeee06eb49121930c1d0bd3fcce2801b75b6c9dd852503ce1
                  • Instruction ID: 46782c0789625d757f63d6bcb16191ea8ddfa722128584520dacd5a75e668586
                  • Opcode Fuzzy Hash: d6038ec0c6f54ceaeee06eb49121930c1d0bd3fcce2801b75b6c9dd852503ce1
                  • Instruction Fuzzy Hash: C891D374E00219CFDB54DFA9C498BADBBF2BB89310F1081ADD509AB354DB719981DF90
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID: K%^S
                  • API String ID: 0-2240672959
                  • Opcode ID: 4b4d912faf4427287283fd395c61645e996aadafac4bab8df4166e8139b0a895
                  • Instruction ID: 4d7f36a5095cabc6886d36820549dbdad1e8388d04ead602e728faab0ced1d65
                  • Opcode Fuzzy Hash: 4b4d912faf4427287283fd395c61645e996aadafac4bab8df4166e8139b0a895
                  • Instruction Fuzzy Hash: E251D0B4D05219EFCB04DFA8D585AAEBFB2BF49310F2481AED405A7315D731AA80DB90
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID: K%^S
                  • API String ID: 0-2240672959
                  • Opcode ID: d3538a4ec6f8b8e4fe474152fb0ddd746c043a32cd39b1006ee1d382c6060ebb
                  • Instruction ID: 00389b9050aa826a458e61478d2e7abf1c0d2bc7e94006581386b8d0c16f2916
                  • Opcode Fuzzy Hash: d3538a4ec6f8b8e4fe474152fb0ddd746c043a32cd39b1006ee1d382c6060ebb
                  • Instruction Fuzzy Hash: 1641C2B4D05219EFCB04DFA8D585AAEFBB2BF49310F2481AED505A7314D730AA90DF94
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID: %Cbq^
                  • API String ID: 0-1050651627
                  • Opcode ID: e7641adb49c2e4930d29871e721621f4fc90e8af2716482b9710d81a9eb7f3b2
                  • Instruction ID: 2626ccfcb455b74d13c6d0005b8ff24cff91d27b826179ffd1e7d7c117445d35
                  • Opcode Fuzzy Hash: e7641adb49c2e4930d29871e721621f4fc90e8af2716482b9710d81a9eb7f3b2
                  • Instruction Fuzzy Hash: AA119074D19209AFCB04CFE4D6909AEBBF1FF86210B11989BD416EB250DB349B00CB95
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID: %Cbq^
                  • API String ID: 0-1050651627
                  • Opcode ID: d3394cc1efe4e62184da76ecb3d78bb38319b8051684401b08979a758a0c640e
                  • Instruction ID: 2072c90c36f7067bbe72c00158eb47f70936d1c63eccf2ca02c32e0e877c992f
                  • Opcode Fuzzy Hash: d3394cc1efe4e62184da76ecb3d78bb38319b8051684401b08979a758a0c640e
                  • Instruction Fuzzy Hash: 72114C74D19209EFCB08DFA9D5416BEBBF6FF85200F1098AAD416A7244DB349B00DB95
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID: <
                  • API String ID: 0-4251816714
                  • Opcode ID: 4222d45f01a0738f4a56a3d164b0f78f55c2d79af21f592a58c2883a5bc8828b
                  • Instruction ID: 4e7f2e35d3b49b5de0f56765ce9fd437c5d8e14c8804ee48bcb4255a588d7a35
                  • Opcode Fuzzy Hash: 4222d45f01a0738f4a56a3d164b0f78f55c2d79af21f592a58c2883a5bc8828b
                  • Instruction Fuzzy Hash: 8201B270E0A329DFEB24DF24DC69B99BBB2BB49301F0081DED20A67280C7305A84CF15
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID: f]Ir
                  • API String ID: 0-3302829692
                  • Opcode ID: 4f2bcea8b2aa6508f50ab34ed6753331420477308281a8a3bae6afc52cdf58dc
                  • Instruction ID: 049487a6d04d7491b5fad7eab4e9ea6fcca7528aae1b47deadde50286fefd2f5
                  • Opcode Fuzzy Hash: 4f2bcea8b2aa6508f50ab34ed6753331420477308281a8a3bae6afc52cdf58dc
                  • Instruction Fuzzy Hash: 5BE06D34A01228CFD714CB54D444B4EB7F2BB52310F5290AD8C49AB200C734AF44CF51
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID: l.dl
                  • API String ID: 0-670203805
                  • Opcode ID: f81ad5addf9ee16bf9487018e71b4ab8dc5a73ea1f58760f0f3b3f5b5b1489a4
                  • Instruction ID: bc61e57b0e6d0320cabffdbc02e3dcd625d149df48f23c5b6639fc463170e9fa
                  • Opcode Fuzzy Hash: f81ad5addf9ee16bf9487018e71b4ab8dc5a73ea1f58760f0f3b3f5b5b1489a4
                  • Instruction Fuzzy Hash: 6BE05A78941228CBCB10CFA8C889AADBBF6FF09300F25A089D419AB725C2349940CF19
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 4828ed5d206852c0f69619dbfae14bcfcd506a09a480475e602c3d401b8658f8
                  • Instruction ID: 7c7095ca164eb202140eb16413651e97ea0fbbc3917e20ae22994d75593a5f28
                  • Opcode Fuzzy Hash: 4828ed5d206852c0f69619dbfae14bcfcd506a09a480475e602c3d401b8658f8
                  • Instruction Fuzzy Hash: 5EB1B674E0021ACFCB44DFA8C88099DFBB2FF89314F60966AD515AB358D770A946CF91
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226880222.00000000018F2000.00000040.00000001.sdmp, Offset: 018F2000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 8da35f06001124d3fd15636e939c332045bee19a1ae74221c600ad072fb125f2
                  • Instruction ID: 1ae08fb9340fe4ee48459d9762d4561559c34e48e60362cdac9727510be3b3fd
                  • Opcode Fuzzy Hash: 8da35f06001124d3fd15636e939c332045bee19a1ae74221c600ad072fb125f2
                  • Instruction Fuzzy Hash: 3161CE6250E7C28FC7878774687D554BF77AA2B33070E41CFE392CA0A3D254CA45A72A
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 8ee27b310cd19eb2b0ae7984a8cbd444bdfbc7be919eefa66a2c6c6e390e4a16
                  • Instruction ID: 79c1cb5606838bd6ed5c81c13eb062da05b3cb7e5120ad31e3e5ee5b30216611
                  • Opcode Fuzzy Hash: 8ee27b310cd19eb2b0ae7984a8cbd444bdfbc7be919eefa66a2c6c6e390e4a16
                  • Instruction Fuzzy Hash: 79518178A04218DFDB10CFA8C484AADBBF1FF4D310F1154A9E906AB3A1D775A951EF60
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: f210e12d8d6a93a361d23e099b0af58e7275a0be19eb910fd5326735f21c5413
                  • Instruction ID: 4b3849afad64010989611253633809ad1385f1693459846759b6dcfadffe0041
                  • Opcode Fuzzy Hash: f210e12d8d6a93a361d23e099b0af58e7275a0be19eb910fd5326735f21c5413
                  • Instruction Fuzzy Hash: 7F417178A00318DFDB10DFA8C484BADBBF2BB4D710F105499E506AB3A0D775A990EF64
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226908893.0000000001912000.00000040.00000001.sdmp, Offset: 01912000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 502308f662c38d7caa4325f4d4692098417798769fc85ffd95bcbbebd0bb2397
                  • Instruction ID: 4cfe5c4f340cbbc701b9ca7140952e85a505646fd750f066745744a84bfc3fcb
                  • Opcode Fuzzy Hash: 502308f662c38d7caa4325f4d4692098417798769fc85ffd95bcbbebd0bb2397
                  • Instruction Fuzzy Hash: 72319CB6549300AFD710CF09EC41A57FFE8EB88630F18C96EFD499B611D275A904CBA2
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 256eeff567fe4ee365491b473a7f1bb5d4bbe8f826f786f3e0c0311941a485cb
                  • Instruction ID: b6de766e248c76b4af2cea9331ba65ff297384e0a16266e843bacb886e2ae945
                  • Opcode Fuzzy Hash: 256eeff567fe4ee365491b473a7f1bb5d4bbe8f826f786f3e0c0311941a485cb
                  • Instruction Fuzzy Hash: 193156B0D15219DFCB04CFA9D581AEDFFB9EB89310F20946EE80AB6204D7309A009B64
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226908893.0000000001912000.00000040.00000001.sdmp, Offset: 01912000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: b57baa03f544e76a141b43b7bad6fb3cfdadac133db70a936815f78387f03f1e
                  • Instruction ID: 90f5f0d52be6e29256c3eff49ab6826d5f6317db62d32fbdd3b318cf3f618487
                  • Opcode Fuzzy Hash: b57baa03f544e76a141b43b7bad6fb3cfdadac133db70a936815f78387f03f1e
                  • Instruction Fuzzy Hash: 1F21F172549304AFD710CF09EC81E67FFA8EB85630F18C96EFD099B611D275A4048BA2
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226908893.0000000001912000.00000040.00000001.sdmp, Offset: 01912000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: bd636f556efb078695e9e6af34350ea99cb23c3209fcb59307e2b97116b9c2e0
                  • Instruction ID: 1e11bef718055bf20edd0faf925ef446b4d97f9d60bf64f46f6465672b390b2b
                  • Opcode Fuzzy Hash: bd636f556efb078695e9e6af34350ea99cb23c3209fcb59307e2b97116b9c2e0
                  • Instruction Fuzzy Hash: 8A213DB6504304BFD610CF09EC41E67FFE8EB88A60F14C92EFD4997611D271A9148BB2
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226908893.0000000001912000.00000040.00000001.sdmp, Offset: 01912000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 08fcd575bdcfdcb28804d340ec5e0059a3ea638af4bea404a24e90a3c35d524e
                  • Instruction ID: af6c8cd3afb1e43cf60cbdf93eeac58da89172d5b97b819b3857b7863ed4cb30
                  • Opcode Fuzzy Hash: 08fcd575bdcfdcb28804d340ec5e0059a3ea638af4bea404a24e90a3c35d524e
                  • Instruction Fuzzy Hash: E4214FB6544304BFD610CF49EC41E67FFE8EB88A60F14C91EFD4997610D271A9148BB2
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 98e41c275d60fdb469c0ce8d76353523b0c4768aaec3a6e883ecfec97710c609
                  • Instruction ID: 8edd9459ea7b68c39bd60b6ab8f5498488aaf5809cb3c650a70c02f3a722bb05
                  • Opcode Fuzzy Hash: 98e41c275d60fdb469c0ce8d76353523b0c4768aaec3a6e883ecfec97710c609
                  • Instruction Fuzzy Hash: CA21933090D3848FCB56CB68886D7AEBFB0AB06300F1A44DFC440E7193E2655845E7A2
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226908893.0000000001912000.00000040.00000001.sdmp, Offset: 01912000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 9b808722cb798f2bb9c815fd8d88d4caf51cb7b98da9eb25ba8e9f5957b22930
                  • Instruction ID: 9db7c7a154a9955223df5db28e415b608a54ad417174754b72cbf92eb9c35b98
                  • Opcode Fuzzy Hash: 9b808722cb798f2bb9c815fd8d88d4caf51cb7b98da9eb25ba8e9f5957b22930
                  • Instruction Fuzzy Hash: 58314DB550E3C19FD302CF259850A56BFF4EF86214F0989DEE8C8DB252D2759908CB62
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: ec53daf2f3583b3d05cc2d73c0ddda81d8a03a4bd23c52654bb7236389288377
                  • Instruction ID: 3ec99ea723cb3c8b4add373b630704a20ed6d3447ac4c01a45ae33f5e5791946
                  • Opcode Fuzzy Hash: ec53daf2f3583b3d05cc2d73c0ddda81d8a03a4bd23c52654bb7236389288377
                  • Instruction Fuzzy Hash: 27310874E0520A9FCF44CFA9C5919AEBBF2FF89301F10849AD815AB715D338AA42DF50
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226908893.0000000001912000.00000040.00000001.sdmp, Offset: 01912000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: be1bd5648b5fb30bfc7c790aae903c7010e5e812fab3eab5dc8a59f755f52d3e
                  • Instruction ID: 49fb5a1f72b7cc363acd3dcd7dd3dd034079c303e9e1f1146828e26e2cd501a3
                  • Opcode Fuzzy Hash: be1bd5648b5fb30bfc7c790aae903c7010e5e812fab3eab5dc8a59f755f52d3e
                  • Instruction Fuzzy Hash: FB21A1B6544304BFD6108E0AEC41E67FFA8EB84A70F14C91EFE0957600D276B9049BB1
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226908893.0000000001912000.00000040.00000001.sdmp, Offset: 01912000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 68ded4686751f6a13b1eaa1efa064926c75d20bc84ede69e458401de278fc0f6
                  • Instruction ID: db0c027927cc9bad065974a0a1b934669025a71d62bd9a0d3b74b7c724d28ee1
                  • Opcode Fuzzy Hash: 68ded4686751f6a13b1eaa1efa064926c75d20bc84ede69e458401de278fc0f6
                  • Instruction Fuzzy Hash: 39212FB6544304AFD650CF09EC41E67FBE8EB88630F14C92EFD4997711D275A9148BB2
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226908893.0000000001912000.00000040.00000001.sdmp, Offset: 01912000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: c88e43778e5994ef0847e6468d8c08d41bbab09b092a61c2bf5e9174acbeb83c
                  • Instruction ID: 077109d23af7acab915c82e3ac7e982724ff636a33099b906b6ba9384936c745
                  • Opcode Fuzzy Hash: c88e43778e5994ef0847e6468d8c08d41bbab09b092a61c2bf5e9174acbeb83c
                  • Instruction Fuzzy Hash: D0214FB6544304AFD650CF09EC41E57FBE8EB88630F14C92EFD4997711D271A9148BB2
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226908893.0000000001912000.00000040.00000001.sdmp, Offset: 01912000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: e2f760362f6ee19c9d8b6288ee8dfd45b87bc14269a9ff7c1ee9648f2e127bb5
                  • Instruction ID: 35fb1635db8d52f7a32a4b15543a60acab1c60604ae58c5b658c5c0f4c607409
                  • Opcode Fuzzy Hash: e2f760362f6ee19c9d8b6288ee8dfd45b87bc14269a9ff7c1ee9648f2e127bb5
                  • Instruction Fuzzy Hash: A0213DB6504304AFD650CF09EC81E67FBE8EB88620F14C92EFD4997701D271A9148BA2
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226908893.0000000001912000.00000040.00000001.sdmp, Offset: 01912000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: d9fad4219864fc7d8379cc93452a8f70d81ed63b613d62ed339b2ebc0313e4a3
                  • Instruction ID: 58293d29fcae40794f7c307bb815181f5861eda246319339b45419ef6ae574a8
                  • Opcode Fuzzy Hash: d9fad4219864fc7d8379cc93452a8f70d81ed63b613d62ed339b2ebc0313e4a3
                  • Instruction Fuzzy Hash: 511193B6644204BFD6108E0AEC41E67FFACEB84A70F14C95EFE095B601D272B9149BB5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: fc9efdb602b6d41cf5ddd7ef365d97f7f99ab20f2909f1bd3d45802890907287
                  • Instruction ID: abeec66fde70e12bd61745b908a32dcefdbfdbbad3958c4c36784e8a87549f79
                  • Opcode Fuzzy Hash: fc9efdb602b6d41cf5ddd7ef365d97f7f99ab20f2909f1bd3d45802890907287
                  • Instruction Fuzzy Hash: 4631E8B4E05209DFCB44CFA9C5919AEBBF2FF88301F50949AD815A7314D7389A41DF60
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: e168afa866dc9610c161428b1d0816a63489d856e39992ffc744729e68c03d97
                  • Instruction ID: 907ee0f38ca4b9e1069a87ee19fcd069d5d72f032036abc8e056de975288c7ab
                  • Opcode Fuzzy Hash: e168afa866dc9610c161428b1d0816a63489d856e39992ffc744729e68c03d97
                  • Instruction Fuzzy Hash: D72119B0E0420ADFCB04CFA9D4859AEBFB2BB89301F21C4EDC515A7215E7349A41DF51
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 22b4968d662843ed615d0b0535dda7f2705db8b801adcf91779a8edc8884ff59
                  • Instruction ID: 844d2b506758af7b7ede6c309ab8976f27d979779f129d527142a3268ce1c247
                  • Opcode Fuzzy Hash: 22b4968d662843ed615d0b0535dda7f2705db8b801adcf91779a8edc8884ff59
                  • Instruction Fuzzy Hash: 5E31D474E14209DFCB14DFA5C584AAEBBF2FF99310F1080A9D805AB354DB74AA41DF54
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: b5249d3b33f5f3cd3d7e292ab16fbf67fe4520a520f8ee763b67faa621efb75a
                  • Instruction ID: 72964f36873a885f941bc24db490cc1bcd183a30e4452697145baec221e7889e
                  • Opcode Fuzzy Hash: b5249d3b33f5f3cd3d7e292ab16fbf67fe4520a520f8ee763b67faa621efb75a
                  • Instruction Fuzzy Hash: B7212CB0D0924ADFCB18CFA9C5445AEBFB1FF8A300F5499AED405AB255D731AA41EF40
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226908893.0000000001912000.00000040.00000001.sdmp, Offset: 01912000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: c013f8cda35b6fe704b6392c12ba2ab2dcbe436cfa6ddedb226b6cb31e2b9887
                  • Instruction ID: a0f83d068f2018abaa0d82316b37e69f2d322b1a9efc98723103ea2173f07bd9
                  • Opcode Fuzzy Hash: c013f8cda35b6fe704b6392c12ba2ab2dcbe436cfa6ddedb226b6cb31e2b9887
                  • Instruction Fuzzy Hash: 1E1181B6544204ABD6108E0AEC41E67FBA8EB84630F14C96AFD0D5B611D276A5149AB2
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226908893.0000000001912000.00000040.00000001.sdmp, Offset: 01912000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: ffd8330025bc9cf4d427d44be472c84e2968295c9ffb59f4217967eb753a9bec
                  • Instruction ID: d032adfafcd4be7e658ec30cf54f89da01fff69d8514c93536601f2cca5d1942
                  • Opcode Fuzzy Hash: ffd8330025bc9cf4d427d44be472c84e2968295c9ffb59f4217967eb753a9bec
                  • Instruction Fuzzy Hash: 0711B1B2504204AFD6108E0AEC41E67FBA8EB84A30F14C82AFD0D5B600D272B5149AB2
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 398372a62899eb43858cc6e2ab8e309d627d4ff2ccda712ead0f3ebea250b28c
                  • Instruction ID: 9dcc40bc8fd83e5f29cfe4ea3fdac0dd1f2cd4bfd83f951ee128300018715ed6
                  • Opcode Fuzzy Hash: 398372a62899eb43858cc6e2ab8e309d627d4ff2ccda712ead0f3ebea250b28c
                  • Instruction Fuzzy Hash: D9214870E5522ACFCB28CF24D959BADBBB2BB44301F1054EAD50EA6650EB345F80CF90
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226908893.0000000001912000.00000040.00000001.sdmp, Offset: 01912000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 8f3bf97e8e3baa6fb02332c3bb0783c60e1114042dcc9e8342456a3d70acbff3
                  • Instruction ID: cb46fc51b493e060e305e2c854b3c7cb78ef36913fa3cabe27cab5ae4d99ccf7
                  • Opcode Fuzzy Hash: 8f3bf97e8e3baa6fb02332c3bb0783c60e1114042dcc9e8342456a3d70acbff3
                  • Instruction Fuzzy Hash: AC216DB550D380AFD702CF259C50957BFF4EF86620F09899AF9889B212D234A908CB62
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226908893.0000000001912000.00000040.00000001.sdmp, Offset: 01912000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 9de77e1ea365c306f82d1e078dcd79bf0418726f2ae123a1094eebbc39dd9682
                  • Instruction ID: 2587682609b303788162bb85cf4630273189721aba40e07b7feda7599821a00c
                  • Opcode Fuzzy Hash: 9de77e1ea365c306f82d1e078dcd79bf0418726f2ae123a1094eebbc39dd9682
                  • Instruction Fuzzy Hash: 3911CAB2644204BFD6108E0AEC41E63FFA8EB84A30F14C46EFD0D5B601D272B5149BB5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 22b8151ee9819c495aca2110052f4c0940b92dfc727825e4b475e004ab600e34
                  • Instruction ID: e52259c8ff2374071737edff06eb4965f4a26afd82db5e0ce14d777d799e0a6a
                  • Opcode Fuzzy Hash: 22b8151ee9819c495aca2110052f4c0940b92dfc727825e4b475e004ab600e34
                  • Instruction Fuzzy Hash: 71212774D09209DFDB04CFE4D68599EFFF6FB88300F2094AAC81AA7254E7349A019F51
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: a4f0b5a65ba1d22afc6cd31eaea5ed9989638407405cc1e2ac9365703b3945c1
                  • Instruction ID: 4b434bab50f52e458c8d8b2da01a99e1c2b3015c9ced4f8d65b8433b7e11ba61
                  • Opcode Fuzzy Hash: a4f0b5a65ba1d22afc6cd31eaea5ed9989638407405cc1e2ac9365703b3945c1
                  • Instruction Fuzzy Hash: A0212BB4E0062A8FDB64CF24CC48BE9FBB2BB98300F1185EAD55CA7650E7705E849F44
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 7a21a20405afeb871af04361713607d0b97121f656f7664b74c8103144be98ed
                  • Instruction ID: aa5566aaf9eaf05847cd6b7ca6d32f0857ebcdb1e2d455a86163aa1d92673c6b
                  • Opcode Fuzzy Hash: 7a21a20405afeb871af04361713607d0b97121f656f7664b74c8103144be98ed
                  • Instruction Fuzzy Hash: 422133B4E092489FCF09CFA8C5509AEBBF2FB89300F1080AEC801A7245D734AA41DF81
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226898700.0000000001900000.00000040.00000040.sdmp, Offset: 01900000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 4f65de43dcc6da4ceaf86e8dcc857e9258916596b9d704f46b302022c8fa25fc
                  • Instruction ID: e42e7115c3a7c3d4f4cbe20714ab3b8af84e5c7f16dc5087eab815dda5b46230
                  • Opcode Fuzzy Hash: 4f65de43dcc6da4ceaf86e8dcc857e9258916596b9d704f46b302022c8fa25fc
                  • Instruction Fuzzy Hash: A611A534204684DFD716CB14C984F26BB95AB88709F28C99DF94D1B693C77BD403CE51
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226898700.0000000001900000.00000040.00000040.sdmp, Offset: 01900000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 2eee9bffdc5bdcca41986d168274feeef9fe67ca6e7b19627dda318a40c0f748
                  • Instruction ID: 347920cb16cb00dc2aa0faca26aa20b03244ce9b9c2c18cd09d2b2dc64945523
                  • Opcode Fuzzy Hash: 2eee9bffdc5bdcca41986d168274feeef9fe67ca6e7b19627dda318a40c0f748
                  • Instruction Fuzzy Hash: 6F213E351093C49FC717CB24C850B55BFB1AF47314F1985EAD8895B6A3C33A9806DB52
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 3d63569b6de2727bdfb2862cdd27da4ce61b40013f3bd950760ffc4b50bc7284
                  • Instruction ID: 56a19153172b8321a513b0148e26f468309c82e802f00672074c54986b9ab0b2
                  • Opcode Fuzzy Hash: 3d63569b6de2727bdfb2862cdd27da4ce61b40013f3bd950760ffc4b50bc7284
                  • Instruction Fuzzy Hash: E6211778E04208EFDB09DFA8C54499DFFF2EF99300F15C49AD914AB265D731AA41EB41
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226908893.0000000001912000.00000040.00000001.sdmp, Offset: 01912000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 44142f97cd263343ae3af6d64fdf19e859ec662808f13ed582d7645a83947f7b
                  • Instruction ID: d90ef40a9640487abd864bf26931e7c9d74bdb89673c565a2e1cf0043cc409de
                  • Opcode Fuzzy Hash: 44142f97cd263343ae3af6d64fdf19e859ec662808f13ed582d7645a83947f7b
                  • Instruction Fuzzy Hash: E011A7B5909301AFD350CF19D881A5BFBE4FB88660F14896EF998A7311D375E9048FA2
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 6ca810c13c7f395af81082d444507061fc4640bf9fc4dd1f3c0c369848ff2f1e
                  • Instruction ID: 5f8a1b93f9e48c774127a8daaea6b9b9dca384465f5cdf130044b5b16413b816
                  • Opcode Fuzzy Hash: 6ca810c13c7f395af81082d444507061fc4640bf9fc4dd1f3c0c369848ff2f1e
                  • Instruction Fuzzy Hash: 0B216030E0521EDFCB14EBA8D5548ADBFB2FF84304B20456DD6069B258DFB09E44DB92
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: d73ee068ac7bc0b9e20172edee26127e2da141fd01683d452a00add01de7dd39
                  • Instruction ID: fa1f2fc889ee9349089fa1319fe2233090fc57e5f599278f65d57721133e0c4d
                  • Opcode Fuzzy Hash: d73ee068ac7bc0b9e20172edee26127e2da141fd01683d452a00add01de7dd39
                  • Instruction Fuzzy Hash: E91146B0E05209DFCB08DFA8C154AAEBBF2FB89301F5081ADC815A7344D730AA41CF40
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: f8b9017e137a49c0a2772bff3d84c1e4baaf053cf4e188c6bedc2eb78913ef1c
                  • Instruction ID: bf6c0d48c2f939cf582e145c57105711ee7c4bdc5562a0338f1c74ac185cd7d1
                  • Opcode Fuzzy Hash: f8b9017e137a49c0a2772bff3d84c1e4baaf053cf4e188c6bedc2eb78913ef1c
                  • Instruction Fuzzy Hash: EF115A70915308EFCB25DFA4D448AADBFB0AB06304F1055AED80167292C7B59A45DB85
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: b0ddcc3e61db1b392994bd2a7bbf0ea6f587b3df7db776317b2e1358a444dfac
                  • Instruction ID: c580ac0616c67a91c96bee7478a43863276d958786e88dc6706d371414b8a559
                  • Opcode Fuzzy Hash: b0ddcc3e61db1b392994bd2a7bbf0ea6f587b3df7db776317b2e1358a444dfac
                  • Instruction Fuzzy Hash: 75112878E04208EFDB08DFA8C584A9DFBF2EF88300F15C499D915AB350C731AA40DB45
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: f79a2aec2b5d331516866073a75a1c53e90f03d8bbf590df840c68001cab8303
                  • Instruction ID: 61b0ace2ca2ed54993129359429f51953c73d20162dc10fb088f7b1383ac8d78
                  • Opcode Fuzzy Hash: f79a2aec2b5d331516866073a75a1c53e90f03d8bbf590df840c68001cab8303
                  • Instruction Fuzzy Hash: 0F1179B4C0A349EFDB15DFA4D5419AEBFB1FB46310F2084EED802AB256D3309A51EB45
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 898e6695b48d7c50594caed3153a344e5f67541c0eb0722f252b9b23bcc43337
                  • Instruction ID: fa26e02d04eb9746c346fb4ae8496565ca34d17cb328a1ba8117899aeae369a0
                  • Opcode Fuzzy Hash: 898e6695b48d7c50594caed3153a344e5f67541c0eb0722f252b9b23bcc43337
                  • Instruction Fuzzy Hash: 79112E30E0121EDFCB14EBA9D5445ADBBB2FF84304B204569DA0697358DFB0AE45DB92
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 13283651c9135455ed4df14083d86a6c5dab9662db5268fee1fcfb14e5d83625
                  • Instruction ID: 2d5d67d754d9de55c1b88d5a76bad54a465429a8bbbdfaed177829b6774268fc
                  • Opcode Fuzzy Hash: 13283651c9135455ed4df14083d86a6c5dab9662db5268fee1fcfb14e5d83625
                  • Instruction Fuzzy Hash: 46113630906249DFCB19EFA8D8486ADBFB2FF81304F2445EEC5029B255DB755A81EB81
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 1a59bd7a04b0f8e54490dc9ca4e267d06a98347de8254803e8e61685a641d7ca
                  • Instruction ID: 7c87df2343cb58d4d20e3f636a447f60e1f84f7aa0a5530941155757db21be7f
                  • Opcode Fuzzy Hash: 1a59bd7a04b0f8e54490dc9ca4e267d06a98347de8254803e8e61685a641d7ca
                  • Instruction Fuzzy Hash: 1A117C74D19309EFCB14CFE4D58159DBBB1FF4A210F14A8AAC416A72A0D734AA41CF51
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 23d0694c4c9dbe951a23eb385ee3a7534aae1208d73865c761be7b39aa7951c3
                  • Instruction ID: c72a524dd7bc3aa196b457fe88f46b2f25186c98efa0a6116225e12495558405
                  • Opcode Fuzzy Hash: 23d0694c4c9dbe951a23eb385ee3a7534aae1208d73865c761be7b39aa7951c3
                  • Instruction Fuzzy Hash: A101D374D41209EBCB14EFA4C954AAEBBB2FF84301F2085A9D806A7344CB359E82CB51
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 760f3293808c300ed0f53b1dd1009ba8ff08081f8c6c9fff33f55e77e5333eee
                  • Instruction ID: 561a246acaeb17a3e9485309ea185a79a2a22f7728a0854dee48344ef3deb45a
                  • Opcode Fuzzy Hash: 760f3293808c300ed0f53b1dd1009ba8ff08081f8c6c9fff33f55e77e5333eee
                  • Instruction Fuzzy Hash: 08015AB4C0A208EFDB04DFA4D5419AEFFB1FB45340F6094AED806AB245C7309650EB48
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: caad37b5d614644e333340f83e15d91209cda06563f3d0edb1c6d64af80ad109
                  • Instruction ID: abce010df775f35c259dee7993ec00271a1f1cfe0d3fda22258e7d5eb286930f
                  • Opcode Fuzzy Hash: caad37b5d614644e333340f83e15d91209cda06563f3d0edb1c6d64af80ad109
                  • Instruction Fuzzy Hash: 13F04430A45208DFDB05D7B0D510FFF77B6EBC6704F2058DDD40563686CA75AE02AA95
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 74b892b1948d173c8e5e9c0d00d66dda4803561b202f0ff658910ec4293c31cd
                  • Instruction ID: 5dd80c06925f638150d954697df133177a0cfa7b58e1650501671ba0dc19e461
                  • Opcode Fuzzy Hash: 74b892b1948d173c8e5e9c0d00d66dda4803561b202f0ff658910ec4293c31cd
                  • Instruction Fuzzy Hash: AD018C74D19308EFCF18DFA4D5865AEBBB5FB49300F10A4AAC416A7250D774AA41CF91
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226898700.0000000001900000.00000040.00000040.sdmp, Offset: 01900000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 0e2da95d56ed7dd9ef51ad735499b304f0a2a9ddc1c762fd1b7a7420ce64092a
                  • Instruction ID: 46b2e45b9243d8a62293eefda7e86ff683b31e996185dc0c44a5f2bbfb798ece
                  • Opcode Fuzzy Hash: 0e2da95d56ed7dd9ef51ad735499b304f0a2a9ddc1c762fd1b7a7420ce64092a
                  • Instruction Fuzzy Hash: 1EF0A9B65097805FD7128B16EC40862FFB8EA86660709C4AFED498B611D125B908CBB2
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 2610bc913278b43482fd4fd134318617a5b443833976eab6c6df54f0ae6240b5
                  • Instruction ID: 22fd05381b39733a60c01d002cced552a9d296f9d19c074ca9445370ddc8a7f2
                  • Opcode Fuzzy Hash: 2610bc913278b43482fd4fd134318617a5b443833976eab6c6df54f0ae6240b5
                  • Instruction Fuzzy Hash: 12011B3090124DEBCB18EFA8D844AADBFB2FF80304F2049ADD51667254DB745E81DB91
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 5199ab44e4d3a25fc3cb4e45c5bc886c30681e3883c5cc223b76b6307982ec92
                  • Instruction ID: ae42719694f34b655aed0338aba7457f9f36e385088c53824b944a450539e523
                  • Opcode Fuzzy Hash: 5199ab44e4d3a25fc3cb4e45c5bc886c30681e3883c5cc223b76b6307982ec92
                  • Instruction Fuzzy Hash: 8201C474D41209EBCB14EFA8C5549AEBBB2FF84301F6045A9D806A3344DB71AE81CB91
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 4da5921e4f9a7778a4160b3b7a25fae4d28bb4aed0af9452660452ae20feaf37
                  • Instruction ID: bf7f6be5b3f14c99690d7294527c849102d1bcab43e790914efa96bf0e40d2a6
                  • Opcode Fuzzy Hash: 4da5921e4f9a7778a4160b3b7a25fae4d28bb4aed0af9452660452ae20feaf37
                  • Instruction Fuzzy Hash: D1F08730E48209DFCB04CBA8E805AADBBB1BB45310F1446EDD808E7350E3B19E41EB80
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: f57f255086bde9492e85e29dfe682e1e9ce3d4b418db380aa9d57b40940e3d9d
                  • Instruction ID: ec9c49229c9ef0f21dbc0d931346979d5184926af0f270a53aedba834de40208
                  • Opcode Fuzzy Hash: f57f255086bde9492e85e29dfe682e1e9ce3d4b418db380aa9d57b40940e3d9d
                  • Instruction Fuzzy Hash: 9E01F730D093849FCB59DFB8D95429CBFB0AF46310F1481D7C8589B2E1C6345A41DB52
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 626e26dea2317ed78c5dab6452e40bd17c8f25aeea709f38069eb40c7e4f757f
                  • Instruction ID: b9e9d95cb3f7265c182e822902a58d172bf0050d1f7697d84c2d5768ba1da4a3
                  • Opcode Fuzzy Hash: 626e26dea2317ed78c5dab6452e40bd17c8f25aeea709f38069eb40c7e4f757f
                  • Instruction Fuzzy Hash: A501AD75819208DFCB20DFA4E54A69CBFB1EF0A321F2088EED446D7211D771C681EB46
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 6823ca56ae7a6307c1c8b72e8c36e8d69213c30dd8765e09db2f7904b7346a5f
                  • Instruction ID: dee644a65a9ef46711e4524ce32508dc76d6a08857719e7199b6a884aaa91ffc
                  • Opcode Fuzzy Hash: 6823ca56ae7a6307c1c8b72e8c36e8d69213c30dd8765e09db2f7904b7346a5f
                  • Instruction Fuzzy Hash: 8411BD78901229DFDBA4CF64C885BECBBB1FB49304F5084E9D509A7251CB306E85DF94
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 7f966d730be12b727fcdd030fa89d12b3acf9d28c4bb870ed3525866367db878
                  • Instruction ID: 4ca6a3d11a5f8b977610062b331baf132da508a38298add419934a154b7d685f
                  • Opcode Fuzzy Hash: 7f966d730be12b727fcdd030fa89d12b3acf9d28c4bb870ed3525866367db878
                  • Instruction Fuzzy Hash: AF018C74C19308EFCB10DFE4E14959CBFB5FB0A322F2088ADD446A3101C7309680EB56
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: d217225214fb58a8a817a1210fe723044b5b6bd0eab9e141349974156d6ebcb6
                  • Instruction ID: 2b27f281550a3faa190c1b0f3de9476e22d39ee92bf1db8d10910793aa7d1201
                  • Opcode Fuzzy Hash: d217225214fb58a8a817a1210fe723044b5b6bd0eab9e141349974156d6ebcb6
                  • Instruction Fuzzy Hash: 78012270914208EFCB48CFA8E58158C7FF2FF89304F1085DAE400E7226DB306A12EB41
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: ac1a51ee30046f4bea6642b53cec5d1110be49ada002afe3cbdc587230d0a1c9
                  • Instruction ID: 75fbf4db70846e0b74ac0fd75509a1d2ae931da86ca2a39839b1eac7dfab5db1
                  • Opcode Fuzzy Hash: ac1a51ee30046f4bea6642b53cec5d1110be49ada002afe3cbdc587230d0a1c9
                  • Instruction Fuzzy Hash: DA018C758082AACFCB54CF64C8847E9BBB0FB56300F1055EB881AEB241C7349B86DF51
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 4cbfc8f6f3d559a8d130be36b5a16822577dcc65e2d17a6fb9902fed67366a77
                  • Instruction ID: d893a746816044b16d7caef3b7e100bb2681dd8803ba04f8a97d876ea49bf8c4
                  • Opcode Fuzzy Hash: 4cbfc8f6f3d559a8d130be36b5a16822577dcc65e2d17a6fb9902fed67366a77
                  • Instruction Fuzzy Hash: 06F05870D01209DBDB689BA4C8597AFBEF5EB49700F11182EC111B3280EA7559849BE5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 88c5c1f1c5ab46bfa28ddf2ac1a85793881fef2e70ef99eccae5bf5141171ad8
                  • Instruction ID: 27b9f806e78efedd6d533467ff6f0ed1ba199e30dff3179df01d819315213a8a
                  • Opcode Fuzzy Hash: 88c5c1f1c5ab46bfa28ddf2ac1a85793881fef2e70ef99eccae5bf5141171ad8
                  • Instruction Fuzzy Hash: 7DF01F34E08348AFCB51DFA8D4946ACBFF0AF0A320F1880EADC489B212D6359A44DF41
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: bfd023799f0bba3feaae1231f48976630ac73c4455094b33430247db1ecc283b
                  • Instruction ID: 2a117fd2963c395e18459d80809c7ba7ae6126724a92a97f0ea9895653cee352
                  • Opcode Fuzzy Hash: bfd023799f0bba3feaae1231f48976630ac73c4455094b33430247db1ecc283b
                  • Instruction Fuzzy Hash: 33F01474E0420AEFCB04DBA8C44499DBBF1FB09310F2085A9E804A7315D3709E81EF90
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 0c5e189cfc6ab074ce68872a957802231cd6b6915c8f3afc35e5fbe405de4f96
                  • Instruction ID: 4febef9eb17be1af801015d1e0af6da73cf9b8afe3290dfe9b440bcb23eedb6a
                  • Opcode Fuzzy Hash: 0c5e189cfc6ab074ce68872a957802231cd6b6915c8f3afc35e5fbe405de4f96
                  • Instruction Fuzzy Hash: 85F0AC34A46208EBD708DBF0D550FAF73AAEBC6704F2058989405337858A756F41EAA5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 52404cd63d62eeb30d872c59d6d82674bb87bd2108017c82312ee8dd83725897
                  • Instruction ID: 605bf29616977177eb0a13d40a44333afa0b1b43ec9925db0584aae1aae8621f
                  • Opcode Fuzzy Hash: 52404cd63d62eeb30d872c59d6d82674bb87bd2108017c82312ee8dd83725897
                  • Instruction Fuzzy Hash: 3EF0BB70A1420CDBDB44DFA9E54166D7FF6FF88305F50819DE90893254EF305A15EB91
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226898700.0000000001900000.00000040.00000040.sdmp, Offset: 01900000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 525cef522958239b2deb72ab7ac90410e2832b06fb356f1b7ca8807ee3c9392c
                  • Instruction ID: 2b4d628ab8446d1bcc7f8071b07598a4fdc5bd33f053b249ca487edc954b6650
                  • Opcode Fuzzy Hash: 525cef522958239b2deb72ab7ac90410e2832b06fb356f1b7ca8807ee3c9392c
                  • Instruction Fuzzy Hash: 55F0FB35108644DFC206CB44D940B15FBA6EB89718F28CAA9E9490B652C3379813DE81
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 1869152ba105ee34f0ee75c8b259817113635a707f541c621ed624cc6230e48f
                  • Instruction ID: f441238bfe25e42a216768dda827b6d12755cc2e3a2793f2b0dfef4d8f4165d6
                  • Opcode Fuzzy Hash: 1869152ba105ee34f0ee75c8b259817113635a707f541c621ed624cc6230e48f
                  • Instruction Fuzzy Hash: FAF08C34909304CFCB15DBA5D405AACBFB1FB46310F1080EED84697252D2766A46EB92
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: d56489f2f484d19ffea6233945314dfcd78d21b8c25ed02f6ff94b028dcba9ea
                  • Instruction ID: ee85b296def5d6058d9d1226141b5f7499b53c2f567716a7f8cf03a74bc73203
                  • Opcode Fuzzy Hash: d56489f2f484d19ffea6233945314dfcd78d21b8c25ed02f6ff94b028dcba9ea
                  • Instruction Fuzzy Hash: 3101A2B4D45228CFEB64CF65C981BE8FBB1FB48300F2084D9D449AB291D3769A81DF44
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 28a8812b927f6fffd5cff2ad6cef28bc43487d969b6499c9b8e0abb66930f85a
                  • Instruction ID: 3f5916237e5265a2ae07f5bcecedea9eecf496d877900b20266eebe2eed3a94b
                  • Opcode Fuzzy Hash: 28a8812b927f6fffd5cff2ad6cef28bc43487d969b6499c9b8e0abb66930f85a
                  • Instruction Fuzzy Hash: 8301D670A022199FEB58DB28CD90F9DBBB2BF89200F0042E9D40DA7294DB305E84CF51
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 8e4f820b2ef0a0c8989657ebddf3354176deb144ac1099d1240b254aa1b5383a
                  • Instruction ID: 9410f291bc5672ecd40be8f9c226561707180e222069b173efae655f0debc919
                  • Opcode Fuzzy Hash: 8e4f820b2ef0a0c8989657ebddf3354176deb144ac1099d1240b254aa1b5383a
                  • Instruction Fuzzy Hash: 0EF03A74C05308EFCB10EFA4D4486AEBBB0EB45301F1045AAC815A3345D7759A51CF91
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 9ac7857d196f4db26c1d9d35a0984de17ef6b076f9639fcd5671520ccf18bbbc
                  • Instruction ID: 872efe5998efabdaa2d5c58b07438a91085c58bff6aae299ba41c67a6a9f6bd3
                  • Opcode Fuzzy Hash: 9ac7857d196f4db26c1d9d35a0984de17ef6b076f9639fcd5671520ccf18bbbc
                  • Instruction Fuzzy Hash: 2C01D2B494022C9FCB68CF50C942BE8BBB1BB49304F1084D99609AB251C7305BC5CFA0
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: b3ccc26935bbb5a549fc7bd7857f60799b00f4619f49cbdbfb4840f9272b77c2
                  • Instruction ID: 779d3937c4e9c7c58a2249d14e0199d677c8d15f0d8cf3f805ddb63d40841a44
                  • Opcode Fuzzy Hash: b3ccc26935bbb5a549fc7bd7857f60799b00f4619f49cbdbfb4840f9272b77c2
                  • Instruction Fuzzy Hash: 3701E8B4C41228CFCB64CF20C988BD9BBB1BB49350F1055DA848AA72A1CB704ED2DF54
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226898700.0000000001900000.00000040.00000040.sdmp, Offset: 01900000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: a2c00e003e6dff0b1577494d824efad2a4fabcefab8eae16f62dbfc46807b224
                  • Instruction ID: 0635cce39c47cb84712e1c0254509bf34d0579fc6b249937760e917a73d704ac
                  • Opcode Fuzzy Hash: a2c00e003e6dff0b1577494d824efad2a4fabcefab8eae16f62dbfc46807b224
                  • Instruction Fuzzy Hash: FFE092B6A006008BD650DF0BEC81462FBE8EB88630B18C47FDD0D8BB00E135B508CEB5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: d5ad259ab8e49a2aa73b62f324e8af6acb8bc8636f1597c976f7c9e1434d7843
                  • Instruction ID: 43709230ecbef19abbb43216a2159fb3d18c234237761358760bd1fc9f2a90b6
                  • Opcode Fuzzy Hash: d5ad259ab8e49a2aa73b62f324e8af6acb8bc8636f1597c976f7c9e1434d7843
                  • Instruction Fuzzy Hash: 87F01534D49344EFCB55DBA8951459DBFF0EF46314F2581EEC84997212C2324A4ADB82
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226908893.0000000001912000.00000040.00000001.sdmp, Offset: 01912000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 6700397bb10cd3a1a73d0ffcc8ee5d5f43027166a4d7e0347f3cb8279cc34b5c
                  • Instruction ID: 51f6237d4b2c81f17f3f2a73eae5ce7cd39c2bbd88306112e4fcf7072fa181b3
                  • Opcode Fuzzy Hash: 6700397bb10cd3a1a73d0ffcc8ee5d5f43027166a4d7e0347f3cb8279cc34b5c
                  • Instruction Fuzzy Hash: C9E0D8B2941300A7D2509F06AC82F63FB98EB44A30F18C56BEE0C1B701E1B1B5048AF5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226908893.0000000001912000.00000040.00000001.sdmp, Offset: 01912000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: fc8c5c02b97ac45928142718976d4aca53ba7a0c76875253f6866609200d0d93
                  • Instruction ID: 1fad66856b3ad1e20d98c2a8a97f6ca47988457339f25cd2c68e173181d90880
                  • Opcode Fuzzy Hash: fc8c5c02b97ac45928142718976d4aca53ba7a0c76875253f6866609200d0d93
                  • Instruction Fuzzy Hash: 1FE0D8B19413046BD6509E06EC82B63FB98EB40A30F54C45BEE0C5B701D1B5B5049AF5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226908893.0000000001912000.00000040.00000001.sdmp, Offset: 01912000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 6d083348df9a18512d28806e374f789f4f2253eb856842b5939b1388766f7adf
                  • Instruction ID: f2f70a0172725b941c8d9706eb4084883f52e81ded854148cc90f118507452f2
                  • Opcode Fuzzy Hash: 6d083348df9a18512d28806e374f789f4f2253eb856842b5939b1388766f7adf
                  • Instruction Fuzzy Hash: 43E0D8B2941300ABD2509F06AC82F63FB98EB50A30F14C55BEE0C1B701D1B1B5048AF5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226908893.0000000001912000.00000040.00000001.sdmp, Offset: 01912000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: be04a421d2603d9caefa0cf9e91e0ccf2a774b7ce6dab7ea245d98af9ce25833
                  • Instruction ID: aacfc29c63c4ce0b18fa980d6c9a0bc190c6c79bbf5e68472637af2da3516caa
                  • Opcode Fuzzy Hash: be04a421d2603d9caefa0cf9e91e0ccf2a774b7ce6dab7ea245d98af9ce25833
                  • Instruction Fuzzy Hash: AFE0D8B2951300A7D2509E06AC86B63FF98EB40A30F14C55BEE0C1B702D1B1B5148AF5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226908893.0000000001912000.00000040.00000001.sdmp, Offset: 01912000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 773d9263d99036fc72546401a6337ba591324e5f82d4bfedd5f501c2985a9456
                  • Instruction ID: 9ea5d509e46b8f1167485eb068b4868a1b46db57dc92ec0a0cb89ce07e59ddc3
                  • Opcode Fuzzy Hash: 773d9263d99036fc72546401a6337ba591324e5f82d4bfedd5f501c2985a9456
                  • Instruction Fuzzy Hash: 47E0D8B194130067D6509E06AC82B63FB98EB40A30F14C45BEE0C1B701D1B5B5048AF5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226908893.0000000001912000.00000040.00000001.sdmp, Offset: 01912000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: fe86a4ac87ecaa08296ad16170f34f9be8c94cff84c3f3d92272c6de1a0a00fd
                  • Instruction ID: 50a8b5afa499010ca3b868b08c18b8311f39dcf2ce1ae56767f9f0174631e89f
                  • Opcode Fuzzy Hash: fe86a4ac87ecaa08296ad16170f34f9be8c94cff84c3f3d92272c6de1a0a00fd
                  • Instruction Fuzzy Hash: D1E0D8B2941300ABD2509F06AC82F63FF98EB40A30F14C55BEE0C1B701D1B1B5048AF5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226908893.0000000001912000.00000040.00000001.sdmp, Offset: 01912000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 1d8dbb9a02899ce3681ccf4f44335b5723936031d10ca965cf3ed7806752a13f
                  • Instruction ID: e962b3f4420d5bdb863305e961fb8a6d0f5cda419899f14b46fe12cfbf034d1b
                  • Opcode Fuzzy Hash: 1d8dbb9a02899ce3681ccf4f44335b5723936031d10ca965cf3ed7806752a13f
                  • Instruction Fuzzy Hash: 90E0D8B194130467D6509E06AC82B63FB98EB40A30F54C45BEE0C1B701D1B5B5049AF5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 6fb733cb63a705aeb118ee86877a837b3d8f0efefb7cc596993f4c69cdb8c678
                  • Instruction ID: cfd26d1d38350fdc9fdbfb7fe4245cb51e9cd95fccb19356a51c64718412ce97
                  • Opcode Fuzzy Hash: 6fb733cb63a705aeb118ee86877a837b3d8f0efefb7cc596993f4c69cdb8c678
                  • Instruction Fuzzy Hash: F6F0BE70804299EFCB12DFE8CD8499D7FB1BF06310F04868AE860272A1C3325560EB86
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 6974d0fba03c48c89ae10fadd688f738cbccf392f1f5e2bf3e191f863122d111
                  • Instruction ID: cfe0c088b24239f56764b503c62449eba4b22994a65be477285aa67e39cf7192
                  • Opcode Fuzzy Hash: 6974d0fba03c48c89ae10fadd688f738cbccf392f1f5e2bf3e191f863122d111
                  • Instruction Fuzzy Hash: 18F03930C0864ADACB16CFA8C4105EEFF7AAF02314F90869CD8612B292C7B6214BDB41
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 32711dfca1f46ac4dc8be4c81141516bb78b16365f38a962e5d53751f3adaa9d
                  • Instruction ID: ba8aaf8b7e47f65cd0d5a2a3121487559995856b6f4c334e0e6a6e01ed7ba45d
                  • Opcode Fuzzy Hash: 32711dfca1f46ac4dc8be4c81141516bb78b16365f38a962e5d53751f3adaa9d
                  • Instruction Fuzzy Hash: C1F06D74C05208DFCB14EFB8C0486AEBBB0FB45300F2049AEC815A3344D771AA41CF90
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: d3785ac7c2e4501a582adb78e11eceabc5dc4732b75bfe4add2b21a61cd1f7e5
                  • Instruction ID: 0b4b022c4981de469fe503ff02dbced0856e07b7899694c482892da3d297dc84
                  • Opcode Fuzzy Hash: d3785ac7c2e4501a582adb78e11eceabc5dc4732b75bfe4add2b21a61cd1f7e5
                  • Instruction Fuzzy Hash: C7F01C74C18219DEDF54CBA1C840BAEBFF6BF46300F10A4DE845AA6654E6309545EF25
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: a5a1c210f01a4d988419c79ac3414c29bf6b3fc02bc9cca24a51edf2300b2964
                  • Instruction ID: 6a7d1620714c237c520c95daadf7b5544f9b97c05d1591d397fa1991f0fb2044
                  • Opcode Fuzzy Hash: a5a1c210f01a4d988419c79ac3414c29bf6b3fc02bc9cca24a51edf2300b2964
                  • Instruction Fuzzy Hash: F4F015B69002189FDB14CF90C980BEDB7B8FB48305F04849A9909EB281D334AB86CF50
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 0191de81c1c46c33c97a62254bd2d72e6087a4f75b0d828ad74b4d612c000029
                  • Instruction ID: 9340ac61f9970a31e19e65c7b752155fe1c670927bbde57f12f4fe02eb3e4a1a
                  • Opcode Fuzzy Hash: 0191de81c1c46c33c97a62254bd2d72e6087a4f75b0d828ad74b4d612c000029
                  • Instruction Fuzzy Hash: E1F0C975D0420CEFCF45EFA8D944AADBBB1FB48300F0085A9E815A3250D7719A60EF91
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 1db0d4ab967847fcddf54f18d314d78c06ca9b5af09ca6a5262bb83f2b826beb
                  • Instruction ID: 35b4a0a13f1ea99c789f281766c1f81c16d97c3c5563e1d4373b577645652523
                  • Opcode Fuzzy Hash: 1db0d4ab967847fcddf54f18d314d78c06ca9b5af09ca6a5262bb83f2b826beb
                  • Instruction Fuzzy Hash: 58E04F34D09308DBCB14DFA5D105A5CBBB5FB45301F1080ADD84653340D7716E54EB81
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 804e81a807d7125a1ee21c3ab5b45804e200af3758be36b307b38f7ca1652688
                  • Instruction ID: 04e674ec6c2a9bb4b4df7e24cbfba415d3a36b448e37d9d8e9fcecee3281e426
                  • Opcode Fuzzy Hash: 804e81a807d7125a1ee21c3ab5b45804e200af3758be36b307b38f7ca1652688
                  • Instruction Fuzzy Hash: FCE086308262859FC769DFB494812D87FF1EF46305F6005FEC804AB660D7365695DF41
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: fb977dac802077f7d934c5fd59aefcaeae2da7182222c656d765a8506513df7f
                  • Instruction ID: 6907bf8a912dc0da40af8280531073190a2f76f40c29b4ec3ccab3e768d36e85
                  • Opcode Fuzzy Hash: fb977dac802077f7d934c5fd59aefcaeae2da7182222c656d765a8506513df7f
                  • Instruction Fuzzy Hash: F2E0867085A384DFC759DFB494406583FF1EF02301F1109EECC04972A5D3359694CB82
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: ce67526c9ecc5292dd6f4a47e4ec637bbe8d82396f42bc1b84f004c7b89ce3ce
                  • Instruction ID: 09903b47e0b746be5d4d796d53c60bf3b179a6377be06bbaf242397982d34557
                  • Opcode Fuzzy Hash: ce67526c9ecc5292dd6f4a47e4ec637bbe8d82396f42bc1b84f004c7b89ce3ce
                  • Instruction Fuzzy Hash: 74E0C2300182858BC766A3BCA6847A43FE09F43268F494AC6C8902B0E2CA652443E7C7
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 8c7c6757db00730227cf4c478a0f31023288a291cf8a4434774ccbd22ac7e91a
                  • Instruction ID: 0e1f539296da1526088b077723908821028ab04ece3b9ebd1371236c838263a1
                  • Opcode Fuzzy Hash: 8c7c6757db00730227cf4c478a0f31023288a291cf8a4434774ccbd22ac7e91a
                  • Instruction Fuzzy Hash: D1E04F78A18359CFCB45CFA1C880A9DBBF6EB8A300F10A0E5954DAB204DB344A41CF15
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 11817b5e21ec807e3f014168676a24d233f6f0f39c3b02e2ac01b2693836df0a
                  • Instruction ID: 7298a587fa914fa9cefaa8caaf2889b87b43ef4567ea8df5b0ac52a244c7eda1
                  • Opcode Fuzzy Hash: 11817b5e21ec807e3f014168676a24d233f6f0f39c3b02e2ac01b2693836df0a
                  • Instruction Fuzzy Hash: 41F01978906668CFCB61CF68D984AD8BBB1FB48306F5011D9E849AB711D735AE91CF00
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 33ee1c26c00950b0d512419752ac9b72eb132563718f04d002e5c55ce3995900
                  • Instruction ID: dbc816fa3006e7e9f1c877956dbb8854d8ef3f9a2bde9c692f8999c0488b3f21
                  • Opcode Fuzzy Hash: 33ee1c26c00950b0d512419752ac9b72eb132563718f04d002e5c55ce3995900
                  • Instruction Fuzzy Hash: E5E086744083C5DEC742DFA8D1C56987FE0AF46114B4848CAC8486F613D67A6589DBD2
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 1d3f6f281412b2121932d129c79f605b1805483b83824ba9c84df36780141845
                  • Instruction ID: 025d6799e8e4f5585937665b4d802c8bd546a7ac0f11db8afbc3af6b47caf5f0
                  • Opcode Fuzzy Hash: 1d3f6f281412b2121932d129c79f605b1805483b83824ba9c84df36780141845
                  • Instruction Fuzzy Hash: 07E0DF308082858FCB15DFE8D6906A8BFB0AF42214F2882CAC8655B2E2CA302945DB52
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 8ee002c61d0948755d44d3d9ff42a05a2b157004614a7f2048989acfef95134f
                  • Instruction ID: b21817bd8428c6637cf3f3049fcc54ea62ef89014bf707c80a58e960332a9ac0
                  • Opcode Fuzzy Hash: 8ee002c61d0948755d44d3d9ff42a05a2b157004614a7f2048989acfef95134f
                  • Instruction Fuzzy Hash: 9BE0D8348087459FC725DBA8C184548BFF0AF06218F1446DAC8645B2E1C635A545DB42
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 17d8d93f6f24709b8f50cea2d2db8ceaa35dcaa99c6cf49b6f9ce03fc4d09fb5
                  • Instruction ID: 325f2d0b315d719a9589d9046c0065b683268634a4d27d6da4604efcc83c8e1e
                  • Opcode Fuzzy Hash: 17d8d93f6f24709b8f50cea2d2db8ceaa35dcaa99c6cf49b6f9ce03fc4d09fb5
                  • Instruction Fuzzy Hash: 91E0C2B5D002188FCF24CFA1C944BDDBBB2FB48310F20819A9418A3252C33A9A86DF00
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 769be8c71652543b6c715a8ff694c983b34c0e73a51a6d2ac7252d914d6bf70d
                  • Instruction ID: e9940e8eb5d66617a4d0ea21cb23c9d33cb26fda0395d89eeb4b60e59c13df14
                  • Opcode Fuzzy Hash: 769be8c71652543b6c715a8ff694c983b34c0e73a51a6d2ac7252d914d6bf70d
                  • Instruction Fuzzy Hash: E1D01735D01108CBCB00CFA8E0486ECBBB1EB89325F11846AC114A3200C3315485CF90
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: d9236282331d2de2ecc0cf1e7c17a3ac065cf236ee192c96e5f66004d71cb481
                  • Instruction ID: d83e91b209d486a6f13b1debc68f2466ff51dde066a63c055104304120eced51
                  • Opcode Fuzzy Hash: d9236282331d2de2ecc0cf1e7c17a3ac065cf236ee192c96e5f66004d71cb481
                  • Instruction Fuzzy Hash: 4AE0BD74E04308AFCB50EFA8D54869CBBF4AB08205F1080EA9C0893350E635AA84DF82
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 91ae228f4e22f8ea411bf6e6426b25309c108ca8f8850602f20911765736163b
                  • Instruction ID: 1676ffe2b39fd7817be7577328a7f581f1a85b194af7bdb7eb67dcd3afa2cc6a
                  • Opcode Fuzzy Hash: 91ae228f4e22f8ea411bf6e6426b25309c108ca8f8850602f20911765736163b
                  • Instruction Fuzzy Hash: 6ED01770D0930CABCB58EFA8E8446ADBBF4AB44300F1081E98C18A3240D6745A51DF91
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 4ee4bed02fa667384bc811da629e5c523f978261d2247295671d7a17643b6c9a
                  • Instruction ID: 66deedbb25b5e7f4b2c4dfd7cfc8f9c9cd55a6b9218cdec6c40ee290c4e8262e
                  • Opcode Fuzzy Hash: 4ee4bed02fa667384bc811da629e5c523f978261d2247295671d7a17643b6c9a
                  • Instruction Fuzzy Hash: 30E0EC74D052089FC754EFA8D14865CBBF4FB04214F1041E99C0493350E635A944DF41
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 3adb3560390d6ce02f1b2cff9d63970828cc36124218e9f68fd309944011b8a2
                  • Instruction ID: a4e2959a0bd417eabe70dad2f62f0b8bb2834ea4fae3b64ee7d7ed690998aa9c
                  • Opcode Fuzzy Hash: 3adb3560390d6ce02f1b2cff9d63970828cc36124218e9f68fd309944011b8a2
                  • Instruction Fuzzy Hash: BED01774D05348AFCBA0EBB8A4443ACBFF4AB04200F1081EA8C9492280E6385640DF82
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 19005c93e6769b4cbd0d30363b87f86c2766d038f58343068195e6826d92ac0d
                  • Instruction ID: d9cd93e2e83f767ab7f9d99ab82196a85835af879aa811ec52d0a4683a2953d2
                  • Opcode Fuzzy Hash: 19005c93e6769b4cbd0d30363b87f86c2766d038f58343068195e6826d92ac0d
                  • Instruction Fuzzy Hash: 42F092B09552A98FEB79CF20C9157DDBA71BB49300F4049DAC44E76264C7B02AC0CF81
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: e07940c0352216ba4ead6a56c2730c4ef52158fd4243f92f2b97325e2ac4c867
                  • Instruction ID: 30184acd59783a422caf510c55a25d4f9dee68facf97aa5ad6e9a17c60d708f6
                  • Opcode Fuzzy Hash: e07940c0352216ba4ead6a56c2730c4ef52158fd4243f92f2b97325e2ac4c867
                  • Instruction Fuzzy Hash: F8D0A734855308DFC758EFB8A50535C7BF4AB40205F5000FCCC0453240E7369580CF91
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 2d665021fbeb40f6ecc609a8f221236222521d61f35e9d29958dfc26a748123b
                  • Instruction ID: 00f053d8cb2297b89d18fa921f78969ab1a33776df4719630c64a77b3596d792
                  • Opcode Fuzzy Hash: 2d665021fbeb40f6ecc609a8f221236222521d61f35e9d29958dfc26a748123b
                  • Instruction Fuzzy Hash: 7BE01A789002248FDB64CF60C995B98FBB1FF48310F1089DA8419A7292D7359BC5DF00
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 5715cf7f1f6d9fecfb5ff6eeff3c9849f73ac1d560290c968d58ad19dc336afd
                  • Instruction ID: 3e6d4942b8e10db41f28bc0651334e7589a67a486c50d8ba846ca714b63ca1ab
                  • Opcode Fuzzy Hash: 5715cf7f1f6d9fecfb5ff6eeff3c9849f73ac1d560290c968d58ad19dc336afd
                  • Instruction Fuzzy Hash: E5D01770D1420CAFCB54EFA8D94439CBBF4AB44200F1080E9880893240EA346A44CF82
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: dfffd4b8968784f16c79c1543c1c9e79066b03af73cbb1c7339b6f38220f7f69
                  • Instruction ID: 52e2d9552414ebf3aa8850233191579429f34a0e982da0c853ddc1788e886cb5
                  • Opcode Fuzzy Hash: dfffd4b8968784f16c79c1543c1c9e79066b03af73cbb1c7339b6f38220f7f69
                  • Instruction Fuzzy Hash: 20D0A72080E3CD8EC707C7A0A844BEABFB9AB03300F8915EDD0D46B5A3C3A8041CC702
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 5fc47445cbd30a0d5b29d032c7304a61e4ac30c0e6e514108a99717f677edec7
                  • Instruction ID: 4eeffafc50cb3dce16fd0b8743207525cef0c45b568bc47e74dbfdeab577a832
                  • Opcode Fuzzy Hash: 5fc47445cbd30a0d5b29d032c7304a61e4ac30c0e6e514108a99717f677edec7
                  • Instruction Fuzzy Hash: CDD0A930C2520C9BC784FBBCA84836CBBB4AB00200F6008A98C08932C0EA705A80CB82
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226880222.00000000018F2000.00000040.00000001.sdmp, Offset: 018F2000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 37177a12be6c89ec9c5f6f1753153f55dd0cdbe0d42e515aa9f0f613d7ecebf3
                  • Instruction ID: f9c749668dfaf395a4636102fb83cea055703b22a832f24a96d70541efb20bb4
                  • Opcode Fuzzy Hash: 37177a12be6c89ec9c5f6f1753153f55dd0cdbe0d42e515aa9f0f613d7ecebf3
                  • Instruction Fuzzy Hash: A2D05E79215A818FE327CA1CC1A8B953FA5BB61B04F4644FEE900CB663C3A8DA81D210
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: aa5126e1d1795d5de63dadb0e80d81d1fab6d7018e41fe6b9390702fa0452ab7
                  • Instruction ID: c9a22ffbab23131117a5112a8c56b6a86cfadabc88602d6c1b818500ec8da6fa
                  • Opcode Fuzzy Hash: aa5126e1d1795d5de63dadb0e80d81d1fab6d7018e41fe6b9390702fa0452ab7
                  • Instruction Fuzzy Hash: B6D05BB4D1430D9ACB84DA90C441B9DF7FAAB45300F0090DA855DBA2D4CB345644CF25
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: c7a5b12f0d36342690e3a6f83324e312a989c6c8b97d70b9d01cf9a9f036ccf0
                  • Instruction ID: 0517630cbed80c1bd620c999c1220a1e0937b686aa2b06ac9bb8b499b8d256c4
                  • Opcode Fuzzy Hash: c7a5b12f0d36342690e3a6f83324e312a989c6c8b97d70b9d01cf9a9f036ccf0
                  • Instruction Fuzzy Hash: DCD0C93AE01108CF8B108FF8E0444DCF775EBCA225B11946AC514B3300C7319856CF50
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 14c63056e3824a89b16fd29b04ce7bb07880fabadca1c001e0c4e58c4b009555
                  • Instruction ID: 7dbc92ddc29ec504db9ba56231c6811f05c0a25a25353eca4632a7207254efe4
                  • Opcode Fuzzy Hash: 14c63056e3824a89b16fd29b04ce7bb07880fabadca1c001e0c4e58c4b009555
                  • Instruction Fuzzy Hash: 28D0A9309053089BC780FFFCE84934DBBF8AB04200F1004A58C0893240E671A688CBD2
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226880222.00000000018F2000.00000040.00000001.sdmp, Offset: 018F2000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: eda3ed329b90c208b328d84999f0e74a2255ab94b730f3718772c81dd599fb5f
                  • Instruction ID: 5285894689ad944d83bbab11fe4efeaee7424f909db1f3abdee2474675806bc6
                  • Opcode Fuzzy Hash: eda3ed329b90c208b328d84999f0e74a2255ab94b730f3718772c81dd599fb5f
                  • Instruction Fuzzy Hash: 4BD05E742006818BD715DB0CC594F593BD5EB41B00F0645ECAE00CB672C3A4D981C600
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 9588b872ab4bb7f91027df90e3734e97733d1329df9be61a6afd6c6ba6614d6e
                  • Instruction ID: 4ee884d74f65a2ad93ee69726f8407e852e2c8f3072481a38f08b374073ce9f4
                  • Opcode Fuzzy Hash: 9588b872ab4bb7f91027df90e3734e97733d1329df9be61a6afd6c6ba6614d6e
                  • Instruction Fuzzy Hash: BDD05E78C0922A9BDFD0DB94D88568DB7BBBB96310F2055CE9109F6390CB306A84DF11
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 51b8488b38dd3b3298b7b898aa6fa27af8c1487e36266b157b2ca2c14fb22149
                  • Instruction ID: 7208933b73498a6aa1cb727c7426fb2e7fce6cede441ced82fba01280b42aeef
                  • Opcode Fuzzy Hash: 51b8488b38dd3b3298b7b898aa6fa27af8c1487e36266b157b2ca2c14fb22149
                  • Instruction Fuzzy Hash: 88D067749083588EDB40CBA4C540B9DBBF6BB56300F205095850D67245C7345A41CF16
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: d264c3940c917c0363117476f55115d465d76dd4d8ab1e6c65f4eec813a5c691
                  • Instruction ID: 51dad00d3da56a7401f44810e0636c96eef87bb35179bd862d2082b814ffccc6
                  • Opcode Fuzzy Hash: d264c3940c917c0363117476f55115d465d76dd4d8ab1e6c65f4eec813a5c691
                  • Instruction Fuzzy Hash: 20D01774C4422ADACB54CFA0C880BAEBBB6AB45304F0090D9C41AA6244D6309940DF25
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 0c34aa5806006f79f882aa623e85382de53f5dc609f0814010995002c886e654
                  • Instruction ID: 093edaebb92952b14c00d971c4c93712eae5bab0debedafb4f7cc8565132e64b
                  • Opcode Fuzzy Hash: 0c34aa5806006f79f882aa623e85382de53f5dc609f0814010995002c886e654
                  • Instruction Fuzzy Hash: 8BE0EC79901258CFDB14CF21C9446D9BBB1BB56320F1085DA845AA7291C2755A82CF41
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 0e8f4534286af0d1cd9576f2be70788c1ef1754ef96508262a7b1db32d8e6d83
                  • Instruction ID: 0caf60ae6d201c4ef7706b14a6c0d1ee9f7a89420d6c4bc3484b3f9dc3d437ac
                  • Opcode Fuzzy Hash: 0e8f4534286af0d1cd9576f2be70788c1ef1754ef96508262a7b1db32d8e6d83
                  • Instruction Fuzzy Hash: 97D05E30A1A21AEFCB64CB28EC8479DBFB2FB05300F10569C9045AF154DB309E408F00
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: a866f3dd8e9b2ca84045e0d3ce9daf5cc1077b0dcc75eb08afa7c56d413742cc
                  • Instruction ID: e7b5249736cf1bdaa9f18b6bc9df0e607c74df56997c5d9be3ed586031f459bf
                  • Opcode Fuzzy Hash: a866f3dd8e9b2ca84045e0d3ce9daf5cc1077b0dcc75eb08afa7c56d413742cc
                  • Instruction Fuzzy Hash: 14D06C75905314CFCB68CF24C5A8A987BB3AB09316F1004ACE80A6B265CB32DAC0CF01
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 48aeabc5d6559897e31d28e81e41f389821aa6c45f0836fefafd725f762c955a
                  • Instruction ID: c16a4ccc13076bad81a864e17909401ff3ca2719112dcf7996ff0eb7096c6dc6
                  • Opcode Fuzzy Hash: 48aeabc5d6559897e31d28e81e41f389821aa6c45f0836fefafd725f762c955a
                  • Instruction Fuzzy Hash: 3CC002B8D0411D9ECB98DFD4D4407EDB7BAEB95300F10A099454973654DA305A84CF56
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 493ab7ad42f086685a5f6eb8c94732372b8cdf84c7d28115519d6f7685508453
                  • Instruction ID: 085543e26cb1193f137c44945dc39c3a982f4e9f5a193d75a22c61138ca66c5f
                  • Opcode Fuzzy Hash: 493ab7ad42f086685a5f6eb8c94732372b8cdf84c7d28115519d6f7685508453
                  • Instruction Fuzzy Hash: 2EC01274D043088FCB50CFA4C44079DBBF6AB46300F10909A800C77644CA304940CF16
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: db3540a44189aa6e51d3a35797d8bbf826961cd632417a36481e517bc4d721fd
                  • Instruction ID: 92ee7e7fdb59a15b5e8a32d7d6a49513cfc047bc3b81cc4024963173938fde94
                  • Opcode Fuzzy Hash: db3540a44189aa6e51d3a35797d8bbf826961cd632417a36481e517bc4d721fd
                  • Instruction Fuzzy Hash: F2C04C718152868F8B04CFE0D6A549DBFB1FB15343B10585D8007AE098D6355544DB11
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 601f4aa5660ca9b7141d1cb8d0f7e5b26a7e27cf0d1509e36818f0c98e6866b5
                  • Instruction ID: 2170105f066d147135c47b30d5e0dab11f96e0de5c1e8da9579b7d5111ea5a70
                  • Opcode Fuzzy Hash: 601f4aa5660ca9b7141d1cb8d0f7e5b26a7e27cf0d1509e36818f0c98e6866b5
                  • Instruction Fuzzy Hash: CEC08C72429216CACB20CA10C08639ABA60BB08202F0084A1C04AD2815C3308280CA50
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Non-executed Functions

                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID: Bgsn$^Mx2
                  • API String ID: 0-1809678249
                  • Opcode ID: bd468889a4af03b9630c231d9375f9d9791d6a85899c9db25d33318fb54e33cf
                  • Instruction ID: 3b9b2620ea4fb7ae5956d1684352ce2c049a8cc0cb13071fc57b2e2cc33fabd7
                  • Opcode Fuzzy Hash: bd468889a4af03b9630c231d9375f9d9791d6a85899c9db25d33318fb54e33cf
                  • Instruction Fuzzy Hash: 1D515970D042099FCB09CFAAC5815AEFFB2FB85310F14C5AEC415AB254EB349A51EF95
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID: |Up]
                  • API String ID: 0-1346336988
                  • Opcode ID: f81612fd4d418b85d03e34ad6e970ef3cc5beea442de0b364ce1a6cad819255b
                  • Instruction ID: 496ce7a91f0fafe621da5647f6fc31a7b4663470e2ef04c966540ae27afb3496
                  • Opcode Fuzzy Hash: f81612fd4d418b85d03e34ad6e970ef3cc5beea442de0b364ce1a6cad819255b
                  • Instruction Fuzzy Hash: 2F911274E15209EFCB40CFA9D5849ADBBF2FF49310F1489AEE815AB251D734AA40DF50
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID: |Up]
                  • API String ID: 0-1346336988
                  • Opcode ID: fe30f0f1b1306da46ae407b3e1f6c554d06634554fee2f801e6a91a4fde71911
                  • Instruction ID: e8407869c51048f5c79aad3f9e23fd8dff7aa2d4e1442461cff87c736584f310
                  • Opcode Fuzzy Hash: fe30f0f1b1306da46ae407b3e1f6c554d06634554fee2f801e6a91a4fde71911
                  • Instruction Fuzzy Hash: 5A71EC74E15209EFCB40CFA9D58499DBBF2BF89310F14D4AAE805AB261D734AA40DF50
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID: |Up]
                  • API String ID: 0-1346336988
                  • Opcode ID: 4cc3713a175309795667c933f6aab6b160bca1260dcf27b8b8e26c16e5e5cadd
                  • Instruction ID: 3232e9248914bb57d9b7ec697fe5e3608ffc9d8882bf16f2c4b022a87955daee
                  • Opcode Fuzzy Hash: 4cc3713a175309795667c933f6aab6b160bca1260dcf27b8b8e26c16e5e5cadd
                  • Instruction Fuzzy Hash: 5C71C974E15219EFCB44CFA9D58499DFBF2FB88310F14D4A9E809AB220D734AA41DF50
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID: s
                  • API String ID: 0-3507966331
                  • Opcode ID: 74afc439114f0196439f6666c489b82634e859fce849339d19f56a82c1faa901
                  • Instruction ID: c484195503f3229b0fdb9adbe7e5fcd4a12d477ee098627b275bbdc4141dbd5b
                  • Opcode Fuzzy Hash: 74afc439114f0196439f6666c489b82634e859fce849339d19f56a82c1faa901
                  • Instruction Fuzzy Hash: 4951E171D1520AAFCB08CFAAC9819AEBBF2FB89300F54D5AED415B7214D738A601DF54
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID: s
                  • API String ID: 0-3507966331
                  • Opcode ID: 97a6c781f88dcd405ef73889708ed92200aff169bd815452b428caf1a4f1a2d7
                  • Instruction ID: caee5b6d9dd15f18d3acdf754bd6fbf5c22a62d412c8dc9a31f48784c3bca937
                  • Opcode Fuzzy Hash: 97a6c781f88dcd405ef73889708ed92200aff169bd815452b428caf1a4f1a2d7
                  • Instruction Fuzzy Hash: 4B51D070D1520AAFCB08CFAAC5819AEBBF2FB89300F54D5AED515B7214D7389A01DF54
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID: Bgsn
                  • API String ID: 0-4091147365
                  • Opcode ID: cfde9db20d9c1a6b33ba895effb4905baf172fcafc4dbcf5c6696dd2cf16b52f
                  • Instruction ID: ae7412f4f6def16b914f35685410be4cc8a4071f2add30b457c0700010ebf3b4
                  • Opcode Fuzzy Hash: cfde9db20d9c1a6b33ba895effb4905baf172fcafc4dbcf5c6696dd2cf16b52f
                  • Instruction Fuzzy Hash: DB41E570D0460A9FCB08CFAAC5819AEFBF2FB88340F50D4AEC415BB214DB3496519F94
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID: u%P
                  • API String ID: 0-1269227331
                  • Opcode ID: 93caef2351ced9013a7c50f3646ed1b19e3a7d6bf6556e75d96dd23330c5587b
                  • Instruction ID: cd0be3d43bf2a451a4463ecf78012366bb3352af216b85d071361e69d3843293
                  • Opcode Fuzzy Hash: 93caef2351ced9013a7c50f3646ed1b19e3a7d6bf6556e75d96dd23330c5587b
                  • Instruction Fuzzy Hash: 4511DAB1D05608DBEB58CFAB894059EFBF7BFC8300F24C17E8418A7215EA3446029F41
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.226376369.0000000000EC2000.00000002.00020000.sdmp, Offset: 00EC0000, based on PE: true
                  • Associated: 00000000.00000002.226369562.0000000000EC0000.00000002.00020000.sdmp Download File
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 21de2c3620ec86b3dad74fadf82c9bbf23a8ca196cb5894a2bb5ff8f8fb2f49d
                  • Instruction ID: 3a3bd6e30ed8880f5609e672a84bbe4b7fe519e05f993e6620b3aa4c300d47be
                  • Opcode Fuzzy Hash: 21de2c3620ec86b3dad74fadf82c9bbf23a8ca196cb5894a2bb5ff8f8fb2f49d
                  • Instruction Fuzzy Hash: 4492AC2244E3D04FEB07AB7485BA5D2BF60AD5332932DA1EFC8C55F093D256444BEB62
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 5ad22812698cc232ea3194765f6a7cf6a15198589907d4125585712700ba4c94
                  • Instruction ID: 3ea76493abf69de8d5a2a3f4f6b8f6b11dcdf24a85a2bca2addf71d8d1ab8e90
                  • Opcode Fuzzy Hash: 5ad22812698cc232ea3194765f6a7cf6a15198589907d4125585712700ba4c94
                  • Instruction Fuzzy Hash: 6CB1F874D04298DFDB24CFA9C580AADFBB2FF89304F2481AED415AB255D7349A42EF50
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 0240c2376b0dc7d8a452fb58b64fbfb13c047f082ae3ad0acc8b084c771269ae
                  • Instruction ID: 7b3cefbe8ddd13e1fe556137cd4a270792f50e5ab6eca5b0bfd04f6c79eba75f
                  • Opcode Fuzzy Hash: 0240c2376b0dc7d8a452fb58b64fbfb13c047f082ae3ad0acc8b084c771269ae
                  • Instruction Fuzzy Hash: 5EA158B0D05209DFCB04CFAAD5859AEBFF6FF49310F24959DD428AB254D7309A429F90
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: e45064892db84044330f8da404da41eb46c3271ff08d64fd4379ee94cfe7755c
                  • Instruction ID: dbfe80bfb8007d3289913e81369bb803251bb4d60c4ea0a39c224f7e70c14fbc
                  • Opcode Fuzzy Hash: e45064892db84044330f8da404da41eb46c3271ff08d64fd4379ee94cfe7755c
                  • Instruction Fuzzy Hash: BD71F5B4D1521ADFDB48CFA8D5819AEFBF1FB48310F10859ED815AB201D7309A81DFA5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: fbe1ed0ec0b6bfc866b5afe0f6a089790582cd07f3d6485e17f0702af04fb01f
                  • Instruction ID: d099c58053df16721b1307069a5f32be5eb4d205ad327008aeaff61946b58d3a
                  • Opcode Fuzzy Hash: fbe1ed0ec0b6bfc866b5afe0f6a089790582cd07f3d6485e17f0702af04fb01f
                  • Instruction Fuzzy Hash: 98518C70D0520A9FCB05CFAAC544AAEFBFAFF89310F10969DC025BB254D3349A41DBA5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 1415d1cc4a4e98b2aa0b0e535017052c86b9ef30b5b17fda79438cd96c36981e
                  • Instruction ID: ad670f2a507364ba9c4a32a593d0d9d34e5fc6bf06893c275217d5519f082e75
                  • Opcode Fuzzy Hash: 1415d1cc4a4e98b2aa0b0e535017052c86b9ef30b5b17fda79438cd96c36981e
                  • Instruction Fuzzy Hash: 79511A71E4461A8BDB28CF66D9447E9BBF2BB88300F05C5EAC51DB7654E7304A85DF40
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 40b8735ae6002406354425e06886a2db5f6bb4d2d8bb4191a8b099ca3a6c6bf1
                  • Instruction ID: 6073479d751351817c1e50862f5078b23555eb002af29eea97d6177404170c73
                  • Opcode Fuzzy Hash: 40b8735ae6002406354425e06886a2db5f6bb4d2d8bb4191a8b099ca3a6c6bf1
                  • Instruction Fuzzy Hash: B451D574D1521ADFDB48CFA8D5819AEFBF2FB88310F10859ED405AB205D730AA81DFA5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: c28dc26d8895f0bc04e8d542853154a2d55697f78d6c417a912ccec92a13cd89
                  • Instruction ID: 75b6cf318d50d6cd3e27c4bcf9fd3679f681f4a29905979cb4c5371e5070c65a
                  • Opcode Fuzzy Hash: c28dc26d8895f0bc04e8d542853154a2d55697f78d6c417a912ccec92a13cd89
                  • Instruction Fuzzy Hash: C151C3B4D1521ADFDB08CFA8D5819AEFBB2FF88310F10959DD405AB205D730AA81DFA5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 709811e6fe6d8740e23d2c053663d9d4a17e33c8c9078ec7aad5333d18e12378
                  • Instruction ID: 7914f9d640fead558449f82de1240519eaee071a3c6fd64475e70aaeba5249c1
                  • Opcode Fuzzy Hash: 709811e6fe6d8740e23d2c053663d9d4a17e33c8c9078ec7aad5333d18e12378
                  • Instruction Fuzzy Hash: 5B51F5B0D05249DFCB48CFA8C5816AEBFB2FB49300F24959ED815AB204D7349A41EFA5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: db5870a749e43d5e21091825ce74874f1f5a5a74eb966be92fe9a53ee91d28cb
                  • Instruction ID: e33b8f74ec536266ed8ff226bf5b1140242a76c21ef8760b56cd6b80f3150b76
                  • Opcode Fuzzy Hash: db5870a749e43d5e21091825ce74874f1f5a5a74eb966be92fe9a53ee91d28cb
                  • Instruction Fuzzy Hash: AA51F2B8D04209DBCB05CFAAC880AADBFF2FF89310F2095AED451A7261D7349A41DF55
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 21ed19a7a8e766d6cc56d2ddd2b70d58cea8bccc333481ee1c1f20c0b2887b91
                  • Instruction ID: b7b8fd46cef26a2835a52eaf36d14fdbf28101f6f6e446bb262a1752c5b58577
                  • Opcode Fuzzy Hash: 21ed19a7a8e766d6cc56d2ddd2b70d58cea8bccc333481ee1c1f20c0b2887b91
                  • Instruction Fuzzy Hash: B951F3B8D04209DBCB04CFAAD880AAEBBF2FF89310F1095ADD455BB251D7349A41DF55
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 5b86fde6e946f44077b83f11d5bc6f7bf01e3d05701701a5bcdcff1664327127
                  • Instruction ID: 5455d9a7bb2e1067f96598d9544986150437312f93759daa390c6691373be1ee
                  • Opcode Fuzzy Hash: 5b86fde6e946f44077b83f11d5bc6f7bf01e3d05701701a5bcdcff1664327127
                  • Instruction Fuzzy Hash: F1418E70E0920AEFCB04CF99C5849AEFFB2FB89314F1499DEC816A7205D7349A41EB51
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: c166fec52935655ddfb23a81d4bdbe2bdb076b780d05dfdc12360d5cde8d2282
                  • Instruction ID: b86a2527d6264c1cb36b2845e7d9043d588831b72f1043cc81f92132827521bb
                  • Opcode Fuzzy Hash: c166fec52935655ddfb23a81d4bdbe2bdb076b780d05dfdc12360d5cde8d2282
                  • Instruction Fuzzy Hash: 79410470D1520A9FCB08CFAAC9815AEFBB2FB88340F2494AEC415BB215D7309B509F95
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 7f7de574679c29b7eff41281f1ad9a08071863bc931840cbe017f8e269a4b4e2
                  • Instruction ID: 6218f7dfae7cbfd6ae10b2202f7a51091a1a0c6a18e4b2d08647fcc5b5ec0b86
                  • Opcode Fuzzy Hash: 7f7de574679c29b7eff41281f1ad9a08071863bc931840cbe017f8e269a4b4e2
                  • Instruction Fuzzy Hash: 1041F2B4D04219DFCB04CFA9C5899AEFBF2AB89300F10D5AED416AB254D335AA41DF50
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 5ea30d3d3eab81239d3ddf9dfc6246efd5a19114973477c33eadcd675afc3741
                  • Instruction ID: 776d610eb1d783b23a0081ebe3ac287d731d003b290f429283f3c5cbe9ffada5
                  • Opcode Fuzzy Hash: 5ea30d3d3eab81239d3ddf9dfc6246efd5a19114973477c33eadcd675afc3741
                  • Instruction Fuzzy Hash: 66410670D1520ADFCB08CFAAC5815AEFBB2FB88340F2495AEC415BB214D7309B509F95
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 85ee416bbf7e52d9212e29b905ab9225ffd5be9c1bae95cdf1c4a5db239ce8ed
                  • Instruction ID: e651da26c61c4d6d2427e3a2a145fa4d7cbaaad2195a06ae991ce287e31e600c
                  • Opcode Fuzzy Hash: 85ee416bbf7e52d9212e29b905ab9225ffd5be9c1bae95cdf1c4a5db239ce8ed
                  • Instruction Fuzzy Hash: DB31F370D04619CFDB18CFAAC940AAEFBB6FF89300F10C1AED419AB215DB345A429F40
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 954fc5a5c84b460bf1d0ab8cb97df3a702058fd808fa84c9905cd3a23d14bc99
                  • Instruction ID: e5a165c8092709ec20577daaa1c82e99647c4a251c9f193219b42473edd28345
                  • Opcode Fuzzy Hash: 954fc5a5c84b460bf1d0ab8cb97df3a702058fd808fa84c9905cd3a23d14bc99
                  • Instruction Fuzzy Hash: 03210971E056199BEB18CF6BD84069EBBF7AFC9300F08C0BAD408A6215DB3005419F51
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: fbb1c93343f23257d5acd06c2e7e873cd5a4d8e2f42c420b65ee67e4441ee9b4
                  • Instruction ID: f9faf379467279cecf414c295238b6cabb989f290bca8d3ee8e83fa7b9a7de16
                  • Opcode Fuzzy Hash: fbb1c93343f23257d5acd06c2e7e873cd5a4d8e2f42c420b65ee67e4441ee9b4
                  • Instruction Fuzzy Hash: 13210B76E056189BEB19CF6BD8406DEFBF3AFD9300F08C1BAD408A6259D7304546CB51
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 64f1071976cc4f560b309f097cf17f1ab0e68770719cb0f73b80792381ffd694
                  • Instruction ID: 42fa528b193acd5e4acd4ff5caa983e630cb97212da2749bc2e59a215685c3f2
                  • Opcode Fuzzy Hash: 64f1071976cc4f560b309f097cf17f1ab0e68770719cb0f73b80792381ffd694
                  • Instruction Fuzzy Hash: 9F11E470D542199FCB68DFA5D884BEEBBF4BF5A300F14556AD005B3294DB348A40DFA4
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230704378.00000000055E0000.00000040.00000001.sdmp, Offset: 055E0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 32f068ab61d1f2087a2544942fd19f53bf26784f69a40f7fd01ce5d14cd43ebc
                  • Instruction ID: 6e4857dc15e1b94bf9ee1974a4bd589dea0de790e4fe8282762e9cecabc584be
                  • Opcode Fuzzy Hash: 32f068ab61d1f2087a2544942fd19f53bf26784f69a40f7fd01ce5d14cd43ebc
                  • Instruction Fuzzy Hash: 9B11F874D442199FDB28DFAAD854BEEBAF5BF4A300F149469D005B3244DB348A40DFA8
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: f526d9639e6506d40efee5199c9f59df21d8729c8b7bd5a88eca01e7072caf37
                  • Instruction ID: d56266e502a1d77326ca5bd66c0fa2b1d3a03d4d33117e00652b553095a54b9b
                  • Opcode Fuzzy Hash: f526d9639e6506d40efee5199c9f59df21d8729c8b7bd5a88eca01e7072caf37
                  • Instruction Fuzzy Hash: A411C9B1D14608DBEB18CFABD54159EFBF6BF88300F14C56ED418AB215DB344A029F41
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.230815419.00000000057C0000.00000040.00000001.sdmp, Offset: 057C0000, based on PE: false
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 300f8b44f64698713468ebd305e00803cdba8f522759007946b37192b2bd9b45
                  • Instruction ID: cb11d8bee4fd55521f6dcb7bf3006edceb6388f6a432eb10e69e0a2932cf794b
                  • Opcode Fuzzy Hash: 300f8b44f64698713468ebd305e00803cdba8f522759007946b37192b2bd9b45
                  • Instruction Fuzzy Hash: 3611DBB0D04609CBEB18CFAB99415AEFBF7AFC8300F14C17E9918A7215EA3456419F41
                  Uniqueness

                  Uniqueness Score: -1.00%