Loading ...

Similarity Report

Overview

General Information

Joe Sandbox Version:23.0.0
Analysis ID:646398
Start date:28.08.2018
Start time:12:55:34
Joe Sandbox Product:Cloud
Overall analysis duration:0h 7m 43s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:Zx7i3Q9U9i (renamed file extension from none to exe)
Cookbook file name:default.jbs
Analysis system description:Windows 7 (Office 2010 SP2, Java 1.8.0_40, Flash 16.0.0.305, Acrobat Reader 11.0.08, Internet Explorer 11, Chrome 55, Firefox 43)
Number of analysed new started processes analysed:14
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:1
Technologies
  • HCA enabled
  • EGA enabled
  • HDC enabled
Analysis stop reason:Timeout
Detection:MAL
Classification:mal100.phis.bank.troj.spyw.evad.winEXE@15/13@12/5
EGA Information:
  • Successful, ratio: 100%
HDC Information:
  • Successful, ratio: 22.4% (good quality ratio 22.4%)
  • Quality average: 97.2%
  • Quality standard deviation: 6%
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 137
  • Number of non-executed functions: 173
Cookbook Comments:
  • Adjust boot time
Warnings:
Show All
  • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, conhost.exe
  • Report size getting too big, too many NtAllocateVirtualMemory calls found.
  • Report size getting too big, too many NtDeviceIoControlFile calls found.
  • Report size getting too big, too many NtEnumerateKey calls found.
  • Report size getting too big, too many NtOpenKeyEx calls found.
  • Report size getting too big, too many NtProtectVirtualMemory calls found.
  • Report size getting too big, too many NtQueryValueKey calls found.
  • Report size getting too big, too many NtReadVirtualMemory calls found.

Static File Info

File type:PE32 executable (GUI) Intel 80386, for MS Windows
Entropy (8bit):7.988606409235657
TrID:
  • Win32 Executable (generic) a (10002005/4) 99.96%
  • Generic Win/DOS Executable (2004/3) 0.02%
  • DOS Executable Generic (2002/1) 0.02%
  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
File name:Zx7i3Q9U9i.exe
File size:267776
MD5:e2476ed98a57bbb14f45fd1e04d4c43c
SHA1:999a0891ff900227f6a23b95eb708fab5caa7d78
SHA256:bd36dfdb6de9b3785f089dca00c2bbcbdd01a158b6112c5505119c3c9464ef9f
SHA512:3f31c7eebea35265d5fd6e740ca51e29ccd4b5f08f688197c4b4ee2ed81bf82643470535de070f1857a72cbf71bb012fb36659a0431b4edde5d12e29d9500e05
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........Q...?...?...?.......?...>...?...b...?..FN...?..FG...?.Rich..?.........................PE..L......Z...........................

Similarity Information

Algorithm:APISTRING
Total Signature IDs in Database:4106864
Total Processes Database:48838
Total similar Processes:985
Total similar Functions:23722

Similar Processes

  • Zx7i3Q9U9i.exe (MD5: E2476ED98A57BBB14F45FD1E04D4C43C, PID: 3424)
    • explorer.exe (PID: 1432, MD5: 6DDCA324434FFA506CF7DC4E51DB7935 AnalysisID: 44237 Similar Functions: 79)
    • 87024.exe (PID: 3984, MD5: 1714CF2647A549D0D7529223ACF0FC97 AnalysisID: 56552 Similar Functions: 61)
    • apdsroxy.exe (PID: 3636, MD5: B6EECE7B4FD1B4BD2626AA07E17DA9DE AnalysisID: 60981 Similar Functions: 39)
    • 111post.exe (PID: 3632, MD5: 2E3FB8B38E59480ED8F47449A46E2082 AnalysisID: 66610 Similar Functions: 37)
    • crypmgmt.exe (PID: 3868, MD5: E5C7B986B6FD3733504DB3FD6D6FAADA AnalysisID: 68428 Similar Functions: 37)
    • sort.exe (PID: 3472, MD5: A8B931811E8A8BDB83E0AFF2E1C6E560 AnalysisID: 67025 Similar Functions: 37)
    • crypmgmt.exe (PID: 3564, MD5: 3F602782259014F0253ECDEDFEF4D261 AnalysisID: 68262 Similar Functions: 37)
    • crypmgmt.exe (PID: 3816, MD5: 34C71A2B5584813A6BC94888E3669320 AnalysisID: 64003 Similar Functions: 36)
    • crypmgmt.exe (PID: 3828, MD5: 479B945127CC75C2A44ED1B13482FB07 AnalysisID: 67591 Similar Functions: 36)
    • crypmgmt.exe (PID: 3524, MD5: C007415B17DF758F2ED04850F95EE60E AnalysisID: 64002 Similar Functions: 36)
    • crypmgmt.exe (PID: 3792, MD5: 707D88A25F54B3F8785905F254974BCE AnalysisID: 63657 Similar Functions: 35)
    • foaqDTP.exe (PID: 3540, MD5: B6EECE7B4FD1B4BD2626AA07E17DA9DE AnalysisID: 60981 Similar Functions: 35)
    • gifmsg.exe (PID: 3448, MD5: 5BDD37EDD3740A4E2DA2E05ABDC20A20 AnalysisID: 60136 Similar Functions: 34)
    • gifmsg.exe (PID: 3520, MD5: 5BDD37EDD3740A4E2DA2E05ABDC20A20 AnalysisID: 60136 Similar Functions: 34)
    • crypmgmt.exe (PID: 3524, MD5: 13FFE10E12298A4E8DC1EE7A0B003B93 AnalysisID: 58680 Similar Functions: 34)
    • crypmgmt.exe (PID: 3872, MD5: 0520E2BE92296DE286739115ACA14892 AnalysisID: 57932 Similar Functions: 34)
    • 010.exe (PID: 3696, MD5: 39E01E2F5A5FBFECA5ABC01131E7E3A1 AnalysisID: 63143 Similar Functions: 33)
    • scansione_F24_.jpg.exe (PID: 3776, MD5: E5C7B986B6FD3733504DB3FD6D6FAADA AnalysisID: 68428 Similar Functions: 32)
    • crypmgmt.exe (PID: 3532, MD5: B58623B61A3D254FB9FF47FF0A4A74C6 AnalysisID: 66839 Similar Functions: 32)
    • 032901.exe (PID: 3384, MD5: F3C6625D8EDE3FE6C8C4023337D761AC AnalysisID: 66739 Similar Functions: 32)
    • wukapedof.exe (PID: 2468, MD5: AD22F7E25E6FCCF900B5060D4C5E9532 AnalysisID: 68439 Similar Functions: 32)
    • yyya.exe (PID: 3736, MD5: 479B945127CC75C2A44ED1B13482FB07 AnalysisID: 67591 Similar Functions: 32)
    • 0.exe (PID: 3388, MD5: 8905AD755F4CDCD7C4AF3FD546F67BFC AnalysisID: 65738 Similar Functions: 32)
    • 10.exe (PID: 3420, MD5: 0CEEE3CE1679E892A20AEBA2258A928C AnalysisID: 59085 Similar Functions: 32)
    • crypt_0001_1096b.exe (PID: 3720, MD5: 34C71A2B5584813A6BC94888E3669320 AnalysisID: 64003 Similar Functions: 32)
    • itera.exe (PID: 3940, MD5: 1C84D323D09233F71A6087CD5DA1F24A AnalysisID: 57776 Similar Functions: 32)
    • upsc.exe (PID: 3700, MD5: 5F53229E5AC3246C28629EE07946ADB6 AnalysisID: 63295 Similar Functions: 32)
    • crypt_0001_1096a.exe (PID: 3408, MD5: C007415B17DF758F2ED04850F95EE60E AnalysisID: 64002 Similar Functions: 31)
    • file2.exe (PID: 3684, MD5: 2B6E31835DAF786F3E9DEEC103C208BB AnalysisID: 66847 Similar Functions: 31)
    • 251287.exe (PID: 3620, MD5: 164138344D25F82E73E5E2EDB810187B AnalysisID: 544867 Similar Functions: 31)
  • d3d8sext.exe (MD5: E2476ED98A57BBB14F45FD1E04D4C43C, PID: 3520)
    • explorer.exe (PID: 1432, MD5: 6DDCA324434FFA506CF7DC4E51DB7935 AnalysisID: 37523 Similar Functions: 898)
    • cmd.exe (PID: 4004, MD5: AD7B9C14083B52BC532FBA5948342B98 AnalysisID: 544867 Similar Functions: 247)
    • apdsroxy.exe (PID: 3636, MD5: B6EECE7B4FD1B4BD2626AA07E17DA9DE AnalysisID: 60981 Similar Functions: 193)
    • crypmgmt.exe (PID: 3564, MD5: 3F602782259014F0253ECDEDFEF4D261 AnalysisID: 68262 Similar Functions: 178)
    • crypmgmt.exe (PID: 3784, MD5: AD22F7E25E6FCCF900B5060D4C5E9532 AnalysisID: 68439 Similar Functions: 172)
    • crypmgmt.exe (PID: 3888, MD5: 28093D270494BF7FD72450B008A4D71A AnalysisID: 68250 Similar Functions: 161)
    • crypmgmt.exe (PID: 3872, MD5: 0520E2BE92296DE286739115ACA14892 AnalysisID: 57932 Similar Functions: 158)
    • crypmgmt.exe (PID: 3816, MD5: 34C71A2B5584813A6BC94888E3669320 AnalysisID: 64003 Similar Functions: 156)
    • crypmgmt.exe (PID: 3868, MD5: E5C7B986B6FD3733504DB3FD6D6FAADA AnalysisID: 68428 Similar Functions: 156)
    • crypmgmt.exe (PID: 3520, MD5: 2977C206A36F6D0CEC371F9F767DE1D3 AnalysisID: 63005 Similar Functions: 155)
    • crypmgmt.exe (PID: 3524, MD5: C007415B17DF758F2ED04850F95EE60E AnalysisID: 64002 Similar Functions: 155)
    • crypmgmt.exe (PID: 3532, MD5: B58623B61A3D254FB9FF47FF0A4A74C6 AnalysisID: 66839 Similar Functions: 152)
    • crypmgmt.exe (PID: 3828, MD5: 479B945127CC75C2A44ED1B13482FB07 AnalysisID: 67591 Similar Functions: 151)
    • crypmgmt.exe (PID: 3752, MD5: 333EE1C0443D17DF5C79F6C4E40EA594 AnalysisID: 61981 Similar Functions: 150)
    • crypmgmt.exe (PID: 3568, MD5: F3C6625D8EDE3FE6C8C4023337D761AC AnalysisID: 66739 Similar Functions: 150)
    • crypmgmt.exe (PID: 3552, MD5: 2977C206A36F6D0CEC371F9F767DE1D3 AnalysisID: 63005 Similar Functions: 148)
    • crypmgmt.exe (PID: 3460, MD5: 9D985C429B23E924BB4D4ED98778EBBA AnalysisID: 67745 Similar Functions: 141)
    • crypmgmt.exe (PID: 3472, MD5: FA37EB66B10EB030E777AF9420FFCE9A AnalysisID: 66745 Similar Functions: 141)
    • crypmgmt.exe (PID: 4060, MD5: DA7FC1804FFFBD92337277B095147E63 AnalysisID: 64193 Similar Functions: 141)
    • crypmgmt.exe (PID: 2240, MD5: AD22F7E25E6FCCF900B5060D4C5E9532 AnalysisID: 68439 Similar Functions: 141)
    • crypmgmt.exe (PID: 2104, MD5: 3067FCCA87759E8F70DE41B4B5C179D9 AnalysisID: 63270 Similar Functions: 141)
    • crypmgmt.exe (PID: 3524, MD5: 13FFE10E12298A4E8DC1EE7A0B003B93 AnalysisID: 58680 Similar Functions: 141)
    • crypmgmt.exe (PID: 3912, MD5: 39E01E2F5A5FBFECA5ABC01131E7E3A1 AnalysisID: 63143 Similar Functions: 140)
    • crypmgmt.exe (PID: 3740, MD5: DA7FC1804FFFBD92337277B095147E63 AnalysisID: 64193 Similar Functions: 136)
    • crypmgmt.exe (PID: 3552, MD5: B91092360DF199385AC3DC6C3AA8A0E3 AnalysisID: 61691 Similar Functions: 135)
    • cmd.exe (PID: 2956, MD5: AD7B9C14083B52BC532FBA5948342B98 AnalysisID: 51932 Similar Functions: 134)
    • cmd.exe (PID: 3972, MD5: AD7B9C14083B52BC532FBA5948342B98 AnalysisID: 53359 Similar Functions: 133)
    • cmd.exe (PID: 2364, MD5: AD7B9C14083B52BC532FBA5948342B98 AnalysisID: 51301 Similar Functions: 133)
    • cmd.exe (PID: 2768, MD5: AD7B9C14083B52BC532FBA5948342B98 AnalysisID: 55548 Similar Functions: 133)
    • cmd.exe (PID: 3876, MD5: AD7B9C14083B52BC532FBA5948342B98 AnalysisID: 56191 Similar Functions: 133)

Similar Functions

  • Function_0000272A API ID: GetLastError$memcpymemset, String ID: , Total Matches: 409
  • Function_000177D7 API ID: GetLastError$memcpymemset, String ID: , Total Matches: 409
  • Function_0000272A API ID: GetLastError$memcpymemset, String ID: , Total Matches: 409
  • Function_00001175 API ID: ResumeThreadSuspendThreadWaitForSingleObjectmemset, String ID: , Total Matches: 388
  • Function_0001B212 API ID: ResumeThreadSuspendThreadWaitForSingleObjectmemset, String ID: , Total Matches: 388
  • Function_00001175 API ID: ResumeThreadSuspendThreadWaitForSingleObjectmemset, String ID: , Total Matches: 388
  • Function_00002368 API ID: CloseHandleCreateFileReadFileSetFilePointer, String ID: , Total Matches: 385
  • Function_00002368 API ID: CloseHandleCreateFileReadFileSetFilePointer, String ID: , Total Matches: 385
  • Function_000173C8 API ID: CloseHandleCreateFileReadFileSetFilePointer, String ID: , Total Matches: 385
  • Function_00003A60 API ID: CloseHandleCreateFileGetFileSizeGetLastErrorReadFile, String ID: , Total Matches: 377
  • Function_00015D18 API ID: CloseHandleCreateFileGetFileSizeGetLastErrorReadFile, String ID: , Total Matches: 377
  • Function_00003A60 API ID: CloseHandleCreateFileGetFileSizeGetLastErrorReadFile, String ID: , Total Matches: 377
  • Function_00003B0D API ID: GetLastError$CloseHandleCreateFileSetEndOfFileWriteFile, String ID: , Total Matches: 320
  • Function_00003B0D API ID: GetLastError$CloseHandleCreateFileSetEndOfFileWriteFile, String ID: , Total Matches: 320
  • Function_000012D2 API ID: ResumeThread$GetLastErrorSuspendThreadWaitForSingleObjectmemset, String ID: , Total Matches: 307
  • Function_000012D2 API ID: ResumeThread$GetLastErrorSuspendThreadWaitForSingleObjectmemset, String ID: , Total Matches: 307
  • Function_000019FB API ID: CreateEventGetCurrentProcessIdGetVersionOpenProcess, String ID: , Total Matches: 305
  • Function_000019FB API ID: CreateEventGetCurrentProcessIdGetVersionOpenProcess, String ID: , Total Matches: 305
  • Function_0000178F API ID: NtCloseNtCreateSectionRtlNtStatusToDosErrormemset, String ID: , Total Matches: 297
  • Function_0000178F API ID: NtCloseNtCreateSectionRtlNtStatusToDosErrormemset, String ID: , Total Matches: 297
  • Function_0001BC65 API ID: NtCloseNtCreateSectionRtlNtStatusToDosErrormemset, String ID: , Total Matches: 297
  • Function_0000321D API ID: RegCloseKeyRegEnumKeyExRegOpenKeyExWaitForSingleObject, String ID: , Total Matches: 294
  • Function_0000321D API ID: RegCloseKeyRegEnumKeyExRegOpenKeyExWaitForSingleObject, String ID: , Total Matches: 294
  • Function_00002DE6 API ID: NtReadVirtualMemoryRtlNtStatusToDosErrorSetLastError, String ID: , Total Matches: 238
  • Function_00002DE6 API ID: NtReadVirtualMemoryRtlNtStatusToDosErrorSetLastError, String ID: , Total Matches: 238
  • Function_00002E27 API ID: NtWriteVirtualMemoryRtlNtStatusToDosErrorSetLastError, String ID: , Total Matches: 236
  • Function_00002E27 API ID: NtWriteVirtualMemoryRtlNtStatusToDosErrorSetLastError, String ID: , Total Matches: 236
  • Function_00002880 API ID: GetLastErrorNtSetContextThreadRtlNtStatusToDosErrormemcpymemset, String ID: , Total Matches: 233
  • Function_00002880 API ID: GetLastErrorNtSetContextThreadRtlNtStatusToDosErrormemcpymemset, String ID: , Total Matches: 233
  • Function_00002E68 API ID: NtAllocateVirtualMemoryRtlNtStatusToDosErrorSetLastError, String ID: , Total Matches: 229
  • Function_00002E68 API ID: NtAllocateVirtualMemoryRtlNtStatusToDosErrorSetLastError, String ID: , Total Matches: 229
  • Function_000022C5 API ID: CloseHandleGetModuleHandleGetProcAddressIsWow64ProcessOpenProcess, String ID: , Total Matches: 223
  • Function_00017325 API ID: CloseHandleGetModuleHandleGetProcAddressIsWow64ProcessOpenProcess, String ID: , Total Matches: 223
  • Function_000022C5 API ID: CloseHandleGetModuleHandleGetProcAddressIsWow64ProcessOpenProcess, String ID: , Total Matches: 223
  • Function_00003B73 API ID: GetCurrentThreadIdGetSystemTimeAsFileTimeGetTempFileNamePathFindExtensionlstrcpy, String ID: , Total Matches: 218
  • Function_00003B73 API ID: GetCurrentThreadIdGetSystemTimeAsFileTimeGetTempFileNamePathFindExtensionlstrcpy, String ID: , Total Matches: 218
  • Function_0001792D API ID: GetLastErrorRtlNtStatusToDosErrormemcpymemset, String ID: , Total Matches: 207
  • Function_00002F3A API ID: GetTokenInformation$CloseHandleGetSidSubAuthorityGetSidSubAuthorityCountOpenProcessToken, String ID: , Total Matches: 204
  • Function_00000093 API ID: CloseHandleCreateThreadHeapCreateHeapDestroyInterlockedDecrementInterlockedIncrementSleepEx, String ID: , Total Matches: 199
  • Function_00000093 API ID: CloseHandleCreateThreadHeapCreateHeapDestroyInterlockedDecrementInterlockedIncrementSleepEx, String ID: , Total Matches: 199
  • Function_00000673 API ID: GetLastError$CreateFileCreateFileMappingGetFileSizeMapViewOfFile, String ID: , Total Matches: 194
  • Function_00000673 API ID: GetLastError$CreateFileCreateFileMappingGetFileSizeMapViewOfFile, String ID: , Total Matches: 194
  • Function_00001033 API ID: GetLastError$CloseHandleCreateMailslotHeapReAllocReadFileSleep, String ID: \\.\mailslot\msl0, Total Matches: 190
  • Function_00001034 API ID: GetLastError$CloseHandleCreateMailslotHeapReAllocReadFileSleep, String ID: \\.\mailslot\msl0, Total Matches: 190
  • Function_00001033 API ID: GetLastError$CloseHandleCreateMailslotHeapReAllocReadFileSleep, String ID: \\.\mailslot\msl0, Total Matches: 190
  • Function_00001034 API ID: GetLastError$CloseHandleCreateMailslotHeapReAllocReadFileSleep, String ID: \\.\mailslot\msl0, Total Matches: 190
  • Function_00001CD0 API ID: lstrcpy$CoInitializeExCoUninitializePathFindExtensionShellExecuteExlstrlenmemsetwsprintf, String ID: <, Total Matches: 183
  • Function_00001CD0 API ID: lstrcpy$CoInitializeExCoUninitializePathFindExtensionShellExecuteExlstrlenmemsetwsprintf, String ID: <, Total Matches: 183
  • Function_00000224 API ID: HeapFreePathFindFileNameRegCloseKeyRegOpenKeyExRegQueryValueExRtlAllocateHeapStrStrIlstrcmpilstrlen, String ID: , Total Matches: 182
  • Function_00000224 API ID: HeapFreePathFindFileNameRegCloseKeyRegOpenKeyExRegQueryValueExRtlAllocateHeapStrStrIlstrcmpilstrlen, String ID: , Total Matches: 182
  • Function_00000395 API ID: CreateProcessGetLastErrorHeapFreememset, String ID: D, Total Matches: 162
  • Function_00000186 API ID: HeapFree, String ID: Local\, Total Matches: 157
  • Function_00000186 API ID: HeapFree, String ID: Local\, Total Matches: 157
  • Function_00001427 API ID: CloseHandleGetLastError$CreateRemoteThreadOpenProcess, String ID: , Total Matches: 154
  • Function_00001427 API ID: CloseHandleGetLastError$CreateRemoteThreadOpenProcess, String ID: , Total Matches: 154
  • Function_0001C61D API ID: HeapFreeRtlEnterCriticalSectionRtlLeaveCriticalSectionSleep, String ID: , Total Matches: 151
  • Function_0001C75C API ID: HeapFreeRtlEnterCriticalSectionRtlLeaveCriticalSectionSleep, String ID: , Total Matches: 151
  • Function_00001E04 API ID: RegCloseKeyRegQueryValueExlstrcpy$CreateDirectoryHeapFreeRegOpenKey$RegCreateKeyRegDeleteValueRegOpenKeyExRtlAllocateHeapStrChrlstrcmpilstrlen, String ID: (, Total Matches: 146
  • Function_00001389 API ID: lstrlenmemset$GetProcAddressLoadLibrary, String ID: ~, Total Matches: 143
  • Function_00001389 API ID: lstrlenmemset$GetProcAddressLoadLibrary, String ID: ~, Total Matches: 143
  • EntryPoint API ID: ExitThreadGetLastErrorGetModuleHandleHeapCreate, String ID: , Total Matches: 141
  • Function_00000040 API ID: NtProtectVirtualMemory, String ID: z, Total Matches: 134
  • Function_0001AD3F API ID: memcpy$CloseHandleNtUnmapViewOfSectionRtlNtStatusToDosErrormemset, String ID: , Total Matches: 131
  • Function_00002BF0 API ID: RegCreateKeyRegOpenKeylstrlen, String ID: , Total Matches: 129
  • Function_0000364F API ID: lstrlen$RtlAllocateHeapwsprintf, String ID: , Total Matches: 128
  • Function_0000AEAE API ID: GetLastError$CloseHandleCreateNamedPipeCreateThread, String ID: , Total Matches: 120
  • Function_000034E2 API ID: GetLastError$CloseHandleReleaseMutexWaitForMultipleObjects, String ID: , Total Matches: 117
  • Function_00002F3A API ID: CloseHandleGetSidSubAuthorityGetSidSubAuthorityCountOpenProcessToken, String ID: , Total Matches: 114
  • Function_0001D2F9 API ID: lstrcpy$lstrlenmemcpy, String ID: , Total Matches: 113
  • Function_0000A978 API ID: GetLastError$CancelIoCloseHandleCreateEventGetOverlappedResultReadFileWaitForMultipleObjectsWriteFile, String ID: , Total Matches: 110
  • Function_000171E6 API ID: CreateEventGetCurrentProcessIdGetLastErrorGetVersionOpenProcess, String ID: , Total Matches: 108
  • Function_00002684 API ID: HeapFree$RtlAllocateHeap$lstrlenwsprintf, String ID: , Total Matches: 106
  • Function_00002682 API ID: HeapFree$RtlAllocateHeap$lstrlenwsprintf, String ID: , Total Matches: 106
  • Function_0000CF8E API ID: CloseHandleCreateThreadGetLastErrorHeapFree, String ID: , Total Matches: 105
  • Function_0000ACD2 API ID: CreateFileGetLastErrorWaitForSingleObjectWaitNamedPipe, String ID: , Total Matches: 99
  • Function_000167D8 API ID: VirtualProtect$GetLastErrorRtlEnterCriticalSectionRtlLeaveCriticalSection, String ID: , Total Matches: 97
  • Function_0001B371 API ID: ResumeThread$GetLastErrorSuspendThreadWaitForSingleObjectmemset, String ID: d, Total Matches: 97
  • Function_00001639 API ID: CloseHandleCreateThreadGetExitCodeThreadGetLastErrorWaitForSingleObject$TerminateThread, String ID: , Total Matches: 95
  • Function_000010FB API ID: GetLastErrorSleep$CloseHandleCreateFileWriteFilememset, String ID: \\.\mailslot\msl0, Total Matches: 95
  • Function_00001639 API ID: CloseHandleCreateThreadGetExitCodeThreadGetLastErrorWaitForSingleObject$TerminateThread, String ID: , Total Matches: 95
  • Function_000010FB API ID: GetLastErrorSleep$CloseHandleCreateFileWriteFilememset, String ID: \\.\mailslot\msl0, Total Matches: 95
  • Function_00006262 API ID: CloseHandleOpenFileMappinglstrlenmemset, String ID: , Total Matches: 95
  • Function_0001B4E7 API ID: CloseHandleGetLastError$OpenProcess, String ID: , Total Matches: 95
  • Function_0001E4FD API ID: FreeLibraryGetLastErrorlstrlenmbstowcs, String ID: , Total Matches: 92
  • Function_0001699E API ID: GetModuleHandleStrChrlstrcpylstrlen, String ID: , Total Matches: 87
  • Function_0000CCA5 API ID: HeapFreeNtUnmapViewOfSectionRtlNtStatusToDosError, String ID: , Total Matches: 86
  • Function_00002122 API ID: NtCloseNtQueryInformationToken$NtOpenProcessNtOpenProcessTokenmemcpy, String ID: , Total Matches: 84
  • Function_000189D2 API ID: NtCloseNtQueryInformationToken$NtOpenProcessNtOpenProcessTokenmemcpy, String ID: , Total Matches: 84
  • Function_00002122 API ID: NtCloseNtQueryInformationToken$NtOpenProcessNtOpenProcessTokenmemcpy, String ID: , Total Matches: 84
  • Function_0000AB92 API ID: CloseHandleGetLastError$ConnectNamedPipeCreateEventDisconnectNamedPipeFlushFileBuffersWaitForMultipleObjectsWaitForSingleObject, String ID: , Total Matches: 83
  • Function_000017F6 API ID: GetLastError$CloseHandleDuplicateHandleOpenProcessRegCloseKeyRegCreateKeyRegOpenKey, String ID: , Total Matches: 80
  • Function_00001B66 API ID: CloseHandleGetLastErrorHeapFreememset, String ID: , Total Matches: 79
  • Function_0001C885 API ID: memcpy$RtlAllocateHeaplstrlen, String ID: , Total Matches: 76
  • Function_00006341 API ID: GetLastError$CloseHandleCreateFileCreateFileMappingGetFileSizeGetTickCountHeapFreelstrcpylstrlen, String ID: Local\, Total Matches: 75
  • Function_0000D37D API ID: GetModuleHandleGetTickCountwsprintf, String ID: {%08X-%04X-%04X-%04X-%08X%04X}, Total Matches: 70
  • Function_00001884 API ID: CreateFileGetLastErrorWaitForSingleObjectlstrcat, String ID: , Total Matches: 66
  • Function_00016CFA API ID: VirtualProtect$GetLastErrorlstrcpylstrlen, String ID: , Total Matches: 65
  • Function_00002C55 API ID: HeapFreeRegCloseKeyRegQueryValueExRtlAllocateHeap, String ID: , Total Matches: 64
  • Function_0001A838 API ID: CloseHandle$LocalFreeRtlDeleteCriticalSectionRtlEnterCriticalSectionRtlLeaveCriticalSectionSetEventSleepWaitForSingleObject, String ID: , Total Matches: 62
  • Function_0000671B API ID: HeapFree$CloseHandleCreateFileRtlAllocateHeaplstrlenmbstowcs, String ID: , Total Matches: 62
  • Function_000001B3 API ID: CreateDirectoryDeleteFileGetLastErrorHeapFreeRemoveDirectory, String ID: , Total Matches: 61
  • Function_00009C3A API ID: memcpy$RtlAllocateHeapmemset$HeapFreelstrcmpi, String ID: , Total Matches: 61
  • Function_00000473 API ID: HeapFreeRtlAllocateHeapwsprintf, String ID: | "%s" | %u, Total Matches: 61
  • Function_0000A593 API ID: RtlAllocateHeaplstrlen$HeapFree_wcsuprlstrcatlstrcpymemcpy, String ID: , Total Matches: 61
  • Function_00003EEE API ID: GetCurrentThreadGetCurrentThreadIdRtlAllocateHeaplstrcmplstrlenwsprintf, String ID: , Total Matches: 61
  • Function_000010A7 API ID: HeapFree$lstrlenmemcpy$RtlAllocateHeapSwitchToThreadlstrcpy, String ID: , Total Matches: 60
  • Function_000060F5 API ID: lstrlen$GetDriveTypeHeapFreeRtlAllocateHeapWaitForSingleObjectmemset, String ID: , Total Matches: 60
  • Function_0000D0EE API ID: GetLastError$RtlEnterCriticalSectionRtlLeaveCriticalSection, String ID: , Total Matches: 60
  • Function_00002ACC API ID: HeapFreeRtlAllocateHeaplstrlen, String ID: EMPTY, Total Matches: 59
  • Function_0000A35F API ID: CreateToolhelp32SnapshotGetModuleHandleGetProcAddressOpenThreadQueueUserAPCThread32FirstThread32Next, String ID: , Total Matches: 59
  • Function_0001D3AA API ID: memcpy$GetSystemTimeAsFileTimelstrlen, String ID: , Total Matches: 59
  • Function_00000C50 API ID: HeapFree$RtlAllocateHeaplstrcat$CreateDirectoryDeleteFilelstrlenmbstowcs, String ID: %APPDATA%$%APPDATA%\Mozilla\Firefox\Profiles$\cookie.ff$\cookie.ie$\sols, Total Matches: 59
  • Function_0001A47B API ID: GetLastError$WaitForSingleObject$ReleaseMutexlstrcpynmemcpymemset, String ID: , Total Matches: 59
  • Function_00006E21 API ID: StrToIntExmemcpy, String ID: 0x, Total Matches: 59
  • Function_00008F0B API ID: HeapFreeRtlAllocateHeaplstrcpylstrcpynlstrlen, String ID: , Total Matches: 59
  • Function_00019FC4 API ID: GetLastError$VirtualAlloc$RtlEnterCriticalSectionRtlLeaveCriticalSectionSwitchToThread, String ID: , Total Matches: 59
  • Function_00006878 API ID: HeapFree$RtlAllocateHeaplstrlenwsprintf, String ID: , Total Matches: 58
  • Function_00000A08 API ID: HeapFree$GetCurrentThreadGetCurrentThreadIdRtlAllocateHeapRtlImageNtHeaderlstrlenwsprintf, String ID: W, Total Matches: 58
  • Function_00016222 API ID: mbstowcs, String ID: account{*}.oeaccount, Total Matches: 58
  • Function_00007CA3 API ID: HeapFreelstrlen$mbstowcswcstombs, String ID: , Total Matches: 58
  • Function_0000AD48 API ID: memcpy$CallNamedPipeGetLastErrorHeapFreeRtlAllocateHeaplstrlen, String ID: , Total Matches: 58
  • Function_00006D61 API ID: memcpy$RtlAllocateHeap, String ID: [URL]$https://, Total Matches: 58
  • Function_00009D95 API ID: memcpy$HeapFreeRtlAllocateHeaplstrcmpi, String ID: , Total Matches: 58
  • Function_000035F0 API ID: HeapFree$RegCloseKeyWaitForSingleObject, String ID: , Total Matches: 58
  • Function_000096B0 API ID: HeapFreeRtlAllocateHeapmemcpy, String ID: Access-Control-Allow-Origin:, Total Matches: 58
  • Function_000067DE API ID: HeapFreeRtlAllocateHeap, String ID: cmd /C "%s> %s1", Total Matches: 58
  • Function_0001D1CF API ID: GetComputerNameHeapFreeRtlAllocateHeap, String ID: Client, Total Matches: 57
  • Function_0001C36B API ID: SetLastErrorSleepWaitForSingleObjectmemset, String ID: vids, Total Matches: 57
  • Function_00006B90 API ID: GetSystemTimeAsFileTimeHeapFreeRtlAllocateHeaplstrlenmemcpy, String ID: , Total Matches: 57
  • Function_00001554 API ID: GetSystemTimeAsFileTimeRtlAllocateHeaplstrcpylstrlen, String ID: , Total Matches: 57
  • Function_00015DF6 API ID: GetLastError$CloseHandleSetEndOfFileSetFilePointerWaitForSingleObjectWriteFile, String ID: , Total Matches: 57
  • Function_00003E59 API ID: RtlAllocateHeaplstrcpylstrlenmemcpy, String ID: , Total Matches: 57
  • Function_000069A7 API ID: HeapFree$DeleteFileStrTrimlstrlen, String ID: ss: *.*.*.*, Total Matches: 56
  • Function_00005241 API ID: GetModuleHandleTlsAlloc, String ID: CHROME.DLL, Total Matches: 56
  • Function_000162AD API ID: DeleteFileFindFirstFileFindNextFileGetLastErrorRemoveDirectory, String ID: , Total Matches: 56
  • Function_00007B4E API ID: HeapFreememcpy$RtlAllocateHeap, String ID: , Total Matches: 56
  • Function_0000339B API ID: CreateWaitableTimerGetLastErrorGetSystemTimeAsFileTimeHeapFreeOpenWaitableTimer, String ID: , Total Matches: 56
  • Function_0000748E API ID: GetLastError$HeapFreeRtlAllocateHeapWaitForSingleObject, String ID: , Total Matches: 56
  • Function_00006E94 API ID: HeapFreememcpymemset, String ID: chun, Total Matches: 56
  • Function_00018EAA API ID: lstrlen$RtlAllocateHeap, String ID: [FILE]$DllRegisterServer, Total Matches: 56
  • Function_0001A703 API ID: CreateEventCreateMutexCreateThreadGetLastErrorRtlInitializeCriticalSectionmemcpymemset, String ID: , Total Matches: 56
  • Function_00015F2E API ID: FindFirstFile$FindCloseFindNextFileWaitForSingleObjectmemset, String ID: , Total Matches: 56
  • Function_000018FD API ID: RegCloseKeyRegOpenKeylstrcmpilstrlen, String ID: , Total Matches: 55
  • Function_0000CB50 API ID: HeapFree$RtlImageNtHeaderStrChrStrTrimlstrlen, String ID: , Total Matches: 55
  • Function_0000B42B API ID: HeapFreelstrlenmemcpy, String ID: Access-Control-Allow-Origin:, Total Matches: 55
  • Function_0000738C API ID: HeapFreeRtlAllocateHeap, String ID: https://, Total Matches: 54
  • Function_00018BD6 API ID: FindNextFileHeapFree$CloseHandleCompareFileTimeCreateFileGetFileTimeStrChrStrRChrlstrcatmemcpymemset, String ID: [FILE]$}nls, Total Matches: 54
  • Function_0000CCEC API ID: GetCurrentThreadGetCurrentThreadIdRtlAllocateHeapRtlEnterCriticalSectionRtlLeaveCriticalSectionSleepmemset, String ID: , Total Matches: 54
  • Function_00008D54 API ID: HeapFree$RegCloseKeyRegCreateKey, String ID: , Total Matches: 54
  • Function_00003202 API ID: HeapFreeRegCloseKeyRegOpenKeyRtlAllocateHeap, String ID: Main, Total Matches: 53
  • Function_000164F7 API ID: CreateDirectoryGetTempFileNameGetTickCount, String ID: \Low, Total Matches: 53
  • Function_00018692 API ID: StrTrim$_struprlstrlenmemcpymemset, String ID: , Total Matches: 53
  • Function_0000078D API ID: CloseHandleRegCloseKey$CreateEventDeleteFileGetLastErrorRegOpenKeyResumeThreadSetEventSleepSuspendThread, String ID: , Total Matches: 53
  • Function_00009895 API ID: RtlAllocateHeaplstrcpy, String ID: http, Total Matches: 52
  • Function_0000BB46 API ID: HeapFreeRtlAllocateHeaplstrlen$StrChrmemcpy$lstrcpynmemmove, String ID: GET $GET $OPTI$OPTI$POST$PUT , Total Matches: 52
  • Function_00002996 API ID: CreateFileGetLastErrorHeapFreeRegCloseKeyRegOpenKey, String ID: [FILE]$[FILE], Total Matches: 51
  • Function_00001B25 API ID: GetLastError$CloseHandleFlushFileBuffersSetEndOfFile, String ID: , Total Matches: 51
  • Function_00001416 API ID: CloseHandleCreateThreadGetLastErrorHeapFreeRtlAllocateHeaplstrcpylstrlen, String ID: , Total Matches: 50
  • Function_0000973F API ID: HeapFreeRegCloseKeyRegCreateKeyRtlAllocateHeapwsprintf, String ID: , Total Matches: 50
  • Function_0000064D API ID: GetTickCountHeapFreeRegCloseKeyRegCreateKeyRtlAllocateHeapRtlImageNtHeaderStrRChrlstrlenwsprintf, String ID: , Total Matches: 49
  • Function_00008BEF API ID: memcpy$HeapFreeRtlAllocateHeapRtlReAllocateHeap, String ID: W, Total Matches: 48
  • Function_0000A4E6 API ID: RtlEnterCriticalSectionRtlLeaveCriticalSectionSetEventSleep, String ID: , Total Matches: 46
  • Function_000019BF API ID: CreateDirectoryHeapFreeRtlAllocateHeaplstrlen, String ID: %APPDATA%\Microsoft\, Total Matches: 45
  • Function_00004816 API ID: HeapFreeRtlEnterCriticalSectionRtlLeaveCriticalSectionSleeplstrcpylstrlenmemcpy, String ID: , Total Matches: 43
  • Function_00001A39 API ID: HeapFree$CloseHandleRtlImageNtHeader, String ID: [FILE]$[FILE], Total Matches: 43
  • Function_00016471 API ID: GetCurrentThreadIdGetSystemTimeAsFileTimeGetTempFileNamelstrcpy, String ID: , Total Matches: 43
  • Function_00000586 API ID: GetLastError$CloseHandleCreateFileGetModuleHandleGetWindowsDirectoryHeapFreeRtlAllocateHeapStrChrWriteFilewsprintf, String ID: , Total Matches: 43
  • Function_00006664 API ID: HeapFree$GetLastErrorRtlAllocateHeap, String ID: , Total Matches: 40
  • Function_00009F14 API ID: HeapFreeInterlockedExchangeRtlAllocateHeapmemcpywsprintf, String ID: , Total Matches: 40
  • Function_00000CB2 API ID: memcpy$CloseHandleNtUnmapViewOfSectionRtlNtStatusToDosErrormemset, String ID: pnls, Total Matches: 38
  • Function_00002D4D API ID: RegCloseKeyRegQueryValueExwsprintf, String ID: Client, Total Matches: 38
  • Function_00000CB2 API ID: memcpy$CloseHandleNtUnmapViewOfSectionRtlNtStatusToDosErrormemset, String ID: pnls, Total Matches: 38
  • Function_000037EC API ID: HeapFreememcpy, String ID: ($Client, Total Matches: 38
  • Function_0001E422 API ID: GetLastError$FreeLibraryGetProcAddressLoadLibraryRegCloseKeyRegOpenKey, String ID: , Total Matches: 37
  • Function_0001D6E9 API ID: GetLastErrorGetVersion, String ID: GET$POST, Total Matches: 37
  • Function_00002F95 API ID: HeapFree$RtlAllocateHeaplstrcmpi, String ID: Main, Total Matches: 37
  • Function_0000CA13 API ID: CreateEventGetLastErrorRtlAddVectoredExceptionHandlerRtlRemoveVectoredExceptionHandlerStrRChr_struprlstrlen, String ID: , Total Matches: 36
  • Function_00015996 API ID: FlushFileBuffersGetLastErrormemset, String ID: K$P, Total Matches: 35
  • Function_00000E86 API ID: HeapFreeInterlockedExchangeRtlAllocateHeaplstrcpy, String ID: , Total Matches: 34
  • Function_0000332F API ID: FindNextFileHeapFree$CloseHandleCompareFileTimeCreateFileFindFirstFileGetFileTimeStrChrStrRChrlstrcatmemcpy, String ID: pnls$}nls, Total Matches: 33
  • Function_0000332F API ID: FindNextFileHeapFree$CloseHandleCompareFileTimeCreateFileFindFirstFileGetFileTimeStrChrStrRChrlstrcatmemcpy, String ID: pnls$}nls, Total Matches: 33
  • Function_00003CEB API ID: lstrlen$CloseHandleDeleteFileHeapFreeMapViewOfFileRtlAllocateHeapUnmapViewOfFilewcstombs, String ID: , Total Matches: 33
  • Function_0000C171 API ID: CreateEventGetLastErrorInterlockedDecrementOpenEventRtlExitUserThreadWaitForMultipleObjects, String ID: , Total Matches: 31
  • Function_00000B85 API ID: CreateDirectory$CopyFileHeapFreeRtlAllocateHeaplstrcpy, String ID: \sols, Total Matches: 31
  • Function_000004CA API ID: FindWindowGetModuleHandleGetWindowThreadProcessIdLoadLibrary, String ID: USER32.DLL$pnls$pnls, Total Matches: 29
  • Function_000004CA API ID: FindWindowGetModuleHandleGetWindowThreadProcessIdLoadLibrary, String ID: USER32.DLL$pnls$pnls, Total Matches: 29
  • Function_00005604 API ID: HeapFreeRegisterWaitForSingleObjectRtlAllocateHeapmemcpy, String ID: , Total Matches: 29
  • Function_000049D7 API ID: GetSystemTimeAsFileTimeInterlockedIncrementRtlAllocateHeapRtlEnterCriticalSectionRtlLeaveCriticalSection, String ID: , Total Matches: 27
  • Function_00004C23 API ID: lstrcmpi$GetSystemTimeAsFileTimeRtlEnterCriticalSectionRtlLeaveCriticalSection, String ID: Main, Total Matches: 27
  • Function_000041AB API ID: _allmul$ReleaseMutex$SwitchToThreadWaitForMultipleObjects$CreateEventGetVersionExHeapFreeRtlAllocateHeapWaitForSingleObjectwsprintf, String ID: Main, Total Matches: 26
  • Function_0000A410 API ID: CloseHandleCreateThreadGetCommandLineGetLastErrorGetModuleHandle, String ID: , Total Matches: 26
  • Function_00004B7B API ID: HeapFreeRtlAllocateHeapRtlEnterCriticalSectionRtlLeaveCriticalSectionmemcpy, String ID: , Total Matches: 25
  • Function_00000F61 API ID: HeapFree$DeleteFileGetLastErrorInterlockedDecrementInterlockedIncrementlstrcpy, String ID: , Total Matches: 25
  • Function_0001E75B API ID: LocalFreelstrcatlstrcpymemcpy, String ID: IMAP$P$POP3$SMTP, Total Matches: 23
  • Function_000003D6 API ID: CloseHandleHeapDestroySetEvent, String ID: , Total Matches: 21
  • Function_00000395 API ID: GetLastErrorHeapFreememset, String ID: D, Total Matches: 21
  • Function_00005C08 API ID: RegCloseKeyRegOpenKeySetEventWaitForSingleObject, String ID: %APPDATA%\Mozilla\Firefox\Profiles, Total Matches: 19
  • Function_00002C8B API ID: GetModuleFileName$GetLastError, String ID: , Total Matches: 12
  • Function_0000044C API ID: HeapFreeStrStrI, String ID: pnls, Total Matches: 9
  • Function_00006422 API ID: CreateProcessGetExitCodeProcessGetLastErrorWaitForMultipleObjectslstrlenmemsetwcstombs, String ID: D$cmd /C "%s> %s1", Total Matches: 8
  • Function_00016A61 API ID: VirtualProtect$GetLastErrorRtlEnterCriticalSectionRtlLeaveCriticalSection, String ID: , Total Matches: 6
  • Function_00003003 API ID: VirtualAllocVirtualFreelstrcpynmemcpy, String ID: Apr 14 2018$pnls$pnls, Total Matches: 5
  • Function_00003003 API ID: VirtualAllocVirtualFreelstrcpynmemcpy, String ID: Apr 14 2018$pnls$pnls, Total Matches: 5
  • Function_000016C0 API ID: HeapFreeRtlAllocateHeaplstrcpylstrlen, String ID: W, Total Matches: 4
  • Function_0000C890 API ID: HeapFreeLocalFreeReleaseMutexRtlRemoveVectoredExceptionHandlerSleepEx, String ID: , Total Matches: 3
  • Function_00000535 API ID: RtlFreeAnsiStringRtlUpcaseUnicodeString, String ID: pnls, Total Matches: 2
  • Function_00000535 API ID: RtlFreeAnsiStringRtlUpcaseUnicodeString, String ID: pnls, Total Matches: 2
  • Function_00000000 API ID: HeapFree$CloseHandleCreateFileRtlAllocateHeapWriteFilelstrcpy, String ID: qwerty, Total Matches: 1
  • Function_0001D8D2 API ID: GetLastErrorlstrlenwsprintf, String ID: `, Total Matches: 1
  • Function_0001CB79 API ID: HeapFree$GetTickCountRtlAllocateHeap$QueryPerformanceCounterQueryPerformanceFrequencyRtlEnterCriticalSectionRtlLeaveCriticalSectionStrTrim_aulldivlstrcpy, String ID: , Total Matches: 1
  • Function_0000C519 API ID: GetLastErrorRtlAllocateHeap$CloseHandle$CreateMutexLoadLibraryNtQueryInformationProcessOpenProcessmemsetwsprintf, String ID: , Total Matches: 1
  • Function_0001CE6F API ID: HeapFree$lstrcat$RtlAllocateHeap$StrTrimlstrcpy, String ID: , Total Matches: 1
  • Function_0000A7D1 API ID: RtlAllocateHeap$GetLastErrorRtlInitializeCriticalSection, String ID: , Total Matches: 1