Windows Analysis Report Fra FAC-ES101-2107-03806.doc.exe
Overview
General Information
Detection
Score: | 80 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
Process Tree |
---|
|
Malware Configuration |
---|
Threatname: GuLoader |
---|
{"Payload URL": "https://drive.google.com/uc?export=downlo"}
Yara Overview |
---|
Memory Dumps |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_GuLoader_2 | Yara detected GuLoader | Joe Security |
Sigma Overview |
---|
No Sigma rule has matched |
---|
Jbx Signature Overview |
---|
Click to jump to signature section
AV Detection: |
---|
Found malware configuration | Show sources |
Source: | Malware Configuration Extractor: |
Multi AV Scanner detection for submitted file | Show sources |
Source: | Virustotal: | Perma Link | ||
Source: | Metadefender: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Static PE information: |
Networking: |
---|
C2 URLs / IPs found in malware configuration | Show sources |
Source: | URLs: |
Source: | Static PE information: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 0_2_004016F4 | |
Source: | Code function: | 0_2_00401741 | |
Source: | Code function: | 0_2_00401505 | |
Source: | Code function: | 0_2_0212B763 | |
Source: | Code function: | 0_2_021274A7 | |
Source: | Code function: | 0_2_0212AA13 | |
Source: | Code function: | 0_2_02124A14 | |
Source: | Code function: | 0_2_02124E15 | |
Source: | Code function: | 0_2_02128E1A | |
Source: | Code function: | 0_2_0212721C | |
Source: | Code function: | 0_2_02126205 | |
Source: | Code function: | 0_2_02129A0B | |
Source: | Code function: | 0_2_0212B20B | |
Source: | Code function: | 0_2_0212A609 | |
Source: | Code function: | 0_2_0212020D | |
Source: | Code function: | 0_2_02124E0D | |
Source: | Code function: | 0_2_0212363D | |
Source: | Code function: | 0_2_02127A2B | |
Source: | Code function: | 0_2_0212822F | |
Source: | Code function: | 0_2_02120257 | |
Source: | Code function: | 0_2_0212765B | |
Source: | Code function: | 0_2_02129259 | |
Source: | Code function: | 0_2_02125647 | |
Source: | Code function: | 0_2_02127244 | |
Source: | Code function: | 0_2_02125E70 | |
Source: | Code function: | 0_2_02126E85 | |
Source: | Code function: | 0_2_0212BABD | |
Source: | Code function: | 0_2_02125AAB | |
Source: | Code function: | 0_2_021266AF | |
Source: | Code function: | 0_2_0212AEDB | |
Source: | Code function: | 0_2_021252C5 | |
Source: | Code function: | 0_2_02127EF3 | |
Source: | Code function: | 0_2_021216F7 | |
Source: | Code function: | 0_2_0212BEE1 | |
Source: | Code function: | 0_2_021296E6 | |
Source: | Code function: | 0_2_02129AEF | |
Source: | Code function: | 0_2_02120319 | |
Source: | Code function: | 0_2_02126B03 | |
Source: | Code function: | 0_2_02128B09 | |
Source: | Code function: | 0_2_0212630E | |
Source: | Code function: | 0_2_0212AF31 | |
Source: | Code function: | 0_2_02124F35 | |
Source: | Code function: | 0_2_0212A73B | |
Source: | Code function: | 0_2_0212AB53 | |
Source: | Code function: | 0_2_02128F47 | |
Source: | Code function: | 0_2_02127B4B | |
Source: | Code function: | 0_2_0212A349 | |
Source: | Code function: | 0_2_0212777F | |
Source: | Code function: | 0_2_0212537C | |
Source: | Code function: | 0_2_02125F67 | |
Source: | Code function: | 0_2_02120365 | |
Source: | Code function: | 0_2_0212B365 | |
Source: | Code function: | 0_2_02125768 | |
Source: | Code function: | 0_2_02128F97 | |
Source: | Code function: | 0_2_0212A79E | |
Source: | Code function: | 0_2_02128B89 | |
Source: | Code function: | 0_2_0212938F | |
Source: | Code function: | 0_2_0212B78F | |
Source: | Code function: | 0_2_0212BFBB | |
Source: | Code function: | 0_2_021213BC | |
Source: | Code function: | 0_2_021297D1 | |
Source: | Code function: | 0_2_021267D7 | |
Source: | Code function: | 0_2_02125BC3 | |
Source: | Code function: | 0_2_02129BC1 | |
Source: | Code function: | 0_2_02127FCD | |
Source: | Code function: | 0_2_0212B7FD | |
Source: | Code function: | 0_2_02124FE2 | |
Source: | Code function: | 0_2_021253E8 | |
Source: | Code function: | 0_2_02128FEF | |
Source: | Code function: | 0_2_0212AFEF | |
Source: | Code function: | 0_2_02121417 | |
Source: | Code function: | 0_2_0212A001 | |
Source: | Code function: | 0_2_02128805 | |
Source: | Code function: | 0_2_0212180F | |
Source: | Code function: | 0_2_0212AC37 | |
Source: | Code function: | 0_2_02125435 | |
Source: | Code function: | 0_2_0212903B | |
Source: | Code function: | 0_2_02129039 | |
Source: | Code function: | 0_2_0212A82F | |
Source: | Code function: | 0_2_02128C53 | |
Source: | Code function: | 0_2_02127C57 | |
Source: | Code function: | 0_2_0212BC55 | |
Source: | Code function: | 0_2_02125041 | |
Source: | Code function: | 0_2_02126446 | |
Source: | Code function: | 0_2_0212587E | |
Source: | Code function: | 0_2_0212707F | |
Source: | Code function: | 0_2_0212908F | |
Source: | Code function: | 0_2_021214B2 | |
Source: | Code function: | 0_2_02128CB2 | |
Source: | Code function: | 0_2_021228A1 | |
Source: | Code function: | 0_2_0212B8AA | |
Source: | Code function: | 0_2_02126CD3 | |
Source: | Code function: | 0_2_021288D1 | |
Source: | Code function: | 0_2_021278D8 | |
Source: | Code function: | 0_2_021260C3 | |
Source: | Code function: | 0_2_021274CF | |
Source: | Code function: | 0_2_02125CF3 | |
Source: | Code function: | 0_2_021290F3 | |
Source: | Code function: | 0_2_021268F0 | |
Source: | Code function: | 0_2_021278F6 | |
Source: | Code function: | 0_2_021298EE | |
Source: | Code function: | 0_2_02125516 | |
Source: | Code function: | 0_2_0212B115 | |
Source: | Code function: | 0_2_0212A91D | |
Source: | Code function: | 0_2_0212350F | |
Source: | Code function: | 0_2_02127523 | |
Source: | Code function: | 0_2_0212A12B | |
Source: | Code function: | 0_2_0212B95B | |
Source: | Code function: | 0_2_02129141 | |
Source: | Code function: | 0_2_0212014A | |
Source: | Code function: | 0_2_0212A17F | |
Source: | Code function: | 0_2_0212357C | |
Source: | Code function: | 0_2_0212AD6F | |
Source: | Code function: | 0_2_0212196C | |
Source: | Code function: | 0_2_0212719F | |
Source: | Code function: | 0_2_02127D80 | |
Source: | Code function: | 0_2_0212598B | |
Source: | Code function: | 0_2_021251AD | |
Source: | Code function: | 0_2_021295AD | |
Source: | Code function: | 0_2_021229D8 | |
Source: | Code function: | 0_2_0212B9CF | |
Source: | Code function: | 0_2_0212BDF7 | |
Source: | Code function: | 0_2_021269E5 |
Source: | Code function: | 0_2_021274A7 | |
Source: | Code function: | 0_2_021274CF | |
Source: | Code function: | 0_2_02127523 |
Source: | Process Stats: |
Source: | Virustotal: | ||
Source: | Metadefender: | ||
Source: | ReversingLabs: |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Section loaded: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Data Obfuscation: |
---|
Yara detected GuLoader | Show sources |
Source: | File source: |
Source: | Code function: | 0_2_00404883 | |
Source: | Code function: | 0_2_00404A5D | |
Source: | Code function: | 0_2_00403903 | |
Source: | Code function: | 0_2_0212073B | |
Source: | Code function: | 0_2_021204C4 | |
Source: | Code function: | 0_2_021237DC | |
Source: | Code function: | 0_2_02123BBF | |
Source: | Code function: | 0_2_02122C10 | |
Source: | Code function: | 0_2_02124C59 | |
Source: | Code function: | 0_2_021210E2 |
Hooking and other Techniques for Hiding and Protection: |
---|
Uses an obfuscated file name to hide its real file extension (double extension) | Show sources |
Source: | Static PE information: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion: |
---|
Tries to detect virtualization through RDTSC time measurements | Show sources |
Source: | RDTSC instruction interceptor: | ||
Source: | RDTSC instruction interceptor: |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Code function: | 0_2_02124A14 |
Anti Debugging: |
---|
Found potential dummy code loops (likely to delay analysis) | Show sources |
Source: | Process Stats: |
Source: | Code function: | 0_2_02124A14 | |
Source: | Code function: | 0_2_0212960F | |
Source: | Code function: | 0_2_02129B4A | |
Source: | Code function: | 0_2_0212A79E | |
Source: | Code function: | 0_2_02126BE9 |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Code function: | 0_2_02124A14 |
Source: | Code function: | 0_2_0212B763 | |
Source: | Code function: | 0_2_0212BABD | |
Source: | Code function: | 0_2_0212BB9D | |
Source: | Code function: | 0_2_0212B78F | |
Source: | Code function: | 0_2_0212B7FD | |
Source: | Code function: | 0_2_0212BC55 | |
Source: | Code function: | 0_2_0212B8AA | |
Source: | Code function: | 0_2_0212B95B | |
Source: | Code function: | 0_2_0212B9CF |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Mitre Att&ck Matrix |
---|
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | Path Interception | Process Injection1 | Masquerading1 | OS Credential Dumping | Security Software Discovery21 | Remote Services | Archive Collected Data1 | Exfiltration Over Other Network Medium | Encrypted Channel1 | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Virtualization/Sandbox Evasion11 | LSASS Memory | Virtualization/Sandbox Evasion11 | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | Application Layer Protocol1 | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | Process Injection1 | Security Account Manager | Process Discovery1 | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | Steganography | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | Obfuscated Files or Information11 | NTDS | System Information Discovery11 | Distributed Component Object Model | Input Capture | Scheduled Transfer | Protocol Impersonation | SIM Card Swap | Carrier Billing Fraud |
Behavior Graph |
---|
Screenshots |
---|
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Antivirus, Machine Learning and Genetic Malware Detection |
---|
Initial Sample |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
51% | Virustotal | Browse | ||
34% | Metadefender | Browse | ||
54% | ReversingLabs | Win32.Trojan.AgentTesla |
Dropped Files |
---|
No Antivirus matches |
---|
Unpacked PE Files |
---|
No Antivirus matches |
---|
Domains |
---|
No Antivirus matches |
---|
URLs |
---|
No Antivirus matches |
---|
Domains and IPs |
---|
General Information |
---|
Joe Sandbox Version: | 33.0.0 White Diamond |
Analysis ID: | 501942 |
Start date: | 13.10.2021 |
Start time: | 12:44:11 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 7m 21s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | Fra FAC-ES101-2107-03806.doc.exe |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 28 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal80.troj.evad.winEXE@1/0@0/0 |
EGA Information: | Failed |
HDC Information: |
|
HCA Information: | Failed |
Cookbook Comments: |
|
Warnings: | Show All
|
Simulations |
---|
Behavior and APIs |
---|
No simulations |
---|
Joe Sandbox View / Context |
---|
Created / dropped Files |
---|
No created / dropped files found |
---|
Static File Info |
---|
General | |
---|---|
File type: | |
Entropy (8bit): | 5.81188292947866 |
TrID: |
|
File name: | Fra FAC-ES101-2107-03806.doc.exe |
File size: | 102400 |
MD5: | 18b804e21a3c1c80c195e7d20dc38477 |
SHA1: | 9622e70cd6db56de3488e99cd18c5f51e54afb64 |
SHA256: | cbc14388711803d5a3f90396d4d33c9b3da952c37a5d919daed329cbd487c1b4 |
SHA512: | 21eade10fb00f4ef5356025ce037983b2e220835345b4bd141f1063367da309390caa83d9d822177bf5c3ef900c311a12afff2f9731787f0afb4c6f35576ffec |
SSDEEP: | 1536:tfD8AJkfjAx20HgXeyTftunugia21jbnD:tfeUxxAZnn/n |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........i.......................*..............Rich....................PE..L...(.KY.................P...0......x........`....@........ |
File Icon |
---|
Icon Hash: | 69e1c892f664c884 |
Static PE Info |
---|
General | |
---|---|
Entrypoint: | 0x401378 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED |
DLL Characteristics: | |
Time Stamp: | 0x594BF828 [Thu Jun 22 17:02:32 2017 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | 669316531b5190f02843878b6ed87394 |
Entrypoint Preview |
---|
Instruction |
---|
push 00410384h |
call 00007FB15496C115h |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
xor byte ptr [eax], al |
add byte ptr [eax], al |
inc eax |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [ecx+esi*8-01239E7Dh], bl |
inc ebp |
inc esi |
mov ecx, edx |
out 90h, eax |
mov eax, dword ptr [00E6209Fh] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [ecx], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [ecx+6Eh], cl |
jbe 00007FB15496C18Bh |
je 00007FB15496C187h |
jc 00007FB15496C187h |
xor dword ptr [eax], eax |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
dec esp |
xor dword ptr [eax], eax |
cmp byte ptr [ebx+59h], bl |
out dx, al |
mov edi, 4A47AB16h |
stosb |
fbld [esi-764BB8D2h] |
ret |
cmpsd |
mov ch, 2Dh |
push 00000025h |
rcl byte ptr [esi-71DF64BCh], cl |
out 29h, eax |
and byte ptr [eax+40h], 0000003Ah |
dec edi |
lodsd |
xor ebx, dword ptr [ecx-48EE309Ah] |
or al, 00h |
stosb |
add byte ptr [eax-2Dh], ah |
xchg eax, ebx |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
push ebx |
in eax, dx |
add byte ptr [eax], al |
sbb eax, 00000009h |
or byte ptr [eax], al |
jc 00007FB15496C18Ch |
jbe 00007FB15496C18Ah |
jne 00007FB15496C195h |
add byte ptr [44000E01h], cl |
push esi |
inc ebp |
dec ebx |
dec edi |
dec esi |
Data Directories |
---|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x150d4 | 0x28 | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x17000 | 0x1cb2 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x230 | 0x20 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x1000 | 0x134 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Sections |
---|
Name | Virtual Address | Virtual Size | Raw Size | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x14588 | 0x15000 | False | 0.496163504464 | data | 6.24678665883 | IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ |
.data | 0x16000 | 0xd0c | 0x1000 | False | 0.00634765625 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ |
.rsrc | 0x17000 | 0x1cb2 | 0x2000 | False | 0.348510742188 | data | 3.76228374891 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Resources |
---|
Name | RVA | Size | Type | Language | Country |
---|---|---|---|---|---|
CUSTOM | 0x189b4 | 0x2fe | MS Windows icon resource - 1 icon, 32x32, 16 colors | English | United States |
CUSTOM | 0x180f6 | 0x8be | MS Windows icon resource - 1 icon, 32x32, 8 bits/pixel | English | United States |
CUSTOM | 0x17df8 | 0x2fe | MS Windows icon resource - 1 icon, 32x32, 16 colors, 4 bits/pixel | English | United States |
RT_ICON | 0x17550 | 0x8a8 | data | ||
RT_GROUP_ICON | 0x1753c | 0x14 | data | ||
RT_VERSION | 0x171a0 | 0x39c | data | English | United States |
Imports |
---|
DLL | Import |
---|---|
MSVBVM60.DLL | _CIcos, _adj_fptan, __vbaVarMove, __vbaFreeVar, __vbaStrVarMove, __vbaFreeVarList, _adj_fdiv_m64, _adj_fprem1, __vbaSetSystemError, __vbaHresultCheckObj, _adj_fdiv_m32, _adj_fdiv_m16i, _adj_fdivr_m16i, __vbaVarTstLt, _CIsin, __vbaChkstk, EVENT_SINK_AddRef, __vbaStrCmp, DllFunctionCall, _adj_fpatan, EVENT_SINK_Release, _CIsqrt, EVENT_SINK_QueryInterface, __vbaExceptHandler, _adj_fprem, _adj_fdivr_m64, __vbaFPException, __vbaStrVarVal, __vbaDateVar, _CIlog, __vbaErrorOverflow, __vbaFileOpen, __vbaNew2, _adj_fdiv_m32i, _adj_fdivr_m32i, __vbaStrCopy, __vbaFreeStrList, _adj_fdivr_m32, _adj_fdiv_r, __vbaLateMemCall, __vbaVarAdd, __vbaStrToAnsi, __vbaVarDup, __vbaFpI4, _CIatan, __vbaStrMove, _allmul, __vbaLateIdSt, _CItan, _CIexp, __vbaFreeStr, __vbaFreeObj |
Version Infos |
---|
Description | Data |
---|---|
Translation | 0x0409 0x04b0 |
LegalCopyright | Collides Systems, Inc. |
InternalName | Saarede3 |
FileVersion | 4.00 |
CompanyName | Collides Systems, Inc. |
LegalTrademarks | Collides Systems, Inc. |
Comments | Collides Systems, Inc. |
ProductName | Collides Systems, Inc. |
ProductVersion | 4.00 |
FileDescription | Collides Systems, Inc. |
OriginalFilename | Saarede3.exe |
Possible Origin |
---|
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Network Behavior |
---|
No network behavior found |
---|
Code Manipulations |
---|
Statistics |
---|
CPU Usage |
---|
Click to jump to process
Memory Usage |
---|
Click to jump to process
System Behavior |
---|
General |
---|
Start time: | 12:45:11 |
Start date: | 13/10/2021 |
Path: | C:\Users\user\Desktop\Fra FAC-ES101-2107-03806.doc.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 102400 bytes |
MD5 hash: | 18B804E21A3C1C80C195E7D20DC38477 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | Visual Basic |
Yara matches: |
|
Reputation: | low |
Disassembly |
---|
Code Analysis |
---|
Executed Functions |
---|
Function 0212B8AA, Relevance: 1.7, APIs: 1, Instructions: 212COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212B78F, Relevance: 1.7, APIs: 1, Instructions: 206COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212B7FD, Relevance: 1.7, APIs: 1, Instructions: 198COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212B763, Relevance: 1.7, APIs: 1, Instructions: 182COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212B95B, Relevance: 1.7, APIs: 1, Instructions: 168COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212B9CF, Relevance: 1.7, APIs: 1, Instructions: 163COMMON
APIs |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212BABD, Relevance: 1.6, APIs: 1, Instructions: 124COMMON
APIs |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212BC55, Relevance: 1.6, APIs: 1, Instructions: 69COMMON
APIs |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212BB9D, Relevance: 1.6, APIs: 1, Instructions: 69COMMON
APIs |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212765B, Relevance: .1, Instructions: 66COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004133A0, Relevance: 321.6, APIs: 161, Strings: 22, Instructions: 1312COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Non-executed Functions |
---|
Function 02129039, Relevance: 5.8, Strings: 4, Instructions: 791COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02125435, Relevance: 4.4, Strings: 3, Instructions: 670COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02125516, Relevance: 4.4, Strings: 3, Instructions: 659COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02125647, Relevance: 3.1, Strings: 2, Instructions: 596COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02125768, Relevance: 3.0, Strings: 2, Instructions: 540COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212A79E, Relevance: 3.0, Strings: 2, Instructions: 510COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212587E, Relevance: 3.0, Strings: 2, Instructions: 500COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212598B, Relevance: 3.0, Strings: 2, Instructions: 462COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02125AAB, Relevance: 2.9, Strings: 2, Instructions: 405COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021214B2, Relevance: 2.9, Strings: 2, Instructions: 362COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02125BC3, Relevance: 2.9, Strings: 2, Instructions: 359COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02125CF3, Relevance: 2.8, Strings: 2, Instructions: 327COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02125E70, Relevance: 2.7, Strings: 2, Instructions: 239COMMON
Strings |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021278D8, Relevance: 1.6, Strings: 1, Instructions: 308COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02120319, Relevance: 1.5, Strings: 1, Instructions: 262COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021278F6, Relevance: 1.5, Strings: 1, Instructions: 242COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02125F67, Relevance: 1.5, Strings: 1, Instructions: 231COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02127A2B, Relevance: 1.4, Strings: 1, Instructions: 190COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212537C, Relevance: 1.4, Strings: 1, Instructions: 176COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02127B4B, Relevance: 1.4, Strings: 1, Instructions: 144COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02127EF3, Relevance: 1.4, Strings: 1, Instructions: 128COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02124A14, Relevance: 1.4, Strings: 1, Instructions: 121COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02127FCD, Relevance: 1.3, Strings: 1, Instructions: 96COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02124E0D, Relevance: 1.3, Strings: 1, Instructions: 93COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02127C57, Relevance: 1.3, Strings: 1, Instructions: 93COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021298EE, Relevance: 1.3, Strings: 1, Instructions: 85COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02126E85, Relevance: 1.3, Strings: 1, Instructions: 75COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212A349, Relevance: 1.3, Strings: 1, Instructions: 68COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021216F7, Relevance: 1.3, Strings: 1, Instructions: 64COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02128CB2, Relevance: 1.3, Strings: 1, Instructions: 47COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212BFBB, Relevance: 1.3, Strings: 1, Instructions: 40COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021228A1, Relevance: 1.3, Strings: 1, Instructions: 39COMMON
Strings |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212A82F, Relevance: .3, Instructions: 288COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212A91D, Relevance: .3, Instructions: 254COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212AA13, Relevance: .2, Instructions: 214COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02124FE2, Relevance: .2, Instructions: 200COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02120365, Relevance: .2, Instructions: 190COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021260C3, Relevance: .2, Instructions: 180COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212AB53, Relevance: .2, Instructions: 164COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00401505, Relevance: .2, Instructions: 153COMMON
Memory Dump Source |
|
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212AC37, Relevance: .1, Instructions: 131COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212A001, Relevance: .1, Instructions: 127COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02125041, Relevance: .1, Instructions: 126COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212AF31, Relevance: .1, Instructions: 125COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02126205, Relevance: .1, Instructions: 123COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212AEDB, Relevance: .1, Instructions: 109COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02129259, Relevance: .1, Instructions: 98COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02124E15, Relevance: .1, Instructions: 97COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212630E, Relevance: .1, Instructions: 88COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021297D1, Relevance: .1, Instructions: 87COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212AD6F, Relevance: .1, Instructions: 86COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021213BC, Relevance: .1, Instructions: 82COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02126446, Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212BEE1, Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212AFEF, Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212180F, Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212A12B, Relevance: .1, Instructions: 69COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021266AF, Relevance: .1, Instructions: 68COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212A17F, Relevance: .1, Instructions: 67COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212A609, Relevance: .1, Instructions: 66COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212908F, Relevance: .1, Instructions: 65COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021251AD, Relevance: .1, Instructions: 65COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212903B, Relevance: .1, Instructions: 63COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02126CD3, Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02121417, Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212B20B, Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212721C, Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02127244, Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00401741, Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02129141, Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021296E6, Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02128B09, Relevance: .1, Instructions: 55COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021269E5, Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021290F3, Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02120257, Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212014A, Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02124F35, Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02129BC1, Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212357C, Relevance: .0, Instructions: 48COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02128E1A, Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02126B03, Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02128805, Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212719F, Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021295AD, Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021252C5, Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212938F, Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212B115, Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212350F, Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02129B4A, Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212777F, Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212822F, Relevance: .0, Instructions: 40COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212A73B, Relevance: .0, Instructions: 40COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021267D7, Relevance: .0, Instructions: 40COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212BDF7, Relevance: .0, Instructions: 40COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021268F0, Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212B365, Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02128F97, Relevance: .0, Instructions: 38COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02128C53, Relevance: .0, Instructions: 37COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02128F47, Relevance: .0, Instructions: 37COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021288D1, Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004016F4, Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02127D80, Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02129A0B, Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212363D, Relevance: .0, Instructions: 33COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212707F, Relevance: .0, Instructions: 32COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02129AEF, Relevance: .0, Instructions: 32COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212196C, Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021229D8, Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02128FEF, Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 021253E8, Relevance: .0, Instructions: 30COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212020D, Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02128B89, Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02126BE9, Relevance: .0, Instructions: 7COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0212960F, Relevance: .0, Instructions: 5COMMON
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00414D50, Relevance: 16.6, APIs: 11, Instructions: 89COMMON
APIs |
|
Memory Dump Source |
|
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |