Windows
Analysis Report
98765434567890.exe
Overview
General Information
Detection
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64native
- 98765434567890.exe (PID: 9072 cmdline:
C:\Users\u ser\Deskto p\98765434 567890.exe MD5: 1C4E3E615E3596572062BCA5EC498D41) - 98765434567890.exe (PID: 7584 cmdline:
C:\Users\u ser\Deskto p\98765434 567890.exe MD5: 1C4E3E615E3596572062BCA5EC498D41)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_GuLoader_2 | Yara detected GuLoader | Joe Security | ||
JoeSecurity_GuLoader_2 | Yara detected GuLoader | Joe Security |
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 2_2_00406555 | |
Source: | Code function: | 2_2_00405A03 | |
Source: | Code function: | 2_2_0040287E |
Source: | TCP traffic: |
Source: | UDP traffic detected without corresponding DNS query: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | DNS traffic detected: |
Source: | Code function: | 2_2_004054B0 |
Source: | Static PE information: |
Source: | Code function: | 2_2_0040344A |
Source: | Code function: | 2_2_00404CED | |
Source: | Code function: | 2_2_004068DA | |
Source: | Code function: | 2_2_034AF5DD | |
Source: | Code function: | 2_2_03490F45 | |
Source: | Code function: | 2_2_03490344 | |
Source: | Code function: | 2_2_0349135A | |
Source: | Code function: | 2_2_0349375C | |
Source: | Code function: | 2_2_0349AB50 | |
Source: | Code function: | 2_2_03499774 | |
Source: | Code function: | 2_2_03493B0E | |
Source: | Code function: | 2_2_0349D700 | |
Source: | Code function: | 2_2_03493F04 | |
Source: | Code function: | 2_2_034903CA | |
Source: | Code function: | 2_2_034AF7C2 | |
Source: | Code function: | 2_2_034937C2 | |
Source: | Code function: | 2_2_03498FC4 | |
Source: | Code function: | 2_2_03493BDD | |
Source: | Code function: | 2_2_0349DBFA | |
Source: | Code function: | 2_2_034913F4 | |
Source: | Code function: | 2_2_03493B86 | |
Source: | Code function: | 2_2_03490B96 | |
Source: | Code function: | 2_2_034907AE | |
Source: | Code function: | 2_2_03493FAE | |
Source: | Code function: | 2_2_034A67B8 | |
Source: | Code function: | 2_2_0349364A | |
Source: | Code function: | 2_2_0349324F | |
Source: | Code function: | 2_2_03490245 | |
Source: | Code function: | 2_2_03490A47 | |
Source: | Code function: | 2_2_034B1E5B | |
Source: | Code function: | 2_2_03490E5C | |
Source: | Code function: | 2_2_03493A51 | |
Source: | Code function: | 2_2_03493E56 | |
Source: | Code function: | 2_2_0349DE78 | |
Source: | Code function: | 2_2_03491275 | |
Source: | Code function: | 2_2_034B520C | |
Source: | Code function: | 2_2_0349D610 | |
Source: | Code function: | 2_2_03499E26 | |
Source: | Code function: | 2_2_03499234 | |
Source: | Code function: | 2_2_03499634 | |
Source: | Code function: | 2_2_034992C8 | |
Source: | Code function: | 2_2_03490ECA | |
Source: | Code function: | 2_2_034912CD | |
Source: | Code function: | 2_2_03490AEB | |
Source: | Code function: | 2_2_034936EB | |
Source: | Code function: | 2_2_034932EF | |
Source: | Code function: | 2_2_0349D2E4 | |
Source: | Code function: | 2_2_034906F7 | |
Source: | Code function: | 2_2_034B269F | |
Source: | Code function: | 2_2_03498EAC | |
Source: | Code function: | 2_2_03493AAE | |
Source: | Code function: | 2_2_03494140 | |
Source: | Code function: | 2_2_03499140 | |
Source: | Code function: | 2_2_03490542 | |
Source: | Code function: | 2_2_03493544 | |
Source: | Code function: | 2_2_03495146 | |
Source: | Code function: | 2_2_0349395A | |
Source: | Code function: | 2_2_03499178 | |
Source: | Code function: | 2_2_03493173 | |
Source: | Code function: | 2_2_034B150A | |
Source: | Code function: | 2_2_0349D50D | |
Source: | Code function: | 2_2_03490128 | |
Source: | Code function: | 2_2_034B2929 | |
Source: | Code function: | 2_2_0349A92A | |
Source: | Code function: | 2_2_03490922 | |
Source: | Code function: | 2_2_03490D39 | |
Source: | Code function: | 2_2_03493D35 | |
Source: | Code function: | 2_2_03498D34 | |
Source: | Code function: | 2_2_03493936 | |
Source: | Code function: | 2_2_034909CE | |
Source: | Code function: | 2_2_034905DA | |
Source: | Code function: | 2_2_034995DE | |
Source: | Code function: | 2_2_034935D1 | |
Source: | Code function: | 2_2_03493DE8 | |
Source: | Code function: | 2_2_034939EF | |
Source: | Code function: | 2_2_03498D96 | |
Source: | Code function: | 2_2_034901B5 | |
Source: | Code function: | 2_2_03493C4A | |
Source: | Code function: | 2_2_0349AC50 | |
Source: | Code function: | 2_2_03494057 | |
Source: | Code function: | 2_2_03490472 | |
Source: | Code function: | 2_2_0349D80D | |
Source: | Code function: | 2_2_03490001 | |
Source: | Code function: | 2_2_03490C04 | |
Source: | Code function: | 2_2_0349001C | |
Source: | Code function: | 2_2_03493415 | |
Source: | Code function: | 2_2_03493CC6 | |
Source: | Code function: | 2_2_034904D4 | |
Source: | Code function: | 2_2_0349D4EF | |
Source: | Code function: | 2_2_034930FC | |
Source: | Code function: | 2_2_034910F4 | |
Source: | Code function: | 2_2_03490C98 | |
Source: | Code function: | 2_2_03491497 | |
Source: | Code function: | 2_2_034934A9 | |
Source: | Code function: | 2_2_034900AB | |
Source: | Code function: | 2_2_034AFCBF | |
Source: | Code function: | 2_2_034938B1 |
Source: | Code function: | 2_2_034B390B | |
Source: | Code function: | 2_2_034B4860 | |
Source: | Code function: | 14_2_01664634 | |
Source: | Code function: | 14_2_016646E8 | |
Source: | Code function: | 14_2_016646DF |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | File read: | Jump to behavior |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Code function: | 2_2_0040344A |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | Code function: | 2_2_00402104 |
Source: | File read: | Jump to behavior |
Source: | Code function: | 2_2_00404771 |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: |
Data Obfuscation |
---|
Source: | File source: | ||
Source: | File source: |
Source: | Code function: | 2_2_10002E0E | |
Source: | Code function: | 2_2_03496F49 | |
Source: | Code function: | 2_2_03494B96 | |
Source: | Code function: | 2_2_034A2FD3 | |
Source: | Code function: | 2_2_03496F49 | |
Source: | Code function: | 2_2_034962A3 | |
Source: | Code function: | 2_2_0349D162 | |
Source: | Code function: | 2_2_03496078 | |
Source: | Code function: | 2_2_034974FF | |
Source: | Code function: | 14_2_01660C45 | |
Source: | Code function: | 14_2_0166374E | |
Source: | Code function: | 14_2_01663252 | |
Source: | Code function: | 14_2_0166144E |
Source: | Static PE information: |
Source: | Code function: | 2_2_10001B18 |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Dropped PE file which has not been started: | Jump to dropped file |
Source: | Code function: | 2_2_03494749 |
Source: | Code function: | 2_2_00406555 | |
Source: | Code function: | 2_2_00405A03 | |
Source: | Code function: | 2_2_0040287E |
Source: | System information queried: | Jump to behavior |
Source: | API call chain: | graph_2-15787 | ||
Source: | API call chain: | graph_2-15944 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 2_2_10001B18 |
Source: | Code function: | 2_2_03494749 |
Source: | Code function: | 2_2_0349DF36 | |
Source: | Code function: | 2_2_0349DBFA | |
Source: | Code function: | 2_2_034A1788 | |
Source: | Code function: | 2_2_0349DE78 | |
Source: | Code function: | 2_2_0349DE78 | |
Source: | Code function: | 2_2_0349DE18 | |
Source: | Code function: | 2_2_034B06CA | |
Source: | Code function: | 2_2_0349DEC4 | |
Source: | Code function: | 2_2_0349C686 | |
Source: | Code function: | 2_2_034B2929 | |
Source: | Code function: | 2_2_03498D96 | |
Source: | Code function: | 2_2_0349DC48 | |
Source: | Code function: | 2_2_0349D4EF | |
Source: | Code function: | 2_2_0349DCA9 |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 2_2_034B073D |
Source: | Process created: | Jump to behavior |
Source: | Code function: | 2_2_0040344A |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | 1 Native API | 1 Registry Run Keys / Startup Folder | 1 Access Token Manipulation | 12 Virtualization/Sandbox Evasion | OS Credential Dumping | 121 Security Software Discovery | Remote Services | 1 Archive Collected Data | Exfiltration Over Other Network Medium | 1 Encrypted Channel | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | 1 System Shutdown/Reboot |
Default Accounts | Scheduled Task/Job | 1 DLL Side-Loading | 11 Process Injection | 1 Access Token Manipulation | LSASS Memory | 12 Virtualization/Sandbox Evasion | Remote Desktop Protocol | 1 Clipboard Data | Exfiltration Over Bluetooth | 1 Non-Application Layer Protocol | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | 1 Registry Run Keys / Startup Folder | 11 Process Injection | Security Account Manager | 2 File and Directory Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 1 Application Layer Protocol | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | 1 DLL Side-Loading | 1 Obfuscated Files or Information | NTDS | 4 System Information Discovery | Distributed Component Object Model | Input Capture | Scheduled Transfer | Protocol Impersonation | SIM Card Swap | Carrier Billing Fraud | |
Cloud Accounts | Cron | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | Remote System Discovery | SSH | Keylogging | Data Transfer Size Limits | Fallback Channels | Manipulate Device Communication | Manipulate App Store Rankings or Ratings |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
2% | ReversingLabs | |||
0% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
10% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
bulungan.go.id | 103.131.61.194 | true | false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
false |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
false |
| unknown | ||
true |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
false | high | |||
true |
| unknown | ||
false | high | |||
false |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
103.131.61.194 | bulungan.go.id | Indonesia | 138126 | IDNIC-NEWTON-AS-IDPTNEWTONCIPTAINFORMATIKAID | false |
Joe Sandbox Version: | 36.0.0 Rainbow Opal |
Analysis ID: | 755084 |
Start date and time: | 2022-11-28 10:51:05 +01:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 13m 22s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | 98765434567890.exe |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit 20H2 Native physical Machine for testing VM-aware malware (Office 2019, IE 11, Chrome 93, Firefox 91, Adobe Reader DC 21, Java 8 Update 301 |
Run name: | Suspected Instruction Hammering |
Number of analysed new started processes analysed: | 30 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal60.troj.evad.winEXE@3/4@1/1 |
EGA Information: |
|
HDC Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, BackgroundTransferHost.exe, RuntimeBroker.exe, WMIADAP.exe, backgroundTaskHost.exe, SgrmBroker.exe, MoUsoCoreWorker.exe, svchost.exe
- Excluded domains from analysis (whitelisted): ris.api.iris.microsoft.com, wdcpalt.microsoft.com, client.wns.windows.com, fs.microsoft.com, login.live.com, ctldl.windowsupdate.com, settings-win.data.microsoft.com, wdcp.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, arc.msn.com
- Execution Graph export aborted for target 98765434567890.exe, PID 7584 because there are no executed function
- Report size getting too big, too many NtDeviceIoControlFile calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtSetInformationFile calls found.
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
103.131.61.194 | Get hash | malicious | Browse | ||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
bulungan.go.id | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
IDNIC-NEWTON-AS-IDPTNEWTONCIPTAINFORMATIKAID | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
C:\Users\user\AppData\Local\Temp\nstFA69.tmp\System.dll | Get hash | malicious | Browse | ||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse |
Process: | C:\Users\user\Desktop\98765434567890.exe |
File Type: | |
Category: | modified |
Size (bytes): | 11776 |
Entropy (8bit): | 5.656065698421856 |
Encrypted: | false |
SSDEEP: | 192:eY24sihno00Wfl97nH6T2enXwWobpWBTU4VtHT7dmN35Ol+Sl:E8QIl975eXqlWBrz7YLOl+ |
MD5: | 17ED1C86BD67E78ADE4712BE48A7D2BD |
SHA1: | 1CC9FE86D6D6030B4DAE45ECDDCE5907991C01A0 |
SHA-256: | BD046E6497B304E4EA4AB102CAB2B1F94CE09BDE0EEBBA4C59942A732679E4EB |
SHA-512: | 0CBED521E7D6D1F85977B3F7D3CA7AC34E1B5495B69FD8C7BFA1A846BAF53B0ECD06FE1AD02A3599082FFACAF8C71A3BB4E32DEC05F8E24859D736B828092CD5 |
Malicious: | false |
Antivirus: |
|
Joe Sandbox View: |
|
Reputation: | moderate, very likely benign file |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Stempelpligtig93\X\Unsalty\Epithem.Dre
Download File
Process: | C:\Users\user\Desktop\98765434567890.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71042 |
Entropy (8bit): | 7.997487610071428 |
Encrypted: | true |
SSDEEP: | 1536:LoTgnjw+E7cYT8/O3qCaPdc4MgMHJB5KGSZfV:cww+8YSqnG4MNoGSD |
MD5: | B11B64A276E8FEB3D09F2CBCEE1DA91D |
SHA1: | AC7191608193A7479C7BE2AD72754D60BB22801B |
SHA-256: | 5F2966EE48ACB731DCE5B8977D6A61C891059058B76F03F670A75C3B2BDB83EA |
SHA-512: | CA023A0D961F3E4886F5345EE9A877B632D017AC2028DEAB0AFD6BBDB86F19AD9E018CD16F1A692764076FD556FB8AD3BA01366B013EC35153C1BC88B9D9B3B4 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Stempelpligtig93\X\Unsalty\libgiognutls.dll
Download File
Process: | C:\Users\user\Desktop\98765434567890.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 131991 |
Entropy (8bit): | 5.8780987492725405 |
Encrypted: | false |
SSDEEP: | 1536:v6J1cdTEl2OzvUtevCuoCW9fPr+vo9F5J7YWv3vbRnBycYWOGWSeaGymtYWOGWSS:VdW2OLgNCwXKSH8WPvVBjA+KE8S5 |
MD5: | 10D998CF80B4437C2979B25EBCBE16D1 |
SHA1: | 79C99DD2ABB99253E41C5E40DAB29522F93345BB |
SHA-256: | A0A87BC30F4B39D7B642841A10208CE5286C6CA712B28B9D921E1EA6F547AEE6 |
SHA-512: | 44863645B48815C3C248111F86440E3A0C515AF61B5A17D15B5A6C7304277F76056BCEB6C579E7824E11ADCA4DB3E385FA8019D602C40FA527E725C09B6AA523 |
Malicious: | false |
Antivirus: |
|
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Stempelpligtig93\antagonizing\Trespassage\Importprisernes.Qui
Download File
Process: | C:\Users\user\Desktop\98765434567890.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 178390 |
Entropy (8bit): | 6.530973591237936 |
Encrypted: | false |
SSDEEP: | 1536:D2+s6BE+9e6acEoJlwBCIQBMvbN+r9dt0ppPn4t2vcCTAgP+48IhsckBtg6:DVur6aRwssypZ4t2kCMgP8cWtg6 |
MD5: | EE4440124C925FE4F95735EA4568FAE6 |
SHA1: | C7428FDB29B43C77589FF0C160AEE0C063DD20A1 |
SHA-256: | 08705B17B6DAE5798AD5AE935FC23CFFE929B3EA490C0D0F09EBD6F1CE19E4A2 |
SHA-512: | C8927169A8395684C24C680498A152D53FCCFD3C5D05E0CB83926565C77BDAE6F9468744FC2A010E45FD6E6860877AA05F6067C3A2484BD1E26BBE780A01E82D |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.422995711933732 |
TrID: |
|
File name: | 98765434567890.exe |
File size: | 428864 |
MD5: | 1c4e3e615e3596572062bca5ec498d41 |
SHA1: | 40365b3026ba2fca699462877fc106d58d2406c2 |
SHA256: | 622163e09e5ad5324887c02d7834628d7213015fc48d286d69b4a90fa17a772d |
SHA512: | 2e87606c186203ee5018d737721e6de9e5ccfbc3c541f71dc7e836c705d8afa7a41e13b8e70f85223b41117323b9c15cc3301b3438eee5cf26200e48c01ba033 |
SSDEEP: | 6144:0wq3NpnsvZK26XgmwnTi512noHCAibaH+Z23pSzpQl2sCbtORgNbTg:0z772qgvq2njDme2pSzZhtE |
TLSH: | D894DF95F78106D9DC75577149BB9D370277BD3E18B10B9F62AD32312F332828A07A2A |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1...P...P...P..*_...P...P..OP..*_...P...s...P...V...P..Rich.P..........PE..L...8.MX.................b...*......J4............@ |
Icon Hash: | b8eee6a4c0c8c6c2 |
Entrypoint: | 0x40344a |
Entrypoint Section: | .text |
Digitally signed: | true |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x584DCA38 [Sun Dec 11 21:50:48 2016 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | 4ea4df5d94204fc550be1874e1b77ea7 |
Signature Valid: | false |
Signature Issuer: | CN=Derobe, OU="Papirspose Dokumentfilens ", E=Drikkelagets@Unaadigt.Sh, O=Derobe, L=Neu Duvenstedt, S=Schleswig-Holstein, C=DE |
Signature Validation Error: | A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider |
Error Number: | -2146762487 |
Not Before, Not After |
|
Subject Chain |
|
Version: | 3 |
Thumbprint MD5: | 13BD13A74F5989BBBF4626613B253C7F |
Thumbprint SHA-1: | 3FF1D875731FD030D811E21481EF38D2C90E217A |
Thumbprint SHA-256: | 919DEF4FB98F825B484FBCC82721EDA3F9094E0BAFFBEF15B4BC145160DD6350 |
Serial: | 1254C7D01C8577B0 |
Instruction |
---|
sub esp, 000002D4h |
push ebx |
push esi |
push edi |
push 00000020h |
pop edi |
xor ebx, ebx |
push 00008001h |
mov dword ptr [esp+14h], ebx |
mov dword ptr [esp+10h], 0040A230h |
mov dword ptr [esp+1Ch], ebx |
call dword ptr [004080B4h] |
call dword ptr [004080B0h] |
cmp ax, 00000006h |
je 00007F82F8B78203h |
push ebx |
call 00007F82F8B7B35Ch |
cmp eax, ebx |
je 00007F82F8B781F9h |
push 00000C00h |
call eax |
mov esi, 004082B8h |
push esi |
call 00007F82F8B7B2D6h |
push esi |
call dword ptr [0040815Ch] |
lea esi, dword ptr [esi+eax+01h] |
cmp byte ptr [esi], 00000000h |
jne 00007F82F8B781DCh |
push ebp |
push 00000009h |
call 00007F82F8B7B32Eh |
push 00000007h |
call 00007F82F8B7B327h |
mov dword ptr [0042A244h], eax |
call dword ptr [0040803Ch] |
push ebx |
call dword ptr [004082A4h] |
mov dword ptr [0042A2F8h], eax |
push ebx |
lea eax, dword ptr [esp+34h] |
push 000002B4h |
push eax |
push ebx |
push 004216E8h |
call dword ptr [00408188h] |
push 0040A384h |
push 00429240h |
call 00007F82F8B7AF10h |
call dword ptr [004080ACh] |
mov ebp, 00435000h |
push eax |
push ebp |
call 00007F82F8B7AEFEh |
push ebx |
call dword ptr [00408174h] |
add word ptr [eax], 0000h |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x8504 | 0xa0 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x6e000 | 0x28868 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x675d8 | 0x1568 | .ndata |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x8000 | 0x2b4 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x61f1 | 0x6200 | False | 0.6656967474489796 | data | 6.477074763411717 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x8000 | 0x13a4 | 0x1400 | False | 0.4529296875 | data | 5.163001655755973 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0xa000 | 0x20338 | 0x600 | False | 0.501953125 | data | 3.9745558434885093 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.ndata | 0x2b000 | 0x43000 | 0x0 | False | 0 | empty | 0.0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x6e000 | 0x28868 | 0x28a00 | False | 0.4693269230769231 | data | 6.072692072533226 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country |
---|---|---|---|---|---|
RT_BITMAP | 0x6e3b8 | 0x368 | Device independent bitmap graphic, 96 x 16 x 4, image size 768 | English | United States |
RT_ICON | 0x6e720 | 0x10828 | Device independent bitmap graphic, 128 x 256 x 32, image size 65536 | English | United States |
RT_ICON | 0x7ef48 | 0x94a8 | Device independent bitmap graphic, 96 x 192 x 32, image size 36864 | English | United States |
RT_ICON | 0x883f0 | 0x5488 | Device independent bitmap graphic, 72 x 144 x 32, image size 20736 | English | United States |
RT_ICON | 0x8d878 | 0x4228 | Device independent bitmap graphic, 64 x 128 x 32, image size 16384 | English | United States |
RT_ICON | 0x91aa0 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9216 | English | United States |
RT_ICON | 0x94048 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4096 | English | United States |
RT_ICON | 0x950f0 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2304 | English | United States |
RT_ICON | 0x95a78 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1024 | English | United States |
RT_DIALOG | 0x95ee0 | 0x144 | data | English | United States |
RT_DIALOG | 0x96028 | 0x13c | data | English | United States |
RT_DIALOG | 0x96168 | 0x100 | data | English | United States |
RT_DIALOG | 0x96268 | 0x11c | data | English | United States |
RT_DIALOG | 0x96388 | 0xc4 | data | English | United States |
RT_DIALOG | 0x96450 | 0x60 | data | English | United States |
RT_GROUP_ICON | 0x964b0 | 0x76 | data | English | United States |
RT_MANIFEST | 0x96528 | 0x33e | XML 1.0 document, ASCII text, with very long lines (830), with no line terminators | English | United States |
DLL | Import |
---|---|
KERNEL32.dll | SetCurrentDirectoryW, GetFileAttributesW, GetFullPathNameW, Sleep, GetTickCount, CreateFileW, GetFileSize, MoveFileW, SetFileAttributesW, GetModuleFileNameW, CopyFileW, ExitProcess, SetEnvironmentVariableW, GetWindowsDirectoryW, GetTempPathW, GetCommandLineW, GetVersion, SetErrorMode, WaitForSingleObject, GetCurrentProcess, CompareFileTime, GlobalUnlock, GlobalLock, CreateThread, GetLastError, CreateDirectoryW, CreateProcessW, RemoveDirectoryW, lstrcmpiA, GetTempFileNameW, WriteFile, lstrcpyA, lstrcpyW, MoveFileExW, lstrcatW, GetSystemDirectoryW, GetProcAddress, GetModuleHandleA, GlobalFree, GlobalAlloc, GetShortPathNameW, SearchPathW, lstrcmpiW, SetFileTime, CloseHandle, ExpandEnvironmentStringsW, lstrcmpW, GetDiskFreeSpaceW, lstrlenW, lstrcpynW, GetExitCodeProcess, FindFirstFileW, FindNextFileW, DeleteFileW, SetFilePointer, ReadFile, FindClose, MulDiv, MultiByteToWideChar, lstrlenA, WideCharToMultiByte, GetPrivateProfileStringW, WritePrivateProfileStringW, FreeLibrary, LoadLibraryExW, GetModuleHandleW |
USER32.dll | GetSystemMenu, SetClassLongW, IsWindowEnabled, EnableMenuItem, SetWindowPos, GetSysColor, GetWindowLongW, SetCursor, LoadCursorW, CheckDlgButton, GetMessagePos, LoadBitmapW, CallWindowProcW, IsWindowVisible, CloseClipboard, SetClipboardData, EmptyClipboard, OpenClipboard, wsprintfW, ScreenToClient, GetWindowRect, GetSystemMetrics, SetDlgItemTextW, GetDlgItemTextW, MessageBoxIndirectW, CharPrevW, CharNextA, wsprintfA, DispatchMessageW, PeekMessageW, GetDC, ReleaseDC, EnableWindow, InvalidateRect, SendMessageW, DefWindowProcW, BeginPaint, GetClientRect, FillRect, EndDialog, RegisterClassW, SystemParametersInfoW, CreateWindowExW, GetClassInfoW, DialogBoxParamW, CharNextW, ExitWindowsEx, DestroyWindow, LoadImageW, SetTimer, SetWindowTextW, PostQuitMessage, ShowWindow, GetDlgItem, IsWindow, SetWindowLongW, FindWindowExW, TrackPopupMenu, AppendMenuW, CreatePopupMenu, DrawTextW, EndPaint, CreateDialogParamW, SendMessageTimeoutW, SetForegroundWindow |
GDI32.dll | SelectObject, SetBkMode, CreateFontIndirectW, SetTextColor, DeleteObject, GetDeviceCaps, CreateBrushIndirect, SetBkColor |
SHELL32.dll | SHGetSpecialFolderLocation, SHGetPathFromIDListW, SHBrowseForFolderW, SHGetFileInfoW, ShellExecuteW, SHFileOperationW |
ADVAPI32.dll | RegDeleteKeyW, SetFileSecurityW, OpenProcessToken, LookupPrivilegeValueW, AdjustTokenPrivileges, RegOpenKeyExW, RegEnumValueW, RegDeleteValueW, RegCloseKey, RegCreateKeyExW, RegSetValueExW, RegQueryValueExW, RegEnumKeyW |
COMCTL32.dll | ImageList_AddMasked, ImageList_Destroy, ImageList_Create |
ole32.dll | OleUninitialize, OleInitialize, CoTaskMemFree, CoCreateInstance |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 28, 2022 10:54:30.187997103 CET | 49812 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:54:31.193437099 CET | 49812 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:54:33.208492994 CET | 49812 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:54:35.224991083 CET | 49820 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:54:36.239165068 CET | 49820 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:54:38.254264116 CET | 49820 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:54:40.272130013 CET | 49821 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:54:41.284867048 CET | 49821 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:54:43.300009012 CET | 49821 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:54:45.318454981 CET | 49822 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:54:46.330590010 CET | 49822 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:54:48.330260992 CET | 49822 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:54:50.378714085 CET | 49824 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:54:51.392167091 CET | 49824 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:54:53.407237053 CET | 49824 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:54:55.423963070 CET | 49825 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:54:56.437838078 CET | 49825 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:54:58.453049898 CET | 49825 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:00.526283026 CET | 49826 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:01.530446053 CET | 49826 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:03.545794010 CET | 49826 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:05.546643972 CET | 49828 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:06.560669899 CET | 49828 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:08.575784922 CET | 49828 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:10.576622963 CET | 49830 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:11.590811968 CET | 49830 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:13.605881929 CET | 49830 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:15.623647928 CET | 49831 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:16.636519909 CET | 49831 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:18.651608944 CET | 49831 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:20.680504084 CET | 49832 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:21.682284117 CET | 49832 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:23.697439909 CET | 49832 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:25.729513884 CET | 49833 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:26.743746042 CET | 49833 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:28.758754015 CET | 49833 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:30.776875973 CET | 49834 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:31.789541006 CET | 49834 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:33.804660082 CET | 49834 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:35.821508884 CET | 49842 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:36.835243940 CET | 49842 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:38.850505114 CET | 49842 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:40.866740942 CET | 49843 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:41.881050110 CET | 49843 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:43.896049023 CET | 49843 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:45.898655891 CET | 49844 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:46.911051035 CET | 49844 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:48.926511049 CET | 49844 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:50.927023888 CET | 49845 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:51.941179991 CET | 49845 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:53.956402063 CET | 49845 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:55.973335981 CET | 49846 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:56.971406937 CET | 49846 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:55:58.986800909 CET | 49846 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:01.019787073 CET | 49847 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:02.032861948 CET | 49847 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:04.032371998 CET | 49847 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:06.080360889 CET | 49850 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:07.094300032 CET | 49850 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:09.109371901 CET | 49850 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:11.126271963 CET | 49851 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:12.139914036 CET | 49851 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:14.155178070 CET | 49851 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:16.172648907 CET | 49852 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:17.185770988 CET | 49852 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:19.200824022 CET | 49852 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:21.228969097 CET | 49853 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:22.231462955 CET | 49853 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:24.246814966 CET | 49853 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:26.248178959 CET | 49854 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:27.246130943 CET | 49854 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:29.261281967 CET | 49854 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:31.279381990 CET | 49855 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:32.291937113 CET | 49855 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:34.306965113 CET | 49855 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:36.323838949 CET | 49858 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:37.337627888 CET | 49858 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:39.352720976 CET | 49858 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:41.369080067 CET | 49859 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:42.383279085 CET | 49859 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:44.398480892 CET | 49859 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:46.431916952 CET | 49860 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:47.444664001 CET | 49860 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:49.459991932 CET | 49860 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:51.477034092 CET | 49861 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:52.490502119 CET | 49861 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:54.505712032 CET | 49861 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:56.524600983 CET | 49862 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:57.536298990 CET | 49862 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:56:59.551567078 CET | 49862 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:01.568989038 CET | 49863 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:02.581984997 CET | 49863 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:04.597390890 CET | 49863 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:06.598014116 CET | 49865 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:07.596613884 CET | 49865 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:09.611804008 CET | 49865 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:11.628869057 CET | 49866 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:12.642282009 CET | 49866 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:14.657557011 CET | 49866 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:16.675077915 CET | 49867 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:17.688127041 CET | 49867 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:19.703243971 CET | 49867 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:21.720341921 CET | 49868 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:22.733994007 CET | 49868 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:24.749190092 CET | 49868 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:26.800112009 CET | 49870 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:27.810956001 CET | 49870 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:29.810519934 CET | 49870 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:31.829051971 CET | 49871 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:32.840976000 CET | 49871 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:34.856129885 CET | 49871 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:36.872922897 CET | 49873 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:37.886737108 CET | 49873 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:39.901972055 CET | 49873 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:41.918633938 CET | 49874 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:42.932626009 CET | 49874 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:44.947797060 CET | 49874 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:46.949680090 CET | 49875 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:47.962759972 CET | 49875 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:49.977935076 CET | 49875 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:51.979172945 CET | 49876 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:52.992934942 CET | 49876 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:55.008126974 CET | 49876 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:57.024323940 CET | 49877 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:57:58.038645983 CET | 49877 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:00.053936958 CET | 49877 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:02.071464062 CET | 49878 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:03.084405899 CET | 49878 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:05.099628925 CET | 49878 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:07.131587029 CET | 49880 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:08.145934105 CET | 49880 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:10.145384073 CET | 49880 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:12.177973986 CET | 49881 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:13.191543102 CET | 49881 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:15.206808090 CET | 49881 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:17.225186110 CET | 49883 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:18.237379074 CET | 49883 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:20.252567053 CET | 49883 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:22.268892050 CET | 49884 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:23.283250093 CET | 49884 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:25.298259020 CET | 49884 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:27.299217939 CET | 49885 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:28.313138962 CET | 49885 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:30.328452110 CET | 49885 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:32.343628883 CET | 49886 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:33.359143972 CET | 49886 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:35.374325037 CET | 49886 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:37.374980927 CET | 49888 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:38.389206886 CET | 49888 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:40.404258966 CET | 49888 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:42.421195030 CET | 49889 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:43.434988022 CET | 49889 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:45.450242996 CET | 49889 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:47.483366013 CET | 49890 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:48.496408939 CET | 49890 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:50.511499882 CET | 49890 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:52.528223991 CET | 49891 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:53.542205095 CET | 49891 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:55.557322025 CET | 49891 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:57.573951006 CET | 49892 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:58:58.587961912 CET | 49892 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:00.603005886 CET | 49892 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:02.620888948 CET | 49893 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:03.633661032 CET | 49893 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:05.648925066 CET | 49893 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:07.649625063 CET | 49895 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:08.663825035 CET | 49895 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:10.679035902 CET | 49895 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:12.681091070 CET | 49896 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:13.693999052 CET | 49896 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:15.709053040 CET | 49896 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:17.726602077 CET | 49897 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:18.739679098 CET | 49897 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:20.755100012 CET | 49897 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:22.771559000 CET | 49898 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:23.785511017 CET | 49898 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:25.800860882 CET | 49898 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:27.833148956 CET | 49899 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:28.846950054 CET | 49899 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:30.861983061 CET | 49899 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:32.888746023 CET | 49901 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:33.892534018 CET | 49901 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:35.907705069 CET | 49901 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:37.924417019 CET | 49906 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:38.938529968 CET | 49906 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:40.953531981 CET | 49906 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:42.970020056 CET | 49909 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:43.984220028 CET | 49909 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:45.999322891 CET | 49909 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:48.001791000 CET | 49910 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:49.014296055 CET | 49910 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:51.029535055 CET | 49910 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:53.030348063 CET | 49911 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:54.044497967 CET | 49911 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:56.059720993 CET | 49911 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:58.077323914 CET | 49912 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 10:59:59.090270996 CET | 49912 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:01.105341911 CET | 49912 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:03.122889042 CET | 49914 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:04.135937929 CET | 49914 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:06.151257992 CET | 49914 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:08.183094025 CET | 49917 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:09.197350025 CET | 49917 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:11.212527990 CET | 49917 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:13.229162931 CET | 49918 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:14.243180990 CET | 49918 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:16.258325100 CET | 49918 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:18.276468992 CET | 49919 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:19.288947105 CET | 49919 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:21.304090023 CET | 49919 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:23.320858955 CET | 49920 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:24.334673882 CET | 49920 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:26.349948883 CET | 49920 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:28.394682884 CET | 49921 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:29.396176100 CET | 49921 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:31.411497116 CET | 49921 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:33.428755999 CET | 49922 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:34.441785097 CET | 49922 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:36.457056999 CET | 49922 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:38.485424995 CET | 49925 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:39.487612963 CET | 49925 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:41.502767086 CET | 49925 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:43.535232067 CET | 49926 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:44.549021006 CET | 49926 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:46.564161062 CET | 49926 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:48.581890106 CET | 49927 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:49.594763994 CET | 49927 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:51.609882116 CET | 49927 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:53.626293898 CET | 49928 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:54.640521049 CET | 49928 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:56.640245914 CET | 49928 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:58.672840118 CET | 49929 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:00:59.686446905 CET | 49929 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:01.701549053 CET | 49929 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:03.734842062 CET | 49930 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:04.747889996 CET | 49930 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:06.763072014 CET | 49930 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:08.779289961 CET | 49933 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:09.793904066 CET | 49933 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:11.808631897 CET | 49933 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:13.825259924 CET | 49934 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:14.839381933 CET | 49934 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:16.854435921 CET | 49934 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:18.887801886 CET | 49935 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:19.900556087 CET | 49935 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:21.916140079 CET | 49935 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:23.932964087 CET | 49936 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:24.946552992 CET | 49936 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:26.961783886 CET | 49936 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:28.978512049 CET | 49937 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:29.992268085 CET | 49937 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:32.007447004 CET | 49937 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:34.025393009 CET | 49938 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:35.037931919 CET | 49938 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:37.053098917 CET | 49938 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:39.086092949 CET | 49941 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:40.099397898 CET | 49941 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:42.114679098 CET | 49941 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:44.131227970 CET | 49942 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:45.145226002 CET | 49942 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:47.160248041 CET | 49942 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:49.187200069 CET | 49943 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:50.190814972 CET | 49943 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:52.206218004 CET | 49943 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:54.222393036 CET | 49944 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:55.236732960 CET | 49944 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:01:57.251832962 CET | 49944 | 80 | 192.168.11.20 | 103.131.61.194 |
Nov 28, 2022 11:02:01.266597986 CET | 49944 | 80 | 192.168.11.20 | 103.131.61.194 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 28, 2022 10:54:29.964380026 CET | 64889 | 53 | 192.168.11.20 | 1.1.1.1 |
Nov 28, 2022 10:54:30.161679029 CET | 53 | 64889 | 1.1.1.1 | 192.168.11.20 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 28, 2022 10:54:29.964380026 CET | 192.168.11.20 | 1.1.1.1 | 0xed43 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 28, 2022 10:54:30.161679029 CET | 1.1.1.1 | 192.168.11.20 | 0xed43 | No error (0) | 103.131.61.194 | A (IP address) | IN (0x0001) | false |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 2 |
Start time: | 10:53:33 |
Start date: | 28/11/2022 |
Path: | C:\Users\user\Desktop\98765434567890.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 428864 bytes |
MD5 hash: | 1C4E3E615E3596572062BCA5EC498D41 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Target ID: | 14 |
Start time: | 10:54:10 |
Start date: | 28/11/2022 |
Path: | C:\Users\user\Desktop\98765434567890.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 428864 bytes |
MD5 hash: | 1C4E3E615E3596572062BCA5EC498D41 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Execution Graph
Execution Coverage: | 4.7% |
Dynamic/Decrypted Code Coverage: | 3.6% |
Signature Coverage: | 19.1% |
Total number of Nodes: | 1077 |
Total number of Limit Nodes: | 43 |
Graph
Function 0040344A Relevance: 91.4, APIs: 33, Strings: 19, Instructions: 401stringfilecomCOMMON
Control-flow Graph
C-Code - Quality: 82% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404CED Relevance: 63.5, APIs: 33, Strings: 3, Instructions: 481windowmemoryCOMMONCrypto
Control-flow Graph
C-Code - Quality: 96% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034A67B8 Relevance: 28.8, Strings: 20, Instructions: 3837COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 95% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00405A03 Relevance: 17.6, APIs: 7, Strings: 3, Instructions: 148filestringCOMMON
Control-flow Graph
C-Code - Quality: 98% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004068DA Relevance: 5.4, APIs: 4, Instructions: 382COMMONCrypto
C-Code - Quality: 98% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0349D4EF Relevance: 1.7, Strings: 1, Instructions: 417COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034B1E5B Relevance: 1.6, Strings: 1, Instructions: 400COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034AF5DD Relevance: 1.6, APIs: 1, Instructions: 125fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034B390B Relevance: 1.5, APIs: 1, Instructions: 32nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03499E26 Relevance: .2, Instructions: 222COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034B073D Relevance: .2, Instructions: 161COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00403DFE Relevance: 58.1, APIs: 32, Strings: 1, Instructions: 345windowstringCOMMON
Control-flow Graph
C-Code - Quality: 83% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00403A5B Relevance: 49.2, APIs: 14, Strings: 14, Instructions: 215stringregistryCOMMON
Control-flow Graph
C-Code - Quality: 96% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00402ED5 Relevance: 26.5, APIs: 5, Strings: 10, Instructions: 203memoryCOMMON
Control-flow Graph
C-Code - Quality: 99% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00406234 Relevance: 21.2, APIs: 8, Strings: 4, Instructions: 207stringCOMMON
Control-flow Graph
C-Code - Quality: 74% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040176F Relevance: 15.9, APIs: 5, Strings: 4, Instructions: 145stringtimeCOMMON
Control-flow Graph
C-Code - Quality: 77% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00402660 Relevance: 10.7, APIs: 5, Strings: 1, Instructions: 153fileCOMMON
Control-flow Graph
C-Code - Quality: 83% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 73% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040657C Relevance: 10.5, APIs: 3, Strings: 3, Instructions: 36libraryCOMMON
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004023EA Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 73registrystringCOMMON
Control-flow Graph
C-Code - Quality: 86% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 84% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 92% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00401C19 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 84windowtimeCOMMON
C-Code - Quality: 59% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004060DF Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 45registryCOMMON
C-Code - Quality: 89% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 84% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 86% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004052E5 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 46windowCOMMON
C-Code - Quality: 89% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004058F2 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 24processCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00406D0F Relevance: 5.2, APIs: 4, Instructions: 236COMMON
C-Code - Quality: 99% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00406F10 Relevance: 5.2, APIs: 4, Instructions: 208COMMON
C-Code - Quality: 98% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00406C26 Relevance: 5.2, APIs: 4, Instructions: 205COMMON
C-Code - Quality: 98% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040672B Relevance: 5.2, APIs: 4, Instructions: 198COMMON
C-Code - Quality: 98% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00406B79 Relevance: 5.2, APIs: 4, Instructions: 180COMMON
C-Code - Quality: 98% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00406C97 Relevance: 5.2, APIs: 4, Instructions: 170COMMON
C-Code - Quality: 98% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00406BE3 Relevance: 5.2, APIs: 4, Instructions: 168COMMON
C-Code - Quality: 98% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00403283 Relevance: 4.6, APIs: 3, Instructions: 101COMMON
C-Code - Quality: 94% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00402032 Relevance: 4.6, APIs: 3, Instructions: 73libraryCOMMON
C-Code - Quality: 60% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00401B71 Relevance: 4.6, APIs: 2, Strings: 1, Instructions: 72memoryCOMMON
C-Code - Quality: 59% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 86% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 79% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 100028A4 Relevance: 3.2, APIs: 2, Instructions: 156fileCOMMON
C-Code - Quality: 16% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040317B Relevance: 3.1, APIs: 2, Instructions: 88COMMON
C-Code - Quality: 92% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 84% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00401389 Relevance: 3.0, APIs: 2, Instructions: 43windowCOMMON
C-Code - Quality: 69% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00401E43 Relevance: 3.0, APIs: 2, Instructions: 25COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00405DE7 Relevance: 3.0, APIs: 2, Instructions: 16fileCOMMON
C-Code - Quality: 68% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00405DC2 Relevance: 3.0, APIs: 2, Instructions: 13COMMON
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004058BD Relevance: 3.0, APIs: 2, Instructions: 9COMMON
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03495F58 Relevance: 1.6, APIs: 1, Instructions: 91COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040167B Relevance: 1.5, APIs: 1, Instructions: 38fileCOMMON
C-Code - Quality: 70% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00402805 Relevance: 1.5, APIs: 1, Instructions: 28COMMON
C-Code - Quality: 33% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040230C Relevance: 1.5, APIs: 1, Instructions: 25COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00401735 Relevance: 1.5, APIs: 1, Instructions: 24COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 79% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00405E6A Relevance: 1.5, APIs: 1, Instructions: 22fileCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00405E99 Relevance: 1.5, APIs: 1, Instructions: 22fileCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 100027C7 Relevance: 1.5, APIs: 1, Instructions: 21memoryCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040234E Relevance: 1.5, APIs: 1, Instructions: 20COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004015A3 Relevance: 1.5, APIs: 1, Instructions: 18COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00403402 Relevance: 1.5, APIs: 1, Instructions: 6COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040430B Relevance: 1.5, APIs: 1, Instructions: 6windowCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 1000121B Relevance: 1.3, APIs: 1, Instructions: 6memoryCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004054B0 Relevance: 66.8, APIs: 36, Strings: 2, Instructions: 284windowclipboardmemoryCOMMON
C-Code - Quality: 95% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404771 Relevance: 26.5, APIs: 10, Strings: 5, Instructions: 275stringCOMMON
C-Code - Quality: 78% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034937C2 Relevance: 5.4, Strings: 4, Instructions: 394COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034932EF Relevance: 4.3, Strings: 3, Instructions: 568COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03493173 Relevance: 4.3, Strings: 3, Instructions: 548COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03493415 Relevance: 4.3, Strings: 3, Instructions: 524COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034930FC Relevance: 4.3, Strings: 3, Instructions: 510COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03493544 Relevance: 4.3, Strings: 3, Instructions: 507COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03490D39 Relevance: 4.3, Strings: 3, Instructions: 503COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034934A9 Relevance: 4.2, Strings: 3, Instructions: 464COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034936EB Relevance: 4.2, Strings: 3, Instructions: 452COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0349364A Relevance: 4.2, Strings: 3, Instructions: 445COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034935D1 Relevance: 4.2, Strings: 3, Instructions: 434COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0349324F Relevance: 4.2, Strings: 3, Instructions: 431COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0349375C Relevance: 4.2, Strings: 3, Instructions: 402COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034939EF Relevance: 4.1, Strings: 3, Instructions: 363COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0349395A Relevance: 4.1, Strings: 3, Instructions: 356COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03493A51 Relevance: 4.1, Strings: 3, Instructions: 348COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034938B1 Relevance: 4.1, Strings: 3, Instructions: 343COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03493936 Relevance: 4.1, Strings: 3, Instructions: 336COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034AFCBF Relevance: 3.9, Strings: 3, Instructions: 171COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 67% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034903CA Relevance: 3.2, Strings: 2, Instructions: 703COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034900AB Relevance: 3.2, Strings: 2, Instructions: 698COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03490245 Relevance: 3.2, Strings: 2, Instructions: 688COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034B2929 Relevance: 3.2, Strings: 2, Instructions: 687COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03490344 Relevance: 3.2, Strings: 2, Instructions: 673COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03490542 Relevance: 3.2, Strings: 2, Instructions: 665COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03490922 Relevance: 3.2, Strings: 2, Instructions: 660COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034905DA Relevance: 3.1, Strings: 2, Instructions: 638COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0349001C Relevance: 3.1, Strings: 2, Instructions: 637COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034904D4 Relevance: 3.1, Strings: 2, Instructions: 626COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034901B5 Relevance: 3.1, Strings: 2, Instructions: 613COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03490001 Relevance: 3.1, Strings: 2, Instructions: 613COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03490128 Relevance: 3.1, Strings: 2, Instructions: 605COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034906F7 Relevance: 3.1, Strings: 2, Instructions: 591COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03490472 Relevance: 3.1, Strings: 2, Instructions: 584COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03490C04 Relevance: 3.1, Strings: 2, Instructions: 567COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03490F45 Relevance: 3.0, Strings: 2, Instructions: 535COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03490AEB Relevance: 3.0, Strings: 2, Instructions: 534COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034907AE Relevance: 3.0, Strings: 2, Instructions: 520COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034909CE Relevance: 3.0, Strings: 2, Instructions: 519COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03490C98 Relevance: 3.0, Strings: 2, Instructions: 508COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03490E5C Relevance: 3.0, Strings: 2, Instructions: 497COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03490B96 Relevance: 3.0, Strings: 2, Instructions: 496COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03490A47 Relevance: 3.0, Strings: 2, Instructions: 489COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034912CD Relevance: 3.0, Strings: 2, Instructions: 467COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034910F4 Relevance: 2.9, Strings: 2, Instructions: 444COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03490ECA Relevance: 2.9, Strings: 2, Instructions: 428COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03491497 Relevance: 2.9, Strings: 2, Instructions: 416COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0349135A Relevance: 2.9, Strings: 2, Instructions: 402COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03493B0E Relevance: 2.9, Strings: 2, Instructions: 396COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03491275 Relevance: 2.9, Strings: 2, Instructions: 390COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03493E56 Relevance: 2.9, Strings: 2, Instructions: 389COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03493BDD Relevance: 2.9, Strings: 2, Instructions: 374COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034913F4 Relevance: 2.9, Strings: 2, Instructions: 366COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03493B86 Relevance: 2.9, Strings: 2, Instructions: 360COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03493CC6 Relevance: 2.9, Strings: 2, Instructions: 358COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03493D35 Relevance: 2.8, Strings: 2, Instructions: 340COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03493C4A Relevance: 2.8, Strings: 2, Instructions: 337COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03494057 Relevance: 2.8, Strings: 2, Instructions: 330COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03493AAE Relevance: 2.8, Strings: 2, Instructions: 320COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03493F04 Relevance: 2.8, Strings: 2, Instructions: 309COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03493FAE Relevance: 2.8, Strings: 2, Instructions: 303COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03493DE8 Relevance: 2.8, Strings: 2, Instructions: 300COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03494749 Relevance: 2.8, Strings: 2, Instructions: 283COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03494140 Relevance: 2.8, Strings: 2, Instructions: 261COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040287E Relevance: 1.5, APIs: 1, Instructions: 30fileCOMMON
C-Code - Quality: 39% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0349D50D Relevance: 1.5, Strings: 1, Instructions: 268COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034995DE Relevance: 1.5, Strings: 1, Instructions: 265COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03499634 Relevance: 1.5, Strings: 1, Instructions: 242COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03498D34 Relevance: 1.5, Strings: 1, Instructions: 221COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03498D96 Relevance: 1.5, Strings: 1, Instructions: 221COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03499774 Relevance: 1.4, Strings: 1, Instructions: 184COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034992C8 Relevance: 1.4, Strings: 1, Instructions: 118COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034B150A Relevance: 1.4, Strings: 1, Instructions: 116COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0349C686 Relevance: 1.3, Strings: 1, Instructions: 92COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0349A92A Relevance: .3, Instructions: 260COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0349D610 Relevance: .2, Instructions: 226COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0349DBFA Relevance: .2, Instructions: 211COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034AF7C2 Relevance: .2, Instructions: 194COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0349D700 Relevance: .2, Instructions: 190COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03498EAC Relevance: .2, Instructions: 183COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03498FC4 Relevance: .2, Instructions: 181COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03499234 Relevance: .2, Instructions: 180COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0349AB50 Relevance: .2, Instructions: 175COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03495146 Relevance: .2, Instructions: 167COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03499178 Relevance: .2, Instructions: 161COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0349D80D Relevance: .2, Instructions: 161COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03499140 Relevance: .2, Instructions: 160COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0349DC48 Relevance: .1, Instructions: 148COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0349DCA9 Relevance: .1, Instructions: 148COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0349D2E4 Relevance: .1, Instructions: 147COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034B520C Relevance: .1, Instructions: 143COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0349DE78 Relevance: .1, Instructions: 128COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0349AC50 Relevance: .1, Instructions: 127COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034B269F Relevance: .1, Instructions: 116COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0349DEC4 Relevance: .1, Instructions: 109COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0349DF36 Relevance: .1, Instructions: 107COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0349DE18 Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034A1788 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 034B06CA Relevance: .0, Instructions: 4COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404473 Relevance: 42.2, APIs: 20, Strings: 4, Instructions: 207windowstringCOMMON
C-Code - Quality: 93% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 90% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00405F41 Relevance: 24.6, APIs: 11, Strings: 3, Instructions: 131stringmemoryCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 91% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040433D Relevance: 12.1, APIs: 8, Instructions: 61COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404C3B Relevance: 10.5, APIs: 5, Strings: 1, Instructions: 48windowCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00402D98 Relevance: 10.5, APIs: 4, Strings: 2, Instructions: 36timeCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 100022D0 Relevance: 9.1, APIs: 6, Instructions: 136memoryCOMMON
C-Code - Quality: 86% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 100024A9 Relevance: 9.1, APIs: 6, Instructions: 98COMMON
C-Code - Quality: 76% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 93% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404B2D Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 84stringCOMMON
C-Code - Quality: 77% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004025AE Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 69stringCOMMON
C-Code - Quality: 88% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 100015FF Relevance: 7.5, APIs: 5, Instructions: 41memorylibraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00405CCE Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 47stringCOMMON
C-Code - Quality: 53% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00405BC6 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 16stringCOMMON
C-Code - Quality: 58% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00405C12 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 16stringCOMMON
C-Code - Quality: 77% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 100010E1 Relevance: 5.1, APIs: 4, Instructions: 104memoryCOMMON
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00405D4C Relevance: 5.0, APIs: 4, Instructions: 37stringCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |