Windows Analysis Report tftpd64_svc.exe
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
Process Tree |
---|
|
Malware Configuration |
---|
No configs have been found |
---|
Yara Overview |
---|
No yara matches |
---|
Sigma Overview |
---|
No Sigma rule has matched |
---|
Jbx Signature Overview |
---|
Click to jump to signature section
AV Detection: |
---|
Multi AV Scanner detection for submitted file | Show sources |
Source: | Virustotal: | Perma Link |
Source: | Static PE information: |
Source: | Code function: | 0_2_00007FF61DDA8078 | |
Source: | Code function: | 0_2_00007FF61DD8F80C |
Source: | Code function: | 0_2_00007FF61DD846B0 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 0_2_00007FF61DD9CF20 | |
Source: | Code function: | 0_2_00007FF61DD8BE90 | |
Source: | Code function: | 0_2_00007FF61DDB0688 | |
Source: | Code function: | 0_2_00007FF61DD84E90 | |
Source: | Code function: | 0_2_00007FF61DD8E68C | |
Source: | Code function: | 0_2_00007FF61DDA7E6C | |
Source: | Code function: | 0_2_00007FF61DD95634 | |
Source: | Code function: | 0_2_00007FF61DDA1118 | |
Source: | Code function: | 0_2_00007FF61DD95914 | |
Source: | Code function: | 0_2_00007FF61DD9B0EC | |
Source: | Code function: | 0_2_00007FF61DD8B080 | |
Source: | Code function: | 0_2_00007FF61DDA8078 | |
Source: | Code function: | 0_2_00007FF61DDAD018 | |
Source: | Code function: | 0_2_00007FF61DD8D82B | |
Source: | Code function: | 0_2_00007FF61DD8C7A0 | |
Source: | Code function: | 0_2_00007FF61DD9EB00 | |
Source: | Code function: | 0_2_00007FF61DDAA27C | |
Source: | Code function: | 0_2_00007FF61DD83A80 | |
Source: | Code function: | 0_2_00007FF61DDAB200 | |
Source: | Code function: | 0_2_00007FF61DD8A200 | |
Source: | Code function: | 0_2_00007FF61DDA396C | |
Source: | Code function: | 0_2_00007FF61DD9E150 | |
Source: | Code function: | 0_2_00007FF61DD95148 | |
Source: | Code function: | 0_2_00007FF61DD9D4D4 | |
Source: | Code function: | 0_2_00007FF61DD9E4B4 | |
Source: | Code function: | 0_2_00007FF61DD9ABE0 | |
Source: | Code function: | 0_2_00007FF61DD8C3C0 | |
Source: | Code function: | 0_2_00007FF61DD8FBB8 | |
Source: | Code function: | 0_2_00007FF61DD953CC | |
Source: | Code function: | 0_2_00007FF61DDA53A0 |
Source: | Code function: | 0_2_00007FF61DD816A0 |
Source: | Virustotal: |
Source: | Code function: | 0_2_00007FF61DD8ED18 |
Source: | Code function: | 0_2_00007FF61DD816A0 |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Code function: | 0_2_00007FF61DD816A0 |
Source: | Process created: | ||
Source: | Process created: |
Source: | Mutant created: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Classification label: |
Source: | Code function: | 0_2_00007FF61DD816A0 |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Code function: | 0_2_00007FF61DD816A0 |
Source: | Last function: |
Source: | API coverage: |
Source: | Code function: | 0_2_00007FF61DD885F0 |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Code function: | 0_2_00007FF61DDA8078 | |
Source: | Code function: | 0_2_00007FF61DD8F80C |
Source: | Code function: | 0_2_00007FF61DD91130 |
Source: | Code function: | 0_2_00007FF61DDA9EF0 |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Code function: | 0_2_00007FF61DD90B68 | |
Source: | Code function: | 0_2_00007FF61DD91130 | |
Source: | Code function: | 0_2_00007FF61DD90804 | |
Source: | Code function: | 0_2_00007FF61DD912D8 | |
Source: | Code function: | 0_2_00007FF61DDA19B8 |
Source: | Code function: | 0_2_00007FF61DDB04D0 |
Source: | Code function: | 0_2_00007FF61DDA55A8 |
Source: | Code function: | 0_2_00007FF61DD816A0 |
Source: | Code function: | 0_2_00007FF61DD885F0 |
Source: | Code function: | 0_2_00007FF61DD8DE20 | |
Source: | Code function: | 0_2_00007FF61DD888B0 | |
Source: | Code function: | 0_2_00007FF61DD8C7A0 | |
Source: | Code function: | 0_2_00007FF61DD84A10 | |
Source: | Code function: | 0_2_00007FF61DD90450 | |
Source: | Code function: | 0_2_00007FF61DD89C00 |
Mitre Att&ck Matrix |
---|
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Command and Scripting Interpreter2 | Windows Service14 | Windows Service14 | Process Injection1 | OS Credential Dumping | System Time Discovery12 | Remote Services | Archive Collected Data1 | Exfiltration Over Other Network Medium | Encrypted Channel1 | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Service Execution12 | Boot or Logon Initialization Scripts | Process Injection1 | Deobfuscate/Decode Files or Information1 | LSASS Memory | Security Software Discovery2 | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | Ingress Tool Transfer1 | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information1 | Security Account Manager | File and Directory Discovery1 | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | Steganography | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | Binary Padding | NTDS | System Information Discovery13 | Distributed Component Object Model | Input Capture | Scheduled Transfer | Protocol Impersonation | SIM Card Swap | Carrier Billing Fraud |
Behavior Graph |
---|
Screenshots |
---|
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Antivirus, Machine Learning and Genetic Malware Detection |
---|
Initial Sample |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
8% | Virustotal | Browse | ||
3% | Metadefender | Browse | ||
7% | ReversingLabs | Win64.Network.Generic |
Dropped Files |
---|
No Antivirus matches |
---|
Unpacked PE Files |
---|
No Antivirus matches |
---|
Domains |
---|
No Antivirus matches |
---|
URLs |
---|
No Antivirus matches |
---|
Domains and IPs |
---|
General Information |
---|
Joe Sandbox Version: | 34.0.0 Boulder Opal |
Analysis ID: | 524512 |
Start date: | 18.11.2021 |
Start time: | 16:10:36 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 5m 12s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | tftpd64_svc.exe |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 21 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.winEXE@2/1@0/0 |
EGA Information: |
|
HDC Information: |
|
HCA Information: | Failed |
Cookbook Comments: |
|
Warnings: | Show All
|
Simulations |
---|
Behavior and APIs |
---|
No simulations |
---|
Joe Sandbox View / Context |
---|
Created / dropped Files |
---|
Process: | C:\Users\user\Desktop\tftpd64_svc.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 323 |
Entropy (8bit): | 4.3991263512448855 |
Encrypted: | false |
SSDEEP: | 6:mbQBs0egLsiW7aUvX1UnMxAYyyjB5y+PNMWFGtssfxyk:mkW09It79vFLjrOwVCffT |
MD5: | C9923ACC1B05E65898460A860A6B6D91 |
SHA1: | 55219B71289C186AA746FB1269048E22E4BEBBA0 |
SHA-256: | E81D5A1B93A30F94DCE779649E0D05BFC0186A24C4CEEAFCEA7BF28B48B079B4 |
SHA-512: | 0502DDCD301C5345C456D41B2787594FCCC37F8E4101F82703332AF1DF61B02E8CF71FA38C8E6953FE7800EFABCE782D5962E3B5A8F295287BC9B98BB5E7070C |
Malicious: | false |
Reputation: | low |
Preview: |
|
Static File Info |
---|
General | |
---|---|
File type: | |
Entropy (8bit): | 6.138396322407685 |
TrID: |
|
File name: | tftpd64_svc.exe |
File size: | 334336 |
MD5: | 7ea3bbf84f39cc37c208945461230614 |
SHA1: | a2c2c0912f9632024245007083b0f75c4d520afe |
SHA256: | cfc0fdbf62d6b3be3960cee3f27d19d6c81ec125b2856912f331f5413e3f12be |
SHA512: | d6a39dc4471da3d8ee57ba4a68342b36c1805b3f9ccabb29809d199f0f99393268c90edfcb99c9e61b91ea0de3921c70eab6f725247e80bf33e17ec68385ec27 |
SSDEEP: | 6144:bUJiJIHR90uwDK09BFBMCNDrGwsQ9nEfet:bTmwDPDqqb |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........e...6...6...6...7...6...7...6...7...6...7...6...7...6...7...6...7...6...7...6...6f..6...7...6...6...6..y6...6...7...6Rich... |
File Icon |
---|
Icon Hash: | 9966ce33d4c96288 |
Static PE Info |
---|
General | |
---|---|
Entrypoint: | 0x140010d00 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x140000000 |
Subsystem: | windows cui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE |
DLL Characteristics: | TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT, HIGH_ENTROPY_VA |
Time Stamp: | 0x5C768010 [Wed Feb 27 12:18:24 2019 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 2 |
File Version Major: | 5 |
File Version Minor: | 2 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 2 |
Import Hash: | 9f5c11ad09c4f9854ca1d2f71809a230 |
Entrypoint Preview |
---|
Instruction |
---|
dec eax |
sub esp, 28h |
call 00007F40B4A509F4h |
dec eax |
add esp, 28h |
jmp 00007F40B4A50557h |
int3 |
int3 |
dec eax |
sub esp, 28h |
dec ebp |
mov eax, dword ptr [ecx+38h] |
dec eax |
mov ecx, edx |
dec ecx |
mov edx, ecx |
call 00007F40B4A506F2h |
mov eax, 00000001h |
dec eax |
add esp, 28h |
ret |
int3 |
int3 |
int3 |
inc eax |
push ebx |
inc ebp |
mov ebx, dword ptr [eax] |
dec eax |
mov ebx, edx |
inc ecx |
and ebx, FFFFFFF8h |
dec esp |
mov ecx, ecx |
inc ecx |
test byte ptr [eax], 00000004h |
dec esp |
mov edx, ecx |
je 00007F40B4A506F5h |
inc ecx |
mov eax, dword ptr [eax+08h] |
dec ebp |
arpl word ptr [eax+04h], dx |
neg eax |
dec esp |
add edx, ecx |
dec eax |
arpl ax, cx |
dec esp |
and edx, ecx |
dec ecx |
arpl bx, ax |
dec edx |
mov edx, dword ptr [eax+edx] |
dec eax |
mov eax, dword ptr [ebx+10h] |
mov ecx, dword ptr [eax+08h] |
dec eax |
mov eax, dword ptr [ebx+08h] |
test byte ptr [ecx+eax+03h], 0000000Fh |
je 00007F40B4A506EDh |
movzx eax, byte ptr [ecx+eax+03h] |
and eax, FFFFFFF0h |
dec esp |
add ecx, eax |
dec esp |
xor ecx, edx |
dec ecx |
mov ecx, ecx |
pop ebx |
jmp 00007F40B4A50136h |
int3 |
dec eax |
sub esp, 28h |
call 00007F40B4A50E60h |
test eax, eax |
je 00007F40B4A50703h |
dec eax |
mov eax, dword ptr [00000030h] |
dec eax |
mov ecx, dword ptr [eax+08h] |
jmp 00007F40B4A506E7h |
dec eax |
cmp ecx, eax |
je 00007F40B4A506F6h |
xor eax, eax |
dec eax |
cmpxchg dword ptr [00032AECh], ecx |
jne 00007F40B4A506D0h |
xor al, al |
dec eax |
add esp, 28h |
ret |
mov al, 01h |
Data Directories |
---|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x3f370 | 0x8c | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x52000 | 0xcf28 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x4e000 | 0x2274 | .pdata |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x5f000 | 0x7dc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x3cbc0 | 0x38 | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x3cc00 | 0x108 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x31000 | 0x688 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Sections |
---|
Name | Virtual Address | Virtual Size | Raw Size | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x2ff70 | 0x30000 | False | 0.565739949544 | zlib compressed data | 6.48269396487 | IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ |
.rdata | 0x31000 | 0xf77e | 0xf800 | False | 0.446966355847 | data | 5.27609719005 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x41000 | 0xc690 | 0x2000 | False | 0.179565429688 | data | 2.51483766286 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ |
.pdata | 0x4e000 | 0x2274 | 0x2400 | False | 0.4716796875 | data | 5.3242848263 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
_RDATA | 0x51000 | 0x94 | 0x200 | False | 0.201171875 | data | 1.42338039998 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.rsrc | 0x52000 | 0xcf28 | 0xd000 | False | 0.100717397837 | data | 2.80452122995 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x5f000 | 0x7dc | 0x800 | False | 0.62939453125 | data | 5.38146824912 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Resources |
---|
Name | RVA | Size | Type | Language | Country |
---|---|---|---|---|---|
RT_ICON | 0x52588 | 0xa068 | data | English | United States |
RT_ICON | 0x5c5f0 | 0xa68 | dBase IV DBT of \200.DBF, blocks size 0, block length 2048, next free block index 40, next free block 2290649224, next used block 2290649224 | English | United States |
RT_ICON | 0x5d058 | 0x2e8 | dBase IV DBT of @.DBF, block length 512, next free block index 40, next free block 43530, next used block 0 | English | United States |
RT_ICON | 0x5d340 | 0x668 | data | English | United States |
RT_ICON | 0x5d9e8 | 0x2e8 | data | English | United States |
RT_ICON | 0x5dce8 | 0x10a8 | data | English | United States |
RT_GROUP_ICON | 0x5d9a8 | 0x3e | data | English | United States |
RT_GROUP_ICON | 0x5dcd0 | 0x14 | data | English | United States |
RT_GROUP_ICON | 0x5ed90 | 0x14 | data | English | United States |
RT_VERSION | 0x52280 | 0x308 | data | English | United States |
RT_MANIFEST | 0x5eda8 | 0x17d | XML 1.0 document text | English | United States |
Imports |
---|
DLL | Import |
---|---|
WS2_32.dll | listen, WSASetLastError, send, accept, select, getsockname, ntohs, connect, recv, WSACloseEvent, WSACreateEvent, WSAEventSelect, gethostbyname, getnameinfo, getaddrinfo, freeaddrinfo, bind, WSAIoctl, closesocket, ntohl, inet_addr, socket, inet_ntoa, getservbyname, gethostname, recvfrom, htonl, sendto, setsockopt, WSAGetLastError, WSACleanup, WSAStartup, htons |
IPHLPAPI.DLL | GetIpNetTable, SendARP, GetAdaptersAddresses, DeleteIpNetEntry |
KERNEL32.dll | LCMapStringW, HeapReAlloc, GetTimeZoneInformation, OutputDebugStringW, GetModuleFileNameA, lstrlenA, lstrcatA, lstrcpyA, lstrcmpiA, SetConsoleCtrlHandler, Sleep, GetLastError, GetVersionExA, LocalFree, FormatMessageA, WriteFile, SetThreadPriority, SetFilePointer, CreateFileA, GetCurrentThread, GetThreadPriority, CloseHandle, GetLocalTime, FlushFileBuffers, SetLastError, GetCurrentThreadId, lstrcmpA, GetFileSize, GetTickCount, lstrcpynA, WaitForSingleObject, ResetEvent, GetEnvironmentVariableA, GetCurrentDirectoryW, GetCurrentDirectoryA, GetSystemTime, WaitForMultipleObjects, SetEvent, CreateEventA, CreateThread, ReadFile, SetFilePointerEx, CreateMutexA, ReleaseMutex, OutputDebugStringA, GetPrivateProfileStringA, WritePrivateProfileStringA, FileTimeToLocalFileTime, FindClose, FindFirstFileA, FindNextFileA, GetFileAttributesA, FileTimeToSystemTime, GetDateFormatA, GetSystemTimeAsFileTime, HeapAlloc, GetCommandLineW, GetCommandLineA, SystemTimeToTzSpecificLocalTime, HeapFree, PeekNamedPipe, GetFileInformationByHandle, GetDriveTypeW, CreateFileW, WriteConsoleW, GetModuleFileNameW, GetFileType, GetStdHandle, FreeLibraryAndExitThread, ResumeThread, ExitThread, GetModuleHandleExW, ExitProcess, RaiseException, LoadLibraryExW, GetProcAddress, CompareStringW, MultiByteToWideChar, GetFullPathNameW, SetStdHandle, FindFirstFileExW, FindNextFileW, IsValidCodePage, GetACP, GetOEMCP, GetCPInfo, WideCharToMultiByte, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetEnvironmentVariableW, GetStringTypeW, GetProcessHeap, GetConsoleCP, GetConsoleMode, GetFileSizeEx, HeapSize, ReadConsoleW, SetEndOfFile, GetFullPathNameA, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, IsProcessorFeaturePresent, QueryPerformanceCounter, GetCurrentProcessId, InitializeSListHead, IsDebuggerPresent, GetStartupInfoW, GetModuleHandleW, RtlUnwindEx, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, FreeLibrary |
USER32.dll | LoadIconA, GetParent, GetDesktopWindow, GetClassLongPtrA, GetWindowLongPtrA, GetWindowRect, SetWindowTextA, ReleaseDC, GetDC, DrawIcon, GetSystemMetrics, SetFocus, EndDialog, DialogBoxIndirectParamA, SetWindowPos, DestroyWindow, CreateWindowExA, MessageBeep, MessageBoxA, wsprintfA, DestroyIcon, SendMessageA |
GDI32.dll | GetTextExtentPoint32A |
ADVAPI32.dll | RegSetValueExA, RegQueryValueExA, RegOpenKeyExA, RegCreateKeyExA, RegCloseKey, RegDeleteKeyA, StartServiceCtrlDispatcherA, DeregisterEventSource, CreateServiceA, QueryServiceStatus, CloseServiceHandle, SetServiceStatus, RegisterServiceCtrlHandlerA, OpenSCManagerA, DeleteService, ControlService, ReportEventA, ChangeServiceConfig2A, OpenServiceA, RegisterEventSourceA |
Version Infos |
---|
Description | Data |
---|---|
LegalCopyright | Copyrighted 2018 by Ph. Jounin |
InternalName | tftpd32 service edition |
FileVersion | |
CompanyName | Ph. Jounin |
LegalTrademarks | |
ProductName | tftpd32 service edition |
ProductVersion | 4.62 |
FileDescription | TFTP server |
OriginalFileName | tftpd32 |
Translation | 0x040c 0x04e4 |
Possible Origin |
---|
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Network Behavior |
---|
No network behavior found |
---|
Code Manipulations |
---|
Statistics |
---|
CPU Usage |
---|
Click to jump to process
Memory Usage |
---|
Click to jump to process
Behavior |
---|
Click to jump to process
System Behavior |
---|
General |
---|
Start time: | 16:11:42 |
Start date: | 18/11/2021 |
Path: | C:\Users\user\Desktop\tftpd64_svc.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff61dd80000 |
File size: | 334336 bytes |
MD5 hash: | 7EA3BBF84F39CC37C208945461230614 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
General |
---|
Start time: | 16:11:43 |
Start date: | 18/11/2021 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7ecfc0000 |
File size: | 625664 bytes |
MD5 hash: | EA777DEEA782E8B4D7C7C33BBF8A4496 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Disassembly |
---|
Code Analysis |
---|
Execution Graph |
---|
Execution Coverage: | 2.8% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 14.4% |
Total number of Nodes: | 1302 |
Total number of Limit Nodes: | 18 |
Graph
Executed Functions |
---|
Function 00007FF61DD816A0, Relevance: 100.0, APIs: 28, Strings: 29, Instructions: 240servicesleepstringCOMMON
Control-flow Graph |
---|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph |
---|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD815B0, Relevance: 10.5, APIs: 4, Strings: 2, Instructions: 47registryCOMMON
Control-flow Graph |
---|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph |
---|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph |
---|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph |
---|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8E468, Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 43threadCOMMON
Control-flow Graph |
---|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph |
---|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDA1F9C, Relevance: 3.5, APIs: 1, Strings: 1, Instructions: 19COMMON
Control-flow Graph |
---|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph |
---|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph |
---|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph |
---|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph |
---|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph |
---|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph |
---|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDA2EC8, Relevance: 1.5, APIs: 1, Instructions: 29memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Non-executed Functions |
---|
Function 00007FF61DD8B080, Relevance: 144.2, APIs: 46, Strings: 36, Instructions: 662networkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD84E90, Relevance: 91.4, APIs: 33, Strings: 19, Instructions: 404sleepnetworkstringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8D82B, Relevance: 91.3, APIs: 34, Strings: 18, Instructions: 312networksleepsynchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD83A80, Relevance: 79.5, APIs: 22, Strings: 23, Instructions: 706stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD89C00, Relevance: 66.8, APIs: 27, Strings: 11, Instructions: 288stringnetworkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8BE90, Relevance: 61.6, APIs: 18, Strings: 17, Instructions: 321networkfileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8E68C, Relevance: 56.3, APIs: 28, Strings: 4, Instructions: 281windowstringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8C7A0, Relevance: 54.5, APIs: 20, Strings: 11, Instructions: 287networksleepthreadCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8C3C0, Relevance: 47.5, APIs: 14, Strings: 13, Instructions: 232networkfileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD888B0, Relevance: 43.9, APIs: 16, Strings: 9, Instructions: 197networkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD84A10, Relevance: 40.4, APIs: 19, Strings: 4, Instructions: 133networkthreadCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD9B0EC, Relevance: 40.4, APIs: 20, Strings: 2, Instructions: 1863COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8A200, Relevance: 35.4, APIs: 10, Strings: 10, Instructions: 371sleepthreadnetworkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDAB200, Relevance: 24.0, APIs: 9, Strings: 4, Instructions: 1207COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD885F0, Relevance: 22.9, APIs: 10, Strings: 3, Instructions: 150networksleeptimeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD90450, Relevance: 22.8, APIs: 9, Strings: 4, Instructions: 94networkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD9EB00, Relevance: 21.3, APIs: 3, Strings: 9, Instructions: 332COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8F80C, Relevance: 19.3, APIs: 9, Strings: 2, Instructions: 70filestringtimeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDA53A0, Relevance: 12.6, APIs: 6, Strings: 1, Instructions: 329timeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8DE20, Relevance: 12.1, APIs: 8, Instructions: 95networkCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDA19B8, Relevance: 9.1, APIs: 6, Instructions: 83COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDA55A8, Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 157timeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD846B0, Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 62COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8ED18, Relevance: 6.0, APIs: 4, Instructions: 30stringwindowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDA396C, Relevance: 3.7, APIs: 1, Strings: 1, Instructions: 248COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDA7E6C, Relevance: 3.7, APIs: 1, Strings: 1, Instructions: 165COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDB0688, Relevance: 3.2, APIs: 2, Instructions: 232COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8FBB8, Relevance: .7, Instructions: 683COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD9ABE0, Relevance: .3, Instructions: 285COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD95634, Relevance: .2, Instructions: 217COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD9D4D4, Relevance: .1, Instructions: 91COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDB04D0, Relevance: .0, Instructions: 32COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD912D8, Relevance: .0, Instructions: 2COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD87E90, Relevance: 43.9, APIs: 22, Strings: 3, Instructions: 181networkstringsynchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8A8E0, Relevance: 42.2, APIs: 17, Strings: 7, Instructions: 236networkthreadCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD897E0, Relevance: 40.5, APIs: 16, Strings: 7, Instructions: 207filestringsynchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD82AB0, Relevance: 38.8, APIs: 17, Strings: 5, Instructions: 271COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD81F60, Relevance: 38.7, APIs: 18, Strings: 4, Instructions: 170threadsleepfileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD81B50, Relevance: 35.1, APIs: 9, Strings: 11, Instructions: 128sleepnetworkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD87430, Relevance: 31.8, APIs: 7, Strings: 11, Instructions: 296COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD86F00, Relevance: 31.8, APIs: 8, Strings: 10, Instructions: 283stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD89040, Relevance: 31.7, APIs: 12, Strings: 6, Instructions: 194synchronizationsleepthreadCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD82EF0, Relevance: 29.9, APIs: 12, Strings: 5, Instructions: 190networksleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD89470, Relevance: 26.4, APIs: 9, Strings: 6, Instructions: 185synchronizationthreadsleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD847E0, Relevance: 24.6, APIs: 13, Strings: 1, Instructions: 117sleepnetworkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD861D0, Relevance: 24.6, APIs: 10, Strings: 4, Instructions: 100stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD85A80, Relevance: 24.3, APIs: 11, Strings: 5, Instructions: 272stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD82740, Relevance: 22.9, APIs: 6, Strings: 7, Instructions: 122stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8AE20, Relevance: 22.8, APIs: 8, Strings: 5, Instructions: 77stringfileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8EDAC, Relevance: 22.7, APIs: 15, Instructions: 186networkCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD881C0, Relevance: 21.2, APIs: 8, Strings: 4, Instructions: 163synchronizationsleepnetworkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD85F70, Relevance: 19.4, APIs: 4, Strings: 7, Instructions: 120stringthreadCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD88BD0, Relevance: 19.4, APIs: 7, Strings: 4, Instructions: 100networkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD88DC0, Relevance: 17.6, APIs: 7, Strings: 3, Instructions: 124synchronizationsleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8F534, Relevance: 17.6, APIs: 5, Strings: 5, Instructions: 96synchronizationsleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD82520, Relevance: 15.9, APIs: 4, Strings: 5, Instructions: 114stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDA4204, Relevance: 15.9, APIs: 1, Strings: 8, Instructions: 104COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD86AE0, Relevance: 15.1, APIs: 3, Strings: 7, Instructions: 117stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD87B90, Relevance: 14.2, APIs: 7, Strings: 1, Instructions: 175networkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD864E0, Relevance: 13.6, APIs: 4, Strings: 5, Instructions: 110stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8F2E8, Relevance: 13.6, APIs: 9, Instructions: 96registrystringfileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8DF84, Relevance: 12.3, APIs: 5, Strings: 2, Instructions: 87networkfileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD9F004, Relevance: 12.3, APIs: 4, Strings: 3, Instructions: 84COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8CCC0, Relevance: 12.3, APIs: 4, Strings: 3, Instructions: 81synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD822A0, Relevance: 12.3, APIs: 4, Strings: 3, Instructions: 69synchronizationsleepstringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD81DE0, Relevance: 12.3, APIs: 5, Strings: 2, Instructions: 68sleepnetworkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD87A30, Relevance: 12.3, APIs: 4, Strings: 3, Instructions: 68sleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8D6B4, Relevance: 12.3, APIs: 3, Strings: 4, Instructions: 64synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD823F0, Relevance: 12.3, APIs: 4, Strings: 3, Instructions: 64synchronizationsleepstringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8BB90, Relevance: 12.3, APIs: 3, Strings: 4, Instructions: 46networkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD868D0, Relevance: 12.1, APIs: 3, Strings: 5, Instructions: 119stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD86CF0, Relevance: 12.1, APIs: 3, Strings: 5, Instructions: 118stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD866C0, Relevance: 12.1, APIs: 3, Strings: 5, Instructions: 115stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8D1CF, Relevance: 10.6, APIs: 5, Strings: 2, Instructions: 141stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8F0F4, Relevance: 10.6, APIs: 7, Instructions: 133registrystringCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8E260, Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 64networkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8BC50, Relevance: 10.6, APIs: 3, Strings: 3, Instructions: 60networkwindowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD81220, Relevance: 10.6, APIs: 3, Strings: 3, Instructions: 57registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDB012C, Relevance: 10.5, APIs: 5, Strings: 1, Instructions: 48fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8D4B3, Relevance: 10.5, APIs: 4, Strings: 2, Instructions: 43networkstringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD81500, Relevance: 10.5, APIs: 5, Strings: 1, Instructions: 42stringwindowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8CFEC, Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 68COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8D5BA, Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 63networkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8CF35, Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 60COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8EC74, Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 42registrystringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8D0E4, Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 37networkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8D14B, Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 37networkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8D3FE, Relevance: 8.8, APIs: 2, Strings: 3, Instructions: 34registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8F790, Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 30synchronizationsleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD92A38, Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 24libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD84C40, Relevance: 7.6, APIs: 5, Instructions: 143networkCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8AD30, Relevance: 7.6, APIs: 5, Instructions: 63networkstringCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDB02C4, Relevance: 7.6, APIs: 5, Instructions: 56COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD863E0, Relevance: 7.6, APIs: 3, Strings: 2, Instructions: 52stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDA5C00, Relevance: 7.2, APIs: 1, Strings: 3, Instructions: 212COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD93DDC, Relevance: 7.2, APIs: 2, Strings: 2, Instructions: 151COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD9420C, Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 147COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDA3DB8, Relevance: 7.1, APIs: 1, Strings: 3, Instructions: 134COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD81360, Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 80COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8F6A8, Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 61synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8AF90, Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 55COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD829B0, Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 55COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD88500, Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 53sleepsynchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDA26FC, Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 50COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDA2650, Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 30COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDA25E0, Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 28COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD835F9, Relevance: 6.1, APIs: 4, Instructions: 64filenetworkCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD94684, Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 171COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD905BC, Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 112timenetworkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDAA978, Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 100fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDA6E7C, Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 68COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD9F17C, Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 57COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD8BD60, Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 51stringnetworkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDA2118, Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 50COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDA23CC, Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 50COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDADC30, Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 34COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDA2368, Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 25COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DD92648, Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 21COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDA22CC, Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 21COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF61DDA24A8, Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 21COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |