Windows Analysis Report KDVTOodd7T
Overview
General Information
Detection
Score: | 92 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
Process Tree |
---|
|
Malware Configuration |
---|
Threatname: GuLoader |
---|
{"Payload URL": "https://bara-seck.com/bin_dwjDbyFc82.bin, http://benvenuti.rs/wp-content/bin_dwjDbyFc82.bin"}
Yara Overview |
---|
Initial Sample |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_GuLoader_1 | Yara detected GuLoader | Joe Security |
Memory Dumps |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_GuLoader_2 | Yara detected GuLoader | Joe Security | ||
JoeSecurity_GuLoader_1 | Yara detected GuLoader | Joe Security | ||
JoeSecurity_GuLoader_1 | Yara detected GuLoader | Joe Security |
Unpacked PEs |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_GuLoader_1 | Yara detected GuLoader | Joe Security | ||
JoeSecurity_GuLoader_1 | Yara detected GuLoader | Joe Security |
Sigma Overview |
---|
No Sigma rule has matched |
---|
Signature Overview |
---|
Click to jump to signature section
AV Detection: |
---|
Antivirus detection for URL or domain | Show sources |
Source: | Avira URL Cloud: |
Found malware configuration | Show sources |
Source: | Malware Configuration Extractor: |
Source: | Static PE information: |
Networking: |
---|
C2 URLs / IPs found in malware configuration | Show sources |
Source: | URLs: |
Source: | Process Stats: |
Source: | Code function: | 1_2_021E5BFE | |
Source: | Code function: | 1_2_021E5E16 | |
Source: | Code function: | 1_2_021E5BFF | |
Source: | Code function: | 1_2_021E5C4F | |
Source: | Code function: | 1_2_021E5C64 | |
Source: | Code function: | 1_2_021E5CD6 | |
Source: | Code function: | 1_2_021E5D1E | |
Source: | Code function: | 1_2_021E5D5E | |
Source: | Code function: | 1_2_021E5DCA |
Source: | Code function: | 1_2_0040E16D | |
Source: | Code function: | 1_2_00404D55 | |
Source: | Code function: | 1_2_021E5BFE | |
Source: | Code function: | 1_2_021E9A18 | |
Source: | Code function: | 1_2_021E0E16 | |
Source: | Code function: | 1_2_021E1A3F | |
Source: | Code function: | 1_2_021E4A3C | |
Source: | Code function: | 1_2_021E1A3D | |
Source: | Code function: | 1_2_021E4638 | |
Source: | Code function: | 1_2_021E9A30 | |
Source: | Code function: | 1_2_021E1226 | |
Source: | Code function: | 1_2_021E3258 | |
Source: | Code function: | 1_2_021E9A57 | |
Source: | Code function: | 1_2_021E9254 | |
Source: | Code function: | 1_2_021E4E46 | |
Source: | Code function: | 1_2_021E0E72 | |
Source: | Code function: | 1_2_021E1268 | |
Source: | Code function: | 1_2_021E1A9E | |
Source: | Code function: | 1_2_021E46BA | |
Source: | Code function: | 1_2_021E32BA | |
Source: | Code function: | 1_2_021E62AA | |
Source: | Code function: | 1_2_021E4AA6 | |
Source: | Code function: | 1_2_021E0EA6 | |
Source: | Code function: | 1_2_021E12C6 | |
Source: | Code function: | 1_2_021E76C2 | |
Source: | Code function: | 1_2_021E1AFE | |
Source: | Code function: | 1_2_021E46FE | |
Source: | Code function: | 1_2_021E4AF2 | |
Source: | Code function: | 1_2_021E3AF1 | |
Source: | Code function: | 1_2_021E1B1F | |
Source: | Code function: | 1_2_021E8B17 | |
Source: | Code function: | 1_2_021E6313 | |
Source: | Code function: | 1_2_021E3B0E | |
Source: | Code function: | 1_2_021E330B | |
Source: | Code function: | 1_2_021E0708 | |
Source: | Code function: | 1_2_021E8B04 | |
Source: | Code function: | 1_2_021E0F00 | |
Source: | Code function: | 1_2_021E1326 | |
Source: | Code function: | 1_2_021E0F5A | |
Source: | Code function: | 1_2_021E475A | |
Source: | Code function: | 1_2_021E4B58 | |
Source: | Code function: | 1_2_021E3B50 | |
Source: | Code function: | 1_2_021E1B76 | |
Source: | Code function: | 1_2_021E136E | |
Source: | Code function: | 1_2_021E6362 | |
Source: | Code function: | 1_2_021E3360 | |
Source: | Code function: | 1_2_021E0F9E | |
Source: | Code function: | 1_2_021E3B9F | |
Source: | Code function: | 1_2_021E8B8F | |
Source: | Code function: | 1_2_021E338B | |
Source: | Code function: | 1_2_021E3FB8 | |
Source: | Code function: | 1_2_021E63A3 | |
Source: | Code function: | 1_2_021E47A0 | |
Source: | Code function: | 1_2_021E2BDB | |
Source: | Code function: | 1_2_021E4BC8 | |
Source: | Code function: | 1_2_021E8BC4 | |
Source: | Code function: | 1_2_021E13C3 | |
Source: | Code function: | 1_2_021E5BFF | |
Source: | Code function: | 1_2_021E1FF3 | |
Source: | Code function: | 1_2_021E1FE8 | |
Source: | Code function: | 1_2_021E0FE4 | |
Source: | Code function: | 1_2_021E3BE3 | |
Source: | Code function: | 1_2_021E4C1E | |
Source: | Code function: | 1_2_021E641F | |
Source: | Code function: | 1_2_021E441C | |
Source: | Code function: | 1_2_021E8C1A | |
Source: | Code function: | 1_2_021E2C14 | |
Source: | Code function: | 1_2_021E4800 | |
Source: | Code function: | 1_2_021E1038 | |
Source: | Code function: | 1_2_021E3036 | |
Source: | Code function: | 1_2_021E4430 | |
Source: | Code function: | 1_2_021E202A | |
Source: | Code function: | 1_2_021E4C5E | |
Source: | Code function: | 1_2_021E484E | |
Source: | Code function: | 1_2_021E5C4F | |
Source: | Code function: | 1_2_021E304B | |
Source: | Code function: | 1_2_021E8849 | |
Source: | Code function: | 1_2_021E447F | |
Source: | Code function: | 1_2_021E2C78 | |
Source: | Code function: | 1_2_021E3C6B | |
Source: | Code function: | 1_2_021E8C66 | |
Source: | Code function: | 1_2_021E1464 | |
Source: | Code function: | 1_2_021E5C64 | |
Source: | Code function: | 1_2_021E3C9C | |
Source: | Code function: | 1_2_021E108C | |
Source: | Code function: | 1_2_021E308C | |
Source: | Code function: | 1_2_021E0C87 | |
Source: | Code function: | 1_2_021E0CBE | |
Source: | Code function: | 1_2_021E48BA | |
Source: | Code function: | 1_2_021E54B5 | |
Source: | Code function: | 1_2_021E14B0 | |
Source: | Code function: | 1_2_021E8CA7 | |
Source: | Code function: | 1_2_021E30DE | |
Source: | Code function: | 1_2_021E98DA | |
Source: | Code function: | 1_2_021E58D3 | |
Source: | Code function: | 1_2_021E44CF | |
Source: | Code function: | 1_2_021E98CD | |
Source: | Code function: | 1_2_021E74CA | |
Source: | Code function: | 1_2_021E2CC7 | |
Source: | Code function: | 1_2_021E4CC5 | |
Source: | Code function: | 1_2_021E4CFF | |
Source: | Code function: | 1_2_021E98F7 | |
Source: | Code function: | 1_2_021E10EB | |
Source: | Code function: | 1_2_021E8CEB | |
Source: | Code function: | 1_2_021E0D17 | |
Source: | Code function: | 1_2_021E4913 | |
Source: | Code function: | 1_2_021E9913 | |
Source: | Code function: | 1_2_021E2D05 | |
Source: | Code function: | 1_2_021E3138 | |
Source: | Code function: | 1_2_021E9937 | |
Source: | Code function: | 1_2_021E1132 | |
Source: | Code function: | 1_2_021E4532 | |
Source: | Code function: | 1_2_021E8D30 | |
Source: | Code function: | 1_2_021E0D31 | |
Source: | Code function: | 1_2_021E995A | |
Source: | Code function: | 1_2_021E2D4A | |
Source: | Code function: | 1_2_021E457F | |
Source: | Code function: | 1_2_021E997A | |
Source: | Code function: | 1_2_021E4D70 | |
Source: | Code function: | 1_2_021E8D6A | |
Source: | Code function: | 1_2_021E4968 | |
Source: | Code function: | 1_2_021E119B | |
Source: | Code function: | 1_2_021E4990 | |
Source: | Code function: | 1_2_021E6180 | |
Source: | Code function: | 1_2_021E4DBB | |
Source: | Code function: | 1_2_021E61BB | |
Source: | Code function: | 1_2_021E8DAA | |
Source: | Code function: | 1_2_021E99A8 | |
Source: | Code function: | 1_2_021E31A0 | |
Source: | Code function: | 1_2_021E99DF | |
Source: | Code function: | 1_2_021E45D6 | |
Source: | Code function: | 1_2_021E0DD3 | |
Source: | Code function: | 1_2_021E11C8 | |
Source: | Code function: | 1_2_021E99C3 | |
Source: | Code function: | 1_2_021E4DFA | |
Source: | Code function: | 1_2_021E99F7 | |
Source: | Code function: | 1_2_021E8DF2 | |
Source: | Code function: | 1_2_021E31EF | |
Source: | Code function: | 1_2_021E49EF | |
Source: | Code function: | 1_2_021E61EC |
Source: | Static PE information: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | Section loaded: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Data Obfuscation: |
---|
Yara detected GuLoader | Show sources |
Source: | File source: |
Yara detected GuLoader | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Code function: | 1_2_00408277 | |
Source: | Code function: | 1_2_004072D3 | |
Source: | Code function: | 1_2_004046ED | |
Source: | Code function: | 1_2_004057F8 | |
Source: | Code function: | 1_2_021E5467 | |
Source: | Code function: | 1_2_021EA194 |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion: |
---|
Contains functionality to detect hardware virtualization (CPUID execution measurement) | Show sources |
Source: | Code function: | 1_2_021E0E16 | |
Source: | Code function: | 1_2_021E4A3C | |
Source: | Code function: | 1_2_021E4638 | |
Source: | Code function: | 1_2_021E9254 | |
Source: | Code function: | 1_2_021E4E46 | |
Source: | Code function: | 1_2_021E0E72 | |
Source: | Code function: | 1_2_021E46BA | |
Source: | Code function: | 1_2_021E4AA6 | |
Source: | Code function: | 1_2_021E0EA6 | |
Source: | Code function: | 1_2_021E4ECE | |
Source: | Code function: | 1_2_021E76C2 | |
Source: | Code function: | 1_2_021E46FE | |
Source: | Code function: | 1_2_021E4EFA | |
Source: | Code function: | 1_2_021E4AF2 | |
Source: | Code function: | 1_2_021E3AF1 | |
Source: | Code function: | 1_2_021E8B17 | |
Source: | Code function: | 1_2_021E8B04 | |
Source: | Code function: | 1_2_021E0F00 | |
Source: | Code function: | 1_2_021E0F5A | |
Source: | Code function: | 1_2_021E475A | |
Source: | Code function: | 1_2_021E4B58 | |
Source: | Code function: | 1_2_021E4F54 | |
Source: | Code function: | 1_2_021E0F9E | |
Source: | Code function: | 1_2_021E8B8F | |
Source: | Code function: | 1_2_021E3FB8 | |
Source: | Code function: | 1_2_021E47A0 | |
Source: | Code function: | 1_2_021E4BC8 | |
Source: | Code function: | 1_2_021E4FC6 | |
Source: | Code function: | 1_2_021E8BC4 | |
Source: | Code function: | 1_2_021E0FE4 | |
Source: | Code function: | 1_2_021E4C1E | |
Source: | Code function: | 1_2_021E4800 | |
Source: | Code function: | 1_2_021E1038 | |
Source: | Code function: | 1_2_021E4430 | |
Source: | Code function: | 1_2_021E7C22 | |
Source: | Code function: | 1_2_021E4C5E | |
Source: | Code function: | 1_2_021E484E | |
Source: | Code function: | 1_2_021E8849 | |
Source: | Code function: | 1_2_021E7C47 | |
Source: | Code function: | 1_2_021E447F | |
Source: | Code function: | 1_2_021E108C | |
Source: | Code function: | 1_2_021E0C87 | |
Source: | Code function: | 1_2_021E0CBE | |
Source: | Code function: | 1_2_021E48BA | |
Source: | Code function: | 1_2_021E54B5 | |
Source: | Code function: | 1_2_021E44CF | |
Source: | Code function: | 1_2_021E74CA | |
Source: | Code function: | 1_2_021E4CC5 | |
Source: | Code function: | 1_2_021E4CFF | |
Source: | Code function: | 1_2_021E10EB | |
Source: | Code function: | 1_2_021E0D17 | |
Source: | Code function: | 1_2_021E4913 | |
Source: | Code function: | 1_2_021E1132 | |
Source: | Code function: | 1_2_021E4532 | |
Source: | Code function: | 1_2_021E0D31 | |
Source: | Code function: | 1_2_021E457F | |
Source: | Code function: | 1_2_021E4D70 | |
Source: | Code function: | 1_2_021E4968 | |
Source: | Code function: | 1_2_021E119B | |
Source: | Code function: | 1_2_021E6998 | |
Source: | Code function: | 1_2_021E4990 | |
Source: | Code function: | 1_2_021E4DBB | |
Source: | Code function: | 1_2_021E45D6 | |
Source: | Code function: | 1_2_021E29D5 | |
Source: | Code function: | 1_2_021E0DD3 | |
Source: | Code function: | 1_2_021E11C8 | |
Source: | Code function: | 1_2_021E4DFA | |
Source: | Code function: | 1_2_021E49EF |
Detected RDTSC dummy instruction sequence (likely for instruction hammering) | Show sources |
Source: | RDTSC instruction interceptor: |
Tries to detect virtualization through RDTSC time measurements | Show sources |
Source: | RDTSC instruction interceptor: | ||
Source: | RDTSC instruction interceptor: | ||
Source: | RDTSC instruction interceptor: | ||
Source: | RDTSC instruction interceptor: |
Source: | Code function: | 1_2_021E6A1F |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Anti Debugging: |
---|
Found potential dummy code loops (likely to delay analysis) | Show sources |
Source: | Process Stats: |
Source: | Code function: | 1_2_021E6A1F |
Source: | Code function: | 1_2_021E3AF1 | |
Source: | Code function: | 1_2_021E8B17 | |
Source: | Code function: | 1_2_021E3B0E | |
Source: | Code function: | 1_2_021E8B04 | |
Source: | Code function: | 1_2_021E57A7 | |
Source: | Code function: | 1_2_021E7FC9 | |
Source: | Code function: | 1_2_021E37C6 | |
Source: | Code function: | 1_2_021E3036 | |
Source: | Code function: | 1_2_021E8849 | |
Source: | Code function: | 1_2_021E79CB |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 1_2_021E2A10 |
Mitre Att&ck Matrix |
---|
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | Path Interception | Process Injection1 | Virtualization/Sandbox Evasion11 | OS Credential Dumping | Security Software Discovery41 | Remote Services | Archive Collected Data1 | Exfiltration Over Other Network Medium | Encrypted Channel1 | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Process Injection1 | LSASS Memory | Virtualization/Sandbox Evasion11 | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | Application Layer Protocol1 | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information1 | Security Account Manager | Process Discovery1 | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | Steganography | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | Binary Padding | NTDS | System Information Discovery311 | Distributed Component Object Model | Input Capture | Scheduled Transfer | Protocol Impersonation | SIM Card Swap | Carrier Billing Fraud |
Behavior Graph |
---|
Screenshots |
---|
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Antivirus, Machine Learning and Genetic Malware Detection |
---|
Initial Sample |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
7% | ReversingLabs |
Dropped Files |
---|
No Antivirus matches |
---|
Unpacked PE Files |
---|
No Antivirus matches |
---|
Domains |
---|
No Antivirus matches |
---|
URLs |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware |
Domains and IPs |
---|
Contacted Domains |
---|
No contacted domains info |
---|
Contacted URLs |
---|
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown |
Contacted IPs |
---|
No contacted IP infos |
---|
General Information |
---|
Joe Sandbox Version: | 32.0.0 Black Diamond |
Analysis ID: | 435339 |
Start date: | 16.06.2021 |
Start time: | 12:41:13 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 6m 4s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | KDVTOodd7T (renamed file extension from none to exe) |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 24 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal92.troj.evad.winEXE@1/0@0/0 |
EGA Information: | Failed |
HDC Information: |
|
HCA Information: | Failed |
Cookbook Comments: |
|
Warnings: | Show All
|
Simulations |
---|
Behavior and APIs |
---|
No simulations |
---|
Joe Sandbox View / Context |
---|
Created / dropped Files |
---|
No created / dropped files found |
---|
Static File Info |
---|
General | |
---|---|
File type: | |
Entropy (8bit): | 6.031806399752245 |
TrID: |
|
File name: | KDVTOodd7T.exe |
File size: | 94208 |
MD5: | 457fcb32ec7df1868df42f31cce2a301 |
SHA1: | 8bd3a8d8e0f6a48b51e5b3fbc119b154304044ec |
SHA256: | c7d1295093d4112a976f0c13be811d2a1fb6dc5928e1fabefe7b1315f7b0e95f |
SHA512: | 503902cb165b587751270b511c13dd7ae6065814f2ea2ca4b145d831c77d1b36735526827ac185c99b81bb702628f26e9f43f5ccbd075cc491bcd4c836708708 |
SSDEEP: | 1536:L10ol0/gh4343HqtCJWg4edfJPVo8xZSsIgO4jcYzy6ipu5W3EUanOYA2nJ29GLN:L6UdJ/4edfA0ZSsmVu5W3EUanOYA2nJn |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........c.S............&........ .......$......Rich....................PE..L...6..T.................@...0......D........P....@........ |
File Icon |
---|
Icon Hash: | 11c0c48c86cc08c4 |
Static PE Info |
---|
General | |
---|---|
Entrypoint: | 0x401644 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED |
DLL Characteristics: | |
Time Stamp: | 0x54EF7F36 [Thu Feb 26 20:16:54 2015 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | d5d16d1b76210dd28c8586fe9bac3119 |
Entrypoint Preview |
---|
Instruction |
---|
push 0040278Ch |
call 00007FD2008D38D3h |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
xor byte ptr [eax], al |
add byte ptr [eax], al |
inc eax |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [ecx+45h], ah |
fcom qword ptr [edx] |
adc bh, byte ptr [319F405Fh] |
arpl word ptr [C2CC377Ah], sp |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add dword ptr [eax], eax |
add byte ptr [eax], al |
adc dword ptr [ebx], eax |
inc edi |
add byte ptr [eax], al |
add byte ptr [ecx+4Eh], cl |
push esp |
inc ebp |
push edx |
push esi |
inc ecx |
dec esp |
push esp |
pop ecx |
push eax |
inc ebp |
push edx |
dec esi |
inc ebp |
add byte ptr [eax], al |
add byte ptr [eax], al |
add bh, bh |
int3 |
xor dword ptr [eax], eax |
add byte ptr [esp+ebp*8+3Fh], dl |
test eax, 4E2C7F85h |
xchg dword ptr [185B32B1h], ebx |
js 00007FD2008D3934h |
xchg eax, edx |
jmp 00007FD2008D38D3h |
inc eax |
scasb |
sbb al, 62h |
dec esi |
Data Directories |
---|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x14174 | 0x28 | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x17000 | 0xd6a | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x230 | 0x20 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x1000 | 0x190 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Sections |
---|
Name | Virtual Address | Virtual Size | Raw Size | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x137a8 | 0x14000 | False | 0.502783203125 | data | 6.41658995771 | IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ |
.data | 0x15000 | 0x1b84 | 0x1000 | False | 0.00634765625 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ |
.rsrc | 0x17000 | 0xd6a | 0x1000 | False | 0.348876953125 | data | 3.58378808404 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Resources |
---|
Name | RVA | Size | Type | Language | Country |
---|---|---|---|---|---|
RT_ICON | 0x17c42 | 0x128 | GLS_BINARY_LSB_FIRST | ||
RT_ICON | 0x1739a | 0x8a8 | dBase IV DBT of @.DBF, block length 1024, next free block index 40, next free block 16776176, next used block 10526884 | ||
RT_GROUP_ICON | 0x17378 | 0x22 | data | ||
RT_VERSION | 0x17120 | 0x258 | data | English | United States |
Imports |
---|
DLL | Import |
---|---|
MSVBVM60.DLL | _CIcos, _adj_fptan, __vbaVarMove, __vbaFreeVar, __vbaLineInputStr, __vbaFreeVarList, _adj_fdiv_m64, __vbaFreeObjList, _adj_fprem1, __vbaSetSystemError, __vbaHresultCheckObj, _adj_fdiv_m32, __vbaAryDestruct, __vbaOnError, __vbaObjSet, _adj_fdiv_m16i, _adj_fdivr_m16i, __vbaFpR8, _CIsin, __vbaErase, __vbaChkstk, __vbaFileClose, EVENT_SINK_AddRef, __vbaGenerateBoundsError, __vbaStrCmp, __vbaVarTstEq, __vbaAryConstruct2, __vbaI2I4, DllFunctionCall, _adj_fpatan, __vbaRedim, EVENT_SINK_Release, __vbaUI1I2, _CIsqrt, EVENT_SINK_QueryInterface, __vbaExceptHandler, __vbaStrToUnicode, _adj_fprem, _adj_fdivr_m64, __vbaFPException, __vbaStrVarVal, _CIlog, __vbaErrorOverflow, __vbaFileOpen, __vbaNew2, __vbaR8Str, _adj_fdiv_m32i, _adj_fdivr_m32i, __vbaStrCopy, __vbaFreeStrList, _adj_fdivr_m32, _adj_fdiv_r, __vbaVarTstNe, __vbaI4Var, __vbaInStrB, __vbaLateMemCall, __vbaVarDup, __vbaStrToAnsi, __vbaFpI4, __vbaVarLateMemCallLd, _CIatan, __vbaStrMove, _allmul, __vbaLateIdSt, _CItan, __vbaFPInt, _CIexp, __vbaFreeObj, __vbaFreeStr |
Version Infos |
---|
Description | Data |
---|---|
Translation | 0x0409 0x04b0 |
InternalName | Oders |
FileVersion | 1.00 |
CompanyName | Violet Solution |
Comments | Violet Solution |
ProductName | INTERVALTYPERNE |
ProductVersion | 1.00 |
OriginalFilename | Oders.exe |
Possible Origin |
---|
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Network Behavior |
---|
No network behavior found |
---|
Code Manipulations |
---|
Statistics |
---|
CPU Usage |
---|
Click to jump to process
Memory Usage |
---|
Click to jump to process
System Behavior |
---|
General |
---|
Start time: | 12:42:04 |
Start date: | 16/06/2021 |
Path: | C:\Users\user\Desktop\KDVTOodd7T.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 94208 bytes |
MD5 hash: | 457FCB32EC7DF1868DF42F31CCE2A301 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | Visual Basic |
Yara matches: |
|
Reputation: | low |
Disassembly |
---|
Code Analysis |
---|
Executed Functions |
---|
Function 021E5BFE, Relevance: 3.7, APIs: 1, Strings: 1, Instructions: 153memorynativeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E5BFF, Relevance: 3.6, APIs: 1, Strings: 1, Instructions: 139memorynativeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E5C64, Relevance: 3.6, APIs: 1, Strings: 1, Instructions: 133memorynativeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E5C4F, Relevance: 3.6, APIs: 1, Strings: 1, Instructions: 124memorynativeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00410310, Relevance: 253.3, APIs: 117, Strings: 27, Instructions: 1278COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Non-executed Functions |
---|
Function 021E0C87, Relevance: 4.6, Strings: 3, Instructions: 867COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E6180, Relevance: 4.0, Strings: 3, Instructions: 260COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E61EC, Relevance: 4.0, Strings: 3, Instructions: 219COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E9254, Relevance: 3.6, Strings: 2, Instructions: 1096COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E54B5, Relevance: 3.6, Strings: 2, Instructions: 1071COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E74CA, Relevance: 3.3, Strings: 2, Instructions: 825COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E76C2, Relevance: 3.3, Strings: 2, Instructions: 795COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4430, Relevance: 3.2, Strings: 2, Instructions: 746COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E447F, Relevance: 3.2, Strings: 2, Instructions: 732COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E44CF, Relevance: 3.2, Strings: 2, Instructions: 717COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E61BB, Relevance: 2.7, Strings: 2, Instructions: 214COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E62AA, Relevance: 2.7, Strings: 2, Instructions: 183COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4532, Relevance: 1.9, Strings: 1, Instructions: 698COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E457F, Relevance: 1.9, Strings: 1, Instructions: 684COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E45D6, Relevance: 1.9, Strings: 1, Instructions: 670COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4638, Relevance: 1.9, Strings: 1, Instructions: 652COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E46BA, Relevance: 1.9, Strings: 1, Instructions: 625COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E3036, Relevance: 1.9, Strings: 1, Instructions: 620COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E46FE, Relevance: 1.9, Strings: 1, Instructions: 613COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E475A, Relevance: 1.8, Strings: 1, Instructions: 599COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E47A0, Relevance: 1.8, Strings: 1, Instructions: 584COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4800, Relevance: 1.8, Strings: 1, Instructions: 565COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E484E, Relevance: 1.8, Strings: 1, Instructions: 548COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E48BA, Relevance: 1.8, Strings: 1, Instructions: 525COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4913, Relevance: 1.8, Strings: 1, Instructions: 506COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4968, Relevance: 1.7, Strings: 1, Instructions: 492COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E0D31, Relevance: 1.7, Strings: 1, Instructions: 490COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4990, Relevance: 1.7, Strings: 1, Instructions: 486COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E0CBE, Relevance: 1.7, Strings: 1, Instructions: 478COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E49EF, Relevance: 1.7, Strings: 1, Instructions: 469COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E0D17, Relevance: 1.7, Strings: 1, Instructions: 457COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4A3C, Relevance: 1.7, Strings: 1, Instructions: 455COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E0DD3, Relevance: 1.7, Strings: 1, Instructions: 430COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E0E16, Relevance: 1.7, Strings: 1, Instructions: 414COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E304B, Relevance: 1.7, Strings: 1, Instructions: 410COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E0E72, Relevance: 1.6, Strings: 1, Instructions: 395COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E308C, Relevance: 1.6, Strings: 1, Instructions: 395COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E0EA6, Relevance: 1.6, Strings: 1, Instructions: 388COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E30DE, Relevance: 1.6, Strings: 1, Instructions: 379COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E0F00, Relevance: 1.6, Strings: 1, Instructions: 367COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E3138, Relevance: 1.6, Strings: 1, Instructions: 357COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E0F5A, Relevance: 1.6, Strings: 1, Instructions: 351COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E0F9E, Relevance: 1.6, Strings: 1, Instructions: 337COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E31A0, Relevance: 1.6, Strings: 1, Instructions: 334COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E0FE4, Relevance: 1.6, Strings: 1, Instructions: 324COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E31EF, Relevance: 1.6, Strings: 1, Instructions: 315COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E1038, Relevance: 1.6, Strings: 1, Instructions: 305COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E3258, Relevance: 1.5, Strings: 1, Instructions: 293COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E108C, Relevance: 1.5, Strings: 1, Instructions: 287COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E32BA, Relevance: 1.5, Strings: 1, Instructions: 270COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E3AF1, Relevance: 1.5, Strings: 1, Instructions: 269COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E10EB, Relevance: 1.5, Strings: 1, Instructions: 264COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E1132, Relevance: 1.5, Strings: 1, Instructions: 247COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E330B, Relevance: 1.5, Strings: 1, Instructions: 246COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E3360, Relevance: 1.5, Strings: 1, Instructions: 225COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E119B, Relevance: 1.5, Strings: 1, Instructions: 225COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E11C8, Relevance: 1.5, Strings: 1, Instructions: 214COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E3B0E, Relevance: 1.4, Strings: 1, Instructions: 193COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E1226, Relevance: 1.4, Strings: 1, Instructions: 190COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E3B50, Relevance: 1.4, Strings: 1, Instructions: 181COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E1268, Relevance: 1.4, Strings: 1, Instructions: 178COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E3B9F, Relevance: 1.4, Strings: 1, Instructions: 165COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E6313, Relevance: 1.4, Strings: 1, Instructions: 161COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E3BE3, Relevance: 1.4, Strings: 1, Instructions: 152COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E6362, Relevance: 1.4, Strings: 1, Instructions: 148COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E63A3, Relevance: 1.4, Strings: 1, Instructions: 137COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E8DAA, Relevance: 1.4, Strings: 1, Instructions: 117COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E641F, Relevance: 1.4, Strings: 1, Instructions: 113COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E441C, Relevance: 1.3, Strings: 1, Instructions: 69COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E6998, Relevance: 1.3, Strings: 1, Instructions: 55COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E8849, Relevance: .5, Instructions: 540COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4AA6, Relevance: .4, Instructions: 439COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4AF2, Relevance: .4, Instructions: 426COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4B58, Relevance: .4, Instructions: 402COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4BC8, Relevance: .4, Instructions: 378COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4C1E, Relevance: .4, Instructions: 363COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4C5E, Relevance: .4, Instructions: 350COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4CC5, Relevance: .3, Instructions: 330COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4CFF, Relevance: .3, Instructions: 322COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4D70, Relevance: .3, Instructions: 299COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4DBB, Relevance: .3, Instructions: 288COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4DFA, Relevance: .3, Instructions: 273COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E8B17, Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E8B04, Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E58D3, Relevance: .3, Instructions: 263COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4E46, Relevance: .3, Instructions: 260COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E0708, Relevance: .2, Instructions: 244COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E8B8F, Relevance: .2, Instructions: 241COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E1A3D, Relevance: .2, Instructions: 238COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E2BDB, Relevance: .2, Instructions: 235COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404D55, Relevance: .2, Instructions: 232COMMON
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E8BC4, Relevance: .2, Instructions: 231COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4ECE, Relevance: .2, Instructions: 226COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4EFA, Relevance: .2, Instructions: 224COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E338B, Relevance: .2, Instructions: 218COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E2C14, Relevance: .2, Instructions: 213COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E8C1A, Relevance: .2, Instructions: 210COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E1A3F, Relevance: .2, Instructions: 209COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4F54, Relevance: .2, Instructions: 204COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E8C66, Relevance: .2, Instructions: 188COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E1A9E, Relevance: .2, Instructions: 185COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E2C78, Relevance: .2, Instructions: 184COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E8CA7, Relevance: .2, Instructions: 181COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E4FC6, Relevance: .2, Instructions: 179COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E37C6, Relevance: .2, Instructions: 170COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E12C6, Relevance: .2, Instructions: 168COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E1AFE, Relevance: .2, Instructions: 168COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E1FE8, Relevance: .2, Instructions: 168COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E2CC7, Relevance: .2, Instructions: 163COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E1B1F, Relevance: .2, Instructions: 161COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E8CEB, Relevance: .2, Instructions: 161COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E98CD, Relevance: .2, Instructions: 158COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E2D05, Relevance: .2, Instructions: 158COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E3FB8, Relevance: .2, Instructions: 156COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E1FF3, Relevance: .2, Instructions: 154COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E98DA, Relevance: .2, Instructions: 150COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E202A, Relevance: .1, Instructions: 147COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E8D30, Relevance: .1, Instructions: 147COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E98F7, Relevance: .1, Instructions: 146COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E1326, Relevance: .1, Instructions: 143COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E9913, Relevance: .1, Instructions: 143COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E1B76, Relevance: .1, Instructions: 142COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E9937, Relevance: .1, Instructions: 141COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E2D4A, Relevance: .1, Instructions: 141COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E995A, Relevance: .1, Instructions: 133COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E997A, Relevance: .1, Instructions: 133COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E8D6A, Relevance: .1, Instructions: 133COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E136E, Relevance: .1, Instructions: 129COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E99A8, Relevance: .1, Instructions: 124COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E3C6B, Relevance: .1, Instructions: 122COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E99C3, Relevance: .1, Instructions: 122COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E99DF, Relevance: .1, Instructions: 117COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E99F7, Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E3C9C, Relevance: .1, Instructions: 113COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E13C3, Relevance: .1, Instructions: 111COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E9A18, Relevance: .1, Instructions: 109COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E9A30, Relevance: .1, Instructions: 106COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E9A57, Relevance: .1, Instructions: 104COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E8DF2, Relevance: .1, Instructions: 97COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E2A10, Relevance: .1, Instructions: 91COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E7C22, Relevance: .1, Instructions: 83COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E1464, Relevance: .1, Instructions: 80COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E7C47, Relevance: .1, Instructions: 73COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E14B0, Relevance: .1, Instructions: 63COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E29D5, Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E6A1F, Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E7FC9, Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E57A7, Relevance: .0, Instructions: 8COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021E79CB, Relevance: .0, Instructions: 8COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00411F60, Relevance: 49.8, APIs: 33, Instructions: 309COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00412870, Relevance: 28.7, APIs: 19, Instructions: 152COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00411AA0, Relevance: 19.6, APIs: 13, Instructions: 128COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00413EC0, Relevance: 18.1, APIs: 12, Instructions: 89COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00411C60, Relevance: 6.1, APIs: 4, Instructions: 56COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |