Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
webex.exe

Overview

General Information

Sample name:webex.exe
Analysis ID:1447090
MD5:253d21dbe18ed326858237394b988416
SHA1:77a49051e8869eceb9a7babb8908d4177cf26a16
SHA256:c4a6bf1fabb7eec2f96b59691d28812f798974a7f8ebcf8fd314135e2eb55a4b
Infos:

Detection

Score:39
Range:0 - 100
Whitelisted:false
Confidence:0%

Compliance

Score:33
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Self deletion via cmd or bat file
Adds / modifies Windows certificates
Binary contains a suspicious time stamp
Checks for available system drives (often done to infect USB drives)
Contains capabilities to detect virtual machines
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Creates a DirectInput object (often for capturing keystrokes)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Deletes files inside the Windows folder
Detected potential crypto function
Drops PE files
Drops PE files to the windows directory (C:\Windows)
EXE planting / hijacking vulnerabilities found
Enables debug privileges
Extensive use of GetProcAddress (often used to hide API calls)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains executable resources (Code or Archives)
PE file contains more sections than normal
PE file contains sections with non-standard names
PE file does not import any functions
Potential key logger detected (key state polling based)
Queries the volume information (name, serial number etc) of a device
Queries time zone information
Sample file is different than original file name gathered from version info
Stores files to the Windows start menu directory
Stores large binary data to the registry
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Uses taskkill to terminate processes
Uses the keyboard layout for branch decision (may execute only for specific keyboard layouts)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

  • System is w10x64
  • webex.exe (PID: 7256 cmdline: "C:\Users\user\Desktop\webex.exe" MD5: 253D21DBE18ED326858237394B988416)
    • msiexec.exe (PID: 7444 cmdline: msiexec.exe /i "C:\Users\user\AppData\Local\Temp\c64e3759-805b-47c0-b4ab-a6ec7fecd393.msi" /quiet /norestart AUTOSTART_WITH_WINDOWS=false MD5: 9D09DC1EDA745A5F87553048E57620CF)
    • cmd.exe (PID: 5296 cmdline: cmd.exe /c timeout /NOBREAK /T 3 > nul & del /f /q "C:\Users\user\Desktop\webex.exe" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • conhost.exe (PID: 7528 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • timeout.exe (PID: 2300 cmdline: timeout /NOBREAK /T 3 MD5: 976566BEEFCCA4A159ECBDB2D4B1A3E3)
    • CiscoCollabHost.exe (PID: 1448 cmdline: "C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exe" /protocolUri="webex://meet/?bt=12&bv=121&cr=065f9a40-5723-45ab-9507-cf2766bb45fe&dns=appleinc.webex.com&en=3&flag=17&jointxid=x7Pbq0RE2n&jt=eyJkdDAiOjE3MTY1NDg2NDIsImR0MSI6Nzk4LCJkdDIiOjIxODUsImR0MyI6MzUzNSwiZHQ0IjoyNDEyODMsImR0NSI6MzcxODI4NTUxLCJkdDYiOjE3MTY5MjA3MjEsImZ0IjoxLCJ0IjoyNSwidXAiOjF9&mtid=m547a808dce8d2d3d893e20fa794cb8a1&od=6f783f73-9637-4b83-90b9-434a5fccb49d&rc=4&sip=24877802128@appleinc.webex.com&siteurl=appleinc&tr=7A2D3FEB1EC64A498D4F669177387376_1709540815837&uuid=04485f8191de4a7c891a7dfe933370dc&vp=0" MD5: 309513CE428B34A3FE286DBD4E56539B)
      • CiscoCollabHost.exe (PID: 2344 cmdline: "C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe" "C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1" spark-windows-app.dll /Hosted=true "C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exe" /protocolUri="webex://meet/?bt=12&bv=121&cr=065f9a40-5723-45ab-9507-cf2766bb45fe&dns=appleinc.webex.com&en=3&flag=17&jointxid=x7Pbq0RE2n&jt=eyJkdDAiOjE3MTY1NDg2NDIsImR0MSI6Nzk4LCJkdDIiOjIxODUsImR0MyI6MzUzNSwiZHQ0IjoyNDEyODMsImR0NSI6MzcxODI4NTUxLCJkdDYiOjE3MTY5MjA3MjEsImZ0IjoxLCJ0IjoyNSwidXAiOjF9&mtid=m547a808dce8d2d3d893e20fa794cb8a1&od=6f783f73-9637-4b83-90b9-434a5fccb49d&rc=4&sip=24877802128@appleinc.webex.com&siteurl=appleinc&tr=7A2D3FEB1EC64A498D4F669177387376_1709540815837&uuid=04485f8191de4a7c891a7dfe933370dc&vp=0" MD5: 309513CE428B34A3FE286DBD4E56539B)
  • msiexec.exe (PID: 7476 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 7592 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding 305732C6DAD0EE72C0E34B949704E1E8 MD5: 9D09DC1EDA745A5F87553048E57620CF)
      • taskkill.exe (PID: 7652 cmdline: "C:\Windows\system32\\taskkill.exe" /F /IM CiscoCollabHost.exe /T MD5: CA313FD7E6C2A778FFD21CFB5C1C56CD)
        • conhost.exe (PID: 7664 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • msiexec.exe (PID: 7804 cmdline: C:\Windows\System32\MsiExec.exe -Embedding 80617056B0CA03034534C28A67086463 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: webex.exeAvira: detected
Source: C:\Users\user\Desktop\webex.exeEXE: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\webexhost.exeJump to behavior
Source: C:\Users\user\Desktop\webex.exeEXE: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\wmlhost.exeJump to behavior
Source: C:\Users\user\Desktop\webex.exeEXE: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\teamsdcvagent.exeJump to behavior
Source: C:\Users\user\Desktop\webex.exeEXE: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\washost.exeJump to behavior
Source: C:\Users\user\Desktop\webex.exeEXE: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\CiscoWebExStart.exeJump to behavior
Source: C:\Users\user\Desktop\webex.exeEXE: msiexec.exeJump to behavior
Source: C:\Users\user\Desktop\webex.exeEXE: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\x86\CiscoCollabHost.exeJump to behavior
Source: C:\Users\user\Desktop\webex.exeEXE: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\CiscoLocalRecordConverter.exeJump to behavior
Source: C:\Windows\System32\msiexec.exeEXE: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exeJump to behavior
Source: C:\Users\user\Desktop\webex.exeEXE: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\teamshvdagent.exeJump to behavior
Source: C:\Users\user\Desktop\webex.exeEXE: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\CiscoCollabHost.exeJump to behavior
Source: C:\Users\user\Desktop\webex.exeEXE: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeJump to behavior
Source: C:\Users\user\Desktop\webex.exeEXE: cmd.exeJump to behavior

Compliance

barindex
Source: C:\Users\user\Desktop\webex.exeEXE: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\webexhost.exeJump to behavior
Source: C:\Users\user\Desktop\webex.exeEXE: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\wmlhost.exeJump to behavior
Source: C:\Users\user\Desktop\webex.exeEXE: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\teamsdcvagent.exeJump to behavior
Source: C:\Users\user\Desktop\webex.exeEXE: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\washost.exeJump to behavior
Source: C:\Users\user\Desktop\webex.exeEXE: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\CiscoWebExStart.exeJump to behavior
Source: C:\Users\user\Desktop\webex.exeEXE: msiexec.exeJump to behavior
Source: C:\Users\user\Desktop\webex.exeEXE: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\x86\CiscoCollabHost.exeJump to behavior
Source: C:\Users\user\Desktop\webex.exeEXE: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\CiscoLocalRecordConverter.exeJump to behavior
Source: C:\Windows\System32\msiexec.exeEXE: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exeJump to behavior
Source: C:\Users\user\Desktop\webex.exeEXE: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\teamshvdagent.exeJump to behavior
Source: C:\Users\user\Desktop\webex.exeEXE: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\CiscoCollabHost.exeJump to behavior
Source: C:\Users\user\Desktop\webex.exeEXE: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeJump to behavior
Source: C:\Users\user\Desktop\webex.exeEXE: cmd.exeJump to behavior
Source: webex.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: C:\Windows\System32\msiexec.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4A82B9CC-F7B3-5000-9CA4-89764C5A9DA4}Jump to behavior
Source: webex.exeStatic PE information: certificate valid
Source: webex.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: J:\qt_build\workspace\qt_build\qtbase\lib\libGLESv2.pdb source: CiscoCollabHost.exe, 00000013.00000002.3556069538.00007FFDE64E9000.00000002.00000001.01000000.0000004B.sdmp
Source: Binary string: E:\VSExclude\Jenkins_Workspace\wme-release\wme\mediaengine\maps\x64\Release\wmeclient.pdbyy GCTL source: CiscoCollabHost.exe, 00000013.00000002.3563229356.00007FFDE8847000.00000002.00000001.01000000.0000003C.sdmp
Source: Binary string: J:\qt_build\workspace\qt_build\qtbase\plugins\platforms\qwindows.pdb source: CiscoCollabHost.exe, 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmp
Source: Binary string: E:\VSExclude\Jenkins_Workspace\wme-release\wme\mediaengine\maps\x64\Release\wmeclient.pdb source: CiscoCollabHost.exe, 00000013.00000002.3563229356.00007FFDE8847000.00000002.00000001.01000000.0000003C.sdmp
Source: Binary string: E:\VSExclude\Jenkins_Workspace\wme-release\wme\mediaengine\maps\x64\Release\wseclient.pdb source: CiscoCollabHost.exe, 00000013.00000002.3563909544.00007FFDE8C54000.00000002.00000001.01000000.00000037.sdmp
Source: Binary string: E:\VSExclude\Jenkins_Workspace\wme-release\wme\vendor\video_process\bin\windows\x86_64\Release\videoprocess.pdb source: CiscoCollabHost.exe, 00000013.00000002.3562293246.00007FFDE85F7000.00000002.00000001.01000000.0000003E.sdmp
Source: Binary string: J:\TeamsVDI\out\hvdsdk\release\bin\VxcCommunication.dll.pdb source: CiscoCollabHost.exe, 00000013.00000002.3557154248.00007FFDE6863000.00000002.00000001.01000000.00000047.sdmp
Source: Binary string: E:\VSExclude\Jenkins_Workspace\wme-release\wme\mediaengine\maps\x64\Release\wbxaudioengine.pdb source: CiscoCollabHost.exe, 00000013.00000002.3558824995.00007FFDE70C6000.00000002.00000001.01000000.00000043.sdmp
Source: Binary string: E:\VSExclude\Jenkins_Workspace\wme-release\wme\mediaengine\maps\x64\Release\wrtp.pdb source: CiscoCollabHost.exe, 00000013.00000002.3560651202.00007FFDE8109000.00000002.00000001.01000000.00000040.sdmp
Source: Binary string: E:\VSExclude\Jenkins_Workspace\wme-release\wme\mediaengine\maps\x64\Release\wbxaudioengine.pdbi source: CiscoCollabHost.exe, 00000013.00000002.3558824995.00007FFDE70C6000.00000002.00000001.01000000.00000043.sdmp
Source: Binary string: J:\TeamsVDI\out\hvdsdk\release\bin\VxcCommunication.dll.pdb``# source: CiscoCollabHost.exe, 00000013.00000002.3557154248.00007FFDE6863000.00000002.00000001.01000000.00000047.sdmp
Source: Binary string: J:\TeamsVDI\out\hvdsdk\release\bin\VDIFramework.dll.pdb source: CiscoCollabHost.exe, 00000013.00000002.3557908733.00007FFDE6B9E000.00000002.00000001.01000000.00000045.sdmp
Source: Binary string: J:\TeamsVDI\out\hvdsdk\release\bin\VDIFramework.dll.pdbmm$ source: CiscoCollabHost.exe, 00000013.00000002.3557908733.00007FFDE6B9E000.00000002.00000001.01000000.00000045.sdmp
Source: Binary string: J:\qt_build\workspace\qt_build\qtbase\lib\libGLESv2.pdb4 source: CiscoCollabHost.exe, 00000013.00000002.3556069538.00007FFDE64E9000.00000002.00000001.01000000.0000004B.sdmp
Source: Binary string: CiscoCollabHost.pdb source: CiscoCollabHost.exe, 00000012.00000002.3326490032.00007FF7EC6B3000.00000002.00000001.01000000.00000008.sdmp, CiscoCollabHost.exe, 00000012.00000000.3322197488.00007FF7EC6B3000.00000002.00000001.01000000.00000008.sdmp, CiscoCollabHost.exe, 00000013.00000000.3323639313.00007FF6F8013000.00000002.00000001.01000000.0000000A.sdmp, CiscoCollabHost.exe, 00000013.00000002.3555496022.00007FF6F8013000.00000002.00000001.01000000.0000000A.sdmp
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://angularjs.org
Source: webex.exe, 00000000.00000003.1713521252.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713706381.0000000003354000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713249908.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713571138.0000000003357000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713631047.000000000335B000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C73000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C80000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713521252.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713706381.0000000003354000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713249908.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713571138.0000000003357000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713631047.000000000335B000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C73000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C80000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000003.3339395518.000001EFB0EA4000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000003.3340180113.000001EFB0EEC000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3549445254.000001EFB0EBA000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000003.3339530361.000001EFB0DCD000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000003.3339802143.000001EFB0EB5000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000003.3338203628.000001EFB0EA4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.net/root-r2.crl0
Source: CiscoCollabHost.exe, 00000013.00000002.3549445254.000001EFB0EBA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.micro
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.securetrust.com/SGCA.crl0
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.securetrust.com/STCA.crl0
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.xrampsecurity.com/XGCA.crl0
Source: webex.exe, 00000000.00000003.1713521252.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713706381.0000000003354000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713249908.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713571138.0000000003357000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713631047.000000000335B000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C73000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C80000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713521252.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713706381.0000000003354000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713249908.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713571138.0000000003357000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713631047.000000000335B000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C73000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C80000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000003.3339395518.000001EFB0EA4000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000003.3340180113.000001EFB0EEC000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3549445254.000001EFB0EBA000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000003.3339530361.000001EFB0DCD000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000003.3339802143.000001EFB0EB5000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000003.3338203628.000001EFB0EA4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
Source: webex.exe, 00000000.00000003.1713521252.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713706381.0000000003354000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713249908.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713571138.0000000003357000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713631047.000000000335B000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C73000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C80000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://link.com
Source: webex.exe, 00000000.00000003.1713521252.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713706381.0000000003354000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713249908.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713571138.0000000003357000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713631047.000000000335B000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C73000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C80000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713521252.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713706381.0000000003354000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713249908.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713571138.0000000003357000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713631047.000000000335B000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C73000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C80000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000003.3339395518.000001EFB0EA4000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000003.3340180113.000001EFB0EEC000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3549445254.000001EFB0EBA000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000003.3339530361.000001EFB0DCD000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000003.3339802143.000001EFB0EB5000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000003.3338203628.000001EFB0EA4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0A
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://policy.camerfirma.com0
Source: CiscoCollabHost.exe, 00000013.00000002.3560651202.00007FFDE8109000.00000002.00000001.01000000.00000040.sdmpString found in binary or memory: http://protocols.cisco.com/av1
Source: CiscoCollabHost.exe, 00000013.00000002.3560651202.00007FFDE8109000.00000002.00000001.01000000.00000040.sdmpString found in binary or memory: http://protocols.cisco.com/framemarking
Source: CiscoCollabHost.exe, 00000013.00000002.3560651202.00007FFDE8109000.00000002.00000001.01000000.00000040.sdmpString found in binary or memory: http://protocols.cisco.com/namedmediagroup
Source: CiscoCollabHost.exe, 00000013.00000002.3560651202.00007FFDE8109000.00000002.00000001.01000000.00000040.sdmpString found in binary or memory: http://protocols.cisco.com/namedmediagrouplist
Source: CiscoCollabHost.exe, 00000013.00000002.3560651202.00007FFDE8109000.00000002.00000001.01000000.00000040.sdmpString found in binary or memory: http://protocols.cisco.com/priority
Source: CiscoCollabHost.exe, 00000013.00000002.3539279947.000001EFAF190000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3560651202.00007FFDE8109000.00000002.00000001.01000000.00000040.sdmpString found in binary or memory: http://protocols.cisco.com/timestamp#100us
Source: CiscoCollabHost.exe, 00000013.00000002.3539279947.000001EFAF190000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://protocols.cisco.com/timestamp#100usn
Source: CiscoCollabHost.exe, 00000013.00000002.3539279947.000001EFAF190000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3560651202.00007FFDE8109000.00000002.00000001.01000000.00000040.sdmpString found in binary or memory: http://protocols.cisco.com/virtualid
Source: CiscoCollabHost.exe, 00000013.00000002.3560651202.00007FFDE8109000.00000002.00000001.01000000.00000040.sdmpString found in binary or memory: http://protocols.cisco.com/virtualidhttp://protocols.cisco.com/framemarkingurn:ietf:params:rtp-hdrex
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://repository.swisssign.com/0
Source: webex.exe, 00000000.00000003.1713521252.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713612449.0000000003349000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713706381.0000000003354000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713249908.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713571138.0000000003357000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713631047.000000000335B000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C73000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C80000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://s.symcb.com/universal-root.crl0
Source: webex.exe, 00000000.00000003.1713521252.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713612449.0000000003349000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713706381.0000000003354000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713249908.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713571138.0000000003357000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713631047.000000000335B000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C73000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C80000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://s.symcd.com06
Source: webex.exe, 00000000.00000003.1713521252.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713612449.0000000003349000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713706381.0000000003354000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713249908.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713571138.0000000003357000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713631047.000000000335B000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C73000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C80000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
Source: webex.exe, 00000000.00000003.1713521252.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713612449.0000000003349000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713706381.0000000003354000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713249908.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713571138.0000000003357000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713631047.000000000335B000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C73000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C80000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
Source: webex.exe, 00000000.00000003.1713521252.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713612449.0000000003349000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713706381.0000000003354000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713249908.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713571138.0000000003357000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713631047.000000000335B000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C73000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C80000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ts-ocsp.ws.symantec.com0;
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.cert.fnmt.es/dpcs/0
Source: CiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB0860000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.cisco.com/c/en/us/about/legal/privacy.html
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3541683541.000001EFAFA16000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.cisco.com/security/pki/certs/crcam1.cer0
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3541683541.000001EFAFA16000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.cisco.com/security/pki/crl/crcam1.crl0N
Source: webex.exe, 00000000.00000003.1713521252.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713706381.0000000003354000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713249908.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713571138.0000000003357000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713631047.000000000335B000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C73000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C80000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.digicert.com/CPS0
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.firmaprofesional.com/cps0
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.gnu.org/licenses/gpl-2.0.html.
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.html-tidy.org
Source: CiscoCollabHost.exe, 00000013.00000002.3543772157.000001EFB01DE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/Microsoft
Source: CiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.msftncsi.com/ncsi.txt
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.qt-project.org/legal
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.qt.io/contact-us.
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.qt.io/licensing/
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.qt.io/terms-conditions.
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.quovadisglobal.com/cps0
Source: CiscoCollabHost.exe, 00000013.00000002.3549659031.000001EFB0F2C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.tiro.comMicrosoft
Source: CiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB08E8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.urwpp.deNormalNormaaliNormalNorm
Source: CiscoCollabHost.exe, 00000013.00000002.3539279947.000001EFAF190000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3560651202.00007FFDE8109000.00000002.00000001.01000000.00000040.sdmpString found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/abs-capture-time
Source: CiscoCollabHost.exe, 00000013.00000002.3539279947.000001EFAF190000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/abs-capture-timeI
Source: CiscoCollabHost.exe, 00000013.00000002.3560651202.00007FFDE8109000.00000002.00000001.01000000.00000040.sdmpString found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/abs-capture-timehttp://protocols.cisco.com/namedmediagr
Source: CiscoCollabHost.exe, 00000013.00000002.3551254415.000001EFB395A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.zhongyicts.com.cn
Source: CiscoCollabHost.exe, 00000013.00000002.3540066323.000001EFAF5F5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://accounts.snap.com
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://alpha.webex.com/alpha-sc/j.php?MTID=m2a40b18df319615a16fefa5d8d4df1eb
Source: CiscoCollabHost.exe, 00000013.00000002.3548188494.000001EFB097E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://appleinc.webex.com
Source: CiscoCollabHost.exe, 00000013.00000002.3548188494.000001EFB097E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://appleinc.webex.com.
Source: CiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB0842000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3545166079.000001EFB07B0000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3538642634.000001EFACE59000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://appleinc.webex.com/
Source: CiscoCollabHost.exe, 00000013.00000002.3548188494.000001EFB097E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://appleinc.webex.comv
Source: CiscoCollabHost.exe, 00000013.00000002.3544628106.000001EFB04C0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://atlas-api-a.wbx2.com/admin/api/v1
Source: CiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB087F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.c
Source: webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB0842000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3545166079.000001EFB07B0000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3544235755.000001EFB038E000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB0860000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/.
Source: CiscoCollabHost.exe, 00000013.00000002.3545166079.000001EFB07B0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/B
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/C
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/FranciscE
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/JL
Source: CiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB0860000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/LOCALAPP
Source: CiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB0860000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/PowerShe
Source: CiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB087F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/V$q
Source: webex.exe, 00000000.00000003.1706246150.00000000013E0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/Webex
Source: CiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20221110032238/WebexVDIPlugin.7z
Source: CiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20221110032238/WebexVDIPlugin_x86.7z
Source: CiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20221207133244/WebexVDIPlugin.7z
Source: CiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20221207133244/WebexVDIPlugin_x86.7z
Source: CiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20230216133805/WebexVDIPlugin.7z
Source: CiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20230216133805/WebexVDIPlugin_x86.7z
Source: CiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20230421085439/WebexVDIPlugin.7z
Source: CiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20230421085439/WebexVDIPlugin_x86.7z
Source: CiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20231018100743/WebexVDIPlugin.7z
Source: CiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20231018100743/WebexVDIPlugin_x86.7z
Source: CiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20231211114034/WebexVDIPlugin.7z
Source: CiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20231211114034/WebexVDIPlugin_x86.7z
Source: CiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20240219145217/WebexVDIPlugin.7z
Source: CiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20240219145217/WebexVDIPlugin_x86.7z
Source: CiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-VDI-Win-64-Gold/20230713030330/WebexVDIPlugin.7z
Source: CiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-VDI-Win-64-Gold/20230713030330/WebexVDIPlugin_x86.7z
Source: CiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-VDI-Win-64-Gold/20230906100245/WebexVDIPlugin.7z
Source: CiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-VDI-Win-64-Gold/20230906100245/WebexVDIPlugin_x86.7z
Source: webex.exe, 00000000.00000003.2032458997.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1948632756.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1706246150.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1979201557.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032844232.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1982453215.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2095203618.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2813652807.00000000013EB000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.00000000013E0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-Win-64-Gold/
Source: webex.exe, 00000000.00000003.1706246150.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1979201557.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032844232.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1982453215.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2095203618.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2813652807.00000000013EB000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.00000000013E0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/DynamicComponent-ladon.7z
Source: webex.exe, 00000000.00000003.2032458997.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1948632756.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1706246150.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1979201557.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032844232.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1982453215.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2095203618.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2813652807.00000000013EB000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.00000000013E0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/DynamicComponent-xcodec.7zCo
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1706246150.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/DynamicComponent-xnn_engine.7z
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/Webex.exe
Source: webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/WebexStub.msi
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/WebexStub.msi7z
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/WebexStub.msi7zcom
Source: webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/WebexTeams.7z
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/WebexTeams.7z-a.wbx2.com
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/WebexTeams.7z2.comIaB
Source: webex.exe, 00000000.00000003.2032458997.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1948632756.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1706246150.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1979201557.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032844232.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1982453215.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2095203618.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2813652807.00000000013EB000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.00000000013E0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/WebexTeamsPatchUpgrade_1.7zE
Source: webex.exe, 00000000.00000003.2032458997.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1948632756.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1706246150.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1979201557.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032844232.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1982453215.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2095203618.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2813652807.00000000013EB000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.00000000013E0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/WebexTeamsPatchUpgrade_2.7zH
Source: webex.exe, 00000000.00000003.1706246150.00000000013DB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/WebexTeamsPatchUpgrade_3.7z
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-Win-64-MV-Gold/20240514195518/WebexTeams.7ze?
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/WebexDesktop-Win-64-MV-Gold/20240514195518/WebexTeams.7zfa
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/false
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/l
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/mpany
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/nager.cpw
Source: CiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB0860000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/nd
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/r.cpp:17
Source: CiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB087F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/static-content-pipeline/webex-app-resources/44.5/translations/manifest.jw
Source: CiscoCollabHost.exe, 00000013.00000002.3551254415.000001EFB39A9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/webview2runtime-win64/MicrosoftEdgeWebView2RuntimeInstaller_118.0.2088.69
Source: CiscoCollabHost.exe, 00000013.00000002.3551254415.000001EFB396F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com/y$
Source: CiscoCollabHost.exe, 00000013.00000002.3551507487.000001EFB3A91000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com:443/static-content-pipeline/webex-app-resources/44.5/translations/spark-w
Source: CiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB092C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.com:443/webview2runtime-win64/MicrosoftEdgeWebView2RuntimeInstaller_118.0.208
Source: CiscoCollabHost.exe, 00000013.00000002.3544235755.000001EFB038E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://binaries.webex.comD)
Source: CiscoCollabHost.exe, 00000013.00000002.3543096123.000001EFAFFC3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bitmoji.api.snapchat.com/direct/
Source: CiscoCollabHost.exe, 00000013.00000002.3543096123.000001EFAFFC3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bitmoji.api.snapchat.com/direct/avatar
Source: CiscoCollabHost.exe, 00000013.00000002.3543096123.000001EFAFFC3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bitmoji.api.snapchat.com/direct/avatar8Ev
Source: CiscoCollabHost.exe, 00000013.00000002.3543096123.000001EFAFFC3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bitmoji.api.snapchat.com/direct/pack/
Source: CiscoCollabHost.exe, 00000013.00000002.3543096123.000001EFAFFC3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bitmoji.api.snapchat.com/direct/packs
Source: CiscoCollabHost.exe, 00000013.00000002.3543096123.000001EFAFFC3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bitmoji.api.snapchat.com/direct/packshE&
Source: CiscoCollabHost.exe, 00000013.00000002.3542641508.000001EFAFDD3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://captive.apple.com/hotspot-detect.html
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cisco.com/go/schedule-meetings-from-google-workspace
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cisco.com/go/schedule-meetings-from-outlook
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cisco.com/go/smart-audio-settings
Source: CiscoCollabHost.exe, 00000013.00000002.3538642634.000001EFACED9000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3540182171.000001EFAF66E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cisco.com/go/webex-assistant-meetings-voice-commands
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cisco.com/go/webex-events-webcasts
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cisco.com/go/webex-restricted-networks
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://client-upgrade-a.wbx2.com
Source: CiscoCollabHost.exe, 00000013.00000002.3541455192.000001EFAF935000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://client-upgrade-a.wbx2.com/client-upgrade/api/v1
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://collaborationhelp.cisco.com/article/en-us/WBX000028818
Source: webex.exe, 00000000.00000003.1713521252.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713612449.0000000003349000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713706381.0000000003354000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713249908.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713571138.0000000003357000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713631047.000000000335B000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C73000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C80000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://d.symcb.com/cps0%
Source: webex.exe, 00000000.00000003.1713521252.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713612449.0000000003349000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713706381.0000000003354000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713249908.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713571138.0000000003357000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713631047.000000000335B000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C73000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C80000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://d.symcb.com/rpa0
Source: webex.exe, 00000000.00000003.1713521252.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713612449.0000000003349000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713706381.0000000003354000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713249908.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713571138.0000000003357000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713631047.000000000335B000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C73000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C80000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://d.symcb.com/rpa0.
Source: webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ds.ciscospark.com
Source: webex.exe, 00000000.00000003.2032458997.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1948632756.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2873018624.00000000013EB000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1706246150.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1979201557.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032844232.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1982453215.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2095203618.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2813652807.00000000013EB000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.00000000013E0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ds.ciscospark.com/
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ds.ciscospark.com6
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ds.ciscospark.comh
Source: CiscoCollabHost.exe, 00000013.00000002.3551507487.000001EFB3A91000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://go.webex
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://go.webex.com/go/globalcallin.php?serviceType=MC&eventID=169900787&tollFree=1
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://go.webex.com/m/35cf15b4-8b8c-4a99-b33f-20d086d2
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://go.webex.com/meeting/barbara
Source: CiscoCollabHost.exe, 00000013.00000002.3540985171.000001EFAF82F000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3541594618.000001EFAF9D0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/0p4gb1
Source: CiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB0860000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/article/n6fwepj/Where-is-Webex-available?#id_98290
Source: CiscoCollabHost.exe, 00000013.00000002.3540182171.000001EFAF66E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmail
Source: CiscoCollabHost.exe, 00000013.00000002.3540182171.000001EFAF6B4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmail#
Source: CiscoCollabHost.exe, 00000013.00000002.3539279947.000001EFAF190000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmail%
Source: CiscoCollabHost.exe, 00000013.00000002.3542641508.000001EFAFDD3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmail%O
Source: CiscoCollabHost.exe, 00000013.00000002.3541621203.000001EFAF9E2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmail)Aa
Source: CiscoCollabHost.exe, 00000013.00000002.3541621203.000001EFAF9E2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmail/C
Source: CiscoCollabHost.exe, 00000013.00000002.3539279947.000001EFAF190000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmail3
Source: CiscoCollabHost.exe, 00000013.00000002.3542641508.000001EFAFDD3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmail4M
Source: CiscoCollabHost.exe, 00000013.00000002.3541621203.000001EFAF9E2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmail5N
Source: CiscoCollabHost.exe, 00000013.00000002.3539279947.000001EFAF190000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmail=
Source: CiscoCollabHost.exe, 00000013.00000002.3540182171.000001EFAF6B4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmail?
Source: CiscoCollabHost.exe, 00000013.00000002.3541621203.000001EFAF9E2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmail?OK
Source: CiscoCollabHost.exe, 00000013.00000002.3540182171.000001EFAF6B4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-GmailC
Source: CiscoCollabHost.exe, 00000013.00000002.3540182171.000001EFAF6B4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-GmailG
Source: CiscoCollabHost.exe, 00000013.00000002.3539279947.000001EFAF190000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-GmailI
Source: CiscoCollabHost.exe, 00000013.00000002.3540182171.000001EFAF6B4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-GmailL
Source: CiscoCollabHost.exe, 00000013.00000002.3539279947.000001EFAF190000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-GmailM
Source: CiscoCollabHost.exe, 00000013.00000002.3541621203.000001EFAF9E2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-GmailMJ
Source: CiscoCollabHost.exe, 00000013.00000002.3539279947.000001EFAF190000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-GmailN
Source: CiscoCollabHost.exe, 00000013.00000002.3541621203.000001EFAF9E2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-GmailOM
Source: CiscoCollabHost.exe, 00000013.00000002.3541621203.000001EFAF9E2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-GmailPN
Source: CiscoCollabHost.exe, 00000013.00000002.3540182171.000001EFAF6B4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-GmailQ
Source: CiscoCollabHost.exe, 00000013.00000002.3540182171.000001EFAF6B4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-GmailR
Source: CiscoCollabHost.exe, 00000013.00000002.3541621203.000001EFAF9E2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-GmailSC
Source: CiscoCollabHost.exe, 00000013.00000002.3540182171.000001EFAF6B4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-GmailT
Source: CiscoCollabHost.exe, 00000013.00000002.3539279947.000001EFAF190000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-GmailW
Source: CiscoCollabHost.exe, 00000013.00000002.3541621203.000001EFAF9E2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-GmailXC
Source: CiscoCollabHost.exe, 00000013.00000002.3540182171.000001EFAF66E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-GmailZ
Source: CiscoCollabHost.exe, 00000013.00000002.3541621203.000001EFAF9E2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-GmaildK
Source: CiscoCollabHost.exe, 00000013.00000002.3539279947.000001EFAF190000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmaile
Source: CiscoCollabHost.exe, 00000013.00000002.3540182171.000001EFAF6B4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmailg
Source: CiscoCollabHost.exe, 00000013.00000002.3540182171.000001EFAF6B4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmailh
Source: CiscoCollabHost.exe, 00000013.00000002.3540182171.000001EFAF6B4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmaili
Source: CiscoCollabHost.exe, 00000013.00000002.3540182171.000001EFAF6B4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmailj
Source: CiscoCollabHost.exe, 00000013.00000002.3540182171.000001EFAF6B4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmaill
Source: CiscoCollabHost.exe, 00000013.00000002.3539279947.000001EFAF190000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3540182171.000001EFAF6B4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmailr
Source: CiscoCollabHost.exe, 00000013.00000002.3541621203.000001EFAF9E2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-GmailrK
Source: CiscoCollabHost.exe, 00000013.00000002.3540182171.000001EFAF6B4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmailu
Source: CiscoCollabHost.exe, 00000013.00000002.3540182171.000001EFAF6B4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmailv
Source: CiscoCollabHost.exe, 00000013.00000002.3541621203.000001EFAF9E2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-GmailvA2
Source: CiscoCollabHost.exe, 00000013.00000002.3540182171.000001EFAF6B4000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3542641508.000001EFAFDD3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmailw
Source: CiscoCollabHost.exe, 00000013.00000002.3541621203.000001EFAF9E2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-GmailwL3
Source: CiscoCollabHost.exe, 00000013.00000002.3540182171.000001EFAF6B4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmailz
Source: CiscoCollabHost.exe, 00000013.00000002.3540182171.000001EFAF6B4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/now4kjcb/Explore-Cisco-Webex-for-G-Suite-Google-Calendar-and-Gmail~
Source: CiscoCollabHost.exe, 00000013.00000002.3540182171.000001EFAF66E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/en-us/nttajz6/Schedule-and-Join-Meetings-with-Cisco-Webex-Scheduler-for-Micro
Source: CiscoCollabHost.exe, 00000013.00000002.3548188494.000001EFB09E0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/ld-n0bl93g-CiscoWebexTeams/Webex-Teams-App?omiReferProduct=WebexTeams
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://help.webex.com/n0qtkri
Source: CiscoCollabHost.exe, 00000013.00000002.3542700270.000001EFAFE23000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3544235755.000001EFB038E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://idbroker.webex.com
Source: CiscoCollabHost.exe, 00000013.00000002.3544235755.000001EFB038E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://identity.webex.com
Source: CiscoCollabHost.exe, 00000013.00000002.3544628106.000001EFB04C0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://mercury-connection-a.wbx2.com/v1
Source: CiscoCollabHost.exe, 00000013.00000002.3548188494.000001EFB099A000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3536542014.000000DFB04FD000.00000004.00000010.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3548188494.000001EFB097E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://metrics-a.wbx2.com
Source: CiscoCollabHost.exe, 00000013.00000002.3548188494.000001EFB097E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://metrics-a.wbx2.com/
Source: CiscoCollabHost.exe, 00000013.00000002.3544628106.000001EFB04C0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://metrics-a.wbx2.com/metrics/api/v1
Source: CiscoCollabHost.exe, 00000013.00000002.3548188494.000001EFB099A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://metrics-a.wbx2.com/metrics/api/v1/clientmetrics-prelogin
Source: CiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB08C3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://metrics-a.wbx2.com/metrics/api/v1/clientmetrics-preloginrigin.clientIn
Source: CiscoCollabHost.exe, 00000013.00000002.3548188494.000001EFB099A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://metrics-a.wbx2.comi
Source: CiscoCollabHost.exe, 00000013.00000002.3542700270.000001EFAFE23000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://reachable.webex.comU
Source: CiscoCollabHost.exe, 00000013.00000002.3540066323.000001EFAF5F5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sdk.bitmoji.com
Source: CiscoCollabHost.exe, 00000013.00000002.3543096123.000001EFAFFC3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sdk.bitmoji.com/me/sticker/
Source: CiscoCollabHost.exe, 00000013.00000002.3540066323.000001EFAF5F5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://sdk.bitmoji.com5
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://snap.com/en-GB/privacy/privacy-policy
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://snap.com/en-GB/terms
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://snap.com/en-US/privacy/privacy-policy
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://snap.com/en-US/terms
Source: CiscoCollabHost.exe, 00000013.00000002.3543096123.000001EFAFFC3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://status.webex.com/incidents
Source: CiscoCollabHost.exe, 00000013.00000002.3543096123.000001EFAFFC3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://status.webex.com/index.json
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB0860000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.ciscospark.com/customer/en/portal/articles/1911657-firewall-and-network-requirements
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://test.webex.com/meet/pmrlink
Source: CiscoCollabHost.exe, 00000013.00000002.3544482263.000001EFB042C000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3543171994.000001EFB0019000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://u2c-intb.ciscospark.com/u2c/api/v1
Source: CiscoCollabHost.exe, 00000013.00000002.3542641508.000001EFAFDD3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://u2c.gov.ciscospark.com/u2c/api/v1
Source: CiscoCollabHost.exe, 00000013.00000002.3544482263.000001EFB042C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://u2c.gov.ciscospark.com/u2c/api/v1/
Source: CiscoCollabHost.exe, 00000013.00000002.3544482263.000001EFB042C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://u2c.gov.ciscospark.com/u2c/api/v1/ndard
Source: CiscoCollabHost.exe, 00000013.00000002.3542700270.000001EFAFE23000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3544235755.000001EFB038E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://u2c.wbx2.com/u2c/api/v1
Source: CiscoCollabHost.exe, 00000013.00000002.3548188494.000001EFB09E0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://web.webex.com
Source: CiscoCollabHost.exe, 00000013.00000002.3544315068.000001EFB03D4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://web.webex.com/deviceAuth?
Source: CiscoCollabHost.exe, 00000013.00000002.3542243530.000001EFAFC25000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://web.webex.com/logout?mobile=webex
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://webex.meeting.com/meet/longname
Source: CiscoCollabHost.exe, 00000013.00000002.3560651202.00007FFDE8109000.00000002.00000001.01000000.00000040.sdmpString found in binary or memory: https://webrtc.googlesource.com/src/
Source: CiscoCollabHost.exe, 00000013.00000002.3540066323.000001EFAF5F5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.bitmoji.com/avatar
Source: CiscoCollabHost.exe, 00000013.00000002.3540066323.000001EFAF5F5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.bitmoji.com/avatarR
Source: CiscoCollabHost.exe, 00000013.00000002.3540066323.000001EFAF5F5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.bitmoji.com/connect
Source: CiscoCollabHost.exe, 00000013.00000002.3540066323.000001EFAF5F5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.bitmoji.com/connectW
Source: CiscoCollabHost.exe, 00000013.00000002.3540066323.000001EFAF5F5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.bitmoji.com/login
Source: CiscoCollabHost.exe, 00000013.00000002.3540066323.000001EFAF5F5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.bitmoji.com/sign-up
Source: CiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB0860000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.cisco.com/c/dam/en_us/about/doing_business/legal/docs/universal-cloud-agreement.pdf
Source: CiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB0860000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.cisco.com/c/dam/en_us/about/doing_business/legal/eula/cisco_end_user_license_agreement-e
Source: CiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB0860000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.cisco.com/c/en/us/about/legal/privacy-full.html
Source: CiscoCollabHost.exe, 00000013.00000002.3550823039.000001EFB3826000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.cisco.com/c/en/us/about/legal/privacy-full.htmlreLo
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.ciscospark.com/notices-and-disclaimers.html
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.ciscospark.com/plans.html
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.gnu.org/licenses/gpl-2.0.html
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.gnu.org/licenses/gpl-3.0.html.
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.gnu.org/licenses/lgpl-3.0.html.
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.gnu.org/licenses/lgpl.html.
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.qt.io/contact-us.
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.qt.io/licensing/
Source: webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.qt.io/terms-conditions.
Source: CiscoCollabHost.exe, 00000013.00000002.3540066323.000001EFAF5F5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.snapchat.com/bitmoji
Source: webex.exe, 00000000.00000003.1713521252.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713706381.0000000003354000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713249908.0000000006C71000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713571138.0000000003357000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713631047.000000000335B000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C73000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1713658818.0000000006C80000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.webex.com
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.webex.com/license.html
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.webex.com/pdf/tollfree_restrictions.pdf
Source: CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.webex.com/security.html
Source: CiscoCollabHost.exe, 00000013.00000002.3563909544.00007FFDE8C54000.00000002.00000001.01000000.00000037.sdmpBinary or memory string: DirectDrawCreateEx failed! errorcode = memstr_a3b71437-b
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE65D20E0 GetWindowLongPtrW,GetClientRect,ClientToScreen,GetCursorPos,?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ,?handleNativeEvent@QWindowSystemInterface@@SA_NPEAVQWindow@@AEBVQByteArray@@PEAXPEAJ@Z,??1?$QVector@VQPointF@@@@QEAA@XZ,?cast@QMetaObject@@QEBAPEAVQObject@@PEAV2@@Z,ImmAssociateContext,?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ,?transientParent@QWindow@@QEBAPEAV1@XZ,?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ,?parent@QWindow@@QEBAPEAV1@XZ,?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ,??0QMessageLogger@@QEAA@PEBDH0@Z,?warning@QMessageLogger@@QEBA?AVQDebug@@XZ,??6QDebug@@QEAAAEAV0@PEBD@Z,??6@YA?AVQDebug@@V0@PEBVQWindow@@@Z,??6QDebug@@QEAAAEAV0@PEBD@Z,??6@YA?AVQDebug@@V0@PEBVQWindow@@@Z,??6QDebug@@QEAAAEAV0@PEBD@Z,??6@YA?AVQDebug@@V0@PEBVQWindow@@@Z,??1QDebug@@QEAA@XZ,??1QDebug@@QEAA@XZ,??1QDebug@@QEAA@XZ,??1QDebug@@QEAA@XZ,?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ,?isTopLevel@QWindow@@QEBA_NXZ,?flags@QWindow@@QEBA?AV?$QFlags@W4WindowType@Qt@@@@XZ,DwmGetWindowAttribute,DwmGetWindowAttribute,??0QMessageLogger@@QEAA@PEBDH0@Z,?warning@QMessageLogger@@QEBAXPEBDZZ,?nextNode@QHashData@@SAPEAUNode@1@PEAU21@@Z,?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ,??$handleThemeChange@UDefaultDelivery@QWindowSystemInterface@@@QWindowSystemInterface@@SAXPEAVQWindow@@@Z,?nextNode@QHashData@@SAPEAUNode@1@PEAU21@@Z,?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ,GetCursor,SetCursor,GetWindowDpiAwarenessContext,GetAwarenessFromDpiAwarenessContext,EnableNonClientDpiScaling,GetLastError,?qErrnoWarning@@YAXHPEBDZZ,??0QMessageLogger@@QEAA@PEBDH0@Z,?warning@QMessageLogger@@QEBAXPEBDZZ,?isDebugEnabled@QLoggingCategory@@QEBA_NXZ,?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ,??0QMessageLogger@@QEAA@PEBDH00@Z,?debug@QMessageLogger@@QEBA?AVQDebug@@XZ,??6QDebug@@QEAAAEAV0@PEBD@Z,??6@YA?AVQDebug@@V0@PEBVQWindow@@@Z,??1QDebug@@QEAA@XZ,??1QDebug@@QEAA@XZ,?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ,ScreenToClient,GetWindowLongPtrW,GetClientRect,GetClientRect,GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyState,?handleContextMenuEvent@QWindowSystemInterface@@SAXPEAVQWindow@@_NAEBVQPoint@@2V?$QFlags@W4KeyboardModifier@Qt@@@@@Z,?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ,?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ,?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ,?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ,?isTopLevel@QWindow@@QEBA_NXZ,?minimumSize@QWindow@@QEBA?AVQSize@@XZ,?maximumSize@QWindow@@QEBA?AVQSize@@XZ,?scaleAndOrigin@QHighDpiScaling@@SA?AUScaleAndOrigin@1@PEBVQWindow@@PEAVQPoint@@@Z,?mapFromGlobal@QWindow@@QEBA?AVQPoint@@AEBV2@@Z,?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ,?flags@QWindow@@QEBA?AV?$QFlags@W4WindowType@Qt@@@@XZ,?parent@QWindow@@QEBAPEAV1@XZ,?cast@QMetaObject@@QEBAPEAVQObject@@PEAV2@@Z,?qt_localeFromLCID@@YA?AVQLocale@@K@Z,??4QUrl@@QEAAAEAV0@$$QEAV0@@Z,??1QLocale@@QEAA@XZ,?emitLocaleChanged@QPlatformInputContext@@QEAAXXZ,?isDebugEnabled@QLoggingCategory@@QEBA_NXZ,??0QMessageLogger@@QEAA@PEBDH00@Z,?debug@QMessageLogger@@QEBA?AVQDebug19_2_00007FFDE65D20E0
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE65D41E0 ?mouseButtons@QGuiApplication@@SA?AV?$QFlags@W4MouseButton@Qt@@@@XZ,GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetCursorPos,?mimeData@QDrag@@QEBAPEAVQMimeData@@XZ,?contains@QRect@@QEBA_NAEBVQPoint@@_N@Z,??$handleMouseEvent@UDefaultDelivery@QWindowSystemInterface@@@QWindowSystemInterface@@SA_NPEAVQWindow@@AEBVQPointF@@1V?$QFlags@W4MouseButton@Qt@@@@W4MouseButton@Qt@@W4Type@QEvent@@V?$QFlags@W4KeyboardModifier@Qt@@@@W4MouseEventSource@5@@Z,19_2_00007FFDE65D41E0
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE65DE930 GetWindowLongPtrW,GetClientRect,GetWindowLongPtrW,GetClientRect,ClientToScreen,ScreenToClient,GetWindowLongPtrW,GetClientRect,GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyState,?mimeData@QDrag@@QEBAPEAVQMimeData@@XZ,GetCapture,?flags@QWindow@@QEBA?AV?$QFlags@W4WindowType@Qt@@@@XZ,?parent@QWindow@@QEBAPEAV1@XZ,??0QRect@@QEAA@AEBVQPoint@@AEBVQSize@@@Z,?contains@QRect@@QEBA_NAEBVQPoint@@_N@Z,?mimeData@QDrag@@QEBAPEAVQMimeData@@XZ,ScreenToClient,GetWindowLongPtrW,GetClientRect,?handleWheelEvent@QWindowSystemInterface@@SA_NPEAVQWindow@@AEBVQPointF@@1VQPoint@@2V?$QFlags@W4KeyboardModifier@Qt@@@@W4ScrollPhase@Qt@@W4MouseEventSource@7@@Z,GetMessageExtraInfo,?handleFrameStrutMouseEvent@QWindowSystemInterface@@SA_NPEAVQWindow@@AEBVQPointF@@1V?$QFlags@W4MouseButton@Qt@@@@W4MouseButton@Qt@@W4Type@QEvent@@V?$QFlags@W4KeyboardModifier@Qt@@@@W4MouseEventSource@6@@Z,??$handleMouseEvent@UDefaultDelivery@QWindowSystemInterface@@@QWindowSystemInterface@@SA_NPEAVQWindow@@AEBVQPointF@@1V?$QFlags@W4MouseButton@Qt@@@@W4MouseButton@Qt@@W4Type@QEvent@@V?$QFlags@W4KeyboardModifier@Qt@@@@W4MouseEventSource@5@@Z,?handleFrameStrutMouseEvent@QWindowSystemInterface@@SA_NPEAVQWindow@@AEBVQPointF@@1V?$QFlags@W4MouseButton@Qt@@@@W4MouseButton@Qt@@W4Type@QEvent@@V?$QFlags@W4KeyboardModifier@Qt@@@@W4MouseEventSource@6@@Z,?isDebugEnabled@QLoggingCategory@@QEBA_NXZ,??0QMessageLogger@@QEAA@PEBDH00@Z,?debug@QMessageLogger@@QEBA?AVQDebug@@XZ,??6QDebug@@QEAAAEAV0@PEBD@Z,??6@YA?AVQDebug@@V0@PEBVQWindow@@@Z,??1QDebug@@QEAA@XZ,??1QDebug@@QEAA@XZ,??$handleLeaveEvent@UDefaultDelivery@QWindowSystemInterface@@@QWindowSystemInterface@@SAXPEAVQWindow@@@Z,??$handleMouseEvent@UDefaultDelivery@QWindowSystemInterface@@@QWindowSystemInterface@@SA_NPEAVQWindow@@AEBVQPointF@@1V?$QFlags@W4MouseButton@Qt@@@@W4MouseButton@Qt@@W4Type@QEvent@@V?$QFlags@W4KeyboardModifier@Qt@@@@W4MouseEventSource@5@@Z,?flushWindowSystemEvents@QWindowSystemInterface@@SA_NV?$QFlags@W4ProcessEventsFlag@QEventLoop@@@@@Z,19_2_00007FFDE65DE930
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\59c988.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSICB5D.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSICBCC.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{4A82B9CC-F7B3-5000-9CA4-89764C5A9DA4}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSID11C.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\59c98b.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\59c98b.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\MSICB5D.tmpJump to behavior
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334C2FE0_3_0334C2FE
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334C2FE0_3_0334C2FE
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CAFE0_3_0334CAFE
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CAFE0_3_0334CAFE
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CBFE0_3_0334CBFE
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CBFE0_3_0334CBFE
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334C2FE0_3_0334C2FE
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334C2FE0_3_0334C2FE
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CAFE0_3_0334CAFE
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CAFE0_3_0334CAFE
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CBFE0_3_0334CBFE
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CBFE0_3_0334CBFE
Source: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exeCode function: 18_2_00007FF7EC6B10C018_2_00007FF7EC6B10C0
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FF6F80110C019_2_00007FF6F80110C0
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE626C49019_2_00007FFDE626C490
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE626688019_2_00007FFDE6266880
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE626A0A019_2_00007FFDE626A0A0
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE626E0A019_2_00007FFDE626E0A0
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE626B4E019_2_00007FFDE626B4E0
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE626D2E019_2_00007FFDE626D2E0
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE626BB4019_2_00007FFDE626BB40
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE6265B6019_2_00007FFDE6265B60
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE626696019_2_00007FFDE6266960
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE6266F6019_2_00007FFDE6266F60
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE626B7B019_2_00007FFDE626B7B0
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE626EBA019_2_00007FFDE626EBA0
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE626E40019_2_00007FFDE626E400
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE626A7F019_2_00007FFDE626A7F0
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE626D64019_2_00007FFDE626D640
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE626703019_2_00007FFDE6267030
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE626E82019_2_00007FFDE626E820
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE65C666019_2_00007FFDE65C6660
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE65C882019_2_00007FFDE65C8820
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE65D44E019_2_00007FFDE65D44E0
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE65F012019_2_00007FFDE65F0120
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE65D20E019_2_00007FFDE65D20E0
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE65D4DA019_2_00007FFDE65D4DA0
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE65DE93019_2_00007FFDE65DE930
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE65C2A5019_2_00007FFDE65C2A50
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE65D14C019_2_00007FFDE65D14C0
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE66294C019_2_00007FFDE66294C0
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE65CD2B819_2_00007FFDE65CD2B8
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE66090A019_2_00007FFDE66090A0
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE65C50E019_2_00007FFDE65C50E0
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE6601F3019_2_00007FFDE6601F30
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE6609FE019_2_00007FFDE6609FE0
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE663389019_2_00007FFDE6633890
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE66099B019_2_00007FFDE66099B0
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE66666D019_2_00007FFDE66666D0
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE660E66019_2_00007FFDE660E660
Source: libmp3lame.dll.0.drStatic PE information: Resource name: RT_VERSION type: COM executable for DOS
Source: libav1rtp.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: libav1enc.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: libdav1d.dll.0.drStatic PE information: Number of sections : 13 > 10
Source: api-ms-win-core-util-l1-1-0.dll.0.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-private-l1-1-0.dll.0.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-process-l1-1-0.dll.0.drStatic PE information: No import functions for PE file found
Source: api-ms-win-core-synch-l1-1-0.dll.0.drStatic PE information: No import functions for PE file found
Source: api-ms-win-core-timezone-l1-1-0.dll.0.drStatic PE information: No import functions for PE file found
Source: api-ms-win-core-string-l1-1-0.dll.0.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-math-l1-1-0.dll.0.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-locale-l1-1-0.dll.0.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-time-l1-1-0.dll.0.drStatic PE information: No import functions for PE file found
Source: api-ms-win-core-sysinfo-l1-1-0.dll.0.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-environment-l1-1-0.dll.0.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-stdio-l1-1-0.dll.0.drStatic PE information: No import functions for PE file found
Source: api-ms-win-core-synch-l1-2-0.dll.0.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-utility-l1-1-0.dll.0.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-filesystem-l1-1-0.dll.0.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-multibyte-l1-1-0.dll.0.drStatic PE information: No import functions for PE file found
Source: api-ms-win-core-rtlsupport-l1-1-0.dll.0.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-conio-l1-1-0.dll.0.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-heap-l1-1-0.dll.0.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-convert-l1-1-0.dll.0.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-runtime-l1-1-0.dll.0.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-string-l1-1-0.dll.0.drStatic PE information: No import functions for PE file found
Source: webex.exe, 00000000.00000000.1670922438.0000000000C31000.00000008.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilename, vs webex.exe
Source: webex.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: webex.exeStatic PE information: Section: UPX1 ZLIB complexity 0.9990817866726297
Source: Qt5Core.dll.0.drStatic PE information: Section: .qtmimed ZLIB complexity 0.997458770800317
Source: CiscoCollabHost.exe, 00000013.00000002.3539279947.000001EFAF190000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3542641508.000001EFAFDD3000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: .vbproj
Source: CiscoCollabHost.exe, 00000013.00000002.3539279947.000001EFAF190000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3541867501.000001EFAFABD000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: .csproj
Source: classification engineClassification label: sus39.evad.winEXE@20/756@0/6
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\ProgramsJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeMutant created: NULL
Source: C:\Users\user\Desktop\webex.exeMutant created: \Sessions\1\BaseNamedObjects\WebexInstallerMutex
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7664:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7528:120:WilError_03
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\Temp\WebInstallerJump to behavior
Source: C:\Windows\SysWOW64\taskkill.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\msiexec.exeFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Users\user\Desktop\webex.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: webex.exeString found in binary or memory: nnen Sie die installierte Version nicht ersetzen. Weitere Informationen erhalten Sie bei Ihrem Administrator.", "AppNameText": "{APP_NAME}-Installationsprogramm", "ConvergedDownloadingText": "{APP_NAME} wird heruntergeladen...", "Con
Source: webex.exeString found in binary or memory: .", "ConvergedGenericErrorDetails": "Offenbar ist ein Fehler aufgetreten. Versuchen wir es erneut.", "ConvergedQuitInstallationHeader": "{APP_NAME}-Installation beenden?", "ConvergedQuitInstallationDetails": "{APP_NAME}-App-Installat
Source: webex.exeString found in binary or memory: tzt derzeit keine Befehlszeilenparameter.", "InstallPackageRejected": "Die App-Installation kann nicht autorisiert werden", "InstallPackageRejectedDetails": "Wenden Sie sich an den Systemadministrator, um Webex zu installieren.", "In
Source: CiscoCollabHost.exeString found in binary or memory: <!--StartFragment-->
Source: C:\Users\user\Desktop\webex.exeFile read: C:\Users\user\Desktop\webex.exeJump to behavior
Source: unknownProcess created: C:\Users\user\Desktop\webex.exe "C:\Users\user\Desktop\webex.exe"
Source: C:\Users\user\Desktop\webex.exeProcess created: C:\Windows\SysWOW64\msiexec.exe msiexec.exe /i "C:\Users\user\AppData\Local\Temp\c64e3759-805b-47c0-b4ab-a6ec7fecd393.msi" /quiet /norestart AUTOSTART_WITH_WINDOWS=false
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 305732C6DAD0EE72C0E34B949704E1E8
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\\taskkill.exe" /F /IM CiscoCollabHost.exe /T
Source: C:\Windows\SysWOW64\taskkill.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 80617056B0CA03034534C28A67086463
Source: C:\Users\user\Desktop\webex.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c timeout /NOBREAK /T 3 > nul & del /f /q "C:\Users\user\Desktop\webex.exe"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout /NOBREAK /T 3
Source: C:\Users\user\Desktop\webex.exeProcess created: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exe "C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exe" /protocolUri="webex://meet/?bt=12&bv=121&cr=065f9a40-5723-45ab-9507-cf2766bb45fe&dns=appleinc.webex.com&en=3&flag=17&jointxid=x7Pbq0RE2n&jt=eyJkdDAiOjE3MTY1NDg2NDIsImR0MSI6Nzk4LCJkdDIiOjIxODUsImR0MyI6MzUzNSwiZHQ0IjoyNDEyODMsImR0NSI6MzcxODI4NTUxLCJkdDYiOjE3MTY5MjA3MjEsImZ0IjoxLCJ0IjoyNSwidXAiOjF9&mtid=m547a808dce8d2d3d893e20fa794cb8a1&od=6f783f73-9637-4b83-90b9-434a5fccb49d&rc=4&sip=24877802128@appleinc.webex.com&siteurl=appleinc&tr=7A2D3FEB1EC64A498D4F669177387376_1709540815837&uuid=04485f8191de4a7c891a7dfe933370dc&vp=0"
Source: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exeProcess created: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe "C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe" "C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1" spark-windows-app.dll /Hosted=true "C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exe" /protocolUri="webex://meet/?bt=12&bv=121&cr=065f9a40-5723-45ab-9507-cf2766bb45fe&dns=appleinc.webex.com&en=3&flag=17&jointxid=x7Pbq0RE2n&jt=eyJkdDAiOjE3MTY1NDg2NDIsImR0MSI6Nzk4LCJkdDIiOjIxODUsImR0MyI6MzUzNSwiZHQ0IjoyNDEyODMsImR0NSI6MzcxODI4NTUxLCJkdDYiOjE3MTY5MjA3MjEsImZ0IjoxLCJ0IjoyNSwidXAiOjF9&mtid=m547a808dce8d2d3d893e20fa794cb8a1&od=6f783f73-9637-4b83-90b9-434a5fccb49d&rc=4&sip=24877802128@appleinc.webex.com&siteurl=appleinc&tr=7A2D3FEB1EC64A498D4F669177387376_1709540815837&uuid=04485f8191de4a7c891a7dfe933370dc&vp=0"
Source: C:\Users\user\Desktop\webex.exeProcess created: C:\Windows\SysWOW64\msiexec.exe msiexec.exe /i "C:\Users\user\AppData\Local\Temp\c64e3759-805b-47c0-b4ab-a6ec7fecd393.msi" /quiet /norestart AUTOSTART_WITH_WINDOWS=falseJump to behavior
Source: C:\Users\user\Desktop\webex.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c timeout /NOBREAK /T 3 > nul & del /f /q "C:\Users\user\Desktop\webex.exe"Jump to behavior
Source: C:\Users\user\Desktop\webex.exeProcess created: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exe "C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exe" /protocolUri="webex://meet/?bt=12&bv=121&cr=065f9a40-5723-45ab-9507-cf2766bb45fe&dns=appleinc.webex.com&en=3&flag=17&jointxid=x7Pbq0RE2n&jt=eyJkdDAiOjE3MTY1NDg2NDIsImR0MSI6Nzk4LCJkdDIiOjIxODUsImR0MyI6MzUzNSwiZHQ0IjoyNDEyODMsImR0NSI6MzcxODI4NTUxLCJkdDYiOjE3MTY5MjA3MjEsImZ0IjoxLCJ0IjoyNSwidXAiOjF9&mtid=m547a808dce8d2d3d893e20fa794cb8a1&od=6f783f73-9637-4b83-90b9-434a5fccb49d&rc=4&sip=24877802128@appleinc.webex.com&siteurl=appleinc&tr=7A2D3FEB1EC64A498D4F669177387376_1709540815837&uuid=04485f8191de4a7c891a7dfe933370dc&vp=0"Jump to behavior
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 305732C6DAD0EE72C0E34B949704E1E8Jump to behavior
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 80617056B0CA03034534C28A67086463Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\\taskkill.exe" /F /IM CiscoCollabHost.exe /TJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout /NOBREAK /T 3Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exeProcess created: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe "C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe" "C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1" spark-windows-app.dll /Hosted=true "C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exe" /protocolUri="webex://meet/?bt=12&bv=121&cr=065f9a40-5723-45ab-9507-cf2766bb45fe&dns=appleinc.webex.com&en=3&flag=17&jointxid=x7Pbq0RE2n&jt=eyJkdDAiOjE3MTY1NDg2NDIsImR0MSI6Nzk4LCJkdDIiOjIxODUsImR0MyI6MzUzNSwiZHQ0IjoyNDEyODMsImR0NSI6MzcxODI4NTUxLCJkdDYiOjE3MTY5MjA3MjEsImZ0IjoxLCJ0IjoyNSwidXAiOjF9&mtid=m547a808dce8d2d3d893e20fa794cb8a1&od=6f783f73-9637-4b83-90b9-434a5fccb49d&rc=4&sip=24877802128@appleinc.webex.com&siteurl=appleinc&tr=7A2D3FEB1EC64A498D4F669177387376_1709540815837&uuid=04485f8191de4a7c891a7dfe933370dc&vp=0"Jump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: secur32.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: dhcpcsvc6.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: dhcpcsvc.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: atlthunk.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: oleacc.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: dwrite.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: webio.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: winnsi.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: fwpuclnt.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: schannel.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: mskeyprotect.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: ncryptsslp.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: dpapi.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: cryptnet.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: ieframe.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: windows.staterepositoryps.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: edputil.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: mlang.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: wininet.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: appresolver.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: slc.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: sppc.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msisip.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cryptnet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: linkinfo.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntshrui.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cscapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: framedynos.dllJump to behavior
Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: dbghelp.dllJump to behavior
Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: wbemcomn.dllJump to behavior
Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: winsta.dllJump to behavior
Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: amsi.dllJump to behavior
Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vbscript.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: amsi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\SysWOW64\timeout.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: spark-windows-desktop-ui.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: libcurl.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: libcrypto-1_1-x64.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: libssl-1_1-x64.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: d3d11.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: d2d1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: dwrite.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: wininet.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: d3dcompiler_47.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: sparkprtdll.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: hunspell.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: windows-os-integrations.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msdelta.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: qt5widgets.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: qt5gui.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: qt5core.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: spark-windows-desktop-ui-rcc.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: kf5syntaxhighlighting.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: eventbus.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: servicessignalemitters.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: qt5quickwidgets.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: qt5quick.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: qt5qml.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: qt5network.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: lambdathreadswitcher.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: uitoolkit.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: wtsapi32.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: meetingcontaineractivitystreamtype.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: qt5svg.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: qt5winextras.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: uielements.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: webview2loader.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: threadids.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: dxgi.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: qt5multimediawidgets.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: qt5multimedia.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msvcp140_atomic_wait.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: concrt140.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: dxgi.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: dcomp.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: pdh.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: spark-windows-office-integration.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: activeds.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: ntdsapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: secur32.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: bwc.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: common_md.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: enhanced-callcontrol_md.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: hid.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: mediasession.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: wseclient.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: wmeclient.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: sqlite3.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: dbghelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: threadids.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msvcp140_atomic_wait.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: concrt140.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msvcp140_atomic_wait.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: threadids.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: dxgi.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: qt5core.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: mpr.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: winmm.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msvcp140_1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: qt5network.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: threadids.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msvcp140_atomic_wait.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: qt5quick.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: qt5qml.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msvcp140_1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: qt5qmlmodels.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: qt5network.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: qt5network.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: uielements.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: csflogger.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: libxml2.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: adsldpc.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: csflogger.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: libxml2.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: srtp.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: wsock32.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: util.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: tp.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: wmeclient.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: mediastores.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: util.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: mediastores.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: videoprocess.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: ddraw.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: wbxaudioengine.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: mediastores.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: wrtp.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: dbgcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: dpapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: dciman32.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: wqos.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: ciscosrtp.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: avrt.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msdmo.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: wbxaecodec.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: wlanapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: common-vdiframework.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: vxccommunication.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: winsta.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: netprofm.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: dhcpcsvc6.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: dhcpcsvc.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: msi.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: libegl.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: libglesv2.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: d3d9.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: resourcepolicyclient.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: npmproxy.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: webio.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: winnsi.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: dxcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: fwpuclnt.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: schannel.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: dataexchange.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: mskeyprotect.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: ncryptsslp.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: cryptnet.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: explorerframe.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\InprocServer32Jump to behavior
Source: C:\Users\user\Desktop\webex.exeFile opened: C:\Users\user\Desktop\dependencies\accessories\DseaSupportList.cfgJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Windows\System32\msiexec.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4A82B9CC-F7B3-5000-9CA4-89764C5A9DA4}Jump to behavior
Source: webex.exeStatic PE information: certificate valid
Source: webex.exeStatic file information: File size 1485096 > 1048576
Source: webex.exeStatic PE information: Raw size of UPX1 is bigger than: 0x100000 < 0x15d600
Source: webex.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: J:\qt_build\workspace\qt_build\qtbase\lib\libGLESv2.pdb source: CiscoCollabHost.exe, 00000013.00000002.3556069538.00007FFDE64E9000.00000002.00000001.01000000.0000004B.sdmp
Source: Binary string: E:\VSExclude\Jenkins_Workspace\wme-release\wme\mediaengine\maps\x64\Release\wmeclient.pdbyy GCTL source: CiscoCollabHost.exe, 00000013.00000002.3563229356.00007FFDE8847000.00000002.00000001.01000000.0000003C.sdmp
Source: Binary string: J:\qt_build\workspace\qt_build\qtbase\plugins\platforms\qwindows.pdb source: CiscoCollabHost.exe, 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmp
Source: Binary string: E:\VSExclude\Jenkins_Workspace\wme-release\wme\mediaengine\maps\x64\Release\wmeclient.pdb source: CiscoCollabHost.exe, 00000013.00000002.3563229356.00007FFDE8847000.00000002.00000001.01000000.0000003C.sdmp
Source: Binary string: E:\VSExclude\Jenkins_Workspace\wme-release\wme\mediaengine\maps\x64\Release\wseclient.pdb source: CiscoCollabHost.exe, 00000013.00000002.3563909544.00007FFDE8C54000.00000002.00000001.01000000.00000037.sdmp
Source: Binary string: E:\VSExclude\Jenkins_Workspace\wme-release\wme\vendor\video_process\bin\windows\x86_64\Release\videoprocess.pdb source: CiscoCollabHost.exe, 00000013.00000002.3562293246.00007FFDE85F7000.00000002.00000001.01000000.0000003E.sdmp
Source: Binary string: J:\TeamsVDI\out\hvdsdk\release\bin\VxcCommunication.dll.pdb source: CiscoCollabHost.exe, 00000013.00000002.3557154248.00007FFDE6863000.00000002.00000001.01000000.00000047.sdmp
Source: Binary string: E:\VSExclude\Jenkins_Workspace\wme-release\wme\mediaengine\maps\x64\Release\wbxaudioengine.pdb source: CiscoCollabHost.exe, 00000013.00000002.3558824995.00007FFDE70C6000.00000002.00000001.01000000.00000043.sdmp
Source: Binary string: E:\VSExclude\Jenkins_Workspace\wme-release\wme\mediaengine\maps\x64\Release\wrtp.pdb source: CiscoCollabHost.exe, 00000013.00000002.3560651202.00007FFDE8109000.00000002.00000001.01000000.00000040.sdmp
Source: Binary string: E:\VSExclude\Jenkins_Workspace\wme-release\wme\mediaengine\maps\x64\Release\wbxaudioengine.pdbi source: CiscoCollabHost.exe, 00000013.00000002.3558824995.00007FFDE70C6000.00000002.00000001.01000000.00000043.sdmp
Source: Binary string: J:\TeamsVDI\out\hvdsdk\release\bin\VxcCommunication.dll.pdb``# source: CiscoCollabHost.exe, 00000013.00000002.3557154248.00007FFDE6863000.00000002.00000001.01000000.00000047.sdmp
Source: Binary string: J:\TeamsVDI\out\hvdsdk\release\bin\VDIFramework.dll.pdb source: CiscoCollabHost.exe, 00000013.00000002.3557908733.00007FFDE6B9E000.00000002.00000001.01000000.00000045.sdmp
Source: Binary string: J:\TeamsVDI\out\hvdsdk\release\bin\VDIFramework.dll.pdbmm$ source: CiscoCollabHost.exe, 00000013.00000002.3557908733.00007FFDE6B9E000.00000002.00000001.01000000.00000045.sdmp
Source: Binary string: J:\qt_build\workspace\qt_build\qtbase\lib\libGLESv2.pdb4 source: CiscoCollabHost.exe, 00000013.00000002.3556069538.00007FFDE64E9000.00000002.00000001.01000000.0000004B.sdmp
Source: Binary string: CiscoCollabHost.pdb source: CiscoCollabHost.exe, 00000012.00000002.3326490032.00007FF7EC6B3000.00000002.00000001.01000000.00000008.sdmp, CiscoCollabHost.exe, 00000012.00000000.3322197488.00007FF7EC6B3000.00000002.00000001.01000000.00000008.sdmp, CiscoCollabHost.exe, 00000013.00000000.3323639313.00007FF6F8013000.00000002.00000001.01000000.0000000A.sdmp, CiscoCollabHost.exe, 00000013.00000002.3555496022.00007FF6F8013000.00000002.00000001.01000000.0000000A.sdmp
Source: api-ms-win-core-rtlsupport-l1-1-0.dll.0.drStatic PE information: 0x7D43BEB4 [Tue Aug 5 23:28:52 2036 UTC]
Source: qtaudio_windows.dll.0.drStatic PE information: section name: .qtmetad
Source: qgenericbearer.dll.0.drStatic PE information: section name: .qtmetad
Source: cfom.dll.0.drStatic PE information: section name: fipstx
Source: cfom.dll.0.drStatic PE information: section name: fipsro
Source: cfom.dll.0.drStatic PE information: section name: fipsda
Source: cfom.dll.0.drStatic PE information: section name: fipsrd
Source: common_MD.dll.0.drStatic PE information: section name: .didat
Source: common_MD.dll.0.drStatic PE information: section name: .00cfg
Source: qsvgicon.dll.0.drStatic PE information: section name: .qtmetad
Source: qgif.dll.0.drStatic PE information: section name: .qtmetad
Source: qicns.dll.0.drStatic PE information: section name: .qtmetad
Source: qico.dll.0.drStatic PE information: section name: .qtmetad
Source: qjpeg.dll.0.drStatic PE information: section name: .qtmetad
Source: qsvg.dll.0.drStatic PE information: section name: .qtmetad
Source: qtga.dll.0.drStatic PE information: section name: .qtmetad
Source: qwbmp.dll.0.drStatic PE information: section name: .qtmetad
Source: libav1enc.dll.0.drStatic PE information: section name: .buildid
Source: libav1enc.dll.0.drStatic PE information: section name: .xdata
Source: libav1rtp.dll.0.drStatic PE information: section name: .buildid
Source: libav1rtp.dll.0.drStatic PE information: section name: .xdata
Source: libcrypto-1_1-x64.dll.0.drStatic PE information: section name: .00cfg
Source: libcurl.dll.0.drStatic PE information: section name: .00cfg
Source: libdav1d.dll.0.drStatic PE information: section name: .buildid
Source: libdav1d.dll.0.drStatic PE information: section name: .xdata
Source: libmp3lame.dll.0.drStatic PE information: section name: .00cfg
Source: libssl-1_1-x64.dll.0.drStatic PE information: section name: .00cfg
Source: dsengine.dll.0.drStatic PE information: section name: .qtmetad
Source: qtmedia_audioengine.dll.0.drStatic PE information: section name: .qtmetad
Source: wmfengine.dll.0.drStatic PE information: section name: .qtmetad
Source: ngraph.dll.0.drStatic PE information: section name: _RDATA
Source: openh264.dll.0.drStatic PE information: section name: .rodata
Source: openh264.dll.0.drStatic PE information: section name: _RDATA
Source: qwindows.dll.0.drStatic PE information: section name: .qtmetad
Source: qtmultimedia_m3u.dll.0.drStatic PE information: section name: .qtmetad
Source: qtlabscalendarplugin.dll.0.drStatic PE information: section name: .qtmetad
Source: qmlfolderlistmodelplugin.dll.0.drStatic PE information: section name: .qtmetad
Source: labsmodelsplugin.dll.0.drStatic PE information: section name: .qtmetad
Source: qmlsettingsplugin.dll.0.drStatic PE information: section name: .qtmetad
Source: Qt5Core.dll.0.drStatic PE information: section name: .qtmimed
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0337D9E4 push esp; iretd 0_3_0337D9EA
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0337D94F push edi; iretd 0_3_0337D953
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_03351936 push FFFFFF9Ah; ret 0_3_0335193D
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_03351936 push FFFFFF9Ah; ret 0_3_0335193D
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334C366 push 680334C3h; ret 0_3_0334C36D
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334C366 push 680334C3h; ret 0_3_0334C36D
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CB66 push 680334CBh; retf 0_3_0334CB6D
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CB66 push 680334CBh; retf 0_3_0334CB6D
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CF66 push 680334CFh; iretd 0_3_0334CF6D
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CF66 push 680334CFh; iretd 0_3_0334CF6D
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334C362 pushad ; ret 0_3_0334C365
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334C362 pushad ; ret 0_3_0334C365
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CB62 pushad ; retf 0_3_0334CB65
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CB62 pushad ; retf 0_3_0334CB65
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CF62 pushad ; iretd 0_3_0334CF65
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CF62 pushad ; iretd 0_3_0334CF65
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334C352 push eax; ret 0_3_0334C355
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334C352 push eax; ret 0_3_0334C355
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CB52 push eax; retf 0_3_0334CB55
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CB52 push eax; retf 0_3_0334CB55
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CF52 push eax; iretd 0_3_0334CF55
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CF52 push eax; iretd 0_3_0334CF55
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334EB53 push eax; ret 0_3_0334EB71
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334EB53 push eax; ret 0_3_0334EB71
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334C35E pushad ; ret 0_3_0334C361
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334C35E pushad ; ret 0_3_0334C361
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CB5E pushad ; retf 0_3_0334CB61
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CB5E pushad ; retf 0_3_0334CB61
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CF5E pushad ; iretd 0_3_0334CF61
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334CF5E pushad ; iretd 0_3_0334CF61
Source: C:\Users\user\Desktop\webex.exeCode function: 0_3_0334C34E push eax; ret 0_3_0334C351
Source: cfom.dll.0.drStatic PE information: section name: fipstx entropy: 7.59093805812135
Source: initial sampleStatic PE information: section name: UPX0
Source: initial sampleStatic PE information: section name: UPX1
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml\StateMachine\qtqmlstatemachine.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\inference_engine_ir_reader.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\mediaservice\wmfengine.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\accessories\JabraPluginController.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\bin\vcruntime140_1.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\libdav1d.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-processenvironment-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\msvcp140_1.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-utility-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\mediastores.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-file-l1-2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoSparkLauncher.dll (copy)Jump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\CiscoSparkLauncher.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-debug-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Common-HvdAgent.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Dialogs\Private\dialogsprivateplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5QmlWorkerScript.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\EventBus.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\bin\msvcp140_1.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\imageformats\qtga.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\playlistformats\qtmultimedia_m3u.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\msvcp140.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5MultimediaWidgets.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtGraphicalEffects\private\qtgraphicaleffectsprivate.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls.2\Material\qtquickcontrols2materialstyleplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\libssl-1_1-x64.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Dialogs\dialogplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5OpenGL.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-runtime-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\inference_engine_legacy.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-processthreads-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\CitrixServer.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-private-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-handle-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\concrt140.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\HttpDownloader.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\ServicesFramework.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\imageformats\qjpeg.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs\calendar\qtlabscalendarplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\CiscoLocalRecordConverter.exeJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\hunspell.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\imageformats\qicns.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exeJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5Gui.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\ciscosrtp.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\d3dcompiler_47.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtMultimedia\declarative_multimedia.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\RDPServer.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\imageformats\qsvg.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs\settings\qmlsettingsplugin.dllJump to dropped file
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeFile created: C:\Users\user\AppData\Local\Temp\WebView2Runtime\MicrosoftEdgeWebView2RuntimeInstaller_118.0.2088.69.exeJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\mediaservice\qtmedia_audioengine.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Shapes\qmlshapesplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-string-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Templates.2\qtquicktemplates2plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSICB5D.tmpJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-profile-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-time-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-localization-l1-2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-synch-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\bwc.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\clDNNPlugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-filesystem-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5RemoteObjects.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-sysinfo-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-datetime-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\KF5SyntaxHighlighting.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml\WorkerScript.2\workerscriptplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5QuickShapes.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\libxml2.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\DCVServer.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5Network.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\MKLDNNPlugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\JCFCoreUtils.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5QuickControls2.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Layouts\qquicklayoutsplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\libcrypto-1_1-x64.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\ServicesSignalEmitters.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\csfstorage.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-namedpipe-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-heap-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Common-VDIFramework.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\imageformats\qico.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\mediaconverter.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\scenegraph\qsgd3d12backend.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-memory-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls\qtquickcontrolsplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\accessories\DSEAPluginController.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\msvcp140_atomic_wait.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5MultimediaQuick.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick.2\qtquick2plugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-timezone-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\libcurl.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml\Models.2\modelsplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-stdio-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5QmlModels.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\ConfigService.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Window.2\windowplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-heap-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\dnsutils.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\bin\concrt140.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5QuickTemplates2.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls.2\Imagine\qtquickcontrols2imaginestyleplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\bin\msvcp140_2.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\inference_engine_transformations.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5Core.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-libraryloader-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\mediasession.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls.2\Universal\qtquickcontrols2universalstyleplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\imageformats\qwbmp.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-console-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\msvcp140_2.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-rtlsupport-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\spark-windows-accessories.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSICBCC.tmpJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls\Styles\Flat\qtquickextrasflatplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-file-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\audio\qtaudio_windows.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-environment-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-string-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\bin\msvcp140_atomic_wait.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5Qml.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-synch-l1-2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\libav1enc.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5WinExtras.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\common_MD.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\HVDAgent.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\ngraph.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtGraphicalEffects\qtgraphicaleffectsplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\csfdiagnostics.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\appshare.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\spark-windows-desktop-ui-rcc.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\csflogger.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-convert-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-conio-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5Widgets.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\accessories\PolyPluginController.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\bin\msvcp140.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-processthreads-l1-1-1.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\LambdaThreadSwitcher.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-locale-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs\folderlistmodel\qmlfolderlistmodelplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\ProcessCleaner.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\bin\vcruntime140.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\accessories\CiscoPluginControl.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5QuickWidgets.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\spark-windows-media.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\accessories\Cisco3rdPartyPlugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\openh264.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\libGLESv2.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-fibers-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\msvcp140_codecvt_ids.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-console-l1-2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\platforms\qwindows.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-interlocked-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5Multimedia.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5Svg.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\MeetingContainerActivityStreamType.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-process-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\spark-windows-desktop-ui.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\inference_engine_lp_transformations.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\enhanced-callcontrol_MD.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-errorhandling-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls.2\qtquickcontrols2plugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-multibyte-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\iconengines\qsvgicon.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Extras\qtquickextrasplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\csfnetutils.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\imageformats\qgif.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\mediaservice\dsengine.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\bearer\qgenericbearer.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-util-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\PrivateWidgets\widgetsplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-math-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\bin\msvcp140_codecvt_ids.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-file-l2-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\libmp3lame.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml\qmlplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\CiscoWebExStart.exeJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\inference_engine.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs\qmlmodels\labsmodelsplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\cfom.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\libav1rtp.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\spark-windows-app-impl.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\LadonSDK.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\libEGL.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls.2\Fusion\qtquickcontrols2fusionstyleplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml\RemoteObjects\qtqmlremoteobjects.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\spark-windows-bwc.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\MJPGDecoder.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeFile created: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5Quick.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSICB5D.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSICBCC.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WebexJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Webex\Webex.lnkJump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Users\user\Desktop\webex.exeProcess created: cmd.exe /c timeout /NOBREAK /T 3 > nul & del /f /q "C:\Users\user\Desktop\webex.exe"
Source: C:\Users\user\Desktop\webex.exeProcess created: cmd.exe /c timeout /NOBREAK /T 3 > nul & del /f /q "C:\Users\user\Desktop\webex.exe"Jump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE65D2CC1 IsIconic,19_2_00007FFDE65D2CC1
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE6608BF0 ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ,??0QMessageLogger@@QEAA@PEBDH00@Z,?debug@QMessageLogger@@QEBA?AVQDebug@@XZ,??6QDebug@@QEAAAEAV0@PEBD@Z,??6QDebug@@QEAAAEAV0@PEBD@Z,??1QDebug@@QEAA@XZ,?fromLatin1@QString@@SA?AV1@PEBDH@Z,?utf16@QString@@QEBAPEBGXZ,LoadLibraryW,??1?$QVector@VQPointF@@@@QEAA@XZ,GetLastError,?qErrnoWarning@@YAXHPEBDZZ,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,19_2_00007FFDE6608BF0
Source: C:\Users\user\Desktop\webex.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdateJump to behavior
Source: C:\Users\user\Desktop\webex.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
Source: C:\Windows\System32\msiexec.exeKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54 BlobJump to behavior
Source: C:\Users\user\Desktop\webex.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\webex.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\webex.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\taskkill.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\webex.exeFile opened / queried: C:\Users\user\Desktop\dependencies\VMWareServer.dllJump to behavior
Source: C:\Users\user\Desktop\webex.exeWindow / User API: threadDelayed 855Jump to behavior
Source: C:\Users\user\Desktop\webex.exeWindow / User API: threadDelayed 1417Jump to behavior
Source: C:\Users\user\Desktop\webex.exeWindow / User API: threadDelayed 2557Jump to behavior
Source: C:\Users\user\Desktop\webex.exeWindow / User API: threadDelayed 744Jump to behavior
Source: C:\Users\user\Desktop\webex.exeWindow / User API: threadDelayed 952Jump to behavior
Source: C:\Users\user\Desktop\webex.exeWindow / User API: threadDelayed 471Jump to behavior
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml\StateMachine\qtqmlstatemachine.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\mediaservice\wmfengine.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\inference_engine_ir_reader.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\accessories\JabraPluginController.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-processenvironment-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\libdav1d.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-utility-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoSparkLauncher.dll (copy)Jump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-file-l1-2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\CiscoSparkLauncher.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-debug-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Common-HvdAgent.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Dialogs\Private\dialogsprivateplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5QmlWorkerScript.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\imageformats\qtga.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\playlistformats\qtmultimedia_m3u.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls.2\Material\qtquickcontrols2materialstyleplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtGraphicalEffects\private\qtgraphicaleffectsprivate.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Dialogs\dialogplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5OpenGL.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\inference_engine_legacy.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-runtime-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-processthreads-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\CitrixServer.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-private-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-handle-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\ServicesFramework.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\HttpDownloader.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\imageformats\qjpeg.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs\calendar\qtlabscalendarplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\CiscoLocalRecordConverter.exeJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\imageformats\qicns.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\RDPServer.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtMultimedia\declarative_multimedia.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\imageformats\qsvg.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs\settings\qmlsettingsplugin.dllJump to dropped file
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\WebView2Runtime\MicrosoftEdgeWebView2RuntimeInstaller_118.0.2088.69.exeJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Shapes\qmlshapesplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\mediaservice\qtmedia_audioengine.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-string-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Templates.2\qtquicktemplates2plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSICB5D.tmpJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-profile-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-localization-l1-2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-time-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-synch-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\clDNNPlugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-filesystem-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5RemoteObjects.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-sysinfo-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-datetime-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml\WorkerScript.2\workerscriptplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5QuickShapes.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\DCVServer.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\MKLDNNPlugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5QuickControls2.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\JCFCoreUtils.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Layouts\qquicklayoutsplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\csfstorage.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-namedpipe-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-heap-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\imageformats\qico.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\scenegraph\qsgd3d12backend.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\mediaconverter.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-memory-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls\qtquickcontrolsplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\accessories\DSEAPluginController.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick.2\qtquick2plugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5MultimediaQuick.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-timezone-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml\Models.2\modelsplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-stdio-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\ConfigService.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Window.2\windowplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-heap-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\dnsutils.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\bin\msvcp140_2.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5QuickTemplates2.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls.2\Imagine\qtquickcontrols2imaginestyleplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\inference_engine_transformations.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-libraryloader-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls.2\Universal\qtquickcontrols2universalstyleplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\imageformats\qwbmp.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-console-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\msvcp140_2.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-rtlsupport-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSICBCC.tmpJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\spark-windows-accessories.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-file-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls\Styles\Flat\qtquickextrasflatplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\audio\qtaudio_windows.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-environment-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-string-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-synch-l1-2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\libav1enc.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\HVDAgent.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtGraphicalEffects\qtgraphicaleffectsplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\ngraph.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\csfdiagnostics.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\appshare.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-conio-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-convert-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\accessories\PolyPluginController.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-processthreads-l1-1-1.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-locale-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs\folderlistmodel\qmlfolderlistmodelplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\ProcessCleaner.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\accessories\CiscoPluginControl.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\spark-windows-media.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\accessories\Cisco3rdPartyPlugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\openh264.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-fibers-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-console-l1-2-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\msvcp140_codecvt_ids.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\platforms\qwindows.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-interlocked-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-process-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\inference_engine_lp_transformations.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-errorhandling-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls.2\qtquickcontrols2plugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-multibyte-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\iconengines\qsvgicon.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Extras\qtquickextrasplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\mediaservice\dsengine.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\imageformats\qgif.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\bearer\qgenericbearer.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-util-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\PrivateWidgets\widgetsplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-crt-math-l1-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\bin\msvcp140_codecvt_ids.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\api-ms-win-core-file-l2-1-0.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\libmp3lame.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml\qmlplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\CiscoWebExStart.exeJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\inference_engine.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs\qmlmodels\labsmodelsplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\cfom.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\spark-windows-app-impl.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\LadonSDK.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls.2\Fusion\qtquickcontrols2fusionstyleplugin.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml\RemoteObjects\qtqmlremoteobjects.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\MJPGDecoder.dllJump to dropped file
Source: C:\Users\user\Desktop\webex.exe TID: 7284Thread sleep time: -30000s >= -30000sJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE65D02E0 GetKeyboardLayoutList followed by cmp: cmp ecx, 31h and CTI: je 00007FFDE65D064Dh19_2_00007FFDE65D02E0
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: CiscoCollabHost.exe, 00000013.00000002.3542641508.000001EFAFDD3000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: VMware Virtual Platform
Source: webex.exe, 00000000.00000003.2871943685.0000000006D26000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2220147328.0000000006D26000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2217530290.0000000006D26000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2030837751.0000000006D26000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2217819546.0000000006D26000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2162928824.0000000006D26000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2167379117.0000000006D16000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2764198146.0000000006D26000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815876681.0000000006D26000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2165355487.0000000006D16000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2813726842.0000000006D26000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: qemUb
Source: CiscoCollabHost.exe, 00000013.00000002.3563909544.00007FFDE8C54000.00000002.00000001.01000000.00000037.sdmpBinary or memory string: VMware
Source: CiscoCollabHost.exe, 00000013.00000002.3557908733.00007FFDE6B9E000.00000002.00000001.01000000.00000045.sdmpBinary or memory string: invalid string positionCITRIXVMWARERDPTCPSocketDCVNONEteamshvdagent.exemeetingshvdagent.execiscohvdagent.exeLocal\018AD6CC-18A5-4EBE-A3B7-ACE1C7414F52_hvd_agent_identifier_Local\018AD6CC-18A5-4EBE-A3B7-ACE1C7414F52_hvd_agent_start_event_Local\018AD6CC-18A5-4EBE-A3B7-ACE1C7414F52_hvd_agent_shutdown_HvdAgentProcessManagerstart hvdagent process.VDIFramework::HvdAgentProcessManager::startHvdAgentProcesssrc\VDIFramework\src\HVD\HvdAgentProcessManager.cppHVDAgent.dll|hvdagent process started.stop hvdagent process.VDIFramework::HvdAgentProcessManager::stopHvdAgentProcesshvdagent released the appropriate mutex, meaning it has completed the execution.Error: hvdagent has not released the appriate mutex, so it might be still running.hvdagent process is not running, nothing to be terminated.Hvdagent process has not completely exited, will restart it after 3s.VDIFramework::HvdAgentProcessManager::onHvdAgentExitHvdagent process restart count exceeds max value
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3548188494.000001EFB09CE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
Source: CiscoCollabHost.exe, 00000013.00000002.3557908733.00007FFDE6B9E000.00000002.00000001.01000000.00000045.sdmpBinary or memory string: VMWARE
Source: CiscoCollabHost.exe, 00000013.00000002.3563909544.00007FFDE8C54000.00000002.00000001.01000000.00000037.sdmpBinary or memory string: CDirect3D9ExDraw::InitD3D9Ex find a VMware device which driver version is low
Source: CiscoCollabHost.exe, 00000013.00000002.3557908733.00007FFDE6B9E000.00000002.00000001.01000000.00000045.sdmpBinary or memory string: vmwareversion
Source: webex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW@
Source: CiscoCollabHost.exe, 00000013.00000002.3557908733.00007FFDE6B9E000.00000002.00000001.01000000.00000045.sdmpBinary or memory string: VMWare:
Source: CiscoCollabHost.exe, 00000013.00000002.3557908733.00007FFDE6B9E000.00000002.00000001.01000000.00000045.sdmpBinary or memory string: WindowsLinuxMacvc.healthCheck1.0.705.0HealthCheckManager::initHealthCheckManagerBasicVDIFramework::HealthCheckManager::initHealthCheckManagersrc\VDIFramework\src\HVD\VirutalChannelManager\HealthCheckManager.cpponConnectionDeadDetectedVDIFramework::HealthCheckManager::onConnectionLostDetectedonHeartBeatReceived: VDIFramework::HealthCheckManager::onHeartBeatReceivedOnVirtualChannelStateChange: VDIFramework::HealthCheckManager::OnVirtualChannelStateChangeOnSessionStateChange: VDIFramework::HealthCheckManager::OnSessionStateChangeOnVirtualChannelProcessIdReceived: VDIFramework::HealthCheckManager::OnVirtualChannelProcessIdReceivedHVD Agent exited, pid: VDIFramework::HealthCheckManager::onVirtualChannelProcessDiedHealthCheckManager stopped.VDIFramework::HealthCheckManager::OnStreamStateChangeOnThinClientPlatformChange: VDIFramework::HealthCheckManager::OnThinClientPlatformChangeOnChannelBlockedByPolicySetting: VDIFramework::HealthCheckManager::OnChannelBlockedByPolicySettingVDIFramework::HealthCheckManager::OnStreamMessageReceivedreceived unsupported message, but no detail infosVDIFramework::HealthCheckManager::sendMessageToChannel PeerInternal: MyInternal: VMWare: Citrix: HVDAgent: TCPlugin: HVDSDK: TCSDK: ThinClient: HVDClient:VDIFramework::HealthCheckManager::printVersionsCurrent process id:VDIFramework::HealthCheckManager::setHVDClientInfoPeer is legacy version, ignore feature set.VDIFramework::HealthCheckManager::broadcastVirtualChannelStatusPeer is NOT legacy version, merge feature set into virutal channel status.
Source: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exeAPI call chain: ExitProcess graph end nodegraph_18-446
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\SysWOW64\taskkill.exeProcess token adjusted: DebugJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess token adjusted: DebugJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeProcess token adjusted: DebugJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE64DC6B4 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,19_2_00007FFDE64DC6B4
Source: C:\Users\user\Desktop\webex.exeProcess created: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exe "C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exe" /protocolUri="webex://meet/?bt=12&bv=121&cr=065f9a40-5723-45ab-9507-cf2766bb45fe&dns=appleinc.webex.com&en=3&flag=17&jointxid=x7Pbq0RE2n&jt=eyJkdDAiOjE3MTY1NDg2NDIsImR0MSI6Nzk4LCJkdDIiOjIxODUsImR0MyI6MzUzNSwiZHQ0IjoyNDEyODMsImR0NSI6MzcxODI4NTUxLCJkdDYiOjE3MTY5MjA3MjEsImZ0IjoxLCJ0IjoyNSwidXAiOjF9&mtid=m547a808dce8d2d3d893e20fa794cb8a1&od=6f783f73-9637-4b83-90b9-434a5fccb49d&rc=4&sip=24877802128@appleinc.webex.com&siteurl=appleinc&tr=7A2D3FEB1EC64A498D4F669177387376_1709540815837&uuid=04485f8191de4a7c891a7dfe933370dc&vp=0"Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\\taskkill.exe" /F /IM CiscoCollabHost.exe /TJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout /NOBREAK /T 3Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\\taskkill.exe" /F /IM CiscoCollabHost.exe /TJump to behavior
Source: C:\Users\user\Desktop\webex.exeProcess created: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exe "c:\users\user\appdata\local\programs\cisco spark\ciscocollabhost.exe" /protocoluri="webex://meet/?bt=12&bv=121&cr=065f9a40-5723-45ab-9507-cf2766bb45fe&dns=appleinc.webex.com&en=3&flag=17&jointxid=x7pbq0re2n&jt=eyjkddaioje3mty1ndg2ndisimr0msi6nzk4lcjkddiiojixodusimr0myi6mzuznswizhq0ijoyndeyodmsimr0nsi6mzcxodi4ntuxlcjkddyioje3mty5mja3mjesimz0ijoxlcj0ijoynswidxaiojf9&mtid=m547a808dce8d2d3d893e20fa794cb8a1&od=6f783f73-9637-4b83-90b9-434a5fccb49d&rc=4&sip=24877802128@appleinc.webex.com&siteurl=appleinc&tr=7a2d3feb1ec64a498d4f669177387376_1709540815837&uuid=04485f8191de4a7c891a7dfe933370dc&vp=0"
Source: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exeProcess created: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe "c:\users\user\appdata\local\ciscosparklauncher\ciscocollabhost.exe" "c:\users\user\appdata\local\ciscosparklauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1" spark-windows-app.dll /hosted=true "c:\users\user\appdata\local\programs\cisco spark\ciscocollabhost.exe" /protocoluri="webex://meet/?bt=12&bv=121&cr=065f9a40-5723-45ab-9507-cf2766bb45fe&dns=appleinc.webex.com&en=3&flag=17&jointxid=x7pbq0re2n&jt=eyjkddaioje3mty1ndg2ndisimr0msi6nzk4lcjkddiiojixodusimr0myi6mzuznswizhq0ijoyndeyodmsimr0nsi6mzcxodi4ntuxlcjkddyioje3mty5mja3mjesimz0ijoxlcj0ijoynswidxaiojf9&mtid=m547a808dce8d2d3d893e20fa794cb8a1&od=6f783f73-9637-4b83-90b9-434a5fccb49d&rc=4&sip=24877802128@appleinc.webex.com&siteurl=appleinc&tr=7a2d3feb1ec64a498d4f669177387376_1709540815837&uuid=04485f8191de4a7c891a7dfe933370dc&vp=0"
Source: C:\Users\user\Desktop\webex.exeProcess created: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exe "c:\users\user\appdata\local\programs\cisco spark\ciscocollabhost.exe" /protocoluri="webex://meet/?bt=12&bv=121&cr=065f9a40-5723-45ab-9507-cf2766bb45fe&dns=appleinc.webex.com&en=3&flag=17&jointxid=x7pbq0re2n&jt=eyjkddaioje3mty1ndg2ndisimr0msi6nzk4lcjkddiiojixodusimr0myi6mzuznswizhq0ijoyndeyodmsimr0nsi6mzcxodi4ntuxlcjkddyioje3mty5mja3mjesimz0ijoxlcj0ijoynswidxaiojf9&mtid=m547a808dce8d2d3d893e20fa794cb8a1&od=6f783f73-9637-4b83-90b9-434a5fccb49d&rc=4&sip=24877802128@appleinc.webex.com&siteurl=appleinc&tr=7a2d3feb1ec64a498d4f669177387376_1709540815837&uuid=04485f8191de4a7c891a7dfe933370dc&vp=0"Jump to behavior
Source: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exeProcess created: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe "c:\users\user\appdata\local\ciscosparklauncher\ciscocollabhost.exe" "c:\users\user\appdata\local\ciscosparklauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1" spark-windows-app.dll /hosted=true "c:\users\user\appdata\local\programs\cisco spark\ciscocollabhost.exe" /protocoluri="webex://meet/?bt=12&bv=121&cr=065f9a40-5723-45ab-9507-cf2766bb45fe&dns=appleinc.webex.com&en=3&flag=17&jointxid=x7pbq0re2n&jt=eyjkddaioje3mty1ndg2ndisimr0msi6nzk4lcjkddiiojixodusimr0myi6mzuznswizhq0ijoyndeyodmsimr0nsi6mzcxodi4ntuxlcjkddyioje3mty5mja3mjesimz0ijoxlcj0ijoynswidxaiojf9&mtid=m547a808dce8d2d3d893e20fa794cb8a1&od=6f783f73-9637-4b83-90b9-434a5fccb49d&rc=4&sip=24877802128@appleinc.webex.com&siteurl=appleinc&tr=7a2d3feb1ec64a498d4f669177387376_1709540815837&uuid=04485f8191de4a7c891a7dfe933370dc&vp=0"Jump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\Temp VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\Temp VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\calibril.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\calibriz.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\comic.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\comici.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\constan.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\constani.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\cour.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\couri.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\framd.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\Gabriola.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\impact.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\taile.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\pala.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\palai.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\palab.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\ALGER.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\ARLRDBD.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\BELLB.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\BERNHC.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\BOD_I.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\BOD_B.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\BOOKOSI.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\BSSYM7.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\CALIFR.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\CALIFB.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\CURLZ___.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\DUBAI-REGULAR.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\DUBAI-MEDIUM.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\DUBAI-LIGHT.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\DUBAI-BOLD.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\ELEPHNT.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\ENGR.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\ERASMD.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\ERASLGHT.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\FREESCPT.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\FRSCRIPT.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\FTLTLT.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\GARAIT.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\GARABD.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\GOUDOSB.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\HARLOWSI.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\HARNGTON.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\HTOWERT.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\ITCKRIST.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\LFAXD.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\LSANSI.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\LTYPEO.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\MSUIGHUB.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\ONYX.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\PALSCRI.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\PARCHM.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\PER_____.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\RAGE.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\ROCKEB.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\ROCKBI.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\ROCC____.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\ROCCB___.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtGraphicalEffects VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls\Styles VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls\Styles VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls.2 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Dialogs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Dialogs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\x86 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\lib VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls\Styles\Flat VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\accessories VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\accessories VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\accessories VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs\calendar VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs\calendar VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs\calendar VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs\calendar VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs\folderlistmodel VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs\folderlistmodel VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs\qmlmodels VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs\qmlmodels VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs\settings VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt\labs\settings VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtGraphicalEffects VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtGraphicalEffects VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtGraphicalEffects VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtGraphicalEffects VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtGraphicalEffects VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtGraphicalEffects VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtGraphicalEffects VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtGraphicalEffects VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtGraphicalEffects\private VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtGraphicalEffects\private VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtGraphicalEffects\private VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtGraphicalEffects\private VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtGraphicalEffects\private VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtGraphicalEffects\private VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtGraphicalEffects\private VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtGraphicalEffects\private VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtGraphicalEffects VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtMultimedia VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtMultimedia VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtMultimedia VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml\Models.2 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml\Models.2 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml\RemoteObjects VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml\StateMachine VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQml VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls\Private VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls\Private VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls\Private VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls\Private VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls\Private VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls\Private VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\QtQuick\Controls VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\webex.exeQueries volume information: C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies VolumeInformationJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeKey value queried: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation TimeZoneKeyNameJump to behavior
Source: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exeCode function: 18_2_00007FF7EC6B1FE0 GetSystemTime,GetDateFormatEx,GetTimeFormatEx,18_2_00007FF7EC6B1FE0
Source: C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exeCode function: 18_2_00007FF7EC6B2300 GetUserNameW,SHGetKnownFolderPath,lstrlenW,WriteFile,18_2_00007FF7EC6B2300
Source: C:\Users\user\Desktop\webex.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
Source: C:\Windows\System32\msiexec.exeRegistry key created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54 BlobJump to behavior
Source: C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exeCode function: 19_2_00007FFDE660E3F0 ??1?$QVector@VQPointF@@@@QEAA@XZ,AddClipboardFormatListener,?qErrnoWarning@@YAXPEBDZZ,SetClipboardViewer,?isDebugEnabled@QLoggingCategory@@QEBA_NXZ,??0QMessageLogger@@QEAA@PEBDH00@Z,?debug@QMessageLogger@@QEBA?AVQDebug@@XZ,??6QDebug@@QEAAAEAV0@PEBD@Z,??6QDebug@@QEAAAEAV0@PEBD@Z,??6QDebug@@QEAAAEAV0@PEBX@Z,??6QDebug@@QEAAAEAV0@PEBD@Z,??6QDebug@@QEAAAEAV0@_N@Z,??6QDebug@@QEAAAEAV0@PEBD@Z,??6QDebug@@QEAAAEAV0@PEBX@Z,??1QDebug@@QEAA@XZ,19_2_00007FFDE660E3F0
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
1
Windows Management Instrumentation
1
DLL Side-Loading
1
DLL Side-Loading
2
Disable or Modify Tools
2
Input Capture
11
System Time Discovery
Remote Services1
Archive Collected Data
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault Accounts12
Command and Scripting Interpreter
1
DLL Search Order Hijacking
1
DLL Search Order Hijacking
21
Obfuscated Files or Information
LSASS Memory11
Peripheral Device Discovery
Remote Desktop Protocol2
Input Capture
Junk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAt1
Windows Service
1
Windows Service
21
Software Packing
Security Account Manager1
Account Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCron1
Registry Run Keys / Startup Folder
11
Process Injection
1
Timestomp
NTDS1
File and Directory Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script1
Registry Run Keys / Startup Folder
1
DLL Side-Loading
LSA Secrets25
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
DLL Search Order Hijacking
Cached Domain Credentials1
Query Registry
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items11
File Deletion
DCSync11
Security Software Discovery
Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job21
Masquerading
Proc Filesystem2
Virtualization/Sandbox Evasion
Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt1
Modify Registry
/etc/passwd and /etc/shadow1
Process Discovery
Direct Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
IP AddressesCompromise InfrastructureSupply Chain CompromisePowerShellCronCron2
Virtualization/Sandbox Evasion
Network Sniffing11
Application Window Discovery
Shared WebrootLocal Data StagingFile Transfer ProtocolsExfiltration Over Asymmetric Encrypted Non-C2 ProtocolExternal Defacement
Network Security AppliancesDomainsCompromise Software Dependencies and Development ToolsAppleScriptLaunchdLaunchd11
Process Injection
Input Capture1
System Owner/User Discovery
Software Deployment ToolsRemote Data StagingMail ProtocolsExfiltration Over Unencrypted Non-C2 ProtocolFirmware Corruption
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1447090 Sample: webex.exe Startdate: 24/05/2024 Architecture: WINDOWS Score: 39 63 Antivirus / Scanner detection for submitted sample 2->63 8 webex.exe 16 902 2->8         started        13 msiexec.exe 115 65 2->13         started        process3 dnsIp4 53 170.72.245.107 FEDMOG-ASN-01US United States 8->53 55 170.72.245.220 FEDMOG-ASN-01US United States 8->55 57 2 other IPs or domains 8->57 37 C:\Users\...\CiscoSparkLauncher.dll (copy), PE32+ 8->37 dropped 39 C:\Users\user\...\spark-windows-media.dll, PE32+ 8->39 dropped 41 C:\Users\...\spark-windows-desktop-ui.dll, PE32+ 8->41 dropped 49 184 other files (none is malicious) 8->49 dropped 65 Self deletion via cmd or bat file 8->65 15 CiscoCollabHost.exe 7 8->15         started        17 cmd.exe 1 8->17         started        19 msiexec.exe 8->19         started        43 C:\Windows\Installer\MSICBCC.tmp, PE32 13->43 dropped 45 C:\Windows\Installer\MSICB5D.tmp, PE32 13->45 dropped 47 C:\Users\user\AppData\...\CiscoCollabHost.exe, PE32+ 13->47 dropped 21 msiexec.exe 13->21         started        23 msiexec.exe 1 13->23         started        file5 signatures6 process7 process8 25 CiscoCollabHost.exe 56 15->25         started        29 conhost.exe 17->29         started        31 timeout.exe 1 17->31         started        33 taskkill.exe 1 21->33         started        dnsIp9 59 18.66.112.32 MIT-GATEWAYSUS United States 25->59 61 144.196.56.82 CHINATELECOM-SHANDONG-QINGDAO-IDCQingdao266000CN United States 25->61 51 MicrosoftEdgeWebVi...r_118.0.2088.69.exe, PE32 25->51 dropped 35 conhost.exe 33->35         started        file10 process11

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
webex.exe100%AviraDR/Delphi.Gen
SourceDetectionScannerLabelLink
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\CiscoSparkLauncher.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\bin\concrt140.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\bin\msvcp140.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\bin\msvcp140_1.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\bin\msvcp140_2.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\bin\msvcp140_atomic_wait.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\bin\msvcp140_codecvt_ids.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\bin\vcruntime140.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\bin\vcruntime140_1.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\CiscoLocalRecordConverter.exe0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\CiscoWebExStart.exe0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\CitrixServer.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Common-HvdAgent.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Common-VDIFramework.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\ConfigService.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\DCVServer.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\EventBus.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\HVDAgent.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\HttpDownloader.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\JCFCoreUtils.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\KF5SyntaxHighlighting.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\LadonSDK.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\LambdaThreadSwitcher.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\MJPGDecoder.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\MKLDNNPlugin.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\MeetingContainerActivityStreamType.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\ProcessCleaner.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5Core.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5Gui.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5Multimedia.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5MultimediaQuick.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5MultimediaWidgets.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5Network.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5OpenGL.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5Qml.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5QmlModels.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5QmlWorkerScript.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5Quick.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5QuickControls2.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5QuickShapes.dll0%ReversingLabs
C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\dependencies\Qt5QuickTemplates2.dll0%ReversingLabs
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://repository.swisssign.com/00%URL Reputationsafe
http://www.zhongyicts.com.cn0%URL Reputationsafe
http://policy.camerfirma.com00%URL Reputationsafe
http://crl.micro0%URL Reputationsafe
http://crl.xrampsecurity.com/XGCA.crl00%URL Reputationsafe
http://www.firmaprofesional.com/cps00%URL Reputationsafe
http://crl.securetrust.com/SGCA.crl00%URL Reputationsafe
http://crl.securetrust.com/STCA.crl00%URL Reputationsafe
https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/WebexStub.msi0%Avira URL Cloudsafe
https://binaries.webex.com/PowerShe0%Avira URL Cloudsafe
https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20231018100743/WebexVDIPlugin_x86.7z0%Avira URL Cloudsafe
https://metrics-a.wbx2.comi0%Avira URL Cloudsafe
https://go.webex.com/go/globalcallin.php?serviceType=MC&eventID=169900787&tollFree=10%Avira URL Cloudsafe
http://www.msftncsi.com/ncsi.txt0%Avira URL Cloudsafe
https://binaries.webex.com/WebexDesktop-Win-64-MV-Gold/20240514195518/WebexTeams.7zfa0%Avira URL Cloudsafe
https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/WebexStub.msi0%VirustotalBrowse
https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20231018100743/WebexVDIPlugin_x86.7z0%VirustotalBrowse
https://sdk.bitmoji.com/me/sticker/0%Avira URL Cloudsafe
https://cisco.com/go/schedule-meetings-from-outlook0%Avira URL Cloudsafe
https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20240219145217/WebexVDIPlugin_x86.7z0%Avira URL Cloudsafe
http://www.msftncsi.com/ncsi.txt0%VirustotalBrowse
https://sdk.bitmoji.com/me/sticker/0%VirustotalBrowse
https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20221110032238/WebexVDIPlugin.7z0%Avira URL Cloudsafe
https://cisco.com/go/schedule-meetings-from-outlook0%VirustotalBrowse
https://client-upgrade-a.wbx2.com0%Avira URL Cloudsafe
https://u2c.gov.ciscospark.com/u2c/api/v10%Avira URL Cloudsafe
https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20240219145217/WebexVDIPlugin_x86.7z0%VirustotalBrowse
https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20221110032238/WebexVDIPlugin.7z0%VirustotalBrowse
https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20221207133244/WebexVDIPlugin.7z0%Avira URL Cloudsafe
https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20231211114034/WebexVDIPlugin.7z0%Avira URL Cloudsafe
https://client-upgrade-a.wbx2.com0%VirustotalBrowse
https://go.webex.com/go/globalcallin.php?serviceType=MC&eventID=169900787&tollFree=10%VirustotalBrowse
https://binaries.webex.com/nager.cpw0%Avira URL Cloudsafe
https://u2c.gov.ciscospark.com/u2c/api/v10%VirustotalBrowse
https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/WebexTeamsPatchUpgrade_1.7zE0%Avira URL Cloudsafe
https://binaries.webex.com:443/static-content-pipeline/webex-app-resources/44.5/translations/spark-w0%Avira URL Cloudsafe
https://status.webex.com/incidents0%Avira URL Cloudsafe
https://binaries.webex.com/mpany0%Avira URL Cloudsafe
https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20231211114034/WebexVDIPlugin.7z0%VirustotalBrowse
https://binaries.webex.com/static-content-pipeline/webex-app-resources/44.5/translations/manifest.jw0%Avira URL Cloudsafe
https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20221207133244/WebexVDIPlugin.7z0%VirustotalBrowse
http://link.com0%Avira URL Cloudsafe
http://www.tiro.comMicrosoft0%Avira URL Cloudsafe
http://www.jiyu-kobo.co.jp/Microsoft0%Avira URL Cloudsafe
https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/DynamicComponent-xnn_engine.7z0%Avira URL Cloudsafe
https://help.webex.com/en-us/article/n6fwepj/Where-is-Webex-available?#id_982900%Avira URL Cloudsafe
https://webex.meeting.com/meet/longname0%Avira URL Cloudsafe
http://www.jiyu-kobo.co.jp/Microsoft0%VirustotalBrowse
https://status.webex.com/incidents0%VirustotalBrowse
https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/DynamicComponent-xnn_engine.7z0%VirustotalBrowse
http://www.qt.io/contact-us.0%Avira URL Cloudsafe
https://www.bitmoji.com/sign-up0%Avira URL Cloudsafe
https://www.webex.com/license.html0%VirustotalBrowse
https://www.bitmoji.com/connect0%VirustotalBrowse
https://www.bitmoji.com/sign-up0%VirustotalBrowse
http://www.qt.io/contact-us.0%VirustotalBrowse
https://help.webex.com/en-us/article/n6fwepj/Where-is-Webex-available?#id_982900%VirustotalBrowse
https://webex.meeting.com/meet/longname0%VirustotalBrowse
https://www.bitmoji.com/connect0%Avira URL Cloudsafe
http://link.com0%VirustotalBrowse
https://www.webex.com/license.html0%Avira URL Cloudsafe
http://www.cisco.com/security/pki/certs/crcam1.cer00%Avira URL Cloudsafe
https://u2c.gov.ciscospark.com/u2c/api/v1/ndard0%Avira URL Cloudsafe
https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/WebexStub.msi7z0%Avira URL Cloudsafe
http://www.gnu.org/licenses/gpl-2.0.html.0%Avira URL Cloudsafe
http://protocols.cisco.com/virtualid0%Avira URL Cloudsafe
https://www.gnu.org/licenses/lgpl.html.0%Avira URL Cloudsafe
http://www.gnu.org/licenses/gpl-2.0.html.0%VirustotalBrowse
https://www.gnu.org/licenses/lgpl.html.0%VirustotalBrowse
http://www.cisco.com/security/pki/certs/crcam1.cer00%VirustotalBrowse
https://go.webex.com/meeting/barbara0%Avira URL Cloudsafe
https://cisco.com/go/webex-restricted-networks0%Avira URL Cloudsafe
http://protocols.cisco.com/virtualid0%VirustotalBrowse
http://www.html-tidy.org0%Avira URL Cloudsafe
https://go.webex.com/meeting/barbara0%VirustotalBrowse
https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/WebexTeams.7z-a.wbx2.com0%Avira URL Cloudsafe
https://snap.com/en-US/privacy/privacy-policy0%Avira URL Cloudsafe
http://protocols.cisco.com/timestamp#100usn0%Avira URL Cloudsafe
https://help.webex.com/n0qtkri0%Avira URL Cloudsafe
https://www.bitmoji.com/avatarR0%Avira URL Cloudsafe
http://www.html-tidy.org0%VirustotalBrowse
https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20230216133805/WebexVDIPlugin.7z0%Avira URL Cloudsafe
https://u2c.gov.ciscospark.com/u2c/api/v1/ndard0%VirustotalBrowse
https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/WebexTeams.7z0%Avira URL Cloudsafe
https://u2c.gov.ciscospark.com/u2c/api/v1/0%Avira URL Cloudsafe
https://cisco.com/go/webex-restricted-networks0%VirustotalBrowse
https://binaries.webex.com/LOCALAPP0%Avira URL Cloudsafe
http://protocols.cisco.com/priority0%Avira URL Cloudsafe
https://help.webex.com/ld-n0bl93g-CiscoWebexTeams/Webex-Teams-App?omiReferProduct=WebexTeams0%Avira URL Cloudsafe
https://web.webex.com/deviceAuth?0%Avira URL Cloudsafe
https://www.bitmoji.com/connectW0%Avira URL Cloudsafe
https://binaries.webex.comD)0%Avira URL Cloudsafe
https://www.qt.io/contact-us.0%Avira URL Cloudsafe
https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20231211114034/WebexVDIPlugin_x86.7z0%Avira URL Cloudsafe
https://bitmoji.api.snapchat.com/direct/pack/0%Avira URL Cloudsafe
https://client-upgrade-a.wbx2.com/client-upgrade/api/v10%Avira URL Cloudsafe
https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/Webex.exe0%Avira URL Cloudsafe
https://sdk.bitmoji.com0%Avira URL Cloudsafe
http://protocols.cisco.com/virtualidhttp://protocols.cisco.com/framemarkingurn:ietf:params:rtp-hdrex0%Avira URL Cloudsafe
http://www.cisco.com/c/en/us/about/legal/privacy.html0%Avira URL Cloudsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://binaries.webex.com/PowerSheCiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB0860000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://go.webex.com/go/globalcallin.php?serviceType=MC&eventID=169900787&tollFree=1CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20231018100743/WebexVDIPlugin_x86.7zCiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://metrics-a.wbx2.comiCiscoCollabHost.exe, 00000013.00000002.3548188494.000001EFB099A000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/WebexStub.msiwebex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/WebexDesktop-Win-64-MV-Gold/20240514195518/WebexTeams.7zfawebex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://www.msftncsi.com/ncsi.txtCiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
http://repository.swisssign.com/0webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
https://sdk.bitmoji.com/me/sticker/CiscoCollabHost.exe, 00000013.00000002.3543096123.000001EFAFFC3000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://cisco.com/go/schedule-meetings-from-outlookCiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20240219145217/WebexVDIPlugin_x86.7zCiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20221110032238/WebexVDIPlugin.7zCiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://client-upgrade-a.wbx2.comwebex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://u2c.gov.ciscospark.com/u2c/api/v1CiscoCollabHost.exe, 00000013.00000002.3542641508.000001EFAFDD3000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20221207133244/WebexVDIPlugin.7zCiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20231211114034/WebexVDIPlugin.7zCiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/nager.cpwwebex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/WebexTeamsPatchUpgrade_1.7zEwebex.exe, 00000000.00000003.2032458997.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1948632756.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1706246150.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1979201557.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032844232.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1982453215.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2095203618.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2813652807.00000000013EB000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.00000000013E0000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com:443/static-content-pipeline/webex-app-resources/44.5/translations/spark-wCiscoCollabHost.exe, 00000013.00000002.3551507487.000001EFB3A91000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://status.webex.com/incidentsCiscoCollabHost.exe, 00000013.00000002.3543096123.000001EFAFFC3000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/mpanywebex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/static-content-pipeline/webex-app-resources/44.5/translations/manifest.jwCiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB087F000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://link.comCiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
http://www.tiro.comMicrosoftCiscoCollabHost.exe, 00000013.00000002.3549659031.000001EFB0F2C000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://www.jiyu-kobo.co.jp/MicrosoftCiscoCollabHost.exe, 00000013.00000002.3543772157.000001EFB01DE000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/DynamicComponent-xnn_engine.7zwebex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1706246150.00000000013E0000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://help.webex.com/en-us/article/n6fwepj/Where-is-Webex-available?#id_98290CiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB0860000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://webex.meeting.com/meet/longnameCiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
http://www.zhongyicts.com.cnCiscoCollabHost.exe, 00000013.00000002.3551254415.000001EFB395A000.00000004.00000020.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
http://www.qt.io/contact-us.webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://www.bitmoji.com/sign-upCiscoCollabHost.exe, 00000013.00000002.3540066323.000001EFAF5F5000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
http://policy.camerfirma.com0webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
https://www.bitmoji.com/connectCiscoCollabHost.exe, 00000013.00000002.3540066323.000001EFAF5F5000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://www.webex.com/license.htmlCiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://u2c.gov.ciscospark.com/u2c/api/v1/ndardCiscoCollabHost.exe, 00000013.00000002.3544482263.000001EFB042C000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/WebexStub.msi7zwebex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://www.cisco.com/security/pki/certs/crcam1.cer0webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3541683541.000001EFAFA16000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
http://www.gnu.org/licenses/gpl-2.0.html.webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://www.gnu.org/licenses/lgpl.html.webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
http://protocols.cisco.com/virtualidCiscoCollabHost.exe, 00000013.00000002.3539279947.000001EFAF190000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3560651202.00007FFDE8109000.00000002.00000001.01000000.00000040.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://go.webex.com/meeting/barbaraCiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://cisco.com/go/webex-restricted-networksCiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
http://www.html-tidy.orgwebex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/WebexTeams.7z-a.wbx2.comwebex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://snap.com/en-US/privacy/privacy-policyCiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://protocols.cisco.com/timestamp#100usnCiscoCollabHost.exe, 00000013.00000002.3539279947.000001EFAF190000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://help.webex.com/n0qtkriCiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://www.bitmoji.com/avatarRCiscoCollabHost.exe, 00000013.00000002.3540066323.000001EFAF5F5000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20230216133805/WebexVDIPlugin.7zCiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/WebexTeams.7zwebex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://u2c.gov.ciscospark.com/u2c/api/v1/CiscoCollabHost.exe, 00000013.00000002.3544482263.000001EFB042C000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/LOCALAPPCiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB0860000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://protocols.cisco.com/priorityCiscoCollabHost.exe, 00000013.00000002.3560651202.00007FFDE8109000.00000002.00000001.01000000.00000040.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://help.webex.com/ld-n0bl93g-CiscoWebexTeams/Webex-Teams-App?omiReferProduct=WebexTeamsCiscoCollabHost.exe, 00000013.00000002.3548188494.000001EFB09E0000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://crl.microCiscoCollabHost.exe, 00000013.00000002.3549445254.000001EFB0EBA000.00000004.00000020.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
https://web.webex.com/deviceAuth?CiscoCollabHost.exe, 00000013.00000002.3544315068.000001EFB03D4000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://www.bitmoji.com/connectWCiscoCollabHost.exe, 00000013.00000002.3540066323.000001EFAF5F5000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.comD)CiscoCollabHost.exe, 00000013.00000002.3544235755.000001EFB038E000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://www.qt.io/contact-us.webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://crl.xrampsecurity.com/XGCA.crl0webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20231211114034/WebexVDIPlugin_x86.7zCiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://bitmoji.api.snapchat.com/direct/pack/CiscoCollabHost.exe, 00000013.00000002.3543096123.000001EFAFFC3000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://client-upgrade-a.wbx2.com/client-upgrade/api/v1CiscoCollabHost.exe, 00000013.00000002.3541455192.000001EFAF935000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/Webex.exewebex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://sdk.bitmoji.comCiscoCollabHost.exe, 00000013.00000002.3540066323.000001EFAF5F5000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://protocols.cisco.com/virtualidhttp://protocols.cisco.com/framemarkingurn:ietf:params:rtp-hdrexCiscoCollabHost.exe, 00000013.00000002.3560651202.00007FFDE8109000.00000002.00000001.01000000.00000040.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://reachable.webex.comUCiscoCollabHost.exe, 00000013.00000002.3542700270.000001EFAFE23000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://www.cisco.com/c/en/us/about/legal/privacy.htmlCiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB0860000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://www.qt.io/terms-conditions.webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://metrics-a.wbx2.comCiscoCollabHost.exe, 00000013.00000002.3548188494.000001EFB099A000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3536542014.000000DFB04FD000.00000004.00000010.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3548188494.000001EFB097E000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://alpha.webex.com/alpha-sc/j.php?MTID=m2a40b18df319615a16fefa5d8d4df1ebCiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/JLwebex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://www.ciscospark.com/plans.htmlCiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/WebexDesktop-VDI-Win-32-Gold/20231018100743/WebexVDIPlugin.7zCiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/WebexDesktop-Win-64-Gold/20240514192927/WebexTeamsPatchUpgrade_3.7zwebex.exe, 00000000.00000003.1706246150.00000000013DB000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://www.cisco.com/c/en/us/about/legal/privacy-full.htmlreLoCiscoCollabHost.exe, 00000013.00000002.3550823039.000001EFB3826000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://protocols.cisco.com/timestamp#100usCiscoCollabHost.exe, 00000013.00000002.3539279947.000001EFAF190000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3560651202.00007FFDE8109000.00000002.00000001.01000000.00000040.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://www.qt.io/licensing/webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB0842000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3545166079.000001EFB07B0000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3544235755.000001EFB038E000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB0860000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://go.webexCiscoCollabHost.exe, 00000013.00000002.3551507487.000001EFB3A91000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://idbroker.webex.comCiscoCollabHost.exe, 00000013.00000002.3542700270.000001EFAFE23000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3544235755.000001EFB038E000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://www.bitmoji.com/avatarCiscoCollabHost.exe, 00000013.00000002.3540066323.000001EFAF5F5000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://u2c.wbx2.com/u2c/api/v1CiscoCollabHost.exe, 00000013.00000002.3542700270.000001EFAFE23000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3544235755.000001EFB038E000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/WebexDesktop-VDI-Win-64-Gold/20230906100245/WebexVDIPlugin_x86.7zCiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://appleinc.webex.comvCiscoCollabHost.exe, 00000013.00000002.3548188494.000001EFB097E000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://cisco.com/go/smart-audio-settingsCiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://atlas-api-a.wbx2.com/admin/api/v1CiscoCollabHost.exe, 00000013.00000002.3544628106.000001EFB04C0000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://ds.ciscospark.comhwebex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://support.ciscospark.com/customer/en/portal/articles/1911657-firewall-and-network-requirementsCiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmp, CiscoCollabHost.exe, 00000013.00000002.3545415184.000001EFB0860000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://metrics-a.wbx2.com/metrics/api/v1/clientmetrics-preloginCiscoCollabHost.exe, 00000013.00000002.3548188494.000001EFB099A000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://www.firmaprofesional.com/cps0webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
https://test.webex.com/meet/pmrlinkCiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://go.webex.com/m/35cf15b4-8b8c-4a99-b33f-20d086d2CiscoCollabHost.exe, 00000013.00000003.3419221960.000001EFB4ACB000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/WebexDesktop-VDI-Win-64-Gold/20230713030330/WebexVDIPlugin_x86.7zCiscoCollabHost.exe, 00000013.00000002.3542615898.000001EFAFDB5000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://crl.securetrust.com/SGCA.crl0webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
https://binaries.webex.com/BCiscoCollabHost.exe, 00000013.00000002.3545166079.000001EFB07B0000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://protocols.cisco.com/namedmediagrouplistCiscoCollabHost.exe, 00000013.00000002.3560651202.00007FFDE8109000.00000002.00000001.01000000.00000040.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://binaries.webex.com/Cwebex.exe, 00000000.00000003.1994943691.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2164822879.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2815671744.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.2032458997.000000000136F000.00000004.00000020.00020000.00000000.sdmp, webex.exe, 00000000.00000003.1976435661.000000000136F000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://crl.securetrust.com/STCA.crl0webex.exe, 00000000.00000003.2948404053.000000000929B000.00000004.00000020.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
https://www.snapchat.com/bitmojiCiscoCollabHost.exe, 00000013.00000002.3540066323.000001EFAF5F5000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
3.161.119.106
unknownUnited States
16509AMAZON-02USfalse
170.133.160.218
unknownUnited States
1344513445USfalse
170.72.245.220
unknownUnited States
16761FEDMOG-ASN-01USfalse
144.196.56.82
unknownUnited States
58541CHINATELECOM-SHANDONG-QINGDAO-IDCQingdao266000CNfalse
18.66.112.32
unknownUnited States
3MIT-GATEWAYSUSfalse
170.72.245.107
unknownUnited States
16761FEDMOG-ASN-01USfalse
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1447090
Start date and time:2024-05-24 11:27:58 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 12m 26s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Run name:Run with higher sleep bypass
Number of analysed new started processes analysed:20
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:webex.exe
Detection:SUS
Classification:sus39.evad.winEXE@20/756@0/6
EGA Information:
  • Successful, ratio: 66.7%
HCA Information:
  • Successful, ratio: 79%
  • Number of executed functions: 87
  • Number of non-executed functions: 42
Cookbook Comments:
  • Found application associated with file extension: .exe
  • Sleeps bigger than 100000000ms are automatically reduced to 1000ms
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
  • Execution Graph export aborted for target webex.exe, PID 7256 because there are no executed function
  • Not all processes where analyzed, report is missing behavior information
  • Report creation exceeded maximum time and may have missing disassembly code information.
  • Report size exceeded maximum capacity and may have missing behavior information.
  • Report size getting too big, too many NtOpenFile calls found.
  • Report size getting too big, too many NtOpenKeyEx calls found.
  • Report size getting too big, too many NtProtectVirtualMemory calls found.
  • Report size getting too big, too many NtQueryValueKey calls found.
  • Report size getting too big, too many NtQueryVolumeInformationFile calls found.
  • Skipping network analysis since amount of network traffic is too extensive
TimeTypeDescription
05:29:36API Interceptor503488x Sleep call for process: webex.exe modified
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
170.72.245.220webex.exeGet hashmaliciousUnknownBrowse
    webex.exeGet hashmaliciousUnknownBrowse
      webex.exeGet hashmaliciousUnknownBrowse
        18.66.112.32https://knowledgeburrow.com/did-benjamin-franklin-really-say-if-you-fail-to-plan-you-are-planning-to-fail/Get hashmaliciousUnknownBrowse
          170.72.245.107https://webex-install.comGet hashmaliciousNetSupport RATBrowse
            No context
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            AMAZON-02UShttp://waitroseentertainokpf.comGet hashmaliciousUnknownBrowse
            • 52.219.128.176
            https://degroofpetercam.sharefile.eu/f/foeaa098-ab4a-4383-832f-352520075f87?a=adfc24f975fb17a5Get hashmaliciousUnknownBrowse
            • 18.238.217.78
            http://18.158.249.75Get hashmaliciousUnknownBrowse
            • 18.158.249.75
            https://deref-mail.com/mail/client/j_iGygdK9BI/dereferrer/?redirectUrl=Get hashmaliciousUnknownBrowse
            • 108.138.26.74
            3oLSV0THh9.elfGet hashmaliciousGafgyt, MiraiBrowse
            • 34.243.160.129
            Ref_FTD431100.xlsGet hashmaliciousRemcosBrowse
            • 54.241.153.192
            sample.htmlGet hashmaliciousHTMLPhisherBrowse
            • 13.32.99.97
            https://perspectivefunnel.co/664fc385b6e1a200142f71ee/664fc45e205ea60014803d49/Get hashmaliciousUnknownBrowse
            • 13.224.189.74
            nF54KOU30R.exeGet hashmaliciousRHADAMANTHYSBrowse
            • 104.192.141.1
            https://www.unsubv1.site/Get hashmaliciousUnknownBrowse
            • 54.73.26.109
            13445USzsIELy6nuP.elfGet hashmaliciousMiraiBrowse
            • 150.253.133.47
            https://webex-install.comGet hashmaliciousNetSupport RATBrowse
            • 170.133.151.21
            webex.exeGet hashmaliciousUnknownBrowse
            • 173.243.0.162
            webex.exeGet hashmaliciousUnknownBrowse
            • 170.133.151.21
            QDpFqspZaI.elfGet hashmaliciousMiraiBrowse
            • 114.29.218.228
            trxCo4P1wV.elfGet hashmaliciousMiraiBrowse
            • 64.68.116.24
            TduoIaOsBQ.elfGet hashmaliciousUnknownBrowse
            • 150.253.157.58
            qCgtVyWfS6.elfGet hashmaliciousMiraiBrowse
            • 64.68.116.234
            begi6epHVb.elfGet hashmaliciousMiraiBrowse
            • 150.253.175.175
            webex.exeGet hashmaliciousUnknownBrowse
            • 170.133.151.21
            CHINATELECOM-SHANDONG-QINGDAO-IDCQingdao266000CNqwmLv2FcgD.elfGet hashmaliciousUnknownBrowse
            • 144.18.155.5
            jZ6ejWIrSV.elfGet hashmaliciousGafgyt, MiraiBrowse
            • 103.203.97.65
            tZCXYB2uGD.elfGet hashmaliciousGafgyt, MiraiBrowse
            • 103.203.97.32
            d3j5Qle8Zv.elfGet hashmaliciousUnknownBrowse
            • 144.24.166.220
            wget.elfGet hashmaliciousGafgytBrowse
            • 103.203.97.69
            cron.elfGet hashmaliciousGafgytBrowse
            • 103.203.97.32
            KlDqtLWXHA.elfGet hashmaliciousMiraiBrowse
            • 144.9.162.153
            icgYDPuGqT.elfGet hashmaliciousMiraiBrowse
            • 144.20.235.246
            Document.exeGet hashmaliciousMyDoomBrowse
            • 144.197.77.78
            byKLI4nzv2.elfGet hashmaliciousMiraiBrowse
            • 144.151.201.46
            FEDMOG-ASN-01USdn7MMSZM9O.elfGet hashmaliciousUnknownBrowse
            • 170.69.47.201
            Roberts+Onsite.emlGet hashmaliciousUnknownBrowse
            • 170.64.147.92
            S6hCRsyPaN.elfGet hashmaliciousMiraiBrowse
            • 170.72.212.10
            aowNKqhrAX.elfGet hashmaliciousMiraiBrowse
            • 170.64.69.113
            Doco.docGet hashmaliciousHTMLPhisherBrowse
            • 170.64.230.178
            V2wHPAgAHF.elfGet hashmaliciousMiraiBrowse
            • 170.64.69.104
            ccm9HqTuky.elfGet hashmaliciousMiraiBrowse
            • 134.239.101.41
            https://webex-install.comGet hashmaliciousNetSupport RATBrowse
            • 170.72.245.169
            x86.elfGet hashmaliciousMiraiBrowse
            • 170.74.23.37
            PcYRqnCfZK.elfGet hashmaliciousMiraiBrowse
            • 170.74.23.67
            No context
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\bin\msvcp140.dllqk9TaBBxh8.exeGet hashmaliciousLummaC, Glupteba, Mars Stealer, PureLog Stealer, RedLine, RisePro Stealer, SmokeLoaderBrowse
              xSO7sbN2j6.exeGet hashmaliciousUnknownBrowse
                xSO7sbN2j6.exeGet hashmaliciousUnknownBrowse
                  SecuriteInfo.com.Win64.Evo-gen.32634.31069.exeGet hashmaliciousLummaC, Glupteba, LummaC Stealer, Mars Stealer, PureLog Stealer, RedLine, RisePro StealerBrowse
                    whisper-faster.exeGet hashmaliciousUnknownBrowse
                      whisper-faster.exeGet hashmaliciousUnknownBrowse
                        webex.exeGet hashmaliciousUnknownBrowse
                          webex.exeGet hashmaliciousUnknownBrowse
                            ZzutQz4T6D.exeGet hashmaliciousMars Stealer, Stealc, VidarBrowse
                              webex.exeGet hashmaliciousUnknownBrowse
                                C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\bin\concrt140.dllwebex.exeGet hashmaliciousUnknownBrowse
                                  webex.exeGet hashmaliciousUnknownBrowse
                                    webex.exeGet hashmaliciousUnknownBrowse
                                      webex.exeGet hashmaliciousUnknownBrowse
                                        webex.exeGet hashmaliciousUnknownBrowse
                                          webex.exeGet hashmaliciousUnknownBrowse
                                            main.jsGet hashmaliciousUnknownBrowse
                                              main.jsGet hashmaliciousUnknownBrowse
                                                2646fef76ae933018ff8a48e7c46c4ae6a82176107f7d.exeGet hashmaliciousNetSupport RATBrowse
                                                  KCWggPUR7S.exeGet hashmaliciousUnknownBrowse
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:data
                                                    Category:modified
                                                    Size (bytes):24431
                                                    Entropy (8bit):5.943286172256805
                                                    Encrypted:false
                                                    SSDEEP:384:C+hu4t+Q5eQvG8z7jGc0mlmSRjIXGytV63mK3IA06YUUJALl7ciBLBhmALklu4tY:C+huIn5eQvG8njGc0mlmSR8XGSV63mKB
                                                    MD5:502D9D8F8086CDA5CCCA3250C8272506
                                                    SHA1:75A8D02694CBD92AF5A45B1CD741684440F146AF
                                                    SHA-256:94A97265953F2162E5BC1D374AC32AFA958D2328D4887A1C8B8BBB88EDF6BFC1
                                                    SHA-512:6668A717F4C9C343B9A5B673FD7A471F216591E6AC417F85E4B1ABEEB2B0D93596D091C3C20ADC47DD8FA78287CF0DB1E3E36C0B7B9A0047CF44C08A04A549B0
                                                    Malicious:false
                                                    Reputation:low
                                                    Preview:...@IXOS.@.....@.+.X.@.....@.....@.....@.....@.....@......&.{4A82B9CC-F7B3-5000-9CA4-89764C5A9DA4}..Webex(.c64e3759-805b-47c0-b4ab-a6ec7fecd393.msi.@.....@...,.@.....@......ProductIcon.ico..&.{CB8E6878-4597-4DED-84BE-E35CC89B823D}.....@.....@.....@.....@.......@.....@.....@.......@......Webex......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....RollbackLPRFirewallRulesL...RollbackLPRFirewallRules.@F.....Const HKEY_LOCAL_MACHINE = &H80000002..Const msiDoActionStatusSuccess = 1..const vbQuote = """"..Const WebexProgram = "CiscoCollabHost.exe"..Const ProductWebex = "Webex"..Const ProductMeetings = "Cisco Webex Meetings"....Dim LPRAllUsers, NotInstalled, RemoveAll, InstallFolder, IsWebexBundle....Function UpdateLPRFirewallRules().... On Error Resume Next.....call GetMsiProperties()......If LPRAllUsers and NotInstalled Then....call AddWebexLPRFirewallRules()....call AddMeetingsLPRFirewallRules()...End If.....If LPRAllUsers and Not NotInstalled an
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):2732656
                                                    Entropy (8bit):6.796196817967675
                                                    Encrypted:false
                                                    SSDEEP:49152:jGtlqYIU6iOVwASOOQFK0uigyFGHT9sbWj5x/VTEybcosxWhE6zY6EdPFbHcB:R+0F2R0W7/SZoYWU6Eng
                                                    MD5:D46B787A90104FA0B7BF8694F76D5C76
                                                    SHA1:34D275503E5000732EA71DA5BD5B3207053E3F5E
                                                    SHA-256:5A44D14A6435F04486621294EB59A5CB6853416A375D9567DF21F255E7C68A6A
                                                    SHA-512:BDBDF622ACE60B59468F00BE7DB5EC67A2F612D3CDC67C702E636FF28A6F007FC1F3F6FD45A9BB864A39E60D951AB8F5DCF32399211A6E723C97A9FEE290766D
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Reputation:low
                                                    Preview:MZ......................@...................................0...........!..L.!This program cannot be run in DOS mode....$........]..<..<..<.EN..<.EN.S<.2B..<.2B..<.2B..<.EN..<.EN..<..<..<..N.I=..C..<.EN..<..<..=..C..<..C..<..C3..<..C..<.Rich.<.........................PE..d....dCf.........." ...$.....T...............................................0*.....L.*...`A..........................................'.\.....'.......).......(.......).p ....).$Z...6&.p....................7&.(...@5&.@............................................text............................... ..`.rdata..@9.......:..................@..@.data.........'..N....'.............@....pdata........(.......(.............@..@_RDATA..\.....)......2).............@..@.rsrc.........)......4).............@..@.reloc..$Z....)..\...6).............@..B........................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):327576
                                                    Entropy (8bit):6.3539171360285485
                                                    Encrypted:false
                                                    SSDEEP:6144:+lR1HQPSAhsagsKGt70YxiejVz1mHWUTio8AIVnWzgBIGAZuNC:mXwPLhttYYxiO4zRuI
                                                    MD5:4B9A9AF9451D0F8C924276010F2C21FB
                                                    SHA1:DE44BA25679B4B717FFC9ACD5246CAF4E3916F7C
                                                    SHA-256:DE1D1BF38090094B702833DDF3A68EE1F5D4AE20CA57F5392FABCF4C49C5B807
                                                    SHA-512:BBFFC87FB3405A90CAE2A696AF1B155254252E532628A979FA35279DEBFF8BC3D74C82986B388762A3E7AE990B08E351E9412B73A9B12233FBB44DE9AA06C4CE
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Joe Sandbox View:
                                                    • Filename: webex.exe, Detection: malicious, Browse
                                                    • Filename: webex.exe, Detection: malicious, Browse
                                                    • Filename: webex.exe, Detection: malicious, Browse
                                                    • Filename: webex.exe, Detection: malicious, Browse
                                                    • Filename: webex.exe, Detection: malicious, Browse
                                                    • Filename: webex.exe, Detection: malicious, Browse
                                                    • Filename: main.js, Detection: malicious, Browse
                                                    • Filename: main.js, Detection: malicious, Browse
                                                    • Filename: 2646fef76ae933018ff8a48e7c46c4ae6a82176107f7d.exe, Detection: malicious, Browse
                                                    • Filename: KCWggPUR7S.exe, Detection: malicious, Browse
                                                    Reputation:moderate, very likely benign file
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......s}^.7.0.7.0.7.0..n1.5.0.>d..=.0..b1.0.0.7.1...0..b4.?.0..b3.3.0..b5.b.0..b0.6.0..b.6.0..b2.6.0.Rich7.0.........PE..d...b[bW.........." ...$............................................................#M....`A.............................................M...+...................6.......O......x...p5..p...........................04..@............................................text...,........................... ..`.rdata...M.......N..................@..@.data....@...@...:..................@....pdata...6.......8...h..............@..@.rsrc...............................@..@.reloc..x...........................@..B................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):578384
                                                    Entropy (8bit):6.524580849411757
                                                    Encrypted:false
                                                    SSDEEP:12288:RBSNvy11qsslnxU/1ceqHiNHlOp/2M+UHHZpDLO+r2VhQEKZm+jWodEEVAdm:RBSDOFQEKZm+jWodEE2dm
                                                    MD5:1BA6D1CF0508775096F9E121A24E5863
                                                    SHA1:DF552810D779476610DA3C8B956CC921ED6C91AE
                                                    SHA-256:74892D9B4028C05DEBAF0B9B5D9DC6D22F7956FA7D7EEE00C681318C26792823
                                                    SHA-512:9887D9F5838AA1555EA87968E014EDFE2F7747F138F1B551D1F609BC1D5D8214A5FDAB0D76FCAC98864C1DA5EB81405CA373B2A30CB12203C011D89EA6D069AF
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Joe Sandbox View:
                                                    • Filename: qk9TaBBxh8.exe, Detection: malicious, Browse
                                                    • Filename: xSO7sbN2j6.exe, Detection: malicious, Browse
                                                    • Filename: xSO7sbN2j6.exe, Detection: malicious, Browse
                                                    • Filename: SecuriteInfo.com.Win64.Evo-gen.32634.31069.exe, Detection: malicious, Browse
                                                    • Filename: whisper-faster.exe, Detection: malicious, Browse
                                                    • Filename: whisper-faster.exe, Detection: malicious, Browse
                                                    • Filename: webex.exe, Detection: malicious, Browse
                                                    • Filename: webex.exe, Detection: malicious, Browse
                                                    • Filename: ZzutQz4T6D.exe, Detection: malicious, Browse
                                                    • Filename: webex.exe, Detection: malicious, Browse
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$......."...f..f..f.....d..o.A.p..f........c.....n.....b...........g....-.g.....g..Richf..........................PE..d................." ...$.F...V......`1....................................................`A........................................PB..h.......,................9......PO......8...p...p...........................0...@............`...............................text....E.......F.................. ..`.rdata.......`.......J..............@..@.data....8...@......................@....pdata...9.......:...<..............@..@.rsrc................v..............@..@.reloc..8............z..............@..B................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):35704
                                                    Entropy (8bit):6.591016227549893
                                                    Encrypted:false
                                                    SSDEEP:384:z1vZLMtUYqOoKFYpWcm5gW/ki0pSt+eB+Hj+R9zUkUTRtHRN7SoHR9zui5TJ:zpCtzqOjKYWi0QKHji9zSRtnx9zJTJ
                                                    MD5:69D96E09A54FBC5CF92A0E084AB33856
                                                    SHA1:B4629D51B5C4D8D78CCB3370B40A850F735B8949
                                                    SHA-256:A3A1199DE32BBBC8318EC33E2E1CE556247D012851E4B367FE853A51E74CE4EE
                                                    SHA-512:2087827137C473CDBEC87789361ED34FAD88C9FE80EF86B54E72AEA891D91AF50B17B7A603F9AE2060B3089CE9966FAD6D7FBE22DEE980C07ED491A75503F2CF
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......x. c<.N0<.N0<.N0..O1>.N05..08.N0..J1;.N0..M1>.N0<.O0..N0..O19.N0..K1(.N0..N1=.N0..0=.N0..L1=.N0Rich<.N0........PE..d...E.b..........." ...$.....&.......................................................<....`A.........................................?..L...<A..x....p.......`.......<..xO...........4..p...........................`3..@............0..8............................text............................... ..`.rdata..2....0......................@..@.data........P......................@....pdata.......`.......2..............@..@.rsrc........p.......6..............@..@.reloc...............:..............@..B................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):267160
                                                    Entropy (8bit):6.49994972430417
                                                    Encrypted:false
                                                    SSDEEP:6144:FMfjP87f5uV3hf0mApoleUCl8OdiI4hLgx+WKD:1f5uMmApoleUoiI4Zg0W+
                                                    MD5:E7A91F7C9D91F0F7857632436B121781
                                                    SHA1:3F658BB9757F5A9D50C884605C7E04F00151237A
                                                    SHA-256:63F1A20CB17EC5E0CA4EBEA870B68740F24E063E28B235C3C8B58A3D8F57A9C4
                                                    SHA-512:27961BE17CC8DB96DC3F144E4D8C7D0A9AD216B76474993190548FD79B22508B02B1358174F9348D6DB6DA44524FC877C9FA0392D886EBA9EF3A322FF083AFCF
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Z..`...3...3...3..2...3..'3...3..2...3..2...3...3u..3..2...3..2...3..2...3..K3...3..2...3Rich...3........PE..d....:.g.........." ...$............................................................B.....`A................................................X............................O..........0Y..p............................W..@............ ..h............................text............................... ..`.rdata...y... ...z..................@..@.data....*.......&..................@....pdata..............................@..@.rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):50072
                                                    Entropy (8bit):6.630947437101055
                                                    Encrypted:false
                                                    SSDEEP:768:YcpSBz3fhhehUjAPXOYRf0bzl+Hji9zpwmHji9z1I:sPv8UMPXOdbzlA+zpw4+zS
                                                    MD5:21F3417BBD33CBB9F1886E86C7240D1A
                                                    SHA1:37B495E87E55AE940D4D198E55C45A06E825D8CE
                                                    SHA-256:7E02EFE075B7DD385992F621FDE34728EF7C2D4CF090B127B093D0835345F8FE
                                                    SHA-512:A879016494F06308C735A6D2521AF97F93A785A61DDE73C3E2D2F27D7FDB3C28BBDD038EA338B40B74881480599CA93276CB599BE705F95748DFED612B480795
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........^...^...^......Z...W.@.X.......V.......]...^...:.......Y.......C......._.....,._......._...Rich^...........PE..d................" ...$.:...........>.......................................@......I.....`A........................................@f..D....k....... ..........P....t...O...0..X...`X..p........................... W..@............P..H............................text...>9.......:.................. ..`.rdata...$...P...&...>..............@..@.data...............d..............@....pdata..P............f..............@..@.rsrc........ .......l..............@..@.reloc..X....0.......r..............@..B................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):31640
                                                    Entropy (8bit):6.794564512154911
                                                    Encrypted:false
                                                    SSDEEP:384:onhXaLUR9WiUEWhQgKSt+eVo+Hj+R9zUNvnevsHRN77/+Hj+R9zUs2YbuGU:okLBXzlj3Hji9zwWw72Hji9znpbuGU
                                                    MD5:A3D300560D9C554790B3E6EA50E33D0F
                                                    SHA1:9C4C4E904D8A9C53E405BEB53DF13343996C7351
                                                    SHA-256:3BD90DB2F147899C65FE279F3E44AC48F5598CD0C23A09C0410BE072A4C96070
                                                    SHA-512:945AE45635807B0638BB43400F08D0A899A1F6C13B328920EA2B304C0F63B4848BF1DCDF73256811CA078B008A4A31230E56C898AB0094A4081AA265361E5B10
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m8.))Y.z)Y.z)Y.z.+.{+Y.z !~z+Y.z.'.{*Y.z)Y.z.Y.z.'.{.Y.z.'.{+Y.z.'.{%Y.z.'.{(Y.z.'.z(Y.z.'.{(Y.zRich)Y.z........PE..d....O.^.........." ...$............P........................................p............`A........................................p(..0....)..P....P.......@.......,...O...`..,...."..p............................!..@............ ...............................text............................... ..`.rdata..B.... ......................@..@.data........0....... ..............@....pdata.......@......."..............@..@.rsrc........P.......$..............@..@.reloc..,....`.......*..............@..B................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):109440
                                                    Entropy (8bit):6.642252418996898
                                                    Encrypted:false
                                                    SSDEEP:1536:BcghDMWyjXZZIzpdbJhKm6Kuzu8fsecbq8uOFQr+zMtY+zA:BVHyQNdbJAKuzRsecbq8uOFvyU
                                                    MD5:49C96CECDA5C6C660A107D378FDFC3D4
                                                    SHA1:00149B7A66723E3F0310F139489FE172F818CA8E
                                                    SHA-256:69320F278D90EFAAEB67E2A1B55E5B0543883125834C812C8D9C39676E0494FC
                                                    SHA-512:E09E072F3095379B0C921D41D6E64F4F1CD78400594A2317CFB5E5DCA03DEDB5A8239ED89905C9E967D1ACB376B0585A35ADDF6648422C7DDB472CE38B1BA60D
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........{n...=...=...=l..<...=...=...=...=...=...<...=...<...=...<...=...<...=...=...=...<...=Rich...=........PE..d.....K..........." ...$.....`............................................................`A........................................`C..4....K...............p..|....\...O...........-..p............................,..@............................................text............................... ..`.rdata...A.......B..................@..@.data...0....`.......D..............@....pdata..|....p.......H..............@..@_RDATA..\............T..............@..@.rsrc................V..............@..@.reloc...............Z..............@..B................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):49560
                                                    Entropy (8bit):6.6649899041961875
                                                    Encrypted:false
                                                    SSDEEP:768:a0Q4HUcGJZekJSam1BbuBSYcCZbiLzlSHji9z4GwZHji9znwT:afnDex5izbiLzlE+z4Gwl+zwT
                                                    MD5:CF0A1C4776FFE23ADA5E570FC36E39FE
                                                    SHA1:2050FADECC11550AD9BDE0B542BCF87E19D37F1A
                                                    SHA-256:6FD366A691ED68430BCD0A3DE3D8D19A0CB2102952BFC140BBEF4354ED082C47
                                                    SHA-512:D95CD98D22CA048D0FC5BCA551C9DB13D6FA705F6AF120BBBB621CF2B30284BFDC7320D0A819BB26DAB1E0A46253CC311A370BED4EF72ECB60C69791ED720168
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........V...V...V......T.......T..._.D.]...V...e.......S.......Q.......M.......W.....(.W.......W...RichV...........PE..d...}.4..........." ...$.<...8.......A..............................................e4....`A........................................0m.......m..x....................r...O......D....c..p...........................pb..@............P..h............................text...@:.......<.................. ..`.rdata..."...P...$...@..............@..@.data................d..............@....pdata...............f..............@..@.rsrc................l..............@..@.reloc..D............p..............@..B................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):519792
                                                    Entropy (8bit):6.715125645717176
                                                    Encrypted:false
                                                    SSDEEP:12288:4mDVpv6dH3sPp2vzvph0lhSMXliDI2eETSK0n:4mDPv6d8Pp2vzhh0lhSMXlJ2XTSK0n
                                                    MD5:8EC058796AF1317C9300B9930649DC75
                                                    SHA1:388F84341441050BF6A132EED2998319C4BE6A60
                                                    SHA-256:CE5A4299E717DF5E58C14BD255BBD74B78302D49128DDFB10DB4304F0504BFF4
                                                    SHA-512:CBCA04CEA0455610E3B912876B62B2B741CC531D345E2C500C1BE1C9444D999A31A06EA4E3FC25DF919ADA092A8D7DCF3ECCC17E2EDB035FDE6E686EB7F2EB26
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Zo.+..bx..bx..bx.v.x..bx.pcy..bx.p.x..bx.pgy*.bx.pfy..bx.pay..bx.|dy..bx.|cy..bx.qcy..bx..cx,.bx.qkyX.bx.q.x..bx.q`y..bxRich..bx........................PE..d....dCf.........."....$.......................@............................. ......L.....`.................................................HG..................\+......p ......t.......p.......................(...`...@............0..8............................text...<........................... ..`.rdata...V...0...X..................@..@.data....1.......*...p..............@....pdata..\+.......,..................@..@.rsrc...............................@..@.reloc..t...........................@..B........................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):6192736
                                                    Entropy (8bit):6.670952924351473
                                                    Encrypted:false
                                                    SSDEEP:98304:VhmMbMYnAexOHXKZMeJxZzV3tPf6S7UnLL2eFF99cSbwdmUNEpdf0:VIMoYAdHaZMe/2SeFFPcSbsON0
                                                    MD5:BAAF99CF810D2FC5B701A9BE7D9B17AB
                                                    SHA1:192607F46A96E8A7708AD4FCBF8DC3FF638FDBD8
                                                    SHA-256:D180ED4003A71609743AAF90B39280411F22D31EB76A38947AB4B9E3CFD4F883
                                                    SHA-512:B7C4E65609E5F2FE5E51E71BF714AB6821F8D54974D8FDE6E363B069AC6ADEC1CB75E1303637D11E2BCE5DD34B813802AD8C4B65DF982E93C04E9BF424DDE898
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...................................8...........!..L.!This program cannot be run in DOS mode....$.........@....W...W...W..-V...W..+V]..W*.*V...W*.-V...W*.+V...W...W...W..)V...W..*V...W..(V...W..'V...W../V...W../W...W..*V...W).+V...W..+V?..W...W...W...W...W..,V...WRich...W................PE..L......d..................>... .......0.......?...@.......................... _......._...@.................................T.K.h....pO..............,^.`R....[.L...._F.p....................aF.....0`F.@.............?..............................text.....>.......>................. ..`.rdata........?.......>.............@..@.data...4c....L.......K.............@....rsrc........pO.......N.............@..@.reloc..L.....[.......Z.............@..B................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):248432
                                                    Entropy (8bit):6.060793507683207
                                                    Encrypted:false
                                                    SSDEEP:3072:oLHJGdjXTdC63ykIJ10Lc60Igm+QprbVdDnwoZV0u1J8kW6A0QLn3FWL1MZUeHv0:hUjJ1Kz3bVdDnwoPXAFL4y7vHwUw7Ui
                                                    MD5:C02C1F2547D5040E3C2C84F138FE4BAC
                                                    SHA1:52B03E7F82A4C16B138BFD10B1A6DE00E0BCB1A0
                                                    SHA-256:EE616C0E850C47F2B69242A86AE759B9E97D230D0331920E8EADDED244D91AFB
                                                    SHA-512:B26A56A4BC799C6BA41FDEFA110B741DA7E4E9922D224DDAB9A26436537C562DAF31224524E9D4217BB36C5C9DD02FFD5CC738C38ADC86136FFB8D3E0762D236
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........kM{.8M{.8M{.8D..8E{.8(..9O{.8...9\{.8...9E{.8...9N{.8...9I{.8j..8O{.8...9H{.8M{.8.{.8...9E{.8...9L{.8...9L{.8RichM{.8........PE..d....f.f.........." .................{...............................................}....`..........................................v..T....v..........8...............p ......T.......T........................... ................................................text............................... ..`.rdata..............................@..@.data...............................@....pdata..............................@..@.rsrc...8...........................@..@.reloc..T...........................@..B................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):538736
                                                    Entropy (8bit):6.266026396603354
                                                    Encrypted:false
                                                    SSDEEP:12288:tgLtsqgR2RwVEgqLvmXjTkmWxgcAMKvtncklpd2P87:tOsqgR2RBgqLvmXjTkm8AMKvtncklpdX
                                                    MD5:A8B8A70B0D5C06C8AA5C96A135E6335C
                                                    SHA1:4773524D04324B30951CC0772DF88B2C6D732848
                                                    SHA-256:661711C8DD1A98EDE3ECFD5C4BBAAE27EBFA83C70B708336949EE6D2E5ADB6B7
                                                    SHA-512:7A8A9861880CD01C17F40C68648ABD0D0510324443D98AC6827A82910E6F567F7A4990EBD6AD993C88BD794F7E1B6E7BC63A93348260B452904BEC4AED1EF040
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........p.Kx..Kx..Kx..B...Ex......Cx......Hx......Px......Ox......Jx......[x..'...Ix......Hx..Kx..<y......ax......Jx......Jx..RichKx..........PE..d....f.f.........." .....`...................................................P............`.................................................L|..|....0..H........?......p ...@..........T.......................(....................p...............................text...._.......`.................. ..`.rdata...N...p...P...d..............@..@.data...0*..........................@....pdata...?.......@..................@..@.rsrc...H....0......................@..@.reloc.......@......................@..B........................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):535152
                                                    Entropy (8bit):6.26961986074262
                                                    Encrypted:false
                                                    SSDEEP:12288:fHKBxY+NRYaGGS99FMLsEFG0SyQTqLMbKJVcE5Cdsd2bMFwl:AYaGGS99FMrFG0SyQTKMAcE5ld2bMa
                                                    MD5:6557C8228FD2C65EFE4A8D6ECC043CCA
                                                    SHA1:7C940E352E71A18F301EEE59291318164D25B0BC
                                                    SHA-256:21DD2E2068E50A44257841B5FE3513709F4C2318CAB9951A5F5BD475006FE6DB
                                                    SHA-512:FB6CA73D6446445D195468E6682EE046AC3EB767F95121F55E8B33DF7F24DC3F9F2C49AAA5D06B3073C0E2DE96C9444C45E72E596E4376588F0D0A5A244298A4
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........I...(...(...(...P,..(...@...(...@...(...@...(...@...(...N...(...N...(...@...(...(...)..@A...(..@A...(..@A...(..Rich.(..........................PE..d...[f.f.........." .....R...................................................`.......7....`.........................................P...........h....@..L........?......p ...P..........T.......................(....................p...............................text...|P.......R.................. ..`.rdata...P...p...R...V..............@..@.data....)..........................@....pdata...?.......@..................@..@.rsrc...L....@......................@..@.reloc.......P......................@..B................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):948848
                                                    Entropy (8bit):6.136719298313182
                                                    Encrypted:false
                                                    SSDEEP:12288:C2L4gEHAI9SFqm0b12vujKSrmsVtl5ksZMym9:ugAAOSw/4ujKSrmsVtl5lZMy8
                                                    MD5:3FD462EC2B52062673079B8333D69A3D
                                                    SHA1:1D35D6727E392FC177AF869205A05622BF6533C5
                                                    SHA-256:941C6ABE36ED02602A6C657D3F4ACFC903D271F104672A456D6EC7D23944EBA6
                                                    SHA-512:D847FFDE6360ADD50EDCE9921C222B6430F9B3BBBEC4915C31A5A0F4386135460802CA4F4A88BD19302FCFAB95C5204ABBF361BD5A8BDDF57C9C22D5EB79C3D3
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......0.Gat.)2t.)2t.)2}..2~.)2&.-3|.)2&.*3w.)2&.,3l.)2&.(3p.)2..(3p.)2..(3e.)2t.(2K~)2..,3V.)2..)3u.)2...2u.)2..+3u.)2Richt.)2................PE..d......e.........." ................dG....................................................`..........................................7......\?..h....`...;...........Z..p ..............T.......................(....................... ............................text............................... ..`.rdata..D...........................@..@.data................~..............@....pdata...............T..............@..@.rsrc....;...`...<..................@..@.reloc...............D..............@..B........................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):342128
                                                    Entropy (8bit):6.036609933275522
                                                    Encrypted:false
                                                    SSDEEP:3072:pjjrwdb+g2I1mbQhb5qi/Dh9fDp/2esp6SQl+G8dT42vFtovtqCitMc6j+BrqwcF:BjNg2I1m4Z+p6SdT42dLMNjcqwDMcDtS
                                                    MD5:85C52027D52AD3CD1EC8F095AF889B6F
                                                    SHA1:AA4B782CD5ECA618F23603EE9EB0594C0EEEF93B
                                                    SHA-256:5B4D423A22869BD814A0AF243DF37F5A8436DD8298A718E9535ADA405495104D
                                                    SHA-512:C39B728F3E5C36238C0E789477706B660469C827744978EF4F58B39C3F3F59270CCDBC730AACF7A24F54062C389DEBC8D1C89A2CCB62DCE3C1BA77550ACFC74C
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......5f:.q.TWq.TWq.TWx..Wy.TW.aUVu.TW#oQVe.TW#oPVy.TW#oWVs.TW#oUVu.TW.nUVt.TWq.UW..TW.nQVa.TW.nTVp.TW.nVVp.TWRichq.TW........................PE..d....f.f.........." .........H.......c.......................................`.......D....`.........................................@...P............@..0.......d ......p ...P..d...@&..T............................&...............................................text...$........................... ..`.rdata..............................@..@.data...............................@....pdata..d ......."..................@..@.rsrc...0....@......................@..@.reloc..d....P......................@..B........................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):54384
                                                    Entropy (8bit):5.949222096534558
                                                    Encrypted:false
                                                    SSDEEP:768:PQ6XfhJymUQSUkq7t8byJWe61HXYicY3hYo:Y0f/SUk9byJr6dX7B3hYo
                                                    MD5:3AA01FCDD115C60B160F9AE424BCEEB3
                                                    SHA1:18B06F45B500BD58BD18C729D669410CD8BC28BB
                                                    SHA-256:484B84235DA9DA9E797249AD454341D3117695180B69ED5D4228E2763F14EBCA
                                                    SHA-512:A61A6415EE2105D5B0D0E904F8A2BEE8EE70838BACFFA83BC627D07300ADE58F6D39EC94DACC6BF27EC7C5D2C3936089FF6D8269DD369455BB2AEDF0B808DE52
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........./...A...A...A.....A.A.D...A.A.E...A.A.B...A.A.@...A.6.@...A..@...A...@...A..H...A..A...A.....A..C...A.Rich..A.........PE..d...udCf.........." ...$.6..........P8....................................................`A........................................px...,..D...................h.......p ......\...0[..p............................Y..@............P...............................text....4.......6.................. ..`.rdata..Pb...P...d...:..............@..@.data...............................@....pdata..h...........................@..@.rsrc...............................@..@.reloc..\...........................@..B................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):629360
                                                    Entropy (8bit):6.136411710279737
                                                    Encrypted:false
                                                    SSDEEP:12288:TRfN8LyL6GHVupHAoa4I7wLsQ+1l5UKmcZ93mtVep4dIJN:TRfN8LyL6GHVupgoa4I7wLa1rU9cZ93T
                                                    MD5:9D133666F1418C087A47F82177979B0B
                                                    SHA1:7EC67FF28435E2C667A7EECE7E72AF85B82B6B24
                                                    SHA-256:7D59125E297FB0B56114235188AF9514BD61CCC171DF486A45409772E3CB7318
                                                    SHA-512:55C7AD7E7428CC550A944333D3F2F65B41852728E7705C85E6AA88ECE03BEF6BB3E1BD9AFA61B37D0CB82B5CD8C3754E8888C22501D8372C78B9A16D90CE3DD4
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......@.N=.. n.. n.. n...n.. nV.$o.. nV.#o.. nV.%o.. nV.!o.. na.!o.. n..!o.. n..!n]. n..%o.. n.. o.. n.."o.. nRich.. n........................PE..d....f.f.........." .........\.....................................................b.....`.............................................T.......@.......(....`..<6...z..p .......... ...T............................................0..x............................text...D........................... ..`.rdata..|....0......................@..@.data....&...0... ..................@....pdata..<6...`...8...8..............@..@.rsrc...(............p..............@..@.reloc...............t..............@..B........................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):82544
                                                    Entropy (8bit):6.0914690603520665
                                                    Encrypted:false
                                                    SSDEEP:1536:grxduMkYZaJLsDG8m/WCcpzkcMEQ7ys3hjs:grFaRsK81C4kcMEQeYs
                                                    MD5:E1206C49D24B05028C78BF62F5D4318C
                                                    SHA1:9635928C77667DAE4E9FB854582AD9B0D931D78A
                                                    SHA-256:870B4B022A3E01D81DBDAB740F8AC92DACB77B60691023729F609D10958A30AB
                                                    SHA-512:74303F5B647FC6875A0A9B7E07E6D2C04160A3337EDF329791690FB523E3941E861F119222C6EF8832FA194121DB9922E2000228A1EB0E3CE1A8BBAF15FC5AF5
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........{...{...{....#..{......{......{......{......{..W....{......{...{..{..W....{..W....{..W....{..Rich.{..................PE..d......e.........." .........|...............................................`......J.....`.............................................L....................@......."..p ...P......P...T...............................................(............................text...G........................... ..`.rdata..N\.......^..................@..@.data........ ......................@....pdata.......@......................@..@.reloc.......P....... ..............@..B........................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):416880
                                                    Entropy (8bit):6.293816693905265
                                                    Encrypted:false
                                                    SSDEEP:12288:FwNVC6QURz1OybA//saycqBVHSdQGfhAf:FwNVvp1OyEUayc7dQ6if
                                                    MD5:C025F0FF25BD508DFCEF2E17143E1207
                                                    SHA1:F0E9F83F6B551BBBADD3D30012FE056CC548A33A
                                                    SHA-256:A96D73B0EA047D097A141EDDA983A9E7C70D4D51BFE8CCBA1BA80B0F877F92C1
                                                    SHA-512:CCD6FAB6E86F1C8EC30A2743D68B9E76650531DE34773EA807DD8DF85350D672F6A55130DFB346AB935B1BF7DEA2F87C161C3AEB6DB24E60FF4AB8DCCD37EAC2
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$....................................................M..................M......M.....M.....Rich...........PE..d......e.........." .........F...........................................................`..........................................5.......................0.. 4...<..p ...p..L...`r..T....................s..(....r...............................................text............................... ..`.rdata..f...........................@..@.data...."..........................@....pdata.. 4...0...6..................@..@.reloc..L....p.......8..............@..B................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):1777776
                                                    Entropy (8bit):7.876741278509359
                                                    Encrypted:false
                                                    SSDEEP:49152:vwPSrruQNF+G+JAh+88ES5neiqBYZktmt0x8m:DrruQNtA0HDeScm
                                                    MD5:D7A69EB5C82B084FD3902E7E27507AA3
                                                    SHA1:2A8FBC1B0FAC702EFBEB70A92D9CAFA05A96BFE6
                                                    SHA-256:FE8B0789FDBE46C9CC4E62D38F270F2EA8F83698A7689159E19E060CE6539080
                                                    SHA-512:39E4A64236732AD60BF9AFC1FD005F3D5ED0AD4715E253DE7BBD1C05A2C860F5AB84A6DDE74497BC7B360BB81BCEF91633CE2864D5C3CB5FA0CD56801FE4B225
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........................=.....r.......r.......r.......r..........................o........................Rich....................PE..d...$..e.........." ...$.....2...................................._..........@......^.....`..........................................,...8...e....... ...........&......p ...0......P...8.......................(.......@............................................text...>........................... ..`.rdata..N...........................@..@.data....,.......(..................@....pdata...&.......(..................@..@.rsrc........ ......................@..@.reloc.......0......................@..B................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):62064
                                                    Entropy (8bit):6.287341477739301
                                                    Encrypted:false
                                                    SSDEEP:768:UVocuSkSO1leDe2JFJo76aqO4sdxGAAFeGpuD+/BQbUBIlriM5HPuJfYiDC3hhg:UVocuSkS4eDe4wx75D+/PXMwJf7e3hhg
                                                    MD5:173583BA8EF4A40B4983A717DC8A21B0
                                                    SHA1:324DE1D5FDFFE31FD0ECEB6D0CBE69517F185C3C
                                                    SHA-256:FDCB0D27AAA866DE8EF6F58DFFE2662B4FAB4766F63BE43E15FE1B8919711994
                                                    SHA-512:F5142A67504A7A9F940D9EF3DE38A42FA0539421003C0C2BB9941CDB94D1F77FAF5083C6A3858A6E8A8F0AD7C8E006BA3355CB061CBE3BA80D79172C3D567FD8
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........ae..............x.......u.......u.......u.......u.......f..............Lu......Lu......Lu..............Lu......Rich....................PE..d...SJ(f.........." .........J......@..............................................._9....`............................................................. .......4.......p ..............p...............................8............................................text...L........................... ..`.rdata...*.......,..................@..@.data...(...........................@....pdata..4...........................@..@.rsrc... ...........................@..@.reloc..............................@..B........................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):28272
                                                    Entropy (8bit):6.20169453351523
                                                    Encrypted:false
                                                    SSDEEP:384:hNtFqB7doZvg756PGTtAPNKx90IYi5Gga8JN77hhwoP:hjmos5hT+PNUbYi8gl3hOoP
                                                    MD5:1F500080FE37E176275E620AE4E650A8
                                                    SHA1:020AEDE627F67F166DA17E3708E366EFDDA801F5
                                                    SHA-256:F2743A2EA3F31FF8623FB57C7561FC0ED2876338189303D6A36B33A1CE376402
                                                    SHA-512:217C91DFE7DABF2F5B3EA36997A5135563F388435E05E3A912096E66F9649F23CEF7B661EA959FE7E65C9063319D20EEDDDB5E694E2C00EB4839063E55443BAD
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........3...].].]....]...X.]...Y.]...^.]...\.].b.\.]..\.].\...]..T.]..].]...].._.].Rich..].........PE..d....dCf.........." ...$.....4......0...............................................I.....`A.........................................B.......F...............p..$....N..p .......... 6..p............................4..@............0...............................text............................... ..`.rdata... ...0..."... ..............@..@.data........`.......B..............@....pdata..$....p.......F..............@..@.rsrc................J..............@..@.reloc...............L..............@..B................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):64624
                                                    Entropy (8bit):6.429164652838862
                                                    Encrypted:false
                                                    SSDEEP:768:HrmW5GKq2mdnGO6yfFuBDiwHr2FfJlFsRjxGAhhGw/Z8p33RoqtCK9kYiDj3hst5:HqvNsO6OgVnwpw836qtCKk7f3hsD
                                                    MD5:F81C5876EADF6815C90BBBD2D849FB22
                                                    SHA1:BB556137FA25C3F50B1DCBBC0C8030CAAE392613
                                                    SHA-256:116A30A15CAE60E2DBDA5D003EC5C714A678AE4D36AE29D8903EAC283F432E36
                                                    SHA-512:DAB67EC2AB557DE2ED105FA26F065D617A514FD9D1A930960AE91464D40A531F47123A7AED9E300CACE605EFA19B28C2491B005182BB6541172448F1A7B62FA9
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......T.#H.zM..zM..zM......zM.B.L..zM.B.H..zM.B.I..zM.B.N..zM.u.L..zM..zL.(zM..zM..zM...I..zM...D..zM...M..zM......zM..z...zM...O..zM.Rich.zM.........................PE..d...WG(f.........." .........N............................................... ............`.............................................p...............................p ......<...@...................................8...............h............................text............................... ..`.rdata...9.......:..................@..@.data...p...........................@....pdata..............................@..@.rsrc...............................@..@.reloc..<...........................@..B................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):25086576
                                                    Entropy (8bit):6.265473139148056
                                                    Encrypted:false
                                                    SSDEEP:196608:c5UPAH12AbOi/I8/CcCa5/BHFpwk8rhhyWdXnD:cE812AbOiFpXQrRdz
                                                    MD5:E69AA8A3AF3D22F3F9A8620DC7457BB2
                                                    SHA1:31ECEAE720DF21660038631974027EA8A7AD22D4
                                                    SHA-256:FCB53BA2A6BD3C850F1EF377ED2F46EBB78911BC4F6290C51C10EA0E0733E07B
                                                    SHA-512:D987CCCBAC9FC7C6D70DE6ED50A6610C6B68A63A3CBE2875D07408EEF42F6F3BC2C6B365B1A9B9C20CCD2A561F00D50E6F48D965F4CA1CF0A43ECA181B953A96
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...................................(...........!..L.!This program cannot be run in DOS mode....$......................<....b.....b.....b......b.......R..........K.....K.....K.........f...K..\...K.....K.P.....8....K.....Rich...................PE..d...&SP`.........." ......H..t<.....p.E......................................`............`A.........................................=i.X...(>i.h.......0.....z.|!....~.p ......x...p.X.......................X.(.....X.8.............H..............................text.....H.......H................. ..`.rdata...E!...H..F!...H.............@..@.data....d....j.......i.............@....pdata..|!....z.."....s.............@..@.rsrc...0.............|.............@..@.reloc..x.............|.............@..B........................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):19056
                                                    Entropy (8bit):6.317899492031479
                                                    Encrypted:false
                                                    SSDEEP:384:f/dnzUwUwxWelbdhtTt7IYiScE38JN77hhT8I1:f/RzXUwxWerGYiVE83hB8I1
                                                    MD5:F4169B11A69559CCB3E0EF0D1119287F
                                                    SHA1:28A46FDD43FDE59116A4E2BEBB380FA9AF9E96D6
                                                    SHA-256:326E84D44B451564AAFA562D2092C065CC093EE380D93711CDFF1EF07DDA7E68
                                                    SHA-512:607AFA1B88C44CE246E4526779DF9E658FEA3EFCA83395F3AE0F0DC3D19EBECA74A490DF576BE8A09A24B7BCEB2A7F239B6A2C876E0C930BE74C2E4A9D2C5750
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......>.0.z.^.z.^.z.^.s...x.^..._.y.^...[.q.^...Z.r.^...].y.^.._.x.^.z._.Y.^.n.W.{.^.n.^.{.^.n...{.^.n.\.{.^.Richz.^.................PE..d....bCf.........." ...$............p........................................p............`A........................................P(.......(..P....P.......@.......*..p ...`..,....#..p............................!..@............ ...............................text...H........................... ..`.rdata....... ......................@..@.data...8....0......."..............@....pdata.......@.......$..............@..@.rsrc........P.......&..............@..@.reloc..,....`.......(..............@..B................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):57456
                                                    Entropy (8bit):5.974921467169704
                                                    Encrypted:false
                                                    SSDEEP:768:qYeQiv+6aY7NvMf6//ALiD6iOtpapPsl76seJkfKzYE8aUBCLUENY5eqYiFl3hBh:q9tpUft+FpPsbLJ/PCNNkV7T3hBh
                                                    MD5:7BDC68B2793E9A628147D629E135FCC7
                                                    SHA1:EE4D51C4224488A808ED862E47DCBE2A25612E5E
                                                    SHA-256:067856F9395A62F62CB0B0D55C62855C95492BE7801BB0BAB6AEBB7AACA54D91
                                                    SHA-512:D136405AA9BC461B5280F88F65EA529C77E585FB2F9CE4C8297B90802FF30A64FF2FB42AD94DFDEF4A91A332053756B1A40D13ECDADFD30FB500ADC6B3F27991
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........R7..3Y..3Y..3Y..K...3Y.KM]..3Y.KMZ..3Y.KM\..3Y.KMX..3Y.LP\..3Y.<AX..3Y..3X..2Y..LP..3Y..LY..3Y..L...3Y..L[..3Y.Rich.3Y.........................PE..d....dCf.........." ...$.d...^.......)..............................................+.....`A............................................X...............................p ......l.......p.......................(...p...@............................................text....b.......d.................. ..`.rdata...C.......D...h..............@..@.data...(...........................@....pdata..............................@..@.rsrc...............................@..@.reloc..l...........................@..B................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):6476400
                                                    Entropy (8bit):6.783548340227336
                                                    Encrypted:false
                                                    SSDEEP:98304:cWPRNJ0Ti2ORkyxJsv6tWKFdu9C3OhNZ6xqfkgw7:lPRN6Ti2ORVJsv6tWKFdu9C3UKxqfkF7
                                                    MD5:4C77D9EC3F185779FC6CEE2A2828E025
                                                    SHA1:896B3FF0EAF1CF2448340C78123C3FC932E5159B
                                                    SHA-256:68BCDD97BD146AAAC9B849DA005798D7E8F2D68D12579B5EA0976AB6F15FFDFF
                                                    SHA-512:B63CB404E69B9730E09ECA9AF34A9FA8FF00F5ABF827EDAF5F5CA98BB315BF5F038E66A08B6FC45FB6B3DDA9CDB398C1E3B5953A814A87602C81FABF8D8FB9D9
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...................................(...........!..L.!This program cannot be run in DOS mode....$.......b.S.&.=.&.=.&.=./...2.=...<...=.....".=...8.9.=...9...=...>.".=.m.9.$.=.m.;.'.=.m.<.1.=.&.<...=.2.5...=.2.=.'.=.2..'.=.&...'.=.2.?.'.=.Rich&.=.........................PE..d......e.........." ...$..3..x/......I2......................................@c.....z.c...`A........................................ .Q..Q....Y.......c.......[..8....b.p ....c..%...+L.p....................,L.(...@*L.@.............3.H............................text....~3.......3................. ..`.rdata..>.%...3...%...3.............@..@.data...Hq...PY..(...6Y.............@....pdata...8....[..:...^[.............@..@.qtmimed......^.......].............@..P.rsrc.........c.......b.............@..@.reloc...%....c..&....b.............@..B................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):7271024
                                                    Entropy (8bit):6.675835057876044
                                                    Encrypted:false
                                                    SSDEEP:49152:sHFDgYaZFllrvnRtAwQD4Vzxl8gsOdQxCbfts6wqNiN8wV/4wz/zb0UmYpLCjg2M:SFDFaVlbIWe8Yid3g9GPER
                                                    MD5:46BB2500A8D936910129B15876369635
                                                    SHA1:11343ECF1C61E40A6A85463433181CA747844288
                                                    SHA-256:B7563D5FFC92168F5E3BD396133F0CF7A5050094D33CD7B1774E754DDB4A40D5
                                                    SHA-512:ACD06DFA697129395A99676EBB494391DCF45EAE8DF569D8E198A1BC066B36F497C199E4BCBD84978E7AF7E090BBF4C57E94E42652B851BC46E709321E48B23C
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......V.w....................................................................Y.......Y...................c................................Rich............PE..d......e.........." ...$.PB..,-......@B.......................................o......Ao...`A........................................0.N..^....h.|....po.......k.$.....n.p ....o.(2...>I.p....................?I.(...`=I.@............`B..,...........................text....NB......PB................. ..`.rdata..F.&..`B...&..TB.............@..@.data....s...0i.......i.............@....pdata..$.....k.......j.............@..@.rsrc........po.......n.............@..@.reloc..(2....o..4....n.............@..B........................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):767088
                                                    Entropy (8bit):6.2410048988913225
                                                    Encrypted:false
                                                    SSDEEP:6144:iD0WTk80hQWAmEUQI2PQWYGbDMCCXjYxN4oUXhKAnNgYZTQUQnqG/+wSO+WRg4Si:iD0WT+SNzPQRGbDhCXUx0pNgYscLk7nx
                                                    MD5:E3CD12190AE6436C6C8E9A08B3581D78
                                                    SHA1:DCBF391202F883EDE1DE31EF7D3236509AA3AB0A
                                                    SHA-256:34E8552DDB79AA3FB8BE01A69B551C1D5B3206E7E2F82E47C992F1A3D30FD6C4
                                                    SHA-512:E6215DB54106A4B8DFBEB4671BFAA1C3940A9A5C0DAA23558418847ADE5DF50AAA72A67075FD7137189547B1D46B47EA8E9AEAD9803585F1F641AD2673EE0B06
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........\..............]............8.......8.......8.......8...................a.....................1.......Y.............Rich............PE..d......e.........." ...$............0................................................N....`A........................................`........................0..........p ......|.......p.......................(...`...@...............X............................text............................... ..`.rdata...V.......X..................@..@.data........@......................@....pdata.......0......................@..@.rsrc................x..............@..@.reloc..|............~..............@..B........................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):129648
                                                    Entropy (8bit):6.173938667816064
                                                    Encrypted:false
                                                    SSDEEP:3072:+t2p3uWpp0Kfy3DDWfAGkZbAfmtHVYI9ytIeObb0:+t0+VKK3DDN0fmtHVYI9ytIeI0
                                                    MD5:8D5E239FFFCE3BE9D27D4CE40795EDB6
                                                    SHA1:F08E3AD29B0C308CEC87565400D0184F84C3ADC3
                                                    SHA-256:0301DBFB4CA9AC794E58ECDFAF376003715B2087E06844B1BAF273AC8A54C244
                                                    SHA-512:A887763358D66DAE33DEFBBA149F3844FAA7E508B7E390DAEADF599D1162048B92060293BC2667BCDA6F2362873FAC289D2209EA97205A2D4DA2DA957DE13BE0
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......[.s............................T.......................................................................................Rich............................PE..d......e.........." ...$............................................................h.....`A........................................p^..x....u..........................p ......D....0..p....................1..(...p/..@............................................text............................... ..`.rdata..............................@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc..D...........................@..B........................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):106608
                                                    Entropy (8bit):6.09007556866531
                                                    Encrypted:false
                                                    SSDEEP:3072:sm44CiFJWhqn0Cx9pWZlwMrn+P0v9NZ9ARk8UN:QKJDnRxrWZlwMrn+8v9NZ9CUN
                                                    MD5:77A0D674920E23D424AA77ACE3D597B8
                                                    SHA1:6CE8A0A1431CA67B870EDD2C0902297F9A911147
                                                    SHA-256:80F0F6DDA326F374B8608208A05B65201F47B1E52B721CE2EDFE3EDB47F4C4FA
                                                    SHA-512:283D16CDE6E59CC8B8E211268079FD7BBBA84BF4D0A6080904A49BB5EBE14ABC2242DACDE6535806B124DA2E3082555B13D3AE285287BD4727C7B72034330FD3
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........`.O..HO..HO..HF..HG..H..IM..H...IM..H..I[..H..IG..H..IL..H[..IF..HO..H...H[..IJ..H[..IN..H[..HN..HO.HN..H[..IN..HRichO..H........................PE..d......e.........." ...$..................................................................`A........................................@.......<........... .......4.......p ..........p...p...........................0...@............... ............................text.............................. ..`.rdata.............................@..@.data...P....p.......V..............@....pdata..4............j..............@..@.rsrc... ............v..............@..@.reloc...............|..............@..B........................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):1119856
                                                    Entropy (8bit):6.378722147495002
                                                    Encrypted:false
                                                    SSDEEP:24576:aXhKspSsb2U6p3DA31M/IDWCrF88fyW4uIhkXVtog:a+sb2U6p3Dj/IDWKF8M34zkXbX
                                                    MD5:17B3CF34FDFBFF97C081FCD418CF49BC
                                                    SHA1:7B9FE495C79A7C64A190A495CBD34D44A0579CE5
                                                    SHA-256:148201B21D2BA55481341EBC81169DB54D8C0C336FFE7FD2D2371E40812347FF
                                                    SHA-512:8CF8DAC76809662FA9ADA9F0452FB164AEB37E35073467D124BDC8E31B60EE8FD6ADA6C475E411BFE1ED7CB163A0001134151048984D4B8E16EB401A13FFFC32
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......................8...................................................................................T.......<.............Rich....................PE..d.....e.........." ...$.B.......... ?.......................................P............`A....................................................T.... .......p.........p ...0..d.......p.......................(.......@............`...............................text...kA.......B.................. ..`.rdata..FG...`...H...F..............@..@.data...p...........................@....pdata......p......................@..@.rsrc........ ......................@..@.reloc..d....0......................@..B........................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):337520
                                                    Entropy (8bit):6.394975874016104
                                                    Encrypted:false
                                                    SSDEEP:6144:DbpDzT4AU2GyY3BBspkSaqo3mNIVnckNI+STEDkCE53vHylq5ZqxXHKmDZ:D/GyKspkSasNIQotl
                                                    MD5:2400A59E0CEA55DAC59679CFBD4D9B1A
                                                    SHA1:F0734C482008043AB002685288BB956CB2458C47
                                                    SHA-256:4551E5215DAFD772C15F0AF721416E28786806492131BC40BEAB837DC477854A
                                                    SHA-512:A9186BF42E67E326905681B3CD3E34034F5CDD7D22E9CF1675AC024C555EF71BE2B08627FB50C7F5606E45C81F5CAE7B55BC346F1135962FCEF2CB0996A76D36
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........ ...A.U.A.U.A.U.9^U.A.U.?.T.A.U.9.T.A.U.?.T.A.U.?.T.A.U.?.T.A.U.>.T.A.U.A.U.B.U.>.T.A.U.>.T.A.U.>2U.A.U.AZU.A.U.>.T.A.URich.A.U................PE..d...~..e.........." ...$.x...........y.......................................@............`A.........................................o.......!....... ..................p ...0..........p.......................(...`...@............................................text...Kw.......x.................. ..`.rdata...=.......>...|..............@..@.data...h...........................@....pdata...........0..................@..@.rsrc........ ......................@..@.reloc.......0......................@..B................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):3704944
                                                    Entropy (8bit):6.327681975756555
                                                    Encrypted:false
                                                    SSDEEP:98304:YQ1j7BhMA0vyTaDNrSdSG779LLLS/o/L4YqoY0Xba+mRRgB:YQx7BVTak
                                                    MD5:30022C8C8770B084AE7EDD4DDFDF4F6E
                                                    SHA1:BF29C3D05A09613BF2DC6F97F7FDC98A4252FB7F
                                                    SHA-256:A89AF5FC59638EA992CE39EA3406829CA90DBD94D18F40193A82263AB44C8469
                                                    SHA-512:107E29EB9810AFA46A707CD7A5F8B9B6777187AD6642864D18BBF9A7BF127DDB5268DB408CAAA9D77B00E08432BE0A6C2FBCE080614AEE36F7369407F1B71833
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$......./..k..k..k..b.2.g.....c.....o.....u.....m......o.. ...n..k..<............j....^.j..k.6.j......j..Richk..........PE..d......e.........." ...$.L%..F.......>%.......................................8......,9...`A........................................P...... .3......`8......p6......h8.p ...p8.8J....*.p.....................*.(...`.*.@............`%..&...........................text....J%......L%................. ..`.rdata...)...`%..*...P%.............@..@.data...0.....4......z4.............@....pdata.......p6......(6.............@..@.rsrc........`8.......8.............@..@.reloc..8J...p8..L....8.............@..B........................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):450672
                                                    Entropy (8bit):6.322294381438446
                                                    Encrypted:false
                                                    SSDEEP:6144:CrCUxiu4baJiVIkexBvSvHqzvxncxWTgvyuEa/XRo:4CUxiEJiV9oBvS/qj8yeW
                                                    MD5:5BECF7EBCEF986A268CAFD3F0F76FD71
                                                    SHA1:92EFE2AD92C6FE6779CCCC853F440C4D4EE2D4BB
                                                    SHA-256:5EE8460F5C1D7F130FC4E30F3894879DDA45A1AF5A7D3596F296CC974A5B9106
                                                    SHA-512:06105BE897E42F06E8E47147E54E77853C785582F9358E2316570D57403A5967879D5293390769A91AB18CD90B1409148F6E2AD423E589EF87FB30F95E7BDA83
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......=.!_y}O.y}O.y}O.p...q}O.2.N.{}O...K.q}O...L.}}O...J.a}O...N.}}O.m.N.|}O.y}N...O.m.F.k}O.m.O.x}O.m...x}O.y}..x}O.m.M.x}O.Richy}O.........PE..d......e.........." ...$.0...........4...............................................o....`A.........................................B...^......................E......p .............p.......................(.......@............@...............................text..../.......0.................. ..`.rdata..>....@.......4..............@..@.data...XV...0...P..................@....pdata...E.......F...j..............@..@.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):58992
                                                    Entropy (8bit):6.0787336628162745
                                                    Encrypted:false
                                                    SSDEEP:768:/GL3rD0JmkvipPqwq7qTHVHrewW++tWB5YitG3hdW:/G3jsOz0qJHCb++AB57tG3hdW
                                                    MD5:10F4EB55E1AEB45276CA94E65E6DEEAC
                                                    SHA1:B82EDFB5FA27C4B4611845CFB2D2F857ED5039F8
                                                    SHA-256:8923054BABDB0BBE8485AB9A0B14AC392B43192B77219B9060E68B13F6961F4B
                                                    SHA-512:E6C18F82FC5FF823B71904009095A04428A5230FA844B9EC8A6BA39DF2B42B0DF93395BAD56B7BCD97324081B8D5682AB5F71479EE00CC048F6F38F78923C211
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........J..+...+...+...S...+..hU...+..S...+..hU...+..hU...+..hU...+...T...+...+..<+...T...+...T...+...Tw..+...+...+...T...+..Rich.+..................PE..d..."..e.........." ...$.T...v.......X..............................................P.....`A............................................(..............................p ......<.......p...............................@............p...............................text....R.......T.................. ..`.rdata...T...p...V...X..............@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc..<...........................@..B................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):4289648
                                                    Entropy (8bit):6.458630615586146
                                                    Encrypted:false
                                                    SSDEEP:49152:2dFptBa6NraCXqa3cTdIPPOaKSVRgO+3EeGQ895GpBKIout8VJ8QVEUB4On:2IfyI895I/y
                                                    MD5:D1A2E280A5CD128E5D9B967CEA024456
                                                    SHA1:F5067C307FE7D37AE3C1B4A232AC57390F0851CB
                                                    SHA-256:5DBEA7E62AEBE74EC55A6BC16BFE8330AD6520E57E02DD3BED495D45B277854C
                                                    SHA-512:3D204892BBF10672AF33A1F691543E93936AA8B8E9FBE43C908156D2A31CD702518728688B76276C05D98EA22D8880C29BB592E74FFE02EF3F54042937AA2123
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........DQ..*...*...*.......*.......*...)...*.../...*...+...*...+...*..+...*...+.4.*...#.O.*...*...*.......*......*...(...*.Rich..*.........................PE..d......e.........." ...$..&..b......`.&.......................................A.....4&B...`A..........................................1......8.T.... A.......>.|`...TA.p ...0A.4v..P.-.p.....................-.(.....-.@............ &..\...........................text.....&.......&................. ..`.rdata....... &.......&.............@..@.data.........:.......:.............@....pdata..|`....>..b...t>.............@..@.rsrc........ A.......@.............@..@.reloc..4v...0A..x....@.............@..B........................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):180848
                                                    Entropy (8bit):6.11847245719827
                                                    Encrypted:false
                                                    SSDEEP:3072:y/AYpoo4xzsewJOCzdI9iQU8tAd111tdh9dNIltAe11tdqdNqlR11td1iB11td+p:yIOYzYJOCkZhCwmT8
                                                    MD5:AF2F1B4488BFEBB3381275BD43688AB6
                                                    SHA1:03BCB5F18704E3D6CBB2770FFE054945D562FBE7
                                                    SHA-256:E380FF3081D76CA4A2D8518ADF24EEF74027D64EBDCDFDB40DF883380762992B
                                                    SHA-512:B9D24874E113DDAA35EFC9A2D541FFD66906DB7450511734A1576705443E83339804BE15E29FD306CCEBDF305313A7DEC78AAFBE30EFA52CB777915B7B74AF7A
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........R...R...R...[.~.Z.......P.......D.......Z.......Q.......V...F...Y...R.../...F...L...F...S...F...S...R.z.S...F...S...RichR...........................PE..d......e.........." ...$............................................................0|....`A............................................8R..8...........................p .......... g..p....................h..(....e..@............ ..H............................text............................... ..`.rdata...L... ...N..................@..@.data....&...p... ...Z..............@....pdata...............z..............@..@.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):220784
                                                    Entropy (8bit):6.36032206410953
                                                    Encrypted:false
                                                    SSDEEP:3072:R3zEVB9YMX2TKxzciBOv1GIfmhjMTW6vedh2jctg1rVte0OMbs:R3QBu71BwMyNSjctg1rV5s
                                                    MD5:7DE41B5C1F291EF827EB5CDAD67BD3B7
                                                    SHA1:CDA0E233E81193E11E3AB870536CFCE2F2D193F8
                                                    SHA-256:998427AD48C9D5882D19D9C8DD109CF5CD59A260A08EBCBC3AEECDFDB7C32EEB
                                                    SHA-512:F6D6C7F38F44E1667618D2D2652C6CA3BC3E351AE23E358F44356DF1D8A4C35190EAE19B1B7B895223DCBBA5716B32E388CFCE99A552A9DA36C691C8A755FA0B
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......|y.U8...8...8...1`3.>....f..:...s`..:....f.......f..0....f..<...,g..1...8...W...,g..0...,g..9...,g_.9...8.7.9...,g..9...Rich8...........PE..d......e.........." ...$.l...........p....................................................`A........................................p]...)..$........`.......@.......>..p ...p..........p.......................(.......@............................................text...Ak.......l.................. ..`.rdata...v.......x...p..............@..@.data...P6..........................@....pdata.......@......................@..@.rsrc........`.......2..............@..@.reloc.......p.......8..............@..B........................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):1177200
                                                    Entropy (8bit):6.2785709109649614
                                                    Encrypted:false
                                                    SSDEEP:24576:3WXXk9/0SMHaHi/FKR0E9R4cDoK6QvBB3dMf:3WY9BB3C
                                                    MD5:91B2DEC144243DDDD35512C18DD8AF42
                                                    SHA1:E92C0773D8F5823C89D1B644C61BBAB41EF67E33
                                                    SHA-256:97ECD06D0716451E6899B38FA5D9EEE15DA7FD227DFF83EF12F660FE9072DE0B
                                                    SHA-512:7D4A524DE2B3886CF506EB0ADAFAA817287F720AED91B45603D436ABABDAA7D7DD470C54D6F90000A308593522DCB888EC43E8E64C4B14B0BB89B2B893D7B046
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........Gb..Gb..Gb..N.\.Ob......Cb......Eb......Ob......Cb......^b..S...Lb..Gb..f..S...=b..S...Fb..S.0.Fb..GbX.Fb..S...Fb..RichGb..................PE..d...W..e.........." ...$.....2......P........................................ .......:....`A............................................d.................... .........p .......8......p.......................(...`...@...............@!...........................text.............................. ..`.rdata...&.......(..................@..@.data.... ..........................@....pdata...... ......................@..@.rsrc...............................@..@.reloc...8.......:..................@..B................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):93296
                                                    Entropy (8bit):5.9733826679454225
                                                    Encrypted:false
                                                    SSDEEP:1536:Ltu0bipuTJmIdkvCHWm+1d9pb3h9UZq00fRZJ06s7I3hUg:BVbi+9avCH49pb3h9UZq00fRZqhHg
                                                    MD5:F8D7F42BDB2122E11EFC9D086EC92F64
                                                    SHA1:2DD572AA2B77B11E4B304612627EFE1E7D179A8C
                                                    SHA-256:35EF3D4442F6B73566B86695D92D70BDD27ACD7EBF821AA5C2A55BBA40EABC97
                                                    SHA-512:D1BBC123157BF47DDABDA9B9DAAEECA158884C35E99117B57604F3FA43ACAA5911F3C02810CCE573C36CC1D59629FBC8661928321901CFE469E5AE3E38498C70
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........)...z...z...z..cz...z...{...z..{...z...{...z...{...z...{...z...{...z...zF..z...{...z...{...z...z...z..gz...z...{...zRich...z........PE..d.....e.........." ...$.t..........pu...................................................`A............................................L....................p.......L..p ..............p.......................(...@...@............................................text....r.......t.................. ..`.rdata..j............x..............@..@.data........P.......,..............@....pdata.......p.......8..............@..@.rsrc................B..............@..@.reloc...............H..............@..B........................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):494704
                                                    Entropy (8bit):6.330525135579354
                                                    Encrypted:false
                                                    SSDEEP:6144:a9eQmN1Mk83ODlWGERyj5ta1JASCEEDQQMMLhJD5TXYg5hysQbI98n:aPmNc6l+Ry7TpLQSs
                                                    MD5:35B27E83CF4DC5E14F8CFBAB61C983A9
                                                    SHA1:A167EBE4CADEC2CBCF63FF3B4A032D034CF82675
                                                    SHA-256:69828D24CF4D9C9271753EB003604547CC4B6CF2F5CBF99731CF5D0811E558C6
                                                    SHA-512:7F1C3780B9F5A858C91E223268B52A5D37CE208FED388523FF8D0B5B5A8614901907A00B8DB19E56D550AFC6313DD34C19F1F7328BFF43A9DECD352EFDA546FD
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$....................<...............................................P...8.......Rich............PE..d......e.........." ...$..................................................................`A............................................dT..t_...............@...K...l..p ......0...Pz..p....................{..(....y..@...............p............................text...n........................... ..`.rdata..............................@..@.data....R.......J..................@....pdata...K...@...L..................@..@.rsrc................\..............@..@.reloc..0............b..............@..B........................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):340592
                                                    Entropy (8bit):6.382221686307954
                                                    Encrypted:false
                                                    SSDEEP:6144:GjWOBVwWWPIEVpwAOfL0hq+SNre2vHvvMpF1TPM:GyOwHPIEVfTE
                                                    MD5:06D76B26B0C217CA5F009A30A361A7B6
                                                    SHA1:D9785B6AA3526DE214F510ADFED41CC7E5C2E89C
                                                    SHA-256:70B34F2AE1911E447F11958CFB5DC075CB5439089EA08132E10F14F2C2F88BFE
                                                    SHA-512:C122AAF5D52DAD87982AE28DF67F5317DC049940B056E7ABC06DEDF7E25E5E82AD1891D62EB731532EAFD5603D6230ED83B34D6B8429FAAC0E51883CDAC3AD13
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........?J.Q..Q..Q......Q.A.P..Q...P..Q.A.T..Q.A.U..Q.A.R..Q...P..Q..P...Q...X..Q...Q..Q.....Q.....Q...S..Q.Rich.Q.........PE..d.....e.........." ...$.....&......`........................................@.......3....`A.................................................=....... ..........X/......p ...0..\....[..p....................\..(....Z..@............................................text............................... ..`.rdata..............................@..@.data...X...........................@....pdata..X/.......0..................@..@.rsrc........ ......................@..@.reloc..\....0......................@..B........................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):5778032
                                                    Entropy (8bit):6.614298965943744
                                                    Encrypted:false
                                                    SSDEEP:49152:5P1xg9WTAZuPjfF+f5h5icOiuL7O8dfNIHN9/h//oXG520+xZ3oZ41sao:LAZNCYNQXG5goKOd
                                                    MD5:8E8DFB04E1F4F254911FD1DAEC1BFE0C
                                                    SHA1:EF67C26EEEAC54294A7E6A607595A8AB6CA60DE8
                                                    SHA-256:08F606E0CD68616BF17AA4FB46CBB88B9E6C0668F76BF5E76588BD38B9AC8A34
                                                    SHA-512:675450EB1E8501EFE279AC993A8A63954478A715426E4FDCC30221EE22BA65FB1B72FBE9CBDBF58870CC3C5358CFCBCFE369BA717F5092A22D6046C9C420E6B7
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......cZ..';..';..';...C../;...E../;...E..#;...E..=;...E../;..lC..&;..lC..);..3D..";..';...6..3D...;..3D..&;..3D|.&;..';..&;..3D..&;..Rich';..........PE..d...k..e.........." ...$.V6...!......S6......................................PX.....B.X...`A........................................ .F.P^..p.N.h.....W......pT..2....X.p ....W.L....8A.p....................8A.(....6A.@............p6..a...........................text....U6......V6................. ..`.rdata...,...p6......Z6.............@..@.data.........Q.......Q.............@....pdata...2...pT..4...BT.............@..@.rsrc.........W......vW.............@..@.reloc..L.....W......|W.............@..B................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):270960
                                                    Entropy (8bit):5.394886624191087
                                                    Encrypted:false
                                                    SSDEEP:1536:DkwQYYB0ZWSavNzxzubJfRT/Cb8HIx4syFdW11+ZETi0B12wpbt4oD4jJZDOLCOP:xQHB5zxGF6beFIqUpp8vkOWrvV
                                                    MD5:F6D3A1B090059D879C95538AD0E4EEB1
                                                    SHA1:351B700CF046030423CFD3E7573AF49AC78AEBB9
                                                    SHA-256:ADB6E0871AA42875B8EDA2C9ADE49F1565EB45451F6AF81A786BBCB845F6B21E
                                                    SHA-512:3C1338B88CB7ED20E54A096A0153D4B7AD8A411110B13A705D565682DA3DA9BAFD60D527E2CD8C1A86C3A41C1D70B792C3D19C8183267580C477DF2418FA2AE5
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......5..\q~..q~..q~..x.,.w~......s~......y~......u~..:...p~......g~..:...}~..e...t~..q~..t...e....~..e...p~..e.@.p~..q~(.p~..e...p~..Richq~..................PE..d...(..e.........." ...$.....@...... ........................................P......,.....`A.........................................%...:..._.......0..................p ...@..x... ...p...............................@...............@............................text............................... ..`.rdata..............................@..@.data...0{.......v...p..............@....pdata..............................@..@.rsrc........0......................@..@.reloc..x....@......................@..B........................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):19778
                                                    Entropy (8bit):4.506742249246775
                                                    Encrypted:false
                                                    SSDEEP:192:ndscGYxn/aZdntlAb82jPiDJRlGHyNbVMl6wTzBwtv3o7i6q3YrcAvk15Gflp:nDGYxnSb1mzB6+irokDGfj
                                                    MD5:46BDDF3E69B845AC1C59C7352906FE38
                                                    SHA1:9C4DD7507DE1F8A90F3AA2C2935C97700C34CAE5
                                                    SHA-256:AEB67E09E08878484F0C1351A88F823D4A9D063C59EF33F56399747A2F058641
                                                    SHA-512:005B22AB8CD2288D2B8B2D1BE29F2C335BA936E4AB5D4BD966396BFBAF5D4CBA19857BD0C93308A1078742BBD79D3CE4DE8C7B745EF7DFB8DA85E865090D17DF
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):6585
                                                    Entropy (8bit):4.598695759616129
                                                    Encrypted:false
                                                    SSDEEP:48:MCdzO6E+iCshVKzlOWGf0hEVufy9ebNyJUHCShU2sKzlGbSjBV5VCVJys8s8sWWr:ndzgUldGcQWYJ+asieWKNUUxNwl6E
                                                    MD5:4D10A854471E82FE9C1639FA31C650B7
                                                    SHA1:B2D967E879B24C7CB10F41F0643DE81A303B9A11
                                                    SHA-256:98060BFD123D2EE8A00FC6E9EA1C769390EF449CAE69343B84B3D3602769CBB1
                                                    SHA-512:7A192630C134AE54DB3DECE1594DEE9A077131C890BC21DED37E7B617A3EE9839B5B7212460CB326E6DE2F5E42FB628B4442C57AC23312E19C1B607F978C02D4
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5095
                                                    Entropy (8bit):4.707590936577697
                                                    Encrypted:false
                                                    SSDEEP:48:MCdzO6E+iCshVKzlOWGf0hEVufy9qNc/XyU2sMlGbYAJeIcAeYLCYG7ECyNfRjE7:ndzgUldGcQW+ReAJdcVYL3xNwl6op
                                                    MD5:CA164AC3D826D66663092DACF1346749
                                                    SHA1:A49D104698F9262F05A2B79D0E37E3B7CC286A0D
                                                    SHA-256:30D97360EFE13C029774513E6176BF68C8FAC7C87F8E03DDE458C8321784BA12
                                                    SHA-512:9E29605EA07E61353792AAD17B60B39E50C79C2DA411745838C49ADAA262EB17C47983B516604C52BF1B7B2A0B3022643B48F0EA24C29A8ECBF026D2867CA7AF
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):7876
                                                    Entropy (8bit):4.538071539723452
                                                    Encrypted:false
                                                    SSDEEP:96:ndzgUldGcQW4sDA1W6hJNp2MByJuzUQ6sONKNwl6gN:ndscGlsDA1WgNp2MBauV6sONKNwl6gN
                                                    MD5:911DF8B6D57C50176D64598BB623514E
                                                    SHA1:0ACC4D989DBE0025480FCAFB8680816EA417CD5E
                                                    SHA-256:C97BCEA811DC59D480E9857196AC553D4863BA53783040BDFC7F5E339D429865
                                                    SHA-512:4067EA21BA30902934D1995213CDDB95180C0EE0D52AA7D248D5535869361194C79312A1099D3350BF1C43A196EE9DEC12B915D00A7131AF4DEB57C135A3718A
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):10264
                                                    Entropy (8bit):4.632756205734315
                                                    Encrypted:false
                                                    SSDEEP:96:ndzgUldGcQWHgYb5PlokVpaVg+71YlmGzL3lH3DG6lnnqm:ndscGR0xVuIL3V3S6lnnJ
                                                    MD5:BCFC5A243AC02C54BF7DCE968A917D53
                                                    SHA1:8C32A1366569A37A77EA775435B4144E9A3004E8
                                                    SHA-256:F331E1CFA131C3838603948333A1726887817626E6D7569E9540E084DF0D6075
                                                    SHA-512:606E2BB11C1A3F382EFCE09410E020799984FB2547B793B7140F11388E342001DD313A23CF01D2F8E2B0C162C175D0CD3C9F31E3A3C765B53F33660C891A8188
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5079
                                                    Entropy (8bit):4.6854391471828505
                                                    Encrypted:false
                                                    SSDEEP:48:MCdzO6E+iCshVKzlOWGf0hEVufy9PVXNeU2shDGbSMyhcYG7ECyNfRjEIOmr2FN7:ndzgUldGcQWwLM6xNwl6q
                                                    MD5:7E01BECD599DD1E7AB290C1541EDD291
                                                    SHA1:F64C9A96EFFBA7E462E18994EF7933DC912AAAC1
                                                    SHA-256:A4DFF399519267FACFB2F22033C65A03F1F472771CEF1DF91CD8714CC755EB98
                                                    SHA-512:3F0FDCD6AD451DCD0D2AC58A41B46613766BF4D8EDBCB9126FE60D2997A94F01C48CB741923E66DD1E7FB300D9EC456BFF891EA70183B836A502FE22FD1C5B78
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):11031
                                                    Entropy (8bit):4.666918441303095
                                                    Encrypted:false
                                                    SSDEEP:192:ndscGxUUtVOUspxYhZl6aUVBsfyfZWxn9:nDGqPpxYhaaUVBsfyfZW/
                                                    MD5:D9AF0AAB657E1A2D4FB2AE18A8D5CA61
                                                    SHA1:CA846E4A745B55406A63B7DA024291F056EDBB1F
                                                    SHA-256:8E60BB7C92D977238D52808587BA0DCA664D6119278B54453BF07657C815C872
                                                    SHA-512:99E9CA5261DD1F7C5105C6474DFB92A6809F64F6D078D96595B24D0F0F0A9DD82844E7F15E397643811C052A658D319062149AFB9F19145E5FB12F76A5358FDD
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):7217
                                                    Entropy (8bit):4.622194749790818
                                                    Encrypted:false
                                                    SSDEEP:96:ndzgUldGcQWn+HeVrJsaVT69EGs5DFyPww2UKiUxDl66cR:ndscGu+QrJn8ELD0j2UKtxDl6N
                                                    MD5:AF49F3B1F6460643F356DAA270A450AB
                                                    SHA1:B7F81A99D5B23662EFC30D831C97D3BE25372E11
                                                    SHA-256:D575BC8C0419B42DA1881C112ABD76F89FE3E4D115D2EF66BAA60C9391F2E23E
                                                    SHA-512:BD43206D28773744B941BC0FEF328277F5F5CB9ADA4DDD62952723F2BA0A2C9D424B84A534D15C91C0466B9FE1422DA873123C796DB57650EE6B38F8A09C30C0
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):12506
                                                    Entropy (8bit):4.41298894510231
                                                    Encrypted:false
                                                    SSDEEP:96:naizgUldGcQWG3gGj4MhuB4Nd1az/ivsCI8/ivse3gmZJOo1o6ZK5W8f6:nRscGh3g+ldUz/ivfx/ivP3h1o6Chi
                                                    MD5:C4DF6196555578A35D0D81012FB946AD
                                                    SHA1:C33CA563FEAE48724C8F41351A689A4786C682E4
                                                    SHA-256:F1101F41816F3C518EF77077CBDCBEB15F4F8119DB3BDDFC0959CA3C4C45FDF3
                                                    SHA-512:85A99272709A605D55C1FC3F17ED682DB6ACE93EEB2EC1680010676C01F0B4B2C6C0840DE3C5FBBD321F138A5EB0B83E576F82B207ECB26271E781A5EE831273
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Copyright (C) 2017 Jolla Ltd, author: <gunnar.sletta@jollamobile.com>..** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foun
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):13881
                                                    Entropy (8bit):4.530949121957846
                                                    Encrypted:false
                                                    SSDEEP:192:ndscGAwf/x2bVV4xS+rAY9cNJGBRNaTiN/spNYZ4N1SzayJA/+:nDGpxW4xIIxmPcu+ayt
                                                    MD5:6488C787CEA588F7DD68FF4ABCC19461
                                                    SHA1:ACB301300C633AFFE5A515C026E73B9B0D81C91C
                                                    SHA-256:00F6ECA1EB3A1730C09D6657E8A00FBBFAC4944D6D63AC2FB64BD64D48F6491A
                                                    SHA-512:4F61B5F56FCAB5FE9CA6FEE35DC2405394357A6441C76DD148D74F179B28D6D93C581CD4CCA05091918640C1ECED1BFD17360F6DBEBA0B73100E3C4CFB1D7BD4
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):6235
                                                    Entropy (8bit):4.646552357232257
                                                    Encrypted:false
                                                    SSDEEP:48:MCdzO6E+iCshVKzlOWGf0hEVufy9cWNcDU6gk4aU2s4X8dGbFA8NwHlOvu/sJYvt:ndzgUldGcQW66g0uVsvudKNwl6FI
                                                    MD5:9C511E64D3916DA3EEFB6DC01DE7D858
                                                    SHA1:112E4A7B63CEACF737063C1B55FAA3A478D0EE47
                                                    SHA-256:F44A77C8067D0E0FEB45CF34DCF903CE5DE259C481E78E853EDA7B9340CD9761
                                                    SHA-512:4BDFA8596D3E72519F5F1A3E461AD9B8202B9A5F075CBE6FF6453F613BB4FA7F39128193ADF040554A9BD037B8D058B18587E85F73289E83F0DA32381A83A056
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):13602
                                                    Entropy (8bit):4.592145296083761
                                                    Encrypted:false
                                                    SSDEEP:192:nRscGS7ilRz/iv6AT91jCiGh497m9MDJfsYI7GpiZPdt0jIvficiLo:nfGSsOKhS9qgsYI7GQZg0HiO
                                                    MD5:48D62C1689F36F3AA9D4BC54B1DE6FF1
                                                    SHA1:EB863252158AB9AE65ED23058DDA38C6220D1ACA
                                                    SHA-256:CC9533D47C61A70E997882962A870DC4BBB466B88B7D54A9277C8FBAB168B1CB
                                                    SHA-512:45A58B3DA6DCA3A4867AD6804948F18E2640C6AEFCCA0337DE6C6C4F8D02F1EEB483F75F7A8B7C10C04A2869D4ACA8462BD8DD8C0756BBAA1701D6C7738310FB
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Copyright (C) 2017 Jolla Ltd, author: <gunnar.sletta@jollamobile.com>..** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foun
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):10025
                                                    Entropy (8bit):4.44241789855634
                                                    Encrypted:false
                                                    SSDEEP:192:nRscGiaShPFtc/z/iv0/iv6M19kdywWULh:nfGiaSpFa0GD
                                                    MD5:517A0AD29EC812A277469AAB0E5359FC
                                                    SHA1:5354D65E640C5DB8012E36E19A0BC6CDE532B0F4
                                                    SHA-256:91EB6624C489C506C54ECAFDC1EC9703A26A664995C833BA74B69D3F48C09B18
                                                    SHA-512:809D2E10BCDA518FC1959F1EB8547DB0B604BFBD4A3C00C5150B75BD093CFB0FF07421031A014E67EDE75AF7151956F63CDCB4FD913BEE9344015F058CA8BB6D
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Copyright (C) 2017 Jolla Ltd, author: <gunnar.sletta@jollamobile.com>..** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foun
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):7419
                                                    Entropy (8bit):4.551795677868133
                                                    Encrypted:false
                                                    SSDEEP:192:ndscG6u7i5shleXBbwKg833KpNKNwl6Mo:nDGhKhMo
                                                    MD5:27721C5DA4FF5FEDB10808941D939E9A
                                                    SHA1:F3309F93E9F4387C5DA1AA395BEA04EC67CB8FAE
                                                    SHA-256:47E9054D530990ED45650F2ABD8E9212A3FF5D63B2E20AEBB249B3F414216602
                                                    SHA-512:FC3FE0D96120D5213C344A35761AD09E6377FE2ACD145D91E3A3812A9C3270D40797CC7DA6C84F365277E21DCCB872135078B686F53536A9FF005C15C91180B0
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):12859
                                                    Entropy (8bit):4.38678757261808
                                                    Encrypted:false
                                                    SSDEEP:96:ndzgUldGcQWntfslJqz5Wa32hoASjcB8wPZ8:ndscG6fEJHa32h/lPZ8
                                                    MD5:4923D3751EB8B78D8A459D2EFEF66948
                                                    SHA1:331250B29A4E6E934A5C4C3C09203A18D8B5416A
                                                    SHA-256:0BBB5AF2E58FF3696937560DA502DC844D792A26E1EFC73F7A5165E410224386
                                                    SHA-512:6026945A2A02C426FF990F72AA752D4B6FE6EAE184D033C843638D79EA5171DB621CB9A80622FB12D0EF8623FA14A133BFE1B78DEA35B0D2333E10A8EBB712B3
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):15891
                                                    Entropy (8bit):4.556057731614295
                                                    Encrypted:false
                                                    SSDEEP:96:1dsgUldGcQW62Jm7mNWiEyNCNPbjbdKNwl62/+e:1dRcGbrmNWiPY7KNwl62/+e
                                                    MD5:6F9FB56C6BED19906E1864393C76ABD5
                                                    SHA1:E4A6F84CCE7885E9970F048677213D1EE7470296
                                                    SHA-256:87B2ADE3F9E6C5C7B0E5F2EB2F1EF9F0E543D428FC62ACAD58CD8D3A9FD7B188
                                                    SHA-512:6B0314D75B5968957AA69EBC13B72C09C2A5C85ED30AA1B76E70C3B10E086E6E1A2A1882E2BD7334835481E0907BAA5D1F43AD14F06EAC1273D770DC22CCDF10
                                                    Malicious:false
                                                    Preview:/*****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Add-On Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..**
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):10829
                                                    Entropy (8bit):4.563214234773607
                                                    Encrypted:false
                                                    SSDEEP:192:ndscGbAX18AIIe1IefdLSacSS935aX9l63H:nDGbAX18AIIe1nfdLSacSSVX
                                                    MD5:0C441705CF894B52EA283C9A0B72C1F9
                                                    SHA1:F82C2B2E00D906176F90A5E53A53A747303146AE
                                                    SHA-256:21F3E2CF42F8A429458008EFA155C6EE984FD9D2D96FA5B5C9B027AB9BB45EE3
                                                    SHA-512:F52E3E111D9EF32F44D77D304378BFF3E9ADA3E38E740A872D6A6BC84F87037F43FEAA8844C993250C35E0A7CEE36DC1D01FFA09ED8E36EEA8F12834C8911EBD
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):7807
                                                    Entropy (8bit):4.639117118840595
                                                    Encrypted:false
                                                    SSDEEP:96:naizgUldGcQWO9bDMb4L1EKimatisMRA9ryd5P:nRscG1pIUL1GMR8Od5P
                                                    MD5:E1547CFA62DE702D4E06A8312396FF74
                                                    SHA1:4DA2C91538D8B81C640BF4F148A07DF57AB2EB27
                                                    SHA-256:70B5C9437F093FBC2BFD448C7C088C0A27C1141E5F592C42A436AE8F19CB0143
                                                    SHA-512:0FA55542D60493B431C0035C24F094DC0C044AA1A5982D0C67B07E4792B063A3FFD4FA4858BCC92D5781BBA22E8EA78D1CBEA806846C0823A158FC74A7D1AC0F
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Copyright (C) 2017 Jolla Ltd, author: <gunnar.sletta@jollamobile.com>..** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foun
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5585
                                                    Entropy (8bit):4.685627644589191
                                                    Encrypted:false
                                                    SSDEEP:48:MCdzO6E+iCshVKzlOWGf0hEVufy9ONXU2sorhGbHasxGDt5EYG7ECyNfRjEXGqaA:ndzgUldGcQWQLDxoLVNl6l
                                                    MD5:41BAD5D7D181DB5BA516B5006E79E9C1
                                                    SHA1:407538F15D386CBAE91281A981EBA1F8CFC05E06
                                                    SHA-256:2E3DE7C4034B1F9D3376A827CF4A9A910E36431B5D5C5D002C2FDC2ABC05056E
                                                    SHA-512:07644CD9C91C039E6C872B6ED3774BFF860F96EFF2188F3A014B393B3FECF735DA599A6B21B3367D1948B3484BAFD893F6B89149A45B912F2CF35EE755D2121C
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):12345
                                                    Entropy (8bit):4.66784524518964
                                                    Encrypted:false
                                                    SSDEEP:192:ndscGGHNtsOt3z2xNhZl6S+JU7NkdkMDiiFeXaTn9:nDGG12xNhaSgU7NkdkMmiFeXaZ
                                                    MD5:0BDA852F4A3DA9E70944CB9B324139BE
                                                    SHA1:49226B8F2BAE75B5209AF9BD65AF6FA73B25EF1C
                                                    SHA-256:65D16512749C9B8F307265434A4C09BAB3188E49C4EFDC74065FB1F4F0FBCB70
                                                    SHA-512:173BBA2F258E4FE8294F3ECE2C63FF3314146A367F5F786335EADC73B84251E4E7AAF42BDCBE640C63414A467ECF7ECD728F48D4D03C31021A16A2FEC94D9863
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):13745
                                                    Entropy (8bit):4.494703020202901
                                                    Encrypted:false
                                                    SSDEEP:96:ndzgUldGcQW7ByvGv05ahXcPG+6Pi2g+7/YHzo135aX9l6lrik9niAjC:ndscG/sMcPii35aX9l6NX4
                                                    MD5:ED1B7F1AE4D19D1151383FB13E355979
                                                    SHA1:1206793A0E96BCCB75D27C569B61DC8A281849EB
                                                    SHA-256:92BD66E1097F20411A27741A346C88E47B6F9EC6B560FE5A4BA2F756B4418AEA
                                                    SHA-512:7D17B7AF9E6E8E13B770B1B7B5FCB4B75EB6593C81DF87B70ABB1F61FC48166E9B300271F06088CE42D20F83D9CC251E2B8E5EDF11DA74E256DE6F81541CB7FE
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):9305
                                                    Entropy (8bit):4.537386224718856
                                                    Encrypted:false
                                                    SSDEEP:96:ndzgUldGcQWkXn0HNUJAsRmHSuMTmtnWxbQ9VJ:ndscGz0HuJAsRmHSuMTmabE
                                                    MD5:026A4FABB695B3E2BA6C446A464C2BB6
                                                    SHA1:7EAC97EDB6C66FFCA0326697A1C3BC03934726AA
                                                    SHA-256:D42A02D92090166EC878425F28061034C976F3012D1AB6663427E22F84775B41
                                                    SHA-512:4E856E3CF388095FADBD93AEB41613E6BA659BA27EA1D3F7328045C3A05981B0631750E2DEBF7A37D29CAA158B391AE40ECDFEEDE90DB1A0626FBCD8525D61CD
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):11649
                                                    Entropy (8bit):4.575505434264538
                                                    Encrypted:false
                                                    SSDEEP:96:ndzgUldGcQWlbSOF3vHd9eTG8YKCtdbQxiXd6lM54EMzefgbEKaGzSJAIWPkCWN7:ndscGyvF/HTrJ4n9yQBuqIWwRp0LxW
                                                    MD5:5856FB30F65717A3AE1AF8985F9EF38B
                                                    SHA1:22B2DDB2226907F3C5D9554DC65120F8721F02E5
                                                    SHA-256:A15EC6D00168B3369004C406E513A71C1C1082DF2F66EA086A9B956E23189E5D
                                                    SHA-512:D69F9E99E95E45E6EB269F39074EC5107EB81D721F65B952A7F316B080C53D5886C194AEF02A1C1338BE6CEB4B42C2E6CBFD1FF462EFA3406025EB1CF19822F2
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):7462
                                                    Entropy (8bit):4.5825621177486955
                                                    Encrypted:false
                                                    SSDEEP:48:MCdzO6E+iCshVKzlOWGf0hEVufy98N6D+U2sPrhGbHoxGDtlGHyMwRQM/MMM2GkV:ndzgUldGcQWgMoxoPqKbTmY
                                                    MD5:14B0BA19DCDB591AF93735CED2B235F5
                                                    SHA1:E78F75E1C8453A98AA0A7BCD0A4F08B5FFED092F
                                                    SHA-256:2F3593F4FBEC921A1DE0331C443505B0F70AA2E40834C5A1175E298874585B46
                                                    SHA-512:8920FD4F081738E5A21F40DEB78061DA0AE27B8324DAFE4B96E01C1EC99E9DDC3D9F4E070DF6F2827F508AB827E6B43013618DDFADACEC86DDB8CBFD74E06C43
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):11760
                                                    Entropy (8bit):4.654708081969159
                                                    Encrypted:false
                                                    SSDEEP:192:ndscGl6axN/+QCpKYhZl6/UVBsqeiXabD9:nDGf6pKYha/UVBsqeiXaN
                                                    MD5:549BF8839B5460FA531BF5EB9AD8079E
                                                    SHA1:C44C223BEA82BAB57554120B7569465633D0774D
                                                    SHA-256:57D3FB9FF4D4F5D3CD33FCBF45EF156CC74A3BD1A39A76CB6BEAF98F86766DFE
                                                    SHA-512:CB29397C53050F73BD08B7B97AD7F8B6B5C0F1C78E9B600BCF8AF55843B0531DE815133ACD3B18BBCFCCC95FBFAE3F411335C05DAFE7D66EB8C3311E372F83D4
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):327
                                                    Entropy (8bit):4.927041556088633
                                                    Encrypted:false
                                                    SSDEEP:6:IXsKNhYs2FUbJotxLfyj58NS20t37+ASekQ2JdHE9ItULe8yAJZ4Pm:I8VFJtx+L7Ix9E9uULe/Av8m
                                                    MD5:C76BD51B4EC5299E2CC9EBDB505AB848
                                                    SHA1:430083140E4AAB9ADBF39AD81E2FC820274A82A2
                                                    SHA-256:6350C17D1667563EB1DFBA75FE5C4387CCC3F18F8EA1E266648F5DF463C1CCF1
                                                    SHA-512:88068751E49C91D6309098BCAA76A6437ABF36EA1C14174E250ECF5B0F4A55A85BF42607D7B4CF61393D8B7DAD41C2DBAD3A4D15D3726667FD572E06F9B5B40F
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2....// This file describes the plugin-supplied types contained in the library...// It is used for QML tooling purposes only...//..// This file was auto-generated by:..// 'qmlplugindump -nonrelocatable QtGraphicalEffects 1.15'....Module {.. dependencies: ["QtQuick 2.12", "QtQuick.Window 2.12"]..}..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3802
                                                    Entropy (8bit):4.836210598784799
                                                    Encrypted:false
                                                    SSDEEP:48:M0iOO6E+iCshVKzlOWGf0hEVufy9OtsZjO/26l27xJa53KfzX6zVuOfeD:JiOgUldGcQWkQW7xJq3KfjQV+D
                                                    MD5:BEDBC5F0389093B378549613B882DAC7
                                                    SHA1:57C4D4FD27D928FAB37CAAE5B366BA603EA4E36C
                                                    SHA-256:8CF00941F226FB8B15A476FB2CA902E53D8B7092077A89A50DCF4D3B393B8996
                                                    SHA-512:CD2F4DC1797E00371FF31045CB5025041B8ED2A2339F7FBE92777A19580CDA9AFCC125247C6153D3AC9F09E05C38BCCD4459F804F7B5487F199510C86356F943
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 Jolla Ltd, author: <gunnar.sletta@jollamobile.com>..** Contact: http://www.qt-project.org/legal..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):9961
                                                    Entropy (8bit):4.5553960156757025
                                                    Encrypted:false
                                                    SSDEEP:192:ndscGMzlWrTY9cNJGBRNaTiN/spNYZ4N1/WbMXyJA/W:nDGMRxmPcu/byJ
                                                    MD5:0531E44FE5BCCBECBFA912EF5E82EB69
                                                    SHA1:8504E4A972B0806630525F1D2C3E9F935A0C9313
                                                    SHA-256:AD22212950A1C8D9B09F6FA0393F8C0E702CFACC05241B0D5DF0D3D2BA9CEFA5
                                                    SHA-512:1D2BC9F22D1286AA5BE3BF8291A1B33020717F3C3E509634C0497B1FE5CDD4B7A070DABED0AC72CBCD5514DFC2B0449734F79E9AC683C171C649466620587161
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):10099
                                                    Entropy (8bit):4.5547161392604325
                                                    Encrypted:false
                                                    SSDEEP:192:ndscG1zlcCqBY9cNJGBRNaTiN/spNYZ4N1SblXyJA/R:nDG1JxmPcukyA
                                                    MD5:C2C13CC2208F6A6A30139CFA572A7067
                                                    SHA1:EDEDFF0BBF7B6F6FF4A7E6B80A27DD4A6209DC8F
                                                    SHA-256:C3EDFDA7C3677D94681E002C1CE62D1BEA074A04A6232BC398534470F09E2578
                                                    SHA-512:852B2408EE6F8BDF2250CA023A15253467BD3045BBE5AC992261B0B517B616FC6B6F43EC279D83E0AD823384450C6C793CD6E94341A3BA936DAB1663EC7A7FA6
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):7916
                                                    Entropy (8bit):4.650054740700734
                                                    Encrypted:false
                                                    SSDEEP:192:ndscGeOTRkgrAr9cNJGBRNaTiN/spNYZ4N0Trs:nDGehr5xmPchfs
                                                    MD5:681FFB907DC7876FEF710231C3F0D693
                                                    SHA1:DF3DE413EEF094DCDCF6BF0768304859C98AB00D
                                                    SHA-256:D21C5523227CC24443C5A33D89D7A957BDA2376EAE16B9D2B6FBE5AED7D68433
                                                    SHA-512:B82D979FBBAA3DEB154BF90EFCA76401AC3ABD7D04C71B5AE3CFC4DBB342BED7B387E609C1DC409431A439CA7DDCB65A85FDE9A3A39B69C0166CB4A6DBF62353
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):12752
                                                    Entropy (8bit):4.927987689083792
                                                    Encrypted:false
                                                    SSDEEP:96:ndzgUldGcQWR8yl69yuT/jrKOxgmk1Rh+0qpj85TKsv2ceErtdtP+tTtxtUkKD:ndscGvyl6U7JtfNdtPepnU/
                                                    MD5:C0E84EC177B5BD2899D721683311E5CB
                                                    SHA1:1016D6790C4FC3C234F5FBB01DC7678E669135B7
                                                    SHA-256:883D1D8BF62E98EE7D4590D647DC1B5E0B24213C646FE9F6C91C806B59E2277F
                                                    SHA-512:5064F419868CDD32E6CA6DB3567E3EEB5E6B3E4A1EE8A3586B3B0C948972905057D9BD49A00E4612D817FDC7D664125C04B1D89D2BF689D6E09BAF37FCAED646
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3823
                                                    Entropy (8bit):4.784379577769776
                                                    Encrypted:false
                                                    SSDEEP:48:MCdzO6E+iCshVKzlOWGf0hEVufy9pnu6IwSYh7NlyuNTIMiGgjb7OeQ7ruI:ndzgUldGcQWoSYhZlysUb7NEyI
                                                    MD5:E2C260FE7963564B5489900BB4DD3F35
                                                    SHA1:9093C5C745196084D9A034D11CE5E605B62D2595
                                                    SHA-256:04D9A63435F6C8723A0744274750E305375D63532DD7D215526501C66DD0C690
                                                    SHA-512:5F2C6ED09A2647C3C1875A8FB1E3B65FC58CDF99F7245F2F1F820270F2D22EFFA5883766100F7BDE27B6C34C3A50308BB85BD54341691D3A88C3FE50C863969D
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4345
                                                    Entropy (8bit):4.758638626564817
                                                    Encrypted:false
                                                    SSDEEP:48:MCdzO6E+iCshVKzlOWGf0hEVufy9pnuU2YFpNlyIf8jk7r5Q0SOp:ndzgUldGcQWIzlyoQw9Q0Sw
                                                    MD5:87972FA777906FF3A3F0C86989BC7FB3
                                                    SHA1:F015E3685E60CF7B53A6F92448F646E17F34BB7A
                                                    SHA-256:E47DB40488C3CAAE81826F4A070BE22F2FC3D2720F69E6359E7CF027121BB524
                                                    SHA-512:0CCCF2B60769BA97731E90FB1806028072D0676D62652EBDDEB19808CCAE62F4D7BBEF5F5AE2F94B746759B677501FC51DB9E07B9C0163A725F390973728694B
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4041
                                                    Entropy (8bit):4.809241191703437
                                                    Encrypted:false
                                                    SSDEEP:48:MCdzO6E+iCshVKzlOWGf0hEVufy9pvuISYhuh7eaUpTIMiGgj4JmHeQ7rVJmI:ndzgUldGcQWgSYhuhyaKU4o+EpoI
                                                    MD5:436B9F140A9E5B7EC88FF6AB8AABA2F3
                                                    SHA1:716697CE121CFB3601FB217C41ECF8578D3A9C7D
                                                    SHA-256:98A39F372BC7A6DC83A4E7E51B56D2AA81E458DB1B3AA05850B3C22CF4C2F9DC
                                                    SHA-512:4B1EA38CD82E2C73EC3282D8523EC7060656DB7143045A6E8F1A8F437B0333E3811D48A496E230DFC9F4D727D9315ECCDA71C48329B3ED865DC4DF9A7AF9D4DD
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Graphical Effects module...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packagi
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):446
                                                    Entropy (8bit):4.831008563710771
                                                    Encrypted:false
                                                    SSDEEP:12:xr9UIm6eQNuuWFEUG1bkAddYMUEqRpXQu:t82NuTep1LzVypl
                                                    MD5:82BE01F1AD655AE2E5068903171BCA0A
                                                    SHA1:810ADFB9C00A5FA65AC7FF30B0A2CA05F873E058
                                                    SHA-256:D7681C4C0C927F07EEF863A156E254BDE0BFEB48A0EEA88F135B80325AA77FDF
                                                    SHA-512:97E777FC63A9D851B52A4B9FC2EC1696A3F0BEB72DBD91FBBB8EA7F16CBEE421D4707DCC11672F6F8AEAD8098FA3DF3B6044607AACD3F573D5A0B22F4CFB611D
                                                    Malicious:false
                                                    Preview:module QtGraphicalEffects.private..plugin qtgraphicaleffectsprivate..classname QtGraphicalEffectsPrivatePlugin..FastGlow 1.0 FastGlow.qml..FastInnerShadow 1.0 FastInnerShadow.qml..FastMaskedBlur 1.0 FastMaskedBlur.qml..GaussianDirectionalBlur 1.0 GaussianDirectionalBlur.qml..GaussianGlow 1.0 GaussianGlow.qml..GaussianInnerShadow 1.0 GaussianInnerShadow.qml..GaussianMaskedBlur 1.0 GaussianMaskedBlur.qml..DropShadowBase 1.0 DropShadowBase.qml..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):64624
                                                    Entropy (8bit):6.023878067422852
                                                    Encrypted:false
                                                    SSDEEP:768:DEkNSBvaczLN1CO5IE6Hl4S0J44b6dDLMH3XK/+arBVYd/EYif3hf/:DtN2vaQSHwqfBud/E7f3hf/
                                                    MD5:259205E2F143884C5554B671E1B3A3F6
                                                    SHA1:A052CF8BEEC2043B06315929DD80E8DA074E4AF3
                                                    SHA-256:F1228CFD8EBF7B3E19311E53269299CB79BF38AC0918F22819E5EEF330A0013B
                                                    SHA-512:56E7DC3156EA0B8990937C2E1B1FDB571D3D09EF036A3A6F8864FC746CB0491D9950BBC16EB115E4FB584C23A9A0BE4C97767E1D0B1DD04132C5DA5CCD53E363
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........(...F..F..F.....F.+.G..F..G..F.+.C..F.+.B..F.+.E..F..G..F..G.e.F..O..F..F..F.....F..D..F.Rich..F.................PE..d...>..e.........." ...$.X...........].......................................@............`A................................................H........ ..h...............p ...0..4...0...p.......................(.......@............p...............................text...;W.......X.................. ..`.rdata...b...p...d...\..............@..@.data...............................@....pdata..............................@..@.qtmetad............................@..P.rsrc...h.... ......................@..@.reloc..4....0......................@..B................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):1016
                                                    Entropy (8bit):4.97599520054607
                                                    Encrypted:false
                                                    SSDEEP:24:teatRDyUyGlETnlADBYGckBupY8dL6L7toVyiAkRlOPlyNOwPtZAHFK:IcVyhqOna9LBl2ovi3Al6zoE
                                                    MD5:B30FDDA9D8391BC35EBFDDB4AD45952F
                                                    SHA1:E614ABD59DCAFD491E456CB48695A4C932D05B0C
                                                    SHA-256:A33AC64A4DA419166EA7B498F5B5573B8B0F3D9068C7506C6911F17FAEB947F0
                                                    SHA-512:6265E82481CF9627C3FC75458389F61CAE3A5FC719662AD673B6C7F4CD52AC3CCC0AC940EDBA3E8537FA511FC15B69002D17216F351F99BEC335C24014396901
                                                    Malicious:false
                                                    Preview:module QtGraphicalEffects..plugin qtgraphicaleffectsplugin..classname QtGraphicalEffectsPlugin..Blend 1.0 Blend.qml..BrightnessContrast 1.0 BrightnessContrast.qml..Colorize 1.0 Colorize.qml..ColorOverlay 1.0 ColorOverlay.qml..ConicalGradient 1.0 ConicalGradient.qml..Desaturate 1.0 Desaturate.qml..DirectionalBlur 1.0 DirectionalBlur.qml..Displace 1.0 Displace.qml..DropShadow 1.0 DropShadow.qml..FastBlur 1.0 FastBlur.qml..GammaAdjust 1.0 GammaAdjust.qml..GaussianBlur 1.0 GaussianBlur.qml..Glow 1.0 Glow.qml..HueSaturation 1.0 HueSaturation.qml..InnerShadow 1.0 InnerShadow.qml..LevelAdjust 1.0 LevelAdjust.qml..LinearGradient 1.0 LinearGradient.qml..MaskedBlur 1.0 MaskedBlur.qml..OpacityMask 1.0 OpacityMask.qml..RadialBlur 1.0 RadialBlur.qml..RadialGradient 1.0 RadialGradient.qml..RecursiveBlur 1.0 RecursiveBlur.qml..RectangularGlow 1.0 RectangularGlow.qml..ThresholdMask 1.0 ThresholdMask.qml..ZoomBlur 1.0 ZoomBlur.qml..designersupported..depends QtGraphicalEffects/private 1.0..depends QtQu
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):69232
                                                    Entropy (8bit):6.088795156635426
                                                    Encrypted:false
                                                    SSDEEP:768:jnwgBTZWS7/JOyZcCaMgtz8jd4lpdj9Ik4z2txUuM0ZzmYiQ0T23hTXI:jlB0rquM+zm7J23hTY
                                                    MD5:A77196DEA19E41E0E1B1190A1404A3C8
                                                    SHA1:A4C5CA0248866A3B05D3CE06FA684C7375F08A0B
                                                    SHA-256:D0F6B29CB5C7E00A70AE9844F1DA48A4C2581B5CFBC4EDE214EB2AE6531F7EAD
                                                    SHA-512:BDA81A70E7670052DC9D9A0E3A5DA2BD74545E0D2A9BF73805F71EB340D4DD8C6A87AD3339845FF65F99F64E8DA25D6BBCF29B598197DDF23E1C36F9FDC30157
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........g6...X...X...X..~....X.OxY...X.~Y...X.Ox]...X.Ox\...X.Ox[...X..yY...X...Y..X..yQ...X..yX...X..y....X..yZ...X.Rich..X.................PE..d...2..e.........." ...$.....................................................P......U.....`A........................................p................0..h...............p ...@..........p.......................(...p...@............0..8............................text............................... ..`.rdata.......0......................@..@.data...............................@....pdata..............................@..@.qtmetadt.... ......................@..P.rsrc...h....0......................@..@.reloc.......@......................@..B................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):17795
                                                    Entropy (8bit):4.531606609597201
                                                    Encrypted:false
                                                    SSDEEP:192:K3cG+MnvYYP8Jkc3poWCDGSRLClpyzz0TNB730AI/0LlMOfxCG/RmJyv0:PG5wq8nws6Uu0LKmv0
                                                    MD5:8D98EF9242625655D7BCC563BD2CBA5B
                                                    SHA1:0C8A712780E2809575A6FC5047AD4D383155FA9F
                                                    SHA-256:601A5EB469133E4813506E3DE7D59E8F6CA3D1C808DFDF660263462620FF813E
                                                    SHA-512:3FD06CF3D97B7ACAE76BA6C81CDA4B8B1FFBDDE0F83A0B676F7F4695FA3E819F177F3C3C4A3A112BDFD42C3460351A1DB32ABB8AA3D23384EDCBE2AD17144868
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in the..** packaging of this file.
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):279152
                                                    Entropy (8bit):5.860740256994506
                                                    Encrypted:false
                                                    SSDEEP:6144:Z2ivlDZ5D7YZW/BW018PN0Eax5Q8Bj6F1UVtK1:Zh9t5bwFP
                                                    MD5:914BF63D700AB3F951842929D390F94F
                                                    SHA1:DDD47431E2752C6B79C2FC1CB06BC62009426560
                                                    SHA-256:AD875B3AF4E0E6C7EB7D3D9B21F8962904BB51E06A6CE3F88AE82B4173287053
                                                    SHA-512:D33487E8C195A18D0A341FEE80B6F4F38C4CB48276F12B310FC88864B8DC0DEE1C79007FBCB6158BD4D433F6B3183A48FB2E473ADBAA1906B2F85A76D6F421C8
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........L..."T.."T.."T...T.."TX.#U.."T..#U.."TX.'U.."TX.&U.."TX.!U.."T.#U.."T..#T*."T.+U.."T."U.."T..T.."T. U.."TRich.."T................PE..d.....e.........." ...$.....<......@........................................p.......$....`A................................................D........P..`.... ..0...."..p ...`..........p.......................(...@...@............................................text............................... ..`.rdata...f.......h..................@..@.data........p.......T..............@....pdata..0.... ......................@..@.qtmetadr....@......................@..P.rsrc...`....P......................@..@.reloc.......`......................@..B................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):79219
                                                    Entropy (8bit):4.099287752753553
                                                    Encrypted:false
                                                    SSDEEP:768:G5pkjZSE5ofSJS1OeajeRpdXl+p1xTBDBNU:bq1
                                                    MD5:41DF66AD5F8BED5FBFB6719A4BF6F3BA
                                                    SHA1:B3D8A12AC7AC5CD29908F60A06B24C81F617B5B1
                                                    SHA-256:34185224C6F82D8DE0656BAC43EA855316267B862EE129F134B3AC53A54A0ECE
                                                    SHA-512:5CC89F3904B6516A10589B7DD1FE512537F6FF31384A4075269C2CE57E872DAD3BB3E01290359B95E96AE64517B5EF5146932200CE5D3071B5F808B5E4A9E6AE
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2....// This file describes the plugin-supplied types contained in the library...// It is used for QML tooling purposes only...//..// This file was auto-generated by:..// 'qmlplugindump -nonrelocatable QtMultimedia 5.15'....Module {.. dependencies: ["QtQuick 2.0"].. Component {.. name: "QAbstractItemModel".. prototype: "QObject".. Enum {.. name: "LayoutChangeHint".. values: {.. "NoLayoutChangeHint": 0,.. "VerticalSortHint": 1,.. "HorizontalSortHint": 2.. }.. }.. Enum {.. name: "CheckIndexOption".. values: {.. "NoOption": 0,.. "IndexIsValid": 1,.. "DoNotUseParent": 2,.. "ParentIsInvalid": 4.. }.. }.. Signal {.. name: "dataChanged".. Parameter { name: "topLeft"; type: "QModelIndex" }.. Parameter { name: "bott
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):140
                                                    Entropy (8bit):4.506337276553492
                                                    Encrypted:false
                                                    SSDEEP:3:3BsQB174m96tWWm2kwkJ+jrRoLV06qWorQqhFzV:x3fz9t2kjCTegQqhj
                                                    MD5:44E34FA143BFAA33F9DD6EBD13EF0466
                                                    SHA1:DF857A43B313C8D531FFC3C7BD33C14625BCD06A
                                                    SHA-256:BE3831209463405A965A7C66A178D4FFFD0C2F10DE168EBF851CC0965D2C20D3
                                                    SHA-512:BB2C2F3C95508BD6326AC3E29A3765FE8C6ED9B88ADC54BFAD1EA851A957E7575A4E0A254DA4B65D30AC82B081E338A9E60B8B62F6A7C7A5073892303BEEE8DE
                                                    Malicious:false
                                                    Preview:module QtMultimedia..plugin declarative_multimedia..classname QMultimediaDeclarativeModule..typeinfo plugins.qmltypes..Video 5.0 Video.qml..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):27248
                                                    Entropy (8bit):5.903702121363682
                                                    Encrypted:false
                                                    SSDEEP:384:vsoG7s0va8NdO8chs7th1Hjd4ZelvR1uIYiLeG8JN77hh6SG:cDvjc8UO712ZEvR1jYi23hQSG
                                                    MD5:80B64FA41F6F306B19FF03DF019BC5A5
                                                    SHA1:163BAE40CFF8FEE547D704779324A26C830E7BE7
                                                    SHA-256:0FEAFCBB6252EBB63632017024B7AF8634702C2AA33AB878930242A8FB0F64B7
                                                    SHA-512:1DE716187A75971CA1C02EFB34B600A434647606A6CA2D172B67248D9781A7ADF8DCD3E8A39736E2041DCF25BEE7DF71D1C77D68D0C4E2D6B4902FC1B2FB0F04
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........zC..)C..)C..)J..)G..)..(A..)..(A..)..(Q..)..(K..)..(@..)W.(D..)C..)...)W.(B..)W.(B..)W.c)B..)W.(B..)RichC..)................PE..d......e.........." ...$.....6......p................................................\....`A.........................................B..|...lC..........P....`.......J..p ...........6..p....................7..(....5..@............0..(............................text............................... ..`.rdata.......0... ..................@..@.data...P....P.......<..............@....pdata.......`.......>..............@..@.qtmetadj....p.......B..............@..P.rsrc...P............D..............@..@.reloc...............H..............@..B................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text
                                                    Category:dropped
                                                    Size (bytes):14927
                                                    Entropy (8bit):4.122535461102779
                                                    Encrypted:false
                                                    SSDEEP:192:HGi/1PbLDlYHD6x5506yX0y50yUa0ygPNNyEeeyLNNyWNNGNyaGjyugy6yjiNzDD:gC9mTzpkV
                                                    MD5:0D3162158029F3536DAC2EC770BD6941
                                                    SHA1:8B475D4CED3D8A40B2E6FAC08B9F938F1AAFEB10
                                                    SHA-256:62561D56FCA22B762056DD6F08103FC060D3A3825074554BBA68C3CCCF023AAC
                                                    SHA-512:27A632EF47E9E965345EE1A00C86146DB3ED63742B577DA1AE5D27803B787CDACF7B9C054577D82F150DE16D797F8A738D8EC4D2E9EBBC026E2F6AC6799AA299
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2..// This file describes the plugin-supplied types contained in the library..// It is used for QML tooling purposes only..//.// This file was auto-generated by qmltyperegistrar...Module {. dependencies: []. Component {. file: "private/qqmlmodelsmodule_p.h". name: "QItemSelectionModelForeign". exports: ["QtQml.Models/ItemSelectionModel 2.2"]. isCreatable: false. exportMetaObjectRevisions: [2]. }. Component {. file: "private/qqmlabstractdelegatecomponent_p.h". name: "QQmlAbstractDelegateComponent". prototype: "QQmlComponent". exports: ["QtQml.Models/AbstractDelegateComponent 2.0"]. isCreatable: false. exportMetaObjectRevisions: [0]. Signal { name: "delegateChanged" }. }. Component {. file: "private/qqmldelegatemodel_p.h". name: "QQmlDelegateModel". defaultProperty: "delegate". prototype: "QQmlInstanceModel". exports: [.
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):90
                                                    Entropy (8bit):4.243754459555475
                                                    Encrypted:false
                                                    SSDEEP:3:3BQoKBs3VdeIKdXMcvyWmoxmwMeKoAw:xoojeIKKe8oQ5eKo5
                                                    MD5:C6D831AD43AFA82977D838183DE61CD2
                                                    SHA1:D087E5DC826A1C1C9D653529668E7116FB7F2B31
                                                    SHA-256:62F50F9B9AE3B9E6628DD2660B18D326C41794586E0D76B2E40F6FA4B182E0A7
                                                    SHA-512:F36E17CD2345603CFAE07DFB839344DE843622B3FF551E559AE6EB59E234EC37EE8AB80E6FC59958893981A8A00689579832A7352BDD074E8D21816F3071A008
                                                    Malicious:false
                                                    Preview:module QtQml.Models..plugin modelsplugin..classname QtQmlModelsPlugin..designersupported..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2504
                                                    Entropy (8bit):4.360183478146325
                                                    Encrypted:false
                                                    SSDEEP:48:I8VFmGrSPxz4xTomO6PJ+n+L6p5tyflE2pW6Q2:5DOG6pUE2pz
                                                    MD5:3721C18B9889C8A0DB8D66E584F65E5C
                                                    SHA1:68C48995A9CFBECC6B4CBED82F87E0FE481F4B41
                                                    SHA-256:EAAF5BF02376AF6BBA6170EA1D588393CB791BB673C1C18A18E0EF99AA884E5D
                                                    SHA-512:DC1C8869EE373FEBE29BFFE8D21A76AC36A73B9815E4D4C8D02DAC37CE048FEAC89E3EC44726454836D1B9D85329D9BF2CB5891A8EB14BE4CEB2A9A1C4A60D1D
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2....// This file describes the plugin-supplied types contained in the library...// It is used for QML tooling purposes only...//..// This file was auto-generated by:..// 'qmlplugindump -nonrelocatable QtQml.RemoteObjects 1.0'....Module {.. dependencies: ["QtQuick 2.0"].. Component {.. name: "QRemoteObjectAbstractPersistedStore".. prototype: "QObject".. exports: ["QtQml.RemoteObjects/PersistedStore 1.0"].. isCreatable: false.. exportMetaObjectRevisions: [0].. }.. Component {.. name: "QRemoteObjectNode".. prototype: "QObject".. exports: ["QtQml.RemoteObjects/Node 1.0"].. exportMetaObjectRevisions: [0].. Enum {.. name: "ErrorCode".. values: {.. "NoError": 0,.. "RegistryNotAcquired": 1,.. "RegistryAlreadyHosted": 2,.. "NodeIsNoServer": 3,.. "ServerAlreadyCreated": 4,.. "Uni
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):91
                                                    Entropy (8bit):4.367816060677684
                                                    Encrypted:false
                                                    SSDEEP:3:3BQ3xqH4RCeURPtuYG1mox5AIKAqH4VQGn:xieeUDvoFpQGn
                                                    MD5:A1EDA6630C96C80E8FA7E8D870DF7516
                                                    SHA1:D16C2396CDB5CB56DCCA8737AB9408D4A82D3E12
                                                    SHA-256:46B7932B643C11FC40268BAEDC58004A70F1135C50CDE5D4BC2B7841864FBC12
                                                    SHA-512:21D8E111A79A30990C0D6AB4BF310DA3BDBADC285A9BCA6913E2C02EE6D8A7DC67A896102F9A54EE985C822B0BE15CB3FD0FB33F822CACAE4EAC0104348366B0
                                                    Malicious:false
                                                    Preview:module QtQml.RemoteObjects..plugin qtqmlremoteobjects..classname QtQmlRemoteObjectsPlugin..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):34416
                                                    Entropy (8bit):6.018205845714205
                                                    Encrypted:false
                                                    SSDEEP:384:nFiUXhf1dN9GwNDu1KLG9kt+ol8/Ue+fd4S6J/lIYii3N8JN77hhs3Q:nvRffNCStWTS6J/SYiYq3hG3Q
                                                    MD5:7ECF5B09F1DAA7907F58F03691074442
                                                    SHA1:CEDB2443E3CCE7577790153111E2680266937E70
                                                    SHA-256:9B81F6E0E885A8D7A79CDC1CA24A06643D56ED77524492C2765452A8BADE56FE
                                                    SHA-512:7EC672577DA4DBFC6D6498344578C91855982DBDDA395C510718086C76F5856C35223796C4A42B2574344344C7DFF15D7ED72EFD7BDBE09493F78D30F39439E9
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........zC..)C..)C..)J.7)G..)..(A..)..(A..)..(Q..)..(K..)..(@..)W.(D..)C..)'..)W.(B..)W.(B..)W.[)B..)W.(B..)RichC..)........................PE..d......e.........." ...$.&...B......p+....................................................`A........................................pX.......X..........X.......$....f..p ..........`I..p....................J..(... H..@............@..0............................text....%.......&.................. ..`.rdata..b+...@...,...*..............@..@.data........p.......V..............@....pdata..$............Z..............@..@.qtmetadu............^..............@..P.rsrc...X............`..............@..@.reloc...............d..............@..B........................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text
                                                    Category:dropped
                                                    Size (bytes):2798
                                                    Entropy (8bit):4.525340294789565
                                                    Encrypted:false
                                                    SSDEEP:48:I8BFZ7HUivDvXcvwTELvwgACySPS/+Xiu1iAt0aqrsiHL:1CivDvXcvwTELvwgTySPS/+XioiO0rrh
                                                    MD5:5848ACEA021D074366346DF6BA76CBAE
                                                    SHA1:2BD7232D5567D04325A2B5F98AFEC5936320FD96
                                                    SHA-256:4BCC5C5005176E0C383BC0EB7FC9A9668328D85E16BC3257FCEDF51619464753
                                                    SHA-512:2954366CF1181BA3E7D27F85C62E0574B325B12A2AF9454875CB3213179A9D4A2BAE0AC71470E80F5E0398378482D1E23C7F49CB96545A4234C861A9882BF420
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2..// This file describes the plugin-supplied types contained in the library..// It is used for QML tooling purposes only..//.// This file was auto-generated by qmltyperegistrar...Module {. dependencies: []. Component {. file: "finalstate.h". name: "FinalState". defaultProperty: "children". exports: ["QtQml.StateMachine/FinalState 1.0"]. exportMetaObjectRevisions: [0]. Property { name: "children"; type: "QObject"; isList: true; isReadonly: true }. }. Component {. file: "statemachineforeign.h". name: "QAbstractStateForeign". exports: ["QtQml.StateMachine/QAbstractState 1.0"]. isCreatable: false. exportMetaObjectRevisions: [0]. }. Component {. file: "statemachineforeign.h". name: "QHistoryStateForeign". exports: ["QtQml.StateMachine/HistoryState 1.0"]. isCreatable: false. exportMetaObjectRevisions: [0]. }. Component {. fil
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):115
                                                    Entropy (8bit):4.419580262626129
                                                    Encrypted:false
                                                    SSDEEP:3:3BQ2yAZUo0CeUROiHUNNmox4isU1OLy+RLV06qWov:xnHeUkBCoOyOe+key
                                                    MD5:48521EF985C2D6D22D0EFB27B732455D
                                                    SHA1:2CCFF4118E11B22B1115771A85DD8714455C621F
                                                    SHA-256:5344415B19287C163B3031BB07A2FCE8CC16F8D0715682BF803D497D0557F9DE
                                                    SHA-512:39497FAF79EBAD8222109FAF0B0316726EAF7485A7D51CD3ECF87D96ED7F078B2361CF172A5CFBE2E78652C87A2EF490814122862A53B39C876B853475FFE18A
                                                    Malicious:false
                                                    Preview:module QtQml.StateMachine..plugin qtqmlstatemachine..classname QtQmlStateMachinePlugin..typeinfo plugins.qmltypes..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):78448
                                                    Entropy (8bit):5.848373006100214
                                                    Encrypted:false
                                                    SSDEEP:768:UNLpxHDmdjRAQY4MkWrUp6L8c3o83ODVxE5J/awLt+pyv4Yirk3hBit:U56LMRUs93Z3wVW5Jywcpyv47rk3hBit
                                                    MD5:C7C037D2F9334C1200CB6FF8CCE353CB
                                                    SHA1:928080F8E8666EA2EF3525A21DDF36318CB92D54
                                                    SHA-256:1830933014FED5668DC4372D0D47B1507FD3B5D2799A4D6D26BC11AC02619947
                                                    SHA-512:95F3E5984C78AEA96222B6C88F4766C43A1E97679A9971963B8AB60BBFD2F0FE048CB409007C83E9580C3AA7AE1C5E6339CAF38625CD0AD0B934879B6F815E82
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........fM..5M..5M..5D..5K..5..4O..5..4O..5..4_..5..4E..5..4N..5Y.4H..5M..5C..5Y.4D..5Y.4L..5Y.i5L..5Y.4L..5RichM..5........PE..d......e.........." ...$.t...........x.......................................p............`A.........................................................P..X....0..........p ...`..........p.......................(...@...@............................................text....r.......t.................. ..`.rdata...p.......r...x..............@..@.data...............................@....pdata.......0......................@..@.qtmetadt....@......................@..P.rsrc...X....P......................@..@.reloc.......`......................@..B........................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text
                                                    Category:dropped
                                                    Size (bytes):946
                                                    Entropy (8bit):4.536305228921172
                                                    Encrypted:false
                                                    SSDEEP:24:I8BF9dN7/1vFixiBsTZTd5DXaMAlrp+vyr+1vwRyL:I8BFZ7HmJLXaBlrpQyK1oRyL
                                                    MD5:B4E00D7A767AD72D23B0C672949A5232
                                                    SHA1:C373D45D446A43DECC9A2866813AD639AD771410
                                                    SHA-256:17532BA38CEB9F7CA53BD2F2C03DC7A81D843613B63F49A433CD697BCB496CC1
                                                    SHA-512:CA9B61DCD85D9D1F746C428F5E30E3AE2B7C59EAD75807F6557E8043954F1CEF723876A4C2F530F61B9D6E4F7EECB6CFC1F77609EF50CAF6A191EB25783804A2
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2..// This file describes the plugin-supplied types contained in the library..// It is used for QML tooling purposes only..//.// This file was auto-generated by qmltyperegistrar...Module {. dependencies: []. Component {. file: "private/qquickworkerscript_p.h". name: "QQuickWorkerScript". exports: [. "QtQml.WorkerScript/WorkerScript 2.0",. "QtQml.WorkerScript/WorkerScript 2.15". ]. exportMetaObjectRevisions: [0, 15]. Property { name: "source"; type: "QUrl" }. Property { name: "ready"; revision: 15; type: "bool"; isReadonly: true }. Signal { name: "readyChanged"; revision: 15 }. Signal {. name: "message". Parameter { name: "messageObject"; type: "QJSValue" }. }. Method {. name: "sendMessage". Parameter { type: "QQmlV4Function"; isPointer: true }. }. }.}.
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):89
                                                    Entropy (8bit):4.441476903910194
                                                    Encrypted:false
                                                    SSDEEP:3:3BQyMvX2GVspSEc7jQCKovyWmox8a2Gkcen:x4mGVspSEc7/8oK9GYn
                                                    MD5:71D7D495C303E56EC10F6D88F3791BA2
                                                    SHA1:EBEBD741750D63B06CEA337D631256B70175013C
                                                    SHA-256:3C41BB992D227AFC1C613A4FEDC127121C4BC9703F6398CAC9B08766FD3F63C9
                                                    SHA-512:F0C3E50F551E690B1EC6A41D35220C274689C2F3CC1E97BBD6E792FB72D009CBDC3C538E663EF32F2B7D401836BA10FA7840777A59F2C2FDE580C58D6E0E8C72
                                                    Malicious:false
                                                    Preview:module QtQml.WorkerScript..plugin workerscriptplugin..classname QtQmlWorkerScriptPlugin..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):27248
                                                    Entropy (8bit):5.917728889160461
                                                    Encrypted:false
                                                    SSDEEP:384:RsoG7s0va8Nd+8cz7vJKQhnjd4IYsXfgXIYiTDD8JN77hhFK:KDvj88wv0QhWI/XfgYYi43hPK
                                                    MD5:B6872364203585D4C3838EC8BD038FBA
                                                    SHA1:5B7873011647D28909ED7D4711B659160A7FA767
                                                    SHA-256:405559AF840DC1AF7C5F043DE336ABF75B860762E54E4CF2C895F75A076AC7AB
                                                    SHA-512:87B10008B4B19FF8EB6F0F5D232A26E832DCEAC109D6DA27C12B76FBF387DB63F45964048EBA176A587CA9811592E74E3D2B70B6EF25FABBF94FD9025940A641
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........zC..)C..)C..)J..)G..)..(A..)..(A..)..(Q..)..(K..)..(@..)W.(D..)C..)...)W.(B..)W.(B..)W.c)B..)W.(B..)RichC..)................PE..d......e.........." ...$.....6......p.....................................................`A.........................................B......pC..........X....`.......J..p ...........6..p....................7..(....5..@............0..(............................text............................... ..`.rdata.......0... ..................@..@.data...P....P.......<..............@....pdata.......`.......>..............@..@.qtmetadv....p.......B..............@..P.rsrc...X............D..............@..@.reloc...............H..............@..B................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text
                                                    Category:dropped
                                                    Size (bytes):8505
                                                    Entropy (8bit):4.137941153452292
                                                    Encrypted:false
                                                    SSDEEP:192:zVVyiIfzcLfymWMnD5iW/b9loUlulMyqyPXyPXryZ0XykJyuyiJfainClfXWx8iw:6zAP6YTKRGU
                                                    MD5:51EEB6985965EE434DF17A388B4747A2
                                                    SHA1:E7F39EF34F9E38463CFE89954C97BB8700B7E024
                                                    SHA-256:9ACAFB2C123F4DAFF56C2DC09105524557519B8F3EE1E03FF7C561F47DDC4552
                                                    SHA-512:E59B0CEF52F01D2AE0C434E6A6C1B9E9B173C7F717B271B5D8FAE0B70E2E84CAD5D88DAD76A988611B9D6AE06926EBE5F03BAD5097C8A061DA87A79886B2ADA7
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2..// This file describes the plugin-supplied types contained in the library..// It is used for QML tooling purposes only..//.// This file was auto-generated by qmltyperegistrar...Module {. dependencies: []. Component {. file: "private/qqmlengine_p.h". name: "QObjectForeign". exports: ["QML/QtObject 1.0", "QtQml/QtObject 2.0"]. isCreatable: false. exportMetaObjectRevisions: [0, 0]. Method { name: "toString" }. Method { name: "destroy" }. Method {. name: "destroy". Parameter { name: "delay"; type: "int" }. }. }. Component {. file: "private/qqmlbind_p.h". name: "QQmlBind". exports: [. "QtQml/Binding 2.0",. "QtQml/Binding 2.14",. "QtQml/Binding 2.8". ]. exportMetaObjectRevisions: [0, 14, 8]. Enum {. name: "RestorationMode". values: [. "RestoreNone",.
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):142
                                                    Entropy (8bit):4.610020114843702
                                                    Encrypted:false
                                                    SSDEEP:3:3BzNMUIiEvyWmox7eGxRzoKBsCy5RzyMvX2GKlLV06qWov:xzNMUI98oXz7ImGzey
                                                    MD5:F8C6D519E5C03ADF7FB468932A70B17C
                                                    SHA1:F60786737ACE905BE205844B81791447D03CDA97
                                                    SHA-256:2650234B1AFD8056C2EA8D98749FBE79F5101D0D9B6B05EB1B2A313D7EF2BC1B
                                                    SHA-512:99DEFF1B1331E9E9A0D0FB9BA0D9EEFAE48E8043B804EA829350FE78873DCEF1943FF22B7402A1B8FC6D385C8E80A3615B8818D55437617F634F3F1BD80100AE
                                                    Malicious:false
                                                    Preview:module QtQml..plugin qmlplugin..classname QtQmlPlugin..depends QtQml.Models 2.15..depends QtQml.WorkerScript 2.15..typeinfo plugins.qmltypes..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):27760
                                                    Entropy (8bit):5.832027223091296
                                                    Encrypted:false
                                                    SSDEEP:384:j9nh4r1QVt7y/5ec9Gjd4IGDox7IYirWCwb8JN77hhN+:D4R+5g0OPI5xEYiyLQ3hH+
                                                    MD5:0A514A5693D4216F25292375E19550AD
                                                    SHA1:A917E2D8C9267F672F8CC70698BA445C2CA5A482
                                                    SHA-256:3A160BA70AE0113EFE2749758975232F9F8A1A33B946F149276503EC360033E0
                                                    SHA-512:9734A2DBF331188C86A4C5CF045A65873933D9201D64E4B6F81F82B0D27746E65D1385F14DC37A4D47F7EB5D39C4383806F5684EF4E72410E2194142F643D8D8
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........zC..)C..)C..)J.7)G..)..(A..)..(A..)..(Q..)..(K..)..(@..)W.(D..)C..)...)W.(B..)W.(B..)W.[)B..)W.(B..)RichC..)........................PE..d......e.........." ...$.....6......................................................`.....`A........................................pC..x....C..........H....`.......L..p ...........6..p....................7..(....5..@............0..0............................text...+........................... ..`.rdata.......0... ..................@..@.data...p....P.......<..............@....pdata.......`.......@..............@..@.qtmetadY....p.......D..............@..P.rsrc...H............F..............@..@.reloc...............J..............@..B........................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text
                                                    Category:dropped
                                                    Size (bytes):201683
                                                    Entropy (8bit):4.335995563750674
                                                    Encrypted:false
                                                    SSDEEP:1536:oVo4DOMo0IiEHio9WQ36C1xvxzR7GlC5Z:WbEHio4cR7Gkv
                                                    MD5:3266062FC7140B23B5B47BE157F31829
                                                    SHA1:8D6889BFC870BDE7241F89B0D7EC2CE8DC4A9EDC
                                                    SHA-256:0357A207B6563C150BE05A4A98B0877D8DA88B75176A846C4469B6A3FF660DB7
                                                    SHA-512:F551C5489FA7D9D4DF17FA6107C897508EB7D09B279566B4CA89B8746DD487AD0202A652E42A37C9D8232F9599F13F348A02B700A1CD92944DD1C1A6DB5BAE23
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2..// This file describes the plugin-supplied types contained in the library..// It is used for QML tooling purposes only..//.// This file was auto-generated by qmltyperegistrar...Module {. dependencies: []. Component {. file: "private/qquickforeignutils_p.h". name: "QInputMethodForeign". exports: ["QtQuick/InputMethod 2.0"]. isCreatable: false. exportMetaObjectRevisions: [0]. }. Component {. file: "private/qquickforeignutils_p.h". name: "QKeySequenceForeign". exports: ["QtQuick/StandardKey 2.2"]. isCreatable: false. exportMetaObjectRevisions: [2]. }. Component {. file: "private/qquickitemsmodule_p.h". name: "QPointingDeviceUniqueIdForeign". exports: ["QtQuick/PointingDeviceUniqueId 2.9"]. isCreatable: false. exportMetaObjectRevisions: [9]. }. Component {. name: "QQmlApplication". Property { name: "arguments"; type: "QSt
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):131
                                                    Entropy (8bit):4.551217849456656
                                                    Encrypted:false
                                                    SSDEEP:3:3BoMURTEvyWmopYey+RLV06qWoZA2R9bmCoAw:x7Us8oOf+keSAY7o5
                                                    MD5:D2CF96786CE59E93A2FEB2178603A27F
                                                    SHA1:7478DFEDCD7AC1795BF4FF2732EF716EC82B061A
                                                    SHA-256:B6F63056ADE6925AA070D3B2BD4133D26E80DF4EA2719E81AD90027E19661AE8
                                                    SHA-512:4FCDE288C6A690728F919B70308B3BB2EAD62C40223BEA14E52EC5F3EF74F5467B1930F419DF77D78B8D50E84EC81A1FE78CC9A3B42C4A6D261BA77C654A1714
                                                    Malicious:false
                                                    Preview:module QtQuick..plugin qtquick2plugin..classname QtQuick2Plugin..typeinfo plugins.qmltypes..depends QtQml 2.15..designersupported..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):27760
                                                    Entropy (8bit):5.909004096392504
                                                    Encrypted:false
                                                    SSDEEP:384:ezvrTXhGlWfecvE5HdWjd4z4iDGIYiVqW8JN77hh3E3s:IIg3KBz4iDbYiU3htE3s
                                                    MD5:4965C1A28CD129791F742364CED4363C
                                                    SHA1:FDA6BF834AE374E3808A8BCEF3113FEF4949A55F
                                                    SHA-256:8A44E4E8A15207B302D89AB8BD4B90802B4D6F1EAA1A07254134FFA5318ADC7C
                                                    SHA-512:B8015098121CC8CE6FD7C418C8E51F8D3D2C22A248EA8D701BE65CE6763A069EBFBC6A5770BD0A3919694B1854CC4BD98BE9BE7CFF48AE00C3385A2F31225149
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........K..K..K..B.^.O....I.....I....Y....C....H.._..@..K....._..J.._..J.._.2.J.._..J..RichK..........PE..d......e.........." ...$.....6.......................................................=....`A........................................pC..|....C..........P....`.......L..p ...........7..p....................7..(....5..@............0..`............................text...k........................... ..`.rdata.......0... ..................@..@.data...p....P.......<..............@....pdata.......`.......@..............@..@.qtmetad`....p.......D..............@..P.rsrc...P............F..............@..@.reloc...............J..............@..B........................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2196
                                                    Entropy (8bit):4.822911595644864
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OLrQ3JFbtP:nd5CB7fdpFdU3vpP
                                                    MD5:EA48511545DD3181AAD31E175715116E
                                                    SHA1:02D589A22BD260249FAB2FED18EBF2BBCAE7D7B5
                                                    SHA-256:73C1652D0326049D9D43EF24D15EDDE474D1A764BD7DFCB8F3B83C2823D985C1
                                                    SHA-512:25BE70A08983BCC757705D92296C03DC825B20FF520CC3A8AB76F02A25AE46B33D2F79878F21268018667E3B1E3442B7F9A43C7701547F1439A7CEDF1C9961A7
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):1846
                                                    Entropy (8bit):4.798549880380156
                                                    Encrypted:false
                                                    SSDEEP:24:MCdbFTT3QXf8WYwid0szM6RqeRGNfj9TNZlOWIQNydOtQ+y9Oc:MCd5H6E+iCsAaKj7fOWIkFy9Oc
                                                    MD5:FB7B31A91F3E60DC6B0D399106AA126E
                                                    SHA1:274D1F3A351F1138082701CACCC0A5DEA9710359
                                                    SHA-256:523DE0EFBD2CDBBE342ABAB01E8AEB1AB0CC01D840AE27712F87324646DB1D48
                                                    SHA-512:FD65F23E1AA1EB88229786A488D0FEFEB685E056E60ECC59325D35AD1D94EAE6E28880F529435B3A87284036C872600543BC552E3B285A0AE010DB76DE35A37F
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):1851
                                                    Entropy (8bit):4.801036857486239
                                                    Encrypted:false
                                                    SSDEEP:24:MCdbFTT3QXf8WYwid0szM6RqeRGNfj9TNZlOWIQNydOtQ+y9OHn:MCd5H6E+iCsAaKj7fOWIkFy9OHn
                                                    MD5:66FF9D123E79EF8C2E24051173EF4353
                                                    SHA1:0F0D3D8D9633126099F7872ABBBCC7AA620BD664
                                                    SHA-256:AF7AFB4F8FD6E98CADB48E6D6FDEF78EF48D8617C07D1E0EAA927D3FF0F5001C
                                                    SHA-512:D9B3BA5E4587E4DFFE6E67F585DED42FE5DBA7D1E45C353C40D5D10611937AD26BEE05D629FB952625C6DA633826BA86C2006167F8BDA54DF65F41BDD5954980
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2206
                                                    Entropy (8bit):4.859857255789024
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OCMhgatRX:nd5CB7fdpFlL/
                                                    MD5:BCA14E0F28CC7E609E21703B3082AF72
                                                    SHA1:26E8503D57F664523B8344E7B485403113B9B44A
                                                    SHA-256:13AEF729C0A8C10B4D2C7CDC2D07C408837BC4B01BAB8F1E4B7F0F565BE785B5
                                                    SHA-512:6384A8C29301ECB8B41E8980E629ABAF77F1D7CAB1762BCE4F6BCE01074C300024352C8F7995878B1BA4B6776F5B1D5CA3D3FD9FD736B6E11DB626A11CC64069
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2598
                                                    Entropy (8bit):4.845035402761518
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgpDQ3JFbtE6wB:nd5CB7fdpF0d3vpE6c
                                                    MD5:A5CD195A941116FD9FFA1F81A851932E
                                                    SHA1:73BDAFDDC4482C1423B9C7C70ED6C874425E33C3
                                                    SHA-256:9D5F2B8B73243C6FA6B62EDBB2A7E10A461FD8BE29D9DC4F8A352DB2B89BF72C
                                                    SHA-512:892456A23D700F4D61921E8F742BEE9814CBB14A1461F1232BEB196C8F0DDD8140D8785CB6BC2C00260F5EA136EFE1FE3A6E3FBA47E0BB08149AB735D3CDA48D
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3597
                                                    Entropy (8bit):4.784454586015021
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhglQ3JFbtn3kXxEzPwXRpcWr:nd5CB7fdpF0r3vp3kXxI0WW
                                                    MD5:12337A6D1E1B9ED058419D8EF969530D
                                                    SHA1:A65679BD21ED2CC5FEFC48D1DD00F3677AAC9BD2
                                                    SHA-256:B28B1F726DDD5CB408C71F47EC62D9F4E5554BAF7C813A14408ED89E19D0C35A
                                                    SHA-512:91FD2CCDA7345FD5F9DCD0243354D9F6F4F11F84A6E8DF7BBDC5C0848AE10D36EC45A52E5722C01934F231E682AE69CD2D34D74D90D2FB398CDF199434C6BA96
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):1851
                                                    Entropy (8bit):4.801716178540186
                                                    Encrypted:false
                                                    SSDEEP:24:MCdbFTT3QXf8WYwid0szM6RqeRGNfj9TNZlOWIQNydOtQ+y9O1n:MCd5H6E+iCsAaKj7fOWIkFy9O1n
                                                    MD5:59F570E3703E5DF2AA33E6A6833DFC5F
                                                    SHA1:1868D5D4477004A91B027D5692251FEAF437E254
                                                    SHA-256:1394D0A7BD3C10D033426E5FB95CB9DF75FBC3FE22962F152F9EB334836528FE
                                                    SHA-512:3859B2CF04BE03931F0A8CD22BA94888090E506C3E2510A89E8B8D73DC9952D5976F3163E33AB881C55D9F1AEB2D92D84FDADDFC2CC6E7B9ADDEDB4367FFEEDD
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4022
                                                    Entropy (8bit):4.793392595957024
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9Mh6QQ3JFbtoM3W0J4TEw0xeskxJy:nd5CB7fdpFG03vpoM35ogWo
                                                    MD5:B504A8ACF2FD92ACEA40D292455FDA3D
                                                    SHA1:1EC7F59CEC57622763E1610D65DDF2A1A84B429E
                                                    SHA-256:376C36F8BB81EBD6D7CA09BCCAD95F9EF307BA2052DA38DD07228B7489C5BAF9
                                                    SHA-512:21EC9BD071DA65F5A95084868FF8F17AD73FEC1B2A669CC850A42FAA3ABCAC35D62B40DC2847157805D209EE318B4A0046626B3D1574326BE623DAAFE6BCCB0B
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4478
                                                    Entropy (8bit):4.7756725637253234
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhJQ3JFbtoMhxeszxqkXx2Mg1XY4TEVPwX8OZ:nd5CB7fdpFGi3vpoMjLqkXx2MiINyZ
                                                    MD5:BD2D13E8E608EB8DFAE8D345AA1CD12E
                                                    SHA1:BD53B8EAF56B713D0697CC0681E1C2E11B51EC60
                                                    SHA-256:FA4674932BB9B4F3571748440B4141A0C23A6DDB870DE8084081C6B926CC5E57
                                                    SHA-512:3CFA5756C1AAFF9B5259735568F132C89CF7223C0C759F7DE429698876A5DE996FB4DF2D6EC109517F740D99848C3326383DDC113DB19953F7A9A0A73598D3A8
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5934
                                                    Entropy (8bit):4.745195832165489
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFn3vpoMMm0UpyzP+sf7Vgi949q6X7N:nd0Bhp/JblK1jGX
                                                    MD5:78F964BB222C484EC46AB801145815DB
                                                    SHA1:CA923A0A46A2AEAADA6EF52D49EC0066952E02BF
                                                    SHA-256:1A1D39FE89B42924BA484AFC9485E9CB4C5B493ACCAF2DB64AB258BE9E0CB41E
                                                    SHA-512:1C34F8728289EDA3F344367CB9193433A5CBC2A024E25D55D9C3A79797DFBA76B5F85A51157404C17DE7DF448A507D2F12345293216A601317D99753863EF9BE
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2175
                                                    Entropy (8bit):4.816116777865285
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OcQ3JFw0P:nd5CB7fdpF93v5P
                                                    MD5:84DF8B268EF632C64B841C21C7D07BAD
                                                    SHA1:A82F850711BF50BF9B6AD3849A623FCD81910273
                                                    SHA-256:9A35DC7EE7CED74448D59FE12A1E0C289569864BCC5EF0CF643B73A8ACEBE0FF
                                                    SHA-512:673F09577F2AFBC20A1EC5AA980C93F1C128C1949D5E4C291C8C2AB898DFF7F1E84E3BA669AD1FDE810CDD29DE1D7D783015D61B87DF7E03668A22EE8BDF5986
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2189
                                                    Entropy (8bit):4.819043374247721
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OKQ3JFbtP:nd5CB7fdpF73vpP
                                                    MD5:35062D9350B9F6EDE14D98B7FB51E230
                                                    SHA1:BC29795862934E823560769EB0B81B332164B0C4
                                                    SHA-256:C36C30FD83CCD08A34C78684EA95FA902777108C3A3285580DCB51BA5650D3ED
                                                    SHA-512:8983F299A176CA5EDDBFBF2E4D1C60425723A103A4905FD33D9C98E1A81BCEB3F0C7DB0CB633A7B5159EA49EB5798F2E282586ECE7DA9D4AF8866800E355FA97
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4163
                                                    Entropy (8bit):4.713943551661154
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgQrQ3JFbtsrE0qV0OJatWlSC7V/LEWlSCIPwy:nd5CB7fdpF03U3vpsrYNIXYSce
                                                    MD5:5168C33198A4BA990130E5FE7ED8CE8F
                                                    SHA1:63DA160F997797A1FAF0E86EC68F6CC75D17878A
                                                    SHA-256:D53409FE94CFAB9F60485C8472613BB7806F1062C295DD9DF1FBDB61E1AA7F53
                                                    SHA-512:0D46BABC8AE0747210E0BF60C6E03CF4C05B60CE26DD973FD1DA98A780C08F921370A100B48CC37F27F67A6B6C290BC70E272BBBB085FCD035E4BEFF8804A102
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3493
                                                    Entropy (8bit):4.831719719729733
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgTQ3JFfCtj7AroREri52ZUfP+eX3FJ:nd5CB7fdpF0N3vanA0RQi5TX+enFJ
                                                    MD5:DA3A5C0142C1A707756DCA3CC8425704
                                                    SHA1:E06B7962FA75F59FD4A3A5EE99066EC959E326A8
                                                    SHA-256:0F002B11F845EC2BA3FA8DA40CEB5ADDA050E0DE5F75B8F07C98AAB44996E100
                                                    SHA-512:17AF838901AEC3D2A9F863982E8ADE97C224D1BAE1826B329705FE14F30E763066D568B24AADCE161DB8998E56095F70C286B5A3DE103ABBC317ECA9B2B3C3B0
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3310
                                                    Entropy (8bit):4.7462705851417475
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhWQ3JFm0QuLYup5byaxE:nd5CB7fdpFGZ3vn3L/pxyaC
                                                    MD5:8C2EE0D6AECD93E86C85C7CE4D0934C2
                                                    SHA1:98379BD5580F66D4C48A80266367E2B94C8DD39C
                                                    SHA-256:5A9C5FCF25151107B0A4DB78614EF94C2152B1A5CE253FA6A1501E4611CF77D2
                                                    SHA-512:CC6A7250F3814ADF405D5B8F42F417DEEB14ECBFD421895E96D7981EE147CCAC705C5816708475BB674D31A12A1A71E46865BD8431923E794333C88D80604526
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2924
                                                    Entropy (8bit):4.8351607382479385
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OGQ3JFQeGYtaC9GwRCweVXsV:nd5CB7fdpFv3vQeG0aC9G0CHaV
                                                    MD5:570B8CD91543A1F582AF7973DA815CB4
                                                    SHA1:E909B6FBCEFDD63B059141AEAE284654AA0B5346
                                                    SHA-256:409137D65F2B71C5972B3B7E5BF45E83760159ED5E57988020445D8C84A11806
                                                    SHA-512:A56BCBA31EAAD48A5A7F1A018037223E5E710241F250103A58D942DAAAE40A6993C40BD4912E2B46079C6249C86B1CE7514711B7AB90D04EA4AC469F943B57F9
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3301
                                                    Entropy (8bit):4.8590682549607696
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhg4QBJFw0tfnMoWQ+:nd5CB7fdpF0uBv58X
                                                    MD5:C56ADAD225CB248C79852E9D21DE7D9A
                                                    SHA1:DD00F6244743ADF0B6A2F297E1BF205649363A1A
                                                    SHA-256:928267E5627A15217BDA98BA73965918CBACFC35B920355234A07D9B303C2334
                                                    SHA-512:E08164C898F46B7F7DE06414F7190B5C1B565AB2A21CE5A2E3F4C0CCAAE1FDD8083DE3253E8EE0597E3B14041DF816BA05CC491ADBA71481C29A919823A61437
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2366
                                                    Entropy (8bit):4.839215024821948
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhg+Q3JFw0GA:nd5CB7fdpF0W3v5r
                                                    MD5:47481AF358218C030A1C0852656A50B3
                                                    SHA1:EB520D4E99E28FE6137ECC7A38D041DDF8F86DBA
                                                    SHA-256:DB256124A994C6300F9D647E2728A5D0290EA7BE5322A212C501B47781A3B3DD
                                                    SHA-512:BFA75004DC5638209D0DAA2D8BCA50661099C4AFDC8545FE63438C0D68906C1793360EF2021E02555C74D88BED8349B3D61DB5C1232F9F0ACB85E36A9DAD03D7
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2160
                                                    Entropy (8bit):4.845206012132508
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9Oz9XABLF5:nd5CB7fdpFbiLF5
                                                    MD5:DF883F1CB3E3751E64764C89C4391CFF
                                                    SHA1:784EB6B59F1AD3436F8481ECC795872F7B9D8266
                                                    SHA-256:7C00B819586A680A843948CCDED42D5E4C6B82081324B302D3F14F18F781F2EF
                                                    SHA-512:9CBE8DEFFED435E95C4DFADBF5FB5E9CDD596C12C29699957D33A2360905AF910802D2BD3D5CF8DD5F22BF6C8EA126A4AB910482DC60B2BABE6EB6CD5F3CBC3D
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2864
                                                    Entropy (8bit):4.824177918807717
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLADQ3JFbtEWwl9mj9:nd5CB7fdpFGSiLv3vpEWO2
                                                    MD5:0B09CBB6743AB185E5D446E4FD9C0163
                                                    SHA1:FE267A9C8C627ABC9350A7D11882D919C92DF242
                                                    SHA-256:D0B5ECD69BD470599CCD8602881AF8FDA1F8F89BE66E28E874F004296C802A98
                                                    SHA-512:7E56ED145EB266980B9631F38A720DF9438291AFB5A1181C32AAAB46BF593BE74EE177BC2E3770C4A248D9120DF802A3F04D2C94297AC5D31EF670F44C5739AA
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2936
                                                    Entropy (8bit):4.836532220670415
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLaQ3JFbtrkXxVsQ:nd5CB7fdpFGSiL93vprkXxVP
                                                    MD5:749C572263D3A184C5519F23B810BC7D
                                                    SHA1:E1D2F497D980342A4C4D04E765708DAC51FEE3A4
                                                    SHA-256:D90BBADFF45B1463358EEC494056799AB156087EC6F03797614B9B0731E2E853
                                                    SHA-512:41CBC9F2FB0EB5BEC9019C935D436438715E3F33CBEDA38F18FB943C3F8F41FFA5E580AACB8CD7541E091E525D4EA5A138D7CE1ADA660513098928BAD3FC84C5
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3115
                                                    Entropy (8bit):4.817679790501736
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgXABL/SQMmBHbHnhK8:nd5CB7fdpF0SiL/7MOK8
                                                    MD5:FE56D2B65BAF125E6435D384235383DD
                                                    SHA1:64634A66ACA123CE1089672E3B204DA6165E74A6
                                                    SHA-256:24F6A671389371519F38CE151E642435D7BC54EE48C66C31080FD9F8D4545B79
                                                    SHA-512:069AF2172F31A74E66D34F8BC6F73F70B7B691EE8EAD168EBD991F3C543DF589F3D72E6D753BF1178E7D99DBBAE7FCC73E68E344E3813CBAB2108E37A036EB72
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3199
                                                    Entropy (8bit):4.838347826315794
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABL6QQ3JFbtoMd10J4i0xeskxJ3CUlN:nd5CB7fdpFGSiL03vpoMORgWQs
                                                    MD5:14693E426BB83C54A9D424733BF9AFBE
                                                    SHA1:79F96FF8F2163A513059486CEDDFBB5508015A65
                                                    SHA-256:66183E50D01C16D3FA4D68B1EFB331F705D6E9DDA61FA67131B254CD2BC03B7B
                                                    SHA-512:4E427BBF52161EA4575A417F123A6DA0E1107E328E616DB35BB7991221D672EA5B7E2346029BE25AF750674680DB818455B58EE96242C148ADE7CF36B4ABA544
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3676
                                                    Entropy (8bit):4.817076395322281
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLJQ3JFbtoMBxeszxqkXx2Ma6Y49PSAQ8:nd5CB7fdpFGSiLi3vpoMDLqkXx2Mgk08
                                                    MD5:B4A73CE810EB366B3695961E5729C574
                                                    SHA1:43D950EDEDD27CB23D227990BF3CDA45251C5080
                                                    SHA-256:27B877E03265839AAC96CEC61399797B409A3467095E34AA715224BC027ACC5C
                                                    SHA-512:B36BAE6286E896E2B56AA97419D0004FE211B387801F0181897CD342D2C7FB44D584006263E3B236294D56E711D3E6550A69DF97BBD1A73FE01A8139FE72A14E
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3722
                                                    Entropy (8bit):4.840266911534435
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgXABLaXBHFAdz3qzzKOqCVwhRzymiJ:nd5CB7fdpF0SiLaXPezqKO/Vwc
                                                    MD5:774B7D7ABE679CDA3BB204C186BF1922
                                                    SHA1:014891DBE5BFE5C4E2A13A732D3279C3A231FC2A
                                                    SHA-256:AB71B65FDCCB5AA71ED4108885E8CA11906F3C77226A6551014E0E91F906CE71
                                                    SHA-512:A1AF47DDC642AB1A90D8D0A540389969278C9C0714985AD2FCC624402DBC8CC5C205C405EF85F133B3059AE1D7DA7207B7BBCE570F574628D10E6AD6D2AAB1F8
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):6762
                                                    Entropy (8bit):4.653349573149583
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFZdL3vpoMcW0UpnOEzPLbnuN94qq6Oq7h:nd0BhpfTJLlO4jqNBn
                                                    MD5:4A379962BDF0008E52B5431251C4911F
                                                    SHA1:D22BDDD0E50404564F9174CB8D443945A57D5FE3
                                                    SHA-256:F49B8C3FD74416EEDDEC64E98D45A09A13AF906F8BB0688AC700B3BF6D0C392F
                                                    SHA-512:88A9A8BD446AA0A9295D35123C5207A4A412286B78D3208D140C7734B097FEF2780A3461301064826F3FCF8A28A2F1A1E59169E3D81A5518EE91E199132D152C
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4553
                                                    Entropy (8bit):4.654436620802229
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLNrQ3JFbtwrE0qVl4l4WlSC7VkeT+Khd:nd5CB7fdpFGSiLNU3vpwrzWrhaa4LB9
                                                    MD5:995DE288887B969BD338A74FCB4E109D
                                                    SHA1:E9690BD9FA0DB29F3F93D722CDA26E0D1853612C
                                                    SHA-256:07B4350DC2A42443EE58A0B1F5FFB8E9BD7F36F201F3BFBA3A901E94968E49C0
                                                    SHA-512:93149113DD14C299A014DBA46C2670714124B4CE8C543CE89D9DA6248C806E03F713CEE62913182E64F09548977315700C14CC6CE265781BE6BCED6322FCBE54
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3255
                                                    Entropy (8bit):4.816567729769993
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLgQ3JFHCtL7APPAri5296hdITFJ:nd5CB7fdpFGSiLz3vCvAki5KSCTFJ
                                                    MD5:712277F5FD5134234CD10A143E61CC63
                                                    SHA1:FE811C91FF465B60B85996029E6EC00DF723D674
                                                    SHA-256:A220A920B136B42B0064BE6D109C0C53800F0C5DE97D7B940BA4411C8B07A473
                                                    SHA-512:9BD9E6DE6CE39F601FECD1498CF189262D8F7F7A913B84D468822EE93C310B67BD1D9073AFDD77FF1410089B1489C8F1FBAB1A09B8D8ECFCFE9E9739F3670437
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3604
                                                    Entropy (8bit):4.693986025813382
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLWQ3JFm0QuLYupVLbhsby9ku:nd5CB7fdpFGSiLZ3vn3L/p5bcy9D
                                                    MD5:DECC259DE73F443229A11796DF832F7D
                                                    SHA1:0F6910BF1425B669E27216511BA164FA6C40DCDB
                                                    SHA-256:DCA8D31580EE628F8419129C95D141AF738F53BDCE604FA6B8E3104637FCC328
                                                    SHA-512:7407BB79B74BD847B5156DCF0186F1F6877F4088A66E3F4D2A8E4A1AC55A6AB9DBB833AFA25AB74F9ECB5E50A62528E9ED9BAE67E8645D5EF235B84690F8E23C
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2867
                                                    Entropy (8bit):4.847797406023263
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABL3Q3JFw0/nweL4:nd5CB7fdpFGSiLg3v5/nHL4
                                                    MD5:442853E5CD2BF7DE8C32904F3182CF45
                                                    SHA1:5444E410DB904737B0C89CC162A21CB901D9F667
                                                    SHA-256:D27E54D711FB15EA94781E74F92678D740F296ABDEF2263438DDE7B21020A3BC
                                                    SHA-512:78F6A60FBB91885EAF300163B171346C48D28D09E7CB012E515981B7CCE9AF7730EB875CA278A4A4D66C260D72ADAC1A5EBD36C01A5C1303B0F0DA610EA052EB
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3673
                                                    Entropy (8bit):4.8243565891518685
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLPQBJFw0tDNOeWQGNL9W8g:nd5CB7fdpFGSiLYBv59yDiv
                                                    MD5:52DE38171E2AAE5FED7FC051060A5F9E
                                                    SHA1:A2CB3BACD5D7DBD45F092822F0E63E6201A50941
                                                    SHA-256:D94505618774A7124C47C71CFD2789BD4E4FDEE1D67D7FDEE894F342D5CECF22
                                                    SHA-512:B7D03D36FDA4A9EC2F127CA4497EE62A85B82756948D43E1EAB02F70E09EF10C4919245A0C5A3059F641812D814D62C11BEDCF42E1213F6864B73541F0780E19
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2474
                                                    Entropy (8bit):4.872983036596215
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLXQ3JFw0lzS:nd5CB7fdpFGSiLA3v5o
                                                    MD5:BC008897224CA5E6D116B7B3DC0CF714
                                                    SHA1:0D27DAA5B238C93B3C1B932EA908769CF915D9F7
                                                    SHA-256:0EC600E95414A6B1C4EA76F9E96DDD54DEF1E2D6994A3F7DC3EC714A46CF9A42
                                                    SHA-512:4BFF2E5D0D2F8065F2B4ACF7197D335C8C4437B743E1AE92C3E01A575339C3F4A18AEA7F9BF199BCAF32411191B16C623F01238CD2B50B710FCACCCD3AA53311
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3141
                                                    Entropy (8bit):4.850551507437113
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLqQ3JFd0Bva9WW3CUlQjxJgzS:nd5CB7fdpFGSiLN3v6BvaIVHj/b
                                                    MD5:D7F8A890B584BF52B6D8D427C0D50CA4
                                                    SHA1:18AC89CEBC4B5AB17C5CB60A4799FF6832C01EDB
                                                    SHA-256:D7D747F05A567097E70FFCEB635906F6C1F10354C2676CBBB9A5A6590FD9A542
                                                    SHA-512:1ACF1B53A0F4CE4B1D7DA6D4B392D1B221E63BDB2BC11C2BC1F781438E5BB55E51434C0C1F0708BA171A1A0AFF077B698C4A63D69A40B0DA6E23C8393C9C2FA5
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3065
                                                    Entropy (8bit):4.730930951536836
                                                    Encrypted:false
                                                    SSDEEP:48:M25H6E+iCsAaKj7fOWIkFy9lvSQ399tqYVtaQoFbbUWlF:L5CB7fdpF235qYO1b1
                                                    MD5:705CA8FF9E60643A2B9C33AFA9EFBDA9
                                                    SHA1:D3F2E8AF51006F0EFA7984300624B735EDB6A8B6
                                                    SHA-256:0FE5F10591E54CB9200897129FBECA5786635FA16A7B143FC8938D8DEDCF21AD
                                                    SHA-512:4E66F54975815F93664F581EB264F39DDAF130A5353A9F9E3C941606E26969D057783488F263482AB5C18D83EB80C192A56B47158DD1651E5E8506B14C02F73F
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2020 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3257
                                                    Entropy (8bit):4.830700564994332
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABL+Q3JFbtoMVkXx2MiPSAQ8:nd5CB7fdpFGSiLB3vpoMVkXx2Mi08
                                                    MD5:110A3479AA19513F236436ED1476734E
                                                    SHA1:FD5F99F439CBDD00485B9C6D54EBD0B962B537D8
                                                    SHA-256:D5D311129EE2C7128D5AC944878D7C1D89830D96A6F08665C772976D6AA48695
                                                    SHA-512:BE36E1C44D0DA5E36D57BDF5D312F21E09A0AD7010AD5E4957479619EBB6BD9CB3D017F31C2F4AFAE0D2FAFC250626CA4A77E197555BAD5A1247729492467A41
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2085
                                                    Entropy (8bit):4.843093855868019
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLdqQwq:nd5CB7fdpFGSiL/p
                                                    MD5:6C5DA44514C825F2033F7DDB61538E3A
                                                    SHA1:578D1D6993ED4AA6EEEBD6993725693ABBED5188
                                                    SHA-256:3E22F0D23F4EE17CBCB3AAE0E9B5E9C221E33B8887404D4BF1A0AFE3A7A9882B
                                                    SHA-512:449EA018AF6448815B9F1F0381DFF95BE33BC7A8AAFD750108FFCF3F2EC61DD35DC9ABFE0A9ADE8417105F254B91B9ADCC0873FE2768DEE8F850177FA9B03BA8
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3391
                                                    Entropy (8bit):4.778187845123202
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLg15Q3JFw0ck/NtPCccs4dKbhI:nd5CB7fdpFGSiLuS3v5V/vCccfKbe
                                                    MD5:942C7A67C96A74E5A6FEE4AFF1C50004
                                                    SHA1:32FF92BA5480026C3B9A2B8161528FAE5896FBD6
                                                    SHA-256:C7838D5F3755EBCD0A5681999B34A0A049E8EC7B3C0DD6AACF37BF8B349CAA32
                                                    SHA-512:77E8873D68D45D21A7D9E47CA589ED788C7F77CE1B6FF25C06F9CC7B84588FF0A67EED8D3A7B0925E8C6C56A2F2F2DAC03A690AB155ABF477D60E98753AF746C
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2899
                                                    Entropy (8bit):4.7994845792618
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLuQ3JFw077IjqzbrzZ:nd5CB7fdpFGSiLx3v577IjqzbB
                                                    MD5:77BEEC13184687D049C74152377EFDA1
                                                    SHA1:9C6528D54EBC094726DD37AEA52099F1CABC4544
                                                    SHA-256:78DBD76FB7BD3E481D6D634B6D08C27A0CEF3CD4300F1CCDBF59AE925709C1E2
                                                    SHA-512:62D810B28751CA2F82BAC3EDF57305C0B2B85EFF37A8454B13C584AAD69C1458CE28D3E00E867EA6556F530FC300C1CDF0BFD48EE34819D2343A771A14F2F287
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3076
                                                    Entropy (8bit):4.819432599598653
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLBQ3JFbtoMVkXxsS89:nd5CB7fdpFGSiLa3vpoMVkXxsp9
                                                    MD5:1460D50451A7CBDC1A72A77F1B7927A8
                                                    SHA1:26706A64B38067457168447A234F0EA600799FD3
                                                    SHA-256:F2497A9A0C1712E8D5920BDE501A069A74221A9737CCC9C1B6763C1CD9F78762
                                                    SHA-512:197DFC36AA16CF4F6DE0E3B1ECF65918AA5AAD0CF338FC97604E6C94C501F47098C5BA97CB76846231532A9C2A7319EA0D523359C2B6849CEA6F10EFEBBABDBB
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4312
                                                    Entropy (8bit):4.8090339753319835
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFGSiLJ3vpoMzQskXxaJO5kD9:nd0Bhpp+JwxaA5s9
                                                    MD5:3B8D65BF8D411676744028708D511EAD
                                                    SHA1:F5B429A40C6234DC838883604D6127C869A520D9
                                                    SHA-256:839B4B9F5D37EDBD9F7A79DF050D92BD61587BE6D867DEE3CE50DE5310BBD3F8
                                                    SHA-512:2268BE20B651186A039B785F084B04A67723C4AA32F4D1183B00A94BB9FDF0461BCB2D6D2B48D31F3BB7487B2769E7F55215F8D71179E9CBE0410E0E9C989E2B
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2526
                                                    Entropy (8bit):4.872895209398576
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLcDQ3JFbtMuzDw:nd5CB7fdpFGSiLT3vp5Xw
                                                    MD5:DA76E587D1C03E0BD563ED24398D8E22
                                                    SHA1:B9FFF904F618F811D18B450C9E845BDC38E587E4
                                                    SHA-256:FC09EF128B330FDDEBD6D24AFE7AB1C1A5E44606430FDE7D80D43A4DAC24B2E0
                                                    SHA-512:74FBECD8F7397037EE12F0FF69FDEF1D937D6FCCBB752316EF1A4CAC807B847CB0E00754403D7A04146651ED6165A1D6EF79680A08E65CA656BE060E87E9C611
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2683
                                                    Entropy (8bit):4.794789713923403
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLlQ3JFm0QuLYupz:nd5CB7fdpFGSiLe3vn3L/pz
                                                    MD5:25A9B6FB95C3727C8AAB7DF82862FE5B
                                                    SHA1:9E0941331E3A383DAC870E4B1AD81DB66993B9CF
                                                    SHA-256:3B0F970FC3391C9FCF5F33D0FF0BF69408189CAF87689180F4E8E2150BE0212E
                                                    SHA-512:4B4521F578CAE130FF12D241A7D203380544F73F40E6BDB177D535F0DE5B52715AD3530D7F257970775979D1E09C826D84B29D6463FC27D8D649E4BCA5F9DF40
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2845
                                                    Entropy (8bit):4.847383724915905
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABL6DQ3JFbtF6dGZZ:nd5CB7fdpFGSiLZ3vpF6dGz
                                                    MD5:8F8CC36456A71BF65F2038B011E341BC
                                                    SHA1:AA773708FC7913D56354A432DE90AA6F5D12D412
                                                    SHA-256:83A078260D1478CBB114AF7449240BCFDDC9D8A4F741308003D0F2097DB9C097
                                                    SHA-512:93EE7EFD8A72B915707435FCDE3D0C3CF1FE176F66F433C9FA010ECF177AF911127EBA0792FF994B760EC70B564F113802D20D7873D4BC05854F17D40B5CDFB4
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2409
                                                    Entropy (8bit):4.858057181527377
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLUQ3JFw0X:nd5CB7fdpFGSiLH3v5X
                                                    MD5:24AA10D6E16463734C00F3C5BFEADF1D
                                                    SHA1:9F8CDDB2497B54174A241370814A7CA30A92483C
                                                    SHA-256:BF43417ED4A5E03350E0D780F7D0C99C618210D2E687E743EEF377E0AC143B9D
                                                    SHA-512:ED5CAFDF1ABA5CCCF845E6FF39E6631485331C96082244E950DDE83651979D58023C0507A42E3572D4967BC236E5D9B1C7FF0BE4BA425427DFAD9127771396E8
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2627
                                                    Entropy (8bit):4.857247671499901
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLwQ3JFw0XG:nd5CB7fdpFGSiLD3v52
                                                    MD5:6C72322D9FF5B6859A5894A2B73BAB9B
                                                    SHA1:583EB9F2181828148D71B884CE2F86C8C0A4F4BA
                                                    SHA-256:BA07A7F0489F6CCAFE7370DCA83676F80E8D86ED90A4E0838CC3F57071818858
                                                    SHA-512:39F0B5BCF2F72510B6469B893EEAFF209DFA2420699A6CAC872FDC4033AC2FE2545CCF2C030490A0A5278CCC2D6B6E7BACF290BC673E8A80BA73B956AB95D9A6
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4445
                                                    Entropy (8bit):4.6042693161542765
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFGSiLl3vpMoMtlmz4LBsNgJ6FgJLnFJ3TD7rOC:nd0BhppM7B4LB44LnFJDz
                                                    MD5:F7E923E6F2DFE260298A4DED2BC5E1D5
                                                    SHA1:F40D9AD45101E10F55593ED7FBA054F94CD897D1
                                                    SHA-256:9CB492EC1E3BEDA61B399DB322BBA36B743EE3919FFDF2EE1C02545638E5CB49
                                                    SHA-512:C5C918511CC3CC0D6656487B63F5F033BD61627FB3915FC93E18292ED7BDE172D94691E4A6BD51421A3F8A551692888165DC246D10A47F6C4C27D3AFF2253838
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3202
                                                    Entropy (8bit):4.836680663343116
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLFQ3JFbtoMM10J4i0xeskxJ3CUlN:nd5CB7fdpFGSiL+3vpoM3RgWQs
                                                    MD5:F728E138F3E89E2F19D79606AD8E5AD3
                                                    SHA1:812DDA06821A395676CE9C0CDAE25B58EDBA6E56
                                                    SHA-256:224F7F8914C80093588D6E5411F4EEDE8AC0F4C6EDA32A97F1EB4A645B8D54F4
                                                    SHA-512:01067C43B5B28C316FC2C0B66516CA16F06DE82717FB8C69814DE23182C426A43C74360600AE8CA2B67AD37951D45E35F9124D8C32BF7E5A1514864783C0F0C5
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3676
                                                    Entropy (8bit):4.81690208622024
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLKQ3JFbtoMBxeszxqkXx2Mf6Y49PSAQ8:nd5CB7fdpFGSiLt3vpoMDLqkXx2MBk08
                                                    MD5:85F130BDE6D3912EAA2D146088AA7E39
                                                    SHA1:536E3B8B7A4E599D4990A25CBDAF4628EA829AF5
                                                    SHA-256:82C8E61F3A5E91845DE5519D74A9E7B2C67130E0A818CCD6090841817BAE693F
                                                    SHA-512:D7D12F12E3290EBFC16A21B2C160A106C567B2BB05CEDE45E7C582DF9F89C731F62093080CEB0CECBCBBE946EAE0E25B1C9916DA91E7F69D618ABA91A7FD52DA
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3186
                                                    Entropy (8bit):4.839651169203657
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgXABLaXBHFAdz3DjYacMMXAABFq2:nd5CB7fdpF0SiLaXPezzjYacMMXAAB1
                                                    MD5:E3347AE8C25B7C5D14EF43D7140CC0B1
                                                    SHA1:7ABD778E1AA8CEB71FB307DF3AB530E15A61CD17
                                                    SHA-256:A03A14CA059236B5C1290BC2C7DC0A9CE5E051DF34D887F26BEA5745DCBC0BA0
                                                    SHA-512:6474ED83D280047A174F7C3767FE773B9C10ACBDD9A50A25CA7C2604C8B412067B08E431CFF1972CE51722EEAD78BDB6B7FA5F5B04C797D037DC29FCCE744EE1
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3855
                                                    Entropy (8bit):4.806781419849508
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLCQ3JFezY+B1LBWR86EGtoXu1W986EGS:nd5CB7fdpFGSiLF3vW59Bfu13EmyV2eC
                                                    MD5:3158647791DCE0AFB0B053708FAEBB3F
                                                    SHA1:8CB7AFA52563B14A710651BEEEEB63D87974A0F9
                                                    SHA-256:366406CE7422D6F0A9C00CDA48FB641E4BE7BF8766008ED23268F3C39440E035
                                                    SHA-512:4A42076469B5A9D50A51CFE34880DED29323424CB1E6936860293E02C302C008BB7F94BC7D08E03FEAF77C34923E92239612B7687488C06F6D20A2A16EEFD18C
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4110
                                                    Entropy (8bit):4.699758511056258
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLCQ3JFbtVkXx8b/MKfMMKfln:nd5CB7fdpFGSiLF3vpVkXx8DMkMM6ln
                                                    MD5:6C50C5B176C209D5902AD5665A7750ED
                                                    SHA1:F1312480CF7392317F1CC9013A57C04D5F857D4C
                                                    SHA-256:E529AA9F9658F99845CEC7108B91A29CAF640A0E60F3BBE1A97FC6F5E3C66EF4
                                                    SHA-512:860994A4927034570971169F14AF65F392AC59B7C62892D1599AEA8F12EC35E1808162CA413DBD1FD864FF7FF474101C0DC526C20CFB751E70D8FE0448C95ECC
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3290
                                                    Entropy (8bit):4.848952647144185
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLsQ3JFbtfSQkBLIkF/3ys5:nd5CB7fdpFGSiLf3vpf1kBXJ3yG
                                                    MD5:674CE82D2F377B41A90FAF4FD409A305
                                                    SHA1:A09744FDA9F6126E2C77DB66F7A3B7BD333DD270
                                                    SHA-256:2FE72BE9E3C38BA758BB496D5D5C3F47B001EAEAB4716B7C82F00457135666E4
                                                    SHA-512:6CAD4BA15369277BDD00914286BB194087D9910479F973564AD05B043409D450F25DF56DCAAFB58941C1EA31AB431A82D4D0CFA5E94BB29A7EE416E9429D98CA
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3060
                                                    Entropy (8bit):4.774494136354126
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLsDQ3JFbtnLSNxAF/k+isH:nd5CB7fdpFGSiLD3vpnzJxia
                                                    MD5:374220CB2D11E346D6E1A3CC7DBF406D
                                                    SHA1:943D4D988FBBEE0DAE3351AFA4B25D4FB51814F3
                                                    SHA-256:5ECBDE93918A0A049E28741B5E697F5EC716AF9623B49F99665E93FC1EE467DB
                                                    SHA-512:1902C3478C41B2C8BC685911767A66F7923171E966928E6296CF49238F35A059BA26D9C7BF94DCEEB4FCE05DFCBE2CF87EF3BC09F6E6E4F109B57A727FDEC6D0
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3031
                                                    Entropy (8bit):4.851821926768743
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLfQ3JFEIdW586EGtwnTWon8:nd5CB7fdpFGSiLo3vjdRPvn8
                                                    MD5:5CF85741902608195D9DD7C9C44C9EDA
                                                    SHA1:6777DC859D11F61FA473619023034856C6AB434F
                                                    SHA-256:8843BEA4310574A0927699DDF4B5D0F872F490C70A4095C73A6EF5E011CD9F35
                                                    SHA-512:16643BA89E3CDF6FCCDE7C37249EB56515B79406953CBCA1384ECB26CA667D15BC5AA5FB434A1B76AAA3F1497AC25748AFC6DC76E5DAA768EE6557FB88D79676
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3771
                                                    Entropy (8bit):4.773311978412318
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgXABLkJ6pEa7C2C6hrxdE4k3/UZ1JI8M9p:nd5CB7fdpF0SiLNX1F/EFLj9p
                                                    MD5:9EB30D5992BE33B94E2802672DD031F6
                                                    SHA1:4B83874D33E2E34BB2E8FA679D40C7F158C652BF
                                                    SHA-256:4ED39D154168A9302326D15D11D7B50160280F36C62331227D4EF26DD0BCF051
                                                    SHA-512:39550C0C43860501803085ACB3F51CF619F577ACB400F4430F467F3C0E6887767C60548511C26569BF38337D2B7BA18D9F5F8CAE5CD141FE3BE628CB1261ED84
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3181
                                                    Entropy (8bit):4.775336510298412
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgXABLQ4MBama6ME77pBY:nd5CB7fdpF0SiLnr7077vY
                                                    MD5:BC315811884EAD64A90A14439C1AB256
                                                    SHA1:DE8CBFD01D2FD39BCE6E1309A161F036D565650D
                                                    SHA-256:58ADA30E2140CE8418AFCB7F43547D9A40321A00820ED09A5057989B6C3C6B7B
                                                    SHA-512:FFEB7879E16B4524A6DCBE0D82FC1D8B8CEC67B8E6B497A3E4EED793C431BE490316E6CF68E5725263442D36267CFC8830AA6E99A443B0D2EE2E0EF44B128270
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):6907
                                                    Entropy (8bit):4.587500319457438
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFGSiLh63vEgjqi/jK7GlKKub1OYllKBb1OHPa9l1:nd0Bhpp3x2K9R6s
                                                    MD5:94F7A06B2F6F1F309D76DF8B943ABBE4
                                                    SHA1:261D7CBD80D2697F67D9FD2BBD68E88AD0933873
                                                    SHA-256:0AFBDAA23576F95BEB109250EDEB8DFA41E6676732D780940DB0653B83C501CA
                                                    SHA-512:CA4E23FF23C04F4F105D8F5820E581A136D09C33D99BA0A90E1D5AD739FE4B60F258FCED81A6D15EA68BE8F9185AEFDFB0BAC7740E6412D0B9D5189C32F6DBF3
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2632
                                                    Entropy (8bit):4.860099430791201
                                                    Encrypted:false
                                                    SSDEEP:48:M55H6E+iCsAaKj7fOWIkFy9LixvXCQqJFbtyXGJzn:U5CB7fdpFPFqvpyWx
                                                    MD5:67E8AD0B5F4079BB91BBDC6D21D2F083
                                                    SHA1:2C3FF8E7702608B2D4E45A9108237D17BCFA12E2
                                                    SHA-256:8EDAB5178285364A5BA4D5D85F7ED7177CDE22D8C8E5EE58CBAC522443AB9A3F
                                                    SHA-512:1CE7EECDF96C8929C9E6D8BEC56A5C7258DDAEAEE78BCBE3F0BFB91036267A4705016D93E219BBD3DB0B0FDC31A1560A10EC975044CD366879AB5C967DB3C046
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2018 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3364
                                                    Entropy (8bit):4.843018549055649
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLnQ3JFbtoMokXx2MiPSAQ8:nd5CB7fdpFGSiLQ3vpoMokXx2Mi08
                                                    MD5:11CD81C4A16E17D4C70058D7D9B03E1B
                                                    SHA1:66D6C7876F21A3FF9236CD8E078175150065838E
                                                    SHA-256:311410423492D5B145A1D947923AFA2C8A5F8104D724D9EB749E32560FF40663
                                                    SHA-512:1673BC045E1C18F6EE4AFBEBAE2A274D8DBE64F5240EA6651AF9C42E41CF4798452697B4B857A6C307BF7E5864804BF39BC751D17B71F7AE4043C2B3FC9219B1
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3192
                                                    Entropy (8bit):4.833233112426197
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLiQ3JFbtoMl10J4i0xeskx1CUlN:nd5CB7fdpFGSiLl3vpoMGRgWss
                                                    MD5:B16038F98CFAA428B777F65D7EB562DA
                                                    SHA1:65B64232F625D2DED542890046EE6F28DF5E7DE1
                                                    SHA-256:C48F19E2D6E050FE14D2E588BA274ACBEFB9982E1281D303D438E2AFE2A9BE32
                                                    SHA-512:5E316E7BED9893886D84FBF4A41F97075BBD4385F4583D6CB5938C4025775E929D60BCF9DF5B521876C31849BA754579122A2C54B992D9F853F7663242617AF8
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3754
                                                    Entropy (8bit):4.822397929283822
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABL1Q3JFbtoMr/YJ44xeszxqkXx2MiPSAF:nd5CB7fdpFGSiLu3vpoMijLqkXx2Mi08
                                                    MD5:D28BD6BE352D7F231AC85DE3A2450DB0
                                                    SHA1:28C98A11FCECF51B97FA22506AF77D15DA850A87
                                                    SHA-256:7CDDA7B0E360511C10D948A8A30BD8CAC6D00426F77066416677659BD2DDD947
                                                    SHA-512:F7353B41E182CA0F509F1711E8DDA8D03F2BA4E2A41AAF38524CEDA0CDC68D7B08C61ADC2D6B9BF9224702A0DB63F4F0802396CD9FF1336D192C23AB90F0669F
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5133
                                                    Entropy (8bit):4.629006970821916
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpF0SiLaXPezit4ddGiASFXb7b3VO:nd0Bhp3RXP7iASdg
                                                    MD5:E10B3C3EAA58BB65F76FBFE92FAC2A51
                                                    SHA1:DE5A48C252AAD12EFB7EF458E147CC9D3C8B5D70
                                                    SHA-256:547FD1C6F78DCB7232A851A0DFF8F8E85712B6B5D867B33D26A2DDCE5650A993
                                                    SHA-512:908651D9E41D75E56AD558264B63428E1DCBE625D3F1D8C7893785E995047D104C156341D87BFC32123CB0347E850BA83FA79AA53A200407302BF6B2D80BADF2
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3121
                                                    Entropy (8bit):4.850524428400441
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLmQ3JFw03wlcZiSH5fuCPi:nd5CB7fdpFGSiLp3v53NIgul
                                                    MD5:CFA6AA2994748AE4E601F9541BCABA23
                                                    SHA1:5B02AC7F0685B578F6AFE684DC3114D4941463E4
                                                    SHA-256:5B3B6E88FAB37F2035563A3E657649C89087C3AA4E886D29772BD8F0CC0D8CF8
                                                    SHA-512:2E9C4F1F4064E1BD2C3F3407A4CCCEC5166B910394E5C62512D8627A513A27A59A398AF7757C312F1D10B1F915A84F2EF81B0E2F5810E0307ADFD285912599BA
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3862
                                                    Entropy (8bit):4.741203141918409
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABL5Q3JFbtWkXxKRWmzadCkCq:nd5CB7fdpFGSiLS3vpWkXxKRw/R
                                                    MD5:4D2B8287BE5DF8484599262E6AB0B053
                                                    SHA1:C7AACA9FCEF942C8D742B0725899331B54ECD0DB
                                                    SHA-256:493348C45906AA01A17B2DA718FB951D16784F2C5D48C227F816542D3FAE0A09
                                                    SHA-512:E4E566FFB36D5BAE90965BAB3963274CA6C55507A0C14B859C278C7B8ED4C8E3FA5677219774E0E9477D14FB42842621DCF0D0660B56D2FF9B3E9F312D0B421F
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3392
                                                    Entropy (8bit):4.828504041175741
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABL4Q3JgZLzA9NJbjygyi/5Ct:nd5CB7fdpFGSiLr3ONsNJb+t
                                                    MD5:BB8530144FD581EF85E32740A3513393
                                                    SHA1:3272553F7995EDB22BE8BE5FFD4713EA3737AF1B
                                                    SHA-256:5BBDB1032B61CE82C7D018D12E76F101C11045EF5CDD9913BE077937A8F5083B
                                                    SHA-512:5405E2B0B0B6A35739AD87665296C3ABBFB13C74A56993F34038DB9E022E4DB672BA79775DB1469DE1545F79AE04688FA09D417014639F63C4C6E53545A2B1C4
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4120
                                                    Entropy (8bit):4.790784605299055
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLzQ3Tw/nP0p98j+jygyi/5CyFXdjbD:nd5CB7fdpFGSiL83Tcsz8i+yPjbD
                                                    MD5:F5288479BC57682CA3CD4833F7DA282E
                                                    SHA1:DE0BF7E45C6A208B7C0A88DC270CB348E534CD43
                                                    SHA-256:D32203BCBF2D0CA9837C7902319391EDF823C313F95B483D0A09D83FE0BA713E
                                                    SHA-512:5377EB6AD2B459033C4D11EE3D1E2C4124DB4886677DDEBBDC033AB34F0F53BE6FA4673367EFE62C2BA1FE588CC61AADF6EE8A73398E1422734802770AA77DFB
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3252
                                                    Entropy (8bit):4.768611906315124
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLVQ3JFw0K44jhskjSIjkmV5:nd5CB7fdpFGSiLO3v5osaSIjfn
                                                    MD5:119E1548643B45C92F9C3855585EFC89
                                                    SHA1:0BB3FB2036BFA07E8F6089C9203CBECD9C8ACC95
                                                    SHA-256:EA7514BDA98EE718F0D501D5B85DB44CD39636D4557651F269F482BC2E05AD13
                                                    SHA-512:66F4E32663FD1025DE2F49546903BA9E234D8124973EBBB35417080F15A7421531EDE17552213FF1C5353BEB9E4A4EB51C716C9E5350CE4D2BD1F68130C2ACD5
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2923
                                                    Entropy (8bit):4.829927267906487
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLAQ3JFbtVkXxVSP:nd5CB7fdpFGSiLT3vpVkXxVI
                                                    MD5:0C991C37BAC82E6F7A0AB9ECA772A0B6
                                                    SHA1:8C5D422184FC561CF00694EA4724B02D88D9D46F
                                                    SHA-256:26182AA0C57FEF02F6A1F9F2D1561F535F4537AFDF4EEC4FDECA8C3C76DC9F8D
                                                    SHA-512:AD87F5643415B7835FE2990F2BB18F5DCC772316B1F9A8162BECDA290F3D1BD313D628058CE00EB4156085AF260AB34FA5EB5464D4EAC793FF6512B140C99A52
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2757
                                                    Entropy (8bit):4.835324916684116
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLDDQ3JFbtUiY3ARy:nd5CB7fdpFGSiLw3vpPY3Ag
                                                    MD5:53DF676C4AC9F3310C15F872A521BF02
                                                    SHA1:B72C4375F096138F3B29B7089219D6088B26DCC7
                                                    SHA-256:D2E99C4BC2FAB7C8FF0690212947B22FA299ACB2798309FE45EC4D3163BF0C65
                                                    SHA-512:7222F4C801BBCAD1934678F22BC1376DCB4136E7294D5E817CCBA76FD69C3777A0666C1E4FF332D6F45D457DB8CE988587BF421A6058AC850D3AC7B6204E8ABB
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3063
                                                    Entropy (8bit):4.83440111996164
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLlQ3ohgJFw0JWKbK:nd5CB7fdpFGSiLe3Fv5JZbK
                                                    MD5:EAF9A35710EF7B911E20B42C453E3CB6
                                                    SHA1:7BBE3B93E4024497179C2514932979838C62367A
                                                    SHA-256:9647A1BABCB066302924CC634DD0B5830EE8CC8F170D64CF0326CAF53F65B056
                                                    SHA-512:577721C8EF714D786D720CA3EC40DA9716512BF046348B5A8021DC6DF7A0DCB86C86A65408A701D1D8AED63998DFFD2A4002966039897CB569F64CE02CDDDCDE
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3356
                                                    Entropy (8bit):4.834447472537672
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgXABLtQ3JFI4Ctfq4KeGlZusHPwLA:nd5CB7fdpFGSiLG3vIXyrwE
                                                    MD5:DA0B713B66EF41888F7DCC074DB16907
                                                    SHA1:421D9C13927D1F74E79640F68247B4C5881D8AD1
                                                    SHA-256:0E90BEE332AE4C7D09D7AAE3A371EE509CA7EF368C7835EBF039FC80A31AAD4F
                                                    SHA-512:38B34AF0FBD4406F542133BFAFF889FCB3316B31606819BEA9F524BD6691FE7B1C15B964E14311B077C8AA11DEF09126825BDCECA71113DC0F2F54F77A2A3F40
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3062
                                                    Entropy (8bit):4.729236669314113
                                                    Encrypted:false
                                                    SSDEEP:48:M25H6E+iCsAaKj7fOWIkFy9lvAQ3rNqYJzQoFbbUWlF:L5CB7fdpFk3BqY91b1
                                                    MD5:854BCAB1CE11C51043A3DC8301A64981
                                                    SHA1:5934C24F36B9BEE36BA06547400F6263448626BA
                                                    SHA-256:731EE9D1FAB0D86EEE112487BDC5BA1E2BF547D70DE94C1ACB3FCEED1A00E23B
                                                    SHA-512:68ADD03CF160D8DC7D015751AC6C0A27971C4F4D9A82A42B0DAAA9480DD63C5628A7FFEC91CFE3A5183A37BF6F0BD0D00452753FF12E4C46B565A844A907D30E
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2020 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):16065
                                                    Entropy (8bit):4.303609397224569
                                                    Encrypted:false
                                                    SSDEEP:192:deJ7TvFiCnD+f/XO0eXiqegTmSc4EhouBsDTl6tGJYJfcBJfcTJo32BJJfcs:deJznjEsG
                                                    MD5:EDAED0B8F9CB6BC6D6537BADE7C30C25
                                                    SHA1:5EAFBE2F4A34BC58AD5CC487BE828571FE57583F
                                                    SHA-256:3F999849A62AC0ABBBA62BC905C9C955535E1632E230112E63F8C886D2013565
                                                    SHA-512:8D589DE6DE58D55395CC831A2A08F27F1BB23024F2A22360941E5DEC642962D33017C688E5A6F90C0BF2995E239F7EE4EC9B57799BFA1A56B324DF49390FE7DD
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2....// This file describes the plugin-supplied types contained in the library...// It is used for QML tooling purposes only...//..// This file was auto-generated by:..// 'qmlplugindump -nonrelocatable -dependencies dependencies.json QtQuick.Controls.Fusion 2.15'....Module {.. dependencies: ["QtQuick.Controls 2.0"].. Component {.. name: "QQuickFusionBusyIndicator".. defaultProperty: "data".. prototype: "QQuickPaintedItem".. exports: ["QtQuick.Controls.Fusion.impl/BusyIndicatorImpl 2.3"].. exportMetaObjectRevisions: [0].. Property { name: "color"; type: "QColor" }.. Property { name: "running"; type: "bool" }.. }.. Component {.. name: "QQuickFusionDial".. defaultProperty: "data".. prototype: "QQuickPaintedItem".. exports: ["QtQuick.Controls.Fusion.impl/DialImpl 2.3"].. exportMetaObjectRevisions: [0].. Property { name: "highlight"; type: "bool" }.. Propert
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):149
                                                    Entropy (8bit):4.544320813560681
                                                    Encrypted:false
                                                    SSDEEP:3:3BV9NKUQLHMURCNRq6OXvyWmopCxKIDLLNhyxRS9NKSvn:xVfqLHMUJj/8oI3RQCfpvn
                                                    MD5:08266D5A129FF4ECE723F97A96F2A0A6
                                                    SHA1:6CA13C02C1D13966B4FCD5078AA7602642CDB983
                                                    SHA-256:74B2E2268CA241D9D94CE890C102DDB953BE09A4E0667832A196969A45A7FEC7
                                                    SHA-512:0071E8402005DFC0AE9CECD80DBF64355B3AEDF9694375694C422ADF3067867F71EA50811501E492263FC81719470C3D12F7D8AA5109FDC455821D8F8D514915
                                                    Malicious:false
                                                    Preview:module QtQuick.Controls.Fusion..plugin qtquickcontrols2fusionstyleplugin..classname QtQuickControls2FusionStylePlugin..depends QtQuick.Controls 2.5..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):221808
                                                    Entropy (8bit):6.0267692319708175
                                                    Encrypted:false
                                                    SSDEEP:6144:b0zfupprpp9pp1ppeppMppnppcppdpp3p3uppOppIppCppPpp6ppvppKppsppnps:b0zfupprpp9pp1ppeppMppnppcppdppF
                                                    MD5:36E70262EDADC246879B63F9CDB8A277
                                                    SHA1:162AF5C168B9898C1B20FFFE08AD0D9417EB52C5
                                                    SHA-256:79C2516958A8E79935659FC394F7410DC4FD84B98615886158A27CD8FD0B7822
                                                    SHA-512:FF93006FD44A5C5919A8260D8590958DB218F85D01BDB155112D7AECA799B40826314A00E3013A3DC1AC16DA0CCD2DD029D0EAD1A428773E674C7C82793A3CBB
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........+...E^..E^..E^...^..E^).D_..E^.D_..E^).@_..E^).A_..E^).F_..E^..D_..E^..D^U.E^..L_..E^..E_..E^...^..E^..G_..E^Rich..E^................PE..d.....e.........." ...$.N..........@S....................................................`A................................................P...........x....`..|....B..p ......d...@...p.......................(.......@............`..h............................text....M.......N.................. ..`.rdata.......`.......R..............@..@.data...P....@.......$..............@....pdata..|....`.......2..............@..@.qtmetad.....p.......8..............@..P.rsrc...x............:..............@..@.reloc..d............>..............@..B................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2992
                                                    Entropy (8bit):4.81273228791819
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhghQ3JFd0zva9WW3CUlQjxBA:nd5CB7fdpF0T3v6zvaIVHjw
                                                    MD5:7E614A1C63108F26F14C10E9343168D9
                                                    SHA1:74EF43743AB456BDF439C11F2635A2A6D0821B5C
                                                    SHA-256:2C61E245CD57E76D2E93E85443B429893914079C0572E889161661D3A9468374
                                                    SHA-512:391008186118867EB59E00768FED5A36AF6E5E454A389F25C52885E118D58BA4F6DD39E7F9A4B2691E1125D1D2576F98B11BC598A43891DDFD7E1E86577E1FC6
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2836
                                                    Entropy (8bit):4.811093739134321
                                                    Encrypted:false
                                                    SSDEEP:48:M25H6E+iCsAaKj7fOWIkFy9lvSQ399tqYVt2FbbUWlF:L5CB7fdpF235qY+b1
                                                    MD5:C51A96CFE7DE9EF5F7499B520AEF04EE
                                                    SHA1:FD088304215EC2F081FB3B30383140FB716F0842
                                                    SHA-256:C7F74755B3FC438DBDCB415930BEAADA79E45A540424282DAECF5F538EE3489A
                                                    SHA-512:80A19AB44C7232ABB863575C63FF25F235E2EA49A9532FA23ADACC8BEEBACAA3B36067E3E486B5BDB5F936BAFD442C70127F7E028EAD02241AA2B3CB35512BE3
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2020 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2791
                                                    Entropy (8bit):4.789368816922667
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9Oz9mjFlUipUiFaUis:nd5CB7fdpFiFJP
                                                    MD5:EABCA84FB7CA236CFD4D888B5927FEC7
                                                    SHA1:DE2E0D86856451AC436A63C1EAD2C426A621FBE6
                                                    SHA-256:B406E02EBA28CE5CCE0FDC2DFBECF5E5E33489365D542F9304917CA46954927E
                                                    SHA-512:9AEB3C36330298F61C29B7907DB642B0173E10CCC126F7BB7B20B4D40DDF3239C7F988E5ECDAE429322270813A4AB89B9608721BEB7EFE33092A5E1A5B1A4964
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3737
                                                    Entropy (8bit):4.824480757210452
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9mjADQ3JFbturXRgOZM3lG9liitlCSrlcdwlXx7:nd5CB7fdpF+v3vpuT6EMVSbHCou8BjDj
                                                    MD5:5A8305773F1C3EB04EEB95669A0DFC86
                                                    SHA1:38D76AB40DD45903EA7EECE12901CCAAD0E0B98B
                                                    SHA-256:C2E7F54227E7269EAAD59A694A6BDA7E270FFF440DB971EC656C463EC6C0CE7B
                                                    SHA-512:E0566CBC13CF82FE13AA499CD479F4DCB367FFE51B085E3D2BEAE835BD2870DE24093D400ABD1D4E78106972A093B10E386174BBCC3B2042945DADFB6437EBC9
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4372
                                                    Entropy (8bit):4.831554448921381
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFG593vpeT6EMVSbHCo6dlWkXxvd1aS:nd0BhpaeT6EwS7bmxB
                                                    MD5:CBA900B56A0BB79B3C0ADAEC5EA4BD11
                                                    SHA1:45A096A4519AD04657D24D1D0D235B9DC81BBBD6
                                                    SHA-256:6E171ABA2624FC2355A81D10AF62AA0B54D2A5DEA9D5045B7EC0D1EF8E3DC71B
                                                    SHA-512:36CA2555C0C1FD4BB53FE162433E4B0B8E2056C1E151CA4BE1AA985BA1C6342C8A39835BF0EFDD1A589A89764F4A46A9FCA768A7CE7D8A2E3073B1076ED44953
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4671
                                                    Entropy (8bit):4.813432516940473
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpF+03vpoMeT6EMVSbHCodqDgWQ3Q:nd0BhpdJeT6EwS7bd4
                                                    MD5:F8C04DC34CE496E8229D92F557586F15
                                                    SHA1:D3F857E59A6A7838E23A310DE0D7EB98B77A2F0D
                                                    SHA-256:E58DFD296BE0DF39FAE916D8C6487C442738D8D585F679172AA31F4E387149DA
                                                    SHA-512:135747DC5067955B9FE230D5D7C6BC8690D60FAD7C7DD497F09082C21A2956B9446072251ADB03EBAE9F45A7B6D986A4061A0BF948F2DE536993AFC6B3305065
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5024
                                                    Entropy (8bit):4.79541956094615
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFG5i3vpoMPT6EMVSbHCo7C3LqkXx2MKa:nd0BhphJPT6EwS7b7sxvT
                                                    MD5:E9BB45D8613ABABA027AA52B71120AD2
                                                    SHA1:E7DD09EBA800FAEB8C6A8723184AD7693136BF30
                                                    SHA-256:DE14B28466BE01F6099A601E31CCF6AEE2B7D2257390453558B312C34109D70B
                                                    SHA-512:DD341DA13BD34C4DC8941E67057F39F4C0C590CDADDAF2E451084D5A0FE2BCF74CE26854A924AFAD7A80ED5D0F8E157C16486CA86474C422BFE296D2BDFD6953
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):7602
                                                    Entropy (8bit):4.719539415261596
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpF93vb1VSbHCoMW0UCTzJu39ZjbXwFv5Vy7HCIXAq6Dn:nd0BhpTS7b7ev83/bXwFvXybLwln
                                                    MD5:83FD3A877869C8BF5F32575832E30C47
                                                    SHA1:7A65AF01B8F2F5DC4BE4779036BB4A3C4CE030A8
                                                    SHA-256:25A1E6243777E47036B4246BB9D33DDF9E8B4D231FD038ECFF7B31957240E340
                                                    SHA-512:B23D38AD68A58FCAF0D7A876A6A831311FB30A4A086309DD9E9D6CC60B63220848FEFF22446CAFCCA3CA4F0B265C92BD174AC28782CC967ED949EE184E0E8D40
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5557
                                                    Entropy (8bit):4.655914886412063
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpF+DU3vpuT6EMVSbHCoArbYYqAlEe:nd0BhpjuT6EwS7bArMe
                                                    MD5:18C9E71FB941ABBFB6EB29CA6EBE8386
                                                    SHA1:C6705BBB0F8D13B3E26DC267CEF5340A406FB9FF
                                                    SHA-256:122AE2AF3549231302EE693D72DD9FC77060A853AE26E56F6722F089CDAD60A6
                                                    SHA-512:5E4ECB72BD4CD2947443254A1D69EBF610D5FA93B21DCD5D737C0620A19B688C905C163E36F984234703AD356F7588F6212DFB09926340232EB6DA951F44B101
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4328
                                                    Entropy (8bit):4.773188583090913
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpF+z3vZPuT6EMVSbHCoQX7vICGf5/Q:nd0BhpAPuT6EwS7bQ7IdY
                                                    MD5:B5FBA5514574D94C9938E92CF9A74BA2
                                                    SHA1:DE08FE4C2194320A30FE9D27C061320A31531EF2
                                                    SHA-256:3B04B4BA3E8E3E96DCF41D1CBBBA40F734F7C1550FD21E7D5B62C9549C7BB261
                                                    SHA-512:BA38D4FA4FEA68802053CF588764E2A4A88253C818F9E629A7A60ED4806E8D057B6A5B26582B12FE4AB68122163671BF2D617D0E978E57F4BFBA6A10398017C9
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4382
                                                    Entropy (8bit):4.703390501746145
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFFZ3vn3L/p4T6EMVSbHCoqEyuYT:nd0BhpRbR4T6EwS7bqrvT
                                                    MD5:47B7DC67488BE1966E8034B84E7BC645
                                                    SHA1:B447BA31C0639066E4F80BB89C00CD9437BE33DB
                                                    SHA-256:9B32CCBAFD54DF69945ACB8948388ECAD6C287C400AD81F1530D74D1608DD16D
                                                    SHA-512:3174CE4F8757BACBA8B3BB38675FB8EE9FC73BBF9025B12BF1D6CDBBCC9A7EE1D24D5DFEF3EE2FEEA98BFC1A21AE14AFB27701952C8DB9ECBE15783642BD5F78
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3498
                                                    Entropy (8bit):4.882407171422219
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFFg3vQrxuT6EMVSbHCoM02DH4:nd0BhpHxuT6EwS7bMJE
                                                    MD5:D6739FD335FEDCBDBA66EB59E6773DCF
                                                    SHA1:C3ADE4ACDDE28445870CCABC57CF42D6B8CF78CC
                                                    SHA-256:05950FDDEAEEC5591DCB53879E51FBD7240926DF625546B4FFB631D7812B5A5D
                                                    SHA-512:1C391BE279FB17C789F05ABC7F289A85013C92D33CE25D031EFA8AC869F73EFA1EB45A06E20511BCA80C6B3BA0A3D8C3E485063A9FE1BD0B4A73F4E743EDA3C1
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3851
                                                    Entropy (8bit):4.838060697766782
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9mjPQ7JFw0urXRgOZM3lG9liitlCSrlnUii1Zlq:nd5CB7fdpF+Y7v5uT6EMVSbHCom1Lq
                                                    MD5:88368F9ECD36C6DEAA51B7AA221F8C2A
                                                    SHA1:BAA8AA7DE1F659FEDB282FC7EDA073994F7E5D8C
                                                    SHA-256:F562C7CD82A67B83317B99D02DF702E3828CE4248DC96BA90134C1FFBC9F452B
                                                    SHA-512:979271C615C7CA486AD7F676812D0AF0C194CCA23B40D748934AD0A32BDAF6884914FD78062AFD6D1AE5ED14FD1BCF2EF0BCC83D719D890262A1D5C4E5DAEBA3
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3019
                                                    Entropy (8bit):4.878555491459342
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9mjXQ3JFw0urXRgOZM3lG9liitlCSrloUi4Q:nd5CB7fdpF+A3v5uT6EMVSbHCoK
                                                    MD5:C1789DC0F6807473FA33C9A2503AA3F0
                                                    SHA1:4524BBC1DEC99AF1F7D2BE873F45E4CE128FD380
                                                    SHA-256:A16C4A94FBD714868E02A1F3D2F077FCBB82A052F6DE586D79B75CBA14585850
                                                    SHA-512:183FBE005103AB8E09A4DB5DF1E2D239EE5B15C0996773A8040ECCBBAA615DC86B33D2B14311EE9DC59B50ABDF04E562112926BD4616C22C43C225F855A7B26E
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4025
                                                    Entropy (8bit):4.764012906104621
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MmjqQ3JFd0rva0RgOZTQbwDJvfCUl0u5ki4t0P:nd5CB7fdpFFN3v6rva06E0bwFvqK00P
                                                    MD5:BBAECC9F5EDE63EB9B23CB52B75BC196
                                                    SHA1:4531EC1E8D7BBE3E47105DD79E92358788201668
                                                    SHA-256:95588355F32B55E431FDB9A808B438AAEEEFA6C8C6BC4313DA48276251A91126
                                                    SHA-512:82700C6B1C5B4192715A2909A1E38C7F4BD366119E2F21993A77B274E3881BEE0EEE4860122A989F95B5A5BAABE1302ED572DFE294CC16150EA04FB27DC05937
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2836
                                                    Entropy (8bit):4.811093739134321
                                                    Encrypted:false
                                                    SSDEEP:48:M25H6E+iCsAaKj7fOWIkFy9lvSQ399tqYVt2FbbUWlF:L5CB7fdpF235qY+b1
                                                    MD5:C51A96CFE7DE9EF5F7499B520AEF04EE
                                                    SHA1:FD088304215EC2F081FB3B30383140FB716F0842
                                                    SHA-256:C7F74755B3FC438DBDCB415930BEAADA79E45A540424282DAECF5F538EE3489A
                                                    SHA-512:80A19AB44C7232ABB863575C63FF25F235E2EA49A9532FA23ADACC8BEEBACAA3B36067E3E486B5BDB5F936BAFD442C70127F7E028EAD02241AA2B3CB35512BE3
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2020 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3906
                                                    Entropy (8bit):4.848347352860404
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFG5B3vpoMPT6EMVSbHCojkXx2MJ:nd0BhpaJPT6EwS7bcxvJ
                                                    MD5:24283D7771DEEAB25C0183F61BE3AD0F
                                                    SHA1:ED6B62D1A92AE9FA9E31FC75A7A11E6C21614D53
                                                    SHA-256:FCA66154C62837967498F6227B80B2F198CBC9CE1800826BA494419D2FB84FBD
                                                    SHA-512:069127FBA7C0EABC18D193F54B6EC62780CBEC626980548FDDE8BE430B9430D66368728E33BED34F31E9254EC67FEC5D0BD3A3C8C6BC55F77A80986632A0B178
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2598
                                                    Entropy (8bit):4.8596742357415375
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9mjdqQe3lG9liitlCSrlPxUi4Ot:nd5CB7fdpF+/eVSbHCop
                                                    MD5:42E21069F05FE82841410AC980B39C82
                                                    SHA1:BEBEF34997E19F0D0159343BECEBDC8B16067315
                                                    SHA-256:89692FBAB9D2574E58680029B8108451693E60E905BA59E12BBB206D08FC4124
                                                    SHA-512:27F355CC5F40EA6ADE283EEBD24E4DCC1B05A56BD092C8F17F17E2F6DC4FF080206EA80FFC048299016F5C7EEDC6EC0EACEBCD8F7774BA97A2CC9C628D2541FE
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4174
                                                    Entropy (8bit):4.807910198787664
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFhuS3v5bjcnzhLIT6EMVSbHCoO/vCc0A:nd0BhpGq/czlIT6EwS7bmvb0A
                                                    MD5:A842EF113BC327D6032C357B78E10636
                                                    SHA1:885D290B946C79B39FB46BFDE9278AEEC710D8DA
                                                    SHA-256:2C745E09F01BDDDC980DD1FD7D9BC59F852F8CD4D31936E8744FBC686D1CA267
                                                    SHA-512:4600ED8045EFEB92C8F1A022510144A1CD36A79680C02FD76F4F8AFB1C5CD43AE8BE237021131B0255F2B40818A6D2101E4F9241A1E3DC7D8BB66425A670A51E
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5765
                                                    Entropy (8bit):4.728345300633004
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFG5J3vpoMeT6EMVSbHCopQskXxxmF:nd0BhpKJeT6EwS7bmxxmF
                                                    MD5:98855F15171D99774C89A37FEE15283E
                                                    SHA1:AEC9CD96AA708BE2D6DC40C91798D1DC2E75051B
                                                    SHA-256:C08D871DC5470E61139083FDC91BAC3F1CDEEC5A08F2D65B6A234A3D01ABA1F9
                                                    SHA-512:7EC8569ABD078C93265A8DA48BBD9F8C5A2E8C53A14773909FB9092230AA196939A50F3FD0BBBAE2949676A472BC1EA01CE1445C91249D555ADFF00A5525B696
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3342
                                                    Entropy (8bit):4.8458039947129325
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9mjcDQ3JFbturXRgOZM3lG9liitlCSrl+Ui4rUS:nd5CB7fdpF+T3vpuT6EMVSbHCoP
                                                    MD5:2650B36C3100D680C3F8078458E2C0E1
                                                    SHA1:B2CDE7248A5EF0F7438BF3B36A7051BA26A46B0F
                                                    SHA-256:8C54AA32CF04F779D9F652EC107B817DC1671C2012DBA78C551222195AD6C577
                                                    SHA-512:69173761EC70FA4E73517BFFA50457453C261138C12014B7BB7C7FFCDB5E8788105DD44047F6AFC7CFFDD6D58161FD9BDBDFC0300A6FE32997B731931585C2B6
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3309
                                                    Entropy (8bit):4.819542812483565
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9mjlQ3JFm0QuLYup4rXRgOZM3lG9liitlCSrlYj:nd5CB7fdpF+e3vn3L/p4T6EMVSbHCo6
                                                    MD5:76AB39A0A2E5E2E55ADAF8412D52DAC1
                                                    SHA1:73183325AB53DC4EFA16FD7423F9AFAEAA24EE80
                                                    SHA-256:5726D9FF233CF4A582B49EF6B0462A6B8C2B1F8DD31AC1E3DA52E9EE04BD46EA
                                                    SHA-512:83F437C2C698691E106C51FDDF846ED2217C928B7BDEDE8FBD075C94E563D84953136A41E3D636EA92D29FF16C79C2F031E51D8D0A29A1A7A1B745657697B3B3
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3719
                                                    Entropy (8bit):4.810079466894038
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9mj6DQ3JFbturXRgOZM3lG9liitlCSrlNUiyOAe:nd5CB7fdpF+Z3vpuT6EMVSbHCoGe
                                                    MD5:C7191B16522225AA36C8F23C6403DCBF
                                                    SHA1:55662B1265C79169867901F61D59293E107C334C
                                                    SHA-256:53E5EF43405E865313A06998AE4FF4D18C9804BBAFA9F3EE3733343146B3E24D
                                                    SHA-512:7EB524594584477289A6631A0D4F3302CB7634A0DFEA78A8DB184E48F7C7B0D7FD64AF2D45954BE60CEDB2117A1525106803C7464B77B27EAFAE3FC0CE6E585F
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3017
                                                    Entropy (8bit):4.876939712111225
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9mjUQ3JFw0urXRgOZM3lG9liitlCSrlJUi4Q:nd5CB7fdpF+H3v5uT6EMVSbHCo9
                                                    MD5:202F476876C2CD50EC953B21804F3947
                                                    SHA1:926541451AAA55DB88017AAF6D165DFEC44E87CA
                                                    SHA-256:98F970085EF9172E50CF41691721140AA8E1918E6ABEAB3158217640417B20E0
                                                    SHA-512:A4E53792742D75BD27E9226F0BCDAD53C0915D8AACFD684ADB46616185E14CF100C2DA207C2CB5582D2B9FA65C6DC2C1D56E90226531FD1C48161423056C1367
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3481
                                                    Entropy (8bit):4.830165993116169
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9mjwQ3JFw0uzeUc3lG9liitlCSrlHUii0TUikTk:nd5CB7fdpF+D3v5uzeUcVSbHCoGQ
                                                    MD5:69BE6E659F2D8C1BB0713F7C94E97F0A
                                                    SHA1:48ABD582D27788A6B9325F24606B09A7C3EC92A7
                                                    SHA-256:13058CE750490FE19573D0E5055FC45AE6E0201A02A2C33FDF32A5BC53109F0B
                                                    SHA-512:52DAAC09A9D37B880EA4FA6E180F4BC4550C7FAA8093A7F189048422E49FB06F5F0E5B7BF8B415EB8C586CD677D368DD78A5BE6944603019BD8AC70C266DA889
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5987
                                                    Entropy (8bit):4.630541041994902
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpF+v3vpuT6EMVSbHCord67dYslQ8D7brbHYfX7b+T8rZ7bF:nd0BhpuuT6EwS7bkYZP
                                                    MD5:30889BD8029CB44B1EACB72DE3A525E6
                                                    SHA1:312377B89F4CA5625CEB553DF12F2D500B7B82CB
                                                    SHA-256:76B5B566BDEF42FA02A6695EAD12DA75A55485BA5950E586E8E0937961537E07
                                                    SHA-512:2099EAF9B9A1A0F3E43EB967E37F622C2776D4043731810B1FC809D313DC91C0D89E46A5107138F5F9C97C653C80D2D2A091930BD50EBE7703C0706084C20611
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4484
                                                    Entropy (8bit):4.793960034634668
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpF++3vpoMeT6EMVSbHCoangWQf:nd0BhphJeT6EwS7bay
                                                    MD5:330C86F6C5468FF2D037094D076F3FD3
                                                    SHA1:8005BF5FB4C9283E9712C0757F1241052C813CA5
                                                    SHA-256:D7C67CEC5EA3C04764B006E43AB52ECE69AD9244FEBAE8279F29B7262B128ACA
                                                    SHA-512:39F43E4DA9288C11271E72047C53764E43BCB93D69FC5CE9968BB233E1B8082ED50ADA8BCCD1ABF2A38A2557375605FEFF6DF0CB977315DAB015848A5C28113E
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4820
                                                    Entropy (8bit):4.784026716831396
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFG5t3vpoMPT6EMVSbHCo7QLqkXx2MD:nd0BhpIJPT6EwS7b7UxvD
                                                    MD5:2D8334D177FBF90A56D0DF25C6873A01
                                                    SHA1:5A795C5731BE3AD838A51AE039A7FB1946F33532
                                                    SHA-256:B2893C46FDE5D274D881C50BDBA4B1EDB739EFC461C61EE4AA82F97AF6490AC1
                                                    SHA-512:5E91D6D0FBBA03489FF5C4901602AD5119640C375057CAC3A760350156C542F93DEF10B2CD60E3A11ADA39067C53D81F2BA5E9741E536B5BA483B97EDA036E7C
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):6578
                                                    Entropy (8bit):4.692267725745071
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpF+F3vqSuT6EMVSbHCokWDWgw1NGF9H6f9:nd0BhpXSuT6EwS7bkWDWv1Eu9
                                                    MD5:ACB7AF8AC207B804193E69AB0F090FF5
                                                    SHA1:0F49A55B64AC257AA9628ADF139B62DEEA61D9E1
                                                    SHA-256:6A9160817684B071035C77C909B5C0344B91446B31B5C0DB76794395B2FE6CA9
                                                    SHA-512:51C7B8A950F76C36FC20BA865C43F14879E4D7489D7F9C32BE7EA7301EE6F8411F994B3382798B8DCFD4124FA6297F5AF7BD2AF5CF9F76CB482001A715268F18
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4387
                                                    Entropy (8bit):4.835879535269276
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFG5F3vpuT6EMVSbHCo6dlWkXxvd1Q:nd0Bhp0uT6EwS7bmxc
                                                    MD5:BA8B1FD2F9BD70CC6F0E75CE1DCF3474
                                                    SHA1:305D284FF8173E7901DD4B64486BF5ECE39F7379
                                                    SHA-256:A09B06BF3056ADED3FCDA0FEB006809817B9BF844952CACB68D7DAC426F648A8
                                                    SHA-512:0B784ABE126BE8D0312564ED61AD4B9C9B86A3C60A93692B32EB6AE2A824402FC31964C836B6A672993335AE654BC053C3F4457B0B346402B1AF5AEFA5B0B6DB
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4876
                                                    Entropy (8bit):4.7687011712210685
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpF+f3vpb1cT6EMVSbHCoJCHCjKPai4Pb:nd0BhpebST6EwS7bJGmKKj
                                                    MD5:83C1F30435896F967F9A5DFA285A4EA3
                                                    SHA1:8099FEE9ECB5C090D1B13B50A6F06A6608FBCA0C
                                                    SHA-256:E3BC5FFC1B6F2953BED0C35DE23697E56E81DABC41303C4475C35A08D9A42F0D
                                                    SHA-512:5FF6CDFB45AE75B8970256712E26732572B40E8AA74715E674938F4E6FF3A10632DCB90DE01BE88765ADB686F6FD503F528CFB39A66BCDABAA446F79282494FD
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4374
                                                    Entropy (8bit):4.760226215625045
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpF+D3vpuT6EMVSbHCo1+iKPQqPQ:nd0BhpCuT6EwS7b1+iKHo
                                                    MD5:1B48E3E61E0850FDBDEC5643ABC09680
                                                    SHA1:9BC6250D53D4F35E2319360626225AC58E98AC97
                                                    SHA-256:40A0025D6847EEA59D6BEAF42DFC75B7B4C4A9FAC2D72411FA88FA123EC6506C
                                                    SHA-512:459E49FE4C9690B7551A960CF7B13FAE6D2B1E0E8FEED5A65866C898F43AA875943E348CD51F2ADDBA80298D21BE391AC488180C92753899C669308AD9CC2CFC
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5371
                                                    Entropy (8bit):4.688829549188415
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpF+o3vjuT6EMVSbHCovzioFk4cR:nd0BhpnuT6EwS7bvziEsR
                                                    MD5:5F50E18EBA5A16DD5F9AABC5C169BB55
                                                    SHA1:20FEFCEE56FAB4B2446AE0900367F39F54CB30A3
                                                    SHA-256:4E106B1E1FF32CCF2B4417980099839C66A14FA8D35C9F6DBE6E286EB7FB19CE
                                                    SHA-512:C0E3FBAC0287BA3C9B35CF63D47DE6830743DC0861565B918BA79B90AED475A2C3C3D2856EA3A25CAF5A8CA61D732867963F8616BC76AD662C928C9BA546876F
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):6103
                                                    Entropy (8bit):4.642383266979424
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpF+h63vARkq3LbMVSbHCozjKAzmI:nd0BhprybwS7bzNL
                                                    MD5:E4CBC448724089C507B8FBEE8455C5D2
                                                    SHA1:5BF804E3AFFFADF597E0D54B0B83D430D3F7C165
                                                    SHA-256:733713EF52011577022D8903D8811C0D677486BB74B18DDF8A8A5758C57CD7D1
                                                    SHA-512:32EE767B855B0BAE2E70B144F25FF2ED974E8EF8E46EEDCCF691E0DD84FCFD90CFCA239C563B540AF030A7BCC4D5E5C9F52D9896F7B72BF136A1D9B82D864EBA
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2796
                                                    Entropy (8bit):4.829189502970955
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9LiDGQ3JFbtfUiKqX:nd5CB7fdpFz3vpmk
                                                    MD5:08D36E87EAE7A20AAA25636F481B38CE
                                                    SHA1:1CB288148AEA051CA90DC44733031556E43D62B1
                                                    SHA-256:D7B3551F3E7BEE194A107D72E3797990B6308ADBCBF62BE576B5E679CF5E69A7
                                                    SHA-512:540A050964DC4CC736F786510CF3D0B2601E9AA7D557C297FE71BA1C10B4A54FCF6E499BC51BDA1C4B8C424EFF3375EB44CFB7ADDB26AD0B20721BD6B9754660
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3793
                                                    Entropy (8bit):4.938984451415522
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9mjjQ3DrXRgOZM3lG9liitlCSrl8A5Ui4Q:nd5CB7fdpF+s3DT6EMVSbHCo8At
                                                    MD5:D2D5D885EA6A4C074B1766AA47A3321D
                                                    SHA1:90036DCAEC5C3EACFA923B6527F2B0DBCCCD6D26
                                                    SHA-256:4E4E8F91474CF6D1DF29C77EA61CA55EFCC2E7DC0F5D9E9C36CC399D47D98A19
                                                    SHA-512:673E62B7539B33E321EF717A295C33E1663064C511D503D9E94EBF2727E4965B67D67231FB9F7E6A1A06D1F409697C2C159374C66AA2CD8D8980FCE43454C6FD
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4014
                                                    Entropy (8bit):4.858721617896421
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFG5Q3vpoMPT6EMVSbHComkXx2MM:nd0BhpzJPT6EwS7brxvM
                                                    MD5:CF9802997ACD0CB65C1DCF604DF7EE60
                                                    SHA1:91D2A5BB1F38CA615569FA75643A927D7D7CF8C2
                                                    SHA-256:968F32BB64D47754B0B2CB5C7284853789B9F902F5C8E53D335F752F04734E9A
                                                    SHA-512:3380AB51136E911832F16C6F879783F6DD2281D6591F7686826E60DD78A66BE24F847A2F81B4397F074A15424AA3EFEB2FED8640C48461C666869A8BD101DBDF
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3771
                                                    Entropy (8bit):4.8458737978772914
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9mjdQ3JFw0urXRgOZM3lG9liitlCSrlVJeSaVz8:nd5CB7fdpF+23v5uT6EMVSbHCoV3amCu
                                                    MD5:6B95DA8AB7715071D5D08262E7738E6A
                                                    SHA1:C9BA30DDD257E3A090A4F5034E3337AB8924F61F
                                                    SHA-256:AF4CE6FD19D35AABE7E93929701CDC96DDD8D5E8BE044AC14B02045E19B0AA7A
                                                    SHA-512:6A4E4273EB64DD051616643C0890F6726EA4A5DCF5ADF089E6248A3F587FE8809CCD1D4E33EEBF1691995A8D42ECBC371EF1F6C9E76007995A1A13301525B94D
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5835
                                                    Entropy (8bit):4.716808999876189
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpF+l3vpoMeT6EMVSbHCo0CsyPhYi6gWQK:nd0BhpWJeT6EwS7b0Cdk
                                                    MD5:BEC5443EB93D736505D5122BD5FE1A40
                                                    SHA1:B2C62BBFBE01E76E58D5F2B6C5334C8AAD870385
                                                    SHA-256:D8CC0FFAF04A72B3BB294C8135C2F4FD0B56EBBA4B450DFAEA974604095A6FC9
                                                    SHA-512:26CDCF57E2F1909801A58EC5C04068D7E372B3227052EA8F79EBC89B4805252DA9AEDC67424D6F8058D3198232E76D8E61394A30797225C43C76AD3B0EFD1511
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):6334
                                                    Entropy (8bit):4.7154167386387655
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFG5u3vpoMPT6EMVSbHCoKCsPPhY/sLqkXx2MG:nd0BhpjJPT6EwS7bKC6LxvG
                                                    MD5:0134656F3AB414CAD1FF65D54A85D796
                                                    SHA1:0A5F0B237867D098914B06612A3925EF0DD3D910
                                                    SHA-256:35008C52C5133318150FC54859A20A76F80D848FFF4F85C37B99B644E21DCE21
                                                    SHA-512:F72E7FC6AAA125FABC70595144BD121EFFE5A4D4EE35ED500C9EF0ED0EB6EB4E4D27950878B58BC99C781BAA8C7AAD4496354B08CE2F2EB8655AE4656852DABA
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3663
                                                    Entropy (8bit):4.886746712746387
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9mjmQ3JFw0urXRgOZM3lG9liitlCSrllwlcZjI3:nd5CB7fdpF+p3v5uT6EMVSbHColNs
                                                    MD5:75BDB94BB6E425D8A651C84FE2693989
                                                    SHA1:E80B3AB31581F2382EDAA884920C19E0C93EEE99
                                                    SHA-256:56AB9B8B2ADE6B34F0C6439F36EBFC20008BC20E2ED89CBFAAEA5B32BC6773A2
                                                    SHA-512:13C53E5C55F461FCD12EAE14B821CD71A6F178B09FF529AB55D03D074EF251D0D80EA5E4C941DB9267C76D293690BF4169615782F3FEA733A231C78A002CB30D
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3681
                                                    Entropy (8bit):4.849122683445348
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9Mhgmj5Q3JFbterXRgOZM3lG9liitlCSrlHkXxA:nd5CB7fdpFG5S3vpeT6EMVSbHCoHkXxA
                                                    MD5:DA55AB91E26CC8AA84561F925189B76B
                                                    SHA1:7105C856D95B7C7682E83809DD0DA1DD19649F02
                                                    SHA-256:4080C05B7C3D121467A46064A7947A237777C83BBCD04D104039516B05911F5D
                                                    SHA-512:CB903DD888ACE8667A9AB4B545504DD29AC9418A4AB1B4263B6BF180EF0D5675EEE4D901B8D65D829F6FB6C3EAAA5F8853428C9693D4359E8E7EE8F2A19381FE
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4254
                                                    Entropy (8bit):4.845015810046707
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFG5r3ONsuT6EMVSbHCoGeb+EQ:nd0BhpTsuT6EwS7bZbI
                                                    MD5:FAA41133A73B4DC825653FB970652E9D
                                                    SHA1:C02D376320D4DA4212FA065B6E55472007D7B4BD
                                                    SHA-256:FE3EEA83E17B0653C95204954C1C13492D17182A4029CE6F87D4EC54EDD0C57E
                                                    SHA-512:E8A206DE437178E10CFB2BF5ACEAA981133CB2060979DF247F156389E082193C4547367ED87CAB110CA86C1F354751CC500916F702E6E9A1AE7AB7FCE2D95C21
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4191
                                                    Entropy (8bit):4.8647392482168215
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFG583TcszuT6EMVSbHCoG8++:nd0BhpmszuT6EwS7bbj
                                                    MD5:05D77B4969035EACA21C745EA204C6FB
                                                    SHA1:39BE9694C92A4256818DE11D829FF37FEACB3311
                                                    SHA-256:C0B78028D628701DCDC749F5E23EA34702B38B37396B934E7468166FCC170D1B
                                                    SHA-512:1793FAFA7272FDFC9D91BA169BA5037587A44DEEC91128368EF3881D9F3706D92549DA7FD1FE77FE3FA09FC75BE123A6B3A86EC14747F5D62D165D193B0AB060
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3161
                                                    Entropy (8bit):4.882839077082351
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9mjVQ3JFw0urXRgOZM3lG9liitlCSrlOUimQ:nd5CB7fdpF+O3v5uT6EMVSbHCoe
                                                    MD5:28F144B0A52046A671DC9C9A9302AA10
                                                    SHA1:92383DA085E5B39DAE7BB4A82C75E9E155FB500E
                                                    SHA-256:1C0F5FB837DF23FD38DEDDE1A861AA88F2D19CFF66888193642E111D8EDAC7F6
                                                    SHA-512:BFC9796B4CA608F7EA6949AD4012E2C8707BFBEB52EEE9DAEED21A5BEA43D1D1F8B350CDBFE831A416D4B5BB3EBB5CAB61A841E1334A81635E1ACD08433D40CC
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3830
                                                    Entropy (8bit):4.833756919163597
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgmjAQ3JFbterXRgOZM3lG9liitlCSrlHkXxP:nd5CB7fdpFG5T3vpeT6EMVSbHCoHkXxP
                                                    MD5:D1CD80D9F62E3BC12386E42349B02633
                                                    SHA1:14BBF4A5F6B6F51D4F1028B1BB9D24BB52329559
                                                    SHA-256:394BDC672A6D840601724F96013125F1CF56D76EACC7C4EC9C380CDC0D4A2BB5
                                                    SHA-512:82A159B176A0A3C89B3E7B7D4BB22EFCE20DA3C0657414AB2D5F146B9A8DFE8610BFB8361F0D955882192C5DC2D18D0F8B8A46E4502BBAAB41F2A8583B6A5323
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3546
                                                    Entropy (8bit):4.82751167160194
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9mjDDQ3JFbturXRgOZM3lG9liitlCSrlDUiKVI7:nd5CB7fdpF+w3vpuT6EMVSbHCoCF2
                                                    MD5:6FC66BE2941180FEF96E8505948AFDE5
                                                    SHA1:4F815FB4D32E251D216E1F053A83B083BCCDFCA6
                                                    SHA-256:DE2B80194C888E934C3C69C81F503AB088265B761E0403725393BEF4533D7798
                                                    SHA-512:1B993DBF048721C159ADE565DA56C0474B74508F18B4D03FA9A15836B9187E4A77C58EB5C3D8C00D0370A71E246FAA14958CC269E03868D057AEFA19F9D30DBD
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3620
                                                    Entropy (8bit):4.904374904966172
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpF+e3Lv5bjcnzhLIT6EMVSbHCobj:nd0BhpJ/czlIT6EwS7bv
                                                    MD5:83904652E769BDE5143994A507E59B6B
                                                    SHA1:E8D112FC140E384CA90A3E81E9D8DB1EFCC0FC9F
                                                    SHA-256:06C08B5F38CF01420A5DB7C79324F92E3232917010903211AA3C3947F9EC255B
                                                    SHA-512:A514FC496A7190E74ADA3C4CB04093237B37583A2D85B2ABEBA286C45F17A67BCB9256816E40AD765E5861DB3465BD728DE2A9C832EAC5658841F7965A353531
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3981
                                                    Entropy (8bit):4.831862128102055
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgmjtQ3JFI4CtfZ3lG9liitlCSrlJKeGlZusQ:nd5CB7fdpFG5G3vIRVSbHCoJyrwJ
                                                    MD5:B0D74817FD1838CDBA36EF95630482BD
                                                    SHA1:756C5F59C9E99755061C051B65EAA36512DE34FF
                                                    SHA-256:65236F0F2819A352FE4DB4F5BA3576000376BADEBEFC5292A1903ECAD98E4C80
                                                    SHA-512:3934421561B2827F8446E4043DE15E6853A5C6F2C0F4B5A8BE13EE4378FAC733F13C268A117CD81A2F2C9E9D179C7411B337AF3E540DC351479693463B3A0E85
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2833
                                                    Entropy (8bit):4.809421054317256
                                                    Encrypted:false
                                                    SSDEEP:48:M25H6E+iCsAaKj7fOWIkFy9lvAQ3rNqYJ3FbbUWlF:L5CB7fdpFk3BqYvb1
                                                    MD5:F5CD8AC746B6994ED71FF8301B42A56B
                                                    SHA1:BA037B256EE49D9FC2C30BD11CCB8A01993A38B5
                                                    SHA-256:1D4F3F1D0DBB8CAE0D392C2556889C9639A1A51B055E47BDAABEDBD33BD4A934
                                                    SHA-512:6B465228D5918FC4A1EB093A0896ABFBD11A57ABD2641A6F89581B063E6537F5BEC2B33084F873871026526C39741A10CE11C0F52BE80B35257EC86F7BD27E75
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2020 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):13648
                                                    Entropy (8bit):4.31944970441457
                                                    Encrypted:false
                                                    SSDEEP:192:cLXw3CUv1rBbHj+f/XO0eXiqegTmSc4EhouBsc/Qtr/ANL:TEs8
                                                    MD5:A73AC7C03BC7A2F310D752CDFDFA5DC0
                                                    SHA1:3DA2122127FCEAB38A4D5E74C1EAAD317EAC3078
                                                    SHA-256:04F4157E80D7D4E5B6EC8D9C88759D162EFBFC81A90491DC14DC203A1F01B6C0
                                                    SHA-512:92C57719E2CBFCD0619CF7AF8DD7AB47CDD83D34EDE7E2C0770A4306DAB6234CD843961D427036949EB73974AA94A897B38A0C35ED7F6FF247E25306DA9AF5A0
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2....// This file describes the plugin-supplied types contained in the library...// It is used for QML tooling purposes only...//..// This file was auto-generated by:..// 'qmlplugindump -nonrelocatable -dependencies dependencies.json QtQuick.Controls.Imagine 2.15'....Module {.. dependencies: ["QtQuick.Controls 2.0"].. Component {.. name: "QQuickAnimatedImageSelector".. prototype: "QQuickImageSelector".. exports: ["QtQuick.Controls.Imagine.impl/AnimatedImageSelector 2.3"].. exportMetaObjectRevisions: [0].. }.. Component { name: "QQuickAttachedObject"; prototype: "QObject" }.. Component {.. name: "QQuickImage".. defaultProperty: "data".. prototype: "QQuickImageBase".. Enum {.. name: "HAlignment".. values: {.. "AlignLeft": 1,.. "AlignRight": 2,.. "AlignHCenter": 4.. }.. }.. Enum {.. name: "VAl
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):184
                                                    Entropy (8bit):4.7454423417894835
                                                    Encrypted:false
                                                    SSDEEP:3:3BV9NKb90GeCeURCNe96AVhvyWmopCxKHcb7JAeyxRS9NKSvBnR09FGhCULVyn:xVfK906eUn9B58oIwu7CCfpvB+9Itsn
                                                    MD5:0843847828B7895FFE40B82A6D153981
                                                    SHA1:83A9E2D91D5E08C2BFE10959B571A9D513563840
                                                    SHA-256:F1E647A9813764AD9BBD0F1CF1C24161DCB6F8828C3D08907F4B0232C750B1D4
                                                    SHA-512:C37CBC1A0C39C177893DE15543AE6A5AEF1E9670F5B15800060EB696D62CCE33E5C82E56C0031E15DEFA2C675705A88D162DDF566426DAF9E7600D7D3E3B8788
                                                    Malicious:false
                                                    Preview:module QtQuick.Controls.Imagine..plugin qtquickcontrols2imaginestyleplugin..classname QtQuickControls2ImagineStylePlugin..depends QtQuick.Controls 2.5..depends QtGraphicalEffects 1.0..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):1168496
                                                    Entropy (8bit):7.422768481255007
                                                    Encrypted:false
                                                    SSDEEP:24576:yNbyUnF4juIEp1mogpOzH/r1K5JXN/tZh:ydyUnF3ICmogeHTcHXltZh
                                                    MD5:5870C7E851A973A9758927ADF2114420
                                                    SHA1:8C58B5210B754CCD95F347939C333FFA24AC13F3
                                                    SHA-256:D7659464257C5597DB725DA99D2C3C938DE3ACFE2CA84E29E8A4EFA939A14848
                                                    SHA-512:FFA4F899A6B8188803DC176925B7409680DA0A513508B2AB8E4A1A7771797B0CACA92E8B8D1F743056D8340C27F19ADFC6696A94B463B8835ABF760BF7827DCE
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......u.T1...1...1...8.d.7.......3...z...3.......%.......9.......2...%...<...1...i...%...;...%...0...%...0...%...0...Rich1...........................PE..d.....e.........." ...$..................................................................`A........................................ \.......\..........x...............p ......t...04..p....................5..(....2..@............................................text...0........................... ..`.rdata..p...........................@..@.data...............................@....pdata..............................@..@.qtmetad............................@..P.rsrc...x...........................@..@.reloc..t...........................@..B........................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3287
                                                    Entropy (8bit):4.807550250685247
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgNQ3JFbtoM0kXx2MhPwXzrk:nd5CB7fdpF033vpoM0kXx2MhYI
                                                    MD5:6E3845C09360F72E2175D55F6824A8C1
                                                    SHA1:6FCA8FC5EDBA60C288505B569D2AFA16C106A61D
                                                    SHA-256:4E7E9EEB41EA501135FF25BB9C20702F39960CAF2062DB11A5F14AF4B2FF229E
                                                    SHA-512:6DC194F1270E81F9F52C2A1EF14D641809ABDEDA4A50F07B0E40B31EDF0CD9CF2A3E4A34265535B3044E623C4D052E4BA94B910E4AB16E4DF60B25A5FD5382BC
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2006
                                                    Entropy (8bit):4.823272355715288
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgWqQwq:nd5CB7fdpF0xp
                                                    MD5:93E7E784E66D09A9F5661D5AECA1E335
                                                    SHA1:38E5DD3385E1295A8EEDC371B97F1F6574C0016B
                                                    SHA-256:29AD5863DE006243027DA0B490B474F61097F42477577CB6F86167CF5058FF36
                                                    SHA-512:EB933A8AFDBD1266A0E4905B0271A154153DFEBC90494A02E2EB5BEED5BFC405A08422CF43B1F722570F8662F69C2A0850F294F5B7F144D6DDED2D6B87FEF62E
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2301
                                                    Entropy (8bit):4.868241936290458
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OC9GDF/y1/H/J:nd5CB7fdpF5DFq7
                                                    MD5:5F6AAF4B990B3F689F16CAE3D9B7960A
                                                    SHA1:32603C110B38AF5D97A8DC0A9C926BC9944BC07B
                                                    SHA-256:3997B7DC3218FA3BB66AD68AAB2D372FCC5C932225B4EE68E9E9B2530063EB32
                                                    SHA-512:4BAFB9530E1F512689F56D4DF90099AA2549B08121B5DAEEDC3FBB73F5A3D0E327EE02BEB547CB7940F6F73EF6EDE9C115ACF234E0210278BF5164D658197E39
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2911
                                                    Entropy (8bit):4.889093741052121
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OGDgGp1pIPrzyxhFa6Qs:nd5CB7fdpFQDLp1SjMj5
                                                    MD5:B6D09D6C6809841FA11E9B483563508E
                                                    SHA1:522B3973D1B8FFA3F80ADA6D8132C4F416E773A9
                                                    SHA-256:88BFAE64F2598B4591E3A71A64E8520E4F94855B4427C386F26B3ADA0484A779
                                                    SHA-512:6B4B8335975139D83993C576086BE398099E60972ECFD9126AF9E59E00D0D4AD84EDD15C5F55171097EA9EECED141C85FCDEDD424066EAC6E67DC16B7AB80C22
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2640
                                                    Entropy (8bit):4.846310750971607
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9GDgGpADQ3JFbtEWyIwB:nd5CB7fdpF+DLpv3vpE3Ic
                                                    MD5:998014A48C501D6F5CAE34C36A5480FD
                                                    SHA1:6C9F57D7FB8EBAB09ECF03C594C1D27EDBF11C84
                                                    SHA-256:B88BEF72CCB2DF722C7324C7A5B9D5B7A7DAD157F1E425F4366A2CB8764AFE14
                                                    SHA-512:D6CAA3526C95B4AF25334FC5A768DFC17C4ECE6B0EEF044D8E93F5515D612254644860EF840E36F5C8AB32845F33C777E831D8E17AE99743D6F0BD130C8726CA
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4891
                                                    Entropy (8bit):4.712125500495967
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFGLDLp93vpCDkXxpZwnGluzFYkbV:nd0BhpAvR5xDfluF
                                                    MD5:2231BE9FCA62552B9EF504732460B9A5
                                                    SHA1:71DFB6EE4C84E72384E5F1DFD4C1440BCC73C1BE
                                                    SHA-256:156E59F5ADA238F76C0EE47E30E5A10514B35DDF14B6CAECC902CA6EF4C9FE99
                                                    SHA-512:6F2B025808EE57281E98580E1F467AEA5E5797822F5EE009B1E77C5F4D0B56174EFA944E33EF5BC55FB2C7DBC003BB16C5FA6AE5834648B2F3ADA4536BEEE285
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3651
                                                    Entropy (8bit):4.792586493832598
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9GDgGp6QQ3JFbtoMXu10J4Z6/E0xeskxgzMCUlN:nd5CB7fdpF+DLp03vpoMdqgWgxs
                                                    MD5:A7E874448E4E895AAEEEA3590531024B
                                                    SHA1:3976202A28B68B5E8905981C3577C5A7377B3D81
                                                    SHA-256:F0678CF5E73535E683A33AE8843AFF427E344C8A0158ED61C119965CAD096139
                                                    SHA-512:CF804D342CC327D842378DA280ABF3314746DF3104C7A4718C961929CD93ACD794004D1C79A34F8918B23817186867952F4E444B72A94FE01CB13EDFE87A54E4
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4065
                                                    Entropy (8bit):4.79287401260897
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFGLDLpi3vpoMCZySickXx2MXi6:nd0BhpAvEJEy5xvN
                                                    MD5:72203B5852DAF13E66924AACE316341B
                                                    SHA1:05AA4A43F090B0A4B1C56D997452B68EF9F32698
                                                    SHA-256:3859E906C67E38F049C0B99A476A7FFC76F159AD867316F9732AE19BBDC91BBA
                                                    SHA-512:BF56E27E887205AFF8B530BE3D188A574AEAFCA6144B46E15739517F1DF179D89693DDA1779B226D2B9F490A8116910E273FB2409097DA47836C841349850861
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4154
                                                    Entropy (8bit):4.70735936961081
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OGDgGpyQniB6mlOFAoOXt/A4zE7u3iWWrGbWGLf:nd5CB7fdpFQDLpyR5fAcElrGSGD
                                                    MD5:B5BB21C77903BD5D5360BE94C12F2733
                                                    SHA1:D9F189675A8DB324D539C0C7891E2CF2DB6E8BBC
                                                    SHA-256:8A03D5FE3AD0C783F7611FAD9ED5AB7AB75895213B3D8B83CEA478530C2ACD5E
                                                    SHA-512:3EC94B29854D6240E8C2AE602FC0DA0344EDEE6960C672995573F0A7D5B61D13A30787F7930C1EC179F434C236E6AC3414600AB3B80D2F3D1AA7C7F897D52BF5
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):7689
                                                    Entropy (8bit):4.73406088448742
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpF6WB3vpoMCeSIUpUez8vHFTkkn6/9uUU6jYnppzEndq6BpcV:nd0BhpQWbJnw/N/UJ6KpBCd3O
                                                    MD5:684162F6BFFEBBC196DA4D6FF87250D7
                                                    SHA1:97F44B76F93632B4547A3949AEDDD78FDB4AB3E4
                                                    SHA-256:B37F3B3C0D2E3E3D5A4A232755FF0FCFE9BAF7582DD6A7962B09319B3D44B44C
                                                    SHA-512:C117BA7B8D60E809181709D8AF9F6247EA67A012A3A835DDE5F25CA1ED2D65BAA000EF07BB79A954B8B106014CF2DC67B527A5DE69BE7AF774706E020DA11BE7
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2616
                                                    Entropy (8bit):4.794552110693869
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OGDhQxh/DfXDx01r:nd5CB7fdpFQDGP/Dvmt
                                                    MD5:3997FE3281C6F47D2330E117E3712887
                                                    SHA1:0556398A8F6006D19CE6EE73C346CADB5784D7C9
                                                    SHA-256:1C894576FD20CEDDA07919CC2401CC9D15A90EFFB272AFC31D1DDAB31537C3FF
                                                    SHA-512:5BD646B0B4A6DF0FA5A20316FEEF43BF54821916B4D0ED86794BEE5A298EE590372CF26D39E53F54E2814D334F1B7F7D8C1F2398579BDC91D58686531E175949
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4471
                                                    Entropy (8bit):4.701240992370061
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFGLDLpNU3vpCqrcFrwnGYCjvFYkbc:nd0BhpAvQprWfYGY
                                                    MD5:EFA3A440A844F11307A1056F3D20D008
                                                    SHA1:187F407F5388977B27C76C2B8BC797AE8B3E4D97
                                                    SHA-256:1EE9513B607B760E0C7BC5BE8F794A6C5A2DFA96A946D2F5E5874467B03D6B33
                                                    SHA-512:0D2CE0FDB078BC97CD6D1C9E35213DF9652306491879A95BD99CD80B0F44F0B93D1506EF95051001583DDB915B4A60C7230158DEBF4FF60A5EBB71ECB2C4EC66
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3543
                                                    Entropy (8bit):4.792348845887984
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpF+DLpz3vCB6f5noBi5lnFify/Pt:nd0BhpsvImo2lFL/l
                                                    MD5:29D8F30C877B7FB8122F16EC9950A142
                                                    SHA1:4293CBCD68FEA7A3D255FA2D84F8586D13632D8A
                                                    SHA-256:F4302746ED0917CE145534B9B81FE0FAA025531CF5ED04A81A72994FA234E45C
                                                    SHA-512:0D07A75610EA512B25D7DEA8CCBC803FBE9ABF36C376AFFD517C5AAE6486EC0CF5E305E8FA8382479E9EB7E29EEED9F568DC09AE8242E13280A1124935D66018
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4358
                                                    Entropy (8bit):4.812079921863784
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFGLDLpZ3vn3L/p1jYnppjEnF5FyBP1:nd0BhpAvfbR1apxSFOP1
                                                    MD5:2548CFF063C7BE6F57B8D4F81BA33A06
                                                    SHA1:C314CA356D2BC6E985BADD8E75F96A7B9A5C0C6D
                                                    SHA-256:0363B31324C9EF26FA2BB540334774DA0A6545951DD06A149E6B832A6BF6C7EC
                                                    SHA-512:870B3687579C10781A7B110FF885964D0D91D6ECD5A68A41C4CF3F5B09421AD2302014EAE2889E38A00B6538B84E2721F0F056EFA2209383283F333F62F26E90
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3207
                                                    Entropy (8bit):4.869069840142379
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgGDgGp3Q3JFw0Xk6s9H9YMweiWt0D/6x:nd5CB7fdpFGLDLpg3v506sDYMHiW1x
                                                    MD5:06C06A6C5FE0705DE484D089C6E803F4
                                                    SHA1:C3C742F65EFE8DDFB72922C98C265E1E6A6A76C9
                                                    SHA-256:8A0C771BAD8EA0DE60C8B5595C3ADDF6A6E7785426CACB7D57F30D7921524045
                                                    SHA-512:2FF884A5929EE2E3C576AA9BE594E0CDEE5C52B2C4F288CF4AE9BFDD4737CA412FADA63442C245FD34425640AC19FE53CB56863BAF6BD09802B7BFDC2FAAB49A
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3867
                                                    Entropy (8bit):4.862301490461931
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9GDgGpPQBJFw0MyAxyhnMQxWQfgUqRh7/k/J:nd5CB7fdpF+DLpYBv51EgT4hK
                                                    MD5:13FDABAD8449B607D5365D681CCE3015
                                                    SHA1:7BECB74EBCFD5AFA4ED27ED41DA1828496033F2C
                                                    SHA-256:5F37513A7BDD0DADCFDC435882DB4199A224114EC41DF8C9250AA1483F9428C4
                                                    SHA-512:79013303748C61FE97F2E759AE1778157B2C88451F564315BA642180A6E5C5903171E3E6BB600354924B37A24A3D29168FB1C196195222EFDBAC863D0E66FB71
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):10030
                                                    Entropy (8bit):4.806138037085718
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFQDLpKr5EuujsA1GqHVyPDwQHHoxOoumQ91H24L8M5nNG2oLk+WPwub:nd0BhpKvUr5EpjsA1F1hQHHRodU5oQ
                                                    MD5:EF49589B6DDF274E2EF2E77ECD689BD9
                                                    SHA1:0C3DE37CD559D988B9F78A845B8A6D45D6FCA35A
                                                    SHA-256:4E223635E82795BB7A8909C15D1F2739EE7E607344187D30B929B5D8DDB09808
                                                    SHA-512:0A3FE282F8447E04565976791D66F1A177BA7F925AF1663D7DD4CE5D5D86CD14364E7C13E2ECC59BA25B52FF1B4CAFF93B584892673328F576F526167CE77B03
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2710
                                                    Entropy (8bit):4.838309188288612
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9GDgGpXQ3JFw0akHz4y5Fc6RW:nd5CB7fdpF+DLpA3v5L5FLW
                                                    MD5:6E05224A672A8F3683974C2BED54DB19
                                                    SHA1:C67BD494AA339A0F025A1DE7FE0A2C3F4E8D2ECE
                                                    SHA-256:54B7E9D18092BD8AE03E9336554F48CF5178C304457C70FF107F4A2FDAF810F0
                                                    SHA-512:FB38360AAD57AEC7202BA891F9EA4D7F8EE7C49A1C09C5AB924ED65A0D7C77191A9508A2D88006E6762544AB015C42084F04E56CEC3BC3A19ABB85E3884EF9D2
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3408
                                                    Entropy (8bit):4.812150701263161
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9GDgGpqQ3JFd0kHIvaHHtWnzMCUlQjxT4y5Fc6w:nd5CB7fdpF+DLpN3v6LvaYnxHjD5FLW
                                                    MD5:DF99BC50E44F0E6708A96BEE13C330D0
                                                    SHA1:D153FF903F1C7C2BC5692ABF41B91DADA12F2387
                                                    SHA-256:BDFBC86A651DB5FDF65A3FBCB7CBD91BBF295D845612BA369E317FC4A5DB3AB9
                                                    SHA-512:2F409347A4BA5F600D07BC38258C6451C0CD7C83F27D51C4B8EF38B584FE04245A0DB4200BAAE5A7FB800CFA4A628BBDC003567966304704C919F7E9E1549E51
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2968
                                                    Entropy (8bit):4.8077641352008476
                                                    Encrypted:false
                                                    SSDEEP:48:M25H6E+iCsAaKj7fOWIkFy9lv8GXGBQ399tqYVt2ykFbbUWlNzx:L5CB7fdpFgWa35qYDQbdV
                                                    MD5:A4DACE7AF6027943AD4B4513FD75EE40
                                                    SHA1:878BE0B95889815C17D3A97ED5D5F522AD2674AA
                                                    SHA-256:D8F333E3EC6E057BE364A043677A8E3A2762384C05FCFB2A5069184DDBFEEE99
                                                    SHA-512:850FF7CE8304F738D9114E988FB7B9720C5D0B8A3856BF5AF354E5C96062E62024E47E7DAB3653B3458D7F2542116FDA35BA5F452C03011D83047E2C2864A1C3
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2020 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3570
                                                    Entropy (8bit):4.797861913310862
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgGDgGp+Q3JFbtoM2/EyZkXx2MXz1gmx:nd5CB7fdpFGLDLpB3vpoMCZZkXx2MXi6
                                                    MD5:48495866F8B6E452907F4E90F0B1AF19
                                                    SHA1:092CC0136EFE59B8389B7A521628FD05E59F7ADC
                                                    SHA-256:D4FF3080E64C091CAC96A7A4F6F7FE8F2F948F468D70DD39271AA48D02F6B306
                                                    SHA-512:1F9F95545374F75CA3E345737ABA1E86D652FB3E65B3F92FCC2118E6DC15CF6DF5461874AEABF1A1FBE0910CA8752AB6887FF1FC955AFB27B316FBF42901F3F6
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2008
                                                    Entropy (8bit):4.82410778031169
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9GDdqQZEtV:nd5CB7fdpF+D/Zg
                                                    MD5:DEAEDB2DEBDF15BD087D382C28C34291
                                                    SHA1:72FD0FE26E38F816D8572DA1C9425365F64ED9A9
                                                    SHA-256:B82053C1628AB97B4FC2EC4B001E7368B8483B0305C15CCB5BA29B2F61E7AE0E
                                                    SHA-512:D4B2CF07A170F9F68C19E4A98E0FAD270BE2F748C883B988217BC9BD16E3198C06DDDA9BE600E3C66AA84CF1A93E4B6ED69DB0FF88A2AC3834E08F6F770F2F72
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4162
                                                    Entropy (8bit):4.869740301783965
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFTDLpuS1v5EtBjYnppjEn2vCccP5FF:nd0BhpdvgmEtBapxS2vbaB
                                                    MD5:365971BA24915164063E97690F7DAE9C
                                                    SHA1:2A55D6FCC0512A77960FCBF761A1910D5E461FC2
                                                    SHA-256:413199D8146BBF130A26A50753B3F8ECB8A26158A5D77C32D6B1EB22B57B3AC8
                                                    SHA-512:A911D0CEEEA33F52DA8E30D7C946BEB14E39E873658E3EF58DC383292997570C3673A2EBC22AE1159715D5F1DA0427A76133B17C2C3BBD1BB27DF6E89EBD728F
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2604
                                                    Entropy (8bit):4.840411587708949
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgGDgGpuQ3JFw07mXob:nd5CB7fdpFGLDLpx3v57v
                                                    MD5:68ECFF6B2C4A7B65B2D6CBE889DFBFEC
                                                    SHA1:D7DA0CA6412D9C4E81A567C22B1AF44B64C14FBD
                                                    SHA-256:C62DB07B4D429F9BD0CF88EAEF9B15AD8CDB58322C7656D55BE5936044EB1240
                                                    SHA-512:DA91A917EED9C3597D91FA12C4EB4FC620BCBB4E5588A011DDC924F88749CC3CD42B10AE8E654A6920BBC6720EB6B8FF42CE7277F52106F791A0F6708BB3BC4A
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3442
                                                    Entropy (8bit):4.770573402116531
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgGDgGpBQ3JFbtoM2cEyZkXxmz0wwX/gvx:nd5CB7fdpFGLDLpa3vpoMzZZkXxmos5
                                                    MD5:9BEB46066F22FBBBE53106B5FFB6AEF3
                                                    SHA1:10E428EB0D85678230CD138F18536C0AA5CFC53C
                                                    SHA-256:F3A31AE3CEEFEAAE4FDA9A173FD3EDB0DD817D692236120572D874F7FD2838F3
                                                    SHA-512:B7A647B35E2BD15CB5BD43C0CFF81FAB42BF54033E4EB2FFF88A59B0D64C0D2B230AB1907D92F392A71B53C6DF0A6A0D5E1B806A6C4FAA00742AED06A6742F20
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4788
                                                    Entropy (8bit):4.767659902718251
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFGLDLpJ3vpoMWZ4xy0FQskXxmooe5:nd0BhpAvdJg4x+xR
                                                    MD5:10972CD75BE888A0F031B6C6D2FA0E16
                                                    SHA1:354218F2EBE99D987B7AFD2DE04BB7D7A7763E5D
                                                    SHA-256:A7E1B2398C5CBFF591FE34270FC800E2DEBAEC810689744D58BAAA149558A619
                                                    SHA-512:55CF2C2265A5D3604305B29D5998A0D9F2E10709893133A19709C2328F742E065F2F3A60D79C3C10A2C165233A225DEC899D4F60B0AD2A6FF8852F4C7EACE73F
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2400
                                                    Entropy (8bit):4.831926312624564
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9GDcDQ3JFbtPTslb:nd5CB7fdpF+DT3vpro
                                                    MD5:5F7E2FA195063A499F450D38AC067AD2
                                                    SHA1:FC02285B676D836409B46B57EE2D798EB256402B
                                                    SHA-256:8CFD1C4238B721C2FFC6ABB4132F5670E45A6768AD5CBAC7413FDC5BBFB4D92F
                                                    SHA-512:2186361D3C9A1C889C311508C2D92EA20C428B528946DCED53CFDCF312E643BB4783235691BE1EBF0644C2DC52ADB85796D6CD172FA627B1EC4CF6FBCD27E497
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2588
                                                    Entropy (8bit):4.772227959654226
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9GDlQ3JFm0QuLYup+b:nd5CB7fdpF+De3vn3L/p+
                                                    MD5:CBB179BD9C4898ECC26A6EC3C82A41C3
                                                    SHA1:61B2FC2C285F19D0037B825229BDBC9E2BB318B2
                                                    SHA-256:DEFAA9EB6822493956BCA3942ABFFD8C41EC10D40653EBE48147A00C321A4BB7
                                                    SHA-512:4FF25C655307C36C6077EF936AB27C0FD47D8A64BAD5D761BC4E582764524B67E4127E7EAB6CE8A70ADFB6A74EA52579D51123DD1FD22FFA8089CB28A7CDECA4
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2795
                                                    Entropy (8bit):4.828338932063428
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9GD6DQ3JFbth60+jzyZZZ:nd5CB7fdpF+DZ3vph60+jGZz
                                                    MD5:EB291290659332B4760637A4A13C9BB2
                                                    SHA1:8C8B529B020F7F58C911B37587E065197ECE76B3
                                                    SHA-256:F7A71B592744EA1A88843238B5576B4DCD93BC923D79585D3BE0C54F749C1A96
                                                    SHA-512:9E5BB4EC6E40617094C05C10734298A0D60F027EE19FB2C4E383BFA6A7197867350626C024E9BFBA9B2D250A65171DCDE90D5F952EEB9B43C82BF9B86FF051D3
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2594
                                                    Entropy (8bit):4.8344449556473075
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9GDgGpUQ3JFw0o+MFc6RW:nd5CB7fdpF+DLpH3v5eFLW
                                                    MD5:E5FDD28B572D970E35544C60FD8BA0FF
                                                    SHA1:177441A046688D225AB8B60F67D1D8755239535D
                                                    SHA-256:158D1F2A7C116DA47489FF7D022314A79198A9C10784FB04B777B19A9906A284
                                                    SHA-512:F84CF4159FD462FD33AA3E4464F0662FE362D812813A5A688C6809847D906C029BD3471CB8F5F5B3E74471D08C593FCC3037BDD858E62B5DFAF1E501CE2BE603
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3464
                                                    Entropy (8bit):4.898820195124723
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9GDgGpwQjJFw0FQiYnpetijEnIy5y6RC/k/J:nd5CB7fdpF+DLpDjv5FjYnppjEnF5FF
                                                    MD5:7046F5FF3A70AFCA04B39F430AB475B7
                                                    SHA1:DC7DC60B93B54C6E11CD696927FFC11F3D1E28ED
                                                    SHA-256:B25507E5FEFD22BAD1CE21C0CF7910C448789EEA5DDBB74D7B17BDB4059CE6FF
                                                    SHA-512:A58099AE5E66317A1C8B14DEC37896DF1F535327933FA27060FF82BD16062F3166AE78CF7F8D966A83C10CA95960743AB16198E6932DAC4409146603CFA75B7B
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2820
                                                    Entropy (8bit):4.837609805236169
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9GDgGpiQ3JFbt8zgLozak8sBS:nd5CB7fdpF+DLpl3vp+7zanX
                                                    MD5:D1C0A356DE670765571C5E8E4F0F8209
                                                    SHA1:15B8228E3AECEDC6F904A311838589B03B47BE05
                                                    SHA-256:9AC78116B02C1BCB4DCDE91170B10B8DD7BF532F0B800E81BD3C948F5CDA956C
                                                    SHA-512:ECB8EF343476916484F60A840D2F6D80E85C96C221B175A69747FD8186C927D6EDC82839752E2ED66B2960EDC2009DC2B205D184E547299162EB682D8D4855F5
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3654
                                                    Entropy (8bit):4.7911429859967205
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9GDgGpFQ3JFbtoMXe10J4Z6/E0xeskxgzMCUlN:nd5CB7fdpF+DLp+3vpoMtqgWgxs
                                                    MD5:565BF9F71B56FA741400574DACEB11DF
                                                    SHA1:1390677D50F5C32E920FE1C79FDA5C410C4FA922
                                                    SHA-256:A9DAEB562FCEE84DA8E896456C5E8FECDE4E49842EDDBDB87BB45F9E0038CB99
                                                    SHA-512:4FE1BC10B616BFDE5CFCB534F5CC4D7504EF593C4FD68F986130F4B3A5A33202EE1A29A553A215C055CE4FB05D533ADB0979CF6AB075F7C95C8907F857D355EC
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4065
                                                    Entropy (8bit):4.792295622948737
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFGLDLpt3vpoMCZLSickXx2MXi6:nd0BhpAvNJEL5xvN
                                                    MD5:85BD4CF930049F7FAD1A1157CF56E2B9
                                                    SHA1:6B96630AE511416426C53F3CC9B311AFB3B8B8D8
                                                    SHA-256:01CEC46769B7E16A3FFC84123CBBED009A5D565F3D455364C79ED1C0A0006D0F
                                                    SHA-512:67D74C13F5707F94D159E8F9A7352B5A0D21B6F258A98C6C18B8C777B26772CFEAC3D434AF09EA6F9136BF3B8671A37511DEEF5B18CE31ED81B4D7CE172223F2
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2519
                                                    Entropy (8bit):4.827600648510387
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OGDgGpfSiK+T8ocf67:nd5CB7fdpFQDLpf2vNC7
                                                    MD5:3C3E1ECD5F2D9B1C8B8ADF7941BFEE71
                                                    SHA1:EB1EF91F402F7FDE38B6DFE79BAE0022CEE5BAE7
                                                    SHA-256:302175E3FAF2093C879B338872688F9193579CA681B5EE4287807CC487A56DD6
                                                    SHA-512:D753CE1817DE8FDBBCC672FBEAF1740FF993B9573764C1903C893539B04858BE3CA66B8F734CE9A282A3B00692D0A52E32B28952F717C1D2BE8651EFC4D785F2
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4757
                                                    Entropy (8bit):4.795633305434376
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFJLDLpF3vqSs1Z/6Hzt6/1nLdBPuh6mj:nd0Bhpjv2Ss1V6Hzt6t5BPu/
                                                    MD5:517BC83A0059AB0501D89E95B479A244
                                                    SHA1:84BD154840AA09E0349550B466C9A662E53DF8C9
                                                    SHA-256:9119C70F03475B4D5AF2579302986B0694AB4FA6CEB4937B311E7B00A5611C4F
                                                    SHA-512:6E08F72783689DF48BC3A604DBC25FA69B03DFDA1B8C3AEB48AE8F6847B9CEB59BA2FA614A1C8C94B873C61561A392FB02317FE5D3D45682602BB14E6D4DD9BE
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):8309
                                                    Entropy (8bit):4.498428163270163
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy99io5JAS44kH1KWRmoAAJ/H0SAAd449lM688YAAdC:nd5CB7fdpFWJA/RmEZRMTmtnWwbQ9VI
                                                    MD5:F98E2EAE330AEE1FC832A15FC395AE4D
                                                    SHA1:BB91C3051A65832000DB517913F8A4B122C10F5C
                                                    SHA-256:E4ADE2E5C1600BEFE2AE31221035B5BEEE33ACBB9395DB6911C32B117C10A300
                                                    SHA-512:C263A0A3AE0AF2C665A079C4D77E931322FF4A6F062B3AA54D9D96540D53A1CB9D761E2901DA39F869528F3B4F2867DBCB65540D8BF42E876E643C64DE95F944
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4702
                                                    Entropy (8bit):4.724663373079018
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFGLDLpF3vpCQ2kXxYTxUbYbZ2FYW:nd0BhpAvJXxuNY
                                                    MD5:3A77FFFE5EEBC0606072577F2995448A
                                                    SHA1:1A2EF46A74648931CE7A4B2318D62C1AEC0E8E8F
                                                    SHA-256:6BA91BDE18BF2CAE35DE1815F2A1B8C8CF86765900C16B3599CD9650F7F6DF74
                                                    SHA-512:E1E2F0CFE991518AD4D1DFA05AA44018F1EFF79AD1589B44DF816F89104CB01E9634CF4374377FB942117472582D576C4198206CE4AC7694DAFD2EC916F75338
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3771
                                                    Entropy (8bit):4.840999626567917
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9GDsQ3JFbtySQkc2fEZHHkDPxEXiHoPxZ:nd5CB7fdpF+Df3vpy1kCFKPaiHoPb
                                                    MD5:9B79FE506F854CB5E7615A2C241E3755
                                                    SHA1:BCFB14A7B8AC3DED6B1554DF75A02D6B8A65A208
                                                    SHA-256:AE326BD04FD07A2417F5583F2B06BFB68EE166938D1C651F33198F6E4665CB91
                                                    SHA-512:736C108E7F9C524AA68DA52AB22403E068BC347FAC9AF02A77E2B1A1133D5956CBB13B782B9C0C195405685C6FFF0C597DC514D12DBC29D7BCE3B5609C1979ED
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2967
                                                    Entropy (8bit):4.755864058965555
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9GDsDQ3JFbtnRBNxAF/k+isH:nd5CB7fdpF+DD3vpnEJxia
                                                    MD5:435FCB5EAE11DAD6B2411D5BC0787216
                                                    SHA1:CEE1645E5D603A95363D99B72A250500BE9308D1
                                                    SHA-256:A66BA3C2CEB4766CA959A6C94971E4FB3FB2B33FC6157EC89E22F9DEC6B8B5CD
                                                    SHA-512:0836172997069DAC8287ED2D7A07E67DE8C659360D13A8AC6C50921D9F8338FB8BA1AFD4C1205DE09D6447F654D387009E4E1C34D9311E1A0F8A516BD34AD2A6
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3963
                                                    Entropy (8bit):4.829478647325663
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFJLDLpo3vj896/P3nLdBPtF9m2:nd0BhpjvY896/v5BPjV
                                                    MD5:46D343D4FC318CB86E1676A789915BA1
                                                    SHA1:5218BADEBC40B2E50449A545A7843988D859A016
                                                    SHA-256:BEF54AC22986A64AB8539D90568FC1A017FE0ECCCD1931F56A1910E429D0B922
                                                    SHA-512:E611F7959AAACAD4527E2EDC1EF3D0C49EB015FEE1C25C135657D04910C32380BE8080D6E2FCA34506F4AB742D05911E7FA711DD5BDE4CF79EEF06C60D3F3890
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2932
                                                    Entropy (8bit):4.78290740051343
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OGDgGpWnX+9o37M+fHMyzBADYfNsYNvb:nd5CB7fdpFQDLpWO9o37M+fHBzKMltj
                                                    MD5:D647A5CD428C2DD080AEE1D246CAACB3
                                                    SHA1:A5F9D762FC50421B78D55FFD60FDBAE57D75F69B
                                                    SHA-256:BE6421A3B9D158DE3A94B9F737DE8538432414BC3D2AB94977D31CE1FAE755EE
                                                    SHA-512:8DE0E39E5CF2721BADDB2A63AEE00A8BF07107E95FDA57F38E417B7EB3EBEB70193372285CDE17B6CF0760585BA49E755D50A5F8676833FF2B1BEFE9C1A48BA4
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):6225
                                                    Entropy (8bit):4.618752935327141
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpF+DLph63vURkq3KjKbnuzjBUg/HLvWLTFuzjBUg/7ATw4VfsT:nd0BhpsvUhfxD
                                                    MD5:1F3CF71216E54DFBD0A6A352907A95C6
                                                    SHA1:AADC4946FDDD3BE151AB78AB64BC69356A3110FA
                                                    SHA-256:563CA893E4477876ED5DB6DA9F981D0E6D60662378C7D4B77053B1226317C409
                                                    SHA-512:2EE5821C9FDB31B2230F2919C8BFC894B656E5CB32F01F26291E9BC1F15BF8473535F678220BE4F90FA87385A1F9BE63ED7A666A142FC0BC5D1DC520EEB449C5
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3315
                                                    Entropy (8bit):4.790674071189243
                                                    Encrypted:false
                                                    SSDEEP:48:M55H6E+iCsAaKj7fOWIkFy9LixvGmQqJFbtyz6f9JfDZFt:U5CB7fdpFOpqvpy2jZz
                                                    MD5:E46181340B2D9E90775F686AFFF9C2AE
                                                    SHA1:73BAC5091904762063E7D9AB1DFA1D49C3570A5E
                                                    SHA-256:4248D6703D05D41480FFAF12ABEFC63F020B204221684D73D64957ADDC3A8B4F
                                                    SHA-512:34CE77D44809A969247B76DB66F03EAA20FC9B94413B2E49FF9647B7E2841F32B1B271197E510B73FB45BC22F4EA70EDE14D6E8F5C4F24C93A800D8D58526442
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2018 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3885
                                                    Entropy (8bit):4.951612981046042
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpF+DsV7p82+ij+spJOP8u+spk0OPO:nd0Bhpsa7pQiispkP81spklPO
                                                    MD5:10E28FBB58B8A780C527A32A59114312
                                                    SHA1:EB9CC1B8847B3AE2882926429014B1B257E87C1E
                                                    SHA-256:09C499DE9CB6DF74464FD5A66C9A58AF16E34FFDE3E0C67AC12D0E0C81ACFAD6
                                                    SHA-512:F6571C71E912B1850CD6F2211030AF6D9BC96CD32A5AB6D5801EA8FF0ECA679AF72620060A5F22A6D44EE3116013FA20346A4003A00AC1357957E14A9A067611
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3887
                                                    Entropy (8bit):4.773238807520014
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFGLDLpQ3vpoMCZ8kXx2MXfUbK/Ec:nd0BhpAv2JExxvvAc
                                                    MD5:C8A4636D811A78B52E3A333EF90AA494
                                                    SHA1:B1A3AA6D7250ED974AC7B21DF7598F6919A6D5AA
                                                    SHA-256:B19EB0EC5894590163F09F7B66A236CB30EA2C63E3E79846EABC4029A3792F13
                                                    SHA-512:520272046579D975FB9E32DDC330DB698CDF099214D7B95F9B6ACFE03AABB9D05E39501464076AB08827E68248A32AEF4F2220F460E5F5A62AFE5C653875B8AA
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2830
                                                    Entropy (8bit):4.839139747866962
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9GDdQ3JFw0IJeSaVzdSw4:nd5CB7fdpF+D23v5I3aG
                                                    MD5:55A2CB6F3D43441A3AB4D20CCCD8BC27
                                                    SHA1:BE8DB5E36F2333E68976D0A655DB9C047131A7DA
                                                    SHA-256:DF48A6406527FD52342CBD00D50D4F749D023086A01814EA8FC6C550A2FC53E3
                                                    SHA-512:FA05783EDBB4174458FFE860EA3F93740B386CA1BA48309BFA551A410D7267949D0AB652FA78B5DF9B32889A31A67C4A87D6B5FF031DE0A80958E68B62E76F3B
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3612
                                                    Entropy (8bit):4.796786231360721
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OGDgGpg9Q3JFbtoMJA0J4ZWfsu8kE0xeskxgzMCs:nd5CB7fdpFQDLpr3vpoMFLfsu4gWgxs
                                                    MD5:EC5BF32BB60EDCDB2F1C1D07F05E1CDA
                                                    SHA1:D9CC82E6832EA93A2B87A136FF42463CDB27C14A
                                                    SHA-256:E65C894AE653242836BED8789B72E8A208A8D743F840A73E9B6BDDEDEDD11A31
                                                    SHA-512:F0D92BDCFD28CB0FA467F7FE8AF53F96022DF55B5AE81F12666742D3E46B421A443A953D57C3E7CE40E43AE6928E3076CDA14CE86B3465BA01B85217930F2538
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4104
                                                    Entropy (8bit):4.794699611379986
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFGLDLpu3vpoMxZ+SickXx2MXi6:nd0BhpAv8Jv+5xvN
                                                    MD5:8760D7638C811958C997AC97746FDC96
                                                    SHA1:CB5D0324B0E2CF7C90C745F667102EB2B14722DE
                                                    SHA-256:C897DD480D12643F24A357B1969B78B91DA6B7E8A950DF2092856010AB8A8E07
                                                    SHA-512:56CF699B98F0EA9C97740CD5FC7770FEFBE90BA9A801FED5CEA855FED8C3EA53207FF45028FF2220D8EA1553FBF797ADFAD01AAC46D422EB9E82781DC7B880F6
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3330
                                                    Entropy (8bit):4.752119040809457
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OGDgGp5Qq7rgI67BA/X//bXv6VZy/Gly6Ra:nd5CB7fdpFQDLp5/7ULEXbCVo/mFa
                                                    MD5:2EC9174D585AA4F418A831EDB97C0B9C
                                                    SHA1:E2C3ECBE6E7BC4FFA8DD5CEF3767BA3438F76C3E
                                                    SHA-256:F01406646BB316E79AFCF276DDC59BC70BA46DE58562B1173A6ADF33728DC7F4
                                                    SHA-512:00D834A26C0506C183E37A5ED077067684B63BFCE40D3662596C6E31F19B6CF3E3C743B575C3D6A764C1D8B925C9B65055838618842F6BF345CE48411EBE4FFB
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3437
                                                    Entropy (8bit):4.785298813653595
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9GDgGpmQ3JFw0cwlc8L8Nd2JB54xocy5y6Rsf:nd5CB7fdpF+DLpp3v5cNz2r5ws5Fsf
                                                    MD5:E0C9C5E2BFC89B835932400D5F5FC80F
                                                    SHA1:063643A8DEF7A64BFACB373F2B1E6EA9291F3EEF
                                                    SHA-256:DF91849DA352EB0A6FA50AD30188014BC8EE8927676EF2108B7DDF55A3BA97B8
                                                    SHA-512:93E21896F9F31F2E02D7B36E7C52AF63862C6E62422591250219F3A680527B42FEF4D107A89DC33D33E919F40188982AFC88346864E054FAC5331C2CFD3CABDD
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3208
                                                    Entropy (8bit):4.826535254116028
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgGDgGp5Q3JFbt+kXxOqgb:nd5CB7fdpFGLDLpS3vp+kXxOqw
                                                    MD5:22F5EF66ACA2F5F123545E57DA4B9995
                                                    SHA1:E27C692FDC8EC203F3A331481166237A6E15BF27
                                                    SHA-256:6D87E0C63D2A080B7C6728A3E3DFBF8F792032034EA770710202592F1BD532B1
                                                    SHA-512:3627C4ADCE5B6EF2EE4E62280C4394026273DC745301BE6AD463CEB4FB13B0B71EA76BFE4C1121FCF81BCA1044CEBC5C302983541E1227F456823BD6B1274963
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3727
                                                    Entropy (8bit):4.830699947184764
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgGDgGp4Q3JgZLzAjPERh1FjygPi/PCdWFob:nd5CB7fdpFGLDLpr3ONmPMndWa
                                                    MD5:07D5EB3B82FE60F2E43ACD5D2C11C147
                                                    SHA1:73CFA3E99F861EBFC64751BF43535661BBB898FE
                                                    SHA-256:CD31510A2D8460FC131E5A94D753D0B923F50626E575131DEC9C94CB7EE540C6
                                                    SHA-512:2B169294E7F9F281E51BA6254AD43398E0DF5E1586C4B520B432AD3045A0041D8D8316E3C3AC4432D094438C44A95380BA81E56D33460CA64A9E9CE5DCEAE027
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3820
                                                    Entropy (8bit):4.8410761106012945
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgGDgGpzQ3Tw/nP0p9PERh1SijygPi/PCk1pM:nd5CB7fdpFGLDLp83TcszP0nknI/
                                                    MD5:81914053CF4C8B51173BCFDAB127BE2E
                                                    SHA1:1222B9204AC958072ECAA1E28F7D80C987B71685
                                                    SHA-256:09A990D8A73091DA451FE46D518175A4D794B9E955FF45920D0E9D8F4063458E
                                                    SHA-512:35F16E4E063FBBA6A54844E387DBA874B65AB9BBB8BC9E5F281F43F397F85D915090B3A186C68916B172CE0D4FD040EFD65F4E70A9E9500843822901E17ED55E
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2656
                                                    Entropy (8bit):4.830282251562865
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9GDgGpVQhJFw0myjy5y6Rsf:nd5CB7fdpF+DLpOhv5H25Fsf
                                                    MD5:CECCF52B0AEC6FBB914633703AF7A1FA
                                                    SHA1:299363C51B8BB0898E3300A8A5451F3CA85BDA04
                                                    SHA-256:69EF1C4BF0329EB9FE2E6DDEC7E584A3E38430250CA3D9EDCC38181D6E44E636
                                                    SHA-512:8C1968A391708A7F9726D058C831C930D83C613BD33764BE1B6F759ACAB536090F42D2996F1CEC063210A24C794D8F3DEE7D1A2AB8B4D9700EDD9D4F0CD4B49D
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3602
                                                    Entropy (8bit):4.812649874502562
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgGDgGpAQ3JFbtBkXxSWrj7cMb:nd5CB7fdpFGLDLpT3vpBkXxSWTcc
                                                    MD5:42B68708A8B18C126569C42844D844CA
                                                    SHA1:E1DB4E42E6609532AC4731A8CB66866229C85FE2
                                                    SHA-256:8D3AFD8D199595659F42212168ABCF55B7D1AC212A6616573BC083F73CCA1B21
                                                    SHA-512:F48C3575E793E631915BC719FEFFDAD673517AFDD9EBDE93168DF4E4B7306A5C3ECD5669572CAA1A091A044503EE0E3537314AFB65C41FC613EA023EC7E03344
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2489
                                                    Entropy (8bit):4.847822761591629
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9GDDDQ3JFbtM0QHb:nd5CB7fdpF+Dw3vpvQ7
                                                    MD5:AF500ECFBBD1A4792B16FA5C373D9FA4
                                                    SHA1:7FB693155D9DE76B81BC5505BA33A91A7F5F0A36
                                                    SHA-256:595E7895E532F29F9CA2DA32501522B8C8360664238DC82C7793C73AEBCC3D1F
                                                    SHA-512:10E9227C90ED7CD4D52C5D5CA196F1D28F59736A874988FFB46A7BBB18640D6176C33E19E86B00AA8651E877484450E64733EDF6830940F347871FBB57312292
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3206
                                                    Entropy (8bit):4.885163038662627
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9GDlQ3o/JFw0jYWspetiF8ebpt:nd5CB7fdpF+De32v5jY/ppF8ebb
                                                    MD5:CB7A270AC99A4F764986C3731EC6A906
                                                    SHA1:AA9245F722DB3C96084E42F4AB3515D79E0ECC93
                                                    SHA-256:6085F068214BFB06C453F1B671576AC585072A02638D871E212B7FFCBFCEB3E2
                                                    SHA-512:14AC48489D020D7DC406499A4192372D2D344537A9252860DC914D70CE3D85E7476BD4FD6220E6CD335F9AE644B05018F3A6DAEC7E13E1DA896D1BDEC7321F97
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3317
                                                    Entropy (8bit):4.826698729490084
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhg9GDtQ3JFI4CtfXKeGlZusHPwLA:nd5CB7fdpF01DG3vIvyrwE
                                                    MD5:2D0F59B773A845F7F6105A2E6A6CA9AA
                                                    SHA1:686126D568A0B636F4652EB820B6F94433575BCB
                                                    SHA-256:1EF694FF3D76110423D945F9ED5948BA86587DBD130BBB953C1B88F3F7C08729
                                                    SHA-512:06648257FAD90471945F4D56A47C1A0D93E65E1DF957A6A817B91D569CBE4A9EFA7826CECE30202EEF4E9BAE91AC2A8A55BDCA6EBBC2179A8C17C248862D5AED
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2965
                                                    Entropy (8bit):4.806250208072157
                                                    Encrypted:false
                                                    SSDEEP:48:M25H6E+iCsAaKj7fOWIkFy9lv8GXG3Q3rNqYJfykFbbUWlNzx:L5CB7fdpFgWg3BqY8QbdV
                                                    MD5:67CC5584067185FD2979461ED17C75E3
                                                    SHA1:0824D45DAC32996C1F4ABC9294D5E77A8BEDBFC6
                                                    SHA-256:B58DEADECF19234D92FCC035C0B773271B4CFDCCF24CD06E300F7C81903CA433
                                                    SHA-512:C96E7782C9033D28279F5572AEB4910420A52CB72D6DC3D017C240FF50205B6D94D1C8FEFE9065E2F80644E9E38E1B37B5F7D76C0D1951E58D341FC16556B5C4
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2020 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):19745
                                                    Entropy (8bit):4.398954459962296
                                                    Encrypted:false
                                                    SSDEEP:384:0OEsWJxl7IC1CoZT5zkTmOG8pHBhk99bry4:0OEsWJxl7ICMoZT5zkTmOG8pHBhArj
                                                    MD5:9DF4F4EC635616DEBA44BECF1D4B1289
                                                    SHA1:550EAD9AF422A5CCABB4EBACDD53A23F3A4FFC39
                                                    SHA-256:65CEA887FC78F250BAC61E4E4B6BC9F21C9443F74CA16C6461B808574C5BFD98
                                                    SHA-512:92107583FC0A94EC5F6665100036099293B02995BA32384DE61BE1172B1E51F75D7644DD4B262627A7B00B58B9D0D19F6067292BE259285F56D77F0EB1A4AE40
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2....// This file describes the plugin-supplied types contained in the library...// It is used for QML tooling purposes only...//..// This file was auto-generated by:..// 'qmlplugindump -nonrelocatable -dependencies dependencies.json QtQuick.Controls.Material 2.15'....Module {.. dependencies: ["QtQuick.Controls 2.0"].. Component { name: "QQuickAttachedObject"; prototype: "QObject" }.. Component {.. name: "QQuickItem".. defaultProperty: "data".. prototype: "QObject".. Enum {.. name: "Flags".. values: {.. "ItemClipsChildrenToShape": 1,.. "ItemAcceptsInputMethod": 2,.. "ItemIsFocusScope": 4,.. "ItemHasContents": 8,.. "ItemAcceptsDrops": 16.. }.. }.. Enum {.. name: "TransformOrigin".. values: {.. "TopLeft": 0,.. "Top": 1,.. "TopRight": 2,..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):155
                                                    Entropy (8bit):4.5598280105456475
                                                    Encrypted:false
                                                    SSDEEP:3:3BV9NKfNDyVMURCNajJW4whvyWmopCxKD4yMg2cakyxRS9NKSvn:xVfONDGMUj1tw58oI04oG5Cfpvn
                                                    MD5:087236C6EB9A82D9BB57278A08D5D039
                                                    SHA1:B31AC662CE411E2DE7F87973B1A213E3AC620D0C
                                                    SHA-256:BD78A9455635EAC335F2FD294323939B70B5906DC3C26C83441920413157E533
                                                    SHA-512:705FE9B9C21E525E83E66C2594EABF01D42EFE66D7F44CF61A0C8539D7FDE08D75DF5C83E056F49100C901E2073BB9DCAC0457214D5DF32C7FED815F1C0ED9DE
                                                    Malicious:false
                                                    Preview:module QtQuick.Controls.Material..plugin qtquickcontrols2materialstyleplugin..classname QtQuickControls2MaterialStylePlugin..depends QtQuick.Controls 2.5..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):287856
                                                    Entropy (8bit):6.1630711970489935
                                                    Encrypted:false
                                                    SSDEEP:6144:OXCGt/p6mprwppphpVphp/pnp/pNp6pQpQpxpVpApB3p/p4pWpcpgphYpopipmpK:K3ZpxprwppphpVphp/pnp/pNp6pQpQpH
                                                    MD5:0668903B9699C80BA4D79CF90A421DEC
                                                    SHA1:2D898880A42A0F7CF39FFF54053521BB125FC9AE
                                                    SHA-256:025F92A4333341B03FD8BEAE0AC20F77DC7A7BC13145DC5007ED523B0F9690D6
                                                    SHA-512:4D32B04C4255675457D54B297F2A76C850909FD5EA9DE306D413B5A968600090A4A0AF9D8055D7CC418A1F8E362704ACDEAA8BC81390B31DB473495C41A686C1
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......y..*=..y=..y=..y4..y;..y...x?..yv..x?..y...x)..y...x5..y...x>..y)..x0..y=..y...y)..x1..y)..x<..y)..y<..y)..x<..yRich=..y................PE..d.....e.........." ...$.............................................................5....`A........................................p...................x....`..(....D..p ..............p.......................(.......@...............(............................text............................... ..`.rdata...t.......t..................@..@.data...0$...0......................@....pdata..(....`......................@..@.qtmetad.....p.......8..............@..P.rsrc...x............:..............@..@.reloc...............>..............@..B................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3132
                                                    Entropy (8bit):4.814273270880492
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhg915Q3JFw0cw/NtPCccswXO:nd5CB7fdpF0US3v5l/vCccW
                                                    MD5:C17D3D7BFB6888203D88C2C8E5391B7B
                                                    SHA1:9A3F9E3E37F513AE66BA4B6C012B2B7FA3906890
                                                    SHA-256:071F5C638437BBCB3C6992FFA69F4A459F148D060C342F1D0F5E6C122201E743
                                                    SHA-512:707414AA1ECA3B3B8C4CBAF1E39632FE495E60BC9E8D602AEE89A7289F71EB81466E7E1411A929AB50BB924636820109EF2801EB92D2A790CBE8C1A4A7DCF988
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2515
                                                    Entropy (8bit):4.821005781824648
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhuQ3JFw07mX5:nd5CB7fdpFGx3v57q
                                                    MD5:D71025F7D7E9ED4129595A7A0168BC8D
                                                    SHA1:A2EF2D3D093BE18BE7FBC220EE742477C1326222
                                                    SHA-256:E84583C39B610DBC2E89B9D284E6850D4DC80FD7C2151BA3A55D4BEA9926262A
                                                    SHA-512:09BEE1B070EC4B7CF3235F65FD4294816778D3BD263C6CD3EC42A6C31A33ECC5A2B4CAB6A7D03DB276AA6D7110DC2D304B2460205B064C1399E4442E948469D2
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2994
                                                    Entropy (8bit):4.804111096356225
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhBQ3JFbtoMokXxtwwX68:nd5CB7fdpFGa3vpoMokXxtz
                                                    MD5:8ECD638D4ED2FF8B1803D1D5196C1556
                                                    SHA1:5595E12AD1A6FCED601F2A2F4D0FF911F8F0FE58
                                                    SHA-256:25267737CF4A0430631BC80B509647B605B903D9C2BB39A7D0FA05DF3939F5B2
                                                    SHA-512:D81E449DDAD983AB9B89B4C5F8B28A7713D7FA511C0FE23A917E87E4F62992B49D3E24B0C14C50B3E392E6F974ED92B0DD08316752D4DF18EBB86E6982D4113E
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4379
                                                    Entropy (8bit):4.80556368692418
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgFQ3JFbtoM9Zxe/xecakXxntM44QY4jX8swX/:nd5CB7fdpF0X3vpoMtQskXxKLyM3
                                                    MD5:B05869D66C6D02AEA7FEB9CA883D8946
                                                    SHA1:8ECA11E561E4C52DA3D3E6C8EC32A8D640382E30
                                                    SHA-256:2AD146A44A773E8105BBA1A9A1A2552D4F64C0990C7EC48E3A98D59044398BC4
                                                    SHA-512:C55D6326A1E0C68D36DA8272C3BFDB5B1060088617E78BD76B4257C71DF02EE3C4C927268E5FBBD46740FC68BE41C3A95B50E1B4B77048581C2D679470636D12
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2442
                                                    Entropy (8bit):4.839225593423535
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhg5DQ3JFbtrjyA:nd5CB7fdpF0V3vpP/
                                                    MD5:B5F15E86F80B2304F2AE672FADB3EE96
                                                    SHA1:76A5C6EF45C9A05B5EBA7A7907588D69462181B8
                                                    SHA-256:58A848C945814A0E233E775DC308F719FAB3790026687790D66B7974408C5F6C
                                                    SHA-512:9D4B8B45B03D2B41AA44A256BB2A02BC993988E8FF4C52128895C27EACAB1E16A0FACB519132578EEA67395ECA27F2473D8C4A46BF1AD4814C56C91D04E27B50
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2604
                                                    Entropy (8bit):4.774696392771712
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgOQ3JFm0QuLYupz:nd5CB7fdpF083vn3L/pz
                                                    MD5:761015C43D3CB38D4A0E8A0694CA39F3
                                                    SHA1:245BB0B79F994960BBDDB609CD0D143B905EEEB9
                                                    SHA-256:4D4AC1104FD58E70DF514B2AB5D46B037BA489CB96C64505A3D672ADA6CC9884
                                                    SHA-512:E3B37BF9AFAEBDF05B9F4A47810FE0440560E521CFB91FF5B31B4723704339AC5533C04A7AE845760F4968AB53CFD0CD8E0C4597D41A1C31254812ED07C6F259
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2763
                                                    Entropy (8bit):4.829470306877085
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhg3DQ3JFbth60+FZZ:nd5CB7fdpF073vph60+Fz
                                                    MD5:29A933813837994A869AE9839B1C3D26
                                                    SHA1:C29B1149A39BCFD5194510A6679B01826C8C82CA
                                                    SHA-256:43433AF6C1F53A570C8CFCFDCCDFA41D8806CBFC9F1BB962CA12EA46CF4C0A6D
                                                    SHA-512:1266AEBD949CA874EF9CD01E834F005F80B70451D3F83AB0812CD7E5D3C2DC993E9620D4762983D8A29145112C737AD9E98BB2E6D59C2D1DA6A9AE4B74466472
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2331
                                                    Entropy (8bit):4.838692827239353
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhg/Q3JFw0F:nd5CB7fdpF0F3v5F
                                                    MD5:D55630888288DE076EA18EE14D8CFF45
                                                    SHA1:D598CDD2A146D976F577CE49885CE0FDB60462D2
                                                    SHA-256:B01825029C2139A4ECF9BC1CE3C1379D19F4A3D7F8635BDBC0A9DBC28B13C2DA
                                                    SHA-512:6C5C2D322F18385BB9706AED40921DD258E49E4B9B0DCED4C44D1097206118291F06FF4E4BAAACCB15101EE9ABF9BC90D70532856EEC9C404802350D05986A3B
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2592
                                                    Entropy (8bit):4.855929209866687
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhg1Q3JFw0S:nd5CB7fdpF093v5S
                                                    MD5:D03D6CF824C899D2FF247CD0A474D986
                                                    SHA1:DB54B862972C8D722C1DB47B3251975066B230AF
                                                    SHA-256:75C32398761D16E0E875E26E9584EF67CFCD1A1F4F2938F3C86A57E17334CF2C
                                                    SHA-512:065EB0674EB7BF0AA3C7CCC90E7FEDE654674B17E4074A9656C3B36CC37F6AB21C28CD30540360BDD7E497055F4D1C6A35E4874AD27F6B0DCD29C29D82DA0EF9
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2735
                                                    Entropy (8bit):4.8163289625337455
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhiQ3JFbt8zexozakWsfKOZ:nd5CB7fdpFGl3vpOeeza3OZ
                                                    MD5:0BFA56149AFF7B45DED9F77C9CC85F6E
                                                    SHA1:66CF64F0A9994224CF85C3080B59A93B28B2E6CC
                                                    SHA-256:70000725A412BF884244F5E7A170A23BC2F4B96BE636C42F830067FA3F4FF728
                                                    SHA-512:9FD5537CEE85B45106C8604BDE0528868B7357A11B02A8EFBCD63FEA8E8206620F3AF6D3D3CAEB33B6F80D4AD49F13FB97FFF3B1AAC76404FE2D891C6FA097D1
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3713
                                                    Entropy (8bit):4.773769607411336
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgUQ3JFbtoMbW0J4qkofqG0xeskxJy:nd5CB7fdpF0I3vpoMb5TsGgWo
                                                    MD5:8E2E42B0CB63F3B7F68F097CB97B0E71
                                                    SHA1:454F9AEE8A0396FDA827B445318FD320C11AB1C3
                                                    SHA-256:114FF5020E93592ED84368576EEC23AB3F999129D8C2BBB7FCAFAB3603FC28D9
                                                    SHA-512:498F75A42BED01A02503870A3DAA245E2886DDE219D5728D818C3D7A9BCE28072BC74E4FBB493EE42B83FFA05131C958D4525A6E28EA914AB815C2DA25355932
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4169
                                                    Entropy (8bit):4.758093410324449
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhg7Q3JFbtoMhxeszxqkXx2M7XY4qkofqvPwX86:nd5CB7fdpF0v3vpoMjLqkXx2M7ITsvyZ
                                                    MD5:2B788400464D9EA3E1B0A465FCC23958
                                                    SHA1:1D7368BA133BE85DA3D64E37F6986AD55864451C
                                                    SHA-256:B3DBBFC1472B5CA9F5C836AC14BC847E878155AFD875F81CB600A9EC769F148C
                                                    SHA-512:A66E39223AA6568C3BBE597A4FF93FF042EEA117E7B8A0AA6A0319F109D4E3D8D1B869311FBE0C78062E6F8BAAA98F5FA0C3EB548568391234496813D2410562
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5005
                                                    Entropy (8bit):4.758902637937423
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpF033vqSEJmzpFmzhbngPdgcH8:nd0Bhp3SEWM0gV
                                                    MD5:7E419F94FB2F5B1B4C956D66FE04F313
                                                    SHA1:A6A337439BDD2233D727BC8C55FD85966259A01C
                                                    SHA-256:81A2A87DF4D44A5023170189DFCE8076FE8C420B8D6912FEC23249D56A8D6D0E
                                                    SHA-512:595B430F0CB3CD8256A9156C859E48CE38FC85EA73EE60E2F1F32A00B53F965B14520637ACC723C50F06775142977641782DA4B3A27AF430106FCE6CED85F7A4
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3633
                                                    Entropy (8bit):4.778438090721813
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgHQ3JFbtb3kXxEzwwXBpcWr:nd5CB7fdpF0L3vpbkXxIdWW
                                                    MD5:42A33AD9B25996DA051E4A496628F25C
                                                    SHA1:7F49BD32C739ED2378C246104C1A71434C5A2842
                                                    SHA-256:3F06E0F1CC2222D5AC39949DD6AA50C5BCB88BD9BFECB0330CA6ED62A46C53F4
                                                    SHA-512:9BFE3C9AB1D671974078811121D1DC37F69810AFCB58BF95BFBCD19CE4CD257B262C3A3BCECAC69BB9636F4A0B34A58D85FCB0D3FF4E251F85517A24884C9724
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3211
                                                    Entropy (8bit):4.8343887210632195
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhg1Q3JFbtfSQkBLIkF/3ys5:nd5CB7fdpF0d3vpf1kBXJ3yG
                                                    MD5:B851CCBD1786C616CD8C1B069DA5C640
                                                    SHA1:860B1A5338B05FA821EA4F168AC76D894B9C2130
                                                    SHA-256:ABE6BBAF5F31E5DEDA3086423EC8935BAE426F945A5532701982B3E1206857FA
                                                    SHA-512:45CAD29A8569C5F48679D5A447942C7565988E3C1515522256E9511B5265702DC2BA5BC441D848A8D25ED36A80C5BCB56CA59C0C9CD14BE195A5094BF5846698
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2981
                                                    Entropy (8bit):4.75619578796289
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgVDQ3JFbtnLSNxAF/k+isH:nd5CB7fdpF0p3vpnzJxia
                                                    MD5:9FA5611A631E0FABC7C35433CC09E93B
                                                    SHA1:689C9ED60D1F34DBB63C3B6549E471FF081D9601
                                                    SHA-256:4E33A27C70ED092B8FF5DB889A6F2ADFDFC780525AC462E249CE428804C9F2E0
                                                    SHA-512:3646644FE2A3FE69448986BA885899AFEC58772D5D54395DB0FA0B0E5E62F83B8C6B882D4FFF6B082E00E6B160EC1866DAEBFA119E11A62EF699EC77FA1E2D02
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2725
                                                    Entropy (8bit):4.818398008330529
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgdQ3JFw0i54l1K+h:nd5CB7fdpF0v3v5iCl8e
                                                    MD5:4CD5AF2ABBA5A14956D162EEF759C371
                                                    SHA1:689777D7AC3CA08105F3BE4CEA92C655F236C9B9
                                                    SHA-256:E133806D109716F7B355F1D643A18FEE659A64ACC1D8E27089A568E82EB4D3B4
                                                    SHA-512:9FA50C54708C0C29638D69E96FC7372A1B687E6E678C6169A11AFEAD7EA561C69AA116AE0D9F05A40B7D5AE4BE4459F136C09BF3CAFEC67703F7AEA562A36FEF
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3923
                                                    Entropy (8bit):4.794707446109668
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgQQ3JFEIr86EAwNm8JOb6EAM/y24YOdh7q:nd5CB7fdpF0i3vj8Bm1DngPdh7q
                                                    MD5:B469B132AE469ACCA3F396C4BC1886A5
                                                    SHA1:98A9B96BC9BD4CFDAA84871813517524099C3474
                                                    SHA-256:2B435D4E44817A589654C2A41D7758795DD1E148FDDFD9E2E192D1279D354FD8
                                                    SHA-512:625762A0904D48BA78A662D94A03689DA7CC9287DB729FD036AA7A4D184E68B5AD78FBA2BD86DBA5102A9A146A94D8B3B7A5736756767AAD232E4997F96D6ED4
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5365
                                                    Entropy (8bit):4.629971532594098
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpF0X63vARkq3NjK7+b5SnATMSWAlQ:nd0BhpLCM
                                                    MD5:70C54E305C8ED6278387D1605EC35B53
                                                    SHA1:C274B2B47C217AAAD29558E80AA91405F28D1599
                                                    SHA-256:7A8A219B1E85FDBDE2A49C168706CB29C41530720CB4E9D082492104A49F1A0F
                                                    SHA-512:0ABDA48253D43B0A9AC7FBCBE34D3D1459D6BED94A9C16DD0EABEC464536743E7CC70931F81DB3AF6EC50E2F2C0E8A5F343EE8F0869381E046AAE511A12C2C46
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2605
                                                    Entropy (8bit):4.853125997394258
                                                    Encrypted:false
                                                    SSDEEP:48:M55H6E+iCsAaKj7fOWIkFy9LixgQqJFbtyz6V2f:U5CB7fdpFzqvpy2g
                                                    MD5:A0671680A70476FE755E8B4E69A9084E
                                                    SHA1:D1CFB08DE1F3F4295C6A16C1532AAB70379032D3
                                                    SHA-256:FA338E11C1D5CA56D42BCB1952C307EFAED89FF9E62870A768C5CA40F3BC4875
                                                    SHA-512:349022AEB030E6275ED6162B29B3D80105F94554101C058C59F112BAD9205112D1F4442B587837AE8846296EE34D553F9029CCD1401EC019E7E7429EE96E835D
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2018 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2879
                                                    Entropy (8bit):4.918905834543331
                                                    Encrypted:false
                                                    SSDEEP:24:MCdbFTT3QXf8WYwid0szM6RqeRGNfj9TNZlOWIQNydOtQ+y9OMmRQq8vSKSHzSQx:MCd5H6E+iCsAaKj7fOWIkFy9OMeQpAF
                                                    MD5:8A40D2C1EC0D67DF4B7380EE96157B2F
                                                    SHA1:2550BE9770EF8996F37AE469769321606E907AAF
                                                    SHA-256:CFAF9A1325B36060F9E7489E80A5462F11F9FA99E5F78E4DD6D6DD0B10222F09
                                                    SHA-512:44893E3226FEE75D6DAC97CA34C6526998B908DE24E9C6423BF1B5E42883B06DE1FA2689564EFEA07DE409D16FDE63A2FEE519006796B475BC49098DFDE415A6
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3262
                                                    Entropy (8bit):4.81695114339966
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgCQ3JFbtoMIkXx2M0PwXCrk:nd5CB7fdpF0C3vpoMIkXx2M0XI
                                                    MD5:869738000F1E92572EAA2CD8A9BC2AAF
                                                    SHA1:F531473E603BCB8DEB57DDC425CE2C03EFA47A7D
                                                    SHA-256:D46804EE223180A03C18B4525D9BBEA14E8C4A559908CFFB6924BFD2340BB83F
                                                    SHA-512:38DA3A172D40E99F4BAAA2876474FDF937A0400A4F1A3894E3F65C026D55D1BB2D211A36201F2D5092E490627F5E50BDFDB7D2D2854FCADEA99C58FF2C7F04AF
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2821
                                                    Entropy (8bit):4.8381484195048525
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OM8Q3JFw0IJeSaVzdSw4:nd5CB7fdpFu3v5I3aG
                                                    MD5:CEBDA1281CE7EC8EA1D962680730C66C
                                                    SHA1:965F242782FAE447EA9BA757E066132D1AC2B545
                                                    SHA-256:790F1CF3FA94FD7C7ED4741121EB8DAEF603FCDF07A9C43D1B9B3B147CBAAF6A
                                                    SHA-512:C0D666A10E5868B085CCA0AC5B7A0E0C6D93EC114EB5FDBE382FAB1284B8C50756A7373219F0A3150A3BBD201E595E6F17883A9D8983AA18C88E050E401E069A
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3947
                                                    Entropy (8bit):4.757657645064246
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhiQ3JFbtoMSqq0J4FsAlQo/iRJzT0xeskxJy:nd5CB7fdpFGl3vpoMSI81i/TgWo
                                                    MD5:00631CFEE04C7AD041504DB617D36014
                                                    SHA1:46921019213C2B2AC33965FB6763EFCDBE19E2C7
                                                    SHA-256:D2696E10B1054C586A6264C20A4EA70920D947C2C03A1C0FB8EE1261978F701D
                                                    SHA-512:26F25C312555483AE6F54462E3ED9DE5BBF1226FA9B231EDF5FA2956E3611671E3B5000844FF2F7F8032A8E1C83B3C4E7DBEC7DA22B6368445FB524BA33F17AA
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4489
                                                    Entropy (8bit):4.751534437214193
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFGu3vpoMcC81i/sLqkXx2M0yZ:nd0Bhp3Jx81lxv1
                                                    MD5:8C5871CE80D0FF65E57118453E21226A
                                                    SHA1:15B39A26A689B373C5AF907B34C691BDFB0A67AF
                                                    SHA-256:558C928F3C74474C829611AA29D54EED9C598E0213943FEE88A54692A81A7BDD
                                                    SHA-512:E05DA99F8436E1CDB892E6AA5BB4183C53348D312E7BAC827FC07141C31B4143D24A6715D3D229B4346006A4F3E9EC8A00C973BE1AC3D54F6097705F173C7F85
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2773
                                                    Entropy (8bit):4.839153998426681
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O1Q3JFw0cwlcZiSH59:nd5CB7fdpFA3v5cNIy
                                                    MD5:A74E49BB19F90DF902A3EABD598A0A53
                                                    SHA1:C43A49685D43F3425FFE4BB409C9BB0DBE640654
                                                    SHA-256:54FA946D021F78B2E35B38F3769B036F5943259F86C28B4362E184FAFCB9AD01
                                                    SHA-512:8D47E4A041CAF6D758049158F1874E98D1C5923E9DC5C8150219B47A4B3F3548F5CFCF88CB3A03CDBE9D0237A9DE9C2788F41935461BF8F5EFDF3BA8DB864626
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2987
                                                    Entropy (8bit):4.798051662963486
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhggQ3JFbtZckXxNKXCXi:nd5CB7fdpF0Y3vp2kXxLy
                                                    MD5:9C1CA9A17DA0491B998E87B62643E567
                                                    SHA1:75D4FEB4CAEF7F61657B6127B13C18B6B88F3E4C
                                                    SHA-256:777DC9EF7B8278285AF9844E0F465347D321D0F5B9425448E1891F78257A0085
                                                    SHA-512:D3FC772CB97A5A9B91C5D4878913150EFBB6E3AA96CFD5D2E056F90D35A862465F4965F2F6C692C9267D772E784E8451669D6AB52C952E49AC4002DB0459CC81
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3313
                                                    Entropy (8bit):4.81341500049657
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgPQ3JgZLzA9Uujygyi/5Ct:nd5CB7fdpF0p3ONsUu+t
                                                    MD5:7522606A7EA70E450F859848C41FC134
                                                    SHA1:130B6277CD65CBDDBEA007D22A9B40A7F3EAC14C
                                                    SHA-256:F912C4DF59C22B53F85F0BF0C5C7BE178DFC66CE2C328C86598FD6C931ADC1A8
                                                    SHA-512:7F205F9BE5189BE424E210AD461675C2A44C58A0DA1C1763A7FC4B141CBC10448172C4B59B3FF2A756CD8F9E860C28F010499256ADE1C392C3899AB198A4FBA6
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3571
                                                    Entropy (8bit):4.831582188655847
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhguQ3Tw/nP0p9Nj+jygyi/5CyswXZA:nd5CB7fdpF0G3TcszNi+yS
                                                    MD5:1DA0C6339D4E766DF8F478C718CC19FF
                                                    SHA1:C7A79E0772D9D97E86E614284638A89752EBF0B2
                                                    SHA-256:8F792EBEA56C72FB291DFCA0DB0C5D93A1782924781008E355504F5F14AB59DB
                                                    SHA-512:5A39FCD79913AB20D71D91FE400FFB535509E22993D3C6EB2B0B6BE32589FD61F4059FF16D35327377BB2E885FA4FCE7F3AD965A7CD13F684ADA7D1D25B579B2
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2343
                                                    Entropy (8bit):4.839387606601536
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgwQ3JFw0YX5:nd5CB7fdpF0s3v5g
                                                    MD5:FB466EBB67A6A80E86D318EAEF23E359
                                                    SHA1:C83442D520026EC261BD31479FA80F6FF3EBED01
                                                    SHA-256:44EF02AD2FB1680D9C8F07E860F31F6559D317688211D6866A48A7D9F61779FC
                                                    SHA-512:C46F838DAE07269BA496F38C1B1119C5A9F9BCEA9DCF9B975519AEC350209F827623C74A2412FCB66188A11BF9A5F57A5512720BC8AA41790419848E12234DAF
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2998
                                                    Entropy (8bit):4.8220367527818055
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgjQ3JFbtQkXx+ww3F2:nd5CB7fdpF0h3vpQkXx+L8
                                                    MD5:EF218CB8A8AD482B657573BD7BF1D11E
                                                    SHA1:0880EB6098F5E2FF13D5B4130CDD53CF10FBD0FC
                                                    SHA-256:CFFA07A4B74ED396E974854782CA8AF88EA8938A99D6A4CF00808133FD609F0F
                                                    SHA-512:2231A1AA47A497126AE67B89F76270C5EA2BAEFD4954BB90BB9D33B1DE6C4383678BB4CA9FA16969A057925B8F7F4204455920859CA2E814B75F32805E33C606
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2492
                                                    Entropy (8bit):4.8422185369621795
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgmDQ3JFbtUiBuXA:nd5CB7fdpF0G3vpPIQ
                                                    MD5:632F3D71CA4A76906A199FC0C6CA735E
                                                    SHA1:AE225C531BA08EC3C7809093E3FCE347822916F9
                                                    SHA-256:7CB420E0DDE01C0B43B97FB0068CFDC4B48802201583098F5ABF129D369FDDAE
                                                    SHA-512:5C55398B8B5855D056E4F9AFCA4F687B2D8C4295F67E98AA2B029B99C94BA8A1D0BAD2E0768A7A3918E517CBA3589F89CDD48ECD10C38A3535E606CB761AF8F8
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2763
                                                    Entropy (8bit):4.861346233395539
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgwQ3ohgJFw0JWO:nd5CB7fdpF0s3Fv5JB
                                                    MD5:A43B5FCFA6BDE733516CD4250DE39BA6
                                                    SHA1:40AB2E0C3EC63FE53EDF25100EE25AED14DC466C
                                                    SHA-256:9ECD0A2492D7E7CC41300688497A7F9EF312164173C3BFA59D619C513C36A843
                                                    SHA-512:E83780D602EC46E0A6E7D2BA65B3140F942625B2AB7098139FCEDACB829FD2C097B87F30DF61638C28A2BA1914F42C7B4630298BC237680F787BD9433FE4BA3A
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3289
                                                    Entropy (8bit):4.813708726729087
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OMhgwQ3JFI4Ctf9KuGlZusHPwLA:nd5CB7fdpF0E3vI1UrwE
                                                    MD5:41B49164E4FEB96D77779D1430D3AF6D
                                                    SHA1:5FC6ACC09EFDB6354F676772C06871BD6CDA04A9
                                                    SHA-256:FA93702565F433661EC3CBF5B9A19A491F59FF92C6B3D45AE83C3FEF44FBA27E
                                                    SHA-512:327F66898AFA927E722F0494CDC68D4424F6A11307E2D47FBB67FA7A12E22252262FAF15C1E68397A836CA5B9AABC68166092F5D56F234B226544126C3DDF6C7
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2442
                                                    Entropy (8bit):4.86493156112326
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OC9igaFk+BrvTd:nd5CB7fdpFxNF7d
                                                    MD5:30922D0121AB46D783CE0BAB31858914
                                                    SHA1:EA686E62CAA788CC849478521D6163F9F5FE7DDD
                                                    SHA-256:EE81D32E871BFD35E69F8D16D3FBB532B048B118CD36E86800198939DA8AEC29
                                                    SHA-512:23A191CA9AD0389DF183B12A1EFB54473975360EE0AC57C39CFF3D60CCAB8EB4119E69FA387CD80F3E0DBCF10EE5A833E8602ED4188488223DE6723B36E442C2
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2614
                                                    Entropy (8bit):4.866256211674586
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9igaADQ3JFbtlSIryy:nd5CB7fdpF6Nv3vplX
                                                    MD5:6AAC2170F96C64FC76DB9495FA8CC758
                                                    SHA1:1C1BB6B6348DE7F5ACFECC70A33E5E4D9CE29DB7
                                                    SHA-256:2BC48326FF3F96C9B45BDB9F40D58C4247F0A3FAED1B6162053E62900DB29681
                                                    SHA-512:7B01D6C7DEBFEE278C3E1798F068F6E677473969188CF6AF88FF6BB94D1D70429970D285322CCC9B98B1C1C0CB47AFA82FFC7BEEEEF3A24D8B9F265751E29032
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3611
                                                    Entropy (8bit):4.7680902199349715
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgiaQ3JFbtdCsuI/kXx5QwMyUbcAx:nd5CB7fdpFGn93vpXkXx5QQUbB
                                                    MD5:11876909BD8C572FCF9C68D861D81741
                                                    SHA1:344F99132458B884F2D194E24AA81A64D973C900
                                                    SHA-256:0BAD423B02C2011707A175A5A0419012D76CB347564E2B755D1556332CFEEA5E
                                                    SHA-512:429D31F52DD66D2FF6BA7AB0C57BB44FC49F98BCB1116278BFEA3428BFA0A321A48DBF294791590541E502B6C4DC31645F3CA80C4C364FAA1BD89E94EC5FE497
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3231
                                                    Entropy (8bit):4.833735206635413
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9iga6QQ3JFbtoMJ510J4i0xeskxICUlLQ:nd5CB7fdpF6N03vpoMYRgWpD
                                                    MD5:1E7B9504E295508689B5970DC46D0BCF
                                                    SHA1:165AF8EDCCC0BD2F1194B4C7ABC2AA01906CF23A
                                                    SHA-256:5D949874D613C39F067E6C8AEDCED87C89041D812C82C8C9C99A940FBBBE6DD0
                                                    SHA-512:E6E3129C374F0C2E52D2CA70F87B8109EBB949CE40B0F15125C92AC3CF77A419818543ECC3541ADBADD823A703B503481DC51794B7DCBC97EFBF5B4501742901
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4189
                                                    Entropy (8bit):4.819183062317373
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFGnNi3vpoM24SickXx2MIb+n:nd0BhpFJ245xvBn
                                                    MD5:EA2A891E3ABA55F35659D09FF6234EB3
                                                    SHA1:E6D71E1AF8A90B52C609395F55D3667C67EAFC63
                                                    SHA-256:CCA48AD0B22E517AC4487713563498EF4C742773E9523667FB89EA16CE1F5384
                                                    SHA-512:E46C4BDD6AA941751503D42484B1B55F5B96D6C907044E66A979633C0F632C925287B6147AD348379A13A0B3D2BCAB6A71D642B089B7F12D1AE3644CBF5E3488
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3964
                                                    Entropy (8bit):4.847429026644494
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgifSv1aTHliQ1WQMaLb:nd5CB7fdpFGnfgoIQEu
                                                    MD5:61CDD8891A294B6B2494E99C618867AA
                                                    SHA1:2EFB0001159C56776B8990D4D8201AECF662C346
                                                    SHA-256:D1A8C5BB4368D063188614F256104D10B51D0AD1932B3B12E7E5F5022BE718E1
                                                    SHA-512:31D5D96F7FAFF791A61DBFFB58B61E9021B9B4A2CDD53C30BB367A3A940B4463675ACE7301B5317351BBEE763134E66A31DADD4E5F59BA46037FBE1BA6C1CFE5
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):7147
                                                    Entropy (8bit):4.739793868011712
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFG3vpoMktW0UpMbYRzH/Yru94+q6JQ:nd0Bhp4JkQlXhAuB8
                                                    MD5:A3776592653DAE5F62961D696BA09731
                                                    SHA1:1BBD4E1268B31E01AFB0FAEE96B04CC209C135F8
                                                    SHA-256:300F8A895A7691D353CC890F64BF2D09E84D77F1E1CFD4C6BB181AD8D963BDDC
                                                    SHA-512:FB39A5528F0A49626D176DA7E8E02749044810781E96237A6C703332637C2A1C4E370E19F73894661B0EEF8070B272A7644E7C50B32D89901F81E87DBED4A3A0
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3597
                                                    Entropy (8bit):4.76073627095022
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9iNrQ3JFbtdCiwrE0TCEGlLLdvyAuKzbcAx:nd5CB7fdpF6NU3vpkr4vdaAdzbB
                                                    MD5:B980189F05C5741173E22F64617CB55D
                                                    SHA1:DECD107743FDC3EA0A3D6B7143FE5EAF2E32184D
                                                    SHA-256:06AB47615A79986D559A5CB7FA39B6D54D12DBE67C4AEC1265345B30459AFB27
                                                    SHA-512:B94A65E82A45CD2394C272405AA410020072C0992127E86AE2FEA37EF100C63BDA5AA40D2E72F24DF897FD54034588B166D8DFBCCBDD0EE32FDBC007C69ED4C8
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3648
                                                    Entropy (8bit):4.790213481862165
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9igQ3JFHCtLFPif51ca5f93ori52/9yiX3FJ:nd5CB7fdpF6z3vCB6f5V1si5G0inFJ
                                                    MD5:F86A18F068D4B114D1430152FEFA2152
                                                    SHA1:D585869C1E698B95EC300C979F23573C6693EA8D
                                                    SHA-256:CA78F83176C643CAAC68AA49DDFE09302B5ACBBA09CAED32804925AFB356C0F5
                                                    SHA-512:461843598BECFD9BE8196C3D84A9146733A47692AE1BB861DE378729DF25729C68426DCC53BAA79E4A97871D96C72E52C94AFB23A8F9590BA64470A16340C3B2
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3544
                                                    Entropy (8bit):4.780414940069658
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MiWQ3JFm0QuLYupDDaSERbLXz5/15Uxb:nd5CB7fdpFLZ3vn3L/p90jW
                                                    MD5:983488B33F7B24FAEB8AD92D60CFF4D8
                                                    SHA1:11B29462C0EAB1AA5C854AC5D491656DCB69DC49
                                                    SHA-256:00740BC73B27262B9F14003A5C86854596F2606FD1F0E20941E007D6A64D678E
                                                    SHA-512:B9DAF80DB07128859815814D5D48963BB0A055503D2C7EB7724C439FBCC699635363A4AC78FE531A8587836AB9F689CD5BB31CD39E3FA969CEBEBD8EF207F56A
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3141
                                                    Entropy (8bit):4.877469106235129
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9Mi3Q3JFQeGYtaC82GwRCwec8P:nd5CB7fdpFLg3vQeG0aC82G0CH9P
                                                    MD5:A01F36E0280CE5B1C7B45F5BA6DF6432
                                                    SHA1:B6CB5C6EB8ACB74E2F3280237E9E55FB6CE24028
                                                    SHA-256:E64EE9833E08D9E2C50AB44889748890B82DFB759A4B4D02599A7EF915F991DC
                                                    SHA-512:CC2DF4237ECB1A18B14C1EB52A07453D170475CB6AD56E95ED858F3FF27C8A82D600E63858CAC85DB6595940641C794EE0AED84FE5BD2F40A09316C357851954
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3272
                                                    Entropy (8bit):4.855458889295017
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9iPQBJFw0t/hnMRxWQyxb:nd5CB7fdpF6YBv5Zh
                                                    MD5:F0FA93B831920358072547A9B83A20A8
                                                    SHA1:EC661FF54B0E1294E1E68760B5254B01C673AE01
                                                    SHA-256:27DB95473D7270B21036E7F7E5EEA66F63D606E134CD3C7A108DC398929670AD
                                                    SHA-512:B051476CC81C3D802DE182F2869878A367809106C3F0F64973C08D2D240B331BD110CF65A200FA3A2CB8726D303C60C0DF310058E830BE0C9FFDA8CABE34A263
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2362
                                                    Entropy (8bit):4.840196634832251
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9iXQ3JFw0Cb:nd5CB7fdpF6A3v5C
                                                    MD5:3CE69D346524C41D081C5471B672535F
                                                    SHA1:A6394A4198094D8E468C422CE3807EB3DA578F3F
                                                    SHA-256:7A4E835E35B97A4EE774042C45DBD1B1250D80141D351734243C2FD25F938EFF
                                                    SHA-512:FFB40E1A4059EA9517E710B2239E33799A54768BA7F72C981DA58B707B2D685F8D37459C9F32369B9B2109C5BFBF9220FC3397FF70EA9C211F9C9912B943CBBE
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3031
                                                    Entropy (8bit):4.815424548202451
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9iqQ3JFd0iva9WLCUlLjjxVb:nd5CB7fdpF6N3v6ivaIOKjn
                                                    MD5:28FA3B9968FC0E1369E0EC0E6F3962F3
                                                    SHA1:356A461F7A6F569A8B37FF8A1CA0D63616DB4A0A
                                                    SHA-256:F795B3BE2A6D4A5885D54CC00A1ECE95EBC707A11DDFBAE20546CF46673D07B2
                                                    SHA-512:3C30DBFEE33949D24B55184FB620F080A65069EE04B89958E4C04028C9526DE5FB6C5F97CAB7641CA66C4A43981A697C6FCB9F0ABB10E971E76FB1ACD7E54E25
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2999
                                                    Entropy (8bit):4.823707297757387
                                                    Encrypted:false
                                                    SSDEEP:48:M25H6E+iCsAaKj7fOWIkFy9lvx8cqQ399tqYVtXFbbUWlF:L5CB7fdpFY35qYBb1
                                                    MD5:057253DD05394B9B0BA19E242A7C03A7
                                                    SHA1:48C95205EA7D791680F624E93F220AA9D8A26498
                                                    SHA-256:7359789F86AE8789F63ACF3566662275CEEA14CD2F973CF4E9724C13408D7073
                                                    SHA-512:47A1D0E0BEBD6595F1BC07DA9417BEFF15F84EACF2EE3C3796447E341E3FC2005C269C20604802DCF16E5D0AE280EA53256125284ED122DE3A5A8C73888DCF8C
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2020 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3649
                                                    Entropy (8bit):4.82315689006633
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9Mhgi+Q3JFbtoM2Lu8kXx2MDUb+n:nd5CB7fdpFGnB3vpoM2bkXx2MIb+n
                                                    MD5:41D103DFD6FBCDE9575E4ECC41C7AF56
                                                    SHA1:FE4453DCEC366E3895A1D59880B9A2079C4BA277
                                                    SHA-256:2BBE9E32EA491CAA7BBCE03064CB3E9329D660A01E107CD6BE2AD62BD4778FE2
                                                    SHA-512:0C83963D1B3D68C933A2C7DEE78E689EF4130ED6BD217E511D927AC7E2B045CFD58597708A97342D0C6A0C938EF5EAA471096B1617657975174CF50C3900B1A6
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2013
                                                    Entropy (8bit):4.823214903186843
                                                    Encrypted:false
                                                    SSDEEP:24:MCdbFTT3QXf8WYwid0szM6RqeRGNfj9TNZlOWIQNydOtQ+y9O9efFpdqQWyTQVNs:MCd5H6E+iCsAaKj7fOWIkFy9O9idqQ/1
                                                    MD5:68118E5701B958BDB5ED8FA8CD5938D6
                                                    SHA1:10CF3F2773B27BA97EAA4E9248FEE8E47C48652C
                                                    SHA-256:CC3264DE0EF9416C869D7736EE50A30310E267D6EC890F3DE741E56A6D3608E1
                                                    SHA-512:4BBE100386809F48671D50446059705A7C0B8D9ADE979ED0607627A5E79F78B69099648C6D8304CFCA96BE4088CDBA42A8F9225D11883979FAE368F1F3070851
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3188
                                                    Entropy (8bit):4.817952074436946
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OM9ig15Q3JFw0cw/NtPCccswXnaSE8xb:nd5CB7fdpFvuS3v5l/vCcc1B
                                                    MD5:BD84F0660D08F74C3F59CA06C3A720AB
                                                    SHA1:3FD62D094C83A1B6515F19174AE3D430490BD510
                                                    SHA-256:BA728FE4C754FCA8A6D9B1A08A114928FE28A0FEBF947DF3B9EEB46058ADD387
                                                    SHA-512:96CD5D78461F1BE5A5A69E738DD16E4C34C6D6B5E6A87DAA57BDBF61E4939F51D36AD74128766DD3A9A30249409E62FBCA225AFEF63801F7284E4977BAAA6C7B
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2568
                                                    Entropy (8bit):4.835909043606398
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgiuQ3JFw07mX3b:nd5CB7fdpFGnx3v57G
                                                    MD5:6505E480F2B9926D4D2C3E5FA891545A
                                                    SHA1:0653562C21BC00F36A09BA5E624508DB7E822F44
                                                    SHA-256:C76E6D27C2E549924D626F3035E50C6ACB5C80C1E27F6F2E563DC8B7AD07DC09
                                                    SHA-512:7A3A7854A0C687FEFCA9B2BF28E02BD530E0DBE6900BE6F0D1572FB719F2A954D74D8CFF81ECCE86697A8A383D0889A33CF05A62E9C82DF59E2EF53E4CCA1ACC
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3579
                                                    Entropy (8bit):4.788049528540249
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgiBQ3JFbtoMruLyZkXxp0ww5Pa:nd5CB7fdpFGna3vpoMRZkXxaFPa
                                                    MD5:5156BFA9A79101C234B9104A3860ED35
                                                    SHA1:C67A1E5141B65C476E0DC3C6B3210BA943C8EF71
                                                    SHA-256:AC73F4E0DFBFB169BDD0EE604D3DA70A935C813262F49117E9D9EF7CEF9C460C
                                                    SHA-512:A738FA57A38E929943BC740F3A0FBA0FD4A6D7316DEA6DA64C0F80235390DA9C0CE4F02FF238F56AEFF74F423B08F48CF1AC6052B8834D49CA743D0C0803CDC8
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5073
                                                    Entropy (8bit):4.803398406819676
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFGnJ3vpoMRPQskXxZyas4SRPa:nd0BhpuJRsxZlspZa
                                                    MD5:E6B30F84CB41750DA47EB3EC0170E226
                                                    SHA1:63CC56C19796A4482471B6C7A48863F6AD754B6F
                                                    SHA-256:AD00BA11BEF803203B3B68D08C17D26B4848546847D3EDD7802D968A6ECC3723
                                                    SHA-512:AB06AB8090F4B50BB18BFF91D08B3C3741818F4F511CDB1A7B6B4AF58BDB0782AABE3AAA9157B9BB9FB1D9C3B25C143B66E87A7D513BA3C7B5123BDA2C688762
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2533
                                                    Entropy (8bit):4.846356002102557
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9icDQ3JFbtMu0b:nd5CB7fdpF6T3vpMF
                                                    MD5:6B0C18B69818DE385FF38137747AF21B
                                                    SHA1:DFCA99F3770E59D0338242859CB63D30DAF5DF8B
                                                    SHA-256:BE42D1BC196BA6E2849C0B536F5B8B9532CF9A212B8838E88C431E3135F040CB
                                                    SHA-512:E97817510C45709C990B9F2C75758658BDEEBE7CA88BFC47C2488B1975644E1FD60302997098061DA814EB53650217EB651C8B6E9C24FD1CDC01D48FB10DFA35
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2585
                                                    Entropy (8bit):4.772316352792342
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9ilQ3JFm0QuLYup1:nd5CB7fdpF6e3vn3L/p1
                                                    MD5:38CCA49F231D57566EFFA74E188DBFA8
                                                    SHA1:AEBC934932605C2F6BF070DDFD38A766CF910E31
                                                    SHA-256:54E4BE75E5355BE1FE22E0B16C51FB81F974AF9FCA4C487D78E4AC4AD391B214
                                                    SHA-512:99F74FFE7F05FD29A2CC92542B6FD5D415CF373CF1CEED17FB2F33100AF75AF9099787A935504790F9E7F309AE59C1A55600D291F1BACF2DCA1C0D004FB377E7
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2769
                                                    Entropy (8bit):4.791992195558291
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9i6DQ3JFbto6qEOFZZ:nd5CB7fdpF6Z3vpo6Tgz
                                                    MD5:D68B0EBE4F30F47A9FA2A8EBB8719044
                                                    SHA1:9A068AD807DAFD0D7C093296849322C26DDA5AD0
                                                    SHA-256:5B42D3E817DFFEF20F3328BBB73F89E11E52F32C5359DE999D898B09D7747FF6
                                                    SHA-512:E98B2A9D14809DDB7F91378541A9467B04F630F4FD604CCE3FDE9C71D9A45608600F17D38CABFAD66D37D095D4A9708A3271CE9CD59E7B4D68060118326D3809
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2312
                                                    Entropy (8bit):4.836628797705159
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9iUQ3JFw0j:nd5CB7fdpF6H3v5j
                                                    MD5:E2EB84D9C62821F21DCDD802F873CFE2
                                                    SHA1:DB2959EFD8F76317AB662513F8083C61F68977A7
                                                    SHA-256:09EACE0320CE3E20AD80D2FB3A9E7E6F1D42C0EB2F84C2EE569AF4345F1B28CB
                                                    SHA-512:62A6CEAB8F7BEBF75DF99EA9FA8CD859A2D0B800E5CD3FD2F58AA2C8499CCEEC9EB856D50575BF67E9C44627BA2453ABB592B8DB0A1BAF2B43F05B0A13EFBCF2
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2618
                                                    Entropy (8bit):4.852512229773011
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9iwQ3JFw0jaSE8xb:nd5CB7fdpF6D3v5ZB
                                                    MD5:96811F768438E70DEB8BE62112EB8571
                                                    SHA1:A9BF49AB45008EE53FA6A60061CEF11056E96F7F
                                                    SHA-256:FCD0CCF5FB6E7B20FFB06E7AA4A0F49C18BB6A5C832A5E3B5D0F72EB8FC857E8
                                                    SHA-512:ABD9ECD915221AA3FD1723D30C68C48BDA166ED0AE3E562367C9257B34481754EB7C8E07F6F3062BE8D234A065F97FA1035EA548419FD2A4628B389E826D8852
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2783
                                                    Entropy (8bit):4.822722121007662
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9igaiQ3JFbt8z2rozak8PjfcxfkPb:nd5CB7fdpF6Nl3vp220zanbAf+
                                                    MD5:919BE776133310D6C9EFC17B64F7BF39
                                                    SHA1:3038245521C3059E1A092C54F327F3EF8D023E62
                                                    SHA-256:CABAD8F6559EF0A38D87A5C7BF8504C3448B8364FCBB8CA4810198D34E74FF94
                                                    SHA-512:66D0907A356535CB14CBE7171EF87F24DD81F5472CDEAA63F8D44639F1C0DFD134B05A227814842E2D419C84EF0FFA59B1814DEEAB703F5D4389E946C9CF2DC6
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3234
                                                    Entropy (8bit):4.831819684485204
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9igaFQ3JFbtoMJA10J4i0xeskxICUlLQ:nd5CB7fdpF6N+3vpoMNRgWpD
                                                    MD5:47B37B8CAFC071F3782645DEE264A0F0
                                                    SHA1:B7E8D3D5557BCA1095609CBB154F72E6123B2D7F
                                                    SHA-256:D045CAC3BB3EB18F555C1BA2E18DB8D29F0BA0618E1C031E430D4E0FEB3225C4
                                                    SHA-512:8F4C9D1FD7D5EDAC9463D1D6F2290DFD07DABAE1D91239F4391F9B94F559D6E43F891424C861E7BC135544FE32EE9FA01E4F73CFA443566DE94B2D593FA808BA
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4189
                                                    Entropy (8bit):4.818559974021103
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFGnNt3vpoM2VSickXx2MIb+n:nd0BhpkJ2V5xvBn
                                                    MD5:F04B8D57B0CF35179A39A63C3B498BF3
                                                    SHA1:5B013B2BECDFC98DD6DED7BB61E75E03389EA954
                                                    SHA-256:A8A0C6E167CA215BACCAD9E343D11A2F259909C88E3B1DC88ADC8B0629D5261B
                                                    SHA-512:ACF92D3FFB610B78839A0A7302761734630286A702CA98AAB32132CCEAD81268AB1595D52D73627DCC5D0024A9372F4AD44C316D600E879032F5EC58734475AC
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3462
                                                    Entropy (8bit):4.757964754620368
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9OifSiK3Iyrr8NL6uryAsLNb:nd5CB7fdpF4f2VrINz2As9
                                                    MD5:4E23BD6C4A28E57D4314EEC0C105BEBC
                                                    SHA1:5355E64D346609C314E6BC31991F920C72C5F160
                                                    SHA-256:E44305CC55790361E327EE9A4E03231070848B9D606F854E6A43638310AB91BF
                                                    SHA-512:161294AD1257FF277F72C328F4C75BB9B84518861B15C51FEA2490503D88F2DB965F9C46022B5BDAD30041283A4262D36B146359931A32523AEF7E132A091067
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5735
                                                    Entropy (8bit):4.762434213586017
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpF6F3vqStm7KqO6oLF9PxJrF9i69xttQ:nd0BhpLSEGAox9jR95Q
                                                    MD5:D0E7BD67863F9214FC91B2DD744F5C97
                                                    SHA1:08F3738040BD9886598E6E513CE9CBCEA5E4674F
                                                    SHA-256:C6EE80AA856F618C3FEB777EB96C329AE7B57D2C53D990BC34548B4CEAB68C98
                                                    SHA-512:1EE5EE2BCEDCD5431CFCF48E6396A1D317E69C0635ABED0FF43F1724659D42C4F94CFDD0E9404BE50A82C2910CA29762FB43FD734E34065D7EF92922E4C501F5
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3650
                                                    Entropy (8bit):4.756460909764809
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgiCQ3JFbtBuI/kXx5gwMyUbMAx:nd5CB7fdpFGnF3vpdkXx5gQUbx
                                                    MD5:6A1A1A3594F7FCFFCA535F343C265D07
                                                    SHA1:A833CDCCE738182AC3F7ECF1D670BF51F7485E95
                                                    SHA-256:4830165063CEA46830FE37DDEF5695A1372F3ADCE5B40CD97A17753904E3D091
                                                    SHA-512:C068764410453E56A0B34CD4AE0EFEAE2CC1C20EC45E9A4EDBCC362545DC2AA305F14CB56078893D2FB8B3E9228FCE194604B76F4E080064A3E0E0E17A8C30FA
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3798
                                                    Entropy (8bit):4.833929967744693
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9isQ3JFbtbSQuWfEJBNvjiykDPxEXi4PxZ:nd5CB7fdpF6f3vpb1uxlKPai4Pb
                                                    MD5:A3E3A50AB10788C00A13998D8B60084C
                                                    SHA1:C27B825B3144D8C9659F604EB4C54610029CF775
                                                    SHA-256:D3A2C52A2B4E31C545EABE98223ABB046A420B46FB933FFAC4785014D3BAF58D
                                                    SHA-512:174A1C30FCBD50DB8261C38FEF4846D02DEA363BFE69EC2D1C42AA1E35086BA4F30191BF3706B92997D6907A93A89598A88D1D45EF850AD85853ABA525FCDDED
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3070
                                                    Entropy (8bit):4.707917185138538
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9isDQ3JFbtSTBNxickzXE8aXH:nd5CB7fdpF6D3vpS1KzaX
                                                    MD5:D80721F83A475CA172D3AB390278D683
                                                    SHA1:E8E32AEAA1EA069BB01CFD814A2EE10BC9FFAE00
                                                    SHA-256:31409DC791AB9690F9ACB1C5581C9EAA60187C12169A249030EC0A22D07ADD69
                                                    SHA-512:989ABBAC2BAFC6853408D6566DE2E6B83D3FDB0F3BAD5D974A4C36E06E03B590C611C8E9610935E1DFFA285D20C426E4C140EF9B07E299371D43C6049A3EC157
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4658
                                                    Entropy (8bit):4.799331765263338
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9ifQ3JFEITdd86EAwWKm6EAm2FLF9d6oAF9miwx:nd5CB7fdpF6o3vjZ2t6oLF9IXF9mi0
                                                    MD5:A483F67E851CFE81A3BB3288E11D6D77
                                                    SHA1:116ABD889A39EDF699A2C4B68CE6D4B88EBC003C
                                                    SHA-256:4E25E9C7BF52800675D934BB24B5F2BBC7BEE91F0B139CAE6F934D453E354EA7
                                                    SHA-512:DC7E84A05EC92731C78F807125D95314E73D535D9A0C114BFF6581C141CAD807B91C46AA4896CAC7E5F5580BA3B96FB0EBD48D57A378CADC0697151F6CFCCC96
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):6648
                                                    Entropy (8bit):4.72624143810639
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFGnh63v5MRkq3JCjKB+bCSQOQ/ra:nd0BhpXhQCQWa+
                                                    MD5:71AD2135502E88D66B0781143923CAC6
                                                    SHA1:99EEF2C55E9F4A6171605656D28EB390094E1497
                                                    SHA-256:44B096B4415E7CB19082F58086E0F5E1726694F206A4364872A3C360953D7052
                                                    SHA-512:FA45DB83E3DDEFC981B4380657B0C5709BC345D859449BC264F1DE9FF789029D82912BD5C6F69D0392A9A98000FD428508139D064EE2C3F44F33ED134098F296
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2682
                                                    Entropy (8bit):4.878133413550622
                                                    Encrypted:false
                                                    SSDEEP:48:M55H6E+iCsAaKj7fOWIkFy9LixvRQqJFbtyz6t1:U5CB7fdpFiqvpy23
                                                    MD5:3ACBE1D1CE8AB0CC2BD7823FDFA4A2FB
                                                    SHA1:4BAAD0103B2EFDAEF9FB1C2B7FD742A2E9DFFD32
                                                    SHA-256:B05DA2F982432D6BEE7604DD04E0E8FF5D5CD160E4156A71C27AB7F1D7FC619F
                                                    SHA-512:E3EBACBE12013E6A690E6E9DAFEB09E43F276F1C9648CD125F8A68552B84CEEAE47ED727AD16603178B0F7477B03236AFC96E811CC33B206EE114C46FA350BE7
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2018 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3388
                                                    Entropy (8bit):4.8990700467566635
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9ijQQLet9LGtDFLfCtP:nd5CB7fdpF6sQLet9LGtDFLfCtP
                                                    MD5:0845F8209BAC4A8AD3409DBDA985AE6B
                                                    SHA1:F143660B4B9FC3E107D798121A995038585ADBE2
                                                    SHA-256:1FB2C1779F30B431D2BFF35948DB799AB409528F39742F2325BF5601E5EDB7EC
                                                    SHA-512:01FD4E84AB2353936220F36F3A80A8A5323DD5D108F9F3985384B495CC9947A33875D2604ABD4406944FEFB1A8F0F3B43E9606DA25200F3D3BB13C506D5C85FF
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3841
                                                    Entropy (8bit):4.788731261366922
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhginQ3JFbtoM2LuJkXx2MCblE7OG:nd5CB7fdpFGnQ3vpoM2ukXx2MCbW7OG
                                                    MD5:E2799AB66803065646838BF4B6059F9A
                                                    SHA1:E2B4F672B00CEB5F9A87056DED3308755AAB1C81
                                                    SHA-256:A1845B21F9FB5163E00DBE0C2EB6761930DC15CBD04D29C624FD0774849A81BE
                                                    SHA-512:6BCE7B2B1CBE8F4BDE8A68A88725091ABC713A32566112598B5ED2418F8CEFAEA4B20E0BAA8CB154D0CA31B14B336AB5027775E5ECAD483944D8E8A62589ABC7
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3230
                                                    Entropy (8bit):4.8302682043142635
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9igaiQ3JFbtoMwx10J4i0xeskxICUlLQ:nd5CB7fdpF6Nl3vpoM/RgWpD
                                                    MD5:415BC326337D27F9C84C6AF2FE9534A0
                                                    SHA1:906D3DCC493BA53667351492BFFFF80D88450884
                                                    SHA-256:41D3A1564F0DF044A541CBCF96CCE0404C6909B198C18B5F7A6B079E766EDBCB
                                                    SHA-512:61F8B564366EF1A123940BB529B606CBA093DB2C811BE4C2D141BECDACC1B7B1FB9AE00BB825B4CBAF6BA844F7C2B4746D041555DDB8547248E3528C7B4C33EF
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4191
                                                    Entropy (8bit):4.818843049822159
                                                    Encrypted:false
                                                    SSDEEP:96:nd5CB7fdpFGnNu3vpoM2ASickXx2MIb+n:nd0Bhp3J2A5xvBn
                                                    MD5:00A6BFFB5C8E7EF66140ECA140CF41FC
                                                    SHA1:6112AFF0672F25CC5261189241E1856206687F11
                                                    SHA-256:6183952A78E9513F90343244FF7FB94ED71FC24329533FBCF983F13A73805E0B
                                                    SHA-512:B5360F9C7C4647EE00A5EE660F98E04DB5F6EF889BA6E689F40DA77B412EED93D9B8FF213DBC2E4EBA1CD1F1B8A173A3B2D47F67BE137E3F912DD6D3A52D8289
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3749
                                                    Entropy (8bit):4.773499896099176
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9i5b76uiN73cfWyTnTY:nd5CB7fdpF65b7EM/jTY
                                                    MD5:408ABDB483638C73F45F54B8DFB8750A
                                                    SHA1:EBEBA2A6A99A038B96B2559679D42757E9DEC6CF
                                                    SHA-256:B43EDACFBC91550236975CE77CE1EC7F0A611E4399C642284BBBC43419E24322
                                                    SHA-512:421D68BD795D2958A72E2DF19F9173C83D6657EE256DEC1DBC9B84558AF55A46E0C4695DD43CB91BA797E59A86F09A0086E4AD9A387A26BD8695577785132356
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2859
                                                    Entropy (8bit):4.856566390652683
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9imQ3JFw0mwlc0jisC:nd5CB7fdpF6p3v5mNHP
                                                    MD5:92413583ABC598468E5A08F8743591EB
                                                    SHA1:DE75EB1671C40C4D6C1076F227E9D67CE9553062
                                                    SHA-256:2ED1060C8E0886E36EF63B9F3A401D75E97EF54C16F2A9F3B2DD8463D013A014
                                                    SHA-512:F4E5799F9B6CB00C8CD516BD5F6762784910C9DA5858BA17AECD21D964E0BE0EEEA6C5679889567E6612D7A39852736D859176431B00981A88824F2B2699F885
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3082
                                                    Entropy (8bit):4.806664956509386
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9Mhgi5Q3JFbtPumkXxL:nd5CB7fdpFGnS3vplkXxL
                                                    MD5:F935656067114BEBE3FBB5E1B060CB36
                                                    SHA1:316C55985EE466FD2CD2E6AB1EE7A99BD4B58EC8
                                                    SHA-256:13C688005A1D38A943E4C971814067E388F5288F1EAF253244EE444E4456F967
                                                    SHA-512:673BFE928F2EDF0F0F7B1504E1CCF6B52CE120F17029FFDCB923A57439DE05D97DD39D87A8EE7C73EDAA48175B6877A9C68F9A4F6DF8A34566F299BF24C70EEE
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4336
                                                    Entropy (8bit):4.801117075800774
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9Mhgi4Q3JgZLzA9Cd7ryljygyy/PCyQMYN6b:nd5CB7fdpFGnr3ONsyaluyQra
                                                    MD5:1E396B6F1AE7085E3C629914AE18CD21
                                                    SHA1:18039DD354BAE88FB0993F72BB1F4F61540BA30D
                                                    SHA-256:541E88FA989E7D56961E7969645E4DA4004BAB7342D9BE5A53452C716B05381A
                                                    SHA-512:D503732EE4CE3C9E72F3636D988B68A47DC33553B15F00EB87C49683A40F9F77F1346FBB30035585FC45389308BDDEA9EE24216550A34CA6134565F52A234E9B
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4319
                                                    Entropy (8bit):4.824043771387485
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgizQ3Tw/nP0p9Cd7rS+jygyy/PCyQMYN6b:nd5CB7fdpFGn83TcszyDuyQra
                                                    MD5:9B0751751CBDC555F47E3286BBB77953
                                                    SHA1:8CDFC51C00A7A8DAC5A636ACD0C409BC194CB337
                                                    SHA-256:BC9BE32033EC2EF5C9FF140D7F21D12B293557DF6FD285CF467E7AD895D20E53
                                                    SHA-512:2FA7A0DC1657F24081A34864A71041F5C4582D9B54A69601A0B9269A6DC0C45D84FD66A1FC62A37EC58BAECEF7D142CE970BBF42912970F1D93016352E034C65
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2359
                                                    Entropy (8bit):4.849036051905213
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9iVQ3JFw0nkH8Nb:nd5CB7fdpF6O3v5nbp
                                                    MD5:AE20FD05FA8EB6037E6FEEED24254E4B
                                                    SHA1:74D9C01353EA4B8A14FB93B16D1B2E7CB31BB4EE
                                                    SHA-256:31519E86E9522627C42B95685226213CED9EC312997A00D5529847009E0E6789
                                                    SHA-512:20275BE170D8B61383146C0CE15E0376736941178662D499AAA26EC97F58E8C488C6393A13F82BD15128DB32480363B4ED3C9096AF97FE7E4CAFF52163420F2F
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3315
                                                    Entropy (8bit):4.835599944070907
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9MhgiAQ3JFbt7uI/kXx5ykHYwrbix:nd5CB7fdpFGnT3vpfkXx5yNgbO
                                                    MD5:77E3A69CA01C54E4424820D937D014DA
                                                    SHA1:FF23A5190097D083DEDFB5F8215A3DCE8FB7699A
                                                    SHA-256:EB353F7EFCB8C77E1ED23EA612FEC9F394D495D5DA4BE3A851CFF9B22072C239
                                                    SHA-512:1DCF1DE5A7A70B0519BA0E6F1B8631BDF5D1BC168703454AF9D0365ECF05527F9B3156420D471DC59233E5ED5E15AB863B594FBE29768CD39A1A44503F90925C
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2564
                                                    Entropy (8bit):4.855878718510748
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9iDDQ3JFbtS6uSb:nd5CB7fdpF6w3vpSDS
                                                    MD5:96D4B0987608270E92965C2FCB1246D6
                                                    SHA1:0D889A38EB375B90F2DFAC4FCD41DC09F1FDA92B
                                                    SHA-256:42FB514CD92C9C87A80EDE4BD648758CF54F74CC05D3338AB76326FBC4D09A1F
                                                    SHA-512:39597673F408F531E4A6812A9E794D233A398206826B6B450C5E18977852AD35C548941D6671C56AD32EB7398A4863CF54A13B74CF90343A168A3EB3265F6A38
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2919
                                                    Entropy (8bit):4.873465289167498
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9ilQ3owJFw0jWrOaFD:nd5CB7fdpF6e35v5jq
                                                    MD5:6B7AFC1DB3A32DB1541023A199F64909
                                                    SHA1:F80875DD56C24CF6EEE538C0AEC0171BF08BC28C
                                                    SHA-256:8C3F4A1AD480B81934A91171C67D61651F39C87FDFFEF348045D492E6EAD32B6
                                                    SHA-512:92024C59DDE029A5B4F1707F0310638CFC6E110E05E8A13A2623D0933FB7E2797326129B22F9171500E804E3EBBECC1B8D7BDD3737E5C3DFDFDEB143549CDB94
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3319
                                                    Entropy (8bit):4.8279801671890015
                                                    Encrypted:false
                                                    SSDEEP:48:MCd5H6E+iCsAaKj7fOWIkFy9O9igMhtQ3JFI4Ctf/KeGlZusHPwLA:nd5CB7fdpF6xG3vInyrwE
                                                    MD5:2A009241245A2ECF132569C737FFEC1F
                                                    SHA1:225D896E1FC4D7BE40B5E7C16AE7E6E8E095DF18
                                                    SHA-256:3B17958A4ADDBD57365B0EE41ADD4F3F80F1CEB35C9E8FF1268E706B7AEE6AD9
                                                    SHA-512:DE81361CB3C1C5713F2627CBD005AD38C1C543DA36716B6E27FE08A8C21FA8E7E2D68C94C991EFBFEFC0CBCF07C9EDCA604211F0D8543FD1E2EEDFFF6372FA2B
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2996
                                                    Entropy (8bit):4.822220527499383
                                                    Encrypted:false
                                                    SSDEEP:48:M25H6E+iCsAaKj7fOWIkFy9lvx8cIQ3rNqYJaFbbUWlF:L5CB7fdpFG3BqY8b1
                                                    MD5:B6908BB475283A82C04F52B8C3584B8A
                                                    SHA1:9DE2170C912B514B5ED1F7EC697EC141799FDEFA
                                                    SHA-256:FEBA09AC8F1B9CBDA59D0EAC4AB68446414C0720A6FEE19351FE1CA1A12612E0
                                                    SHA-512:E9FAA144238C42A583435D5B69DD9D1FBBF6578E0B4229B1312995183B8F0261435605793BFF3B41BBA423CF390116CA275F7FCBEBEDDAF62FFC066572EC8C80
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2020 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):13897
                                                    Entropy (8bit):4.371650370083731
                                                    Encrypted:false
                                                    SSDEEP:192:X+f/XO0eXiqegTmSc4EhouBsDTl6tlK9jFoY3D3yEbfbiseVpTHD3aIq9EgJLeJo:nEssKhFv
                                                    MD5:1AD125081A90751A1B242718BC778618
                                                    SHA1:28A24F7233FCBC29E7C4F3101E617610AC099756
                                                    SHA-256:3422578EFD36D424686F0FEA58A6DB6E2BE606DEB4CA3584143ECD23D9399516
                                                    SHA-512:680D8C1254335434960EDADA3760D65DBFCB94F0F1815FB7C432CE0E757A89329A2BB4D0C21D8E66ECC184DA737433B73ECC2CED12E8B2CD3261EE44717CEF6F
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2....// This file describes the plugin-supplied types contained in the library...// It is used for QML tooling purposes only...//..// This file was auto-generated by:..// 'qmlplugindump -nonrelocatable -dependencies dependencies.json QtQuick.Controls.Universal 2.15'....Module {.. dependencies: ["QtQuick.Controls 2.0"].. Component { name: "QQuickAttachedObject"; prototype: "QObject" }.. Component {.. name: "QQuickItem".. defaultProperty: "data".. prototype: "QObject".. Enum {.. name: "Flags".. values: {.. "ItemClipsChildrenToShape": 1,.. "ItemAcceptsInputMethod": 2,.. "ItemIsFocusScope": 4,.. "ItemHasContents": 8,.. "ItemAcceptsDrops": 16.. }.. }.. Enum {.. name: "TransformOrigin".. values: {.. "TopLeft": 0,.. "Top": 1,.. "TopRight": 2,..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):158
                                                    Entropy (8bit):4.58971464637918
                                                    Encrypted:false
                                                    SSDEEP:3:3BV9NKH4TAXDJoNMURCNC4MXWEJWiwhvyWmopCxKbbJ26akyxRS9NKSvn:xVfW4TAXVoNMU74MXWgWiw58oIst2J58
                                                    MD5:62CA2AD26A8B534945019A03A4C386F8
                                                    SHA1:FDD59AEF9ABE3682A09152FD8C0B5C7A7691E5FB
                                                    SHA-256:1150344EDEB157FAA029A8D93A79B6C6D80E97B492D67F1AB636EFB156E7B19D
                                                    SHA-512:04D4DFABC37079461913B845CE43CC6358E23CCF1A19AC97477143554179B05249C636584CB03CE2B5F5903E309D98E7C5CA3CA651FDBB369362ADA8393F4A3C
                                                    Malicious:false
                                                    Preview:module QtQuick.Controls.Universal..plugin qtquickcontrols2universalstyleplugin..classname QtQuickControls2UniversalStylePlugin..depends QtQuick.Controls 2.5..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):234096
                                                    Entropy (8bit):6.090560863013277
                                                    Encrypted:false
                                                    SSDEEP:6144:vLieapIpVpGp8pzpLpcpopGpxpYpLpupDpwpXp+pWpupBpIpipWpPpXp3p3pIpD8:vLEpIpVpGp8pzpLpcpopGpxpYpLpupDA
                                                    MD5:032E13E1F12CA1C3C3AAA72B9E3A0D22
                                                    SHA1:C82D2A48B8F208F65FF6E2CD0AA5871C55CF4F03
                                                    SHA-256:68930C4CD47A38F09E22A59889AB8B35ECA4C5FD2815D61268842A8B32484AF6
                                                    SHA-512:0694F7FD73228BA4BF45A16D1CAA85F1D3AB59215E7DA528EB6F4EE9CB5524A4F93C789F58EB46C26137FFBDB7E751E1D37CBF545AD86A28AFCAA9C0EEFE8288
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............^..^..^...^..^).._..^.._..^).._..^).._..^).._..^..._..^..^...^..._..^..._..^..z^..^..._..^Rich..^................PE..d.....e.........." ...$.j...........o..............................................k.....`A.........................................(......t).................. ....r..p ..........p...p.......................(...0...@............................................text....i.......j.................. ..`.rdata.. ............n..............@..@.data...p....`.......L..............@....pdata.. ............`..............@..@.qtmetad.............h..............@..P.rsrc................j..............@..@.reloc...............n..............@..B................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2833
                                                    Entropy (8bit):4.809421054317256
                                                    Encrypted:false
                                                    SSDEEP:48:M25H6E+iCsAaKj7fOWIkFy9lvAQ3rNqYJ3FbbUWlF:L5CB7fdpFk3BqYvb1
                                                    MD5:F5CD8AC746B6994ED71FF8301B42A56B
                                                    SHA1:BA037B256EE49D9FC2C30BD11CCB8A01993A38B5
                                                    SHA-256:1D4F3F1D0DBB8CAE0D392C2556889C9639A1A51B055E47BDAABEDBD33BD4A934
                                                    SHA-512:6B465228D5918FC4A1EB093A0896ABFBD11A57ABD2641A6F89581B063E6537F5BEC2B33084F873871026526C39741A10CE11C0F52BE80B35257EC86F7BD27E75
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2020 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls 2 module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):33341
                                                    Entropy (8bit):4.534136956343582
                                                    Encrypted:false
                                                    SSDEEP:192:gima/rqfyvocsgWAEPHd/RBcWTkrmIhUeoiADLTEEZZjHK1TlbyQHhEUGBGgUq2W:Xb/rG+KXD
                                                    MD5:09EBBE642F2775F9B5A752C82D5AA754
                                                    SHA1:B94DB32B0D39C129F3A16DE43697B563658A214D
                                                    SHA-256:86ADC43D2FB0E3AC925E7E7AD545C771D5CB45423F0E352D68C379FC9A205360
                                                    SHA-512:D99E8B633691F0B5A2FC74E179EF97D6419D9951B1202AC17926F9F7C1E1F71D94578AFD545867B64A1FC18E671F95CF616CF88D890A1C5337E773ADA0342A18
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2....// This file describes the plugin-supplied types contained in the library...// It is used for QML tooling purposes only...//..// This file was auto-generated by:..// 'qmlplugindump -nonrelocatable -dependencies dependencies.json QtQuick.Controls 2.15'....Module {.. dependencies: [.. "QtQuick 2.11",.. "QtQuick.Templates 2.5",.. "QtQuick.Window 2.2".. ].. Component {.. name: "QQuickCheckLabel".. defaultProperty: "data".. prototype: "QQuickText".. exports: ["QtQuick.Controls.impl/CheckLabel 2.3"].. exportMetaObjectRevisions: [0].. }.. Component {.. name: "QQuickClippedText".. defaultProperty: "data".. prototype: "QQuickText".. exports: ["QtQuick.Controls.impl/ClippedText 2.2"].. exportMetaObjectRevisions: [0].. Property { name: "clipX"; type: "double" }.. Property { name: "clipY"; type: "double" }.. Property { name: "clipWidth"; type:
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):140
                                                    Entropy (8bit):4.5380471064327965
                                                    Encrypted:false
                                                    SSDEEP:3:3BV9NKF7eURCNHJccvyWmopCxKeJQCKyxRSGIjNUkovBUoAw:xVfy7eU28oIQCDCGIjuvBUo5
                                                    MD5:659ED029AFAEABBE4235968FF5292736
                                                    SHA1:565CEBA5B695EEBBF28030965EE5929C2A5A2346
                                                    SHA-256:7B404175BB8E2B0D3822E75320C8D6D09C61BB53F4513C235A7D04AC7D34FD57
                                                    SHA-512:41FCB039C054C7DECB9FC7CA198F3218DC0965813758B66C5B8B174B732040A33F2D3F54037AEC7A9C48AF5CD3BCC798DDD41C7458924B8C9BDD49A38846195B
                                                    Malicious:false
                                                    Preview:module QtQuick.Controls..plugin qtquickcontrols2plugin..classname QtQuickControls2Plugin..depends QtQuick.Templates 2.5..designersupported..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):293488
                                                    Entropy (8bit):6.13926639051249
                                                    Encrypted:false
                                                    SSDEEP:6144:BvvAV5Mp/pip+pGp6pVpSpFpIpapFpzpUpippp7pgphpWp4pKpjpJpqpypMpapfX:W/Mp/pip+pGp6pVpSpFpIpapFpzpUpi7
                                                    MD5:DD058BE6EF62AA50358205AD27F8C11B
                                                    SHA1:55A7572408AD97A585065B1F64611C89B298A23B
                                                    SHA-256:5FB860DAEB3BB3E1D037FF47261BA33D0C03A32D484E5A1F3822A39C49F5423D
                                                    SHA-512:6CA5A88CA29823EAA2D18630702862459517307DD1E05FCE6C797FF49F5C22B6503E0370DF93729BEFEAD963FBFEA5ACBBA6E2AF4D4E41B06FBC92CAEDDC01E5
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......y..*=v.y=v.y=v.y4.oy;v.y...x?v.yv..x?v.y...x)v.y...x5v.y...x>v.y)..x0v.y=v.y.w.y)..x1v.y)..x<v.y)..y<v.y)..x<v.yRich=v.y........................PE..d...%..e.........." ...$............................................................&y....`A........................................@...................`....`..x....Z..p .......... ...p.......................(......@............................................text............................... ..`.rdata..LT.......V..................@..@.data....+...0...&..................@....pdata..x....`.......@..............@..@.qtmetadq....p.......J..............@..P.rsrc...`............L..............@..@.reloc...............P..............@..B........................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):10075
                                                    Entropy (8bit):4.717439306063525
                                                    Encrypted:false
                                                    SSDEEP:192:KtcG6ZTxk/vxN5PpD5srxnITJ9T0CPnTfvTGeTfUTa:RG61AvxqgJ9pPTfLGSfka
                                                    MD5:5867D5245B718F84DB408F61BEF0586B
                                                    SHA1:1C6D4995807E1A4D4AA1C60AF5E21B1249428068
                                                    SHA-256:89DACB880798DE404343B7C7C601964EA9DB8C94C6D80E94488F16B4CB687A10
                                                    SHA-512:FBE6E03CD93AF72B090CA71BE170F7CC1247C367A6E535D1E6675A12ED504DDE248A0811B663B2650F847E89E731450C950D7492914BDE725B9BF12CA0AD0644
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3172
                                                    Entropy (8bit):4.857750127629911
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nC+OLqF9JXacl40XRJcynK:KogUldGcQWvVQ40X7cynK
                                                    MD5:D1F9F9211AA7FAE7F0D9579FC123D685
                                                    SHA1:62C23659B3A0447043BEB3C3965861574502E89B
                                                    SHA-256:5F8FB95DEE1242FA981C0201D82E0094880C88F98EBB7516D5F692A63CB64F8F
                                                    SHA-512:62948CCE34D7A31A411110ED0D024C61DD9A5372971266C749BD5344EBF92FE5C1ED8C7C67DC38E70DEE7E1DB2BE33234C3A55472EF1E9CA5539B287B878BA19
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4722
                                                    Entropy (8bit):4.806184277509732
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy99nC+r30n9Na8slfYe31ppELTGITqtguPcwfZY:KogUldGcQWg6Y8MpELTGITqtguPcwdCJ
                                                    MD5:2E42047FE47F5B070DC7C903C4E520FC
                                                    SHA1:C4D55119C4E613E0ED48833C232BF6445738E1F2
                                                    SHA-256:E30F2574809B4A3D6804CD6405FD56A1EB59F0EBD63FCCFADE27CC12E45C9EAA
                                                    SHA-512:78BE625E72816EBE760052EFFEE160717F77B388887161589E19D8B4BFB4FCA59D3797BCEABD0C3D71B315D68F24AB0D934EAD0A4DC36ECC485DF6187FD45831
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):14053
                                                    Entropy (8bit):4.631637955400076
                                                    Encrypted:false
                                                    SSDEEP:192:KtcGBf2NDPkWGQA/avHUMw42QsxsfwR2RH29hy7k0FXmFNMa:RGIGQA+2owR2RH2jbhD
                                                    MD5:8271AC3D4E6B5E7BF47DAE0FCF2B6276
                                                    SHA1:6A7E6A614EBCE44A0AFC940FCCD02C4B8EA6A3F2
                                                    SHA-256:D5BC343B79803DBB1F28E2A9E88614F07DB92D04ABBB2C87DF9A83DFF47FC021
                                                    SHA-512:F807C7E50FD158086737E33DD3C58F2395B0DD789C7A8BB322AF4E3A95382CFAAE33863B74B8A1D0BCDB6BDA246D62B00BC8EE0F0C7A5A17D3174A380BBA0921
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):7217
                                                    Entropy (8bit):4.730801636992161
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWMm9NQmNRDuvfQ5cQg0Q0xQMVbQohukHBQEuj82CcSFCrFo5M6F7AOb:KtcGtqOY5x7r+fpmcna5nAOm+wxK
                                                    MD5:CDCE4812D071C06C97A540E246768C75
                                                    SHA1:3F19A67F23AA2D6F65A7A132F1C697F72F01A9FE
                                                    SHA-256:C2972F85CA4BCF1D5F11364E46C297D70F611F43F7618FD7E77B421363E3A4BF
                                                    SHA-512:EC04F782D3E286A650CE68BAF546E70DE1813BBB5A561E4773D97FD1975ED87C76B1EFCC13FDA2AFB496E6D5217B9910FDE1BD97D6F09889EE1A25F0FCCF817A
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):26551
                                                    Entropy (8bit):4.512383919219007
                                                    Encrypted:false
                                                    SSDEEP:384:RG7v/WdaFXoAhPF4qPsTsrCUVUQtayvGH29w:RGz26Rw
                                                    MD5:14E14D914B7C5ACC5AFEBF0F8278AAF9
                                                    SHA1:D77E16C080ED950CD315490AED12C327AF35A16F
                                                    SHA-256:EC8D6D62031D1648DA0F7CF174E7FD707AF73CECAD3A7B1D53BB6FF06CEE6EED
                                                    SHA-512:1E670ABCD65DFE438206D4091BF323AE1AFDA9C2CB1BE6A491E4805DBEE75B72FDD4915A829B98C35CD11502A905FFC7EFF09A1E18545D0BAD16A2155B617BA3
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):9280
                                                    Entropy (8bit):4.5929490054621205
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWVmYoWPEdA+f2a0n0k9BdOwwjo2+tyS+YjdQ+f2gPAs5FWoMmun2g07:KtcGm4dy0+BojgYsxN5uqqjHNGp
                                                    MD5:F62F4F4EEBB6B58235389E671C884AC4
                                                    SHA1:A0CC6F3235A54B4F89A20AE2DE27AEE2F1D53730
                                                    SHA-256:123C647773D5D885A3DB2F5E5BBFB13B51F2C8869783CEB48D5F93CB0E3401E3
                                                    SHA-512:8BF61B9E37C41898216C0659AC728037D56925C4C7404D70B225767DD46F1A22EF7D4037A83E71BD2581B14304989ACBBA30D8BA03A1D71E69A643D6937D05A2
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3212
                                                    Entropy (8bit):4.839032765919857
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9bC+zb184zGdIdePevhTAhv:KogUldGcQWQb1pzESePuAhv
                                                    MD5:1B379BBC8E1523FEFE718627A99EB7D3
                                                    SHA1:35E8319E1C3B8E6294C8FA4A96BB222406973BAB
                                                    SHA-256:F29D6F9D351F71FCD906996C6A3379589333DB53E867278BD0FEDC6504A9AE4C
                                                    SHA-512:AFEF330B0EB7AAD230265EB5B752502E2472B50B1A2957E629D3E090A505384D87486786C2D3AE4CFF277099FC43D794C6024C4D6080C53FA7A29511D0FF4326
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5447
                                                    Entropy (8bit):4.706461728806631
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWRCCspEXP1hNgqjMbvpZOci9buA4KmFvZ:KtcGLCspEjNgqjwi9AKmFvZ
                                                    MD5:6DF072421B299327247E0E4042BCDD19
                                                    SHA1:49DD5B2A1E618FB66B97614D4B43E9AFADF5DE67
                                                    SHA-256:E0DF7E7BD642AA535E7FFD5C1B3EA3A1E201C80B554749B05483ABE322E623FB
                                                    SHA-512:2A75F81ACD054516F95395E1A738FB8CF33AE7A15C72AC73D4B0E0EAAE2DDBD1813FF7F000735C6BD7B886E926309251351F6FF2A19BA6E9761DABAA663FD6B0
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):13079
                                                    Entropy (8bit):4.3505082150816135
                                                    Encrypted:false
                                                    SSDEEP:192:KtcGwslIqMINp8BschTZglH52QuxWYgdpChQ6sEz:RG3HQ35GlSbQ6r
                                                    MD5:5893CD63CD0CF9808A8F0C08FF78B8D9
                                                    SHA1:7C1E9C22AF12A79435210F8F3A878A3FACA8FFB2
                                                    SHA-256:D00319C39C5D8ABA32D480E8A7543B7E9B2913951FE24037C5DC89EDF7F7B084
                                                    SHA-512:A856BD9EBC448067C7607C8CD44F60BE4371832277A00D015BF908B4A4FECCC2F8424479BFB6165AE28DD2A169B54E93B5433C83D1702A8991BBD33BB0E1A7F9
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):6050
                                                    Entropy (8bit):4.801017534733009
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nCflj2CJgwO7dri4vmQGRbAAQjhD6rYL6Kj3T:KogUldGcQWHgwVSFGp0V6r81yJHU7
                                                    MD5:2334B6238EACCB034D39A6AD6E1CD87C
                                                    SHA1:9B9899BC33AC4A9ABF0DA87918DD5EC04E086B09
                                                    SHA-256:F1EC6B3620B6EB0B3D435CE92607FC3E6A229716595938B5BA2E616B8FAD5BC8
                                                    SHA-512:B44AE6DF699AF67FFD8667E639E65723F346E03BE6AADFD994B93471063B965D80B87F292804E82089623CD42BC7EA9707B356627936FE71AC314F5E27CEAD3F
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):8298
                                                    Entropy (8bit):4.7170849721619685
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWLIUJAzsCGfYsgqjeSOOsTII0sRpzdz8oS15omcrp8otIkjXL:KtcG6IUgsC4HnjeSQTI618oq1MTD/
                                                    MD5:884A006ADD8AB89428F89D6393A691FA
                                                    SHA1:C9F0C601EF010D7381A876B976114ECD282358A0
                                                    SHA-256:1651BC9C0BCC321BFC1462D4DE6A51007DC933B159980646656E74B33CE239D7
                                                    SHA-512:A34041F8BF35C3E9AB425AEC096C7D3F66FF0D77AF211464E850FFEA6EBBDDB809C0ADDB73001E19C263EC9661EF7D5C3AC3B494ECDBC70E2F88A2B840130A54
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):33191
                                                    Entropy (8bit):4.2928888800036455
                                                    Encrypted:false
                                                    SSDEEP:384:RGX+HVCDtXjiS0NAiPKBwH5JwGJBZJI0UITLfnNJyXyTHwL5sP:RGX+uYtCLgLTw0
                                                    MD5:2A6FF6D69C3C8AEBAC0577EC495914AB
                                                    SHA1:1F53AA8E32F836D8EE37E9F93EA8C10BEBDA0CA0
                                                    SHA-256:D1C6F040CDDC78498D5FC7E2EE3B2A8AE94F1772F04AF77E2349F60BAF189329
                                                    SHA-512:E2EC07742A91FE3E2B4A9133C1FE2B6975975D315F7450A1D87B08D12A6EB092BD6DCCE19DAA04B809A1A7A1983C8E02725B7E19502F74984C0F989F451027B5
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3841
                                                    Entropy (8bit):4.861457775013162
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nKg9T+L0Dk1akEkg+kyk6kbk1WMue:KogUldGcQW4jKlF+7DQ3ue
                                                    MD5:E93DF9572C77F934688CB8B498820DD8
                                                    SHA1:CC7F75E4FC6C83F4922CE71708D1A8A1445E0BD7
                                                    SHA-256:F4EA2C35462F76B142231DC83B536B1F93F030379BE115BAA131934CAB4D8021
                                                    SHA-512:7436FE36D939A9864AA5C9A7604B281202CE51E149E4556D25030B9AEA73A3B145F81BFD3CC451A3FBF522708B1CA2EFC90E1B5B782B9E66C77F7C5042F439FC
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):9417
                                                    Entropy (8bit):4.628359677996762
                                                    Encrypted:false
                                                    SSDEEP:192:KtcGzp/zjz+D0MUSYbV9fklFtgY0skwhmiWWJ5nU1yZcyc1TJh1fGTr:RGas7T+UACztKr
                                                    MD5:7C237BFF401C547DC20DEFD84CD178B8
                                                    SHA1:35827C05C85DA283060D76F9F6531C3F418F574A
                                                    SHA-256:975BBC80DA2F1BD057F0FEBC8F4F2F4CBA730875F24F1DD1AB19AB9C1424144C
                                                    SHA-512:A60B8AB4C343B2F07DB426F6BB2085EF2D3CD5DFFDD35F6A6A7F25FCFC885B823B517FB32C841DB1ACE819EC245955ACE286D22F5BAA0FB338664BE332161830
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4611
                                                    Entropy (8bit):4.990010731789747
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWL9DiQOOWOaphP1+JIShNUtvme:KtcG8DIOWOQ9EeVV
                                                    MD5:B6B8F57D8DB0F00AA169DCEAFF7496E2
                                                    SHA1:9CBFC0A49DF3BF1B5D0FA4F19C085702A4730096
                                                    SHA-256:EABC8322BE26364621ABB055C8FC60567496F03283CCB29DF52282E5A9FC1CB2
                                                    SHA-512:70F59759BEF5C357B80D60CD0B0276A7E2168B939549B71EACC4A092EF20FA22FB957A1B248E5662D5E5324437D1F1B1AFF12D734D40BF503DC672094824154F
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3391
                                                    Entropy (8bit):4.835501223694417
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nUWBNFGjVjojFvJ6/Jh5jAMtXpiB4oCvhoJ:KogUldGcQW2BN4lkFxSjXgSe
                                                    MD5:C44B244C04F74D3A6AB99849BB974985
                                                    SHA1:342741FE993B9E723CCA3B4FE4BA8D5C7352164D
                                                    SHA-256:AE60C761D16DF1CFC3308DF1D600D5AED403B95377B56B870A5B08AF9FEE476A
                                                    SHA-512:AAD4EA8CC67B8F7559AEFA98930F60940B386094E6FFC879D01D02E2B9E3800E149661AEC72B513584C2C87A6860D5C909C7F86BD699004706B6E24F5FEA1727
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3383
                                                    Entropy (8bit):4.814159570683156
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nCAwomc8c3TiTCo6nPJo:KogUldGcQW6wom9kiTYO
                                                    MD5:B48053C0E232FDE426DAF51151B93DA9
                                                    SHA1:B981463D498E35D158630C2CF5DEF039F3D12621
                                                    SHA-256:46B63D90FF343644506D788C6EEEB99956F55A6CBE297DDD998FC7438196B968
                                                    SHA-512:6E7E9BBB3D4C5B4AC10BD188DCC9463E1A60A3617DED2DB0C808A68464C63F1A63B62EBF94BFB3BAC60DE58C55F3D903D3EF672E95A4769CA670F597FF94FF4A
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5989
                                                    Entropy (8bit):4.636882423408465
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWa40S3uK3eVoqtWo+DPLrHQLhFAP06iM1p8:KtcGBbF2MWT3HADAdiM1G
                                                    MD5:F65418D60C05CF3322ABAFC6FA1412CF
                                                    SHA1:E87102845BAF8FFC20C44C9F34CA2A5DA2E61735
                                                    SHA-256:076E471444B7A512D0D19F39B6DC836F7A50D5049059CB26A0AECCCCDEF55439
                                                    SHA-512:917BEE82351C03538A9AFC47C259FF84A3D93FC0114FE9002A62B65EB7ACAD1ABE50713D656231B65273114BAE5359C311CCC0894E0A1DC5C8824FEBE0F73E06
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):9830
                                                    Entropy (8bit):4.542740073103384
                                                    Encrypted:false
                                                    SSDEEP:192:KtcG4zlGrTY9cNJGBRNaTiN/spNYZ4N1/WbMXyJA/M:RG4xxmPcu/byB
                                                    MD5:AEDFA8AE1834BDAE1D4CF32BA070FFBF
                                                    SHA1:07C477570F131A70D1543C9E1D512B698BB05308
                                                    SHA-256:545DE8F164CA5F49EA73F7A08305FB12806BC7B2654FDD9B0B14C275BF743CF5
                                                    SHA-512:3FE310861519DA2C322F89B5D8C0B9A30F3FB52CB078506B156B9556E93B94CC89707BE6CC9393D6542D51971AD8D46E9B64980F6A72738FFDA168529E1D54C3
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2653
                                                    Entropy (8bit):4.881994442458163
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nC+umv3:KogUldGcQWdm3
                                                    MD5:CDD54D4C1D7F711CCF612B229D1745A4
                                                    SHA1:CE9ADDD7481FDE32A7357F63DCE50A2146CC9E0E
                                                    SHA-256:A4C6F0904FE3A42898A4A6B662491075AE5D10A820172058BF88CD156C733B2C
                                                    SHA-512:25DCA3A22B5C88CC03F4B596A35B6805BE4AA2F6628FEE8670C9FDC8601A826AC69A23080E8CCD3F2969AA9E1AFDFD6BE5D9FE7F0F492B5192A1E9C5F92E45EE
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2931
                                                    Entropy (8bit):4.824223917837498
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nCz5bMHq8PtBi:KogUldGcQWx0Xfi
                                                    MD5:2FEC5D0A5B310A979807837BFA9DDF3D
                                                    SHA1:7CED0A6AD47D373E5C78EE0B4B011716AD1069A7
                                                    SHA-256:F37EE6C81A402309CC49EB69A9500A41E79B4660EB8D8655E31D2EE6557143CE
                                                    SHA-512:16EF0B25088BCF3D80EE2EDFA2688C5F9906D1708FFD8401B258AE70D9DC16235C76C664053FD2A8E334F0477038B991EEFDA0D580B43E244988D30D832301D3
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):11186
                                                    Entropy (8bit):4.547609129759251
                                                    Encrypted:false
                                                    SSDEEP:192:KtcGyRxuSaHzzC/wft/dVoyTc7MgCSdVD0Czs4Yn3GgTf:RGyRI/3o+S1P0Cze3GIf
                                                    MD5:F6C3C649EF339F45202B8D39A6E526CF
                                                    SHA1:F8531CCF789D115E0F59BA075B8FAE8FF64DCD51
                                                    SHA-256:CD10E23812C99EB63FC34C226A8FA739AE4D2AD751BBC372DE37FE1D8EE553CB
                                                    SHA-512:3D0BC8C9B646A935E4D08C318A3A4001BE4F8F853A94D43C0F734D2CD37C7B53C19797B5F586D9177348CF7A9C462B2CD5DED579CEAEDBE4B8064FFE8311CADD
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3156
                                                    Entropy (8bit):4.80385659327207
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nCdJUDLo1IzviEX41+SkDZ:KogUldGcQWTJUDLo1QviCic
                                                    MD5:E23BE324C4489A0FC9ED575F105411AC
                                                    SHA1:E9C0A5F4A8785F924D05460D42567482DF4ECB41
                                                    SHA-256:C7EC54404C3168726BD8C84EDFCE0300139C4C8D0033DEDE6C75BDBF18330321
                                                    SHA-512:E14C2BEBB472481710B13DA3B0FA41C8DF7552C2DA7ABE20EF5CF53F2426D9C6ABF9C395F1D6AC9ABCA48C76EA726EE117BE6E407611E2B87A0839BF911BF866
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2220
                                                    Entropy (8bit):4.8311463753103085
                                                    Encrypted:false
                                                    SSDEEP:24:MLkjCT3QXf8WYwid0szM68qDRGNfFTNZbOWGf0HB+N7YiZTcfy9N739/tv:MLoO6E+iCshVKzlOWGf0hEVufy9l
                                                    MD5:C5840D0329592D5E734826BA47CAC90A
                                                    SHA1:1A5F1BBFE92A8CBF4A6CCE221A7BE6BA6C529222
                                                    SHA-256:76E7F170FE157C78E7D802DC0798CAFD749B5B550D2A3FDEB2699FBC9C0B09AB
                                                    SHA-512:F6079C21EC06A64C768B2E35622B320A825744E963531A7DED9DE5D5FD95E186ACF82CBA6202A602FD23594C5921A53EEA0CB2489A74995308F5689730B34F68
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4605
                                                    Entropy (8bit):4.758962867009659
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9EAj9+9X1y5nTcmdftkZJmFLC5ZXiRS:KogUldGcQW1AB+96Tc6t0JNES
                                                    MD5:A93883D509CFD30E02700670A6D534E8
                                                    SHA1:B38B28A3A31DEA74C18F22EBD8CBCFDCA2958A9D
                                                    SHA-256:AD226BFAF454E3FC1470DFDF487060BCC4CE87C6C1E04F9F41D3FEE2B163195E
                                                    SHA-512:ABD2A03D4DDBC98DD15936992F57F4C291E2967B7DF3C27641612FA261AB326652732DBE4C462E898893920A9CB8E4FB5FA50C7963B2BA8F1A29F3776D2F9277
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):9203
                                                    Entropy (8bit):4.547491093106234
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQW3v8IarAvLnsR2TRk48jWtoSa2HLTGXTdYyDPX2GeXtfTDiOx:KtcGAv8IaanB8jWe1YqXj7XCXBPiOx
                                                    MD5:37F19972A2D331B7A6F2F1ED209D800B
                                                    SHA1:71A7EEED3BFB6E9CEFD63AF76CB17E879297393B
                                                    SHA-256:0F5F51CFEE83E7BAB513F6AFF232958A54952D38D65FC6AB52D0A873BFEC8077
                                                    SHA-512:64AC782CF07889337B277E3135237FED690AEBD950DF0596F0AC1E12CD79FB557F3D0986DFDF4CAA445D864630616D3A3EA01734CE88A1466D1085A019A97258
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):9257
                                                    Entropy (8bit):4.675180698058861
                                                    Encrypted:false
                                                    SSDEEP:192:KtcGf7MaKztzp6B1T79nP0TfWwT5bFZCYEnmKTfQCT9JF:RGfYaKztzpMxPEfxBEmmfhd
                                                    MD5:BA2E9040C82CD7D1D469AC2CF886B64B
                                                    SHA1:FCD1B3B2B046E5F4BE358D10DB8AF5BDF2D56CD1
                                                    SHA-256:C850EE4F3A7AE41834700939CD159845D9BAB2DD3C15A1FBF0B8ECB658342DA1
                                                    SHA-512:E30E4D9044B3619773CEA1EF5B6C51AA049BDFBE2CB302A59AC1575EF795EE3ADC774506AE6DAC1E17FC4D88099E67AC5AB18E7722A420D09EF5FFECAEF94B42
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4873
                                                    Entropy (8bit):4.746641702829244
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWits1hEAMoFMZvf6Zn4k7uxoV0:KtcGdbXvf6ZR7uxoV0
                                                    MD5:C03EDAD44F38B6B0538360599C5762FD
                                                    SHA1:10DDBD689723D9811E03891D980D382E3366B5B3
                                                    SHA-256:3C335EBC60A60EBCEA3B2A468A341B2AF3935DF0AB88F108F517A6DDB1E4EE28
                                                    SHA-512:9DE80F57D8E8B33964508E95CE9D6863A27E3013CC8CF5CBEF9F6C219BCEC2FB8072164D2B7D7B7AB4A7CB7B669F6CEB0099410CB8FFF6E0CECDD4EA1308BE34
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4863
                                                    Entropy (8bit):4.434798897264616
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nZafoM1fI4B2+T/GnW+f4mf2+T/G5+uI433Fz:KogUldGcQWVI43k4+YI4nvC74Kvf6
                                                    MD5:B077A08FF6441BCB06AD98DCFA410D3C
                                                    SHA1:5229A1B8BFDEB3A0C7AFC2A104F24952D4622906
                                                    SHA-256:A1B5C975825B453C5A80F2C4969955C7C0AF5A71ABCB63AAC9FC1AB27D7BAA00
                                                    SHA-512:9E01B406542F54B64C061D1A915A26F8E4E878F58890B095C1505AC83553341A19437C1D178175EB5A3D54093756AC5C9609522AFA7AA559CB91BA0683442F62
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2266
                                                    Entropy (8bit):4.853909747945728
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nC+Qgz:KogUldGcQWiz
                                                    MD5:2A576BBA1CF11537E15C0200137B8201
                                                    SHA1:FA18251A1ADC02EC230E80F7AA9796C5813B0742
                                                    SHA-256:B18E9DE9FBD7B7CCA9AC08BAAD5216C695142CDFCC41B7CAF37D95CD48BC53AF
                                                    SHA-512:B961390C8A91269BEFD5FF71367ECFBE10E5D7D745716F32E7A168BE51FBEFFC1C8AB79ED7C23F3D9BCF142B4C74B8625530CDE4EE87D781F8FF3FB4DBF443D1
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3425
                                                    Entropy (8bit):4.8544567803873955
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufyyU51hdC7m9WYW9ujOn7u3sT0IOBXybv5Urx:KogUldGcQWCy7mWnqVH
                                                    MD5:4C1ADF18775AA9B85EA5E459596917AA
                                                    SHA1:CF899FFF3DBFCD0603C72788A630930949C3D6C0
                                                    SHA-256:E56F3BDCFD879C8693FAA9A279F059D93202CA17CA246D5D1A831CF00AF42080
                                                    SHA-512:582820E357405A831947F0B5A1991EB49C65D280FF4AA2F11008F703E55156D6A38019C61CE6C1B815B716A89B6DD054BD5EBBD0ECA6DEA03EBF8375DFEE2D88
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):12756
                                                    Entropy (8bit):4.426522592087365
                                                    Encrypted:false
                                                    SSDEEP:192:KtcGHOJLyyjiFX70aTrklQO6KaTYSY3E3XS/QoGmpGNlpP:RGPN70uy21UG0Gt
                                                    MD5:38F5465E469F1713C883D1D7AE1B0929
                                                    SHA1:6F2BCD3B11C9AE5D0A8BF3FDFCA854A022C6B555
                                                    SHA-256:D7F4B886C50DD7EA6A54EEF48C34650E5ACAFE303B332044D3162BA1D8E96399
                                                    SHA-512:F33BBF6278C21ABD4BA20AB3AFD6318CC6B5AC49BA06F49AFFCF077EDAA9462299249AC4DBE2C568EBA449FAF9EF084EF09FAB96D077A73184C363BAB389E2C5
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4634
                                                    Entropy (8bit):4.889581868279411
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufyBsa+HEMr8/AvWIzLoGIir7w/g5IY6XFdJ7vM/x:KogUldGcQWS1+FbQGDHj+Jvwx
                                                    MD5:B2649334F094FB84301CE7B4707FC55F
                                                    SHA1:5E098BD41BF4AA7061E078D25D462DCA67867489
                                                    SHA-256:F989CC52662928AD96F2695C927AE7A9030716D2B8B32A3558DE48A71F368053
                                                    SHA-512:7DC7E3553FBD4CD509DF29B7BEAF635320A0F014EA81B7A9732EE792F907126064D789A4C8529DE4AA893B2C764F26294F8B2B29EF93A6FEAC5B0C45401F8081
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):7164
                                                    Entropy (8bit):4.589750615977315
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQW+NDMfucOc96BB7EN3gkO6fGkbGVgiCU:KtcG7MGcOL7ggkONCU
                                                    MD5:F7D17922E90FEAB842FD6E278A6BD853
                                                    SHA1:D617BF6A5972CD510BB5E1C79F6D831A24B1EB91
                                                    SHA-256:ED1935591C3F9A63A3F6123839CE3A8B8869D0350849583EDDB6F075FFF8928F
                                                    SHA-512:F700C13E8857BCE965B2F9FF4035D9E4E97ABA821D5A71BD57D27C196386F26C18CED64F50AED726706F67048DBDBE8AC5D6C5E3700A13738FEC5BB1B2692008
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5192
                                                    Entropy (8bit):4.686492495072203
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQW1SekN7ZGZDwn1qDnr7av7wKOUl04GhfOYj1H:KtcG28NQxgcDnCjwpb4MfOYj1H
                                                    MD5:643BA5029A59F3E401A5DEFEA74299D2
                                                    SHA1:B3117B595D3A428584F4C2CCD512AB7EB9C090B8
                                                    SHA-256:5B7A9043C92CFCBC928579C1341524F034EAC837494FA420EDCA0498D50342F3
                                                    SHA-512:6F2005F598D2EAF55CDC81DD7C56C0BA976DFC9312358892E97619BEF4979554C78C32BF93E9A8254A1E590E398D17440B88F59D1B465E8CD6EB600F245140E0
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):8229
                                                    Entropy (8bit):4.711477100285126
                                                    Encrypted:false
                                                    SSDEEP:192:KtcGMBMlXSJIMr4yCIPMDOhTBoSdAOZM+k+IFMgolRk+ysMzFM1:RGEr4m0DOHw+Q6DRqtz61
                                                    MD5:8AAAB13E4EA785CDDA42AABAC77A957B
                                                    SHA1:B130F63A5D72EAA05FAF08F2B1E8DF7A8B0479D0
                                                    SHA-256:28C45A87F5CCEB7AC9DEFFD6910FB1E1563E0B2FA3E34913D3B6BD3B00C5FB89
                                                    SHA-512:5E3891871B528D18A199759ABB1F9AD1B3A1FA382CC2EDD54F010E64C827BC7567C19DECA7EE51D15A23EFB3400FEA48C5BD6EC0E6DBE38189301D8837B202F4
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2020
                                                    Entropy (8bit):4.825477059078544
                                                    Encrypted:false
                                                    SSDEEP:24:MLkjCT3QXf8WYwid0szM68qDRGNfFTNZbOWGf0HB+N7YiZTcfyyUNH:MLoO6E+iCshVKzlOWGf0hEVufyyU5
                                                    MD5:5BE64BA656B8F7A0957290F889A5D88B
                                                    SHA1:B3470BF3AF63162BCF67C9AAE70E28A60CFBC764
                                                    SHA-256:8649D411DB1A6BD02AE63076A2FE2B1050BAF64ABACBA958930C3E52ECF1988F
                                                    SHA-512:16C44A545A27ED81E7ABE679A3EB4EF4AFE51A43A846D30C99901F5416F4AA7AD925E2AA751B12D4010EB87E6282070A9F04B0500613022E16F793C45FE02994
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4615
                                                    Entropy (8bit):4.792962273105971
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWPItn8Uqhc+B6oIv4Lw69CS1TGITr:KtcGIItn8UqZYoPwHS1TGITr
                                                    MD5:7F1C253C812495BEB83825E770966804
                                                    SHA1:000D0206442A313567180763C1E043CF43DFCC50
                                                    SHA-256:7A136915B179CC75F952D1E57B622216AC884295E085AECC087D3923F5B5B0BA
                                                    SHA-512:AE23CC99F14290431A54AA2719ED23BEB8A3B38C65CB16AB6283B3BC9BFB758B57AF01E354E680C15A5DEC2CB6C6A7489C636D6C4351316AADDC8836922AE2ED
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5059
                                                    Entropy (8bit):4.915575384873494
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufyBsa+HEMG+xuKsO24XX5RZr7w/g5IY6XFJ3zNZZ:KogUldGcQWS1+vsO7/HjkzN/SCD/
                                                    MD5:4A787B69613503A130A393BF4067FA58
                                                    SHA1:680DAF095DFB6C1A5A20129C8DEC093AD95A89CA
                                                    SHA-256:E8E098A622B41C091528F61C611FDBFEF52C9DC50C324C3591B2E86FB21384FC
                                                    SHA-512:B42E175DC1FA94475DD6CEDAE113CD794AA269D58F8BD4F193C4128CCD62B38002A1DF9C50C1182AEF11DCD3B0066FDD300FFDA7FB29E4231F132F3083B9CB5F
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):1486
                                                    Entropy (8bit):4.931489821141917
                                                    Encrypted:false
                                                    SSDEEP:24:GrvV/3OPO+Nv3ASPJbNErXSaLpua0p5IWCIR5JkAUnA4H461yWIBlEvz:Grd4Nv3BPJbNEriaLpua0p66R5JJUASl
                                                    MD5:20AB7D17BE48C20278D09CC12F7626E8
                                                    SHA1:74CFB09A1A59EE6D4E603EA1760268D9D99635B7
                                                    SHA-256:FA434686F6ABC72813F1285A2FE12DDCFF0F197ED719EF2B1557681DF739FFEC
                                                    SHA-512:5AF68D6A6843E8E4B4C6D2CA2C30AAC571D68C6E82B56BFF74DC58C486B9AD27264E2C4CF80766124CBC61AF084992E787F6E50F1CA1095054B4EF5395CFDD9F
                                                    Malicious:false
                                                    Preview:module QtQuick.Controls.Private..AbstractCheckable 1.0 AbstractCheckable.qml..CalendarHeaderModel 1.0 CalendarHeaderModel.qml..Control 1.0 Control.qml..CalendarUtils 1.0 CalendarUtils.js..FocusFrame 1.0 FocusFrame.qml..Margins 1.0 Margins.qml..BasicButton 1.0 BasicButton.qml..ScrollBar 1.0 ScrollBar.qml..ScrollViewHelper 1.0 ScrollViewHelper.qml..Style 1.0 Style.qml..MenuItemSubControls 1.0 MenuItemSubControls.qml..TabBar 1.0 TabBar.qml..StackViewSlideDelegate 1.0 StackViewSlideDelegate.qml..StyleHelpers 1.0 style.js..JSArray 1.0 StackView.js..TableViewSelection 1.0 TableViewSelection.qml..FastGlow 1.0 FastGlow.qml..SourceProxy 1.0 SourceProxy.qml..GroupBoxStyle 1.0 ../Styles/Base/GroupBoxStyle.qml..FocusFrameStyle 1.0 ../Styles/Base/FocusFrameStyle.qml..ToolButtonStyle 1.0 ../Styles/Base/ToolButtonStyle.qml..MenuContentItem 1.0 MenuContentItem.qml..MenuContentScroller 1.0 MenuContentScroller.qml..ColumnMenuContent 1.0 ColumnMenuContent.qml..ContentItem 1.0 ContentItem.qml..HoverButton
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5692
                                                    Entropy (8bit):4.738243897802114
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWWRmW0U4U92YDF1DqkWtZH3WKzMff2sKpJW2yugqN:KtcGb0U41AFdqFFWrsgqN
                                                    MD5:1C2CBE26335E931645073DEBD61D9DB9
                                                    SHA1:31538AACA44E1E1ABB2E79897B5B5E6064142618
                                                    SHA-256:4F35BC6258A283B250AC45BEFA9C6D69C49EAF4805D24AA987DE6F84A4D73E91
                                                    SHA-512:CE95B37DA7DD8C76C226D6691D2A43FD2F1B21873C5FFF3E69857A608EEF4ECA6D56948C34E9F6A7B6CC289FACD12DEBEF602C1AA57697619D0FED94B9B70F49
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3653
                                                    Entropy (8bit):4.812422684711833
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nC+2S1+B+bnnpRU0qiAVXGYqFgZ:KogUldGcQW5EdnDU0qio2XFgZ
                                                    MD5:1DDD77CF9A6DA009A4511D17632747FE
                                                    SHA1:FCADCAD31CC89DC9796267F0494A259F3F9857BF
                                                    SHA-256:69751BF1401CD0275F1269A3FF1245E94C9AB6094B51442E84A0761742D12724
                                                    SHA-512:EB9649EEADF38F04E96E7D0E1190A4449E9CB32F245CA190689641072EA5327C7603D482C8B40C845D4017619F3E34490B1FEDC9E96E0C8DC3A8ABC9A072FF61
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):14604
                                                    Entropy (8bit):4.5894561555109235
                                                    Encrypted:false
                                                    SSDEEP:192:KtcGyKQr880auOa7pNgj4UTmaTq8HBdY9tZ0uhlLt/2YfU:RG9oupCj4km2qIqPlLt/2n
                                                    MD5:14139C1D76D6FDC43BC9CE0626FD75E4
                                                    SHA1:5C9850B3CCBEB8BF0C0EC8C2AE8AE6CC117D33CF
                                                    SHA-256:5085D56222BC970808FECA1CA1634B095C2C6CCD6691F693C1EBAD2AB7EE030C
                                                    SHA-512:CE2680818E338F2E1188E50BB22320C666575DCE39B363830E558DB13EABBC8F46859821C2BFC7F6462EF6CAA187C947BC440072FDB32F4BB6B6843BD24E7824
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):12350
                                                    Entropy (8bit):4.692219470832445
                                                    Encrypted:false
                                                    SSDEEP:192:KtcGqTQlTeEDUlMQ/68WVy4yub3soZhIr/TozrTNVugO:RGWQbOQjconInx
                                                    MD5:364F1C55898244523A4CFC7A5A47E28D
                                                    SHA1:00BE015B1A64880302134B2F852A63D8803CB0A6
                                                    SHA-256:3D8119887B0309D80DD4940BD8A70D1D21561EC0DB1C8AA09F3C295889C7F825
                                                    SHA-512:9EDEA941D5DEB32ACE2149D4DBC342AB6AD95D04A01D4D4BA3C223ECDEAFFCD2917CA6F7ED209EE55D3150E9CE30B84D1CCE0CC5CF369BC0338D23906D2FA19F
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):13281
                                                    Entropy (8bit):4.736074961181643
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWUmDva2s68LsBaPsBaSDYacjm2cjmnMSnjz25tik/8NPIHZulFJfLjr:KtcGuSs6S3HCmhmnKcQIP+mZKFASRMJL
                                                    MD5:AFEC2D213C2C7C3A6B84B499A5CA2FB9
                                                    SHA1:DBC8ABED5CCE2D94519C8AA29C7CFA74D5D5A0E4
                                                    SHA-256:61A59126588ED9D0A2AB0B769D618D6E346861DA8E955624BE3809524E81117F
                                                    SHA-512:0BE1CC72A36954B72ED2D46663807F3936A5C45D2968662B4F8CE7652569797C08C25C36F50E88040361169BC609E3EBC1116EF802113F7341D3DEA095BABFBD
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):25742
                                                    Entropy (8bit):4.445756629003457
                                                    Encrypted:false
                                                    SSDEEP:384:RGhwQLn6eY4Hx6IG+h4gaZAhaWQ0DbhbhdbfFLnLMg:RGWQLnbY4Hx6IG+h4qwWFPb4g
                                                    MD5:0A46072C68E120C0E63205F062D93D43
                                                    SHA1:115B66F2445640F54AADE7B9093878B36AF01940
                                                    SHA-256:B500378FA65BE77A0F08FE26B771789D902591B0E46908B43B7AAAC80CE91788
                                                    SHA-512:752AF4B2438DD3B711739A7AF7A7CB922A6E072CF3385087B9BDF7F9CCDB7F8D74333B8C5ACE4E0B92542488977FAB90ABB60138540B3FCA30BB7AFCD5884F99
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):43458
                                                    Entropy (8bit):4.500096685351172
                                                    Encrypted:false
                                                    SSDEEP:384:RGL8UhiLrV6Zgk+bXhhfotIELfOYmcOklcCDmK51ZlShKoXL552LPvL0rZUawrez:RGLnMFk+bXLfpEBmK7Z8prZUawFSnv
                                                    MD5:D8F78DED9D75F939807CD0219DCD15EC
                                                    SHA1:AE9A0A606FC415E2CB4C330CB7912578C30C8021
                                                    SHA-256:57151175AAC70463274ABCCBCF3E57E08BD4CC6E7C4BD96E3646D03D7C50766E
                                                    SHA-512:502639C3352AF3038F68E6E2DFD81027CCA3610DDD69E75A7D08AFCD023F867C09786CCED13207B24555D10204B7DB27F411A5713844FE68C96138D791307A9B
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3701
                                                    Entropy (8bit):4.770409858757474
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9dpBWeHQEJn1ULlMybLv:KogUldGcQWWW7EXJyv
                                                    MD5:74F5F0AFB5AD03CEE193AB7E63D8B0BB
                                                    SHA1:F0A2C5F9D0BE87760E13C6B0C2460F00731B482F
                                                    SHA-256:6935F441CC0FABE51F102F47495F61ADCED2A31C588A9C1C6D03620C940A0B3F
                                                    SHA-512:E1BDF0F9371AC2C88A9BA9EB521BE892D1F2B2A957F12710261C64B7E827906E597094ABFE06421BF2967725313123842A88A0F055C95C53AFEB8DED8D0A8480
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2535
                                                    Entropy (8bit):4.789416818924003
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy93ZNJGJLB9:KogUldGcQWfNH
                                                    MD5:51D8B8E0D66D80736E6B6A0753BABC82
                                                    SHA1:5BF685996E4DF8BDD9362047EBC9FCEA7ABAD68B
                                                    SHA-256:14E65632333ED9FE15D87E138122E76CB942D5E4E0F58776EBA26CDB73953E06
                                                    SHA-512:85DFF4D5367C4DFE0CA6969C8C0071B9550505FB813AAEAACD432E2B14F99D733962CC7E2F04F4C1C3870870F193EAED6ABCF826F3E3B4F1056A82D9163E7F45
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):6358
                                                    Entropy (8bit):4.63207579935174
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWdVBuWr3myXxjNcrt/k+2Ed9+f2TqUxr6+LnfMmunh+w:KtcGYhr3miNcryg0MHgX+w
                                                    MD5:6299E07B7905A742CCC2894C4788E9CE
                                                    SHA1:BB9EF4D0BD655ED6B1F93C9973B66FD6C6D3D08B
                                                    SHA-256:A4200159ADA2879FF39D94ADA52C64E5D910DC7B3753438E8F9304BD3DD71A2B
                                                    SHA-512:640C6579DA6DD05E1ED899E07A8E8694A761254C6EBC398E04328B4A38445EE03E315F148311DB27E791C4A7EDB268FF3D91793EC43EA548893CA63809DA97B3
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5195
                                                    Entropy (8bit):4.666594294196223
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWCS3sdszCOf/6VtUjMlljMaH0vJ5jMaH0vGVjMaH0vA:KtcGRS3sdsGx6j6jP07jP0uVjP0I
                                                    MD5:DE60DA37658B3737154C69D264F2A414
                                                    SHA1:A3E96470B5F9F179F7086009E6EAC4F0DBD15BB0
                                                    SHA-256:5A667DA03B77D4EF01D9A9BF9DCA168645E102B1147678741892B8E785EA6C54
                                                    SHA-512:5C5C807F5800E29A8DDD9BE4C29C852DA1DCAB0FA313C107444F15A0B25927A622CCD952646D3D08230ECD699888FAE5AFE4146ABB4FA4ED3C811661775EF099
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):6586
                                                    Entropy (8bit):4.829492368514061
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWOsSehCnFssypmbzCjaq418gbQC:KtcG+OywmO9
                                                    MD5:9A43A9C39DD8DC02F2706DC47397CFEF
                                                    SHA1:DC9243A378F713EC44D95237DA4AB6F2EC69034C
                                                    SHA-256:D02446470BA5CD51E390EE1B6F78080942B09974AD089088975795B55CE59DCF
                                                    SHA-512:B60B7EBB41170948606C009CDB41B69C16A74E019FE8FA454B687284CAFC43548C9CE603D2C64BFABBEA536310137D4D4EB620EEF0D0481568698334402B1731
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4455
                                                    Entropy (8bit):4.65121218543489
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nC+rSotC1acVZ3GthgOrwcax09uW/oXjtfZO:KogUldGcQWwScMcQOr3aSboTt4
                                                    MD5:8CF3BDEB2ACB695085D110A67EF7979C
                                                    SHA1:DCBCEAAE55E3D35C5B12828801796ECE274EE773
                                                    SHA-256:88CC52B50EC90FB8DB6DD1CBA81992F329DDF4E2E2438742B6F68C7EE5EEF803
                                                    SHA-512:8931D41A58DA4496D95F3FCA73D8F9A3BB48B62F89FC0727E60D4AFE863027EF34605A8DAAD594E4A2EFD238B9A908ABB7CE57A967AA71115BB318DEB15BEDA3
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):6821
                                                    Entropy (8bit):4.653671475027472
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWl/SrB6D/0ka6G5MXv4+WENtyPqd9+DsSAT/l:KtcGMSrY/0p50GEiSd9+Dsbp
                                                    MD5:C19019451C36D69BCEA15735A5C6E0C3
                                                    SHA1:408F85FA900909FCD74F4487FDFF7E5F731D8496
                                                    SHA-256:E3C05BF3247AE047991D05BD87C9FD8FD282BFA65371E8A36DDF3DEAB5C97FDE
                                                    SHA-512:157FEE38A3E9A32B29347F6CEA19438526A527918BB2CBA7AD3F1AE1FAB07F24059D0B22F80A5131563114008609B510345F63FC50D8235E6096B83183682CEF
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):30093
                                                    Entropy (8bit):4.072348356345042
                                                    Encrypted:false
                                                    SSDEEP:384:RGfLbfssWu9Vbt7xE9pZyj79vSEWO8l0bdAF1KQF3ZW:RGzVVpxE9pZAxVh
                                                    MD5:D23B1165EAD1E7BA0C3E9B029FC9E821
                                                    SHA1:7198E9B32A96C1A51E9A9B4E926EF6A967329CC5
                                                    SHA-256:F36EC8A4ED40596A341E7017FBF13635091E8FA8AC8F509721706A9DC47162D2
                                                    SHA-512:F7C8872C9B34E8FE04678C57D79C026EC6FE4E83FD44BC0CEF950D5DB960DC4AFACA4AE95D2D233FC2C887E594CF349BB3E1B0971191D22EBB550F02DC183C47
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):7275
                                                    Entropy (8bit):4.597937185580846
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWa/SubfmjxiSPM/S7n2iCZJ/49+DYAd/Beg:KtcGVSwBBSr2iK49+DxDeg
                                                    MD5:DAE47DA5A7E22AA82B3E22F17A99F0CC
                                                    SHA1:90C208B5A84BC44C2D9DDF09FF8A6803F0650368
                                                    SHA-256:4CAFEE3390640EBDBC9BFC21BBD55D63905B5C293237EE0B5FCD2596D875A4AE
                                                    SHA-512:F61F1FB74F306A47F05048A78ADFBB67B27C69F15D8CE8CA8324F4248AEAF1B41783F46A06182DD129AEEFFB74190745751FA6BDAA2A7AEA76C31F12AC15824A
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3387
                                                    Entropy (8bit):4.843527940418129
                                                    Encrypted:false
                                                    SSDEEP:48:MLBO6E+iCshVKzlOWGf0hEVufy9nGxGlDSbNajeItbiHoWd:KBgUldGcQWxbNieIwHR
                                                    MD5:8717284E7E0792578D0C07FDA27CBF23
                                                    SHA1:233513A280E3C66FFE5DFDD69ED4107B4C21E9ED
                                                    SHA-256:C230F37E94B347033B9B1D230D81D2DB5F489B68DB7E776185FD6FF1569758AE
                                                    SHA-512:9A59DC02A2109DB9733A26A4E0172D81E35DBD7A0B6E904309671CCC603A65D6AEFD65BC799B3E9D6F6B777922E52CBA14777CA800A6D38402E7FA77CE8A5CC7
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):18599
                                                    Entropy (8bit):4.600615740536773
                                                    Encrypted:false
                                                    SSDEEP:192:KicG3STU3ybV3l9xvd3Es2BZD9PU+s2BZD9WmzKIOQMdLhI3sqfZT3pMm7pS0jKL:4GiOybV3pvGTtiQfOlZucMl3ykFM
                                                    MD5:1E92C54FA7DF591A934D8CC08B4CFBDC
                                                    SHA1:DC59038010B9F618EEDB763B92E84DCE498E956C
                                                    SHA-256:5DDD459D0E56F42672CA239B5EDD9650AB442B5F9D62105BDA19790B22088209
                                                    SHA-512:FF0ABFC326137546EC76E4C80068B4C9658941FFDC7A2FEEFFDA717D15F787D148B28A8CD1BE56585DCE4D11736DC6CB7F01ED4246158FFE0238655841963095
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):13701
                                                    Entropy (8bit):4.405540423788938
                                                    Encrypted:false
                                                    SSDEEP:192:KicGJwTavAQY/9eQTy6ig/uKi/OJzU7A4gUcvoaMZ:4G+//bhigkozUknk
                                                    MD5:77AB0B21EECAB36BFB4D322854CF7F43
                                                    SHA1:594B85BE5FC922B89C114B258E11D9E42C9620E6
                                                    SHA-256:7E582CA7BAD41DBFF72E53F821FE6C5F92B619A883CA567386D08A2A692195FA
                                                    SHA-512:FBABB02AFE10ACD4CCB9303AC70B3D22FE97BE3EC6CDF1099E35924676FBF70C0BEC4860BE8113D228C1A3B4A06AFE7EC9474D4C426075CA237E1AF8518830B5
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):12375
                                                    Entropy (8bit):4.601679376476698
                                                    Encrypted:false
                                                    SSDEEP:192:KtcGqSNWa0XKg5gzwCpjfVEsxd9CDMISxvTwg+v1COCNoOCOCc4:RGlGXKg5gMUfxd99Rw
                                                    MD5:0D5F83CE30836BE4CBDBA1B5B0FA77B5
                                                    SHA1:D8169FF72B8D0B64E81EE10EED5342B95259B0E1
                                                    SHA-256:7EDDA00F6848787DB4BD38A04418D2F99ABA26D4296AFD67A3F67ABEC30C4949
                                                    SHA-512:1ED61C158622739CFD6CDBE79F2162884DB920FC01E5D733ECB8AE1166167B65355538AE7237BBEC029C1F6D6267350E40E1723441FD70BB0E2136817EF58659
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2688
                                                    Entropy (8bit):4.94846948198866
                                                    Encrypted:false
                                                    SSDEEP:48:MLBO6E+iCshVKzlOWGf0hEVufy9ZsV9hF1tgyTbb9f9IK:KBgUldGcQWX9JtgubR9
                                                    MD5:8FDB08DC6713B34EB276C2FC503CC84E
                                                    SHA1:5CCCC4CB7AF003671B694BB3C3CB2D75744B6EE0
                                                    SHA-256:75FEB7954038FC605A7A111592C16B83286716E4FD509615FDDC2419FA7AD98E
                                                    SHA-512:F17C7EF0A50A4843B2A645069E67966266EC134EE5CEF4C41B2790DB9EDC44C3E815639395A7046B8A5E297BE083AA0F83B7FEF0A7333B43FD77FB3D10015752
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):7477
                                                    Entropy (8bit):4.457964454713401
                                                    Encrypted:false
                                                    SSDEEP:192:KicGAS+yVHrMW1TmEmCrFUCz8Itym6kDQbp:4GDRBr3mEmC5VyvF
                                                    MD5:DD14E449040774CF0F8C297ADA0BB230
                                                    SHA1:33FF12A501046315450A488B3CFA9C360D7F766D
                                                    SHA-256:734198AE9B68B20931073ECEC580B3924006A40212A397A26854ACBA3C60D08E
                                                    SHA-512:E984BE5ECEA7260D68AE277C0A6F7EA5252B881B5B9195D0FF7BA7A7530E0691A77FC9A6A5FD9158B3D2D3706FDDE2D4C2B9A64A6607B7CB51D7C017CB9199C9
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):13309
                                                    Entropy (8bit):4.641284565398556
                                                    Encrypted:false
                                                    SSDEEP:192:KicGjStkxvChpI1QjdAfKRhqfIWvw6/aJCiD2pp5opxj86L8PbWv+IzU:4GGAvn1c2SviE6/pkjfvS
                                                    MD5:C9ECBD290C4D4AF10D1F16652064D786
                                                    SHA1:7C967C254D293CC4D2ED5667053C02762A7F466B
                                                    SHA-256:68D38C22B76E28D994B587A9EDDADCDF87682A0F2678551FE67B68C737107B4E
                                                    SHA-512:A1887E899BA983050F84882F4BE70CAF055F4F945E7A7A91E864CCA95A55EB25B15DD4E97CDC2F7846A38D3994F23DE7323947B9AE50C7CCB5B063105AFCF670
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2195
                                                    Entropy (8bit):4.860641581432451
                                                    Encrypted:false
                                                    SSDEEP:24:MLkjCT3QXf8WYwid0szM68qDRGNfFTNZbOWGf0HB+N7YiZTcfy9N9C2RE3P/z:MLoO6E+iCshVKzlOWGf0hEVufy9nC+2
                                                    MD5:AD01AD6DE4CC26FA4270567AC67899BD
                                                    SHA1:4504EBA68FECEB61AE5805AF8FCC9E8F46813368
                                                    SHA-256:4A6FDFC1C81341D6B4127DD76CF30A46CDF1EA080156327C641D93659AD10E4B
                                                    SHA-512:CC463C14BB9B6321B9E0B3B5F9864CA29E5899D8054CFDFA2458AB3FA5005F470EEBCD87FF3278718D1CC7E15C0184C81776D3C650CF9A0A49F2D209B998AA3E
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):22836
                                                    Entropy (8bit):4.299447926284382
                                                    Encrypted:false
                                                    SSDEEP:192:KicGzSPBjuH5kOOqqOipbNpymTjDIkE6ypij2RsDPjdBfNDL9+:4GW0gJ4EdEdYjho
                                                    MD5:7C3C99E2E1F2D6D7AA20BCEE398DA6E5
                                                    SHA1:146F9AEC406A1C8921608C42399BB8F07D5A4F95
                                                    SHA-256:47720FB3600A64E782D23C316B88E2A0B8C04DDB4145C4F3FC715C88E5C4AC58
                                                    SHA-512:578F5B75B7227138994066997E79A0DA7473172220975AC9298C58CB4CAA6C32DE484AB8A01235F374C80882B85D114324D7AAD20F17BBFB417EAADA4C5E3CD6
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4956
                                                    Entropy (8bit):4.6040064729782575
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nC+/GZg3EQ4UWgqk3DJCHB0YpD+0mXkupan9N:KogUldGcQWgG++KvzJu0O+pkXol+1
                                                    MD5:551C67724C444056F370802198A7E5E9
                                                    SHA1:E87F2AF2D3DB8407A3E467B613191C9C268FBB41
                                                    SHA-256:A87CAD5B0BA3FE0E67F183EE47F33B0F92E733ED3150821C0DE76D8AD7A3D664
                                                    SHA-512:7CE6B704CE5B36EB2A88ECB77CD86EADEB9E6B579412E657FA94764B04E2BA4E9F006B0089DE1A4587DD925F9130DD4358541FF40E26922F369FDCC06FE72B48
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2849
                                                    Entropy (8bit):4.799975439686825
                                                    Encrypted:false
                                                    SSDEEP:48:MLBO6E+iCshVKzlOWGf0hEVufy9nfAerCvgC/5qs4pn:KBgUldGcQWXLA
                                                    MD5:4F524B56A3AB03D69866D757F7789BFE
                                                    SHA1:18329971CC6F7DFD0620FABCB68EB5A14C3D385F
                                                    SHA-256:0C49EED4E013CD6D921A73A362AE0B49288C91377CB1A6FD1D9A3C1A79DB78D0
                                                    SHA-512:67D1E2D8E1AF463C850B672121970489A9FB19C6E1ECEC278FE7D40FE8057EE6598B2CE87DB9F1B11D633863E704C17C1F8CDB5E360D040AE3842008208DC3AA
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3955
                                                    Entropy (8bit):4.902843047893749
                                                    Encrypted:false
                                                    SSDEEP:48:MLBO6E+iCshVKzlOWGf0hEVufy91Bbyx4leoEB5wPCLXmic0uV5llN7Dmic0T:KBgUldGcQW4Bbveoa5wPKc5B7DT
                                                    MD5:518B479E244913265C2805AA261295E7
                                                    SHA1:6CC7C85DED85CBD12067D469040FE356FE905147
                                                    SHA-256:08B3432BCA020144EEE63A8EBA54FCD9DE6ABAD39368E316EA5EB3F627E8C113
                                                    SHA-512:D1C05E98F2615F6245767CC03D8368FE605AE50DDBD19C3F3DFE894BE26ADDB4844944B7207B417172DFEC561FD2EBED02E4B52199A414C31BF63525ED6E5FBB
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5266
                                                    Entropy (8bit):4.7800368857594115
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWLSSQ7FUtyV0zZnr64Hlvsy3A:KtcG8Sp74y+zZ79w
                                                    MD5:72E9D9E9FC99FA5DE5157CB65CAB7F49
                                                    SHA1:8D973BE620F3BB6DCE39165DE53C2791907A8D14
                                                    SHA-256:10B0380B7358DC7AD70A5DA292BEE8278A7171249C8E6B64DDDBDC4D64D6885A
                                                    SHA-512:76AFF6AB7DE904EC73CC05DBFD7B76992CC0051BBF5CAC563883C6D29C4BAE47D21BD5B11063D2292B06772BE55D7C7974E698A155931FAF403C30471C5A0CE3
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):19028
                                                    Entropy (8bit):4.517836433157375
                                                    Encrypted:false
                                                    SSDEEP:384:RG3wzT7/U9hj3mJx81JDleATgJxKmgGTuNBb6v:RGgzT7/U9hjjeAEJxJ
                                                    MD5:FFAAC9E0AA74D8288693E93C3D535183
                                                    SHA1:0D8F124B31CC2CD66B769A0B462C3C95D7F6E7C3
                                                    SHA-256:89F8F0FC50908E19EC2ECFD39AC53663E95488812E8B05966184E25B1139DF11
                                                    SHA-512:B269B9F9B6143835A6F2A8B36C3560C545C8AAD6933792714765EB9ACFC38A2240ED660832338613F836B5B7A27814B0839BAD433D6259E0D6030C56EB3DE06B
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):13619
                                                    Entropy (8bit):4.526104451067634
                                                    Encrypted:false
                                                    SSDEEP:192:KicGPST7AttX6JwMo4n2j6CMFnA0HxogPyXccLZV1TSSEZE2qdBQBKk3ThdR:4G6HxfVRJWX1TSSEZEpBQBKc
                                                    MD5:4331645D90F0E38D2486BB5B2C1E402C
                                                    SHA1:BD5548BF8894E5BD20253A691E756A4702CAB0C1
                                                    SHA-256:2E181DDA4E3BE6B21B5141C7B235E93FB25EAA54D21FB3038BBF861C9B445306
                                                    SHA-512:D1337FB0148808E24FF0BC9AEADDAC4837428DB896830A7092078B128B5968DE59E4CB7244AC28632F63540FCA821872F526B23CBC778624DABAB81B6E981346
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):9671
                                                    Entropy (8bit):4.398147008349299
                                                    Encrypted:false
                                                    SSDEEP:192:KtcGfSf6PYKu6KmdxGjeSunJPqvGeOuJ41jHkPx:RGKygzinJPex
                                                    MD5:C29EDE2738CBEB5AFCF438CCB0AC5D0A
                                                    SHA1:D71DEB3F6FB577FABCA903C22EDEFCE9082EB284
                                                    SHA-256:D3FAAFA6630BCD03E81DDE2D87486CBCD0C4A5B20785C74342F37E002B65A2AF
                                                    SHA-512:8D6E88B5B1AAFA8558C17E365F95C51C0E063D6DEE1ED12BC864B3AC5D370F4AFAC71A20F16751AAF130C991D57F9295B567AD7618FE87FAA7C3EF57202374F9
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):6421
                                                    Entropy (8bit):4.608996006455668
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWW/SYUpuj3wPSmnEJqZJ/49kGAd/dR:KtcG9SBE8xnEJy49knrR
                                                    MD5:D03303AF79AE603CFBE6876482F053A8
                                                    SHA1:C8F44F484B05C75B8D081B89BEA1703BC9713E99
                                                    SHA-256:A5A0081052F3AE4C8D97472CA1AD6AD67E8C4A05758143CB18CA8E99114DFBAA
                                                    SHA-512:BDCED49DFE5E8F6C9DD00C432EEB5643C81352ADD3698D683AC9AB2440C4942941DFAA253BFB9C492A4B8BBD7E5D9C5A75A046B88931552218565AF0E4D154C1
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):17548
                                                    Entropy (8bit):4.574607698856005
                                                    Encrypted:false
                                                    SSDEEP:192:KtcGfSi2rZovoKAZCv8pbLGoTR9uDHmnuwPxmEaTjQe0RJ6jGHE:RGKVUlAZs8pJR9uDHi14TjQHRZE
                                                    MD5:96833FE6D42FC67244982F05C244788B
                                                    SHA1:0469818E36FEF3B4F009E7AA79A3BFC183817B35
                                                    SHA-256:8E89154CBF7946D7655149B7F6AED77528C95A88F3F7677C2D1579DF9A3DBDF8
                                                    SHA-512:F5D2A22D5621DB4E7DE9CA005801A16507C8271568F8F9950B04E76CF48BDB159854854071E05FB727BB96ADD1D927C6290C7E8C7107516A872F58F0315282ED
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):9011
                                                    Entropy (8bit):4.524730875753044
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWw/S1DvNkmF0vPwkGO+YCd19MznVXwznoaHFl4a3PkaCAc0rJ15o:KtcGpS17qPwJTd19inV8n3L52
                                                    MD5:683EF25C8A8FAE7C5C6ED4E90F6638AD
                                                    SHA1:8C81D572D01C9C7A9C7B1B871BE68576812F6447
                                                    SHA-256:2A7D2BFC834A4A902EE60361A669355CDA0E401823F42137B83504F97BE0723D
                                                    SHA-512:D334AEDEE899EEEC7AB63A837F71DB23C43A6FCAF0D768B71CC716BDAF9F3AFB8D81EF98CE037C77DC61B07CFE4F295DB1E3FA0257F79464C325FAC140C2602F
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):9683
                                                    Entropy (8bit):4.650784716910415
                                                    Encrypted:false
                                                    SSDEEP:192:KtcGAS9ZBKlV06nI8IgD7KCOCNoOCOCc4:RGD9qlVs
                                                    MD5:0FD415924CB1244BAF277FE75A81795B
                                                    SHA1:446E5BAAA1ACFF2D90397226741A8C49E4572B7D
                                                    SHA-256:C92EA6D633E4B5CB1C2B547096D67AAB6476A9C7493ECA9773835A2FFA4E22F7
                                                    SHA-512:2D55EAE74DF7E2A5C0FF73A0A94214F3AF139ADFE7D28B84CEB21C181CD51C53349C082E372048D58157AEE18ED653E5BCBBCD7735FEB4A604B309A0C334EBF0
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3884
                                                    Entropy (8bit):4.638852057422492
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nC+CSNvd4asGbViYjJ4:KogUldGcQWFSca3bpjJ4
                                                    MD5:D7CED5BF6D92DE149E1784EFEA96EB89
                                                    SHA1:C29645EACB257B526A17F921B4D19463AF3382B6
                                                    SHA-256:E9C144D88DAB0D146F3B32023313BE166BF4FC73E589F4143F4417641789F3D7
                                                    SHA-512:4F0D7F0B447CE10875D60C2EDADA25B9864F9F9F38005C66D45531822927B93FFC6447BFEA7BB3268DC748901F53D3496B39C004B1DFC8160614AAA4A5E2A14C
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):9088
                                                    Entropy (8bit):4.501823834100412
                                                    Encrypted:false
                                                    SSDEEP:96:KBgUldGcQWVuSqw1Q8aDFxHfI781cOMKjhKhqfaLR9XpNqgqgH/mOVGOsDMqRZd5:KicG9ScHHf51cAhKhqcR9Xp+P1B
                                                    MD5:10364A6BE9565F48A752A82424D221AA
                                                    SHA1:D33E7D56A711AB8EC4F4776A948F5518F3F49A53
                                                    SHA-256:50553CE68ADB869229ADE37DE56D3517947ECA4A2C0098A0F3F765329A66EB1A
                                                    SHA-512:E6E278AFD9E9304693B341128B3E6B995438034D955CDBEBC039CA2FEBAEF4B1ED426E86E7878A0E1FA0F7210D91663E890F3F0D596A7CE5475C8ABE6139BE7D
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):6038
                                                    Entropy (8bit):4.651338885566638
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQW6SU0ivWUa0fjra3HDT09IAY5ACDzZZ:KtcGjS0WoyiJCRZ
                                                    MD5:FFB5F8291B67A3FC45CB766FB5401269
                                                    SHA1:0EEFD1249ED80A0565635814FBFB856F02D8B73B
                                                    SHA-256:56F01C435E5BD0B6ED7CFF22B68651AA2CAB6018956284E97220F6BA46C47333
                                                    SHA-512:BD77FD4211FB1774369F7F209B0AC8CEE392B6F604CAE0B493C5505F24F3256B30BB6F2989388AC3B8C15DDDC9738A00378B758117DF4B915D69D631CC88EC55
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):7770
                                                    Entropy (8bit):4.62722489903996
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWHCSowyJ7pSQMBd+3X1yLv58TDjFLfoD:KtcGnSw5uCnQL2DJLf0
                                                    MD5:D3E41A7DFE95B0183D16B0DDE4C29217
                                                    SHA1:1E805515B389ED9DF462E58151DA0D2023E96464
                                                    SHA-256:A5311934501B5029EE2BE2F6B75B00E8920EA05D0E96776FAE2308A5E955B200
                                                    SHA-512:3FFCBB2087A9835BF3F9F7DD95EE4699E7BF7145E2F84EFB146A044144479B8A7545577C4A14623201EE9B7B43B23F5F37C6494EA6A2A265F0D3952485D371A1
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2116
                                                    Entropy (8bit):4.845502592991123
                                                    Encrypted:false
                                                    SSDEEP:24:MLkjCT3QXf8WYwid0szM68qDRGNfFTNZbOWGf0HB+N7YiZTcfy9E9DsK2n:MLoO6E+iCshVKzlOWGf0hEVufy9E1sX
                                                    MD5:C4442C528418356C4115FAC8F196E0E2
                                                    SHA1:213BC47F6348B8D47672340BF7A510333667CA13
                                                    SHA-256:8E717245351E3B2D37EBC2F86A21BE70DE1F23E400C4D87CE7F5FA5F7E15C9BB
                                                    SHA-512:F4683A52E0CAA6F768AD89CB60515BEEDE6E9B3C82F4E2C9EB60AEFDB78117234016768EFAC93DE63D8004B4422616D20FC7DF1B5416EB171849531A8455311E
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):6192
                                                    Entropy (8bit):4.708157783383541
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWESXxAygFMCOXyNoLyCOXyct:KtcGxSXxApOCOCNoOCOCct
                                                    MD5:8C8C3A28F50309394B4688ACA4F59612
                                                    SHA1:8B7F68738C1F942FE4B610054F4D57DE636AEA27
                                                    SHA-256:F9D62727679FFB17D42739D59F0F5198C24650649C01CF0DC124EC413BD6BADC
                                                    SHA-512:ACA39C177EED0F4E29AC2060973719DA681E1F345E969AAA0BBAD20B82929286C83584409FAADF5BCC75C857474DBF096CB981F380859E09E8CA297882455303
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):8423
                                                    Entropy (8bit):4.6776172765953845
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWM/SRYv8/SNU+gEClouvAH/ARII/jYlPbDPMCOXyNoLyCOXyct:KtcGXSg8KW+B7YRI0MdDkCOCNoOCOCct
                                                    MD5:70657CB2AB96E3A4FCC0C1AC76F19C77
                                                    SHA1:E777DE5D90103D2E607AC2B32F09347D28A49DDB
                                                    SHA-256:ED6D8C14FCEFF917C6EEF857723B8085F444A456B95044A01DB65A9E0202C8BC
                                                    SHA-512:1D3AAAE1EC01AFBC588E99C37CC4C7DCED8B68F2BBA3385A973BF2F9ECCEFF761E4898AEAEB00A0C6438746B88685C93FD56A144A182B558DEE2FB0EA5DF1F35
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):10258
                                                    Entropy (8bit):4.560115668765665
                                                    Encrypted:false
                                                    SSDEEP:96:KBgUldGcQW+S2VLSjsLnLG7+hNDMO+Q99Orr+MR4GmwN7Ghw2FNJ/6kDsSAT/l:KicGRS2Vgszi7Ih+Qmrr1EN56kDsbp
                                                    MD5:6C045E9D4AD44B2868CFB552F60828BF
                                                    SHA1:B8FF107C21CA58A23F3D849C625D269DF2646124
                                                    SHA-256:49EC038431E24C713F223054DBE5A9D8D4106D785F5EE2D108B5FC7103C4C0C6
                                                    SHA-512:6691A18B70C835A43B4B23095B31AF82BCCF0466F04A6B2FB6A3685A4E0F659AEDACFF53340B440500216640579B4DBBB566D28977655BA62387F23C2082CBE3
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4448
                                                    Entropy (8bit):4.635039369223241
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nC+SSVvj54cPQXJ5Vv2X4szt4fjFJZNnGeY4:KogUldGcQWlS0c+5/K4h24
                                                    MD5:BE7A015302F2FD4F7A3851063C5C97A0
                                                    SHA1:B412F4522F28BFCC30A59BC2283E773CBF64FDE5
                                                    SHA-256:82D476FD3675E5F4AAF622EF0211835D859FBAD6E718FD5F100E9AC328EA4A0E
                                                    SHA-512:46D3E7AE4B6BFDAD98B867615308801E590121AD78BA2DE5A2418439D9887E3075B5C24AE77C45A99BC6883B42A5979F26A24D082F65D1164391955F3100CD8B
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4334
                                                    Entropy (8bit):4.665613385293802
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nC+j+DIypJR9gXxXOXjQ7i1eipD+BrMX+sf:KogUldGcQWi+DIO4XxXujQO11+tMXTf
                                                    MD5:E6F68E889EFF0EF731F480A5FDE7D338
                                                    SHA1:8BE57E64A6B9F620E132B88E2CB363D94AAE3696
                                                    SHA-256:195B734636F3B55789CC07BADA134D37AA256BE989D4BDE8E10456C598DEABF0
                                                    SHA-512:D3F7DB5F8C64E07A2B764AD9BCDCAE6833B62F58ECAD81C88E9E2C413E4CF641EF3F334392972B8559CF0455154C1038AB21E267D25398510B297128093143AD
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2813
                                                    Entropy (8bit):4.866384722770099
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9EM+suBXZ8XOCNI:KogUldGcQWau
                                                    MD5:B6069EF62D8936486E3C0C6892B302AD
                                                    SHA1:84051674AAB7B3A78B09980148B6923737CD55F3
                                                    SHA-256:838C9D6873D47CED64C308981E88265F2CF80F42540B94411B28C3A5EF930349
                                                    SHA-512:FF30D8E3C85C7279D325D142CD16C445E21D97DA06BD9FEFA24A27675E6A5068AABC7F0953FB328994F2F0CA7E3466DC5DF274141166CAC544A3FAD010A30149
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):12873
                                                    Entropy (8bit):4.629428348660201
                                                    Encrypted:false
                                                    SSDEEP:192:KicG+pSto6U19Emc9W5gZddj3fQSiz1G6BrY4OY4Rwdr27rF:4GJeV1GWO/djhizI6BVOXg23F
                                                    MD5:5EA000E9BF0E1CCCE4233B9BF5AC8916
                                                    SHA1:811CC28DB468D3B5B5FFDE90E27EAE874B055372
                                                    SHA-256:D23A90DB1D8B0DD7E49F7F83CF9C8BA510B2A14125A452F222F82068822457AF
                                                    SHA-512:E79AE8E19F7C13E0FA744BE2E97A9C035A41244FEC17A915919544B5D193CA193831D4C0EC79F357A60B5F36A0E563F129CBD16B35313AC26BDDF839D7DA8CC4
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2037
                                                    Entropy (8bit):4.83051031007633
                                                    Encrypted:false
                                                    SSDEEP:24:MLkjCT3QXf8WYwid0szM68qDRGNfFTNZbOWGf0HB+N7YiZTcfy9kXbY:MLoO6E+iCshVKzlOWGf0hEVufy9d
                                                    MD5:54013A441AF69B499098EEA96FECE200
                                                    SHA1:47877BFA803C0838AB0A47342911C65EC071399B
                                                    SHA-256:05E93F38D7C9FC61DE783DB9DA2ECB29327EEFD0C1D8C9B39AD9B90224C7170A
                                                    SHA-512:1B8B33D378B91319A31FE773BCAB7E0069E9F60CDA1D2CB35EE0FD92B39CCA2260C7246FA6AC37AD24C66765E0FD380E8B6100E31CAA99B5C9B0DB2C72B07B79
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2033
                                                    Entropy (8bit):4.829978509699591
                                                    Encrypted:false
                                                    SSDEEP:24:MLkjCT3QXf8WYwid0szM68qDRGNfFTNZbOWGf0HB+N7YiZTcfy9kXe:MLoO6E+iCshVKzlOWGf0hEVufy9z
                                                    MD5:2DCD6E429D59C09BB08C9EBB65AF183A
                                                    SHA1:5A9E200CED0F4D6202BA8E1BE082EF4F8EF6412C
                                                    SHA-256:269B14A439279C1B28E2D66093E42C8CEC9F9EC4A6996633B263CACA6460FAC9
                                                    SHA-512:084C5C7C1F22C6D2378436592EB3B51593471BF96FCFC13D8CE1C95978E6B073BB3BB88C5B084ABC3F2358DFBD8D6F808FDFFA74552A39E03942BD621F4B4B28
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2728
                                                    Entropy (8bit):4.844188917143975
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nCsPByFTJWjr:KogUldGcQWOPByFtWjr
                                                    MD5:A62D007DC5671CB3B7E899E6C80F212B
                                                    SHA1:D3F14DE84264D533D2262F3A9AAF52010D9677E0
                                                    SHA-256:56BD787A33ADC129D41092CAA2E38BAC074F0ABEB9430CA2EE134566D12A55B0
                                                    SHA-512:7FE3FAFEBB599129FD7B058D58C388A8825D93981EBC600B47814389D9C10CBF5B7D13BD65D06E34E9C4B78E2F84A65817C557755D32A2AD75B04D29229F8A1B
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2027
                                                    Entropy (8bit):4.825830727934058
                                                    Encrypted:false
                                                    SSDEEP:24:MLkjCT3QXf8WYwid0szM68qDRGNfFTNZbOWGf0HB+N7YiZTcfy9kXC:MLoO6E+iCshVKzlOWGf0hEVufy9z
                                                    MD5:D557C09A026B8492A3517007BF4B222D
                                                    SHA1:3031C85AA4B93F676578EFFD1F11ACDFBBB696E9
                                                    SHA-256:15F50D0791445818E933E80650BAA16A94D3B9403B216D87FEC1B5E340D1F267
                                                    SHA-512:DE7854EB35483025D55B08B3A6F3CED06AA90258D0816A8A2DED72B4E981417DD4D22A9B7C5071550D37E8514BA3E06F3F3F46BB453496C16FFFEC505EC414F3
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4043
                                                    Entropy (8bit):4.635695740291305
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nCsauKRsCxUu2oM6XRatjM3CSnhHTXgv:KogUldGcQWOauKRsO2oMC+MSS1LS
                                                    MD5:52AE42A1BF76186E365F0A7F96E639C8
                                                    SHA1:A09A8EF26CCD91155014D86AF57F85FFF3970867
                                                    SHA-256:E4CE3E2C356FDC11F7D5AE4029602CDBE5F40E103CD482281A8D9F8EE6EB9936
                                                    SHA-512:25EF63D9A6A175785EAE639CB135BAB3FC920016EA5F8D53194915F86EBC96FF4943C02A484DC85573CA298160EA1F440F5DA56E92AD62C9A2D087169DDF8553
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5292
                                                    Entropy (8bit):4.717869540578657
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWV+JbB+LjqZyYBAQnxg1AJzenItNx06gVgyx:KtcGZJAqACgDgyx
                                                    MD5:9CEA0D2F653C5E0536C32175995E7EB2
                                                    SHA1:BADC1B9758A4FE56402CEAA0B421E2AE734E5384
                                                    SHA-256:B8EC881A35CF7E90154D2413CDCD53C2B131556C22E96F542FD934FA3AE34C83
                                                    SHA-512:9D64E98D56A30E2D1937B4266008A65A510F773C2750B26695B61B4549F8780F53B29FE8DB23BD0D5B513D3CCFAEA61B578E7D2F5C894E47F4D6E3FCBD2F9ECC
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2261
                                                    Entropy (8bit):4.866831940677612
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nC+ZXn:KogUldGcQW4Xn
                                                    MD5:47CA08817D0EEC6DB4B3EAF514421448
                                                    SHA1:0393CD93A96B8B9A6E9ED6E56CEC9CEED8DDE44C
                                                    SHA-256:8307CEEF8D86F2E307B67A1C4A0B33AF7B83CC4965F698B15960841D20B19F29
                                                    SHA-512:99B632BBD80E9E0A15FB4D43DBEF3BEBFB8F13328F496B5BAF640978B1430CD351FDA50B4DED003FC54664F1E71F4D01A9EFE04577416D701B827D146E492A3A
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3230
                                                    Entropy (8bit):4.914641706249265
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nCX+/CAYnvoYBxnQ:KogUldGcQW9+/CAYgYBq
                                                    MD5:FC05F8A54097E64E9044950470A58E40
                                                    SHA1:ED2DD6FE5FCCAA5B88BD4515E93D2435C43899E4
                                                    SHA-256:6858DB01FA20AD83559BB5DBB9BB6A7711C8C6959EC53FEBD4D0A9C5370CF59B
                                                    SHA-512:11E577F43E332B195BFAD9CE5A0AA8F4127C0C6F1878ED5B99168B8DCDE5C41C89BA9AB752D8C92AAC70C19DA06FB598066FFBE7D6B6449D36D1D704FDCEF07A
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3238
                                                    Entropy (8bit):4.90187484968626
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nCev5COkFNpACuUBEKjo3Zq:KogUldGcQWcv5x+aCuUUI
                                                    MD5:E78025940E8545B158A72910F129AAF0
                                                    SHA1:8CD85D7C384EDF0FF6B05B532A4FE04312162A33
                                                    SHA-256:177F211EE15687E231B2A790172D5CADD638016831AF3E4A55C4F9EEDB37E2AC
                                                    SHA-512:4A494D95DE21929FDF04721096989C966717D89E5FD2C734CB6F9B5397579C32525A918417E305FAD9043AF5BA8E5D343809AADCB53A31CE8C4391A92BFA33AD
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4683
                                                    Entropy (8bit):4.828387956520702
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWzvqVw/vSN93wT4ojVJGkOsjRj1:KtcGKWwyzwTzJLBj1
                                                    MD5:9C457D5FAECD7B9A50671D78B48FD52E
                                                    SHA1:B5C07C5CFB40D4B40F85C9EE7F8417819A5A15EC
                                                    SHA-256:AF75BB0905D646A1A15361D642AB86A1D389695D6BCFEE8291CDA857F84E0CB6
                                                    SHA-512:9434551DC72FB405BADF8BF89C024F7531A2E5AB0EEF1FD3F89999230B65D92E0BBA98D0D51C41CA205763AC9081BE4839E5D2B5E435F0135F5726C14B59C11F
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2916
                                                    Entropy (8bit):4.839363550613035
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nCsnxq2Bh9n1iWUH95XkuMZr:KogUldGcQWOnl31iWQ95XkX
                                                    MD5:5168523E82D5137AD3656165D1D0A2AD
                                                    SHA1:0C27710BC44AE4C0D5A781BA0D807398D70AFD42
                                                    SHA-256:374ECA958EF36B2324ABBEC45E179E11570F6DE5A91F8AD3F2559393B240ED28
                                                    SHA-512:AB2DF3E21E1BF415FC77978F42E64D6BA0273E04CB439367F9093A5BB7E9C7F78A3C2381258FE82AFD67CF45F41E82B8BE116D583D2E628C0C228DE1E6A78E79
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4128
                                                    Entropy (8bit):4.6240539224144275
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nCs+MMLR0K6SCv2oM6XRa2jM3CSnhHTXgv:KogUldGcQWO+MMLRvA2oMCRMSS1LS
                                                    MD5:9DFAC0C040CA518A9E1930D70E90F6F5
                                                    SHA1:A6D338CE117273B5753A982C66C7A76176C01293
                                                    SHA-256:D673E0F7FAD84074A376601CA564445E9A8B428CF50C37EA59D05A7AB5924F6A
                                                    SHA-512:9855008ABB7A5FC71AE9FD8D5BA78B7FF3E44F0C5110B1C0CCE214ED6A58846B31ECD03500F9B8D4F2ACB1F8076D9A1C3B18AE46623365BABCF8E419831815A3
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2070
                                                    Entropy (8bit):4.832400322959624
                                                    Encrypted:false
                                                    SSDEEP:24:MLkjCT3QXf8WYwid0szM68qDRGNfFTNZbOWGf0HB+N7YiZTcfyyU2yEd:MLoO6E+iCshVKzlOWGf0hEVufyyUTEd
                                                    MD5:ED9217025E9EC7239C63D2EF60B78282
                                                    SHA1:C5A7F37EAD74D963D7E2F706D693E31EAFC3BAD0
                                                    SHA-256:5C11ED9112F3D286DD0351CC5166AEB3CF7B4BC8847C0A35422DFBC14FB4F3A4
                                                    SHA-512:7157E905D21B7D5C330EC5275B91ED2B2F3E6A696874CA3EE05586B500820C83350942F990895382C32F8942258E708A297DD76B3A9D62DB9C0EF1DA482A4138
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3920
                                                    Entropy (8bit):4.8675531615918075
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWOLBgWFnl0bNNvGbGDp/s6dkGF:KtcG7qwl0bNN2Cp/uGF
                                                    MD5:CCF3DC3DFB076E1397626FC400502E0F
                                                    SHA1:379E4B968512352773130A95E75D465F3BEE4857
                                                    SHA-256:A6F0CBA47674AF372708D6002506A0514FC8F1C6DF922416B44549BDB5D08806
                                                    SHA-512:2DBEFCF7793C5EDD0B167AE6A82652692063126CAF465B33330292357F7D0F2E0D728C60CD375F279F8A41AC94E9CB4CEA431652F42BC9713AA01E102687FF01
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2912
                                                    Entropy (8bit):4.857002307301528
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nCs+DYs7M00/+BDBqivLm:KogUldGcQWO+DYd/xT
                                                    MD5:C5BE6A9676AE022A4B5C5B67F9CB3483
                                                    SHA1:1105EF627A6B6F46B9860C72E25069ED259AD1A3
                                                    SHA-256:67D3A94B75A01AFEE08644CDED0E393CC3180916FE6DC9BF4B7E7B14727ED582
                                                    SHA-512:303BF89C5C800C0D7C5C2C9682FD82F27CECA7F16044372808A1E88B74C94258B1A638A6DE3A2671CE92B11C445F047BC3BD30EC543B346690EE4EDC1A82A9D9
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5470
                                                    Entropy (8bit):4.769994565901049
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWO+KWtnZkRtrFbWFJRN/3sqNnckMj:KtcGOXZ8UM
                                                    MD5:3BCFD261EC53F77B79FF18EDA94F00A4
                                                    SHA1:806C34F49630C855AB448D1DDD7CC7EC75155A7E
                                                    SHA-256:BC6AA234585366A42DC44D90F15BAF2CDC601F4158E9A2E97A9E8CE4BDABE15D
                                                    SHA-512:96F7FA538D396A03D0660B6D76070D5BB66419C80917AA3BB4135C57B98219A87D318E0EFAEF817CDA896C3ED65554072F6168D3B33E779BE3BA430A8E95404D
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2491
                                                    Entropy (8bit):4.878811646714112
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nC+V4iYSss1bM:KogUldGcQWe4n3oQ
                                                    MD5:A4E30E457C53AEFC73DD84E4FB800AAF
                                                    SHA1:2A18E9793678530EE130464A134DC1D1C036E030
                                                    SHA-256:A605E146BD646C94F5DF54330956FCF355AA994822A3F19D2E8FC8DC7C6FDC72
                                                    SHA-512:D0F7E098A0DC960A20273C5EF33DC089B5D6F4C8C9069E2863152D0FCD3EE5972D19FBCCF3BA57D5CCD6E9A341B3BA115C6600A7E7D8E820E4F375DE3599515A
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2113
                                                    Entropy (8bit):4.854277805833694
                                                    Encrypted:false
                                                    SSDEEP:24:MLkjCT3QXf8WYwid0szM68qDRGNfFTNZbOWGf0HB+N7YiZTcfy9N9C2okXf:MLoO6E+iCshVKzlOWGf0hEVufy9nCfO
                                                    MD5:6C9008235764FF0068F72701943B94FD
                                                    SHA1:F100EAEEDF7D8164215092BF3C9A5F6FDC98F825
                                                    SHA-256:203F0571C301F3215736C0647181D8C40CF7DC6C96C4C22FEE327A0F2643048D
                                                    SHA-512:56BD57F97CA85EDDFF01C4C8DEBE9DFC0CFFC8959C49300A52457DCD0A8B78D3AFC2F3256BF6F38FE8942C72BF68B3B7C3385AD816E7E46AF0D6FA159A619686
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5403
                                                    Entropy (8bit):4.869623049015817
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWROnOVeVVpjou109ek09eeNLuJ1T1OAhEs2TTaJtAtZRt7cQq:KtcGVOVeVVdolm6Jl1O5TTm
                                                    MD5:70AC23990E0708D6C19F141EE87604AF
                                                    SHA1:B887A7EC5240501AB95B576E5B351EDA5D657CFC
                                                    SHA-256:FA8D23345774F673EC2E255FFD773B4F79C9402B1D96FD6B59DAF8296B388322
                                                    SHA-512:11DAFFFA8DF00DC43D28B18D99E32C0806083DEBE15586436C2808F4D6D7F660CC26A03982271AABA8659FB07D076170E4AD0203ED99080EB664F9E36C13483D
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5378
                                                    Entropy (8bit):4.808326079025741
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWOZqOMLwFR9oDsEP+nSjMLldH:KtcGvkaRssEWSjqt
                                                    MD5:68603CC39333371CDD6E1775322F1670
                                                    SHA1:28F91909A18263E06D61EA1FCA4CFB274965EFC4
                                                    SHA-256:D79180C0B2D1FDFE1D99E182D5EE3C28262402CFFA817820379E66618C976114
                                                    SHA-512:9191915011233D238BAD3BFCB0BFB7D3E9D01BEB4BD6B02F4A6C229FDA4A9A343F8704C4079BC8E12991571B15A6AE0BDA0E2B3C2E36D5EBBA69E798C8069FCA
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2739
                                                    Entropy (8bit):4.876333999803406
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nCDtWQwwTeDzT:KogUldGcQWvYT
                                                    MD5:F18A31B21F6E1E07ED2C2384EC9DB07B
                                                    SHA1:F0DB90907002175B39462D21AB886A0D68117B19
                                                    SHA-256:C6B003634227509E65F0BF51DA7C933DDE9EDEEDEC7939A9B4EC6A032D15CE76
                                                    SHA-512:5514AB2ED30618CB5C3AD8A15AFC45E90B3EFB83C26400700CD735D98526B6EB3F934D102B1BC83FD1E4BD559AC65B3266940699B94BB726F308FCBBF5BE2776
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3377
                                                    Entropy (8bit):4.85774329326833
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nCshe/RXWBwwjepxStQE/NPGtuvlxR:KogUldGcQWOhOi6StlFOmlxR
                                                    MD5:E32F36F66E28A5933DB78000F5A728AA
                                                    SHA1:B84E9F41AA9723831BA2F1E33793B280570B2432
                                                    SHA-256:469CC7017A3DEAA57E5AD77F67D92C49730158D4CDD3D4CE4A0565916B4BF046
                                                    SHA-512:B099EADB5AADBD45B9F20089D77C16953F56475D03C84A8B1F1BDF44E6E2A85163252634C060EBEA5B047C85BEA1A4CD625C850CD75AB7B82E2888690C52868C
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2560
                                                    Entropy (8bit):4.895624359026673
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nC+V4FoTtoKNTfM:KogUldGcQWe4FqtooA
                                                    MD5:C00750A748AAC07D2EE770633A1D1977
                                                    SHA1:E33BADC9EF8C258828F19FEC2BE808F86CBE43C4
                                                    SHA-256:19A1F65314D130633F132DFCC0632767870946EDEC1EC3094D77C7EBF1DEDEA2
                                                    SHA-512:33FEF4B179D1BBB6E6559FE4948F1A522E6D8CB08D6B291893A2E3132047E1F0CB0CC5C5849E571B836033B65D7D5032304B9237EBCB13BF88E14949610C578D
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2679
                                                    Entropy (8bit):4.817998343273068
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nCsPeT6L/jx:KogUldGcQWOPeEjx
                                                    MD5:BCFCBFBD6E6B859D0022AC47C639A698
                                                    SHA1:2516F4A662B412923F9C2EAD0B5865E5E0D3CA35
                                                    SHA-256:EAB8AA6660AFC600BB4638790DEE761289226F376DEC5048FF1322CAE9962EA8
                                                    SHA-512:7EA78319472B7ED0D5BD2C93A9C1B5B922F39FFD668D666BB7CEF3CFDF8742EE0B819C2D2C830079D939F01F5078D37E5C71CA6323C0ECE4BCF0CD099A1A0BF0
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2851
                                                    Entropy (8bit):4.83490362938184
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nM+AvKufXjLOH:KogUldGcQWtvrOH
                                                    MD5:6F7FAE0B08A85CC48443CD6C2A0AD367
                                                    SHA1:E668B85D9524862BB0C849239C4E9F20F9610D41
                                                    SHA-256:F25F4D88D7E91A642CF1F1484290398A6FBE56CA30E8D2641674FC2AF95BE28C
                                                    SHA-512:E975DF2161991FB789AAC30CE1B5C42B55FB7C0E039377793F3A09F1A668C531431A916CC9046254EAED0D234D93939FD4E808F2E92E337C24F9FF35F559A0C8
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):72
                                                    Entropy (8bit):4.323595876865264
                                                    Encrypted:false
                                                    SSDEEP:3:SkR5JsRomvBAWQoAw:GAho5
                                                    MD5:5BB63258D01ACFC40E4594162F0A82C3
                                                    SHA1:565D8441B24D8780934A9DD477A10AF102DB1FF0
                                                    SHA-256:55453E2272C4E35AF64C697A91EE082872A33739E88F9BF18E8128C5AB3BC4CE
                                                    SHA-512:74B9A8C62FFCB21C29D48A3CDC0D7EFD2F5CFAC8CEB55C1B6CF0EFCC97730DC3DBA1642EA26E0245C41CC8FDDF10AE97BA12EA3B6388DEC734F8763BAD6A1211
                                                    Malicious:false
                                                    Preview:singleton RowItemSingleton 1.0 RowItemSingleton.qml..designersupported..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):126
                                                    Entropy (8bit):4.704713117740268
                                                    Encrypted:false
                                                    SSDEEP:3:3BV9NKBiA/A6UR7ElXMLovyWmopFRPlDMexR9bVvn:xVfQiAbUNkXD8oDVlMexVv
                                                    MD5:423C1712AA394DBE84F5179B52B1A261
                                                    SHA1:49C875E36D792C01364191C9D236A5A3D3A25186
                                                    SHA-256:A84A08BB95A702C80C249681B7C0E6F42173FEA619124961243F4804ED6CDA70
                                                    SHA-512:C7CE34D2B67E9B2B74848F28648B3781FE3158B9D27FF309179712B4A16E8028DFFE5818C5E21D082816557EE3E29CCA5E182D81B7B7B44C30C760977DD2A1D8
                                                    Malicious:false
                                                    Preview:module QtQuick.Controls.Styles.Flat..plugin qtquickextrasflatplugin..classname QtQuickExtrasStylesPlugin..depends QtQml 2.14..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):831600
                                                    Entropy (8bit):6.689717994878927
                                                    Encrypted:false
                                                    SSDEEP:24576:P8gIwhCNoh+JJ9f9VhCNoh+5i9FrIJJpCNoh+7C:PY2UJ//UioGC
                                                    MD5:9A5E5EE4A87D87D444D1522E6842F010
                                                    SHA1:0CFAC776DEF92C31536603F37BA5159711B33BA7
                                                    SHA-256:AFD5C8BEC73CB20CFA8DFE92CF2AE22149FB69304CA980704EBD09A3922B3931
                                                    SHA-512:3D499AB57686578CB661BC78C895B9AF44E5941A5CE5425644956A57723DA7C2DBC176A9F1E4A624B024DCB5F823DCE92E1C80CC97F385880E2F4BE3C5ED3501
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............~...~...~....3..~..{....~.......~..{....~..{....~..{....~.......~...~..A~.......~.......~...._..~.......~..Rich.~..........................PE..d...p..e.........." ...$.<...V.......@....................................................`A.........................................n......do..........`...............p ......|....]..p....................^..(....\..@............P...............................text...[:.......<.................. ..`.rdata..N<...P...>...@..............@..@.data...h............~..............@....pdata..............................@..@.qtmetad............................@..P.rsrc...`...........................@..@.reloc..|...........................@..B........................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):1575
                                                    Entropy (8bit):4.8088919366233815
                                                    Encrypted:false
                                                    SSDEEP:24:AM0yAwQYdlyGUG9yHg9olJ6DIqrOirQorA6aAUDTQdiCH9BtAH4oeDvXFWdlvZda:ey9y6PAJGIqqiEoU6LUDcEeHy6WXva1F
                                                    MD5:413DCF3E49E01CA487FA65136C6FB0A9
                                                    SHA1:51AA584ECABFC23F38B8C8E9C45ED820A7F404B7
                                                    SHA-256:7BB94BCC9FA7D849C10ED84F476AD7951A61D48FE8F78ED5201956419D38D05C
                                                    SHA-512:999E3ADB3F09CF70140B45DD4B8DB2C524974DEB5826D309419FC995A3912A7DF439FCEF121C28D5BA5FA36A1C0D10A3C9289B6B948C7FB8656BBF20E7992519
                                                    Malicious:false
                                                    Preview:module QtQuick.Controls.Styles..ApplicationWindowStyle 1.3 Base/ApplicationWindowStyle.qml..ButtonStyle 1.0 Base/ButtonStyle.qml..BusyIndicatorStyle 1.1 Base/BusyIndicatorStyle.qml..CalendarStyle 1.1 Base/CalendarStyle.qml..CheckBoxStyle 1.0 Base/CheckBoxStyle.qml..ComboBoxStyle 1.0 Base/ComboBoxStyle.qml..MenuStyle 1.2 Base/MenuStyle.qml..MenuBarStyle 1.2 Base/MenuBarStyle.qml..ProgressBarStyle 1.0 Base/ProgressBarStyle.qml..RadioButtonStyle 1.0 Base/RadioButtonStyle.qml..ScrollViewStyle 1.0 Base/ScrollViewStyle.qml..SliderStyle 1.0 Base/SliderStyle.qml..SpinBoxStyle 1.1 Base/SpinBoxStyle.qml..SwitchStyle 1.1 Base/SwitchStyle.qml..TabViewStyle 1.0 Base/TabViewStyle.qml..TableViewStyle 1.0 Base/TableViewStyle.qml..TreeViewStyle 1.4 Base/TreeViewStyle.qml..TextAreaStyle 1.1 Base/TextAreaStyle.qml..TextFieldStyle 1.0 Base/TextFieldStyle.qml..ToolBarStyle 1.0 Base/ToolBarStyle.qml..StatusBarStyle 1.0 Base/StatusBarStyle.qml....CircularGaugeStyle 1.0 Base/CircularGaugeStyle.qml..CircularBu
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5331
                                                    Entropy (8bit):4.7535262271796865
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQWtqJOuPhnGpgFFbVlCidcJhh2Lzprr:KtcGCqJogJkidcfQprr
                                                    MD5:CA3D8928B9CEE6FA5F816B955E4BAD91
                                                    SHA1:1F260D64D2ABFF2523276C9640411EAD735AABEF
                                                    SHA-256:B13AB37C9E463A9CF8E54EC49227D0D9BFC1E2305AC633C52101B1EBC1F764EA
                                                    SHA-512:EBFFE62093E5C826A466C95475051E70E460849F99B6D4B8641A464432CD16FBB3DC6E9C3FAB9A95EC04D89056BFA1313BDBBF6860B80E6AC8F74E34CC4BB0A1
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3001
                                                    Entropy (8bit):4.819287574242073
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9b1MU3w28oAjlCp8jSj:KogUldGcQWC5LOlCpwc
                                                    MD5:AD45F17A9C359302CB783D120C735607
                                                    SHA1:DEAC44C363B03E2FBAAFD698DB86C9D9CBD22F70
                                                    SHA-256:498A7572ACC1A285857798648F3FEEAAC77364555573AD7225FB2A949A0539F3
                                                    SHA-512:5F0B2C6CFE00567A1DC58BC4C51091223E3862FFD6B4AC513999E05046E6B063796769EF13B2916F71C7F80575D4B6DFB654FF439BF9230EAA14077CC17355C2
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):10775
                                                    Entropy (8bit):4.555931669004076
                                                    Encrypted:false
                                                    SSDEEP:192:KtcGo4BkD2rdt4uI+t2KD31+F74u3h1zcO04SV22TNQbNqcefu1IucX6:RGo4v4Xaz24u0faWducX6
                                                    MD5:21A3BD0847A872DEBB82D5EC259822A6
                                                    SHA1:71A53D4F9C9881B97E9E6131883C7928DCA44FB4
                                                    SHA-256:6D075D592A118CABD04880B806813D447DD8D38B61282A6305D2B6D8CCE2A1F1
                                                    SHA-512:3BA9EE580EC217A4397FDA16B77FDCB5842D4DF5D843A441EB0E71782BDA6DA4A3D468967048614C311AB41A3CD42D6211F31C0BBDE23B904482558343423F8C
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):11555
                                                    Entropy (8bit):4.508062969601809
                                                    Encrypted:false
                                                    SSDEEP:192:KtcGatGcaCIsEeVsAKajWjzfjHNhYjhjEHWgjJAStuKznjnHXbjtxtJt:RGG2CIDe66iHgNGFAg9/Jn
                                                    MD5:A03F6048F017119A2EBDD73699108DDE
                                                    SHA1:801B5E265790085FDEE815A796BDE28230D59915
                                                    SHA-256:10B4650B6196482B2217C5593A1B702E1E85E67B58769D685314C7086E866CCD
                                                    SHA-512:6468E846450D98779D857E8D7413E0D2B5A42CF68ACDC9E63336EBA3FF609754EA252CBA8F3A77F8971783FE2383BBB47EB22BA9A6D20399466E2AA392C8B95D
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):6804
                                                    Entropy (8bit):4.758090724415883
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQW6Gze7Kur0wamqRNjjpLAPzH7Xe8LQL1:KtcGoS7n0wfqjpsPzVLQR
                                                    MD5:114CE7CFC7900F90D9D333963F1FA5CA
                                                    SHA1:F71D8F3A7FCFF316B43A381A300A9704ED96F81B
                                                    SHA-256:AD07F5FB3B72791C0AECA0FE44707CAEC017FDF036B54DFD661D862CA285338B
                                                    SHA-512:0889FF45093FCCFA32ADCB4D8C67D9FCE7DBCD4FCDF7B8B63EF934AB5A896B1DA51C2F24069245802AF4C8974450F37AA1C180FF7B2184389D0AA7D16AAD5689
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):36631
                                                    Entropy (8bit):4.4780442352754575
                                                    Encrypted:false
                                                    SSDEEP:384:RGCsrfpOCQSMCPcc1BjenOjPrvGU5qkV3G6QIwtr6S:RGCCLF1Bj6Er+UR3G6QIwtr6S
                                                    MD5:B7C419EBBFCB12ECD1A01B7863F7C2BA
                                                    SHA1:B188CE06FAEA8BDC846DCF8B3E8CCDCD4940AFB3
                                                    SHA-256:FE67CE4601E82B4954EC6E3A7E6AE91367AAACA41565C09405236E065C9E50D6
                                                    SHA-512:27173C32C6359E75C5AA11E698F08FD6C51CC43891DFD54FB7CE34152B236ADB64EC03686421C2881030BF4232665947223BA2797BB2EE54FF5FADC1F599832B
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):23187
                                                    Entropy (8bit):4.601892640300788
                                                    Encrypted:false
                                                    SSDEEP:192:KtcG4ZAH+wlOXXPbyICpFy440d/nAS3JLzQ5zfKN3h1gdF0qEhPNq+tppmGjheDG:RGffwkIsV3huEhPNTtTeOp
                                                    MD5:438230E5EB067351815803354B75CECD
                                                    SHA1:C1D8DA8AFA9D7BF54347A614C3E10F7B119013CC
                                                    SHA-256:0A5EEC9E6BDE5A318D695351EAEA1187929D08BD9616672290CEFB42B784B27C
                                                    SHA-512:E271F00985D6EF691F4D5C24767DD27623C311D375FCFF20CE5F265BC4937CDF7430929C6AFC7C04D6B01694BD149622C39A2BE7A2302301FDEB5EAA4BF40580
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):7444
                                                    Entropy (8bit):4.556868420703673
                                                    Encrypted:false
                                                    SSDEEP:96:KogUldGcQW9Cs7WWD9z0vqArXxKA/k+PSAdl+f27qUhr6+LnQv1huMmunh+NNMXv:KtcGR+55YCKc8HQ5v3T+NNq
                                                    MD5:C07E4147051E16985F5131A5430A8930
                                                    SHA1:67D261B5394136DDF95649B8186AF3C7106A1118
                                                    SHA-256:A6FDBF00896B66B912C84BD84394637DC418C7B25533FDEE13CDF2C0C530809E
                                                    SHA-512:675B1D5B681E2EFAF45F30BE1C8335CD419C8770B26E701C9E275075968BF811CD8131FF405A474905A67E4B1EC2C5E35C831D6FA8ABD178FD2915FB3A39FDD8
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3229
                                                    Entropy (8bit):4.725674482574039
                                                    Encrypted:false
                                                    SSDEEP:48:MLoO6E+iCshVKzlOWGf0hEVufy9nC+BD4pj4A9z0GWw:KogUldGcQWkDUP9z0s
                                                    MD5:2DAA729A7973A06896E1ED0033FEA2E7
                                                    SHA1:3ECD84596262AB298F07F75E0BC7A3CAAB5F44B1
                                                    SHA-256:3D0FBEE00479A1D6FEBC3F47223F8902D371A59AF84F298C3FCD0D1326E2AE99
                                                    SHA-512:45F5CC021A2CAF1E1751DFD2CDA447BB63960D97CC083F423B204F481B6D60B47F543C61DD5527741CECD868EB5B2F5563CCA7D09E0B19E16823FA96376845A0
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):17067
                                                    Entropy (8bit):4.403605360211459
                                                    Encrypted:false
                                                    SSDEEP:192:KtcGf54RK/P5LgNQL+n5GCVEHuCtJjrjPrVG0dQcAjNs0ThLvoajevjOwjCUJ842:RGzL+5hFeJH7rU4ahTF8qwAuCv
                                                    MD5:E1FD1395D1F8E2FFA28F696FE0411622
                                                    SHA1:FF7C276F0231781D0FA62859800DC95CFFB80AC5
                                                    SHA-256:07BEEE0ADBA375BD9E9648AC6DFBE18A8FE3CE9DEA1BC56F3EFD2E017F2F7B9B
                                                    SHA-512:75403629C1DE9C9E3E40B678DBBEA5FB2F4CE88AB022E5568BD33D4E173793BE81380ADAE21EF5442177A86D5DB10EB743064567C87AFFBD5DC4DF394F2DC802
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Controls module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):157929
                                                    Entropy (8bit):4.394855792362328
                                                    Encrypted:false
                                                    SSDEEP:384:N5pg8X/dXiHasVeW+vrfAUmdR5xK5xO7MF4tXtXMzxo+3aM0XoXyQRcMGMQXv:N5pT/dXQ+TfAR43Pe
                                                    MD5:B4A2ABC03607274408F92857B7BAB3FF
                                                    SHA1:D271819DF46A7D17D37561132F56738DF8ED4A18
                                                    SHA-256:9980DDEB8EBAB08CE397D99A543DC9CDC1E4964026EF9C73D6BA02FE43AD2DE3
                                                    SHA-512:C897A979F60FE3A15BED54825DAE0EAA1CF9B831ADF3AF7B975BD0E4F27EAC8FD7E6E6F79FDC34D6FE996AD15B6FD4FF666CDE60DED0E878867BBF8794E4CC5E
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2....// This file describes the plugin-supplied types contained in the library...// It is used for QML tooling purposes only...//..// This file was auto-generated by:..// 'qmlplugindump -nonrelocatable QtQuick.Controls 1.5'....Module {.. dependencies: [.. "QtGraphicalEffects 1.12",.. "QtQml 2.14",.. "QtQml.Models 2.2",.. "QtQuick 2.9",.. "QtQuick.Controls.Styles 1.4",.. "QtQuick.Extras 1.4",.. "QtQuick.Layouts 1.1",.. "QtQuick.Window 2.2".. ].. Component {.. name: "QAbstractItemModel".. prototype: "QObject".. exports: ["QtQuick.Controls.Private/AbstractItemModel 1.0"].. isCreatable: false.. exportMetaObjectRevisions: [0].. Enum {.. name: "LayoutChangeHint".. values: {.. "NoLayoutChangeHint": 0,.. "VerticalSortHint": 1,.. "HorizontalSortHint": 2.. }.. }.. Enum {..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):212
                                                    Entropy (8bit):4.668721562194963
                                                    Encrypted:false
                                                    SSDEEP:3:3BV9NKF7eURCNPdMcvyWmopCxKdz+RLV06qWoZAhoAcRSfL8SFzSnRSqRHyQR9bF:xVfy7eU9e8oIQ+keSAhowPJ3qRHy+Vv
                                                    MD5:A6CE84D84B95B99795330156F2B48C4F
                                                    SHA1:8530263B6C0E61B715673C77BB2F8E55C51B2AA0
                                                    SHA-256:DFBD5CB07BDDD1A2342B82A442CD4A4504D87D04DF79F3083BBA3A031888BE3E
                                                    SHA-512:0979B08FCB1EC0D7589C3A80F0B24EA77817476D6AFABB9E5F63B8A07BF2F3F3D902695514CB3696F11DB210E1CEB6172CA0B878D6BB366DDD8169B009E9A83B
                                                    Malicious:false
                                                    Preview:module QtQuick.Controls..plugin qtquickcontrolsplugin..classname QtQuickControls1Plugin..typeinfo plugins.qmltypes..designersupported..depends QtQuick.Window 2.2..depends QtQuick.Layouts 1.0..depends QtQml 2.14..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):336496
                                                    Entropy (8bit):6.16280868566064
                                                    Encrypted:false
                                                    SSDEEP:6144:kFxAK+dKuXM65w1h6f4SVFtZLm8JEXnRIi6qyOZPRVCVZCwjG9c7hf:kFx9+dKuj5w1h6f4Twqmd
                                                    MD5:E96BDFFCD4C2FED1D86BD40553B60607
                                                    SHA1:168FD1A56A6D8F66EAA4115C6DFC55AD629D4B13
                                                    SHA-256:09608E4DEB18C998D15A1EC376D83F6EFC5261762C13C9309C306E65AA488AC6
                                                    SHA-512:9A00DD87CA8C7B322EF4BA9B73ABBF774E653E09A159FE693FBE37CCCF1ACF2735E60618568EAC8EEA6289898D3B59B869ED53044FB84BEEE67EF8707FB91999
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........x[.v...v...v.......v.......v.......v.......v.......v.......v.......v...v...u.......v.......v.......v.......v..Rich.v..................PE..d.....e.........." ...$.....B......p........................................P............`A........................................0................0..`........*......p ...@..8.......p.......................(.......@............................................text...b........................... ..`.rdata..............................@..@.data....h.......b...b..............@....pdata...*.......,..................@..@.qtmetado.... ......................@..P.rsrc...`....0......................@..@.reloc..8....@......................@..B................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:C source, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):16805
                                                    Entropy (8bit):4.024511905292934
                                                    Encrypted:false
                                                    SSDEEP:384:iGjfVa31y7foQAOumdPjAa6rhLjm3ADpBUQwNLX:iGI2T1Nj
                                                    MD5:4B200AFD3340E84B92381852B9C4D053
                                                    SHA1:53B52803A2994A2FF56272CCA5AFE91896981B43
                                                    SHA-256:29B816728E1B4450E7B50DDA9287D61052BCC265D178BCD1672C27FB1431FED5
                                                    SHA-512:81824E7710908FCCD0CD74A08E328DAC56B5538FCA6E1011BA892B70D9AD945C8E879A2AB05DA2D0D0F494D9F9EBFA6B03F1F77D4AEA927984B2F5F6540328C6
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Dialogs module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in t
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):8343
                                                    Entropy (8bit):4.489736761557964
                                                    Encrypted:false
                                                    SSDEEP:192:KacGuEXsd6q84cbBNUaf0DuH/ivxMoEu12C1q0E:iGuEXs47zjeU/ivxM7u12C1q0E
                                                    MD5:6E9F9F1D9B0B3EC16B9DD0C8F21EA382
                                                    SHA1:C0F1CC4C1142F60E4DB4795984DC03B5E43F1C3D
                                                    SHA-256:09FDBDC3098BA77DD2261B8CD8FD83866D998EB9BFA9F685DA5C43FF78CE746D
                                                    SHA-512:0350E72EDE7826AE537D2944EC1E6A6D07AD1A691109D4D5ECA01170C8E39CC8D08CCC909769795189B4A4035A30967DC001E0D5E041F6611AD80E0AD3B3EA48
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Dialogs module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in t
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):21837
                                                    Entropy (8bit):3.89069196383034
                                                    Encrypted:false
                                                    SSDEEP:384:iGCRB55UnGfnUeSO4tIXRAXsMOv6REflHEG:iGKKOPMITb
                                                    MD5:D8C075B1466A5DBC163AAF306C8B9C8F
                                                    SHA1:0BE13D591DAF52EF34D22C9375DBF484FAC2415F
                                                    SHA-256:7562DDFB2AC626A253FA3987FCED5DF7AD7E21CE61EAAF102F005CC586FE6BBD
                                                    SHA-512:37A2428C3E7A91CB2626A633447DB586A89D3E35722711B9CE3F2A60634AECE37C0409C965B0E77D31F94B5BE563BB72F94C2D684129BA8597E28908D52A9504
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Dialogs module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in t
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):18789
                                                    Entropy (8bit):3.9546487780736306
                                                    Encrypted:false
                                                    SSDEEP:192:KacGtM5QUU83tyUWheQ3dlbb6zW9e86ewxu2Gy:iGtMQUR3tyUA3bbb6ic8G1
                                                    MD5:75F348472EE20DE837256420D3F05A8E
                                                    SHA1:4D492C74E8E5CFA2500121E9644872C459D19495
                                                    SHA-256:47E4E8472C71959A1CC12FB0857290E655AC901C68D209024A80012555F0C7D8
                                                    SHA-512:64B6E0CE233359E654E3E707B4B2E7125F3719649F17E107E66C5B56C216A63FBA10B3259D5741F05600B8F9DD9CCF9688B8A719D2D17F559551604458AE6516
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Dialogs module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in t
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):12934
                                                    Entropy (8bit):4.097455940794716
                                                    Encrypted:false
                                                    SSDEEP:384:iGReV5+MQbirxkSVx7oEk/Wb7Ri37lwbuUvr/c18/S7:iGWBeZ8/w
                                                    MD5:B0E29EE869FC72FDF86F89E0B0E9B621
                                                    SHA1:97A79B3E5C3343894B1107B72773E0435C2459B4
                                                    SHA-256:CAAA34C2AADF32D0EBBAACF17744C5797B79D4D377321F88139B3F13A14AB61C
                                                    SHA-512:849B344E4B9D17D324DC79CFD62387A08FD147F7B76898B7949928631DB61A16307D97B8671AB7975962693D5EC1413D3D524928177C58AAC2AD795C8AD09A2D
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Dialogs module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in t
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):55408
                                                    Entropy (8bit):5.974453238622661
                                                    Encrypted:false
                                                    SSDEEP:768:uVyRrddvnlKnDQdEh9nakPF5AUHER7s/kYiW3hN6:rnKDQdEEKE+/k7W3hN6
                                                    MD5:4B2419F6799AB1C2D1A910E91BE477BF
                                                    SHA1:31F9C8CB4E15FAE2A86A5C22D1F0FEC51C3FD8C6
                                                    SHA-256:8CDF64B5056D14D112AE342B7BE2469933F201F529E3347382E63DC2AB123C54
                                                    SHA-512:9907B97E1B13DF33DE32D5044C5628D362F21DF7C38BE76FBC46EB66B2D5682C0F8DF919D6AB55E265E57C507D5925ECDB3E7810356F3090618E71934D555AB4
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........w67L.XdL.XdL.XdEn.dJ.Xd.hYeN.Xd.nYeN.Xd.h]e^.Xd.h\eD.Xd.h[eO.XdXiYeK.XdL.Yd..XdXiQeI.XdXiXeM.XdXi.dM.XdXiZeM.XdRichL.Xd........................PE..d...v..e.........." ...$.J...p.......N....................................................`A................................................t...........`.......l.......p ......H....t..p....................u..(....s..@............`..8............................text....H.......J.................. ..`.rdata..@M...`...N...N..............@..@.data...x...........................@....pdata..l...........................@..@.qtmetad}...........................@..P.rsrc...`...........................@..@.reloc..H...........................@..B........................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):12562
                                                    Entropy (8bit):4.0547557110118335
                                                    Encrypted:false
                                                    SSDEEP:48:I8VFmGH8iSSoesW6kDFLN7rgJO4jybtuYR1pbbQDU1N1l1r1nL1DaHfI85I3P8v+:5ciSSts8XTKQfX5nZ35pkx0v
                                                    MD5:01A98548921015519F9BF96AFC6CA3F2
                                                    SHA1:7010F0A761839F0396B184A407F064A24E034CEF
                                                    SHA-256:9F2748312B462C9BD61A1638B91D2F0E36AF088DA06C55DE385D216299325892
                                                    SHA-512:62C11064E927370B42D6758DBCDF42446C7116638941EE6FA7CB5CCCAAE1DC06C5266D3F135C8669E59F4D732C7C5373241D3FC7E37ADCDE0519EC05701113D5
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2....// This file describes the plugin-supplied types contained in the library...// It is used for QML tooling purposes only...//..// This file was auto-generated by:..// 'qmlplugindump -nonrelocatable QtQuick.Dialogs.Private 1.1'....Module {.. dependencies: ["QtQuick 2.0"].. Component {.. name: "QAbstractItemModel".. prototype: "QObject".. Enum {.. name: "LayoutChangeHint".. values: {.. "NoLayoutChangeHint": 0,.. "VerticalSortHint": 1,.. "HorizontalSortHint": 2.. }.. }.. Enum {.. name: "CheckIndexOption".. values: {.. "NoOption": 0,.. "IndexIsValid": 1,.. "DoNotUseParent": 2,.. "ParentIsInvalid": 4.. }.. }.. Signal {.. name: "dataChanged".. Parameter { name: "topLeft"; type: "QModelIndex" }.. Parameter { n
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):128
                                                    Entropy (8bit):4.541086444900037
                                                    Encrypted:false
                                                    SSDEEP:3:3BVa60XzeBz3hVhvyWmopYPJoXhhy+RLV06qWov:xVa60DeR3hV58oOP2X6+key
                                                    MD5:D859E992832670DFFA54EBC48137C3E0
                                                    SHA1:9A36E7C010533552F9BBD537337B9EFE605D0B4B
                                                    SHA-256:328CE7281FF10EF0D90A753A716912656D3F97476624A584A8B50847127FA00D
                                                    SHA-512:7E92DFFB3E83DA37DE50CBF6C3E808EFFEFF1E49509EE68C7D2EF9B8094C025BBEA5CB1E023B0EEA8B406BE3617BFA3346CC022E6027D93207AF9D84E52FF849
                                                    Malicious:false
                                                    Preview:module QtQuick.Dialogs.Private..plugin dialogsprivateplugin..classname QtQuick2DialogsPrivatePlugin..typeinfo plugins.qmltypes..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2046
                                                    Entropy (8bit):4.839194226499755
                                                    Encrypted:false
                                                    SSDEEP:24:MLkMCT3QXf8WYwid0szM68qDRGNfFTNZbOWGf0HB+N7YiZTcfy9N9j:MLZO6E+iCshVKzlOWGf0hEVufy9nj
                                                    MD5:B6D6A211D4018E1871A28DA308C0A264
                                                    SHA1:8EE3F896DD57F62D9CBB01B6BFB5DDB59ADA2ADF
                                                    SHA-256:69A65B64D70B2328258AA1A35B52E1FC4D7A4FFBC2B458BC8CA48DD5BBB28C8F
                                                    SHA-512:A52F8ED39092E8B50923A68DFBD5B8CFD790EAE607575B0B10FE3DEE7E097FDBEBD92FA8D3923F6614FD7CE71DCDFA6F9EED5179DC5F4FF69E99B6A8CC3C20FA
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Dialogs module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in t
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2045
                                                    Entropy (8bit):4.838543971830859
                                                    Encrypted:false
                                                    SSDEEP:24:MLkMCT3QXf8WYwid0szM68qDRGNfFTNZbOWGf0HB+N7YiZTcfy9N9QWC:MLZO6E+iCshVKzlOWGf0hEVufy9nQf
                                                    MD5:9AE11A1E4DD9A3D282AD5BD773CFE0CD
                                                    SHA1:D08399E72B6CAD3634D15C9C3371F3B61112EA60
                                                    SHA-256:275DD745DE7DFBA2CFE20513C72F91DBBCF3A9E79A7C5C5826DDE116407F831C
                                                    SHA-512:4F20EE351C799972FA48DC0FF33B54AC56B51DE7232A14F50D8C3F20A698EC9C7822CDE95C4EC27A574028FEEE40308FB6FA7AA421485ADB0BFCA217E2ED51D9
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Dialogs module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in t
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2045
                                                    Entropy (8bit):4.839477066158387
                                                    Encrypted:false
                                                    SSDEEP:24:MLkMCT3QXf8WYwid0szM68qDRGNfFTNZbOWGf0HB+N7YiZTcfy9N9u:MLZO6E+iCshVKzlOWGf0hEVufy9nu
                                                    MD5:A87880CA314C1F7E637390F555D93CDE
                                                    SHA1:691774B5B2179CC0B31D976EEC8EFF37166A2D23
                                                    SHA-256:DC36D5A4E713A5CEED8E877CB16D30272953E736C99FBF933075220281E3A2EE
                                                    SHA-512:DEE0DFBFBEB7D1F43E7FE5AA7C7EEED019FE96D9D885D2C89C19025878D6213B3C95953922130CF877B7B6BE5962A9867B6B659FDC4328F5B0ABBD4DCFEFB7E3
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Dialogs module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in t
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2048
                                                    Entropy (8bit):4.841495536435705
                                                    Encrypted:false
                                                    SSDEEP:24:MLkMCT3QXf8WYwid0szM68qDRGNfFTNZbOWGf0HB+N7YiZTcfy9N9Q:MLZO6E+iCshVKzlOWGf0hEVufy9nQ
                                                    MD5:36FB0F29228ABACA2E0F0BF72EC62823
                                                    SHA1:FB1C98BA0DBC9D5B9B1D2CC3F947DDE5212CDA73
                                                    SHA-256:DC91A4E687696C4AA83E5A1D6E05BFDE8F3FAE8338691982E42F3282AF9A1E6E
                                                    SHA-512:747B56D7CE4281E25543C6D8705558FF0B3935CE9301FDD00998293B0761FB432143D4040BE97EF0BE15ED8F01045B176F9D08A72AD85B487E834F118122FE75
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Dialogs module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in t
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):148080
                                                    Entropy (8bit):5.959131693876304
                                                    Encrypted:false
                                                    SSDEEP:3072:QlV9pnDub3rpgz/mTdNUxH530LjUTIN/gxGFTfa3R4vx:+V9pncbUI/gxGFTfa3Cx
                                                    MD5:388C969AE797A1DD2B96024CDEC7CD28
                                                    SHA1:3921639E690373FDF88B75B355F64EB025AF2416
                                                    SHA-256:59ED349E9894C22977A4450D6ACD38F0C44A5C8E74162200393CDDFFB2351E6B
                                                    SHA-512:C3EA3A77EA7A1F5FBA432D336903DB27286BB6892A93FCD19F9A1C7397E7AB27C2E74D90532D3D1162DD40B4062D3DFA69FC3880F009B74E5D8C76D6E9C1EAB6
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...............................\.............\....\....\...............{.................e............Rich............................PE..d.....e.........." ...$..................................................................`A........................................`...|...........`..P....0..T...."..p ...p..\...`v..p....................w..(... u..@............0...............................text............................... ..`.rdata......0......................@..@.data...H5.......0..................@....pdata..T....0......................@..@.qtmetadm....P......................@..P.rsrc...P....`......................@..@.reloc..\....p......................@..B........................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):17475
                                                    Entropy (8bit):4.348278578219007
                                                    Encrypted:false
                                                    SSDEEP:192:LHq8/cRcYYcYrV2SDsb3I0+/wblTWOsG0A0+uWp:LILYLtO6bq
                                                    MD5:D42367D4EB91F9CA6204EEECCF4823BC
                                                    SHA1:BA8C790F54A5AD1A24F150A21211253B8F7CF966
                                                    SHA-256:768085CBACE8854A3D094DC13FEDA3F1521D647176AF6822436D6E1F1EEA7E98
                                                    SHA-512:5CC4E6866EF2530966662558FA3686AD9BD9C14F0DB26D6297FD94D5D36D85D9E22A49D370D0B1006FAC0B7443771EAA57A1868D2960A013FFFBE34FCDE1624A
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2....// This file describes the plugin-supplied types contained in the library...// It is used for QML tooling purposes only...//..// This file was auto-generated by:..// 'qmlplugindump -nonrelocatable QtQuick.Dialogs 1.3'....Module {.. dependencies: [.. "Qt.labs.folderlistmodel 2.1",.. "Qt.labs.settings 1.0",.. "QtGraphicalEffects 1.12",.. "QtQml 2.14",.. "QtQml.Models 2.2",.. "QtQuick 2.9",.. "QtQuick.Controls 1.5",.. "QtQuick.Controls.Styles 1.4",.. "QtQuick.Extras 1.4",.. "QtQuick.Layouts 1.1",.. "QtQuick.Window 2.2".. ].. Component {.. name: "QQuickAbstractColorDialog".. prototype: "QQuickAbstractDialog".. Property { name: "showAlphaChannel"; type: "bool" }.. Property { name: "color"; type: "QColor" }.. Property { name: "currentColor"; type: "QColor" }.. Property { name: "currentHue"; type: "double"; isReadonly: true }.. Pr
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5169
                                                    Entropy (8bit):4.536859187559398
                                                    Encrypted:false
                                                    SSDEEP:96:KZgUldGcQWEXgRNCyzWFjj7F6n6Qdt/CZny:KacGPRM2jY6Q6Ny
                                                    MD5:2053BEB17775590145452FF08C214A2D
                                                    SHA1:C659D1D8D08DFFDC300F4E285EB3C9515FAFAD73
                                                    SHA-256:09C0F59403C883BE3DD866A2ADB6BE5F5BE40ED9ABF73109C87BA6627843F3FF
                                                    SHA-512:1FA918BBD8752F61160C43438E0EE420A8ACCD2B44DACDE2D67C3E73C754F84990816EC7C24AFFB387328F4F4FD03B1AA8D91EAAAEE37E88844791FC959B6F77
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Dialogs module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in t
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2923
                                                    Entropy (8bit):4.814473625804855
                                                    Encrypted:false
                                                    SSDEEP:48:MLZO6E+iCshVKzlOWGf0hEVufy9LwM/iGyHzOyWa4rUsNklW:KZgUldGcQWB3C4sNk0
                                                    MD5:84B553B79DFEC2754C249E7B1D9C9866
                                                    SHA1:8FD19667062607A9221C2715930622A3F6D17290
                                                    SHA-256:27EAD3D6967813CC5C72A357536D0353D6A6C44D5199DC0F7BC918993F3AF846
                                                    SHA-512:98F111F4183E3D94D9D33DA91A128D3855A8028B5C59052E2E318DB5D053D6BE9A08ADAF55B4448E5767AE7BC994D8AC7E2D5E0AA0ECA54E3FD2AF6EFA53A2EF
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Dialogs module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in t
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2578
                                                    Entropy (8bit):4.882779279619284
                                                    Encrypted:false
                                                    SSDEEP:48:MLZO6E+iCshVKzlOWGf0hEVufy9nCfpAloH:KZgUldGcQWV
                                                    MD5:73FA314C522EBE80DC8F040691686A0A
                                                    SHA1:5497551F284B4001EA41351BAEFAD32DFBBFA9D7
                                                    SHA-256:C97B15440CF90EABF155D6EA8DBD58FE9821D0D4A5B7688EEA84432CDF5E92DC
                                                    SHA-512:DFCD5C6DF85162CA533326C87F9CE1F132ED5A85B192C9F838A419F7F329C63966A04641ACFAD8B15568149D992C33EFA9B3A1AFC094E2BB4BA43BE57794C166
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Dialogs module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in t
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2253
                                                    Entropy (8bit):4.856978310285491
                                                    Encrypted:false
                                                    SSDEEP:48:MLZO6E+iCshVKzlOWGf0hEVufy9XklypC8Uy:KZgUldGcQWqPF
                                                    MD5:D8710E02063FBE1B4067C084AF031FCB
                                                    SHA1:3DB05373A09ED4A0223228950A145E1F0FF9D2EF
                                                    SHA-256:9E11B7F60E9FDE3C7F923801F226C2211024A1BEDDE78CDFCA94162E53B6CD2F
                                                    SHA-512:FE17C421DAC0F2A31536580F7188B3522379C29BE686C6335D6231FA09F5E8E4DE8B45B0ED6D991A23C8E3794953F2C4F51FF6EEF6DF4FC1B163310F457FA871
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Dialogs module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in t
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):103
                                                    Entropy (8bit):4.4938650535504765
                                                    Encrypted:false
                                                    SSDEEP:3:IlTFBuRKL2ETsGQnERKL2zYsoE8FnQi6g0y:2TyQzgGy4Qh5nB0y
                                                    MD5:F69C5417FDACE8F0FE5777F919F0CC6B
                                                    SHA1:31188CB3833AF3D00E7684598AF82605C486FC87
                                                    SHA-256:F1DCCB2C3B5146E810BD0A09F666FF7487AC01F30EBA79F299405E24E03ED3B2
                                                    SHA-512:25DB3A52CE7CC41BBC998387D370CC94BAF201064BF369B34B4B48DDF3B1965F1DDB635AF0CDEDAE2644502A21CE09117AA66BB28F1F1ED80F11C2E4F5D3F41C
                                                    Malicious:false
                                                    Preview:ColorSlider 1.0 ColorSlider.qml..IconButtonStyle 1.0 IconButtonStyle.qml..IconGlyph 1.0 IconGlyph.qml..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):295
                                                    Entropy (8bit):4.672674055701312
                                                    Encrypted:false
                                                    SSDEEP:6:xVa6zeRxMe8oOP2Jz+keSADPTOsysm8ovyda60yHydfa3Cj98Vv:xleXMCbJfebOsRm0hw8F
                                                    MD5:07EE308A95E51E1307173609A33797BE
                                                    SHA1:22F129C701128699D7F9D2ED61C7E63D41A83D87
                                                    SHA-256:DFB9687DA7EF6417F14A2BD5972E0B801535A80017DC8E8C0C7E6553E535EA30
                                                    SHA-512:79442106707AE1716495AF3797D02DAD57E9F60881D52B90DFC237E5536CFB01197B2FC30D0292D2F7A8F691C3B6679043181610127B237CE36804B44401DF35
                                                    Malicious:false
                                                    Preview:module QtQuick.Dialogs..plugin dialogplugin..classname QtQuick2DialogsPlugin..typeinfo plugins.qmltypes..depends Qt.labs.folderlistmodel 1.0..depends Qt.labs.settings 1.0..depends QtQuick.Dialogs.Private 1.0..depends QtQuick.Controls 1.3..depends QtQuick.PrivateWidgets 1.1..depends QtQml 2.14..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5676
                                                    Entropy (8bit):4.7726498540719176
                                                    Encrypted:false
                                                    SSDEEP:96:KBgUldGcQW1v5WY3BidL2a2x02hl2qdtNLKZeSrarvaiZdHZx:KicGyfBidL2a2x02hl2qdHLKZ7Grvh1x
                                                    MD5:2E1DB6C476F35A8FB3542E0F77DBABBE
                                                    SHA1:97ADF79F907E3FD7A0BF7B0C35ADBFB738E0937A
                                                    SHA-256:24F10223E8925C365A5FCC1E79224C6E593A361A38A1C2B955978E4EB734058A
                                                    SHA-512:E6E6DF6572305F6CA32EA62C33FE05D598DD9C2ECD10F59239967E51A6042546B84B9819AD79827E9DD5468DC99BD7536A16EBF7DD4589B818D2963A433263B8
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5726
                                                    Entropy (8bit):4.7130001045679775
                                                    Encrypted:false
                                                    SSDEEP:96:KBgUldGcQWuKZO4ssJB3Gk11OjoJkTLJhsdS7T+be6Rxd:KicGvKZO4ssJB3Gk11Oj2kTLsdS7T+bv
                                                    MD5:61720E22F2346A1BF133C5D5DD60782A
                                                    SHA1:A89E5F3FD75AC1BF0A146147D0B4C0A5E45E78F3
                                                    SHA-256:EB63601F0723A606BE1E421C4E46FE056105730CB2C0C422554FF99EFE51C0AA
                                                    SHA-512:23013DFB5356FAA38F4D797B7A929E30E6C7477A552403089EBDE6E31CC1DF1D210BE5C67CC86337E43492FE8E5F9563CC0D1344DD1FE7383AC642B5C2488936
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):7052
                                                    Entropy (8bit):4.743862526265205
                                                    Encrypted:false
                                                    SSDEEP:96:KBgUldGcQWYMnV263JOPVlzl5zcdH2mf1q0qki2yh:KicGVW2mJOPVlRVqYpn
                                                    MD5:3B7348E45BE415AEA0C9C4515E274F51
                                                    SHA1:929C0F7C418DFCC62FFAF96DF919CDFE36F15023
                                                    SHA-256:CA2353D83016243F86D827F22E5CDF83B5D55F9C1AC56C0CC1FF96215F7688E7
                                                    SHA-512:7E25335D6B3CC71BD25BF31CD892CE5861374D73828C19A68D59F2365FED50223EAC019CC52D33AD38C675A5EF2EC7A1914334E21183D8B6B0A8CC3D7184A617
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):6678
                                                    Entropy (8bit):4.734079598050507
                                                    Encrypted:false
                                                    SSDEEP:96:KBgUldGcQWgkdREYHX5b8EWipuPFtImUa1vF7O:KicGXkbjJb8EYpF1vhO
                                                    MD5:CA2D951276D5AAE31369A61CE8B28B2A
                                                    SHA1:3CA5E556CA1A89D498F169737CFBC259C96063CC
                                                    SHA-256:65E437029D71CE48687D208F6A3162F775A973F505F9972B487D52F1E3382400
                                                    SHA-512:4ABF76BD67A67EAC5DE201E09DA481F3FD40384DE52F2B41E227AD5292ACEFF48E510586A491AFDA62655863B5DF1A8D953DE31090FEF506462BB49E286E6AAD
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):29354
                                                    Entropy (8bit):4.526297108060977
                                                    Encrypted:false
                                                    SSDEEP:384:4G/t7ir5Z+5kVEGzSovK2X4rFJJdsE/WQsrYxYM053FXqu:4GtiD+5kVEGGovK2X4rFJJdn/WQsrqu
                                                    MD5:0FF4E6187DDADCF90FFDAB49C458505E
                                                    SHA1:D36C3F8AFCE998EACED97CF46DC06C06451DEA10
                                                    SHA-256:58121B1731F5D33D99C11896F2399A04641D88E2158C9E777E0200DF88D9B6EF
                                                    SHA-512:A091D4169C2DA3A1C324D42873FFD76D31241A706C00AFF2566E55CFF0FBD8434AF24696EB7A83F2CAA43A7506BA273FDC47CC4F156FFEFA9994963D8053054B
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2233
                                                    Entropy (8bit):4.881134306782278
                                                    Encrypted:false
                                                    SSDEEP:48:MLBO6E+iCshVKzlOWGf0hEVufy9nMG+eE:KBgUldGcQWx
                                                    MD5:786450DE3F005FA1466EC279F850D241
                                                    SHA1:C8DADCCF4BE59EF6C773029535B26D81920E9379
                                                    SHA-256:C0E52CDA46ED7DB152D3D64CCD1D4BF5A240F49AC76107DB2A7BB161D9412BB9
                                                    SHA-512:12E21DC6857E8F65C922EB48DB50231D8D4203FA4151A91AC76D755DC65A4EB6EA69D30BC4794A3B71AB248DA41F413F53CD1DAC62E08B8400F702D5C1C92B79
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):6177
                                                    Entropy (8bit):4.967662497114283
                                                    Encrypted:false
                                                    SSDEEP:96:KBgUldGcQWe699od3tg9fYKiw4u6OnW1o9Hl2w7q5EQT:KicGNVmPTDF+5/
                                                    MD5:219E0C3F999D5EDC87DC3309972CC6E3
                                                    SHA1:34C2B1D3605024398738F2A4ECF51087A9388BF2
                                                    SHA-256:495F0E92CB6412EACD837F7EF9CDB775606F0FE04649E190628CF297FDA81437
                                                    SHA-512:AFD4C9D07B8F029F22A4CD75E32B9FA350AFF37E2741C070C61A807A2EA634514D3F22B2336E84B429F1DB9B609ED6D9F43BAD1B68B60BE4371E728F2867A204
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5261
                                                    Entropy (8bit):4.82716346895639
                                                    Encrypted:false
                                                    SSDEEP:96:KBgUldGcQWHuEAzkcz0bZi/XIO8XysEl01:KicGyuEQkUOwvIVXtP
                                                    MD5:FC97BBA3A16D4332D157364218F09837
                                                    SHA1:9E268A89858AAA09CE6271755E747146B9B8C225
                                                    SHA-256:4183FE0E604077C73B8FC1F45C7F971095C00D3D1E488A4E41E6B3B5C316898C
                                                    SHA-512:DB33B83016FDAFC21F01849C8E599F518F239FEC691859C906A2A0863DA1C49784F509B60A615693FCC50B2A13C4CE1B3C6D56FAA216603E7C1A70D8228D3675
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4681
                                                    Entropy (8bit):4.8084840069790795
                                                    Encrypted:false
                                                    SSDEEP:48:MLBO6E+iCshVKzlOWGf0hEVufy9IPGfpYz61xiiNhmdsEIhi1g8aIDqLGk1KINSt:KBgUldGcQW5vz6rOdsTi1g8aLyY0
                                                    MD5:8FB6467BE5CCC9FA54AD307F7DDC100E
                                                    SHA1:9ADA1A973E92A73A713011FEFA42888289760C6F
                                                    SHA-256:1CEEE48637239B07D106648585E7241B91EE124EBAEB07DCF63D811A7E45C44A
                                                    SHA-512:5655547B4E08938C6BDE9F62D5BC5F60EEB44FC9726C25CD57243A128F9BB70CE22AF692FDEA1729DF1036D48ABD774735BFFACBAE3C4089F01B241235AC163C
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4559
                                                    Entropy (8bit):4.730940474493659
                                                    Encrypted:false
                                                    SSDEEP:48:MLBO6E+iCshVKzlOWGf0hEVufy9arEUi+MipDS+EmSJydqbsXO2Of8BvR7VbwVtf:KBgUldGcQWTw+EmSJcMsP6AWU3e
                                                    MD5:9C988515EEBD0F96D4CAF7D3FB72827A
                                                    SHA1:BBC4936E6456F86D9B08DFCED6D7C195ECF4EFA4
                                                    SHA-256:A2528141AF8D698E4D1DD06AF73C541D6A16E2C0C5A096AFC3ABD951F9D74FDD
                                                    SHA-512:3782C2BD9339C333CE862793C382EAD3EF0A07140AA8E965D4A258B23448882065642B699ACA27F716E990D396A96F6842ECEF1175BB6C3AA1019550BFBAB9F4
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2020
                                                    Entropy (8bit):4.830013902339838
                                                    Encrypted:false
                                                    SSDEEP:24:MLkV8CT3QXf8WYwid0szM68qDRGNfFTNZbOWGf0HB+N7YiZTcfyyULD:MLBO6E+iCshVKzlOWGf0hEVufyyUv
                                                    MD5:6B4C4C15EA696B3B30359ED43343E8D2
                                                    SHA1:DBF2A8E9A11B7E28B2C42A1ED6732D3450B426DC
                                                    SHA-256:F4B8ECE1E1550AE9D546E1B2FA91C54B76DA874640EDC19A8F64DCF0D1125F3E
                                                    SHA-512:F17197CF3744D4D2B245A04AC8DDF2392410360DD922BC3D31C48F3B98B0A146BCD5EBBB2E45B969AB626ED7269492C0E4391AFF0A08EFD8648638FA0BB44C83
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):31
                                                    Entropy (8bit):4.349199939349345
                                                    Encrypted:false
                                                    SSDEEP:3:3BVaLd3:xVaLd3
                                                    MD5:3500B3083629424F19A55A3A8F58005C
                                                    SHA1:A38CD39CF61E314F05244B2D70D465C0BD36079D
                                                    SHA-256:E99C49C8CAED113ACB26774470338553E0658FF21C6CB9B2534DE200DA466B87
                                                    SHA-512:7A2AFCF8AEE4D01D1F8A0A6CFE6BC07E195694DAA5F56DF7B160E740B5BC74B73B7EBC7A9F4D14564FBAF1EB7901E5F62A32111536C452D668E585B385FF46C2
                                                    Malicious:false
                                                    Preview:module QtQuick.Extras.Private..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):4261
                                                    Entropy (8bit):4.710820074705165
                                                    Encrypted:false
                                                    SSDEEP:96:KBgUldGcQWRbtV199E76sq53r5vA3tshShRHu5:KicGAEy7x0C
                                                    MD5:8E53A9A95F2526CEBF49E0D3BCF47450
                                                    SHA1:9DA912C4EB4CAB0944BF87724E8CA13FA0DFD716
                                                    SHA-256:994CE7A5EB60CF4DA21019263FBBA9B18304D87B711F6E3528E4F404650BC6C1
                                                    SHA-512:3C009084EDCF9E6AABE5819C84D89AE9435F8EC7A815EBDC28E7DEA8C42629CA43770DF48E3EE84073914090E4965E4A859D839093BBA0582E4256B8F045ACEF
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3008
                                                    Entropy (8bit):4.886635162451843
                                                    Encrypted:false
                                                    SSDEEP:48:MLBO6E+iCshVKzlOWGf0hEVufy9nMG+mipJ4m57gquKdO:KBgUldGcQWIo+mKUO
                                                    MD5:9505AF4726B85352E06441B84D91F62E
                                                    SHA1:9360D634A20BE9AB1839E26DB360E2311E1550D3
                                                    SHA-256:E4F3D5529E2FD51DA48E750B9C0BBF9845A19CD59A33599A150021F41DE8B53A
                                                    SHA-512:82F3BAC16AB008426CF2D769F6218BD5C11DE96E9547B525C60B9746D0979BD80B52E2F80631B101B42D7DEE8F185480201A4DBD100EC64E7A6534832B86D875
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:LaTeX document, ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):18368
                                                    Entropy (8bit):4.360636880170929
                                                    Encrypted:false
                                                    SSDEEP:192:KicG2zZzMcGNR8SUvh0Do+4gkhiS+BxlT82Zz77FaAR2MB:4G2zZW5nNdxV82NFaG
                                                    MD5:8D8CFFB011863658FAA1AECFE735AA60
                                                    SHA1:9A538231678B66C804AE9FA3F1EDEA30944D1C71
                                                    SHA-256:8A4722C16E19EFBA0BFB6473C22378D8013975DE3D3DFBE5CC5B6E29FE0EF1DC
                                                    SHA-512:5724D88AEC7B88D7BC63977B0540C1EDC1798C7E5CE8358B9C74442715DFB0FFB519D06F57F61DCD0E5F5246ABB7F1C274BD6373B5F0405930B6223318CA6B5C
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5447
                                                    Entropy (8bit):4.737306098999365
                                                    Encrypted:false
                                                    SSDEEP:96:KBgUldGcQWtQpjRHBGv+JJ3w+Y8wF4lQNt6kJI9:KicG6Uj7++JJ3w+Y8wF4lQP6ko
                                                    MD5:C270DA54F358E963C12D1A85B8F9280A
                                                    SHA1:8204CC91223586F675B0F41D8A695B6F56CC51D2
                                                    SHA-256:1250BD960712C00F7E05EFFA12A81DBD0FA88E273FB44C6370C29A8C845E3BF5
                                                    SHA-512:B0F32A7C655EDC15248ADCF3474C1438854DA059CE07527736C4905E80E89E30D4221B57146C4FC1BBE5A606126C3EC317A6CD5E91B57899C14A7282B3EA7B15
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2016 The Qt Company Ltd...** Contact: https://www.qt.io/licensing/..**..** This file is part of the Qt Quick Extras module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see https://www.qt.io/terms-conditions. For further..** information use the contact form at https://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPL3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):30070
                                                    Entropy (8bit):4.4543713038878705
                                                    Encrypted:false
                                                    SSDEEP:192:cNAIajHy4asgviWbcUlfPYYSTxpkxhp9EkszelHUlfPiuA9uAY0mjdnoH3J7BcYf:kAIajHy45L8Fb
                                                    MD5:A4553474F5C2AFD19157588CF55A8E4B
                                                    SHA1:580B345C7CE893B2B5E9E3DA1087C7FA5D6C6C77
                                                    SHA-256:8D75B0D1E0EF9AF3496989BFB28AF6FC81752A0D148AA72E2D457BF07C2929F6
                                                    SHA-512:5C41145931D17A34A1E0C30F4A8E17257D0A1A5B1B260349F50E58E5C6B7719CAF31FC95F23FD185FE53E71EDFDE2C8C156AD7F8EA051D019BD56156B954C811
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2....// This file describes the plugin-supplied types contained in the library...// It is used for QML tooling purposes only...//..// This file was auto-generated by:..// 'qmlplugindump -nonrelocatable QtQuick.Extras 1.4'....Module {.. dependencies: [.. "QtGraphicalEffects 1.12",.. "QtQml 2.14",.. "QtQml.Models 2.2",.. "QtQuick 2.9",.. "QtQuick.Controls 1.5",.. "QtQuick.Controls.Styles 1.4",.. "QtQuick.Layouts 1.1",.. "QtQuick.Window 2.2".. ].. Component {.. name: "QQuickActivationMode".. exports: ["QtQuick.Extras/ActivationMode 1.0"].. isCreatable: false.. exportMetaObjectRevisions: [0].. Enum {.. name: "ActivationMode".. values: {.. "ActivateOnPress": 0,.. "ActivateOnRelease": 1,.. "ActivateOnClick": 2.. }.. }.. }.. Component {.. name: "QQuickCircularProgressBar"..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):164
                                                    Entropy (8bit):4.765779135496663
                                                    Encrypted:false
                                                    SSDEEP:3:3BVaGJQCeURtvyWmopFRPfG67XLV06qWoGNR09FGhCULVyyQR9bVvn:xVaGdeU38oDVfL7OeA9Itsy+Vv
                                                    MD5:7896B1C0E4737EAF8D683B49E0FE1CCF
                                                    SHA1:569926268B4D948C05EF4C72C526747155C9FF96
                                                    SHA-256:AB1AC853929DBCB99495C2098C2AEBA06E7B3EB0ACCE3DBD2C0F0F6C74211427
                                                    SHA-512:3EC9F6BD2E7D82661E3D7E6E90B6BEC4F812642747A93FC443CAB5083618C2D61F981050F045D7BA945821DCEAB30DEEA495183C61488999C6CAA1A00B1BCA83
                                                    Malicious:false
                                                    Preview:module QtQuick.Extras..plugin qtquickextrasplugin..classname QtQuickExtrasPlugin..#typeinfo plugins.qmltypes....depends QtGraphicalEffects 1.0..depends QtQml 2.14..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):77936
                                                    Entropy (8bit):5.918486721498287
                                                    Encrypted:false
                                                    SSDEEP:1536:4eFepEOmFklVj4q0xS+TebYtI4q0x+VDnPz/Ivo57i33h6Z:ne9Vj4RI+EYtI4Rx+VDnP8vyesZ
                                                    MD5:DC4DFBCA3A1A3ACCE110B9CD83B5A029
                                                    SHA1:FA2D1A41FEDBD637EC24500616152C67BF9C4CB9
                                                    SHA-256:3773F043F2305A73D975527E5B6B9692C51A36E69D56BAB36077E0431295AC1E
                                                    SHA-512:3F5D8711BAA469F97B5290221FC73AB6A275EBBD4D56718200543CBAAACEA79A5AC347DD2B3345D201996D625CBF4B621F695968F1AC978A944F5E568909E68A
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......t...0b..0b..0b..9.j.6b.....2b..{...2b.....$b.....8b.....3b..$...9b..0b..*c..$...=b..$...1b..$...1b..$...1b..Rich0b..........................PE..d......e.........." ...$.v...........z.......................................`.......w....`A................................................P........@..X.... ..8.......p ...P..........p.......................(...@...@............................................text....t.......v.................. ..`.rdata..Hn.......p...z..............@..@.data...............................@....pdata..8.... ......................@..@.qtmetadj....0......................@..P.rsrc...X....@......................@..@.reloc.......P......................@..B........................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text
                                                    Category:dropped
                                                    Size (bytes):4745
                                                    Entropy (8bit):4.502977259745385
                                                    Encrypted:false
                                                    SSDEEP:96:1uxcACwWq5iEgipwiIoorzq8vOuNrtvgIOJ0eKJibiy4lw3yL:8qACwWWiEgipwiIoorzq8vTNrtvgIOJA
                                                    MD5:9283D1D3E47B670E900F93074D4C1A35
                                                    SHA1:71FF0FDAA07BBA0116547FFFCB7189CE586C4572
                                                    SHA-256:ACA88244E2AC5FF225E14A7279E518109B94F82DCDE8DE0640893EFC2B607316
                                                    SHA-512:9C51062860EDF81C3FC9AD0FB6F382E452FB011F849A2415296B93CA707F8A8CD6BCFE36CA865F8145CB6AAA60D03DB1883B34B0B01F94F35CD47E42E03DB43B
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2..// This file describes the plugin-supplied types contained in the library..// It is used for QML tooling purposes only..//.// This file was auto-generated by qmltyperegistrar...Module {. dependencies: ["QtQuick 2.0"]. Component {. file: "qquicklinearlayout_p.h". name: "QQuickColumnLayout". prototype: "QQuickLinearLayout". exports: [. "QtQuick.Layouts/ColumnLayout 1.0",. "QtQuick.Layouts/ColumnLayout 1.1",. "QtQuick.Layouts/ColumnLayout 1.11",. "QtQuick.Layouts/ColumnLayout 1.4",. "QtQuick.Layouts/ColumnLayout 1.7". ]. exportMetaObjectRevisions: [0, 1, 11, 4, 7]. }. Component {. file: "qquicklinearlayout_p.h". name: "QQuickGridLayout". prototype: "QQuickGridLayoutBase". exports: [. "QtQuick.Layouts/GridLayout 1.0",. "QtQuick.Layouts/GridLayout 1.1",. "QtQuick.Layouts/GridLayout 1.11",.
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):130
                                                    Entropy (8bit):4.486904883928531
                                                    Encrypted:false
                                                    SSDEEP:3:3BVq+sCeUUucMjQCzvyWmopjD+RLV06qWoZAhoAw:xVqeeUUurjQG8oF+keSAho5
                                                    MD5:E9CA7D1D1F439C9BE217759F619BF102
                                                    SHA1:C8569CB2A6FCB910121AFE65CABCEA65D28375FF
                                                    SHA-256:CB585C2FC06EDCA4B95C9EE04017CD384CAE70356E8DD468ABD7C4FD1E640B59
                                                    SHA-512:A4F1D3D8B825F9B7E9BFD0C7FBAFD7CDF379C28BFBFD8C78DEC27546EC0CCC3871CB9B69DAF12D0A262756593B39E28D47344C075AAAB68998545638BCF214F8
                                                    Malicious:false
                                                    Preview:module QtQuick.Layouts..plugin qquicklayoutsplugin..classname QtQuickLayoutsPlugin..typeinfo plugins.qmltypes..designersupported..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):117360
                                                    Entropy (8bit):5.963810398013701
                                                    Encrypted:false
                                                    SSDEEP:1536:GwmqMfHnlxuF2A/Oc6tSjSSekydqEmeZk8yEOLme5ITeX3F+VouWE3793hQd:Gwmr9xoX30S2Fk/EbALb5IT238KuWcgd
                                                    MD5:8CADF781FA8DF526E5FB815A595B956A
                                                    SHA1:064E21BEC6DF772A3CB07546959276066EE7490D
                                                    SHA-256:9E52F9D14F95BDE2F77D9354BC74E907903F2C506A05C0EDE52217E90707DACD
                                                    SHA-512:2C1F4978C74B03BD10F276D4A4A0C09C7E97A9205BD072C489CB68EB348077A68C1F7602D0586B6CA2376890178CD1286306E58B5169A9C982C9DAD57712E070
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........~..o-..o-..o-..-..o-t.n,..o-..n,..o-t.j,..o-t.k,..o-t.l,..o-.n,..o-..n-..o-.f,..o-.o,..o-..-..o-.m,..o-Rich..o-................PE..d......e.........." ...$............p.....................................................`A........................................ P.......P..........X...............p ...........'..p....................'..(....%..@...............0............................text............................... ..`.rdata..............................@..@.data................t..............@....pdata..............................@..@.qtmetadn...........................@..P.rsrc...X...........................@..@.reloc..............................@..B................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):11455
                                                    Entropy (8bit):4.228473811710657
                                                    Encrypted:false
                                                    SSDEEP:96:53C8H8/Fu4ELAPQYLAPQyOVdICMTuDsTX3I0+wCiCzwCqlnmhSh0kjoZf:l8/cRcYYcYrV2SDsb3I0+ZwblpG
                                                    MD5:845FF3CE496D07712D628816B9E4AFA9
                                                    SHA1:DE7514C31AFDD73811D7E16D6DBAE6884C5A8512
                                                    SHA-256:D7CBCD34A59B9EB7C2B0D12077EABC8FFCB9091D7AFDCA45633F511A3C670D5E
                                                    SHA-512:F70573880A5BE280A979ED5C85269998B3E5C91E53449BF5178CC4F321A8B020123FC0D538CEA5D18968F9C94BCD75C73F03C9CA3B20E2E482FF49ACE25E4DB7
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2....// This file describes the plugin-supplied types contained in the library...// It is used for QML tooling purposes only...//..// This file was auto-generated by:..// 'qmlplugindump -nonrelocatable QtQuick.PrivateWidgets 1.1'....Module {.. dependencies: ["QtQuick 2.0"].. Component {.. name: "QQuickAbstractColorDialog".. prototype: "QQuickAbstractDialog".. Property { name: "showAlphaChannel"; type: "bool" }.. Property { name: "color"; type: "QColor" }.. Property { name: "currentColor"; type: "QColor" }.. Property { name: "currentHue"; type: "double"; isReadonly: true }.. Property { name: "currentSaturation"; type: "double"; isReadonly: true }.. Property { name: "currentLightness"; type: "double"; isReadonly: true }.. Property { name: "currentAlpha"; type: "double"; isReadonly: true }.. Signal { name: "selectionAccepted" }.. Method {.. name: "setVisible"..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):120
                                                    Entropy (8bit):4.556322130296164
                                                    Encrypted:false
                                                    SSDEEP:3:3BVd6wPCeSADREvyWmopYVKwDz+RLV06qWov:xVj6eSARG8oOVNDz+key
                                                    MD5:816F665BE0760D3076997D321C1A4602
                                                    SHA1:2AB13F275A5F32CE342E5D5465115CC43EED0C33
                                                    SHA-256:D7B049361AC87B285138C2091D489F84CC71CCC517A3D68749F5FCBF963347F3
                                                    SHA-512:7BCDBAABE8D51EB35725CB7CBCC480412BF4A257084FE972C28A13D86D249E3F27CE65D79295563666F33DA6F86167B456EC8A35F78DB700F8A619066F893D85
                                                    Malicious:false
                                                    Preview:module QtQuick.PrivateWidgets..plugin widgetsplugin..classname QtQuick2PrivateWidgetsPlugin..typeinfo plugins.qmltypes..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):131184
                                                    Entropy (8bit):5.91482231020952
                                                    Encrypted:false
                                                    SSDEEP:3072:/EeBCAAY3nFeH9LpH+FeNma/gNGqT+Cf9/qIeLF:xeH91AeNma/gNGqT+CFiF
                                                    MD5:D7A9D2637D32174E552EA6A7D796EB5C
                                                    SHA1:DC534FF97CCA8B93C63ACFBAB21A61C7D675D829
                                                    SHA-256:57B5FA4D9E51417CE0946CA63D06265017F16874686CBE322B915F661BFDE30C
                                                    SHA-512:3F49D254C635C72F4C298BF333C537F3A996F77309A7A66368051714D8CB8A5B397EF2530033C33737809A13BD5E0D4752C167E30E7C64CE43BC7B4A739FCFF4
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..................y...."........"...."...."..........w....................Rich...........................PE..d......e.........." ...$..................................................... ............`A.........................................I..|...\J..........P.......X.......p ..........@"..p....................#..(....!..@...............h............................text............................... ..`.rdata..............................@..@.data...0........(..................@....pdata..X...........................@..@.qtmetad|...........................@..P.rsrc...P...........................@..@.reloc..............................@..B........................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text
                                                    Category:dropped
                                                    Size (bytes):5523
                                                    Entropy (8bit):4.432629890468112
                                                    Encrypted:false
                                                    SSDEEP:96:1O2FQCG5BeEjlKpxoXklAG2aayiyB0oUilLiqfPMiQPPxFygYt1AFbsO7Ky6ZNkt:42FQCGBeEjlmxoUlAG2aayiyB0oUilLQ
                                                    MD5:27DC08C3AB67CE8FECD3E391A50A0339
                                                    SHA1:C3AFFA7BDB41F7928B4113A0081F00BFED6E92D5
                                                    SHA-256:A0D94110525F0AA508B9E861AFED935B7E63F4011C69A2223A990417752D51CB
                                                    SHA-512:608EF53CFC6D7678C99499F605DCA62C98AC3FE685453717ACED4D2DE4899AB581BCB798D9C5D8D85D6191923ABBD01CF2717EE60F2D4D39B030133F4E40C01E
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2..// This file describes the plugin-supplied types contained in the library..// It is used for QML tooling purposes only..//.// This file was auto-generated by qmltyperegistrar...Module {. dependencies: ["QtQuick 2.0"]. Component {. file: "qquickshape_p.h". name: "QQuickShape". defaultProperty: "data". prototype: "QQuickItem". exports: [. "QtQuick.Shapes/Shape 1.0",. "QtQuick.Shapes/Shape 1.1",. "QtQuick.Shapes/Shape 1.11",. "QtQuick.Shapes/Shape 1.4",. "QtQuick.Shapes/Shape 1.7". ]. exportMetaObjectRevisions: [0, 1, 11, 4, 7]. Enum {. name: "RendererType". values: [. "UnknownRenderer",. "GeometryRenderer",. "NvprRenderer",. "SoftwareRenderer". ]. }. Enum {. name: "Status". values: ["Null", "Ready", "Processing"].
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):101
                                                    Entropy (8bit):4.438468136853489
                                                    Encrypted:false
                                                    SSDEEP:3:3BVqEtGJXeUIBOcvyWmxAEtDce+RLV06qWov:xVqndeUIQe8ue+key
                                                    MD5:E41C8121DCBA32E0AC364120D729CDA2
                                                    SHA1:29F76ED802C3C243D436B5761C09A2C97C1BCA70
                                                    SHA-256:5964AF58F2A0371E9C5A4FD87514E006C12A7D97E23E5B8E56A0F86BDA00D64C
                                                    SHA-512:CD8DFB29CFA78F391DDBDC7CE79D59228D92993A6F9D8FBBE22B854CCC1F7162DD99BE3E6215062B96BD96CB247CFEA74C695DAE11C5982B117BA03E59F28807
                                                    Malicious:false
                                                    Preview:module QtQuick.Shapes..plugin qmlshapesplugin..classname QmlShapesPlugin..typeinfo plugins.qmltypes..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):27760
                                                    Entropy (8bit):5.848234632370393
                                                    Encrypted:false
                                                    SSDEEP:384:u9Xh4r1QVt7S/eu15uVjd45sjVBIYiy0P8P8JN77hhZD:o4R+ZAtPB5sjVWYixP8U3hjD
                                                    MD5:5C338BEC1DD591D095338E6F4F18503E
                                                    SHA1:F2CA84B7C199F9AAFA5FBE861C62D0C48949175F
                                                    SHA-256:15CADF0B168C49A70A5F71DF07ECF47132C73F1FF29CEB6FB4A1F7DEF470D6D7
                                                    SHA-512:B3A86DF6DF6D72C7A485B9F179C1AAC27807D54D82B71249F46717B523D99DB839B7B194256D7CF81605E6CF07E580BCA3ED046C895C13AECEBB5DE4867FDFB2
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........zC..)C..)C..)J.7)G..)..(A..)..(A..)..(Q..)..(K..)..(@..)W.(D..)C..)...)W.(B..)W.(B..)W.[)B..)W.(B..)RichC..)........................PE..d......e.........." ...$.....6............................................................`A.........................................C..|....C..........P....`.......L..p ...........6..p....................7..(....5..@............0..0............................text...+........................... ..`.rdata.......0... ..................@..@.data...p....P.......<..............@....pdata.......`.......@..............@..@.qtmetadf....p.......D..............@..P.rsrc...P............F..............@..@.reloc...............J..............@..B........................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):129347
                                                    Entropy (8bit):4.353850126184248
                                                    Encrypted:false
                                                    SSDEEP:384:/w4mzWW7TUwVrpPFKR8wEsCrO413mtCChAIwU7kowHCCRO:/w4mzxPUw2EsCrO4ZQSU7kvHCCRO
                                                    MD5:E2B590A1F1A8596F646D7E4993BCBB43
                                                    SHA1:2FC7385058C8C55CB75EAD3A62146C9179C04CF3
                                                    SHA-256:5DF0927CE02B8C4FB28DD932F41977019329B2A348E3CC1420819C719460CE6E
                                                    SHA-512:77C43A95B884D99F26BC9ED2078DB759DFE3005A3855822E178D290DD653AF6A3668662CCAACFC7C7ECA3D914E1F23F9CD49AD2F8A2B4A30DE9034028F90EDE9
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2....// This file describes the plugin-supplied types contained in the library...// It is used for QML tooling purposes only...//..// This file was auto-generated by:..// 'qmlplugindump -nonrelocatable -dependencies dependencies.json QtQuick.Templates 2.15'....Module {.. dependencies: ["QtQuick 2.9", "QtQuick.Window 2.2"].. Component {.. name: "QQuickAbstractButton".. defaultProperty: "data".. prototype: "QQuickControl".. exports: [.. "QtQuick.Templates/AbstractButton 2.0",.. "QtQuick.Templates/AbstractButton 2.2",.. "QtQuick.Templates/AbstractButton 2.3",.. "QtQuick.Templates/AbstractButton 2.4",.. "QtQuick.Templates/AbstractButton 2.5".. ].. exportMetaObjectRevisions: [0, 2, 3, 4, 5].. Enum {.. name: "Display".. values: {.. "IconOnly": 0,.. "TextOnly": 1,.. "TextBesideIcon": 2,..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):142
                                                    Entropy (8bit):4.511396815119841
                                                    Encrypted:false
                                                    SSDEEP:3:3BVGIjNzeURdUEmsQPcvyWmop8NMXKyxRSfL8SFzSnRcXoyn:xVGIjxeUzDz8o5XDCPJ51n
                                                    MD5:1B909B940F9E8FF6F44D559D99BA98EB
                                                    SHA1:B84E860F41161F5B218DF3FDA1198D7A171D53F1
                                                    SHA-256:B24F2C4AFF9A7F102F2A25BCF552D91F637160E55E053583298B0A16C93AEF23
                                                    SHA-512:E9998A29ACD59336A6FF7C56F09FA128B982621A4965388F1A25B03682114B4725DFFBE292A0C288D053F20D8B3B1D09216B7CA41F567A28495F9C03682A4D13
                                                    Malicious:false
                                                    Preview:module QtQuick.Templates..plugin qtquicktemplates2plugin..classname QtQuickTemplates2Plugin..depends QtQuick.Window 2.2..depends QtQuick 2.9..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):363120
                                                    Entropy (8bit):6.104583192868858
                                                    Encrypted:false
                                                    SSDEEP:3072:Iug9KxYq0wjlgQ4hZ/eAhtHwP4IZxbLFYdNP:Iug9MV0CdGZLjWbLFAP
                                                    MD5:EA63D27BFFF1151A67498033EFC4759A
                                                    SHA1:8AB78057F629183D30747ECA601930005A6BFA40
                                                    SHA-256:B2B768D82C5B3C2C2C52F91956BE09FA01E3B7967C9CE6830B0DD6470C9C610B
                                                    SHA-512:84E80E4D3ECD2B3989542456855A8E25552749C2E1EB10406CFB555ECE18182E2E738CA51B0C0A3570F4DA704DCC4C5538FE36F59E98765BD1A5EFBC742A5367
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$......./...k..k..k..b.^.o....i.. ..i....y....c....h.....`..k..~.....j.....j....2.j.....j..Richk..........................PE..d......e.........." ...$............................................................v.....`A........................................p+.......+..........`....`..p....j..p ..............p.......................(...P...@............................................text...[........................... ..`.rdata..D ......."..................@..@.data...@*...0..."..................@....pdata..p....`.......,..............@..@.qtmetads............D..............@..P.rsrc...`............F..............@..@.reloc........... ...J..............@..B........................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text
                                                    Category:dropped
                                                    Size (bytes):8402
                                                    Entropy (8bit):4.367307060486788
                                                    Encrypted:false
                                                    SSDEEP:192:RyfyibkrKyT5yimDlslXglI3l8lRlzl8lhlilGIl8lml/4ly4lETohsMi3iMeb3T:pODqDSthu
                                                    MD5:922E99D428833D7B95EF41FE392ACC64
                                                    SHA1:ED55E40D8F3FE3EF660782BB98C93212ECA3D0E4
                                                    SHA-256:602810BE90BD59C6682702970A91A003DE5F0F636F006B6C8C7D987DE6C8F250
                                                    SHA-512:0CB8D6A877ED27B6609BC71383D3218EFEFA0916573C86D2DD55B2A7FAE7D05536A8697FC024F0012641B9742843346007EF4802FD64D107A7322DE0AD03FEC7
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2..// This file describes the plugin-supplied types contained in the library..// It is used for QML tooling purposes only..//.// This file was auto-generated by qmltyperegistrar...Module {. dependencies: ["QtQuick 2.0"]. Component {. file: "plugin.h". name: "QQuickRootItem". defaultProperty: "data". prototype: "QQuickItem". Method {. name: "setWidth". Parameter { name: "w"; type: "int" }. }. Method {. name: "setHeight". Parameter { name: "h"; type: "int" }. }. }. Component {. file: "plugin.h". name: "QQuickScreen". exports: [. "QtQuick.Window/Screen 2.0",. "QtQuick.Window/Screen 2.10",. "QtQuick.Window/Screen 2.3". ]. isCreatable: false. exportMetaObjectRevisions: [0, 10, 3]. attachedType: "QQuickScreenAttached". }. Component {. file: "plugin.h". name
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):122
                                                    Entropy (8bit):4.531514845496093
                                                    Encrypted:false
                                                    SSDEEP:3:3BVfL8SyVMSKBK+6ovyWmopY9d+RLV06qWoZAhoAw:xVPGMSatz8oOX+keSAho5
                                                    MD5:C434589591A9B33CBE88891AFBB7C144
                                                    SHA1:42476FB63F3CF463B4BB03B47048AA0918E588B5
                                                    SHA-256:8D88B81547E1573F8C91DF998EA82608E0A79770B014C82F760A67388B41945A
                                                    SHA-512:5A09830970EA37942166C1E5E5CE0FE452290EB9CD662FFAA9858BDB61806CAA03B1016D30C98871A7B6C8FDFA369E29E3940A5F9779D967B98EDE5901F4D30F
                                                    Malicious:false
                                                    Preview:module QtQuick.Window..plugin windowplugin..classname QtQuick2WindowPlugin..typeinfo plugins.qmltypes..designersupported..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):56944
                                                    Entropy (8bit):5.815845853663434
                                                    Encrypted:false
                                                    SSDEEP:768:NFYSXCYVKIueAiLgF425Il9JMYiMr3hP7:NFYaVXHAPK26l9JM7e3hP7
                                                    MD5:268E353AAD9858B70BF1468FE8C61E21
                                                    SHA1:03F9855F44BC8A3BC8B51B37FCBD1739D03F4AAD
                                                    SHA-256:8EC01D2C45936C58FFBBC07DC7081004CF0CDCCFDCF6DC806136502744AF325D
                                                    SHA-512:994EE3ED110707403C9F1B8BAA553FD2A87376C5BA64007ABC1B3F52334B3AFD2A4ADA8B3CAB4400155FE3521825E6AA71836F89C55F7ECBC354455F2ACD7924
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........)b.H...H...H...0...H...6...H...0...H...6...H...6...H...6...H...7...H...H..uH...7...H...7...H...7.H...7...H..Rich.H..........PE..d......e.........." ...$.B...~......0H....................................... ............`A........................................`...|..............P....... .......p ......L...`x..p....................y..(... w..@............`..X............................text....A.......B.................. ..`.rdata...W...`...X...F..............@..@.data...............................@....pdata.. ...........................@..@.qtmetado...........................@..P.rsrc...P...........................@..@.reloc..L...........................@..B........................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2709
                                                    Entropy (8bit):4.819482934287215
                                                    Encrypted:false
                                                    SSDEEP:48:MCdqBH6E+iCsAaKj7fOWIkFy9NQ3JGrSGlSSh:ndqBCB7fdpF53yI8
                                                    MD5:BF2A7F96BB58D1912ABFC880B319EB08
                                                    SHA1:360C5BFCAF8E7B783BF368A22A87EFB148F21B17
                                                    SHA-256:17451D2C875D813FFD669EC8C595F50DA1B288020040B859781929569B90B189
                                                    SHA-512:996522602A1E3AC6A415C0B062AA1EBA3A597BCEDBC5D8BEBDA0D5008E923C0ACF177FFE0F489A61EB0A16CD89186218D3EFA5DA1BEBF017475CB77BBC74A853
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Labs Calendar module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2777
                                                    Entropy (8bit):4.805934489632003
                                                    Encrypted:false
                                                    SSDEEP:48:MCdqBH6E+iCsAaKj7fOWIkFy92Q3JGrfGlutMZFh:ndqBCB7fdpF83y8Zz
                                                    MD5:EE49E56BC5F9AB2D06EE288060476FB4
                                                    SHA1:2B44D1B8387A7931DDD046C24B21B9B7C3B54398
                                                    SHA-256:0C696F3880CB326F7DBB4F4EB0ED9CE951BC6437D9C9489D656DDD79F597BF08
                                                    SHA-512:F074620818C3AC085D60D32C97AB621E1A669BE64A9085D9FAA38EBEBF21304ADF02AC07C1A1CD6CF213C21C1B719EAE70ABE89D37C670BBA6936433CFD8F0B8
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Labs Calendar module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):2717
                                                    Entropy (8bit):4.81440331416218
                                                    Encrypted:false
                                                    SSDEEP:48:MCdqBH6E+iCsAaKj7fOWIkFy9fQ3JGrRGl2Sh:ndqBCB7fdpFL3yT8
                                                    MD5:8EF96CBA0FDE73E0D602FA3A57BA66CE
                                                    SHA1:BFFC8EED8E6502485E210AB6B0E9BB02EC1E925E
                                                    SHA-256:1E8A53653CE0FF1DDE1849FED4DCC8E70E171EB7ACBE1A72049B6079751B2595
                                                    SHA-512:07AB6032071ABDD7CE02407C473BAEA7AE4A960E86C35564FC9BFB3E77034CA5103F99A5809DD12FD79EDC0F02A7522AF2FF9C2FD9D941DB027741910FF7CC41
                                                    Malicious:false
                                                    Preview:/****************************************************************************..**..** Copyright (C) 2017 The Qt Company Ltd...** Contact: http://www.qt.io/licensing/..**..** This file is part of the Qt Labs Calendar module of the Qt Toolkit...**..** $QT_BEGIN_LICENSE:LGPL3$..** Commercial License Usage..** Licensees holding valid commercial Qt licenses may use this file in..** accordance with the commercial license agreement provided with the..** Software or, alternatively, in accordance with the terms contained in..** a written agreement between you and The Qt Company. For licensing terms..** and conditions see http://www.qt.io/terms-conditions. For further..** information use the contact form at http://www.qt.io/contact-us...**..** GNU Lesser General Public License Usage..** Alternatively, this file may be used under the terms of the GNU Lesser..** General Public License version 3 as published by the Free Software..** Foundation and appearing in the file LICENSE.LGPLv3 included in th
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):17167
                                                    Entropy (8bit):4.158357646845498
                                                    Encrypted:false
                                                    SSDEEP:96:5liSSts8XTKQfX5nZ35pdnldtrufOPId3RNARIuIcIDIHt0rZ1FEg:b/W5pdnldtKGPWPXR8g
                                                    MD5:193C638E7BD9F92FC4EB289A90111EBD
                                                    SHA1:75EB4815EE9D4E2F42B32FE7F52BBF8BD2757098
                                                    SHA-256:4BE2AC35A0D8D8554618957F95F5A6F6C04752431F96FA848D1E8B86CDBB1FE1
                                                    SHA-512:701B87558A17FDAD0C0C0AF9286B026695717B78FB51130C081C48205852C0DCDAA90190B0FB4581D44F6B37BF5B9A9DB537650DE8347EB64636EA90395391F6
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2....// This file describes the plugin-supplied types contained in the library...// It is used for QML tooling purposes only...//..// This file was auto-generated by:..// 'qmlplugindump -nonrelocatable Qt.labs.calendar 1.0'....Module {.. dependencies: ["QtQuick 2.12"].. Component {.. name: "QAbstractItemModel".. prototype: "QObject".. Enum {.. name: "LayoutChangeHint".. values: {.. "NoLayoutChangeHint": 0,.. "VerticalSortHint": 1,.. "HorizontalSortHint": 2.. }.. }.. Enum {.. name: "CheckIndexOption".. values: {.. "NoOption": 0,.. "IndexIsValid": 1,.. "DoNotUseParent": 2,.. "ParentIsInvalid": 4.. }.. }.. Signal {.. name: "dataChanged".. Parameter { name: "topLeft"; type: "QModelIndex" }.. Parameter { name: "
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):193
                                                    Entropy (8bit):4.937171413613087
                                                    Encrypted:false
                                                    SSDEEP:3:3B3RxeURnGEhMLovyWmoHlrPv4MYJEvnlYJnQRwczS/L59URqArrQDEI4VI/EIXy:xbeUA+D8oFrPltD5G/L52a4IYI8Ii
                                                    MD5:27EE95E5A423101132C1E01066DBD194
                                                    SHA1:786B8A18092707C3A6B3AC2DBEFE997CBEC4D1DD
                                                    SHA-256:6B14B760A39E3C5546B98E5725E61E06D280DA75669BB58103DE5DF81D8BEEF6
                                                    SHA-512:B379083DAD910DFC05FDB4A550F061E7FC5EC44B1F821F1B38792DBF10FDD9A354FDAD764F7CA2912E19D63759B30570BC1F6FBBF41B45CBAFBCDFBA4D3FAF5E
                                                    Malicious:false
                                                    Preview:module Qt.labs.calendar..plugin qtlabscalendarplugin..classname QtLabsCalendarPlugin..DayOfWeekRow 1.0 DayOfWeekRow.qml..MonthGrid 1.0 MonthGrid.qml..WeekNumberColumn 1.0 WeekNumberColumn.qml..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):99952
                                                    Entropy (8bit):5.800028131314228
                                                    Encrypted:false
                                                    SSDEEP:1536:Jd8VW1wBJKcNsJy62tSrR0KUh2CO+8FdXoIP97Hfz3hvH:s1JtNsAwmKUTO+8FdYIlFH
                                                    MD5:C9E45F3B1AFD5BCD18F17309FE8EAAF5
                                                    SHA1:4037C73572440D38E62ACC1065F357466645CFFC
                                                    SHA-256:718E33308CE071379ADDE7C28E04B7A5B4B9E45A00BD35FE1CC877AAE9A9FC4C
                                                    SHA-512:8DC928DB00C5C501E19BB191BBC185E6C3B6C28B0371D9DFC2AA5358A345AECF1ABAAA803264C2EA331B4A89DE5C90574D838B21CBA83DF4F3FBCAEDC754A682
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......c9..'Xy.'Xy.'Xy.. .!Xy..&x.%Xy.l x.%Xy..&|.3Xy..&}./Xy..&z.$Xy.3'x.,Xy.'Xx.aYy.3'p.6Xy.3'y.&Xy.3'..&Xy.3'{.&Xy.Rich'Xy.........PE..d.....e.........." ...$............@.....................................................`A............................................................`....p.......f..p ..............p.......................(...`...@...............p............................text...k........................... ..`.rdata.............................@..@.data...(!...@.......0..............@....pdata.......p.......L..............@..@.qtmetadm............X..............@..P.rsrc...`............Z..............@..@.reloc...............^..............@..B........................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text
                                                    Category:dropped
                                                    Size (bytes):3339
                                                    Entropy (8bit):4.345026284093875
                                                    Encrypted:false
                                                    SSDEEP:96:1MnXmrQPLKXSXfl8gI5FRjEnkFlo+llFEOdEyIEzkycyTEyoybqyfXyL:KnXmrQPLKXSXfl8gI5FRjEnkFlo+llFa
                                                    MD5:561C691718C7E1BFE9C793F1F8B46655
                                                    SHA1:FA49D715F6E0F9BB9D419609D0CDDC4738EB8703
                                                    SHA-256:11AB6C33257F1660C4AEA137CAD8FCCB7D9635FDF28E234FD905FF6C6E53CBE8
                                                    SHA-512:520850B80D3113365511050A21ACC034E483507EA493BD118B4B29A1E1A6FAB83B4E67F9D4A27B8C483557D190FDA9F21BFE7E06EC64E12442659F7BED09E58A
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2..// This file describes the plugin-supplied types contained in the library..// It is used for QML tooling purposes only..//.// This file was auto-generated by qmltyperegistrar...Module {. dependencies: ["QtQuick 2.0"]. Component {. file: "qquickfolderlistmodel.h". name: "QQuickFolderListModel". exports: [. "Qt.labs.folderlistmodel/FolderListModel 2.0",. "Qt.labs.folderlistmodel/FolderListModel 2.1",. "Qt.labs.folderlistmodel/FolderListModel 2.11",. "Qt.labs.folderlistmodel/FolderListModel 2.12",. "Qt.labs.folderlistmodel/FolderListModel 2.2". ]. exportMetaObjectRevisions: [0, 1, 11, 12, 2]. Enum {. name: "SortField". values: ["Unsorted", "Name", "Time", "Size", "Type"]. }. Enum {. name: "Status". values: ["Null", "Ready", "Loading"]. }. Property { name: "folder"; type: "QUrl" }. P
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):128
                                                    Entropy (8bit):4.415318118360758
                                                    Encrypted:false
                                                    SSDEEP:3:3B3JPAyWxA5pUIIHWxAiCzvyWmxoA5MWbs1Oe+RLV06qWov:x5PT5pUIITiCD8W6g5+key
                                                    MD5:DF20F8FC4BD37E9D47303359FE2EC138
                                                    SHA1:673181FAB53765864747A1833026D018DED7EFBD
                                                    SHA-256:F75BB323DFC225D171DB112E509E34CC7450786CB7120DF4B1F085A510DFB739
                                                    SHA-512:69132E229DA823E51D99BD3851F79C52E95C20F05AF4B6C275450F87FE4EC906C6B31FD16853AABFE557642E16D8C719DB3C4A1D73031BA0493DE49682D9028D
                                                    Malicious:false
                                                    Preview:module Qt.labs.folderlistmodel..plugin qmlfolderlistmodelplugin..classname QmlFolderListModelPlugin..typeinfo plugins.qmltypes..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):66672
                                                    Entropy (8bit):5.974076663579998
                                                    Encrypted:false
                                                    SSDEEP:1536:b3OxYaEK53EoO60XLJ1ijgjHunPtSq7G43hui:b3FwsKnPtDWi
                                                    MD5:6582372724DBC1718A38644CA91EA182
                                                    SHA1:58FD7BE2AA0951AF45EF3F668EA2C17844D24B4F
                                                    SHA-256:CCA5E20000BE6F82D5E0517D4DAD7D9D73769288970D4BCC74869471ECA88C64
                                                    SHA-512:A41B65A6155A31D59F7649C43CD5CC2042FAA0CECC95F3EE4DD18CB07C2D422503B0D77802CEF79C78D5693CF29F5E4CF90C785B0AAB300FCBE376E8DADAC087
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............r...r...r.......r..E....r.......r..E....r..E....r..E....r.......r...r...s.......r.......r....g..r.......r..Rich.r..........PE..d......e.........." ...$.`...........c.......................................@............`A................................................8........ ..h...............p ...0..........p.......................(...`...@............p..x............................text....^.......`.................. ..`.rdata...`...p...b...d..............@..@.data...............................@....pdata..............................@..@.qtmetady...........................@..P.rsrc...h.... ......................@..@.reloc.......0......................@..B........................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):113776
                                                    Entropy (8bit):6.104890339649168
                                                    Encrypted:false
                                                    SSDEEP:3072:SHSRRQMDu4mjKlEGaINBKjzjLMcQfS3cKv:SyXa9+jaSKjzjL9Hpv
                                                    MD5:855CD3707B08B2465B902645715AB89E
                                                    SHA1:2DB25981E3C39D129DB445C337CD47DE81115CC7
                                                    SHA-256:4BF8BDF2E6AD1C6AECF6F37A68C0A68C10AAC9BB65CA912F1F665E202018B322
                                                    SHA-512:2C4AB8ACECE962B28ACD31169BA315FD7908274069DB78FEBECE8EEE71CA643F216BFF740CD730FD0C035001E5D603485BC946883E3D2A89C6872B0F5B6B7A3B
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&...G.L.G.L.G.L.?4L.G.Lp9.M.G.L.?.M.G.Lp9.M.G.Lp9.M.G.Lp9.M.G.L.8.M.G.L.G.L.F.L.8.M.G.L.8.M.G.L.8XL.G.L.8.M.G.LRich.G.L................PE..d......e.........." ...$.............................................................4....`A.........................................L.......L..........X...............p ......t...p*..p....................+..(...0)..@............................................text............................... ..`.rdata...}.......~..................@..@.data.... ...........j..............@....pdata..............................@..@.qtmetadq...........................@..P.rsrc...X...........................@..@.reloc..t...........................@..B................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text
                                                    Category:dropped
                                                    Size (bytes):5365
                                                    Entropy (8bit):4.3339552633102345
                                                    Encrypted:false
                                                    SSDEEP:96:1y+aOubNPaiozNi9lRldhFFyP86yHGFyTO9HuyTO9HyCuyCyWGFyDNynNZyigTLs:g+aTbNPaiozNi9lRldhbyU6yHiyT2uya
                                                    MD5:E1389934641E5CEE99A0C14D3C0D61B1
                                                    SHA1:EBF7CCF0B2FB91E8990067B8A5CD70D1C4F477CF
                                                    SHA-256:46FD88969BD60B9BD7E22DF5D9001284C865A6EDBB90EAB05A26D9E373E2C224
                                                    SHA-512:7BD95C07E328A732E7737C181295D0B316E64BB3134351516C14676D0D5872E8F73097B67F3261B5EFAEC7C4504DAAEC36382104A2ABE1B456DCAC787B60ADD9
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2..// This file describes the plugin-supplied types contained in the library..// It is used for QML tooling purposes only..//.// This file was auto-generated by qmltyperegistrar...Module {. dependencies: []. Component {. file: "qqmldelegatecomponent_p.h". name: "QQmlDelegateChoice". defaultProperty: "delegate". exports: ["Qt.labs.qmlmodels/DelegateChoice 1.0"]. exportMetaObjectRevisions: [0]. Property { name: "roleValue"; type: "QVariant" }. Property { name: "row"; type: "int" }. Property { name: "index"; type: "int" }. Property { name: "column"; type: "int" }. Property { name: "delegate"; type: "QQmlComponent"; isPointer: true }. Signal { name: "changed" }. }. Component {. file: "qqmldelegatecomponent_p.h". name: "QQmlDelegateChooser". defaultProperty: "choices". prototype: "QQmlAbstractDelegateComponent". exports: ["Qt.labs.qmlmodels/Del
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):84
                                                    Entropy (8bit):4.284783869481156
                                                    Encrypted:false
                                                    SSDEEP:3:3B323yVdeJ2LEXMcvyWmoxnWaAYDMen:xljeIZe8oAaAen
                                                    MD5:6B51BCC843146B40C80CB68C3F3698A3
                                                    SHA1:ECC8CE49760EE1D6CDF5A540DD05D4AA8DBB49D7
                                                    SHA-256:D14EFF06AA95349F1AF3C714C56EF85C56E53D0B10E8931963F5D78F098A8E1A
                                                    SHA-512:F297D1370A43142A21DC73E29BFD9300CBECAB6B8E7DDEBD5F27E8F6A043A5620A79FFF32A61283622A59AA2B51C1C8F982B06C9728346AC8A790CCFBFCFE3BF
                                                    Malicious:false
                                                    Preview:module Qt.labs.qmlmodels..plugin labsmodelsplugin..classname QtQmlLabsModelsPlugin..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text
                                                    Category:dropped
                                                    Size (bytes):1102
                                                    Entropy (8bit):4.261818705798837
                                                    Encrypted:false
                                                    SSDEEP:24:I8BF9dN7/1vFNLXxEs4rAZ3rNiyrAZyr+9ZkiyOL:I8BFZ7HFxEs4MZiyMyKrkiyOL
                                                    MD5:99D2EB4BD0FC4D6BD21DD44F394E1B28
                                                    SHA1:E66E78FF51F95F3D9CD63EC2D7FB70C30D74555B
                                                    SHA-256:6B8A8E9E5DB20B0622967E62741173406AB739758DA0B5F6022BABAC9A207E65
                                                    SHA-512:E83FFB49303609B9EBE6ABBA7FE93B9B21732AEED8C4D35539E06F9931FB4413C9889399FEA2E80C57BAE827F3187E1783D8CBF914DD42BAFCC42EBC43D61948
                                                    Malicious:false
                                                    Preview:import QtQuick.tooling 1.2..// This file describes the plugin-supplied types contained in the library..// It is used for QML tooling purposes only..//.// This file was auto-generated by qmltyperegistrar...Module {. dependencies: []. Component {. file: "qqmlsettings_p.h". name: "QQmlSettings". exports: ["Qt.labs.settings/Settings 1.0"]. exportMetaObjectRevisions: [0]. Property { name: "category"; type: "string" }. Property { name: "fileName"; type: "string" }. Method { name: "_q_propertyChanged" }. Method {. name: "value". type: "QVariant". Parameter { name: "key"; type: "string" }. Parameter { name: "defaultValue"; type: "QVariant" }. }. Method {. name: "value". type: "QVariant". Parameter { name: "key"; type: "string" }. }. Method {. name: "setValue". Parameter { name: "key"; type: "string" }.
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):107
                                                    Entropy (8bit):4.282225142848317
                                                    Encrypted:false
                                                    SSDEEP:3:3B3ERMxyjeUItojQEvyWmxN3Mx15+RLV06qWov:xUmyjeUIS/8vY15+key
                                                    MD5:B1F564E1CEC8D91FFA94C36EDE2A8F24
                                                    SHA1:4A04351CF163036E4A56967E4ECA872A93E4E0BC
                                                    SHA-256:49522AF40488E52E8A1DEDA8B51F591DF1ACCA1605336784EB7D4299E5AF02EC
                                                    SHA-512:FB5558F86F0553EBE9F592C1D1EE834194ACC023E6D292E9D543F30C664BF8939AF302141ABFDD300EE5FECCECD2196E22E6DFCBA604E0FEA1C6B888A33AE5B6
                                                    Malicious:false
                                                    Preview:module Qt.labs.settings..plugin qmlsettingsplugin..classname QmlSettingsPlugin..typeinfo plugins.qmltypes..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):45680
                                                    Entropy (8bit):6.010915781028963
                                                    Encrypted:false
                                                    SSDEEP:768:IUQyqyjUK0tyqltYq2aDdkOjETYif3hBMh:BqHoW27OjET7f3hBo
                                                    MD5:86B03F8BF4C7E4CEF1814B651D695164
                                                    SHA1:E5A669C9C82677CFA9473D9A130D6129397A6979
                                                    SHA-256:1557523368667CFA82CADB3BF85B38BBC14ABA5ECC9B34BC0122FD98D530CFE7
                                                    SHA-512:E2C4C66F21B54A8BA38EFC36E7F067BD5C8B969C11F720E2D9E9ADCE9E4132B411195569EBB4C6E6DC3FEB1EB34E646B418B6C2910E021EA05A64F438C53AE43
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$....................w....I............I.......I......I................\...............................Rich...................PE..d......e.........." ...$.<...X.......@...............................................^....`A........................................Pp.......p..........X...............p ..........._..p...................._..(....]..@............P..(............................text...~:.......<.................. ..`.rdata...=...P...>...@..............@..@.data................~..............@....pdata..............................@..@.qtmetadl...........................@..P.rsrc...X...........................@..@.reloc..............................@..B................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):207472
                                                    Entropy (8bit):6.054912705683283
                                                    Encrypted:false
                                                    SSDEEP:3072:gZI9BAAc7Rjgv+mOlAi9rCgK5clcTwcLlTk6ycMv96n4b37t4:Hjc7tAi9rCZxDTk6yc34b54
                                                    MD5:F2328313620F714F0E1C18B39148D507
                                                    SHA1:B874C6ADDEDFD03F2C3092C1CDD1FD98A166DCC4
                                                    SHA-256:06B0FB5FD0791D081A22353F0B4760CBC03D33FAAC1004EE160B20E221DA9A95
                                                    SHA-512:8D7ABBF4F9F5D1D7B40340F50B6697F8B20A8DDFEF7C574AEB0EE60599A36FFD6CE73772C68C7BB7D247E2D9A72638E6D399672E0B28BC3DD63723526C1CCD40
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......a..m%..>%..>%..>,.9>-..>@.?!..>w.?4..>w.?-..>w.?'..>w.?!..>..? ..>%..>...>..?-..>..?$..>..?$..>Rich%..>........................PE..d....f.f.........." .....>...................................................`...........`.............................................P...0........@..0.... ..........p ...P..D....y..T............................y...............P...............................text...D=.......>.................. ..`.rdata......P.......B..............@..@.data...............................@....pdata....... ......................@..@.rsrc...0....@......................@..@.reloc..D....P......................@..B........................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):549488
                                                    Entropy (8bit):6.258571445464066
                                                    Encrypted:false
                                                    SSDEEP:6144:IFnpvScr2dQZ9mZTa2olyWmm0w9qsNXe4cJWAt7GONW5mS9:IFdZ9mZO2+bZqCO4cB7GP
                                                    MD5:779D2DF1D17AE42E549FF84D9FD08D96
                                                    SHA1:A0B4213A5E22133126662E9811BF9D07A6D12E8A
                                                    SHA-256:B4115F84004C9226168DCF912EF3194A352C56EFD489219A83838C39D33A68D0
                                                    SHA-512:478020E57A47250A2A982D6FAB7817A887B3D174CD32AE80E68C48299A188A23AF01D9E18D1C95F49BE8F00EC52BB5A15F353B6FD0A13CA3565CE45CB2F5A34E
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......G.lP....................Q.......Q.......Q.......Q.......f...........................,...................Rich............PE..d......e.........." .........8...............................................p......~3....`.........................................p.......H....................C...B..p ...`..h...`...T.......................(.................... ..0............................text...$........................... ..`.rdata....... ......................@..@.data...8O.......H..................@....pdata...C.......D..................@..@.reloc..h....`.......8..............@..B................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):713328
                                                    Entropy (8bit):6.515482950988438
                                                    Encrypted:false
                                                    SSDEEP:12288:Uw3Z/tD/mwKph0lhSMXlibNnUhyqfJJwK6m2YgsozK1/4s:U2tD/Rgh0lhSMXlQnUhyqfJJwK6m2YgQ
                                                    MD5:C635AC979617226BADFF918E46163386
                                                    SHA1:6C64BA27C64A29F70FD72FFE000DA77F58FB6B46
                                                    SHA-256:FD7570305F3E0D379CCC6721991B3BAFFA7A9F6382A45C70258C675A0AF65284
                                                    SHA-512:BB40E3F7EE788946AFDE08B3D399B6763AA54EB8BDF25E5D0D1F3ECBA35A899F14B3C61AF07677F310DE092C7ABFE8137201611BF2D22A280C25A681B4872C1B
                                                    Malicious:false
                                                    Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......3.u.w...w...w...~..g...............q.......Q..............s.......u.......t......v...c...r...w.....c...O...c...v...c...v...c...v...Richw...................PE..d....dCf.........." ...$.~..........................................................s.....`A.........................................J...?......,............P..p8......p ..............p.......................(.......@............................................text....|.......~.................. ..`.rdata..z........ ..................@..@.data...............................@....pdata..p8...P...:...x..............@..@.rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5466
                                                    Entropy (8bit):5.131234421934646
                                                    Encrypted:false
                                                    SSDEEP:96:3lJF9XUAZafdujyh4S37L2VmKFYTGu3N9G9/j6RFkkLKJUE7RpVtHBwy:jMdujyYhqSu3KVbJUElpVPwy
                                                    MD5:C10D88069CE97E951138FA7B6785CC9A
                                                    SHA1:D3B32FC5768686EB3E33A4CBB15A861F2E474029
                                                    SHA-256:84621C844FDC2384C9FD603E9441CBA09544257BF3526DEAED2E741D2B691CE5
                                                    SHA-512:4A6FDEA9B1F617F2AF079811022F53559C5D45547DD2B62BD127250C7609A350EFB7FECCDE02DD435E9862E03B7D1A172C98546E8A0A055C47B5A1233B66C2B3
                                                    Malicious:false
                                                    Preview:# module..module UIToolkitQml....# plugin..plugin UIToolkitQml....# resourse....# buttons..UTPillButton 1.0 qrc:/plugin/UTPillButton.qml..UTRoundButton 1.0 qrc:/plugin/UTRoundButton.qml..UTIconButton 1.0 qrc:/plugin/UTIconButton.qml..UTHyperlinkButton 1.0 qrc:/plugin/UTHyperlinkButton.qml..UTRadioButton 1.0 qrc:/plugin/UTRadioButton.qml..UTAppListItemExpanded 1.0 qrc:/plugin/UTAppListItemExpanded.qml....# dual buttons..UTToggleButton 1.0 qrc:/plugin/UTToggleButton.qml..UTDualButton 1.0 qrc:/plugin/UTDualButton.qml..UTDualIconButton 1.0 qrc:/plugin/UTDualIconButton.qml..UTCallControlButton 1.0 qrc:/plugin/UTCallControlButton.qml....# text input..UTTextField 1.0 qrc:/plugin/UTTextField.qml..UTTextInputField 1.0 qrc:/plugin/UTTextInputField.qml..UTTextArea 1.0 qrc:/plugin/UTTextArea.qml..UTTextLabel 1.0 qrc:/plugin/UTTextLabel.qml....# tabs..UTTabBar 1.0 qrc:/plugin/UTTabBar.qml..UTTabItem 1.0 qrc:/plugin/UTTabItem.qml....# menus..UTClassificationsMenu 1.0 qrc:/plugin/UTClassificationsMen
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):256624
                                                    Entropy (8bit):5.810847866024545
                                                    Encrypted:false
                                                    SSDEEP:6144:v1y8TDUOoMu7fvDXS+G3iJk/0yiiUdiL4:vZTgOoMmvTBwAPo0
                                                    MD5:0B5C321638EFA5E5ED3BE0A8C5C527D8
                                                    SHA1:F539DE4F145F074594BA8BDA3E79E6FD7556935D
                                                    SHA-256:203EEE00FDDFEB1B5E6BFDA8E68D8AEEE579F44F949BF47E2D31A37A45EC39AD
                                                    SHA-512:983A57077313E232E21C37CEBBBF3F1957DC6E4DC23DE5E5B6C165CD75F722EF539609143947082D8A6B93761CC5FDD045574D7D58CB574374971B53781260A8
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........X]..6...6...6.....6.:.3...6.:.2...6.:.5...6.:.7...6...7...6...7.n.6.8.2...6.8.3...6.8.6...6.8.....6......6.8.4...6.Rich..6.................PE..d....+ea.........." .....h...f.......L..............................................d.....`A.........................................y..<...<}..........`........6......p ......|....>..p...........................`?..8...............h............................text....g.......h.................. ..`.rdata...............l..............@..@.data................z..............@....pdata...6.......8..................@..@.rsrc...`...........................@..@.reloc..|...........................@..B................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):2400368
                                                    Entropy (8bit):5.887172856541035
                                                    Encrypted:false
                                                    SSDEEP:24576:V0iNjfpSEyAB1mmNj1zmb9sVajYDadrxI8f22:hNjfpD+mNj1zxaj9D
                                                    MD5:6F11346103B3DD240F9326CDCEFA5801
                                                    SHA1:C0C7E5A0E3B7892F3D33CD4491D4327F29218609
                                                    SHA-256:DA14FB15299770AD9F6CC446FB6448A5E07F12499B440223E0B2FFD74DB6B6FF
                                                    SHA-512:A66D30660F49E32BAED0CB68B73F73055E85C56DA1D33D4E94A7E12A52FBB9C9C6D3424B20B3226299C142FEEAF750126A803F318927D6BDC5F077073934CF71
                                                    Malicious:false
                                                    Preview:MZ......................@...................................0...........!..L.!This program cannot be run in DOS mode....$...........I..I..I..@.p.[....A....O....O.....H..n(..K..RsH.^.....B..I..6....l..]..K..]..V..]..H..]...H..I.t.H..]..H..RichI..........................PE..d......e.........." ...$............$0........................................$......~%...`.........................................`{!.<.....!.|.....$.......".......$.p ....$.t<..`...p.......................(... ...@............0...............................text............................... ..`.rdata.......0......................@..@.data.........!.......!.............@....pdata........"......b".............@..@.rsrc.........$......<$.............@..@.reloc..t<....$..>...B$.............@..B................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):2496624
                                                    Entropy (8bit):6.338970913298538
                                                    Encrypted:false
                                                    SSDEEP:49152:qAURKjLi5RR7UVaN5oTaH95jVO4R7Um3pzMePhqkWHVbtC3sSfXFKEa:IR2amCJAEa
                                                    MD5:FE0178C4EA10FEFC5B7E33CF1ADFA5E7
                                                    SHA1:F9E0DBCEF9132B0CA60718318F4F4DDD4829273B
                                                    SHA-256:F2B5ECD5784B50FA5F2A6A11CAD0F5A74FA9536336CD92918A889DD892488124
                                                    SHA-512:D5DB74699B923305E88499DC9FE7D59FDA7FD3E30212B667DA7D240A7E55D7C9069A96B84A0D59E0BADA4F5E5BA4379D5C30763A4D827A8D6322FCA19BFB9749
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........................s..................................................E...*......,......,.......,.........w.....,......Rich....................PE..d...c.'e.........." ..........................................................&.....AS&...`A........................................0y#......z#.......&. ....@%..S....%.p ....&......H..T....................K..(...PI..8............................................text...,........................... ..`.rdata..V...........................@..@.data....i....#.......#.............@....pdata...S...@%..T...~$.............@..@.rsrc... .....&.......%.............@..@.reloc........&.......%.............@..B........................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:JSON data
                                                    Category:dropped
                                                    Size (bytes):5447
                                                    Entropy (8bit):3.5760568019939507
                                                    Encrypted:false
                                                    SSDEEP:48:bi0kbi1vialf2RjO+JM8gsEaOBymzaaQWH1CmD9zuGUReGVIBp8B6UB1ZvLvJdlA:mtbi+FHQ
                                                    MD5:0D829D497611521B91D1FED18A385857
                                                    SHA1:67AAD2309CDDE11DF9F655F383F13DC2380E277A
                                                    SHA-256:A90F7A8B9F559CE517393E7E9241A9245D39460C5302DB50A59FF215BB8BE137
                                                    SHA-512:5E31AE7298A5A1FF70BDD45D1E1A407F6E1494948314E45B614845E65166D3BD14F63B45B1AD0C41E482A613B94A5F555C5739C8914ACF906DA13CFF9D559CE4
                                                    Malicious:false
                                                    Preview:{.. "DSEA_HS": [.. {.. "HS_Name": "EPOS ADAPT 160 ANC",.. "PID": "640".. },.. {.. "HS_Name": "EPOS ADAPT 160T ANC",.. "PID": "641".. },.. {.. "HS_Name": "EPOS ADAPT 130",.. "PID": "642".. },.. {.. "HS_Name": "EPOS ADAPT 130T",.. "PID": "643".. },.. {.. "HS_Name": "EPOS ADAPT 160",.. "PID": "644".. },.. {.. "HS_Name": "EPOS ADAPT 160T",.. "PID": "645".. },.. {.. "HS_Name": "EPOS ADAPT 1x5",.. "PID": "646".. },.. {.. "HS_Name": "EPOS ADAPT 1x5T",.. "PID": "647".. },.. {.. "HS_Name": "EPOS ADAPT 130",.. "PID": "660".. },.. {.. "HS_Name": "EPOS ADAPT 130T",.. "PID": "661".. },.. {.. "HS_Name": "EPOS ADAPT 160",..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):585840
                                                    Entropy (8bit):6.442824176566969
                                                    Encrypted:false
                                                    SSDEEP:12288:O3u3h/kPNYynA7OIlKDUBXm2RGNeFSR0rDlmjxdQFzh82qfOoa6MlWRKcbU:O3u3FkP8mWGNePmjQFzhZq2L6Ml3
                                                    MD5:98B5144702D199FC2D45DDD37984F10E
                                                    SHA1:4C6E27117C52AED20EA9296F5D7546EFC5D1670E
                                                    SHA-256:2F505A90881B40D614DCC1744A2AA9AD7649758730A89169A1EF5BC7E6416638
                                                    SHA-512:2821A907100130234D6DAE0B2423FED82D515B692C6A6B44B5CC3E7CEEDB7706EDE2277EC52B6BB5F1DD0900F66EC05DB5E2FA135A35D3C1315956C852775A53
                                                    Malicious:false
                                                    Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$......._.pB............................I.......I.......I...].................................................................................Rich....................PE..d....S:e.........." .....R...................................................0......}.....`A.........................................Z..d...t[..........x........H......p ... ..<...D...T...............................8............p..p............................text....P.......R.................. ..`.rdata.......p.......V..............@..@.data....4...p.......V..............@....pdata...H.......J...r..............@..@_RDATA..............................@..@.rsrc...x...........................@..@.reloc..<.... ......................@..B........................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:JSON data
                                                    Category:dropped
                                                    Size (bytes):45158
                                                    Entropy (8bit):3.5856219567647374
                                                    Encrypted:false
                                                    SSDEEP:96:GogoFwzm6zinAnmPjQIGIGIQZrZK9TluMVMVMwyUO:GogoIBff9ZrZK9/
                                                    MD5:CB86022C3B67461664E31FA3B1415A5C
                                                    SHA1:9E84B67D3FA3DD3422EE7529EE68CC8528B15C23
                                                    SHA-256:FB89706FF28C7BB3152777A22F3907EB988C7D7E39FFEA83EE792A04E34D36B7
                                                    SHA-512:7C80C68F5367201BDF59C4BC88826049EA41CF1254BE5BF3C3D885681948D6AE6296F369AA336334D76E6D3F9E2C782232B089EDC28C084A0187A67E0560F41F
                                                    Malicious:false
                                                    Preview:{.. "Version": "2023-07-12 08:34:31",.. "DevicesForWhichRccWillBeEnabled": [.. {.. "Name": "Jabra BIZ 1100 Mono",.. "PID": 9001.. },.. {.. "Name": "Jabra BIZ 1100 Stereo",.. "PID": 9002.. },.. {.. "Name": "Jabra BIZ 1500 USB Duo",.. "PID": 8999.. },.. {.. "Name": "Jabra BIZ 1500 USB Duo",.. "PID": 9005.. },.. {.. "Name": "Jabra BIZ 1500 USB Duo",.. "PID": 8999.. },.. {.. "Name": "Jabra BIZ 1500 USB Duo",.. "PID": 9005.. },.. {.. "Name": "Jabra BIZ 1500 USB Mono",.. "PID": 8998.. },.. {.. "Name": "Jabra BIZ 1500 USB Mono",.. "PID": 9004.. },.. {.. "Name": "Jabra BIZ 1500 USB Mono",.. "PID": 8998.. },.. {.. "Name": "Jabra BIZ 1500 USB Mono",..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):2642032
                                                    Entropy (8bit):6.114408184916657
                                                    Encrypted:false
                                                    SSDEEP:49152:AQtakk2+ipKHw3mH4by9O6ACtFyWFgvlSwwN5glQ3qbZHyYgMkR6OU84lJn3:A97jACtFBgvlSsfYx4lJ3
                                                    MD5:360BA17B53DD6936EF8D108FCFF2FDF0
                                                    SHA1:3C2DB7423B4E07712CA2B9800962AC6DB3F8B0F8
                                                    SHA-256:56280C1737B5E22DA0F2EEBCA668E566A5E3180A488FD9D438B241490FE5F8E8
                                                    SHA-512:41D97DBDDCCA4A15C1B43DB6F063795F9A52B1BF5D2561EAE94BAF5B5D0E421BD26DA9E6FF525263FD9D97942E9BBEE7D9B6C39FC6F61D247510EB4184F16959
                                                    Malicious:false
                                                    Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$........#m@.B...B...B...:...B...*...B...*...B..7#...B...*...B...*...B...$...B...$...B..."...B...$...B...B..kC..++...B..++...B..++...B...B...B..++...B..Rich.B..........PE..d...uP.d.........." .........L................................................(.....L.(...`A........................................P.%.....L.%......@(.......&.$D...0(.p ...P(..'..`...p.......................(...................................................text...\........................... ..`.rdata..............................@..@.data...P.....&.......%.............@....pdata..$D....&..F....&.............@..@.rsrc........@(.......(.............@..@.reloc...'...P(..(....(.............@..B................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):3155
                                                    Entropy (8bit):4.748643255146154
                                                    Encrypted:false
                                                    SSDEEP:96:EZDhLkyE+Bn5jBsyRMPk+Dg+mG6Bk41pV1p38gC3+F8Lmoy9hm:EBuIEes
                                                    MD5:BC66624BC9B919E65D1F5ED444F6A2AC
                                                    SHA1:D7B30BBEAC1D85ABFB3D9A82AEE42B493EB0FE47
                                                    SHA-256:B3A39C15D41FD893EBCA0367355FC563B2538BE16A2929BA133E887295F04CBD
                                                    SHA-512:84A5DC3DF835CD96449713265BCC5DBB597953A49643054735362EC3067BABC84E0915C1E9BED2BD54AC696B30D756C44D4F248EEDF5D96645AD0C99F3F051FC
                                                    Malicious:false
                                                    Preview:[...{....// Blackwire 3220...."pid": "0xc056",...."version": "216"...},...{....// Blackwire 3320...."pid": "0x430b",...."version": "2025"...},...{....// Blackwire 3320...."pid": "0x430d",...."version": "2025"...},...{....// Blackwire 3320...."pid": "0x4312",...."version": "2025"...},...{....// Blackwire 3320...."pid": "0x4314",...."version": "2025"...},...{....// Blackwire 3320...."pid": "0x430a",...."version": "2025"...},...{....// Blackwire 3320...."pid": "0x430c",...."version": "2025"...},...{....// Blackwire 3320...."pid": "0x4311",...."version": "2025"...},...{....// Blackwire 3320...."pid": "0x4313",...."version": "2025"...},...{....// Blackwire 3320...."pid": "0x4319",...."version": "2025"...},...{....// Blackwire 5220...."pid": "0xc053",...."version": "222"...},...{....// Blackwire 5210...."pid": "0xc054",...."version": "222"...},...{....// Blackwire C510 New...."pid": "0xC019",...."version": "159"...},...{....// Blackwire C510-M New...."pid": "0xC01A",...."version": "159"...},
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.459775574843526
                                                    Encrypted:false
                                                    SSDEEP:192:SOQWvhW/WYnO/VWQ4SWc0NsxZAqnajT9CJIC:SjWvhWvUsNs/Al39AL
                                                    MD5:681C84FB102B5761477D8DA2D68CD834
                                                    SHA1:FD96CF075A956FBC2B74E1ECC3E7958163B58832
                                                    SHA-256:F0F7CB2A9FFCCB43400DB88D6BF99F2FCC3161DE1AC96C48501D4D522C48C2CA
                                                    SHA-512:C41A62F8D10290215B8A7F0DDCC27A1CF12A7453C2DAABEF75BD2CE87C4FFC87D74EDC8CAA1771BEDA0BFA26249CFE3C94D4AF50B22A5DECB6D282BD8A2C4BDD
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d...B4............" .........0...............................................@............`A........................................p...,............0...............0...!..............p............................................................................rdata..t...........................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20960
                                                    Entropy (8bit):4.499619700582879
                                                    Encrypted:false
                                                    SSDEEP:192:L6WvhWFWYnO/VWQ4SWssAtkqnaj6M07i5CK:+WvhW1UslWMui57
                                                    MD5:039D612693E56CCF32AE81C99443EA77
                                                    SHA1:0487AA5E7D283A8840F3005D1E24E8C9ED140974
                                                    SHA-256:4E978EE035B72032D0B7693E09EED6E112DCED6965780BC3E6B8E024EA2366AB
                                                    SHA-512:FFA56C73E977FFCEF7890AB6C3EC52E9827AF28B0552F11C48BB7CA16D37C2B7069FB7E03CEFB89F8679E3755BCC8C47344D0D9B91416C6D92CA7DB28C20240A
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d.....=.........." .........0...............................................@...........`A........................................p................0...............0...!..............p............................................................................rdata..............................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20952
                                                    Entropy (8bit):4.308560743366262
                                                    Encrypted:false
                                                    SSDEEP:192:1WvhW/WYnO/VWQ4yWxK2fvXqnajeCqN+6:1WvhWvU8XlX0
                                                    MD5:2A8065DC6E6E60FB90B4B3F9E6BA7288
                                                    SHA1:400A1F44CD4354DEA0117E79EC04B006D6141B36
                                                    SHA-256:55E5F10D0DD9C85FF1C6DC7798E46B3A4422FB7EBC583BB00D06A7DF2494397B
                                                    SHA-512:787E033E35AA357263639D97FDFE8A2EBC9F17865579BE13C14C0A4C2ED99432ED8EA79C5046D1B4B783BF5FCF7B713EFDD70FCA8445A7AFCB91CFDDC7F9D442
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d...FBe..........." .........0...............................................@.......,....`A........................................p................0...............0...!..............p............................................................................rdata..X...........................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.314779945585029
                                                    Encrypted:false
                                                    SSDEEP:192:JWvhWiWYnO/VWQ4mWAyTIl1PXEKup3JdqnajKsztG2:JWvhWYUQI/PX7aJdlGsztG2
                                                    MD5:720DB2235C4193151FF8987F8A729135
                                                    SHA1:038648798892203B506AB4664BAECA25F78BC43C
                                                    SHA-256:092B72832C47F9C4EDCDE61F1A111C20EB73452984E0A6109482DE74EB03C34D
                                                    SHA-512:CAAC89DC4FE10E7752B6F248623B34A47A77A750E62F0A558C760A8AD672D980AFC966A9E5696BA5C916E722FD221D305C4D2C49D5DDA0E4A768855886D4F3CA
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d...@4............" .........0...............................................@............`A........................................p................0...............0...!..............p............................................................................rdata..d...........................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.363620943088422
                                                    Encrypted:false
                                                    SSDEEP:192:9m7xeiImxD3exWvhW5WWYnO/VWQ4mWACJXEKup3JdqnajKsztJ30:9m7xeiIFxWvhWuUkX7aJdlGsztd0
                                                    MD5:ECDD006AAE56427C3555740F1ABFA8D6
                                                    SHA1:7DFAB7AD873544F627B42C7C4981A8700A250BD4
                                                    SHA-256:13BC8B3F90DA149030897B8F9F08D71E5D1561E3AE604472A82F58DAB2B103F9
                                                    SHA-512:A9B37E36F844796A0FE53A60684BE51AB4013750BB0B8460C261D25FA5F3DE6CE3380044DDC71116825D130A724DF4BA351C2CFFCBF497EF1B6C443545E83F1C
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d......v.........." .........0...............................................@.......p....`A........................................p................0...............0...!..............p............................................................................rdata..............................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.2939305898439235
                                                    Encrypted:false
                                                    SSDEEP:192:8gWvhWliWYnO/VWQ4mWCkJZH2vArqnajKsbTYjtZ:NWvhWlYUDuH24rlGsbTY5Z
                                                    MD5:EB065ED1B5CABDBB90E2403B8564778F
                                                    SHA1:5B511215EE0E347734FB727FAD6A0A959FF81BF1
                                                    SHA-256:BB2D740333AFAEA2A73A163F95FA102D018CCD68DEF28B6815A2BE0696AB57DB
                                                    SHA-512:E5FF38F28253FB31BF583131E23EF58AF60020AD1FB329986C8789FE351F4B73CB06109FBC4220678D93191B04DB353466F728534AA1FEBEDF150C491B8E7C65
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d.....cc.........." .........0...............................................@.......o....`A........................................p................0...............0...!..............p............................................................................rdata..0...........................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):25048
                                                    Entropy (8bit):4.628757275210407
                                                    Encrypted:false
                                                    SSDEEP:192:1mtaNYPvVX8rFTsvWvhWmWYnO/VWQ4yW9AfvXqnajeCqKW:8PvVXhWvhWMU7XlX7W
                                                    MD5:36277B52C64CC66216751AAD135528F9
                                                    SHA1:F2A6740BA149A83E4E58E1E331429FA3EB44FBA0
                                                    SHA-256:F353B6C2DF7AADB457263A02BCE59C44BBAB55F98AE6509674CFBC3751F761B9
                                                    SHA-512:BE729194A0A3C4D70A6FFA8DE5C7F8BB3DDA1F54772F9AEFF4B9AA1D6756720D149613C5DCB911286B6C0181A264A4A2A8A4EB848C09AC30BA60B6FD10DD64C9
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d...!..e.........." .........@...............................................P............`A........................................p................@...............@...!..............p............................................................................rdata..L........ ..................@..@.data........0......................@....rsrc........@.......0..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20960
                                                    Entropy (8bit):4.328858083322922
                                                    Encrypted:false
                                                    SSDEEP:192:IAIEWvhWLIQWYnO/VWQ4eWletp80Hy5qnajsBk9:I5EWvhWLI+UJpslE8
                                                    MD5:D92E6A007FC22A1E218552EBFB65DA93
                                                    SHA1:3C9909332E94F7B7386664A90F52730F4027A75A
                                                    SHA-256:03BD3217EAE0EF68521B39556E7491292DB540F615DA873DD8DA538693B81862
                                                    SHA-512:B8B0E6052E68C08E558E72C168E4FF318B1907C4DC5FC1CD1104F5CAE7CC418293013DABBB30C835A5C35A456E1CB22CC352B7AE40F82B9B7311BB7419D854C7
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d................" .........0...............................................@......p.....`A........................................p...L............0...............0...!..............p............................................................................rdata..............................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20960
                                                    Entropy (8bit):4.41968362445382
                                                    Encrypted:false
                                                    SSDEEP:192:lC+WvhWRWYnO/VWQ4SWHvD480Hy5qnajsBkffy2:4+WvhWRUGEslECl
                                                    MD5:50ABF0A7EE67F00F247BADA185A7661C
                                                    SHA1:0CDDAC9AC4DB3BF10A11D4B79085EF9CB3FB84A1
                                                    SHA-256:F957A4C261506484B53534A9BE8931C02EC1A349B3F431A858F8215CECFEC3F7
                                                    SHA-512:C2694BB5D103BAFF1264926A04D2F0FE156B8815A23C3748412A81CC307B71A9236A0E974B5549321014065E393D10228A0F0004DF9BA677F03B5D244A64B528
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d.....mR.........." .........0...............................................@............`A........................................p................0...............0...!..............p............................................................................rdata..............................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.329081455517674
                                                    Encrypted:false
                                                    SSDEEP:192:ZfWvhWPWYnO/VWQ4SWR7me4qdsxZAqnajT9CRixc:ZfWvhW/UNezs/Al39wiO
                                                    MD5:3039A2F694D26E754F77AECFFDA9ACE4
                                                    SHA1:4F240C6133D491A4979D90AFA46C11608372917F
                                                    SHA-256:625667EA50B2BD0BAE1D6EB3C7E732E9E3A0DEA21B2F9EAC3A94C71C5E57F537
                                                    SHA-512:D2C2A38F3E779AC84593772E11AE70FC8BCFD805903E6010FE37D400B98E37746D4D00555233D36529C53DD80B1DF923714530853A69AA695A493EC548D24598
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d......0.........." .........0...............................................@......=.....`A........................................p...`............0...............0...!..............p............................................................................rdata..............................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20960
                                                    Entropy (8bit):4.447714045651854
                                                    Encrypted:false
                                                    SSDEEP:192:gxlAWvhW5EWYnO/VWQ4SWArSZBUuUgxfzfqnajmGYjB:gxlAWvhW5yUbSsIrlStjB
                                                    MD5:2EDC82C3DA339A4A138B4E84DC11E580
                                                    SHA1:E88F876C9E36D890398630E1B30878AF92DF5B59
                                                    SHA-256:E36B72EAFFFFFB09B3F3A615678A72D561B9469A09F3B4891ABA9D809DA937A5
                                                    SHA-512:6C1B195B2FABE4D233724133AE3BDF883F287B5ECD9639A838AD558159A07E307E7AE5E5407CE9229DCCDE4BE2CC39EC59506A5FB73B45D04B80330B55E2B85C
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d...)\Ix.........." .........0...............................................@............`A........................................p................0...............0...!..............p............................................................................rdata..L...........................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.368970650031484
                                                    Encrypted:false
                                                    SSDEEP:192:ODWvhWJWYnO/VWQ4mWbAcH2vArqnajKsbTY3:ODWvhWJUrcH24rlGsbTY3
                                                    MD5:215E3FA11BE60FEAAE8BD5883C8582F3
                                                    SHA1:F5BF8B29FA5C7C177DFEC0DE68927077E160C9AB
                                                    SHA-256:FBB9032835D0D564F2F53BBC4192F8A732131B8A89F52F5EF3FF0DAA2F71465F
                                                    SHA-512:C555698F9641AF74B4C5BB4CA6385B8D69D5A3D5D48504E42B0C0EB8F65990C96093687BC7EE818AA9C24432247AFAD7DF3BF086010A2EFCD3A1010B2FCD6A31
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d......d.........." .........0...............................................@......5.....`A........................................p................0...............0...!..............p............................................................................rdata..............................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.601897142725442
                                                    Encrypted:false
                                                    SSDEEP:192:pTvuBL3BBLxWvhWcWYnO/VWQ4mW74j21EhqnajKsxX+:pTvuBL3BXWvhWKUBqslGsxu
                                                    MD5:9A8AB7FE8C4CC7604DFF1FBFA57458AA
                                                    SHA1:68ED7B6B5191F53B50D6A1A13513DB780AB19211
                                                    SHA-256:E9A3D7F8A08AB5BC94ACB1EC1BFFDA90469FEC3B7EECDF7CF5408F3E3682D527
                                                    SHA-512:05DAEABBCDE867E63FDE952213FFF42AF05E70AE72643C97060A90DCEA2A88B75947B6F503CB2C33938AFE36AD1BAFBA5008C1BBE839F6498CDA27DA549DAEE9
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d...P.1..........." .........0...............................................@............`A........................................p................0...............0...!..............p............................................................................rdata..`...........................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20960
                                                    Entropy (8bit):5.116096564588074
                                                    Encrypted:false
                                                    SSDEEP:384:6naOMw3zdp3bwjGzue9/0jCRrndbDWvhWfUCBoliM:POMwBprwjGzue9/0jCRrndbwIJY
                                                    MD5:DE5695F26A0BCB54F59A8BC3F9A4ECEF
                                                    SHA1:99C32595F3EDC2C58BDB138C3384194831E901D6
                                                    SHA-256:E9539FCE90AD8BE582B25AB2D5645772C2A5FB195E602ECDBF12B980656E436A
                                                    SHA-512:DF635D5D51CDEA24885AE9F0406F317DDCF04ECB6BFA26579BB2E256C457057607844DED4B52FF1F5CA25ABE29D1EB2B20F1709CF19035D3829F36BBE31F550F
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d.....3..........." .........0...............................................@............`A........................................p................0...............0...!..............p............................................................................rdata..............................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.483681194749599
                                                    Encrypted:false
                                                    SSDEEP:192:WqfWvhWoWYnO/VWQ4mWKNe4XEKup3JdqnajKsztPO/B:WGWvhWWU9X7aJdlGsztP2
                                                    MD5:7DDDA921E16582B138A9E7DE445782A0
                                                    SHA1:9B2D0080EDA4BA86A69B2C797D2AFC26B500B2D3
                                                    SHA-256:EF77B3E4FDFF944F92908B6FEB9256A902588F0CF1C19EB9BF063BB6542ABFFF
                                                    SHA-512:C2F4A5505F8D35FBDD7B2ECA641B9ECFCB31FE410B64FDE990D57B1F8FD932DFF3754D9E38F87DB51A75E49536B4B6263D8390C7F0A5E95556592F2726B2E418
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d...dIx..........." .........0...............................................@.......:....`A........................................p...l............0...............0...!..............p............................................................................rdata..............................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20960
                                                    Entropy (8bit):4.417647805455514
                                                    Encrypted:false
                                                    SSDEEP:192:RWvhW0WYnO/VWQ4SWKeE+Ztc80Hy5qnajsBkUqS:RWvhWiUxslE5qS
                                                    MD5:BF622378D051DB49BDC62ACA9DDF6451
                                                    SHA1:EFD8445656A0688E5A8F20243C2419984BB7743E
                                                    SHA-256:0BFEDB0D28E41E70BF9E4DA11E83F3A94C2191B5CD5DD45D9E9D439673B830CE
                                                    SHA-512:DF32D34C81FDE6EEF83A613CE4F153A7945EECFB1EC936AC6ED674654A4E167EC5E5436185B8064177F5F9273D387CA226C3C9529591180250A9C5C581EC6F70
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d....2............" .........0...............................................@.......p....`A........................................p................0...............0...!..............p............................................................................rdata..............................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.6126507489483375
                                                    Encrypted:false
                                                    SSDEEP:192:qF3qWvhWQWYnO/VWQ4SWL7JJsxZAqnajT9CgsLam:qF6WvhW+UA7s/Al39wR
                                                    MD5:A56E3E2AA6398CCB355C7CDE81CCB6E5
                                                    SHA1:A26273DD41DB7B63D3A79ACF6F4F3CF0381A8F02
                                                    SHA-256:25AF1BC31C4A3FB9F1036C9AA51CB0AE8899C499B3EEF4CF7281515C1EA27B47
                                                    SHA-512:3D5CEC9E5B42724794282974F637B1FDA8C26ADF01ED19DD2EC4F940E01CD43BDC42E46DC3E62704E62553DE96D3FEA1616C9650AF73CDB557DFCA1B52051A64
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d................" .........0...............................................@............`A........................................p...H............0...............0...!..............p............................................................................rdata..............................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.978924663768967
                                                    Encrypted:false
                                                    SSDEEP:384:Hck1JzNcKSIGqAWvhWTUpDX7aJdlGsztMs:3cKSswKz7aJGps
                                                    MD5:82159E8D92E38C4F287EB9420DCF1F9F
                                                    SHA1:2E4436DBE18D943416A388777D05BFE5CB553DE7
                                                    SHA-256:0D22CE9D987EFD6886A8DE66A6A678C287D29B15963B4373F73D79DDE42C9827
                                                    SHA-512:DCEF1E0C7916C8CD08148962949A996FFC5D46B899CD82DFBCD9BB1BC614622BC8997F1E7D3C4E3D75F2DF07540A4C17F39477CFE97BA7F0BD280CDD52E06F91
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d......Y.........." .........0...............................................@.......K....`A........................................p................0...............0...!..............p............................................................................rdata..4...........................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.513848472591714
                                                    Encrypted:false
                                                    SSDEEP:192:pwQpUwzDfIeOWvhW9WYnO/VWQ4+WWXtplsxZAqnajT9CGl:pZDfIeOWvhWNUFbls/Al39Hl
                                                    MD5:74C264CFFC09D183FCB1555B16EA7E4B
                                                    SHA1:0B5B08CDF6E749B48254AC811CA09BA95473D47C
                                                    SHA-256:A8E2FC077D9A7D2FAA85E1E6833047C90B22C6086487B98FC0E6A86B7BF8BF09
                                                    SHA-512:285AFBCC39717510CED2ED096D9F77FC438268ECAA59CFF3CF167FCC538E90C73C67652046B0EE379E0507D6E346AF79D43C51A571C6DD66034F9385A73D00D1
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d...%p_W.........." .........0...............................................@............`A........................................p................0...............0...!..............p............................................................................rdata..,...........................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.293598211920456
                                                    Encrypted:false
                                                    SSDEEP:192:dWvhW/WYnO/VWQ4SWYujPUsxZAqnajT9Cl36:dWvhWvUgMs/Al39Eq
                                                    MD5:D6F37B232E3F2E944EBCF53A662E852F
                                                    SHA1:C10839E941444ED79C2314F90DA34E5742F4E514
                                                    SHA-256:5E6AD9502C8411F29BC072EFD08C4FCD09BC3367814269DEDA74A78536FB8375
                                                    SHA-512:6E0CF1021EF3FF31895D2B6A9E72084EBE52DE4201D317B12FB8B05A7B1946FDEF65D2B046F8FB25189D3A94F70726121F2E8EAC8239C00EE02EF5EAF57F21C5
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d................" .........0...............................................@............`A........................................p................0...............0...!..............p............................................................................rdata.. ...........................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20960
                                                    Entropy (8bit):4.469567491280211
                                                    Encrypted:false
                                                    SSDEEP:192:aGeVTg6WvhWGWYnO/VWQ4SWupBd80Hy5qnajsBkt2NjY:aGeVTg6WvhWsUldslE8+Y
                                                    MD5:6397D5CC116D884D31552F613F748556
                                                    SHA1:B76B19FE4D3D5D26D2DEE1983D384E26D961180E
                                                    SHA-256:40EB38D84DFD13C8A58211B8273C4B4965148742F08EB6FE8B0830392C37ABC1
                                                    SHA-512:4449DA9BAA3F722EB274AC527125F5918A17BC94B243849A0A44F3463E35F368339A58A6AA1E08B83D54D13538C0D52BFCB452A48B8B9A52961BF136256D220E
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d.....C}.........." .........0...............................................@.......T....`A........................................p...<............0...............0...!..............p............................................................................rdata..............................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20960
                                                    Entropy (8bit):4.375396134710155
                                                    Encrypted:false
                                                    SSDEEP:192:v0yyMvJWvhW4WYnO/VWQ4SWQwwV80Hy5qnajsBkrfFIf:zyMvJWvhWmUAIslEAfFI
                                                    MD5:D2D7458AB838E738B54FB4D6FA490BF6
                                                    SHA1:0CFC5659B23A35C987B96CABBC0D10325316385D
                                                    SHA-256:285A481D7BA9859CC28BEDEDD8F05A90BD648A34D66B8C797118920B40E15E4E
                                                    SHA-512:62E0ABB2E59D360D6A066E73289AA1B880E7C1A0B7E6C695F40B1E0F2CB11DEB9E54DEBA4045D2454B911AF109EC198F11073874A8F023EB1B71A16A74354A1E
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d....%fN.........." .........0...............................................@............`A........................................p................0...............0...!..............p............................................................................rdata..<...........................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.889960536352825
                                                    Encrypted:false
                                                    SSDEEP:384:lQMwidv3V0dfpkXc0vVaLnWvhWTULrX7aJdlGsztzO1:xHdv3VqpkXc0vVagQ2L7aJGqO1
                                                    MD5:255B18FE8AB465C87FB8AD20D9A63AAC
                                                    SHA1:645823B0332ADDABA5E4EF40D421B2DA432FDA5E
                                                    SHA-256:E050E1BFBB75A278412380C912266225C3DEE15031468DAE2F6B77FF0617AA91
                                                    SHA-512:19244B084AC811B89E0E6A77F9308D20CF4FBB77621D34EEDC19FCD5C8775A33B2D9ADA3F408CBE5806C39745B30C1C1CC25D724DB9377B437D771AE0BF440B1
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d....>F..........." .........0...............................................@......Re....`A........................................p...X............0...............0...!..............p............................................................................rdata..............................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.557349562243787
                                                    Encrypted:false
                                                    SSDEEP:192:ctZ3ZtIWvhW9NWYnO/VWQ4SWndusxZAqnajT9CMCz4:ctZ3wWvhW9dUds/Al39pCz4
                                                    MD5:0A2432A420640A79FAAFF044AB054EF6
                                                    SHA1:15688BF3C9330309EC5EA602C0AD5AF1FD68BC30
                                                    SHA-256:9DFD114E4182662A669A3B9054DD2A24D96DD66ED96A8B2AC05601928B2084D5
                                                    SHA-512:090D6D5046AEFE9006B319FC3F9740426BC93E50CF262CE65857449891CA69D2A235421CFEA3FB178D3F8B1E3F640B8678AA9D8F6E67B8A17985913BEBFB3FDD
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d................" .........0...............................................@............`A........................................p...x............0...............0...!..............p............................................................................rdata..............................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.617444368323971
                                                    Encrypted:false
                                                    SSDEEP:192:UgdKIMFemVWvhWNWYnO/VWQ4mWY1tcQIj21EhqnajKsxN:JH0WvhWdUDIqslGsxN
                                                    MD5:E1A7B1F8CDB24324D0E44B0078DB8BD1
                                                    SHA1:B6C2FE32AE5FA1398F7AE6245C405378E32A7897
                                                    SHA-256:45D4F1E398E4CC73FD1AAAD80219D2A9D3205A228167C819EB6787D7B01FC186
                                                    SHA-512:144AFE1CB812DE93FBDD08658AFEB4C95480A8E504C5DCF909FF226400CA2D0F48395CF71954FBD1B3DD93A49CBA39EC0DB3FC34A05804C93FD9A48B0A1749CA
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d......d.........." .........0...............................................@.......A....`A........................................p...H............0...............0...!..............p............................................................................rdata..............................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.549935038939539
                                                    Encrypted:false
                                                    SSDEEP:192:+cWvhWoWYnO/VWQ4mWRhXEKup3JdqnajKsztzy:+cWvhWWUqX7aJdlGsztzy
                                                    MD5:CB39EEA2EF9ED3674C597D5F0667B5B4
                                                    SHA1:C133DC6416B3346FA5B0F449D7CC6F7DBF580432
                                                    SHA-256:1627B921934053F1F7D2A19948AEE06FAC5DB8EE8D4182E6F071718D0681F235
                                                    SHA-512:2C65014DC045A2C1E5F52F3FEA4967D2169E4A78D41FE56617CE9A4D5B30EBF25043112917FF3D7D152744DDEF70475937AE0A7F96785F97DCEFAFE8E6F14D9C
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d................" .........0...............................................@............`A........................................p...H............0...............0...!..............p............................................................................rdata..............................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.319450964936577
                                                    Encrypted:false
                                                    SSDEEP:192:MPWvhWRWYnO/VWQ4SWiIsxZAqnajT9CDH:yWvhWRUCs/Al39OH
                                                    MD5:5B6C46F42ED6800C54EEB9D12156CE1F
                                                    SHA1:66CE7A59B82702875D3E7F5B7CF8054D75FF495F
                                                    SHA-256:2631CADCE7F97B9A9E6DF4E88F00F5A43EF73B070EE024ED71F0B447A387FF2F
                                                    SHA-512:38FF6745BB5597A871B67AA53FCC8426BC2CDD16B6497A0EB7B59C21D8716F1ABB1F7C7A40A121AD1BD67B5490FEF5CF82EE8FD0BF848F27DCA27FC5D25DEC61
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d......#.........." .........0...............................................@...........`A........................................p...<............0...............0...!..............p............................................................................rdata..............................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.6478341719136145
                                                    Encrypted:false
                                                    SSDEEP:192:y0WvhW3WYnO/VWQ4mW8iTH2vArqnajKsbTYk:FWvhWnUIH24rlGsbTYk
                                                    MD5:A68D15CAB300774D2A20A986EE57F9F4
                                                    SHA1:BB69665B3C8714D935EE63791181491B819795CB
                                                    SHA-256:966DDBF59E1D6C2A80B8ABBF4A30D37475DE097BF13FB72BA78684D65975CD97
                                                    SHA-512:AC040F92560631CA5162C7559173BDFE858E282225967AB1ADC0A038D34943B00DB140D44319CD2CDC2864295A098AB0BA634DFAA443E1D1782FA143AE4C217D
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d...8.?;.........." .........0...............................................@......5.....`A........................................P................0...............0...!..............p............................................................................rdata..@...........................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):25056
                                                    Entropy (8bit):4.647238720605179
                                                    Encrypted:false
                                                    SSDEEP:192:3jQ/w8u4cy1WvhWb9WYnO/VWQ4SWANsAlosytkqnaj6Md:fy1WvhWhUNsilWMd
                                                    MD5:0E35E369165875D3A593D68324E2B162
                                                    SHA1:6A1FF3405277250A892B79FAED01DCDC9DBF864A
                                                    SHA-256:14694879F9C3C52FBD7DDE96BF5D67B9768B067C80D5567BE55B37262E9DBD54
                                                    SHA-512:D496F0C38300D0EED62B26A59C57463A1444A0C77A75C463014C5791371DECA93D1D5DD0090E8E324C6A09BD9CFF328F94947272CA49018C191C12732E805EE8
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d....A............" .........@...............................................P......4.....`A........................................P................@...............@...!..............p............................................................................rdata..>........ ..................@..@.data........0......................@....rsrc........@.......0..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.454858890873412
                                                    Encrypted:false
                                                    SSDEEP:192:PLGju+OXWvhW+eWYnO/VWQ4mWPiNbj21EhqnajKsxy:PLGjuJWvhWFUztqslGsxy
                                                    MD5:DACF383A06480CA5AB70D7156AECAB43
                                                    SHA1:9E48D096C2E81A7D979F3C6B94315671157206A1
                                                    SHA-256:00F84C438AAB40500A2F2DF22C7A4EC147A50509C8D0CDAC6A83E4269E387478
                                                    SHA-512:5D4146A669DDB963CF677257EC7865E2CFCB7960E41A38BBD60F9A7017474ED2F3291505FA407E25881CBF9E5E6B8055FF3BD891043284A0A04E3FE9CFAD9817
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d................." .........0...............................................@......w.....`A........................................P..."............0...............0...!..............p............................................................................rdata..r...........................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.950541424159939
                                                    Encrypted:false
                                                    SSDEEP:192:RSnWlC0i5CtWvhWJKWYnO/VWQ4SWuMasxZAqnajT9CQMDt:RSnWm5CtWvhWWUyas/Al39ODt
                                                    MD5:D725D87A331E3073BF289D4EC85BD04D
                                                    SHA1:C9D36103BE794A802957D0A8243B066FA22F2E43
                                                    SHA-256:30BCF934CBCC9ED72FF364B6E352A70A9E2AFA46ECEADEA5C47183CB46CFD16E
                                                    SHA-512:6713FF954221C5DD835C15556E5FA6B8684FA7E19CE4F527A5892E77F322B3DAE7199A232040B89AD4A9575C8D9788D771892D2294F3C18DA45E643EB25FDB08
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d......0.........." .........0...............................................@............`A........................................P................0...............0...!..............p............................................................................rdata..............................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.591111522505104
                                                    Encrypted:false
                                                    SSDEEP:192:PUFY17aFBRIWvhWrWYnO/VWQ4mWCJH2vArqnajKsbTYxj:8Q1WvhWLUrH24rlGsbTY5
                                                    MD5:9151E83B4FDFA88353B7A97AE7792678
                                                    SHA1:B46152E70D5D3D75D61D4CCDB50403BD08BB9354
                                                    SHA-256:6C0E0D22B65329F4948FCF36C8048A54CCCCBF6C05B330B2C1A686F3E686EED0
                                                    SHA-512:4D4210474957E656D821E1DC5934A4BFBF7E73DD61D696A1AB39914F887810C8FBE500DBB1E23782B40807F25820F35C9665E04DCDC2FD0F6C83046A4AECB86B
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d...G..d.........." .........0...............................................@............`A........................................P................0...............0...!..............p............................................................................rdata..f...........................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.54281367075804
                                                    Encrypted:false
                                                    SSDEEP:192:g8yWvhWVWYnO/VWQ4mWWeUDj21EhqnajKsxRIM9:gtWvhWFUtDqslGsxRIG
                                                    MD5:EBC168D7D3EA7C6192935359B6327627
                                                    SHA1:AECEB7C071CF1BB000758B6CEEBEFEEC91AD22BD
                                                    SHA-256:C048A3D7AB951DCE1D6D3F5F497B50353F640A1787C6C65677A13C55C8E99983
                                                    SHA-512:891D252ECD50BDED4614547758D5E301BDF8E71FBB1023FF89F8DE2F81927CC7CC84B98985D99E8FA8DCBF361E5117D9C625DC0D36983AFC3F2AA48A54CE3D48
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d....h\..........." .........0...............................................@......}.....`A........................................P...e............0...............0...!..............p............................................................................rdata..............................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):29144
                                                    Entropy (8bit):4.946641263598223
                                                    Encrypted:false
                                                    SSDEEP:384:MQM4Oe59Ckb1hgmLJWvhWdUN8HOhlxAnY:rMq59Bb1jeanOunY
                                                    MD5:7A235962DBAB1E807C6EC7609FC76077
                                                    SHA1:148DDD11A0D366313F75871007057B3F0485AB33
                                                    SHA-256:F7C5D7394643C95FE14C07773A8A206E74A28DB125F9B3976F9E1C8C599F2AF1
                                                    SHA-512:25B21EE7BB333E5E34D2B4A32D631A50B8FFAF1F1320D47C97C2A4DFF59FA2A2703CDF30638B46C800D3150EFAA4A2518C55E7B2A3B2E4273F43DD5CA83AE940
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d...J..R.........." .........P...............................................`............`A........................................P....%...........P...............P...!..............p............................................................................rdata...&.......0..................@..@.data........@......................@....rsrc........P.......@..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):29136
                                                    Entropy (8bit):4.764408242494898
                                                    Encrypted:false
                                                    SSDEEP:384:VA/kPLPmIHJI6/CpG3t2G3t4odXLJWvhWSUwlmX7aJdlGszti:y/kjPmIHJI6AFc7aJGT
                                                    MD5:B3B4A0F3FCE120318E71DE3AFB6BB1AA
                                                    SHA1:D3349409EC717F942769BA67FECA40557C1423D0
                                                    SHA-256:A38E6786DC8EC6D2717343DBE00BB2FDDA008D87935BBD9371AE94E7E004270B
                                                    SHA-512:4A130674DDBB05949665F6F7A070B25E82C34047D1E62EC60C73F815CED39A9041D972BE4E8C505F9B13C5BCDC114F3479BF8D69D7D9CF9987D39A6F5DB7F560
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d....T............" .........P...............................................`............`A........................................P.... ...........P...............P...!..............p............................................................................rdata..D".......0..................@..@.data........@......................@....rsrc........P.......@..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):74192
                                                    Entropy (8bit):5.1227875842071615
                                                    Encrypted:false
                                                    SSDEEP:1536:LLraHgDe5c4bFe2JyhcvxXWpD7d3334BkZnjPgB/P5W:baHgDe5c4bFe2JyhcvxXWpD7d3334Bkb
                                                    MD5:7033AB91EA4F0593E4D6009D549E560F
                                                    SHA1:4951CE111CA56994D007A9714A78CDADEEB0DACF
                                                    SHA-256:BE7901AA1FACEA8E1FD74A62BDE54CC3BD8E898B52E76FABB70342B160989B80
                                                    SHA-512:8BC3B880E31EBE3BC438A24D2AF249C95E320AC3C7A501027EF634F55AAB6FAC4F6D1090A00C29A44657A34EBADCD62023F2E947D31C192072698B645F8651ED
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d.....+..........." ................................................................e.....`A........................................P....................................!..............p............................................................................rdata..............................@..@.data...............................@....rsrc...............................@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.608840616484201
                                                    Encrypted:false
                                                    SSDEEP:192:4adyqjd7VWvhWpWYnO/VWQ4mWB8nXEKup3JdqnajKszt0CkD:4aQ0WvhWpUnX7aJdlGszt0r
                                                    MD5:55463244172161B76546DC2DE37F42BD
                                                    SHA1:C10A5360AD5E340D59C814E159EA1EFCBF5BF3EE
                                                    SHA-256:4166A32551989F960DAC7C0E296FFB28092F45F6539E7C450FA04BF17612BE73
                                                    SHA-512:EACEC78FF95F60DEF6F7F27BDA4A84F1DD2DFA386EFC4F6DA770C37268DF83C5B402693EA5C29F54D48026579F3843DB26ADD4D6448EA10CBF7F14D4D14A72FD
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d....w>..........." .........0...............................................@......M.....`A........................................P...x............0...............0...!..............p............................................................................rdata..............................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):25040
                                                    Entropy (8bit):4.795732177662406
                                                    Encrypted:false
                                                    SSDEEP:192:oHUW9MPrpJhhf4AN5/KiZWvhWMWYnO/VWQ4mWLz8Y5H2vArqnajKsbTYCkI:oHUZr7PWvhW6UeH24rlGsbTYCx
                                                    MD5:27C4A3BCC0F1DBA2DE4C2242CD489F3B
                                                    SHA1:A704FD91E3C67108B1F02FD5E9F1223C7154A9CC
                                                    SHA-256:315DED39D9E157CEC05D83711C09858C23602857C9D8C88BEEF121C24C43BE84
                                                    SHA-512:793E74DFB1052C06AB4C29E7B622C795CC3122A722382B103940B94E9DAC1E6CA8039DF48C558EFCC5D952A0660393AE2B11CED5ADE4DC8D5DD31A9F5BB9F807
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d...4{.+.........." .........@...............................................P............`A........................................P...4............@...............@...!..............p............................................................................rdata........... ..................@..@.data........0......................@....rsrc........@.......0..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):25040
                                                    Entropy (8bit):5.082770273323341
                                                    Encrypted:false
                                                    SSDEEP:192:DA2uWYFxEpahrWvhW/nWYnO/VWQ4mWSmRkH2vArqnajKsbTYMlBzK:DIFVhrWvhWfUERkH24rlGsbTYx
                                                    MD5:306608A878089CB38602AF693BA0485B
                                                    SHA1:59753556F471C5BF1DFEF46806CB02CF87590C5C
                                                    SHA-256:3B59A50457F6B6EAA6D35E42722D4562E88BCD716BAE113BE1271EAD0FEB7AF3
                                                    SHA-512:21B626E619AAF4EDA861A9C5EDF02133C63ADC9E893F38FEDE72D90A6E8BE0E566C117A8A24CA4BAB77928083AE4A859034417B035E8553CC7CCFB88CB4CBD9C
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d...+b............" .........@...............................................P......'l....`A........................................P...a............@...............@...!..............p............................................................................rdata........... ..................@..@.data........0......................@....rsrc........@.......0..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):25040
                                                    Entropy (8bit):5.075489018611419
                                                    Encrypted:false
                                                    SSDEEP:768:dozmT5yguNvZ5VQgx3SbwA71IkFPaPA6XHPe:dozmT5yguNvZ5VQgx3SbwA71IAaP7XH2
                                                    MD5:EC1381C9FDA84228441459151E7BADEA
                                                    SHA1:DB2D37F3C04A2C2D4B6F9B3FD82C1BE091E85D2C
                                                    SHA-256:44DDAB31C182235AC5405D31C1CBA048316CC230698E392A732AC941EC683BAD
                                                    SHA-512:EE9EBBDC23E7C945F2B291FDE5EB68A42C11988182E6C78C0AB8FA9CB003B24910974A3291BCDAA0C8D1F9DFA8DF40293848FB9A16C4BE1425253BED0511A712
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d....w.e.........." .........@...............................................P......0.....`A........................................P................@...............@...!..............p............................................................................rdata../........ ..................@..@.data........0......................@....rsrc........@.......0..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):5.000234308172749
                                                    Encrypted:false
                                                    SSDEEP:192:SNDKWvhW/WYnO/VWQ4mWVx2RoXEKup3JdqnajKsztg/J:RWvhWvUexqoX7aJdlGsztgx
                                                    MD5:4CF70855444F38E1EB71F9C3CD1C6E86
                                                    SHA1:D06AEC4008D397756EE841F0E7A435D1C05B5F07
                                                    SHA-256:A409E25A9D3C252CC0A5AF9DF85D3733E946087B06CD1FB2CF1BF640EB0D49BA
                                                    SHA-512:A13A80645E679343AC5638E8AA6A03012F16200CB3A4637BE52A01AA3BEF854324A8ED1882CA91B304B9C47B6351B1FC1671F4DEDE5BE77BC208A71FE6029064
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d.....p..........." .........0...............................................@............`A........................................P................0...............0...!..............p............................................................................rdata..............................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20944
                                                    Entropy (8bit):4.5308703760687745
                                                    Encrypted:false
                                                    SSDEEP:192:6PjfHQduHWvhWjWYnO/VWQ4mWEwXBXEKup3JdqnajKsztqOT+:QfxWvhWjUoXBX7aJdlGsztqx
                                                    MD5:FCD6B29932D6FB307964B2D3F94E6B48
                                                    SHA1:BE560F8A63C8E36A7B3FA48FF384F99F69A5D4F7
                                                    SHA-256:CFB2EE4E426BB00B76163C1A66CF8CFEF8D7450CBF9BBCE3BC9EB2053F51E0E5
                                                    SHA-512:3EDFCF559F1E21870277358E6D266A1A0CEA68B163B11C73108F3B6A56006D20B51410A3B4EA39BF80906BF6C9D573E1072697CFCD6A3D37E3679EA54757C69F
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.....v...v...v...~...v...v...v...r...v.....v...t...v.Rich..v.................PE..d...w............." .........0...............................................@............`A........................................P...^............0...............0...!..............p............................................................................rdata..............................@..@.data........ ......................@....rsrc........0....... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):1115248
                                                    Entropy (8bit):6.3726355883765
                                                    Encrypted:false
                                                    SSDEEP:24576:iSTvX9udcRO8tsmntwDKebWZdO/5kOuiNJqUEMaoekdzlklK2+T87EEfZkRSxXiM:0LadYuPoSxyDo
                                                    MD5:EA8C79A9243A9D48E5CB8FD68261322A
                                                    SHA1:8ED9EC16E09B491E625DE04C435218638825DE80
                                                    SHA-256:A239CD4DFCA9058EA93C428201489640A4414752BCEF9E11A5670A772240C26B
                                                    SHA-512:6B2DCD7C6B51AD1884D99D3B3615C82FB853793F3B5A64A1173BB9BFB28F489BB2EA5B548ACF5E62533A7FBFBF4CE0B18F85E6E1F3796ECCAB57B462182EDE72
                                                    Malicious:false
                                                    Preview:MZ......................@...................................@...........!..L.!This program cannot be run in DOS mode....$..........d.a.7.a.7.a.7...6.a.7...7.a.7...7.a.7..i7.a.7...7.a.7...6.a.7...6.a.7...6.a.7...6.a.7...6.a.7...6.a.7...6.a.7...6.a.7.a.7.c.7...6.a.7...6.a.7...6.a.7..k7.a.7.a.7.a.7...6.a.7Rich.a.7........PE..d....J(f.........." .........".......8.......................................@............`.........................................P;......H>...................n......p ....... ..`N.......................P..(....N..8...............8............................text............................... ..`.rdata..6...........................@..@.data................v..............@....pdata...n.......p...L..............@..@.rsrc...............................@..@.reloc... ......."..................@..B................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):65648
                                                    Entropy (8bit):6.06744789744509
                                                    Encrypted:false
                                                    SSDEEP:1536:HU/TSOOcoa1kCkaLn/XEh2kHmQrs7oD3h44:kSOOcoYVFLfY2qmQ4D4
                                                    MD5:045E6E517353D75398D38BB1AC517AD8
                                                    SHA1:16A85FAAC32BC6FC9D4AD79CE8E5612282CF67D8
                                                    SHA-256:7C375D5B98AAC2C1FA3946C96A9596E664965358EFC56ECCB27B5C7CA4F358B6
                                                    SHA-512:37E7EADDFED8B9F6F3B7F7DCD432EB3AD5CF731B9D53008AADE4E593A610183C4D42D00CF6C92EE6F0DAD50DD7B2D050D9B210984B3AD2DB5DA3577FEBFDEF72
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........[_..._..._...V.?.Y.......].......I.......W.......\...K...[.......V..._...........]...K...X...K...^...K.S.^...K...^...Rich_...........PE..d.....e.........." ...$.p...t......Pu.......................................0.......C....`A............................................|...<...........P.......4.......p ... ......p...p.......................(...0...@...............X............................text...{o.......p.................. ..`.rdata..BQ.......R...t..............@..@.data...............................@....pdata..4...........................@..@.qtmetadb...........................@..P.rsrc...P...........................@..@.reloc....... ......................@..B................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):57456
                                                    Entropy (8bit):6.0198418568917065
                                                    Encrypted:false
                                                    SSDEEP:768:okzMAYH25Jy/iefVXZ7so5K4r+LtLgqxmJAzuoru3tGbrYiG3hGS:okwAYWLCVPKLBLgq4JA5u3tGbr7G3hGS
                                                    MD5:AEE3C6309229EC8226C4375CC1287774
                                                    SHA1:9378418FAEE2F0CC5C21E42F86520DF6A7941FBC
                                                    SHA-256:556D8AE99CF65173D28EFE11D6ECA8530EE2F94968A976E278E9AAAA2F6ABD55
                                                    SHA-512:44DBB95680D95D99D99838C00CFA55DFEA0E651C7B0F467FBEE2806BED3D66D0774424F155CE033C24D554DC0CA9EB5C6FB01EA80400726226F45B30EE3EF8F1
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k.\.............rf......t.......t.......t.......t.......u.......r..........d....u.......u.......u.......u......Rich............................PE..d......e.........." ...$.R...p.......V....................................................`A............................................|...\...........P...............p ......p.......p.......................(...p...@............p...............................text....P.......R.................. ..`.rdata..TL...p...N...V..............@..@.data...............................@....pdata..............................@..@.qtmetadj...........................@..P.rsrc...P...........................@..@.reloc..p...........................@..B........................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):6818928
                                                    Entropy (8bit):6.529961889974453
                                                    Encrypted:false
                                                    SSDEEP:49152:uoozhvG8tWcBy/FajEhdcMZAbc4hlqUbQ6uKTddbYyDoOagyZz6N1VKCh4Y+FltQ:zGNaYkCuTTMqjmc74ZF
                                                    MD5:5A21CFA6D341E5DA657ECE8270790437
                                                    SHA1:4F5FE585C49E35D56CDFA1199F45833BB70D3E36
                                                    SHA-256:C9FECA396BCC8DABD332AB2815A1664A09A29246086FCBB015BE198B8206346F
                                                    SHA-512:F18DD0F8D3F7B8D8A5618BDA076F6B24B4075D222E984D89D57902283AE27063A74704D988FBE72133F1D9E42FFA168C2252DA7FB96A0150F77C3185A02732BC
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........FH..(...(...(......(.>.,...(.>.+...(.>.-...(.>.)...(.9.-...(...)...(.I.)...(...)...(...!.j.(...(...(.......(...*...(.Rich..(.........................PE..d....cCf.........." ...$..<...+.....0[9.......................................h.......h...`A........................................0.Y.lp...x\.|.....g.......e.......g.p ....g.....@0N.p....................1N.(..../N.@.............<.P............................text.....<.......<................. ..`.rdata........<.......<.............@..@.data.........\.......\.............@....pdata........e......Ve.............@..@.rsrc.........g......Rg.............@..@.reloc........g......Tg.............@..B........................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):801904
                                                    Entropy (8bit):7.119148307782215
                                                    Encrypted:false
                                                    SSDEEP:24576:lalJ5SD0QEWMSBgmOzh3qGtlqIVIH06iyNg9+zq:s5w/EWhgmi1qGtlqoIU6iGzq
                                                    MD5:DE3D21D64176C5B81DBDF71E09F26A6B
                                                    SHA1:A4286DCD86781E07AAD134A267B06ADEE071057E
                                                    SHA-256:E8F120858BAA498063BE6BCD1BFCA8CAE6AEED653C21A20902F7E08CC89D4B2B
                                                    SHA-512:E28AB3F005A67DAC95BA1785CF0EFA7AF14833A7252EC554B11D6C50FC80825B5DB75DE6C6FE2C0CE0B38E046AEFF0DD8C9C14743D34B3D1B8D7721E5E506F20
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......0~p.t...t...t...}g..z....n..v....n..x....n..|....n..p...`t..r....m..w...t.......t...d....m.......m..u....m.u....m..u...Richt...................PE..d......e..........# .........n......D..................................................... .........................................p=..x....=.......p..........xH......p ..............T...............................8............................................text............................... ..`fipstx.............................. ..`.rdata...t.......v..................@..@.data........`.......8..............@....pdata..xH.......J...>..............@..@fipsro...l.......n..................@..@fipsda..~....@......................@...fipsrd..............................@..@.rsrc........p......................@..@........................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):79472
                                                    Entropy (8bit):6.6433568129806195
                                                    Encrypted:false
                                                    SSDEEP:1536:yyOWO5gfNSC0/Gx6MhivZGdw6AvDCpkRMHtSxzIPW4U+RV28qTXguAKR7M+3hli:1OWp/6fMFQt0W4DPVqTXguZRYgi
                                                    MD5:0A9C3CB908C46D2568BC565D6E2EF5BA
                                                    SHA1:311BF8C0101BAC9014A89EBF4B11E81B873DC7CA
                                                    SHA-256:A0155F8F72886DE6CDCA9F71D034CEAC18066997B37D222B7FE106CA28C4709C
                                                    SHA-512:543F82117EC598F2CA356D446D15E7D1A22C62280FB89E07DEB7B005B501C03B38EAE1D534DB5063221E65A64384EA481EDCC5F10EC427F4C3E4105EAF45D376
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........x..........................................u...................&......&......&...........&......Rich...........................PE..d....F(f.........." .........x...............................................`......@C....`.............................................|............@.......0..<.......p ...P..(...@...................................8............... ............................text...X........................... ..`.rdata...X.......Z..................@..@.data...`.... ......................@....pdata..<....0......................@..@.rsrc........@......................@..@.reloc..(....P......................@..B........................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):7596656
                                                    Entropy (8bit):6.609976579191502
                                                    Encrypted:false
                                                    SSDEEP:196608:AAyMgHrO9g/U0TW7dgUcvfNM19SVieOAkPeOUPeOYPeOpPeOisL:4MgHrO9g/U0K7dgUcvfNM1reOAkPeOUs
                                                    MD5:D3334DE362DE51EAFC550E7DC4AA3136
                                                    SHA1:41143F2BC0B49421C3EE1ABF2F7480078234C860
                                                    SHA-256:F026AF49433F53119EC9CDCB3542ECB621C5D76BA2E6E78A0A6B83CA056C7ED2
                                                    SHA-512:0ECCF8CE39B992FB73F30BA662C420952ABEAA55B8083D052084176B015B14B7BEC8BE9A640EA4CE29153BEFADCC4FD05E6E283827FEADEDDAC264B76545F48B
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......;!...@.N.@.N.@.Nv8,No@.N.1.Ow@.N.1.O{@.N.1.Oe@.N.1.Oy@.N$(.O~@.N$(.O{@.N.2.O}@.N.2.Ov@.N.@.N.C.N.2.ObB.N.2.O~@.N.2@N~@.N.@(N~@.N.2.O~@.NRich.@.N........PE..d..."SP`.........." .....T<...7.....@.9......................................pt.......t...`A..........................................l.X...(.l.h.....s.(.....q.......s.p ....s......c.......................c.(... .c.8............p<..............................text....R<......T<................. ..`.rdata...e1..p<..f1..X<.............@..@.data.........m..p....m.............@....pdata........q.......q.............@..@.rsrc...(.....s......2s.............@..@.reloc.......s......:s.............@..B........................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):1244272
                                                    Entropy (8bit):5.573927505926549
                                                    Encrypted:false
                                                    SSDEEP:12288:BqsezYVuRKQdPw+27NOkBz7WBJAgvVRWmfAaah:BqsezYVuRKQdP8OkBOB6gvVRzK
                                                    MD5:656A2475689965B00B077D54555C1AC5
                                                    SHA1:C13FFB2EDE3740883136F8E6B9148C0624C568F1
                                                    SHA-256:2A0648E87596EF72B76CFC833C8D47E1EF70615DCE67BD2243C296F35B1A1C49
                                                    SHA-512:C7D885C6A5339779A239BD4309A72C689A05FCFEF8B5049C2B13435435CFA484211C84242220D6B6F99715CC83D7F0ACCD2E0F1AE4D7263E647B683DAF95BBE5
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........R..............@...............................................................................,.............Rich............PE..d....).f.........." .................Z.......................................`............`.........................................p...........T....0..........@.......p ...@..t......8.......................(...............................@....................text............................... ..`.rdata..............................@..@.data....0....... ..................@....pdata..............................@..@.idata..^A.......B...t..............@..@.didat..-...........................@....tls................................@....00cfg....... ......................@..@.rsrc........0......................@..@.reloc.......@......................@..B................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):317352
                                                    Entropy (8bit):6.298425715332543
                                                    Encrypted:false
                                                    SSDEEP:6144:LUOcVzjbad5roFOcKp8PRhsChd6ZBYzbnWzgqo8C5od:YTdjKoFVKwzKzi4
                                                    MD5:B6A063CCDE77F52BC966DAF4A86F0B90
                                                    SHA1:7DC3DF9B669BDB0EF59AE2DF51B9AE78B4896C79
                                                    SHA-256:E7C3A31351AA8634E062F57C755AADE8B0241971FA99E4E990BB162EF9A2562E
                                                    SHA-512:098A4C5DB4F394244828F49B1F54D01FB0665C771840EFBDC366B45A84E43B31BEDD02501F57B04910CD22FB428039326C546ED248BC8C4F0E96B341114477B8
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........N.../.../.../..X].../...Wu../...W.../.../.../...W.../...W.../...W.../...W.../...W.../...W.../..Rich./..........................PE..d....Y.|.........." ......................................................................`A.............................................M...+...................6.......'......x...p5..p...........................04..@............................................text...,........................... ..`.rdata...M.......N..................@..@.data....?...@...8...0..............@....pdata...6.......8...h..............@..@.rsrc...............................@..@.reloc..x...........................@..B................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):83568
                                                    Entropy (8bit):6.124783005403057
                                                    Encrypted:false
                                                    SSDEEP:1536:m5e+8r4f0vktHhCFNFmTofvX/XDpq8MIT7yc3htg:l+k4f0vklhomWPXdq8MITJg
                                                    MD5:E835BC2D7845FBEBF5F06EBDEFD215E4
                                                    SHA1:286B23282A6BA14E682C1DD17065E8B53772DACB
                                                    SHA-256:29FF1AE8CB34D39982293BF7460F3EF012EFA260C3B3980B994ADD9B8A803887
                                                    SHA-512:2F0AE751C397926EECBAA2368020403120D24DBDACE0353C8D9AA975C305C59C4928DF79660102EF4779F514CFB523D6DC84C059650E1BE7BC96B4EDA6151DA5
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......\..!...r...r...r..Vr...rJ..s...rJ..s...rJ..s...rJ..s...r...s...r}..s...r...ri..r...s...r...s...r...s...rRich...r........PE..d.....e.........." .........................................................`.......I....`.........................................P.......\................@..t....&..p ...P..0.......T.......................(....................................................text...|........................... ..`.rdata...`.......b..................@..@.data...h....0......................@....pdata..t....@......................@..@.reloc..0....P.......$..............@..B................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):212080
                                                    Entropy (8bit):6.21398866801612
                                                    Encrypted:false
                                                    SSDEEP:3072:pvkwNdEj1y1dCXjMcMB2nCQ3EO1P5U6oBRSNCVid4iuXeGU:pnNdEjA1Y/g2nCbaReR2CVid4iOU
                                                    MD5:00192855F4BC7B4D53DB71F63BF67585
                                                    SHA1:5FE43281D613000401C7112CBC38F4CA83A4878B
                                                    SHA-256:014A18363C99B1B9EC813F4F463FE8F49EA5EDDDD7710678DF6C8CCA0A2AACB4
                                                    SHA-512:C276F49CA174DA0F4C9CD5BD98176BBC8B2F44D538F89E1CA51F7AB18BF4D8CE93473FE0DE58B03EB9E4B2F08B1686615504EAD1B51BBBABDADC8119EF9C8CF6
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........@..B!..B!..B!..KY..H!..'G..@!...I..J!...I..@!...I..U!...I..F!...H..A!..B!...!...H..T!...H..C!...H..C!..RichB!..........PE..d......e.........." .........8...............................................`............`.........................................P....9................... ..H!......p ...P.. ..../..T...................P1..(...P0.................. ............................text............................... ..`.rdata..f...........................@..@.data...............................@....pdata..H!... ..."..................@..@.reloc.. ....P......................@..B................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):2064496
                                                    Entropy (8bit):6.266695553133005
                                                    Encrypted:false
                                                    SSDEEP:24576:ZbR0IUX9PRorvAV3LXAPO7ELFuSk16PbU+GJ5o+VNfGLjN7h8/Qq+tpxqNxXfdRd:ZbR0I6pV37AESZU+Qpa5y/X+DxNQ
                                                    MD5:7686B9FDF9FE5B640562C9F00855A0B7
                                                    SHA1:F776C020B4362F679854EA9B3697985DE794EE6C
                                                    SHA-256:7464C665F0EA63B4D9AD76DA264DA7C09D0B26733B27C4A4D96F8D09876195F0
                                                    SHA-512:0AE8D03CD82F0F06214A8B7FCCEF4FF44E92DA52C10FA433AB60926C766607900EBD80406397FF615D74B44918D4F56899A142D41EAD84DE3E6D30C89ACA6FC3
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$......."P..f1..f1..f1..oIk.h1....?.g1..4Y..n1..4Y..e1..4Y..}1..4Y..b1...X..r1...W..k1..f1...0...X...1...X..g1...X..g1..Richf1..........................PE..d...W..e.........." .................N....................................................`.................................................@...................\....`..p ...p......0...T.......................(....................................................text...\........................... ..`.rdata..`...........................@..@.data........ ...r..................@....pdata..\............|..............@..@.reloc.......p.......J..............@..B........................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):238704
                                                    Entropy (8bit):6.210016546382543
                                                    Encrypted:false
                                                    SSDEEP:3072:dubhyDtdjcEBealFqNt/sol2GtUJjeIJVF1iIAGpkN6umWUX:du9yvpBXur/7EGtUJjVTs22N6AUX
                                                    MD5:E6582754116CCEADDA19E7C8DA6AA3DC
                                                    SHA1:7DC010E00FF07065FBC0C67E5F7AFBB47306C77B
                                                    SHA-256:68D5FE5FD1A508CEDAA5F20FC69382DDF1709F9A48601E9051275776DC1842B7
                                                    SHA-512:B19E63929F0DC6C3917E7D99FC7B032E7831CDF1B407582C90639847E0E48343CBB0A230611A9699F43F88C9DCBD33FC9E71B977A6321D21F5D148D2B459EAD5
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......L[@{.:.(.:.(.:.(.B.(.:.(ZR*).:.(ZR-).:.(ZR+).:.(ZR/).:.(m\/).:.(.S/).:.(.:/(.:.(.S+)$:.(.S.).:.(.S,).:.(Rich.:.(........PE..d......e.........." .........z......$................................................L....`.........................................P....M...C..........................p ......d....|..T....................~..(....}............... ...............................text...p........................... ..`.rdata...E... ...F..................@..@.data........p.......X..............@....pdata...............f..............@..@.reloc..d...........................@..B................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):4916712
                                                    Entropy (8bit):6.398049523846958
                                                    Encrypted:false
                                                    SSDEEP:49152:KCZnRO4XyM53Rkq4ypQqdoRpmruVNYvkaRwvhiD0N+YEzI4og/RfzHLeHTRhFRNc:xG2QCwmHPnog/pzHAo/A6l
                                                    MD5:2191E768CC2E19009DAD20DC999135A3
                                                    SHA1:F49A46BA0E954E657AAED1C9019A53D194272B6A
                                                    SHA-256:7353F25DC5CF84D09894E3E0461CEF0E56799ADBC617FCE37620CA67240B547D
                                                    SHA-512:5ADCB00162F284C16EC78016D301FC11559DD0A781FFBEFF822DB22EFBED168B11D7E5586EA82388E9503B0C7D3740CF2A08E243877F5319202491C8A641C970
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........|3..]...]...]..e\...]...\.5.]..e...]..wX...]..wY...]..e^...]..eX.y.]..eY...]..e]...]..eU./.]..e....]..e_...].Rich..].................PE..d...^.}`.........." ......8..........<).......................................K.....:FK...`A........................................`%G.x....(G.P.....J.@.....H.......J..%....J.....p.D.p....................S<.(...pR<.@............S<.(............................text.....8.......8................. ..`.rdata...F....8..P....8.............@..@.data...`....@G......@G.............@....pdata........H......@H.............@..@.rsrc...@.....J......@J.............@..@.reloc........J......PJ.............@..B........................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):183408
                                                    Entropy (8bit):6.222679582031809
                                                    Encrypted:false
                                                    SSDEEP:3072:uqiN6A52wT+fQJAqNQCyST5LyOgeYl98W+JNNHRWUcX04MyGdPZf:u56K2wNJ9OgwOnY1HL04M/f
                                                    MD5:49C90AE8E215D5A2007ED6C6E27134DB
                                                    SHA1:0E4882C3F1EE6BBA4EE5C9C6E55C25E8CDAC37B7
                                                    SHA-256:48A4A822E30B8D77BBCB3414741F5E32D0DE7467A4CCA2706B68510E0658DF33
                                                    SHA-512:5047A130CDBF469B4F3EE9569C2ABA3CE35ADED0CAA399FBAF08F9F0E7A4450AADC214336A3BF3AAEB07000430676D9356FCD4AC61D932C59366152A6892009D
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........i...................................................j...........p...j.......j.......j.......Rich............PE..d...%.d.........." .................}....................................................`..........................................9..LA..,{..................H.......p ..............T........................... ...................@............................text............................... ..`.rdata..............................@..@.data...P...........................@....pdata..H...........................@..@.reloc..............................@..B................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:data
                                                    Category:dropped
                                                    Size (bytes):114618
                                                    Entropy (8bit):7.676731082436654
                                                    Encrypted:false
                                                    SSDEEP:1536:2IkpVIq5JxC0jv2Y0RUzMDVuvj7GNTFeqdKtZHoZyu0bz/IJPlqU:2lpdDeY0R6iVuvjyx2yyjbsXt
                                                    MD5:13CEDE6990F6E6EFA064EA88B422CB82
                                                    SHA1:E57A30017545187C9F37EAC11ED76D2D1CF38839
                                                    SHA-256:D9CCEB753DD5CC11C06E294E9C7D8FC57D9F2DC6E87367EBB60CD8457BAD23A1
                                                    SHA-512:76D0D3EEE7C7ECB81087F1349382E239D6B48FB52B60211EECC4D98618D2985BACA47276C5AC187504A0678D3AFF4A01C5B89FD6B7E455CCB247E60D90CC6FC8
                                                    Malicious:false
                                                    Preview:0......*.H...........0.......1.0...`.H.e......0...H..*.H..........8....30......*.H...........0.......1.0...*.H...........0...0...........~C.NG?.0...*.H........0..1.0...U....HU1.0...U....Budapest1.0...U....Microsec Ltd.1'0%..U....Microsec e-Szigno Root CA 20091.0...*.H........info@e-szigno.hu0...090616113018Z..291230113018Z0..1.0...U....HU1.0...U....Budapest1.0...U....Microsec Ltd.1'0%..U....Microsec e-Szigno Root CA 20091.0...*.H........info@e-szigno.hu0.."0...*.H.............0............c....B...&...cp....3@}m.n..D.....BR..u.t,........,...\q.....~../...u....;.JF..}.....mJ...M3..9@u~.|...P.Ag...aT.lN.......3...U(,.......US..{.H...7.$.Y.P.c........._..Pn.....q~...|.Sn"_.+..|]....L.....W..#y...$...jQ..w..............v.3CI..............0~0...U.......0....0...U...........0...U..........BC.=.H#..z.*.4h0...U.#..0.......BC.=.H#..z.*.4h0...U....0...info@e-szigno.hu0...*.H................^...|>..=..(......y.C.....!....]...B.0l......?.sj>..@~..Tay...7.#.....u..T....).....
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):13511792
                                                    Entropy (8bit):6.333894872156662
                                                    Encrypted:false
                                                    SSDEEP:98304:sNE+JEGP7kjgzblchGZFC4OMZjC70pnSovvipwkGkOPqmVFhqQ:sNE+V19gMZjDNvdksqQ
                                                    MD5:7694DD97308865B4C57DA58629057828
                                                    SHA1:63E2A1E615D8C4764B2900279911A9963275EAC2
                                                    SHA-256:FFEDD0C250260BAF7DFB2E0D602EF1F963DA2CAB5EF9276D3F7AF857239F205D
                                                    SHA-512:FBF839A4958E456F6DBF2512CD28797C0C260A1901D706B8F76379F7474EA50F8549DB195BEB9EC011B5773DAC92BAE0992B0C1F89213C6C2EC415F670A869D0
                                                    Malicious:false
                                                    Preview:MZ......................@...................................0...........!..L.!This program cannot be run in DOS mode....$.................2...>{f...................7.....7..........7.........:.....7......7.....7.....7.^...7.....Rich...................PE..d....1.f.........." ..........9......<...............................................|....`.........................................@.......4...........................p ..............T.....................(..................................................text............................... ..`.rdata..<.0.......0.................@..@.data........0...`..................@....pdata...............|..............@..@.rsrc................6..............@..@.reloc...............<..............@..B................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):426608
                                                    Entropy (8bit):7.143027956967716
                                                    Encrypted:false
                                                    SSDEEP:6144:z82qwx6rSlo05vUZj4QYtGWhr0bck2FAPsByy1zyX2IST20SPN9zIbZg4w:RxfG01U9EGWhBFAPsByypqSFY9Eq/
                                                    MD5:0CF989AE9779E463112D2BCD5EEF8C66
                                                    SHA1:3DFA638FFBD864E042A14DAB62BFBA9012E2A928
                                                    SHA-256:BD277AA3EE9EDA4400C2AF572ADB831C5114782C32C078F5FE625A6F69A39593
                                                    SHA-512:FF77DFA58443BC274A3B75F1CB1EEFB6890076D6E6212E8753B3E5BF907B50B7C66AC6B9575796C3FC8230E360FE0F31EF816EA878AA6C3ADFCA68AFB16D2752
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........|..|/..|/..|/.../..|/+.x...|/+.....|/+.y...|/+.}...|/\.}...|/..}/..|/..u...|/..|...|/../..|/..~...|/Rich..|/........PE..d....aCf.........." ...$............@.....................................................`A.............................................!..8................p.......b..p ......x.......p.......................(...P...@............................................text.............................. ..`.rdata...].......^..................@..@.data...HD... ...@..................@....pdata.......p.......F..............@..@.rsrc................^..............@..@.reloc..x............`..............@..B........................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):44144
                                                    Entropy (8bit):6.183982785876683
                                                    Encrypted:false
                                                    SSDEEP:768:y2DNSssWcmilNocbcjyJWaAJDOI+WOJCu4DYigR3hJJ:XDkymucguJWaIKI+WOJ74D7k3hJJ
                                                    MD5:F41052FD9D94C8DD3C16A62025E55B2B
                                                    SHA1:9293C6BCE1B7BCB5A7B092697D72BA0DA7BFF17A
                                                    SHA-256:28A768C4E1D8368F333F745707053BC7D9DD1010717DD9AF8FC8E548C4C09A23
                                                    SHA-512:D3DF9AB626949D587CAD3B795D01220A374DF50CF1AAB82562DB4E7B773BDE5C0358D17E479C26EBD6B65E271161269E5224DFD9681AD3C73738C58E19FDA9FB
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........Yu..7&..7&..7&..&..7&-.6'..7&..6'..7&-.2'..7&-.3'..7&-.4'..7&..6'..7&..6&:.7&..>'..7&..7'..7&...&..7&..5'..7&Rich..7&........PE..d.....e.........." ...$.@...P......0F...............................................E....`A........................................ k..x....k..........H...............p ...........Z..p....................[..(...pY..@............P...............................text....?.......@.................. ..`.rdata..P7...P...8...D..............@..@.data...h............|..............@....pdata...............~..............@..@.qtmetadj...........................@..P.rsrc...H...........................@..@.reloc..............................@..B........................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):41072
                                                    Entropy (8bit):6.144487861892957
                                                    Encrypted:false
                                                    SSDEEP:768:Nn39ArAeMau9bZJ7nqAYBmp4KovT7UNK5YzCnhGYitd3hJyD:AAYu9bZFGsp7uQNK5YzCnhG7td3hJyD
                                                    MD5:8CB4A8C12667DA2D3CB4914A453EF7A1
                                                    SHA1:ED06A1E8DE3B7D236093D346EA6F5C5312C356F5
                                                    SHA-256:7A5E581BE8EEEE92F4A8EE80C37FFFCDC406E17104736588AEC60F1307C57987
                                                    SHA-512:7117D7EB7D3D9FC4B6085B21857EFA9251A8DD96EA081964DC6057707659BD78DF706C152351D1224FF2CE84345E7B93C1DFD96264BD15022D3C137DBF3E0A5A
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A................G............N........................................r.....................+.............Rich............PE..d......e.........." ...$.@...D.......E....................................................`A.........................................h..t....h..........@...............p ..........PY..p....................Z..(....X..@............P...............................text...;?.......@.................. ..`.rdata...+...P...,...D..............@..@.data...P............p..............@....pdata...............r..............@..@.qtmetads............x..............@..P.rsrc...@............z..............@..@.reloc...............~..............@..B........................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):47728
                                                    Entropy (8bit):6.11275424856801
                                                    Encrypted:false
                                                    SSDEEP:768:Yy3p7TTPsiHlBmlK1GNg5QTQfmTJT9FUwcYE1PLhUUD5EpmmYiY3ht4:Yy1T9l441GgeT5TJZFUwcYEVL2UDOpmE
                                                    MD5:C283D98C5632A5F1488FA03CAD0D8D7F
                                                    SHA1:DD0EB39BBD9EC9E45F3B252566E45B0EEE9D36B6
                                                    SHA-256:A0C70D8C1D553F4D1EF315DB4B8681CD5E43393534A1C0E2F17BF01AB76B9917
                                                    SHA-512:8A25F72EC25A110D9E4B14259F4260E9C62290A7CFBB89E7B6073A6FAEB867F2A4A92BC3AF6BCF6D43202701CDB3E155534C50FF27ECFDDF6F0D92B3E8E7CB61
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$......... ...N.N.N....N...O.N...O.N...K.N...J.N...M.N..O.N.O.*.N..G.N..N.N...N..L.N.Rich..N.................PE..d......e.........." ...$.D...X.......I....................................................`A............................................t...$...........@...............p ...........r..p....................s..(...`q..@............`...............................text...;C.......D.................. ..`.rdata..,<...`...>...H..............@..@.data...............................@....pdata..............................@..@.qtmetadx...........................@..P.rsrc...@...........................@..@.reloc..............................@..B................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):40048
                                                    Entropy (8bit):6.100623998625708
                                                    Encrypted:false
                                                    SSDEEP:768:6tJZS44OohDp6ugh66U1obc0ZXsmcYig3hD7NU:T4cFJgh66U1oIqXsx7g3hD7NU
                                                    MD5:F503C010DA7F163BAEC81F1BCE1439F8
                                                    SHA1:2A4071C4BBD4BAEEF7176D5851D5EAD0959FA69A
                                                    SHA-256:209126E1E95530084F852878AD073B524DD39B92615FEEDBDF908ECCA8E0D695
                                                    SHA-512:07A80BF4B014780590B2A9FFE048952BFF039FBE737B344257D6250EE86EB7C68B0B2A68A1D233D74E0B3C49F5581EFCF207AE5FB228038FE13A9F466F4EC605
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........!..@...@...@...8=..@..!>...@...8...@..!>...@..!>...@..!>...@...?...@...@...@...?...@...?...@...?Q..@...?...@..Rich.@..........PE..d......e.........." ...$.4...J......p9....................................................`A........................................@j..t....j..........@............|..p ..........PZ..p....................[..(....Y..@............P..8............................text....3.......4.................. ..`.rdata..x1...P...2...8..............@..@.data................j..............@....pdata...............n..............@..@.qtmetad.............t..............@..P.rsrc...@............v..............@..@.reloc...............z..............@..B........................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):445040
                                                    Entropy (8bit):5.907217021489764
                                                    Encrypted:false
                                                    SSDEEP:12288:sWhOIZ3ZJCYkcy5DrHYoYeZ7j/w0AKJAgicVx7rwwCkIxnbJiMQw1LDdWaEiwcsA:ycsHg
                                                    MD5:3B01FA156EF2D42A3269C63EBBB47D9D
                                                    SHA1:386AEDE45347AD4E9997D1CEB63F97E1E6560671
                                                    SHA-256:E6A00C035A3C21F3F3F3E98E1CFD57918FEDC31A40CDFB5C8F1D0E2D08BC4768
                                                    SHA-512:7BD3FEC13112939B6BF2F1BB2810F8D3899719B3ACAF8CBAD51A38893B90DCC3B54631D2AF0D3196C960BC35B4523BCF55C5462F77EC2280A8AB4D9874583675
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........H..u&..u&..u&......u&.q.'..u&...'..u&.q...u&.q.#..u&.q."..u&.q.%..u&...'..u&..u'.=u&.../..u&...&..u&.....u&...$..u&.Rich.u&.........................PE..d......e.........." ...$..................................................................`A.........................................p..t....q..........@...............p ...........:..p....................;..(....9..@...............@............................text...+........................... ..`.rdata..F...........................@..@.data...P...........................@....pdata........... ..................@..@.qtmetad............................@..P.rsrc...@...........................@..@.reloc..............................@..B................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):33904
                                                    Entropy (8bit):6.10450975844002
                                                    Encrypted:false
                                                    SSDEEP:384:Z6bE7f4yHfd2WfjqdxMCn1L1dX3zSRWWebAOcsqs4Bd4jOf7TBiIYiW1Mk8JN777:Z1gYscuV1JzmHs54Yjk7TdYiou3hN3
                                                    MD5:F4AD24D710A7E713BA162075ACEE2AAA
                                                    SHA1:224F08BA28257F765F79EC9EE0D0A7E83D18E25E
                                                    SHA-256:613D609E52ED9062E5FE2EC59BA6C3CC391B6B564D8E159FEBA2967FEF0E5DF9
                                                    SHA-512:CBDBC9CE9C3F3BE975C9D1524A3620DD1E73377B8603B811F80CD03395343F47A4B9F332D9030196FECE832A19F96F2AF4177B5AA07D37E8457BCD45B46E9CE1
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........1H.._..._..._......._...^..._...^..._...Z..._...[..._...\..._...^..._...^..._...V..._..._..._......_...]..._.Rich.._.........PE..d.....e.........." ...$.$...D.......)..............................................a.....`A.........................................V..t...dW..........@.......x....d..p ...........J..p....................J..(....H..@............@..0............................text...;#.......$.................. ..`.rdata..z-...@.......(..............@..@.data...`....p.......V..............@....pdata..x............X..............@..@.qtmetad.............\..............@..P.rsrc...@............^..............@..@.reloc...............b..............@..B........................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):33904
                                                    Entropy (8bit):5.9743867773162
                                                    Encrypted:false
                                                    SSDEEP:384:hff7V2t3Xe6+UNws5UybJeW0YwEhgDSSwWUdN0xHArcHIYiHu8JN77hhqZC:h7Vbs5UeJeW0YwEywh0FArJYiJ3hMZC
                                                    MD5:2CF433E557EF356FD3EEA1FFB719D55F
                                                    SHA1:5048A7CF5C51D8BAC1C8673764D93C2C74812640
                                                    SHA-256:55A9CEC25B68DA98AC4707492D98EC635CEFE6783C9171235B5C9752FF3025A2
                                                    SHA-512:7D77B3507B9CA4FB7A687A77362A62A77D4B619EA8994633525730CA7AB676D2BD1DEA58F694954975C2CA31283EE4386E8251E91C34A22B5D1A1B61A033C4B4
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......F.....t...t...t.......t..u...t.I.u...t..q...t..p...t..w...t...u...t...u.r.t...}...t...t...t.......t...v...t.Rich..t.................PE..d......e.........." ...$.$...B.......'..............................................KH....`A........................................ Z..t....Z..........@.......x....d..p ..........@K..p....................L..(....J..@............@..p............................text....".......$.................. ..`.rdata...+...@...,...(..............@..@.data........p.......T..............@....pdata..x............X..............@..@.qtmetadu............\..............@..P.rsrc...@............^..............@..@.reloc...............b..............@..B................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):32368
                                                    Entropy (8bit):6.089048902217162
                                                    Encrypted:false
                                                    SSDEEP:768:1RrZwaiF/x7aukE2wXbURitNJJnYig23hvq:1R+lx7aukE2wXbURitNJJn7g23hvq
                                                    MD5:CD2547A1C363304A46A4F2583DA9C554
                                                    SHA1:36D14A23A745141EF48A80ED4FFF132C7FE61287
                                                    SHA-256:F954521AE14F45091FCA340EC2D2A5C445E3EFBB7856B4CAD2A89D6D3F5E0019
                                                    SHA-512:05F2BBC071A1AB5BBF2A6884E1BF732ED8669FFD89AE268E0B58CA1D86564733C18D598C6FA478789C44AC8D5D6A0C70B50E99E7C01F6F512B4E3C774BEC8327
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Ofv.....................y......@.......y......y......y.......x..........~....x.......x.......x.......x......Rich............PE..d......e.........." ...$."...@.......'....................................................`A.........................................V..t....V..........@.......l....^..p .......... I..p....................J..(....G..@............@...............................text...[!.......".................. ..`.rdata...)...@...*...&..............@..@.data...P....p.......P..............@....pdata..l............R..............@..@.qtmetad~............V..............@..P.rsrc...@............X..............@..@.reloc...............\..............@..B........................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):711280
                                                    Entropy (8bit):6.363731357663382
                                                    Encrypted:false
                                                    SSDEEP:12288:ytpM9GMKhBuVrQuB5G9bWLShKpxDo0Atyk:yty9GMKhBuVrQuB5G9bWLgKf+b
                                                    MD5:579C96A43DBF62156EB7D53F71B39F77
                                                    SHA1:714DE35BFFC741037238ACAC20DBF7AB6F0E6AD2
                                                    SHA-256:C9936174066086F73A10DF2F0465491409401D278FA4A57F3CF9EC03512400BA
                                                    SHA-512:49891FD0F189332E3A6F81299E62C22B4DA335C27AD5DEDD053CB3C31E3CC85AC5F71AC8C877C579AE3405CB26E0CEB52A4E4347268A741B031818F6EFFC0B2C
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$....... ...d.c.d.c.d.c.m...t.c..g.l.c..`.`.c..f...c..b.b.c.U...f.c.?.b.f.c..b.`.c..b.g.c.d.b...c..f.A.c..c.e.c...e.c.d..e.c..a.e.c.Richd.c.........PE..d....SP`.........." .................w....................................................`A............................................|...,|..@.......8.......(S......p ...........s.......................t..(...@s..8...............@............................text............................... ..`.rdata..n#.......$..................@..@.data....g.......`..................@....pdata..(S.......T...N..............@..@.rsrc...8...........................@..@.reloc..............................@..B........................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):213616
                                                    Entropy (8bit):6.3291256143397945
                                                    Encrypted:false
                                                    SSDEEP:6144:Dgts+NEpR1fHyWDAMEU3HDZbheCRoRnR1pTIW8qk6+dLEB:Dgts+NeiW0Am
                                                    MD5:A62E106A12A05CA341416528CE1AE4B2
                                                    SHA1:B1E80B9FF40BBF3F01FE76347ADF703576B36F22
                                                    SHA-256:DECD115B00BC46A1903AE6DE077C64C9FF9E68357488E52287C92F5FDEB49F3A
                                                    SHA-512:35172141DA3D1CB34CAC1D5E558A61B70D127153A130E6F4531D428423EC9E57D69CDD24C6A4AB5E9C3941EB317C87C3FCFC6D70873A903638C58FCF8C4EB558
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........$..E..E..E..=9.E..#4..E..#4..E..#4..E..#4..E...-..E...7..E..E..D...7..E...7..E...7U.E..E=.E...7..E..Rich.E..................PE..d....SP`.........." ................0........................................`......O.....`A...........................................`...0........@..X.... ..p...."..p ...P..l....V.......................X..(....W..8............0..P............................text............................... ..`.rdata..x....0......................@..@.data...@...........................@....pdata..p.... ......................@..@.rsrc...X....@......................@..@.reloc..l....P......................@..B................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):1922672
                                                    Entropy (8bit):6.354424752939712
                                                    Encrypted:false
                                                    SSDEEP:49152:ZNxzIPn14kNn+vnBOj+vMGIepOmURzW55AHRiUi:lcT+MGId8X
                                                    MD5:531916CA51D5A2DE5C3CC74AFC21BF55
                                                    SHA1:DE2CFCC1265D4AE99FF319E0FAE9EF3818D71AD0
                                                    SHA-256:3775957BC6A166F7EED945289CB35BBAAF75034EFD880CA908693F1F861DC77A
                                                    SHA-512:FB9DA2EC4AE594AC64010179A1F1C93CCB2A9C5C4003447846342E3CFD3750A82CCC129E78D54844E3D58F0CFAD1131224B11E22A6762067926FDBD774711825
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......D......H...H...H../H...H...I...H...I...H...I...H...I...H[..I...H...I...H...H...H...IH..H...I...H..CH...H..+H...H...I...HRich...H................PE..d....SP`.........." .........H......p...............................................~.....`A............................................L...\I.......0..@...........6..p ...@..h2..`g.......................i..(....g..8...............8............................text...[........................... ..`.rdata...].......^..................@..@.data...h....p.......T..............@....pdata..............V..............@..@.rsrc...@....0......................@..@.reloc..h2...@...4..................@..B................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):1052784
                                                    Entropy (8bit):6.423664023573067
                                                    Encrypted:false
                                                    SSDEEP:24576:RtyQdlecxVXU9YLSIqrz9Rrkm18S3ZZ8lCHTyGjzv4j3IyO8uDkr:YczIhHZzAj3IyO8uDkr
                                                    MD5:9B6139C1B83B71F50D8F5DF0EDE2B4CA
                                                    SHA1:C14CB548BD4C0DE9DF179A157429BF318E8334D0
                                                    SHA-256:97564EDDB36C2F757DAE31801D595567B7E31B3AE994772B685A1265A23A44DD
                                                    SHA-512:19166A7F736899DEBF96606EDA334077DE0C6821A643EA8828F27A6A5820F2D3C9220BF6F2C820AECF9948BE51509202A487CA4BDBD2B795B2794C1E6E52B5A4
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......4.p...p...p...y...v.......g.......x.......t.......v...+...r.......u...p...\.......].......q.......q...p.{.q.......q...Richp...................PE..d....SP`.........." .........................................................@...........`A.........................................$..\9...].................. U......p ... ..,...p...........................(.......8............0..h............................text...*........................... ..`.rdata.......0......................@..@.data....... ...|..................@....pdata.. U.......V...|..............@..@.rsrc...............................@..@.reloc..,.... ......................@..B................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):1929328
                                                    Entropy (8bit):6.355464318015867
                                                    Encrypted:false
                                                    SSDEEP:49152:5DWz2jsN39MyOCixenvti3cqyriu777eVN0U:vSzjU
                                                    MD5:696106879C72C62BB55909229063C3A1
                                                    SHA1:4A238F4368F83558B6B053C36D85C7EAB472A367
                                                    SHA-256:6E5A523C01902AE92FB34F342C6BCFB14D3E08908DEFB9DA9204B3B00B4A67EC
                                                    SHA-512:9168281DB95D5665891E0EAF7AA9F2C90260E6157D4AFC58DACCFD6EAF13FE85CEE8B4C811E0F4FE5B697066FFB0BD755E4A8B65459440A0BE003B56697FCEAA
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........=...\.,.\.,.\.,.$.,.\.,7-.-.\.,7-.-.\.,7-.-.\.,7-.-.\.,.4.-.\.,...-.\.,.\.,`X.,...-.\.,...-.\.,..B,.\.,.\*,.\.,...-.\.,Rich.\.,........PE..d....SP`.........." .........h.......9....................................................`A.........................................D..DH..D........P...............P..p ...`..86...C.......................E..(....C..8................&...........................text............................... ..`.rdata...C.......D..................@..@.data...PY...`...B...D..............@....pdata..............................@..@.rsrc........P......................@..@.reloc..86...`...8..................@..B........................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):27760
                                                    Entropy (8bit):6.101696861162379
                                                    Encrypted:false
                                                    SSDEEP:384:O/uMSQHLERO1LXwBgphIYidMI38JN77hhuI8:Gv/rERORAqp2Yi633h0X
                                                    MD5:ACDABE71943200265F649ECD2C7B82ED
                                                    SHA1:EF49DC1ADD15D3A7294AD20FD19C92175FD2EFEA
                                                    SHA-256:9689E8001ACF72C8EB31331A7605655F1FC8E2A7180D9279819D1D1F7EA1CA75
                                                    SHA-512:9261F25BE1F20BDC43BAC0530797E7E4A19172001785EBCFA57FE69CE719497507A190C4A9867B7B8954DA69D0011B982CDC0F6AB17BADE9F17970F2F830DB50
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........j...j...j...c...h......h...!..h......a......b......i...~..i...j.......~..k...~..k...~.u.k...j...k...~..k...Richj...........PE..d......e.........." ...$.....:...........................................................`A........................................`<.......E..d.......H....p.......L..p ......,....6..p...........................`5..@............0..0............................text............................... ..`.rdata...&...0...(..................@..@.data...8....`.......@..............@....pdata.......p.......B..............@..@.rsrc...H............D..............@..@.reloc..,............J..............@..B........................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):3484272
                                                    Entropy (8bit):6.4155021392564695
                                                    Encrypted:false
                                                    SSDEEP:49152:wcnzVnUoFwqWIQUQn+ljV20uLGghX/RlJCvRcfrWf9v6O2YrZdsfT7HbVb:rFwxDGR8OIT7x
                                                    MD5:8695199587806470E58249A5FCD2FFA8
                                                    SHA1:A94D1B00C9741A40A926C9CF2DD8A63C45F4FB32
                                                    SHA-256:1DB47C65656C7C4DB712E3371D7E0838C6D796766DAB9CED15D37E13C789EFF0
                                                    SHA-512:4A62E3890A2600E5AA74DEA272C8AF682FC103163630EF59790D53F6985D53A0A94B8D614C3CF286BB8990E84A308221DD0A74AF991B6E8F28419F2E03720625
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........e%...v...v...v..v...v<..w...v<..w...v<..w...v<..w...v...w...v...v...v...w...v...w...v...v...v...v...v...w...vRich...v........................PE..d......e.........." ...$.~(.........0.'......................................`5.......5...`A.........................................82..]...2.......5.P.....3. `....5.p ... 5..:.. +..p....................,..(....)..@.............(.@............................text....|(......~(................. ..`.rdata...)....(..*....(.............@..@.data...(.....2.......2.............@....pdata.. `....3..b...f3.............@..@.rsrc...P.....5.......4.............@..@.reloc...:... 5..<....4.............@..B................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                    Category:dropped
                                                    Size (bytes):3107952
                                                    Entropy (8bit):6.3789417618063995
                                                    Encrypted:false
                                                    SSDEEP:49152:YnjmqpNPSR0Wt1cOdCGswrTvzHWHiNyFX3A6KMJd05FXDDXu:Yjpbwb1XQmw3
                                                    MD5:DD41E5F8819CDF23E0D9DA02655B7B63
                                                    SHA1:43BC5A7E37576BE666E854A95304B4F3CEB7E821
                                                    SHA-256:977A13D5E5A2F9FDE3958E6110E4D180F04CAAA51994A03C34D98668B5421A3F
                                                    SHA-512:8C8022A72A0A50CD300C4EBE431B5FFEC52B7548DB6BB97D9492C148A513898926601351C99204E15FE10226AD9CCC123A72A56FB683E3806E692838A8D3B29A
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."......&..H/..H..0..........m............................. 0......./...`... ......................................./......./.......0........../...L/.p ....0.............................@v..(...................../..............................text...(.&.......&.................`.P`.data....(....&..*....&.............@.`..rdata.......'.......&.............@.p@.buildid5...........................@.0@.pdata.../.......0..................@.0@.xdata...g..../..h..................@.0@.bss....@F...p/.......................`..edata......../......./.............@.0@.idata......../......0/.............@.0..CRT....X...../......8/.............@.@..tls........../......:/.............@.@..rsrc.........0......</.............@.0..reloc........0......@/.............@.0B........................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                    Category:dropped
                                                    Size (bytes):31344
                                                    Entropy (8bit):6.092541836096473
                                                    Encrypted:false
                                                    SSDEEP:768:U5cNO2CvUAjOAVJJemR9xtqj+YiUg3h8N:hNPAjOAn9Sj+7t3h8N
                                                    MD5:81672B0D87D22E2175D4DAFBD514FE3A
                                                    SHA1:5AEE61CBD150098CBFE81FB5854F023A18B87083
                                                    SHA-256:EC5EBE7FA42BAC2027FC53E969B6C03CF4D04AB3CE1A226F886062C928AD5AEE
                                                    SHA-512:CA67A528D4792261B53F5ED9C9CDA7E9FF00763E80ED3C5799639B0B3A36D65B12ADE53CD3E14A9FF21F3B7B0DC21A2C9C20EC66D9127A2E3D4CAA79FBEF0960
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".....2...V......0.........hi.....................................K....`... .................................................................$....Z..p ......d....p......................``..(...................t...8............................text....1.......2..................`.P`.data........P.......6..............@.P..rdata.......`.......8..............@.`@.buildid5....p.......<..............@.0@.pdata..$............>..............@.0@.xdata...............B..............@.0@.bss.... .............................`..edata...............F..............@.0@.idata...............J..............@.0..CRT....X............P..............@.@..tls.................R..............@.@..rsrc................T..............@.0..reloc..d............X..............@.0B........................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):3367024
                                                    Entropy (8bit):6.104544795068781
                                                    Encrypted:false
                                                    SSDEEP:49152:oVwASOkIU6icGtlqJf3YwSp6wihilsB8vSHv+COsNP9KzS+Asshq1CPwDv3uFh0e:S+3wKih81Ch3+AsT1CPwDv3uFh0e
                                                    MD5:9B20085515967B09AD1B165AE3A654A6
                                                    SHA1:EDDDAD4C8BF03FBE52B68F7573BE5ABC94D074F2
                                                    SHA-256:C7C64EE6BEEE4B557F1CC6D5160F334323A30AC8A94EA5C8E89FAB7FEA8AEC78
                                                    SHA-512:255A09377A1BE33AFB9EE03D7E6C47BA92D7A1A52CBDB1AA7C70134C6895CAC1FA43D14E0A72A1B22D9BF90FB20E97241ECF818703E750221F370B7C10622BA9
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........6.c.W.0.W.0.W.0./70.W.0[&.1.W.0[&.1.W.0[&.1.W.0[&.1.W.0.<.1.W.0.W.0{W.0.W.0.W.0r%.1.U.0r%.1.W.0r%[0.W.0r%.1.W.0Rich.W.0........................PE..d......e.........." ......#...................................................3.......3...`.........................................@S..jg....3.@....P3.|....P1......@3.p ...`3..P..,.+.8...........................p.+.8.............3..............................text...T.#.......#................. ..`.rdata........#.......#.............@..@.data...!.....0..:....0.............@....pdata..p....P1.......0.............@..@.idata..8#....3..$....2.............@..@.00cfg..Q....@3.......2.............@..@.rsrc...|....P3.......2.............@..@.reloc..zx...`3..z....2.............@..B................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):799344
                                                    Entropy (8bit):5.765135808873752
                                                    Encrypted:false
                                                    SSDEEP:12288:vYL4jEQRnG2bCxK9Xwy/QJfWCW6e0C1xkp:QL4jfRnNbCxKBwy/WfWCk/0
                                                    MD5:41C70F9B61D383180BE1D14A49E188DD
                                                    SHA1:D18805CCE3C0437346495EECB4F1266CDD195137
                                                    SHA-256:9E6E4F2C27A596B84BF895247C664660F2C562AF4623D8B33A743A6CFED472A3
                                                    SHA-512:D0DEFFECD23232189B816AA9DB5697AFC8A30CCD1FE8E73EC0238133A65E7774FFBA21E87D0002534C4FE293C1A18ABBD86FB57E60CE1598EF730ED7D00E2EEB
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......(...lnr.lnr.lnr.e...~nr.>.s.nnr....dnr.>.w.`nr.>.v.dnr.>.q.onr...s.hnr...s.gnr.lns..or...v..nr...r.mnr.....mnr...p.mnr.Richlnr.........................PE..d...p.ve.........." .....8..........Z........................................p.......i....`..........................................5..;.......h....P.......p...e......p ...`.......j..8...........................@j...............................................text...'6.......8.................. ..`.rdata..K....P.......<..............@..@.data........P......................@....pdata..@q...p...r...:..............@..@.idata...K.......L..................@..@.00cfg.......@......................@..@.rsrc........P......................@..@.reloc.......`......................@..B........................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                                                    Category:dropped
                                                    Size (bytes):1776240
                                                    Entropy (8bit):6.806314500199087
                                                    Encrypted:false
                                                    SSDEEP:24576:c3QKOPvlB4i59oKI32AHEgMH7t8tB7t5+WjNTxvLlz7iomAaV3Y:WkPdgHggMH7k5+WHvLkAaV3Y
                                                    MD5:A6D1AA4D022A343A1E673262DF6C8234
                                                    SHA1:412B33C49377459C7D4D57487B5741D5244E34DB
                                                    SHA-256:1B046D1EC40F4D2F25D536AF518AED8E616342A01356CF23391894B4AC59160B
                                                    SHA-512:CCF8D9E80F0092B0442D1B30B5B94BC37400E40D6905F6F11DCBD9C86E5556CCF59AFF5479F43CEB43A754A4D8FABEE380A3D5A09BD741B5455A96E4B57A0175
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".............J..0......... h..........................................`... ......................................`..j....p..........H.......H*......p ......@...............................(....................r..p............................text...............................`.P`.data... ....0....... ..............@.`..rdata..0Z...@...\...*..............@.p@.buildid5...........................@.0@.pdata..H*.......,..................@.0@.xdata..h+.......,..................@.0@.bss.....I............................p..edata..j....`......................@.0@.idata.......p......................@.0..CRT....X...........................@.@..tls................................@.@..rsrc...H...........................@.0..reloc..@...........................@.0B........................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):500848
                                                    Entropy (8bit):5.7275364420259605
                                                    Encrypted:false
                                                    SSDEEP:6144:5es3tS2fqB+epxfLWkp8kGWHwusHCg01NVvMpYzwSLIZyOnreqX8YmxoF2:ZlBQQHCgGNVvM+NcQOrefX9
                                                    MD5:D1D78616644C3E839996447677500B72
                                                    SHA1:AA8443DAC46935ED49FC8FE72225BC6C1F562BF5
                                                    SHA-256:B99355C54856D7B373219AC863E438ECA1BEE5602AFAD0A9968205A8B5C4B476
                                                    SHA-512:E27BAFC30221803F11B9CFBEAC65621E7D59B74B61E9CF621C6A7CEB0C8633C823DCC4A0387878617678046A489779F194C79D48F4D02BAD820FA792D0FF95D0
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........6...e...e...e.De...e...d...e...d...e...d...e...d...e...d...e...d...e...e...e...d...e..(e...e..@e...e...d...eRich...e........................PE..d...SG(f.........." .........,...............................................0............`.............................................CC........... ..........(&......p ... ......4...8...........................p...8............................................text.............................. ..`.rdata..CV.......X..................@..@.data...)....0... ..................@....pdata.. +.......,...<..............@..@.idata...............h..............@..@.00cfg..Q............|..............@..@.rsrc........ .......~..............@..@.reloc....... .......x..............@..B................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):686704
                                                    Entropy (8bit):5.554379233600809
                                                    Encrypted:false
                                                    SSDEEP:12288:TCZsbRk0crCRnHPQpuOfWrCktqO2mo4GP7fSROnuVAPd1m3e7NUIah:TXcEQpuOhKROnEi1mu7NUIah
                                                    MD5:95CC516C62DD8A98D7C1A70B3C086734
                                                    SHA1:23E2297D80F2515CC7C1B5AA2106C3DB85625318
                                                    SHA-256:686D8193EEA627BDE2396311292D168BA9AEDC42F3D9CBFB748CF1618F0327A1
                                                    SHA-512:1C12B2404D510D57676F35433F0093F6F1A88F238AB92732436322685362DAEEE01E9B681A3C210A520C7494FF609C0CDF84068220D1C25D186226BD41C5863A
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........%2..Ka..Ka..Ka...a..Ka..J`..Ka..J`..Ka..N`..Ka..O`..Ka..H`..Ka:.J`..Ka..JaG.Ka:.O`..Ka:.K`..Ka:.a..Ka:.I`..KaRich..Ka........PE..d......e.........." .....P..........<.....................................................`.........................................@#...N..`%..........s........M...Z..p ..........d...8...............................8...............`............................text....O.......P.................. ..`.rdata..:....`.......T..............@..@.data...1(....... ...h..............@....pdata...U.......V..................@..@.idata...W.......X..................@..@.00cfg..Q....p.......6..............@..@.rsrc...s............8..............@..@.reloc...............@..............@..B................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):1217136
                                                    Entropy (8bit):6.509499743176522
                                                    Encrypted:false
                                                    SSDEEP:24576:5nQnJE9Y+GFauTZEsZzQNtH9KMLs0izyDZ:5QJ7+HoqseNtH9KMLs5QZ
                                                    MD5:B9A377BB119FFD0BC9BB56A88162C9AD
                                                    SHA1:C4EB8C63DC6B24CC55D18EA5185E6669C265D6D7
                                                    SHA-256:A6341781E6A367FDC9BAEC7F698B5B07155B82761E7A11EE585B471342B3C0F1
                                                    SHA-512:FC4DF5DA9BB10E2B71065571A4774290B963B09B79AA40E6BB7929DB1739781A1E08ABF788527CDF22972FD04B0CD3604EDB4918317F86A650254596713FF79B
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......w...3..3..3..:...'..a...1..nP.6..a...8..a...;..a...0..V...6..3..K...........2...h.2..3...2.....2..Rich3..........................PE..d......e.........." .....(...\.......1....................................................`.........................................@...8...x...........x............r..p ......p...0...............................P................@...............................text....'.......(.................. ..`.rdata...M...@...N...,..............@..@.data................z..............@....pdata..............................@..@.rsrc...x............P..............@..@.reloc..p............V..............@..B........................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):658032
                                                    Entropy (8bit):6.208489247736754
                                                    Encrypted:false
                                                    SSDEEP:12288:EMq2VlnqK+QznoclDAdIJ2fVsnMwvWej0B5ASCTWk+48Y/IEWDDoBRMWnX/CJ8ER:FD1ZmdIkfVFej0BaWk+48Y/IEWDDoBR4
                                                    MD5:A2D65BB9296883A9F59FA2AFB7853C0F
                                                    SHA1:4D21C6A2FE5A4FA366399FD0BFAC114A2E58E898
                                                    SHA-256:0F8AFDBFF0371F81441BF7EE1F38C408E59D2594E538816956F5B2541DD8B7DC
                                                    SHA-512:67144E75A1AE85353A35D933BE0D3F04C1FB21D08922B1BACF7E7B9220473A098B833CFE880870129B429FCAE50957C6F8EEAB54228ED81855F3D3ED4FE0DA3D
                                                    Malicious:false
                                                    Preview:MZ......................@...................................8...........!..L.!This program cannot be run in DOS mode....$............pn..pn..pn......pn...j..pn......pn...k..pn...j..pn...m..pn...o..pn...k..pn...h..pn...o..pn.'.j..pn.'.o..pn..po..pn.'.g..pn.'.n..pn.'....pn..p...pn.'.l..pn.Rich.pn.................PE..d....K(f.........." .........n......0........................................0......w.....`.........................................`...`.......T................T......p ... ..h..............................(...`...8............................................text...0........................... ..`.rdata...3.......4..................@..@.data...(...........................@....pdata...T.......V..................@..@.rsrc...............................@..@.reloc..h.... ......................@..B........................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):313968
                                                    Entropy (8bit):6.150455571338784
                                                    Encrypted:false
                                                    SSDEEP:6144:fXebtJqgYVnhDqvF1KrdnPb/ZiOiIvtM+:mncnhD7r
                                                    MD5:EDD0B52FE36ECA8A89162DF64905EC3F
                                                    SHA1:2BABCFAAF45CE82027CDACFD1CD310058836F02F
                                                    SHA-256:9DB3157D9C3BA8346DE50D8F9D2442EB41B228059C9BB1D34F4052F80D9D8BE9
                                                    SHA-512:F806802FD3551553B6BF6D45C7883DCB4B938B288B4ADB32E1DB6DFEF72CE270525F8DC753F97D1B79CDDCD75FA1D8AA0396501A7169EF82F94A9ECA23E7A986
                                                    Malicious:false
                                                    Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$..............U...U...U..aU...U...T...U...T...U...T...U...T...U...T...U..T...U..T...U..T...U...U%..U...T...U...T...U...U...U...T...URich...U........................PE..d......e.........." ...$............................................................d-....`A........................................@...x...............H...............p ..........PK..p....................L..(....J..@............................................text...K........................... ..`.rdata...p.......r..................@..@.data....?...P...8...2..............@....pdata...........0...j..............@..@.qtmetad............................@..P.rsrc...H...........................@..@.reloc..............................@..B........................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):71280
                                                    Entropy (8bit):5.960646941305628
                                                    Encrypted:false
                                                    SSDEEP:1536:+ra1k+m8SYKB/zD+0onZqwULnJm37J3hEi:8Y9PUzD+0okLnJqYi
                                                    MD5:F442587F8DB5BDB7199CDB65B7ACFF98
                                                    SHA1:081229B4AF6116E4EE34E4A7598A5A0E649F64FB
                                                    SHA-256:134F1B07E53173D995069B279BF11693FE173A4043CE7EF96181CFC3204E169F
                                                    SHA-512:5846D4669603E6FF851E918AA21D34DD465CB9CC03F2B502F7606B74B228C24C1319957D98E4C6DB5287A6381EBD2C0FEE7CB21203330F7585F484346DC33673
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......zI.l>(.?>(.?>(.?7Pe?:(.?.V.><(.?uP.><(.?.V.>6(.?.V.>=(.?.V.>+(.?*W.>;(.?>(.?3).?*W.>.(.?*W.>?(.?*W.??(.?*W.>?(.?Rich>(.?........PE..d.....e.........." ...$.f..........`k.......................................P......L.....`A.........................................................0..X.......(.......p ...@..,...0...p.......................(......@............................................text....e.......f.................. ..`.rdata...h.......j...j..............@..@.data...P...........................@....pdata..(...........................@..@.qtmetad..... ......................@..P.rsrc...X....0......................@..@.reloc..,....@......................@..B........................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):220272
                                                    Entropy (8bit):6.049927449820837
                                                    Encrypted:false
                                                    SSDEEP:6144:Vf/GxYUAxjfOG7vXqOLW25kydlLbKG0q4:VfOW1x79j5Kz
                                                    MD5:39990D8A2447400B0F20345D9939C639
                                                    SHA1:549A356BA62F789FB9FA3A87F5D55BAC3CE5029A
                                                    SHA-256:33C50B45EAA3E790CF93F718FBECA95D44D92026189A527C2F3974510E94A412
                                                    SHA-512:893F5A3BA354FD6C49BDAFBE021D14261C24D40BAD856F7926B4B6E27A2FE88B3247ED81D5D3CB0234BD9A707DD2D955C42EB502DA39E8AD4C9D993CF894CA0C
                                                    Malicious:false
                                                    Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$............p...p...p.......p..u....p..u....p..u....p..u....p.......p.......p.......p.......p...p...r.......p.......p....r..p.......p..Rich.p..........................PE..d......e.........." ...$.....t............................................................`A........................................0...x...............H....@... ...<..p ...........;..p....................<..(...`:..@...............x............................text...k........................... ..`.rdata..............................@..@.data...80.......*..................@....pdata... ...@..."..................@..@.qtmetad.....p......................@..P.rsrc...H............0..............@..@.reloc...............4..............@..B........................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):4034672
                                                    Entropy (8bit):6.513054772456626
                                                    Encrypted:false
                                                    SSDEEP:49152:Sl+aqx+6K7MPhYnoU7QEVDwuMOeZqQgsKCJz2UNfvXAX3yHyzE3CanZUGt+k9yQf:LNWQt1HWX3OyzE3CanZUGt+k9yQ4T8b
                                                    MD5:AEBEB90A4703524AB7DB00023C33AADC
                                                    SHA1:C6FD439BF011485A6C0B650E91D529C43E065A0A
                                                    SHA-256:A728D03366C3ED1F21C35B06E445B14BF10D186DE70178F63185A1D74BCF32F1
                                                    SHA-512:EEC1B844CE058F22A25D075FC9B106072389E5216F6B77094564B00510204F021A97C47CDA858B70BDADB8E84CC8FE2F388A30830B23F38B34BEE9F406488BAD
                                                    Malicious:false
                                                    Preview:MZ......................@...................................0...........!..L.!This program cannot be run in DOS mode....$........?T..^:..^:..^:..&...^:.+>..^:.+9..^:.+?..^:.+;..^:.^,;..^:.8<..^:..+;..^:.8;..^:..^;.G\:..+>..^:..+3.d^:..+:..^:..+...^:..^...^:..+8..^:.Rich.^:.........................PE..d....K(f.........." ......1..h......X(........................................=.......=...`...........................................:..`...8;.......=......`<.T....p=.p ....=.(-..0Y6......................[6.(....Y6.8............01.H............................text...g.1.......1................. ..`.rdata...q...01..r....1.............@..@.data........;.......;.............@....pdata..T....`<.......<.............@..@.rsrc.........=......<=.............@..@.reloc..(-....=......B=.............@..B................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):121968
                                                    Entropy (8bit):6.2859247664409095
                                                    Encrypted:false
                                                    SSDEEP:1536:SAY4s0Z3oIAhX20wT4+d0o76q7Hjo9WrssN34CckhixVrolYc7zt73hDM:SAY52o5ML6q70grss+nDxVrolYc3DM
                                                    MD5:735A37C79FDF8EE18C5D6753AE0C3255
                                                    SHA1:14FFA61153CDC04749415DB972A79F66FDC6C0BD
                                                    SHA-256:B6CAFAA7B31B1B3A43F3BD33DE846204E7341800D481DC77EE63FDAE0ECC6E68
                                                    SHA-512:370C0EF767DCEEB5F894273636D6C876B92264CE46E7F2A4AB0FB8C93271D640F98F547F1114C16CFFEE66BB79BC40CEAD201B8E155E1C3F1AFC57DD7F33013C
                                                    Malicious:false
                                                    Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.........4o.Z<.Z<.Z<...<.Z<.._=.Z<..^=.Z<..Y=.Z<..[=.Z<..[=.Z< .[=.Z<.[<..Z< .^=.Z< ._=.Z< .Z=.Z< .<.Z<..<.Z< .X=.Z<Rich.Z<........................PE..d...YG(f.........." .....*...........&..............................................1.....`.............................................T...............................p ..........0T..p....................V..(....T..8............@...............................text....(.......*.................. ..`.rdata..2k...@...l..................@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):574376
                                                    Entropy (8bit):6.485665168975364
                                                    Encrypted:false
                                                    SSDEEP:12288:MTTBM491b1Sh9uDwHnSy2aUXmQ1ZedTpjYU3q1zk7b4u5OQEKZm+jWodEEVkky6:MTZo3qedOQEKZm+jWodEEyI
                                                    MD5:850CDE246823EA9425FB2DF6E6DB576C
                                                    SHA1:77C2867CCFF909FE2F32A7783573F216C8EEDBF1
                                                    SHA-256:4C1B47B146BC5A1B109010CF998B98138DB864C9803FE2DB88D8C6224C01E0E8
                                                    SHA-512:CA55B817C61D250530B4D9A3434621B58536597F88805CA75ECA7EE8BD22CDEA16376680E1104F4F3D8280ED1CC71C69BED127062D3CC6BFDBF1535346CE594F
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......8...|.|.|.....~.u.:.j.|.......y.....t.....x...........}...V.}.....}.Rich|.........PE..d...x+ ..........." .....T...b......p=..............................................//....`A.........................................X..h...(3..,............... :.......'......8.......p...........................@...@............p...............................text...LR.......T.................. ..`.rdata.......p.......X..............@..@.data...P:...P.......4..............@....pdata.. :.......<...R..............@..@.rsrc...............................@..@.reloc..8...........................@..B................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):25512
                                                    Entropy (8bit):6.058650209537277
                                                    Encrypted:false
                                                    SSDEEP:384:I0APP579DmmR3r0FYkWci5gWLjyHRN7xj05seyR9zSG:I0Ci83r06rluxj05sN9zn
                                                    MD5:1CC2E2308B129D74D1526A7BF1550BE7
                                                    SHA1:8AE06DA0B5205F6954D0FD15BA2ACDE4D0271C8A
                                                    SHA-256:E8BD5485C42EC72905E5BE2251A4A13A9D3270573F04A616860E22D57171EF3D
                                                    SHA-512:E4AF03449AC4D6DDCF92D9493C4DCA42235693633ECC7D3FCE23AC5333BE18F0316B104C514043E04BAABFF07A34F6FC45CFA60FB5CCCD2264E632BF925B336F
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......,.D.h.*.h.*.h.*..+.j.*.a...l.*.....o.*...).j.*.h.+.B.*...+.m.*.../.|.*...*.i.*.....i.*...(.i.*.Richh.*.........PE..d..... R.........." .........&......................................................I.....`A.........................................@..L...LA..x....p.......`.......<...'...........4..p...........................`3..@............0..8............................text............................... ..`.rdata..B....0......................@..@.data........P......................@....pdata.......`.......2..............@..@.rsrc........p.......6..............@..@.reloc...............:..............@..B................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):188840
                                                    Entropy (8bit):6.537636311564906
                                                    Encrypted:false
                                                    SSDEEP:3072:OKnGMQu9Dv6zWLF8IKgTimIZklx6nCIc+osZrfS52PTTEtTjQyvvy:OwMWLFjOmI4vtAyy
                                                    MD5:A8E0168A3DC8FA84BB115A1EBD72663A
                                                    SHA1:66D553F30C6E0ABCBA638A5B5DCAE71B07C4AEA7
                                                    SHA-256:B41C89C5B4EA74BAE901988B3A0ED3F3423FF79826CED287C7434C6A7BCE02DC
                                                    SHA-512:C188818C6B96796CAA8212B0158DB96AAEBA90393D1AD4172A0176A4F8572526C7670B5A5B86871A71D1F92C192AFEAE9BDF8EEA4129B2A0A229BF2804868FD7
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........7..jd..jd..jdQ.ke..jd...d..jd.ne..jd.ie..jd..kd..jd.ke..jd.oe..jd.je..jd.d..jd.he..jdRich..jd........................PE..d...Z"............" ................0.....................................................`A................................................h............................'...........]..p............................[..@...............P............................text............................... ..`.rdata..F...........................@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):57256
                                                    Entropy (8bit):5.185557265020722
                                                    Encrypted:false
                                                    SSDEEP:768:bHJ4iJtoSxySinHWex2X2QLcz4unj05sN9zm:trZKHxx2X2QLcz4unQyvzm
                                                    MD5:22F97C58C9636D4ABBED76BF9C6EB566
                                                    SHA1:AAF6E36D3D7209FEFF906AB5D0A8499ED7DD2059
                                                    SHA-256:C372CF464772D3BC9B86C61FD8D03BD465154DD56BA0D1BA109DCFF7C1B2C08E
                                                    SHA-512:081E388BC7664B944650A3872979B4F25A3110AAE6052441D6B56618C5BD203321539473BE637A2A0CE3FBD256AE2D12B5FF9FFC23156BD7A3EC81E7FAF79BC7
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........[...:..:..:.)H..:..BI..:..B..:..B..:..:..:..B..:..B..:..B..:..B%..:..B..:.Rich.:.................PE..d...A.`..........." .....:...........>.......................................@......g.....`A........................................Pf..D....k....... ..........P........'...0..|...pX..p...........................0W..@............P..H............................text...~9.......:.................. ..`.rdata...$...P...&...>..............@..@.data...........B...d..............@....pdata..P...........................@..@.rsrc........ ......................@..@.reloc..|....0......................@..B........................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):21416
                                                    Entropy (8bit):6.2867941280258215
                                                    Encrypted:false
                                                    SSDEEP:384:NvtXaQUBvtWiYEWFyHRN7wj05seyR9zSw:NIQlTuwj05sN9zd
                                                    MD5:42710657AD4806D101F986CE12F2FE39
                                                    SHA1:C0D4906A40F776FDD83F986DCC69B47576604B24
                                                    SHA-256:D40D4816E58D5DB7E387499B72FF8B933E29A2EC02D682EC30A90FF9A93980B3
                                                    SHA-512:51B0D38310FBE1D76FB231BCC9D3904D0D8B228DAC61BE9F8B4A545DBA4F1DBB5ECD96D26504866EDBD05C43C9C8412D11297866B41BF0D8AA0ADD7807D85E35
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........)...z...z...zV.{...z...z...z..{...z...z...z..{...z..{...z..{...z..{...z..zz...z..{...zRich...z........................PE..d...r..4.........." ................P........................................p......`.....`A.........................................(..0....)..P....P.......@.......,...'...`..,...."..p............................!..@............ ...............................text............................... ..`.rdata..R.... ......................@..@.data........0....... ..............@....pdata.......@......."..............@..@.rsrc........P.......$..............@..@.reloc..,....`.......*..............@..B................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):4457072
                                                    Entropy (8bit):6.566908468928723
                                                    Encrypted:false
                                                    SSDEEP:49152:ltcmlkSGD1chmvUhyXpOo/3Zcm2JVxBMtdyrjCuxrHIw0L637Nk7h77JIfa+uOdE:ISB1OP7pgu
                                                    MD5:FF276DB9F10993DF77F9074462F23CD6
                                                    SHA1:0D7ED96D5A0FE2CDD36DFD7665280131CE203759
                                                    SHA-256:421C655614DB4B65C26539C5555505F0EAD27DD58B2B8BCF262887C1EC7B32E8
                                                    SHA-512:9317C3D0C8B9B928C95EEA202979CB2B1E5437C720931EFBF160022F7BB833D1D5750166E424F8B0BE9FD4D3B361C073BE27147D69761AAC4789DEE88F1739AB
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Z.A.../.../.../....../..+.../..,.../..*.../....../.E...../....../..*.../../.../....../......./..-.../.Rich../.................PE..d....SP`.........." .....&0..4................................................D......HD...`A..........................................8.....8.@......PD.......B..B....C.p ...`D..M....3.......................3.(....3.8............@0..............................text...k$0......&0................. ..`.rdata.......@0......*0.............@..@.data.........A..f....@.............@....pdata...B....B..D...HB.............@..@_RDATA..0....@D.......C.............@..@.rsrc........PD.......C.............@..@.reloc...M...`D..N....C.............@..B................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):1153648
                                                    Entropy (8bit):6.664709375609626
                                                    Encrypted:false
                                                    SSDEEP:24576:rB+SOOl3SJAAofiG4aJexokMVZbWE+Jkk9I0Xy:rBfOOtSJSXJyMV4E+JkWy
                                                    MD5:0A15299FEEC763079F5CE368EBD6353A
                                                    SHA1:3F4F4AFDDC6C97D3B28CF0A331C0CCDB2A2E0947
                                                    SHA-256:5FA45502F5D809B12BF017354E995898037640EF01CD7CF3B049528D53A74623
                                                    SHA-512:D5D08BAD1A92C9C9F035B7C524D2A376018CF7B28E98CF51A15AC7BD4E98211898267C31C49FEE77FA2989C3CC76249526F421AA7C78425A7E1EAA8B1A3DE11D
                                                    Malicious:false
                                                    Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......Y..j...9...9...9x..8...9x..8...9x..8...9x..8...9...9B..9O..8?..9O..8...9O..8...9...9...9...8D..9...8F..9...8...9...9...9...8...9Rich...9........................PE..d... J(f.........." .................%....................................................`.....................................................(............ ...w...z..p ..........P...T...............................8...............p............................text...:........................... ..`.rodata. ........................... ..`.rdata...5.......6..................@..@.data...............................@....pdata...w... ...x..................@..@_RDATA...............f..............@..@.rsrc................h..............@..@.reloc...............l..............@..B................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):1570928
                                                    Entropy (8bit):6.5628220301753935
                                                    Encrypted:false
                                                    SSDEEP:24576:umdKfMYhyeswIogYCtOteg6+y339rz3bfXgH+HwpZq0NcI:uV0Y4MNgYCtGZLy3trLUWw/cI
                                                    MD5:F9F2A6A71E066AB491EBCBC6116DC9CE
                                                    SHA1:0318A0AFDAD3615566985597B33FE1F4A7FE2D51
                                                    SHA-256:38AB95B80F90C3BB70A4E4B4CE16F91B573C15EA4B8DABECA5E4BD0CDEECEA38
                                                    SHA-512:14ABD5F8B673A849D4C595399665ED3CD023C2C82B6DC5AC7780A62151EA34891715E6B6EEA10FE2FE5E2B7897487DC752E6D4E30177E877D140C66774FE92E4
                                                    Malicious:false
                                                    Preview:MZ......................@...................................(...........!..L.!This program cannot be run in DOS mode....$.........D..r*.r*.r*....r*.=...r*.=./.r*.=...r*.=.).r*.=.+.r*.....r*...,.r*..+.r*...+.r*.r+..u*..#..r*..*.r*....r*..(.r*.Rich.r*.........................PE..d......e.........." ...$.^...........^.......................................@.......p....`A........................................PA..x....A..........H.... ..p.......p ... ..8.......p.......................(......@............p...4...........................text...O\.......^.................. ..`.rdata..Z'...p...(...b..............@..@.data...Xt.......L..................@....pdata..p.... ......................@..@.qtmetad............................@..P.rsrc...H...........................@..@.reloc..8.... ......................@..B................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):35952
                                                    Entropy (8bit):6.003592400493193
                                                    Encrypted:false
                                                    SSDEEP:768:5Z95FPOrsPWWoeMxJLPcoG8bQsfYiT73h0G:5bxO4M1G8ssf7T73h0G
                                                    MD5:602D3C150FC087489F6CEFE35C5A2E7E
                                                    SHA1:04F69B49FD0F96F484769F4AD047D780C41000BD
                                                    SHA-256:E047B060F09AB1D846ACE4DE50146EC2B7B68D4DE509A5B022100BC19ACC45BD
                                                    SHA-512:9A4EC1476C1A8038BDB5D0EA6EF73EF4E7C523E20E850E253503B65AD09C1FDB60FA320297FCDD542191A15F62241512556AA89B93EA9BF7717B2742202D3377
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........x...+...+...+..4+...+/.*...+..*...+/.*...+/.*...+/.*...+..*...+...+...+..*...+..*...+..X+...+..*...+Rich...+................PE..d......e.........." ...$.$...J.......)....................................................`A.........................................\.......\..........X............l..p ..........0K..p....................L..(....I..@............@..`............................text....#.......$.................. ..`.rdata...3...@...4...(..............@..@.data................\..............@....pdata...............`..............@..@.qtmetadZ............d..............@..P.rsrc...X............f..............@..@.reloc...............j..............@..B................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):689
                                                    Entropy (8bit):4.604810595503562
                                                    Encrypted:false
                                                    SSDEEP:12:Cyg7rFMBO//+dNg74MAO//+dNg7ilZBO//+dNg7ifDO//+dNg72TSO//+dNg77qT:EyBOr4MAOrilbOribOr4SOr7qO9iBlOW
                                                    MD5:527C129D471203B12EA2ED836A7F2EDC
                                                    SHA1:C5E24C42B76091CFFE2453A340D2DBDD0D22E6C4
                                                    SHA-256:ACBA15175ABFFF94E7E9973944197B904BF2C31932F2C34E7A681C24BEAF41C0
                                                    SHA-512:3984BA47AD89051F6B3822DF4B9627E6CB98FDCE68F10BE14E68B1B6C6B55B67B02AAA9393F93DFB2F4805B6145F85AA21B87C721923D83A805B25F9C28E9DE1
                                                    Malicious:false
                                                    Preview:<ie>.. <plugins>.. <plugin name="GNA" location="GNAPlugin.dll">.. </plugin>.. <plugin name="HETERO" location="HeteroPlugin.dll">.. </plugin>.. <plugin name="CPU" location="MKLDNNPlugin.dll">.. </plugin>.. <plugin name="MULTI" location="MultiDevicePlugin.dll">.. </plugin>.. <plugin name="GPU" location="clDNNPlugin.dll">.. </plugin>.. <plugin name="MYRIAD" location="myriadPlugin.dll">.. </plugin>....<plugin name="CPU_VINO2022" location="openvino_intel_cpu_plugin.dll">.. </plugin>....<plugin name="GPU_VINO_2" location="openvino_intel_gpu_plugin.dll">.. </plugin>.. </plugins>..</ie>
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):308336
                                                    Entropy (8bit):6.062402320935309
                                                    Encrypted:false
                                                    SSDEEP:6144:FVbt4hH6wxoCXv6XOZGsnM2xvM/pX0SvIIp5xAtVA4JBnLlSg4zi4rYJX8uwc3Nb:FI1zz2I24jLlegb
                                                    MD5:D62F3D99676A42282E15F7B4D2A77619
                                                    SHA1:936E3790F542A639495DFD7BCA6E3FEAFFBC073D
                                                    SHA-256:97D70CFFCB25A7DA2AA153EA0D8D1CAB77738F5D4C3C329A78D527A652F7F0A2
                                                    SHA-512:B6A48CBB7D287D10E54ADAF3828BB4C608CBDC9B2AA733324D7C9B5FE516B5E498BD31DC5D2523D9F20FB109EA8381C3CB8764F1711442AF3AEAD07AE14A3987
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............|..|..|.....|..'...|..'...|..'...|..'...|.....|......|..|..o~.....|.....|...h.|.....|..Rich.|..........PE..d.....e.........." ...$.z.......... ................................................Y....`A........................................0...|.......@................'......p ...........w..p....................x..(...Pv..@............................................text....y.......z.................. ..`.rdata...............~..............@..@.data........`.......H..............@....pdata...'.......(...`..............@..@.qtmetadc...........................@..P.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):1446512
                                                    Entropy (8bit):6.606286143194019
                                                    Encrypted:false
                                                    SSDEEP:24576:cGnyFaXjMn/I1gG47hl0aW+NFth0lhSMXlOQguK+kQ2hYg:cAyCemX47hl0aW+NW/gJz
                                                    MD5:52816403D029FF445CED61EEB77D4A34
                                                    SHA1:BE70607681A74508F3E1D953E28F93F0DD171F6C
                                                    SHA-256:CB989B24CABB580D2F1A4128DC231755744FA8230550E5C6ACB1B7D5883EB53C
                                                    SHA-512:693B571CBB646370DB110731475733A0AA67E27B4C55E4F19EFCFA55CE52AC289AEEB8E1D2263940454D0369E01CEFA9E81FB50FE83E0BFBBEEE33943056962E
                                                    Malicious:false
                                                    Preview:MZ......................@...................................8...........!..L.!This program cannot be run in DOS mode....$.......$...`.qG`.qG`.qGi..Gx.qG..wFa.qG..pFh.qG...Gd.qG..tFO.qG..uFh.qG..rFf.qG..pFb.qG..tFc.qGt.pFb.qGt.uFj.qG..pFu.qG`.pG..qG..uFd.qGt.xF..qGt.qFa.qGt..Ga.qG`..Ga.qGt.sFa.qGRich`.qG........PE..d...scCf.........." ...$.f...........G.......................................@......F.....`A............................................x...H...................8y......p ... ..........p.......................(.......@...............@............................text...md.......f.................. ..`.rdata...............j..............@..@.data...H....p...~...P..............@....pdata..8y.......z..................@..@.rsrc................H..............@..@.reloc....... ......................@..B........................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):20592
                                                    Entropy (8bit):6.205024908241025
                                                    Encrypted:false
                                                    SSDEEP:384:XPya6mGmsIHC6AnQxIYiIINAd8JN77hhs0:XP36m8YC6wHYiq63hO0
                                                    MD5:0DC11D4126996B709F26169FDF3A4E52
                                                    SHA1:52038D833D4DC28291595D0883D6F66136C342AB
                                                    SHA-256:D1F0597057365E50D838861927E49552EE19440CD1A665B7FA0D2231E47594F0
                                                    SHA-512:5D53571AD690677BEEF3CF840E7BB485FEC62D6DBCA28656A7DC5151F52F1D8836FE3516DF2B9BD17E0125E1FA05D92501CAAB71E6880FD4639C062EE370FD13
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......r9..6X..6X..6X..? H.4X..&..2X..&..=X..&..>X..&..5X...*..4X..W"..4X.."'..5X..6X...X.."'..5X.."'..7X.."'$.7X..6XL.7X.."'..7X..Rich6X..........PE..d....uCf.........." ...$....."...............................................p......(.....`A.........................................(..d...D)..x....P..H....@.......0..p ...`..,...0#..p............................!..@............ .. ............................text...H........................... ..`.rdata....... ......................@..@.data...@....0.......$..............@....pdata.......@.......&..............@..@.rsrc...H....P.......(..............@..@.reloc..,....`......................@..B................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):5306992
                                                    Entropy (8bit):6.520376176263169
                                                    Encrypted:false
                                                    SSDEEP:49152:ohpCrMniZIx3vF3b8Q4lAHSnfsQATO+1abfIZWCXy5tHfwTOYjJ5ziwQ:mNZiTfsQUPY2e
                                                    MD5:03A61ADF665EA8F1D404C52199F5FD3E
                                                    SHA1:16F04364F1165291B726C30204F509A242C71A72
                                                    SHA-256:152FCEB5B99C9F01715AD76C889E09FCCC1E6B939E559BD47B58F90C2531B725
                                                    SHA-512:08D14CAD27BB205B818DB19FDEF338E60AABB92A0B6CC320BD5865574AB9B0FBF4A9251FBA1CBE331303EA7E7E929570F7FBA9578CDA086F605317930D5C28F9
                                                    Malicious:false
                                                    Preview:MZ......................@...................................P...........!..L.!This program cannot be run in DOS mode....$.............{...{...{..f....{.)l}...{.^`z...{.^`....{.^`~...{.^`....{.^`x...{.mlz...{.Y}~...{..a....{.)l|...{.)l....{.)lz...{..az...{...z...{..ar...{..a{...{..a....{.......{..ay...{.Rich..{.........................PE..d....cCf.........." ...$..1... ..... b.......................................PR.....d.Q...`A.........................................ED.X....ED......0P.X.....N......P.p ....Q.4...p.:.p.....................:.(...0.:.@.............2. ............................text.....1.......1................. ..`.rdata........2.......2.............@..@.data.........D..z....D.............@....pdata.......N......&M.............@..@.rsrc...X....0P.......N.............@..@.reloc..4.....Q......VP.............@..B................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):22030448
                                                    Entropy (8bit):7.974205696228686
                                                    Encrypted:false
                                                    SSDEEP:393216:x3gZgAUKn6RfUvs72fAodwtzuwgtLck0yVROVoYHBBM/:NggArncaMTkVITBS
                                                    MD5:3437B563F89F0690321B41BCCBD57912
                                                    SHA1:D91B2E2CB84DD378204822ADB1D3360B34C2C83A
                                                    SHA-256:D69B05E0875365B633D2208FD411E03C3FE0B394391C30F93EE517416DD40D64
                                                    SHA-512:CE59D554A5070FC8018A0B7A82D1671D9E9DDD4BB26B7F4A7DBFB0FC80C7D7CDE4E65C51ED6C12939D5631A956A18BA4A1D77EB5C219CCD35919D346F77C93D5
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......W...............I.....................................................;.....................%.............Rich............................PE..d...4eCf.........." ...$......O..............................................`P.......P...`A..........................................P.......P.x....@P......0P.......P.p ...PP.@.....P.p...........................`.P.@............0..8............................text............................... ..`.rdata....O..0....O.................@..@.data...@.... P.......O.............@....pdata.......0P.......P.............@..@.rsrc........@P.......P.............@..@.reloc..@....PP.......P.............@..B................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):174191728
                                                    Entropy (8bit):6.574112253902268
                                                    Encrypted:false
                                                    SSDEEP:786432:FEYmEjtZ74nAkPWhdOmsr2Sq+5+4CtpgRdCy0+Ijk5ADyOlK8qFKY:F7jtZkn9WhdorZ+bHgRdCyiDyF8Gb
                                                    MD5:8CCF9ED3A2674B2F71256A4F26848C3B
                                                    SHA1:29A8EC2A5C6D775EFFA80356CE9C1A9F95249E3A
                                                    SHA-256:F5E58E4CDBDC09E022311636F867C35103020DDA9F2B3690C1EDACB4336FC4E4
                                                    SHA-512:7C67E2C3F1B304866ADBCF31CE36D1977A81DEBBF52C1A35C37685754B7F70B6C9546142E99633B5E1F670A09C9EC064482DA6130B18F27A30D1540BD8728C65
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........e.q.6.q.6.q.6..T6.q.6...7.q.6...7.q.6...7.q.6)..7.q.6...7.q.6.q.6.q.6Y..7.q.6N..7.q.6...7.q.6...6.q.6...6.q.6...7.q.6...7.q.6Y..7.q.6...7=q.6...7.q.6...7.q.6..:6.q.6Y..7.q.6Y..7.q.6Y..7.q.6.q.6bP.6...7=c.6...7.q.6..V6.q.6.q>6.q.6...7.q.6Rich.q.6................PE..d....sCf.........." ...$.....d:......{"..............................................b...`A.........................................vY.T.+....................../*...a.p ......d9..p.^.p.....................^.(... ...@............ ..0...xuY.`....................text............................... ..`.rdata..&.... ......................@..@.data.....&.......................@....pdata.../*......0*...).............@..@.didat..8.............S.............@....detourcp!......."....S.............@..@.detourd..............T.............@....rsrc.................T.............@..@.reloc..d9.......:....U.
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):5745776
                                                    Entropy (8bit):6.434252061219638
                                                    Encrypted:false
                                                    SSDEEP:49152:lk4JUrMGr06M4N2MuqwHh1Dv39W/UsH1MZYplMwCnzNadOiIF+I/nRM3XR4UrLr:6834ND/UsWrkt
                                                    MD5:6727A5D8007096769D0CED9DD4AE825A
                                                    SHA1:F51890BD31A5D75957DD8A9B400C985ECC613574
                                                    SHA-256:94702AB27233830E7D7F7089ACB3B4F5282A2A298E3635C03162D392CB86E3A6
                                                    SHA-512:5D57345A2D8F55D5342A567A4E0A8D829FE01F824FC2EDDCC216B81B060EED7E071488D8B7897CEC326B9930738A1F0E7C9B5A03883FCC43E414BA03B9B91D7F
                                                    Malicious:false
                                                    Preview:MZ......................@...................................H...........!..L.!This program cannot be run in DOS mode....$.........tx...+...+...+..+...+E..*...+2..*...+2..+...+2..*...+2..*...+2..*...+...*...+5..*...+...*...+R..*...+E..*...+...*...+E..*...+...+...+E..*...+...*...+...*...+...+...+...+...+...*...+Rich...+........PE..d....cCf.........." ...$..2...'.....P#-......................................`Z.....8.W...`A........................................@.J.\.....J.l.... X.......V.......W.p ....Y....P(B.p....................)B.(....'B.@.............2. ............................text...G.2.......2................. ..`.rdata..j)....2..*....2.............@..@.data.........J.......J.............@....pdata........V.......S.............@..@.rsrc........ X......NU.............@..@.reloc.......Y.......V.............@..B........................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):689
                                                    Entropy (8bit):4.604810595503562
                                                    Encrypted:false
                                                    SSDEEP:12:Cyg7rFMBO//+dNg74MAO//+dNg7ilZBO//+dNg7ifDO//+dNg72TSO//+dNg77qT:EyBOr4MAOrilbOribOr4SOr7qO9iBlOW
                                                    MD5:527C129D471203B12EA2ED836A7F2EDC
                                                    SHA1:C5E24C42B76091CFFE2453A340D2DBDD0D22E6C4
                                                    SHA-256:ACBA15175ABFFF94E7E9973944197B904BF2C31932F2C34E7A681C24BEAF41C0
                                                    SHA-512:3984BA47AD89051F6B3822DF4B9627E6CB98FDCE68F10BE14E68B1B6C6B55B67B02AAA9393F93DFB2F4805B6145F85AA21B87C721923D83A805B25F9C28E9DE1
                                                    Malicious:false
                                                    Preview:<ie>.. <plugins>.. <plugin name="GNA" location="GNAPlugin.dll">.. </plugin>.. <plugin name="HETERO" location="HeteroPlugin.dll">.. </plugin>.. <plugin name="CPU" location="MKLDNNPlugin.dll">.. </plugin>.. <plugin name="MULTI" location="MultiDevicePlugin.dll">.. </plugin>.. <plugin name="GPU" location="clDNNPlugin.dll">.. </plugin>.. <plugin name="MYRIAD" location="myriadPlugin.dll">.. </plugin>....<plugin name="CPU_VINO2022" location="openvino_intel_cpu_plugin.dll">.. </plugin>....<plugin name="GPU_VINO_2" location="openvino_intel_gpu_plugin.dll">.. </plugin>.. </plugins>..</ie>
                                                    Process:C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exe
                                                    File Type:very short file (no magic)
                                                    Category:dropped
                                                    Size (bytes):1
                                                    Entropy (8bit):0.0
                                                    Encrypted:false
                                                    SSDEEP:3:U:U
                                                    MD5:C4CA4238A0B923820DCC509A6F75849B
                                                    SHA1:356A192B7913B04C54574D18C28D46E6395428AB
                                                    SHA-256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B
                                                    SHA-512:4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A
                                                    Malicious:false
                                                    Preview:1
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):273
                                                    Entropy (8bit):5.21496681389986
                                                    Encrypted:false
                                                    SSDEEP:6:iDigLgXPrn96XYBei15A/ECgwDuCRZ4kcLKXRna60lka6XV:ihgj9JB/5A/NgwjRNBRna60lkaY
                                                    MD5:CF17DCD92443FFD7100345986AFB97B5
                                                    SHA1:455AF42171B5C4D9B00A17C5BEDEDFF6A32D6119
                                                    SHA-256:6605DBACF262534C21DE2B48F5D38B6282ED65332126DF64676483FC90F77AF7
                                                    SHA-512:1250DFCFAF9D69B8787E031692F1CB8267D35401007FA77C9377EDCC71038C6571C0337FDA6E0E580F60EC98894DC6F21595BE950780EB85F38D4F6EE6563424
                                                    Malicious:false
                                                    Preview:prefix=C:/Program Files (x86)/Project..exec_prefix=${prefix}..libdir=${exec_prefix}/lib..includedir=${prefix}/include....Name: tidy..Description: tidy - HTML syntax checker..URL: http://www.html-tidy.org..Version: 5.7.24..Libs: -L${libdir} -ltidy..Cflags: -I${includedir}..
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):2732656
                                                    Entropy (8bit):6.796196817967675
                                                    Encrypted:false
                                                    SSDEEP:49152:jGtlqYIU6iOVwASOOQFK0uigyFGHT9sbWj5x/VTEybcosxWhE6zY6EdPFbHcB:R+0F2R0W7/SZoYWU6Eng
                                                    MD5:D46B787A90104FA0B7BF8694F76D5C76
                                                    SHA1:34D275503E5000732EA71DA5BD5B3207053E3F5E
                                                    SHA-256:5A44D14A6435F04486621294EB59A5CB6853416A375D9567DF21F255E7C68A6A
                                                    SHA-512:BDBDF622ACE60B59468F00BE7DB5EC67A2F612D3CDC67C702E636FF28A6F007FC1F3F6FD45A9BB864A39E60D951AB8F5DCF32399211A6E723C97A9FEE290766D
                                                    Malicious:false
                                                    Preview:MZ......................@...................................0...........!..L.!This program cannot be run in DOS mode....$........]..<..<..<.EN..<.EN.S<.2B..<.2B..<.2B..<.EN..<.EN..<..<..<..N.I=..C..<.EN..<..<..=..C..<..C..<..C3..<..C..<.Rich.<.........................PE..d....dCf.........." ...$.....T...............................................0*.....L.*...`A..........................................'.\.....'.......).......(.......).p ....).$Z...6&.p....................7&.(...@5&.@............................................text............................... ..`.rdata..@9.......:..................@..@.data.........'..N....'.............@....pdata........(.......(.............@..@_RDATA..\.....)......2).............@..@.rsrc.........)......4).............@..@.reloc..$Z....)..\...6).............@..B........................................................................................................................................................
                                                    Process:C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe
                                                    File Type:Qt Translation file
                                                    Category:dropped
                                                    Size (bytes):2638678
                                                    Entropy (8bit):4.657527262457749
                                                    Encrypted:false
                                                    SSDEEP:49152:oywfU+56knWJunqLxdUsPVdlhY6nhyIomoXf10qOq+:V1pq0vn
                                                    MD5:1ADAF163476F946FE9F9DA0DA0D6AC61
                                                    SHA1:73F93857DD91688E00C80FA6D73E08F22695870A
                                                    SHA-256:4CD73550B9CD28F4EFE4791F97B72D8CF0176AACA837432918555AB00CD19ECA
                                                    SHA-512:A6A75FF070F4C635BC775360EDF756E4FFFE2DD8EDEB7232A168B521A9ADC38CBA64F27119551499CA8AC9E72A6A3F3F168AF5C8A46F70AED901E2635F3E77B5
                                                    Malicious:false
                                                    Preview:<.d....!..`.......en_USB..px......Q........C.............%J......%.....+..........L....0..|....1..o7...1..|....1...5...2..}....3..}....4..}....5..~#...6..~L...7..~u...8..~....9..~....A..@~...A... ...F.......M.......S.......T.......W..[....h...E...m...o...s.......x...a...x...L...|.................!.D... ..........<r......................q.............."J......".......#Y.......LU...............3....."!......%^y.....#-....@..}!...H..}|..............u........................................0.......\......................z#.......=.............s....5.......;../*...;..3....;..4....;..5....;..>....;..gc...;..h....;...;...;.. %...;..\....;..]N...;..w....;..Vu...;...K...;...9...;.......;...}...;..5....;..K....;.......;...o...;.......;..k....;...Z...;.......;.".j...;."....;.#Z....;.#.....;.$....;.%.....;.%....A......O.......O.......[.......[..h....[.......[.. R...[......[...r...[.".d...[.$.s...[.%.k...[.%.....^...X...^."@....h.......h..y........................r.........................
                                                    Process:C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe
                                                    File Type:Qt Translation file
                                                    Category:dropped
                                                    Size (bytes):2638678
                                                    Entropy (8bit):4.657527262457749
                                                    Encrypted:false
                                                    SSDEEP:49152:oywfU+56knWJunqLxdUsPVdlhY6nhyIomoXf10qOq+:V1pq0vn
                                                    MD5:1ADAF163476F946FE9F9DA0DA0D6AC61
                                                    SHA1:73F93857DD91688E00C80FA6D73E08F22695870A
                                                    SHA-256:4CD73550B9CD28F4EFE4791F97B72D8CF0176AACA837432918555AB00CD19ECA
                                                    SHA-512:A6A75FF070F4C635BC775360EDF756E4FFFE2DD8EDEB7232A168B521A9ADC38CBA64F27119551499CA8AC9E72A6A3F3F168AF5C8A46F70AED901E2635F3E77B5
                                                    Malicious:false
                                                    Preview:<.d....!..`.......en_USB..px......Q........C.............%J......%.....+..........L....0..|....1..o7...1..|....1...5...2..}....3..}....4..}....5..~#...6..~L...7..~u...8..~....9..~....A..@~...A... ...F.......M.......S.......T.......W..[....h...E...m...o...s.......x...a...x...L...|.................!.D... ..........<r......................q.............."J......".......#Y.......LU...............3....."!......%^y.....#-....@..}!...H..}|..............u........................................0.......\......................z#.......=.............s....5.......;../*...;..3....;..4....;..5....;..>....;..gc...;..h....;...;...;.. %...;..\....;..]N...;..w....;..Vu...;...K...;...9...;.......;...}...;..5....;..K....;.......;...o...;.......;..k....;...Z...;.......;.".j...;."....;.#Z....;.#.....;.$....;.%.....;.%....A......O.......O.......[.......[..h....[.......[.. R...[......[...r...[.".d...[.$.s...[.%.k...[.%.....^...X...^."@....h.......h..y........................r.........................
                                                    Process:C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe
                                                    File Type:data
                                                    Category:dropped
                                                    Size (bytes):2636
                                                    Entropy (8bit):3.777303630673483
                                                    Encrypted:false
                                                    SSDEEP:48:9AnC/oGRYIK9KAcHAFWZhkY6FD7sapRlDvPc9C/t7/C/xh0Bc:GnC9LeRWZhmJ/RlrkCV7/CZhr
                                                    MD5:8D90DD2E4583CD40DDC3280A94BF7AE7
                                                    SHA1:376A97EE6C55674AA20A844AC61440F531AEAD47
                                                    SHA-256:282C7EC59DA2A88B8604D3855E3E7396342D79ECFD3C56F1F55EC82CB4B57B5F
                                                    SHA-512:C4402FCB9D01456724E8322A2E080014EECB5AA659218A010F0C809EF11CC672DF910C5C2BAE601A51664B3A34EBD6ED9548186592C3181A8357522F3BB89722
                                                    Malicious:false
                                                    Preview:2.0.2.4.-.0.5.-.2.4. .0.9.:.3.1.:.3.4...3.7.2. .C.o.m.m.a.n.d. .l.i.n.e.:. .*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.\.C.i.s.c.o.S.p.a.r.k.L.a.u.n.c.h.e.r.\.C.i.s.c.o.C.o.l.l.a.b.H.o.s.t...e.x.e. .*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.\.C.i.s.c.o.S.p.a.r.k.L.a.u.n.c.h.e.r.\.4.4...5...0...2.9.6.7.2._.f.d.8.2.0.9.0.4.-.d.9.b.e.-.4.b.1.5.-.8.b.f.d.-.e.6.f.6.b.0.f.4.5.d.b.1. .s.p.a.r.k.-.w.i.n.d.o.w.s.-.a.p.p...d.l.l. ./.H.o.s.t.e.d.=.t.r.u.e. .*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.\.P.r.o.g.r.a.m.s.\.C.i.s.c.o. .S.p.a.r.k.\.C.i.s.c.o.C.o.l.l.a.b.H.o.s.t...e.x.e. ./.p.r.o.t.o.c.o.l.U.r.i.=.w.e.b.e.x.:././.m.e.e.t./.?.b.t.=.1.2.&.b.v.=.1.2.1.&.c.r.=.0.6.5.f.9.a.4.0.-.5.7.2.3.-.4.5.a.b.-.9.5.0.7.-.c.f.2.7.6.6.b.b.4.5.f.e.&.d.n.s.=.a.p.p.l.e.i.n.c...w.e.b.e.x...c.o.m.&.e.n.=.3.&.f.l.a.g.=.1.7.&.j.o.i.n.t.x.i.d.=.x.7.P.b.q.0.R.E.2.n.&.j.t.=.e.y.J.k.d.D.A.i.O.j.E.3.M.T.Y.1.N.D.g.2.N.D.I.s.I.m.R.0.M.S.I.6.N.z.k.4.L.C.J.k.d.D.I.i.O.j.I.x.O.D.U.s.
                                                    Process:C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exe
                                                    File Type:data
                                                    Category:dropped
                                                    Size (bytes):2378
                                                    Entropy (8bit):3.827257830741807
                                                    Encrypted:false
                                                    SSDEEP:48:wKIK9KAcHAFWZhkY6FD7sapRlDv2cP8T06MMG:4eRWZhmJ/Rl6S8T8B
                                                    MD5:D31844F86F99362818177A95118DB248
                                                    SHA1:8F612C197411F7C4FB86A2FCDDC526A7F983BF39
                                                    SHA-256:211F202D14DAA559D72EC87AFA75EFC5F90AE65322240EB8C6EB49534BFE16C3
                                                    SHA-512:82CE738C716C41FD0B74A8DB10329570F259982F9469FFD8C78B4580C55CD623283F24BF744298C4DEC71119FC0D0A16423C9DFD04FC3A193EBCAC12C246AC27
                                                    Malicious:false
                                                    Preview:2.0.2.4.-.0.5.-.2.4. .0.9.:.3.1.:.3.4...2.3.8. .C.o.m.m.a.n.d. .l.i.n.e.:. .*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.\.P.r.o.g.r.a.m.s.\.C.i.s.c.o. .S.p.a.r.k.\.C.i.s.c.o.C.o.l.l.a.b.H.o.s.t...e.x.e. ./.p.r.o.t.o.c.o.l.U.r.i.=.w.e.b.e.x.:././.m.e.e.t./.?.b.t.=.1.2.&.b.v.=.1.2.1.&.c.r.=.0.6.5.f.9.a.4.0.-.5.7.2.3.-.4.5.a.b.-.9.5.0.7.-.c.f.2.7.6.6.b.b.4.5.f.e.&.d.n.s.=.a.p.p.l.e.i.n.c...w.e.b.e.x...c.o.m.&.e.n.=.3.&.f.l.a.g.=.1.7.&.j.o.i.n.t.x.i.d.=.x.7.P.b.q.0.R.E.2.n.&.j.t.=.e.y.J.k.d.D.A.i.O.j.E.3.M.T.Y.1.N.D.g.2.N.D.I.s.I.m.R.0.M.S.I.6.N.z.k.4.L.C.J.k.d.D.I.i.O.j.I.x.O.D.U.s.I.m.R.0.M.y.I.6.M.z.U.z.N.S.w.i.Z.H.Q.0.I.j.o.y.N.D.E.y.O.D.M.s.I.m.R.0.N.S.I.6.M.z.c.x.O.D.I.4.N.T.U.x.L.C.J.k.d.D.Y.i.O.j.E.3.M.T.Y.5.M.j.A.3.M.j.E.s.I.m.Z.0.I.j.o.x.L.C.J.0.I.j.o.y.N.S.w.i.d.X.A.i.O.j.F.9.&.m.t.i.d.=.m.5.4.7.a.8.0.8.d.c.e.8.d.2.d.3.d.8.9.3.e.2.0.f.a.7.9.4.c.b.8.a.1.&.o.d.=.6.f.7.8.3.f.7.3.-.9.6.3.7.-.4.b.8.3.-.9.0.b.9.-.4.3.4.a.5.f.c.c.b.4.9.d.&.r.c.=.4.&.s.i.p.=.2.4.8.7.7.8.0.2.
                                                    Process:C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe
                                                    File Type:data
                                                    Category:dropped
                                                    Size (bytes):204
                                                    Entropy (8bit):3.302638651535834
                                                    Encrypted:false
                                                    SSDEEP:6:MlPQs7YniAcUisANHYrtlPQs7YnUZ+4NHYr9n:gjnmbsh9
                                                    MD5:06859CBBDF675EFD126067B9C22D3530
                                                    SHA1:A2DB075550C073B38E438AE17E3B99B26F663C33
                                                    SHA-256:2C4068C4EBBAACBB75CF2152F73AF7C3F97D4A8BA89205A8035289954E74C7C3
                                                    SHA-512:25355F3A8DA4A5855E94F4E9E6581BB5249B29341090083D60E80E218D3D98C6889175BD9374D0EC4ED4A6BD2A9D5472722F83CD2B1037F6E3EEA083DFF431D7
                                                    Malicious:false
                                                    Preview:2.0.2.4.-.0.5.-.2.4. .0.9.:.3.1.:.3.4...3.8.8. .C.h.e.c.k.i.n.g. .a.d.m.i.n. .i.n.s.t.a.l.l...........2.0.2.4.-.0.5.-.2.4. .0.9.:.3.1.:.3.4...3.8.8. .N.o.t. .a.n. .a.d.m.i.n. .i.n.s.t.a.l.l.a.t.i.o.n.....
                                                    Process:C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):14
                                                    Entropy (8bit):3.182005814760214
                                                    Encrypted:false
                                                    SSDEEP:3:UhLev:Udev
                                                    MD5:37E0F9A41FF5436232310B33EBD75549
                                                    SHA1:451641374A7B9D6AB6C938F6FDA30DBA687955F7
                                                    SHA-256:14235F5921538429AE578A9AAE1A4A60F423E96A39D6B7898A2E88B44D63FD3A
                                                    SHA-512:2A26C4B19B64C192D800D6D02CC93F3F9D40AA4D651C5C3ECF078AD45F3D13AB5D83072D27BE5E8514124F7D2AA5782634FC8781F952AB56E82AF99560694EE7
                                                    Malicious:false
                                                    Preview:44.5.0.29672..
                                                    Process:C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exe
                                                    File Type:ASCII text, with very long lines (894), with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):5646
                                                    Entropy (8bit):5.559496855042959
                                                    Encrypted:false
                                                    SSDEEP:96:423w0c53DZ3LjxNA5ZOIHwwuI3u7zO9zuIROj0i3XKQ9Jj9m+O9b9e96zwQ+N1ji:4P0c53t3LjxNIQwuI3unWuIMFZ9Jj9mF
                                                    MD5:E1B1F969A4B8C588CD66C9C4955E6392
                                                    SHA1:3E8E4C5BE9DF573F9F0911514F11C5C387CB7AC8
                                                    SHA-256:BA7E6A11ECFE0AE03E60D16714315C78A35F0BF0A6CD777876427C716BE413CB
                                                    SHA-512:9881A7210C622F20BE1E9648774ADBC2BBC658D85B7F623B1DF2908FD73386B7260E0AD67A733C2FDF8D361416AB949F3C287C266EEA8C91D035D01AD5D76483
                                                    Malicious:false
                                                    Preview:2024-05-24T11:06:47.190Z Webex launcher started, location: **************\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exe, launcher version: 1.0.0.2..2024-05-24T11:06:47.193Z starting version selector in **************\AppData\Local\CiscoSparkLauncher..2024-05-24T11:06:47.193Z Found an original installation directory at: **************\AppData\Local\Programs\Cisco Spark\..*** Creating a directory with name: **************\AppData\Local\Programs\Cisco Spark\..Integrity file missing!..Name: **************\AppData\Local\Programs\Cisco Spark\..Executable type: None..2024-05-24T11:06:47.193Z Current dir: **************\AppData\Local\Programs\Cisco Spark..*** Creating a directory with name: **************\AppData\Local\Programs\Cisco Spark..Integrity file missing!..Name: **************\AppData\Local\Programs\Cisco Spark\..Executable type: None..2024-05-24T11:06:47.194Z The directory **************\AppData\Local\Programs\Cisco Spark\ is being compared to **************\AppData\Local\Pr
                                                    Process:C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe
                                                    File Type:data
                                                    Category:dropped
                                                    Size (bytes):288
                                                    Entropy (8bit):6.381233955234708
                                                    Encrypted:false
                                                    SSDEEP:6:Qa3G3Gk8/glQzl+SkhWlRHm4H0b4eLbkOXOTRC8QZxrrphTCS:QUdkcgbFL4mbkOXOd5QZZFgS
                                                    MD5:6ADE3D18F6BACA34C3E5F1489EE47CBB
                                                    SHA1:97BD79120E34FA7409F54F6F0E240B24A1F1D59A
                                                    SHA-256:ADEB6E394D9D4839D0ADFC4B1365AD30D846C4E0C1A3DC2894DC6BBD64120B7E
                                                    SHA-512:C7042F57F47C510C6240E9AADB50AA591D76CBFC668665079834087848D359435E4E952B8F55D4146CB70B5645F29C570ADA716FF59C0D03530EED859522F8F8
                                                    Malicious:false
                                                    Preview:............z..O..........4O.w.".=.d........s.p.a.r.k.-.w.i.n.d.o.w.s....f...... ...=.0.53.|...k.-.i'.Y.4.g,%/\Q................ ....O.....AI....:......p......$P...0......h...LI./L.....#.-....@J..Sk.....(..v...@.....W}=.w_...v.}............/......]!.o...s.l.>./t.(7.vV........w
                                                    Process:C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe
                                                    File Type:ASCII text, with very long lines (3055), with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):92126
                                                    Entropy (8bit):5.543956846116106
                                                    Encrypted:false
                                                    SSDEEP:1536:e5PnCJ6di5ZmdZOEpOttoYZ05CJ5WgCEcbpr9qXTpqZi+15tnm+kKPa3HXAfvc0A:4PCJ6dKzrsCJ5WgCEcbpxqXTpqZi+1Lc
                                                    MD5:13F6FF09FFCA79B9A4A9B9F7530740F7
                                                    SHA1:C21891F96E62656DE55DFD7C55C1804415A37DB7
                                                    SHA-256:EE371EC56E97105FB17FD9CA4B46ADAF27C7B659007D331E8D06DCB8485C4250
                                                    SHA-512:B075B8F3704F58B838BF86114FFB11312D2D815408D9BE68BB9CB48394AC556AA57257A7A22E696C017B48E1DA2FD92BF046E046E12F14BB953329D4DF549704
                                                    Malicious:false
                                                    Preview:2024-05-24T11:06:47.653Z <Debug> [0xc38][]main.cpp:616 Main::sparkWindowsDesktopMain::***** CMD ARGUMENT: ********\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe..2024-05-24T11:06:47.653Z <Debug> [0xc38][]main.cpp:616 Main::sparkWindowsDesktopMain::***** CMD ARGUMENT: ********\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1..2024-05-24T11:06:47.653Z <Debug> [0xc38][]main.cpp:616 Main::sparkWindowsDesktopMain::***** CMD ARGUMENT: spark-windows-app.dll..2024-05-24T11:06:47.653Z <Debug> [0xc38][]main.cpp:616 Main::sparkWindowsDesktopMain::***** CMD ARGUMENT: /Hosted=true..2024-05-24T11:06:47.653Z <Debug> [0xc38][]main.cpp:616 Main::sparkWindowsDesktopMain::***** CMD ARGUMENT: ********\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exe..2024-05-24T11:06:47.653Z <Debug> [0xc38][]main.cpp:620 Main::sparkWindowsDesktopMain::***** CMD ARGUMENT: launched with /protocolUri..2024-05-24T11:06:47.653Z <Info> [0xc38][]main.cpp:624 Main::sparkWindowsDeskto
                                                    Process:C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):9
                                                    Entropy (8bit):2.9477027792200903
                                                    Encrypted:false
                                                    SSDEEP:3:LmByn:aBy
                                                    MD5:6C902974AA4FDF02BEBDA5054A8C9E6A
                                                    SHA1:697390C9B5A314D3CB40E0C1576468AB7D351CAE
                                                    SHA-256:C27E3EDB6F61C241A34B105F2E434E324F6BF9E5FE1D8539855D84DF1FF4CB1D
                                                    SHA-512:D2B7DBAADD6549AA924F282086B9910ACDB92B497BDFFAC597E3155C38A66A7D2BF3A312A40B2CC6007694A8B6DE3B1EF076D026585129C52B059EB321CC1B62
                                                    Malicious:false
                                                    Preview:started..
                                                    Process:C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe
                                                    File Type:Zip archive data (empty)
                                                    Category:dropped
                                                    Size (bytes):22
                                                    Entropy (8bit):1.0476747992754052
                                                    Encrypted:false
                                                    SSDEEP:3:pjt/l:Nt
                                                    MD5:76CDB2BAD9582D23C1F6F4D868218D6C
                                                    SHA1:B04F3EE8F5E43FA3B162981B50BB72FE1ACABB33
                                                    SHA-256:8739C76E681F900923B900C9DF0EF75CF421D39CABB54650C4B9AD19B6A76D85
                                                    SHA-512:5E2F959F36B66DF0580A94F384C5FC1CEEEC4B2A3925F062D7B68F21758B86581AC2ADCFDDE73A171A28496E758EF1B23CA4951C05455CDAE9357CC3B5A5825F
                                                    Malicious:false
                                                    Preview:PK....................
                                                    Process:C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe
                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 6, database pages 4, cookie 0x1, schema 4, UTF-8, version-valid-for 6
                                                    Category:dropped
                                                    Size (bytes):16384
                                                    Entropy (8bit):0.5125834355206682
                                                    Encrypted:false
                                                    SSDEEP:12:TLwkC/KyNTSFfcABP/0Vc9mTFxdEAKLNLDbibp4JKVxe+ht8rBazMw5QvoXG8:TLw/ncBk6+8RLRkXiBwx5KoXz
                                                    MD5:60910CF67ED3F4D50370FA2EE07314FB
                                                    SHA1:BCB9430F43893F33C1FA47B220B7A9E26F0DA3CD
                                                    SHA-256:E5AE8CEADDC222EB9E68640049C81BEC62357CEFA3062352BAD9FDE1FC7F8E41
                                                    SHA-512:125B8749DC6729E44240F97055EE460C9FACEE3A2A31B83E906C551260F993345561F7F4E0AF5CBF7D78D754F1FE76EDCC617B9EDA61BE2D666366BBF2CE2A81
                                                    Malicious:false
                                                    Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe
                                                    File Type:SQLite Rollback Journal
                                                    Category:dropped
                                                    Size (bytes):16928
                                                    Entropy (8bit):0.4898828185880603
                                                    Encrypted:false
                                                    SSDEEP:12:7+t7tw5QvoXB5Dbibp4JKVxe+ht8rvwqLWUkB/KyNTSFfcABP/0Vc9mTFxdEAKb:7+t25KoXB5RkXivwqL5MncBk6+8b
                                                    MD5:42474FA0B1FAC89B55AA5B438F348433
                                                    SHA1:ED430873F347E6024B8019A4BD7DB967C5AEBA7C
                                                    SHA-256:A38BE29301B03C7C5CDDFA114D8C9FCCEEB2C4C1801DC2B6F03EB9560B9CB2B9
                                                    SHA-512:9AE89908618F29AC5ADCFD493A62BED74B356A1FA792C22E2EDB1F69B115FB54EE51B3C732E8185D13CE55557B9E21AA431210163602574038476F3960F11EB9
                                                    Malicious:false
                                                    Preview:.... .c......n.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe
                                                    File Type:data
                                                    Category:dropped
                                                    Size (bytes):16384
                                                    Entropy (8bit):7.988544683720731
                                                    Encrypted:false
                                                    SSDEEP:384:k/GvaKPauH39UWuYw8mm4YUuKdnmHLiBxw5weG6Ail0BoVC5V7i:k/0euHyHC4YUuKRmriBxRiKBoVAk
                                                    MD5:83D63A9DED4AD1A19EC41809F8C34795
                                                    SHA1:989B1626FB55926896E954CA4237C9E990FCABDE
                                                    SHA-256:97C367C9BBF925DA94E2FCC15EA39AE3F0C456DC7B2466AFB2B800C5271BE008
                                                    SHA-512:7BDA68D56B44A377AFA1E292EDB8A5E1463B55021C20D3F25E1AB5C1F53DB2A1AA17B4FE30830F57418920C70C59886DA60E88CEB258FEB1863657254420CA4C
                                                    Malicious:false
                                                    Preview:..... .&T.x..}......@ Is!]l.;.2U...i...).{....AU..P.Z..Hi.S.K............hM){9..}E.@..Q...]... t.m.H.Z....*D.....#..6.:Ph.|...3f.{2.*.....'>..5...j(.......I..poB[.q.v.WouD._.T..b....`..b..7?.L>.Fkl..W.c.........c..e..$...!]fq..n..H.4.95..g...ui.f.7..7...4X2.<..`h.(.r..,\.~s......[."..i....Ac..?.O..H=...8...W........9c}/..+j.@.:.>..@1.^...<.._c\%...}...g..X...d....W}....}....i<.....r.D.$EC.......u...d......../..P<.h<.Od.`{..m>a..l..7S.M.*.>.<..hu3.@...........H..H.%....m<s.Uq..".l...0.k96...u..0...|U..Q..x.V..n3.....W.e.......v.]..?).;:Z.g..vT..u......m.6.vH.b.T....)...).Q..?..Xm8..".m&f..^ab..\.r...>......$"..j*y..XXNt..X.lO(.aDtW.5.r.Z.X.......o.1......k.......d...W.X...l.` .plD..6AMP]<IL4..kM...9..[-.G.].9p.,."L.<.>R2v3.e..Q`..:.R..^...t./.w..d&..D.........G4..*.hb./i5..M......z.i(6.[..wK....9/....,s.....J..Oar...m.+..yB.Y|Z...tWm.!W..Q.B.6..}........s.>.aL.......]G...Y....Bz.X."...>.j\.J..E.4F.p*....j..k...O.3a.t......N.<.UEN..Y.Z..
                                                    Process:C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe
                                                    File Type:SQLite Rollback Journal
                                                    Category:dropped
                                                    Size (bytes):16928
                                                    Entropy (8bit):7.924277758348622
                                                    Encrypted:false
                                                    SSDEEP:384:7bnvn387TLQnMTCA+YF8mJBNJZ8VowaEmE8cuReDWvuCQKbM3hJNmm8p:3vns7TUMTN5VP80u7QMWvuZK+h/m3p
                                                    MD5:75BD528A2309E1FECD7BDC9A17D777F0
                                                    SHA1:9EC26F038FEF03CA9AB924F6E2A963D1A6B1BD94
                                                    SHA-256:8CEBFB7175F8F15DCC90D1D5D014AF44955F01E51826843FAAA240BA2CD41622
                                                    SHA-512:89DB30EEAB515F0CC5ED63E3DFA3A584C1AB3BEFDE9CD2B783C266D07789696E287D12E38880EAC9567C0E02066BD8038D77EF7733D4EA85D62BA778A547DD7A
                                                    Malicious:false
                                                    Preview:.... .c.............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................c8...Q."...%/}....&)..e.4...>....#...M\.. ..i.m.I...'..@.#1gI.c..6hR.5.h.mq;...Q.e0.........%ub...6.'..2.!.........6...-{...G..G...|.>6....s........^..q.o...pby]...j.}% ....e...6....'r.0"......K.Nz..F.....+.C.C..82..[....;3......f.0T.Fq..{}..."z...7L].lQ..)i...@....HC7"!..+...0.z..@X..x.....r .E.........j..#.!..h..O..[0=-rk`vK....I........H.k.n.,..;.d.ys.:...4...BP.J.~(9.?....s;....Y.$..*...}y1....8.iD)..!0Y..[DU".*<t..^".Kz."Q.L..h...n../...y..0.......H\[.K/_.
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):122480
                                                    Entropy (8bit):7.097480828126144
                                                    Encrypted:false
                                                    SSDEEP:1536:BNlHLXYAcNG6d2vlvPahT21HXNMMUpOh1lyDi8pgP7N3hlGU:JraZ2AtmXmpXDiUgP93
                                                    MD5:309513CE428B34A3FE286DBD4E56539B
                                                    SHA1:A64E46131BA8C912F1C1C4EC1283C7D7E9A1D055
                                                    SHA-256:C5ED8472AA7A22CC0D86AAD6E2DEB2E953F069B7B8B50FC756D016FA0D6F2E08
                                                    SHA-512:B755ACFBD7C1A2E1E3D79728DEBF0C21047AF4E88B5CDC2D9D99A4AC0A048F6E0151D518F5D19C018A2724C27C97F5ED73B88125D75266D736C4AB44B9F14D9A
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........Z..o4..o4..o4...2..o4...5..o4..o5..o4...=..o4......o4..o...o4...6..o4.Rich.o4.........................PE..d....dCf.........."....$.......................@....................................c.....`..................................................=.......p..T....`..........p ......D....9..p............................................0...............................text............................... ..`.rdata..L....0......................@..@.data...`....P.......,..............@....pdata.......`......................@..@.rsrc...T....p.......0..............@..@.reloc..D...........................@..B........................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:7-zip archive data, version 0.4
                                                    Category:dropped
                                                    Size (bytes):145162692
                                                    Entropy (8bit):7.999991459809445
                                                    Encrypted:true
                                                    SSDEEP:3145728:OzV119ClAlJ+ScodASe7sBNP/Z7SFztpVzQczTrD2MUnTke+qdQ:OJr9flMfvSd/8FztfTrD2MUnIqdQ
                                                    MD5:0DCE566929294B33152B10A8F52E6A8A
                                                    SHA1:CFFA2E8E84DADA4A6E732F51C98AF0F12184CD43
                                                    SHA-256:2409ECBD70C2008675F2D5C804FAB0E6102F840146DC950F18B240EB26753C99
                                                    SHA-512:7D69BEC1825C5F9EE91DB8D60197041B06D6A6E3BC173C68C6126BBD12FE79E5584230BD73889799C5543AC465AAF840FEB4C90A691540378F994D11307EE64E
                                                    Malicious:false
                                                    Preview:7z..'.......~.......&.........WU..2..].=.=A....&yX.#....x.....#..up..;\=..9..&..T..Am@.]9.....;..,...d......+B@]..;_..4z.k>..y..V....G}Y ..F....dG.G.._6./M..#..6....P)...v}.Z....QV.e.$...V...8..B8}R.@.K.&"8...4`...<@..-.z8.13...\....[P..(@..N...F...X{}.P.<%.hRg..[.a.M......+k..D.....g...6...k.......S...f...L4.\..........S.7...4......i.|W...^)<....i...s../... .bB....;D.....66.>5.z...u|...b^s.+.xs...g.v..M..7..P...o.<`.<R......r...9R~...C.G......u.......<../7V zK...o`..8h...y..*O..%...!.y.j$.........6.=..#.;.....5.V..g.......O.....l0Z..^\....U...H....:.kE2z...yIh.'o+1.g.N.?....M..##.T..2...'Z.=......XJp7...6C=........B....I.$..I...i...b@!...K.....x..%6nO].yq....tJ...L.>...-.z..o'...:C...qr-R...%LR..).>.k.=&i..?..b.{......d.).U.wA.a..}........$..k....!?.....Q.....+..........n...{..#......R....<Tx...a.x1.N.4.K...@....{8}R./..jERE.Z;.`.z.${O..T.Uc...h.?@.O%..Mk....)/ ...%..yFF....CTj8....YQL.l.V.{N.x.}Q$....k5m...\.....
                                                    Process:C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe
                                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):21889024
                                                    Entropy (8bit):7.999627522312975
                                                    Encrypted:true
                                                    SSDEEP:393216:v9zBI5bPzXfPxAyYXn+z+i8sJFwtBvMsVo+6r/4ELY0f8Ekdm:vRm5bPzXXyVXn+z8sJ+BvMsVo+wxUjE1
                                                    MD5:1E64D97BD5688F9215E193C4098591A8
                                                    SHA1:B27EE6AEBE17548651370642420E1A86DB5759A1
                                                    SHA-256:C796EA6C0D3763EE5D4635D61E4DD6E9319C5591B650D314F40BC0060A1F7891
                                                    SHA-512:7CF832D70DB575E6D915856D1EF8A3508284CB1BB12BD197C337073960357BC42CB23BD201904D5F7C889BACFF366FDCAB52C4A72A1CE6B099E4869DE6EB54C3
                                                    Malicious:false
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......d..[ e.. e.. e..4...+e..4....e..B...1e..B...4e......-e..B....e..4...3e..4...!e..4...-e.. e...e....@.!e.. e(.ve......!e..Rich e..................PE..L....(.d.....................(...... }............@.......................... ......Lt....@..................................?..x........v..............H/...... ....1..p....................1..........@...............H...T>..`....................text...*........................... ..`.rdata..............................@..@.data...,....P.......8..............@....didat..,....p.......B..............@....rsrc....v.......x...D..............@..@.reloc.. ...........................@..B................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\webex.exe
                                                    File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Webex, Author: Cisco Systems, Inc, Keywords: Installer, Comments: Version: 44.5.0.29672, Template: x64;1033, Revision Number: {CB8E6878-4597-4DED-84BE-E35CC89B823D}, Create Time/Date: Tue May 14 14:20:42 2024, Last Saved Time/Date: Tue May 14 14:20:42 2024, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2
                                                    Category:dropped
                                                    Size (bytes):1073152
                                                    Entropy (8bit):4.449313621140226
                                                    Encrypted:false
                                                    SSDEEP:6144:VGxFRhoHXeA7CG/mZE1jOZy2KL4GBiwQtEa4L2sLO2aZ/tmWlidnap2rr22:Go3D/+8jOZy2KsGU6a4KsLO2QYB
                                                    MD5:734D89F77EBC27C4746992FB0BC8D77A
                                                    SHA1:893AAD691AD3ECB9CCE30F340E8752C57123A7CA
                                                    SHA-256:73EFF87365E6852F71186D6E9B6B616FD730C016C7E76667090779ACB194CEB0
                                                    SHA-512:7579DF9062DC7D7F6E1355BCA666FFB17898CB6A14BEC38CB0620266834E61EB0B3B43955F9EBEC6254DAEC2645C22108AC943C7B0F2B43DA74BA18CB140AA77
                                                    Malicious:false
                                                    Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:MS Windows icon resource - 10 icons, 48x48, 8 bits/pixel, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
                                                    Category:dropped
                                                    Size (bytes):98706
                                                    Entropy (8bit):7.129670094424054
                                                    Encrypted:false
                                                    SSDEEP:1536:alHLXYAcNG6d2vlvPahT21HXNMMUpOh1lyDi8n:CraZ2AtmXmpXDiK
                                                    MD5:0A9BF46691CD4DC4D8ADB773ED79076D
                                                    SHA1:ED3D7546C2B1FBDEED107B8DDAEC966C6F07989A
                                                    SHA-256:24D538CEC1A46EFF37DEBC694E13B29C9D7B60FB1BC3B1E0BD704DA1927C46AC
                                                    SHA-512:21034DD519FA57837058407762FFB5530F885C4E66FF8317BF3C4228CCD8454929BC0AEA93030BA5FDB63A36282CACEC9DE3F3E2EA53048C918C00FFA8D1C332
                                                    Malicious:false
                                                    Preview:......00.................... .t...N...@@.... .(B.....<<.... .H:......00.... ..%..2...((.... .h....A.. .... .....B\........ ......l........ .....rv........ .h...*}..(...0...`...................................................................&...$...+...'...1...8...'"..%$.."!..*&..6&..+2..93..))).9,'..9%.4:).000.;;;.B5..C&..[)..T+..Z+..D6..c-..d0..j4...8..B/(.D8%.[5'.b5#.y:".9E(.F@..QC..PI..YJ..RK..@S..hZ..Ol..Vu..Pf..Zw..{`..yi..dz..~{..EY+.`] .Vu+.NNN.RRR.ZZZ.iii.vvv.zzz..5...:...;...>...@...C...U...\...~...z...{...w...u...}.......s...{...}...p...w...f...@'..C#..H$..N&..O(..V'..S-..S+..m"..s#..v"..G...I...M...`...c...k...v...N ..Q&..R!..Y ..S(..U(..X+..R!..U#..X%..W(..Z,..^-..Z&..\(..^)..x)..`...`*..k+..c,..f...h/..p&..c0..g0..i0.i...t...{...i.".w.+.l.*.s.%.`.1.c.2._.?.t.-...-.l.5.z.<.i.;.u.4.o.<.y.9.[.I.g.A.~.E.^.R.f.F.v.K.f.L.s.C.e.S.Z.Y.b.V...............................................................................................................................................
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working directory, Archive, ctime=Tue May 14 17:19:30 2024, mtime=Fri May 24 08:28:55 2024, atime=Tue May 14 17:19:30 2024, length=122480, window=hide
                                                    Category:dropped
                                                    Size (bytes):1472
                                                    Entropy (8bit):4.783254034171189
                                                    Encrypted:false
                                                    SSDEEP:24:8p4ac7W7ZteR6Kc6RjWMjtQUAauUDfau/bUGZdJ9Gprkh7qyFm:8p4RKUR6U4MhaCDzbUGjJ9G9koyF
                                                    MD5:BD16DBF3CA9DEEF015D215FC2E32E595
                                                    SHA1:81AA7A91A881C30ED6C94725274676FA923F2FB9
                                                    SHA-256:BC520AE5A924437850F7669335B40166142886C487D0DBDBD21BF6C5CACC9608
                                                    SHA-512:647CD28744D7EB302C6F37B2C7706328F857EF7BB1C6F82050D426A8F1A26604E54B741A6F89CCB66A3479A03A37F7700CEEE8E2C3A2D03EEC6D7CA0FE354413
                                                    Malicious:false
                                                    Preview:L..................F.... ....e.C+....Yj.....e.C+...p.......................<.:..DG..Yr?.D..U..k0.&...&......vk.v....#.E....9.p........t...CFSF..1.....CW.^..AppData...t.Y^...H.g.3..(.....gVA.G..k...@......CW.^.X.K...........................%..A.p.p.D.a.t.a...B.P.1......X.K..Local.<......CW.^.X.K....b.......................a.L.o.c.a.l.....Z.1......X.K..Programs..B......X.K.X.K..............................P.r.o.g.r.a.m.s.....`.1......X.K..CISCOS~1..H......X.K.X.K....i.......................a.C.i.s.c.o. .S.p.a.r.k.....t.2.p....Xo. .CISCOC~1.EXE..X......Xo..X.K.....4........................C.i.s.c.o.C.o.l.l.a.b.H.o.s.t...e.x.e.......t...............-.......s..............).....C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exe..;..... . . . . . . . .C.l.o.u.d. .b.a.s.e.d. .t.e.a.m. .c.o.l.l.a.b.o.r.a.t.i.o.n. .a.p.p.l.i.c.a.t.i.o.n....... . . . .@.....\.....\.....\.....\.....\.....\.L.o.c.a.l.\.P.r.o.g.r.a.m.s.\.C.i.s.c.o. .S.p.a.r.k.\.C.i.s.c.o.C.o.l.l.a.b.
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working directory, Archive, ctime=Tue May 14 17:19:30 2024, mtime=Fri May 24 08:28:55 2024, atime=Tue May 14 17:19:30 2024, length=122480, window=hide
                                                    Category:dropped
                                                    Size (bytes):1458
                                                    Entropy (8bit):4.802309840777395
                                                    Encrypted:false
                                                    SSDEEP:24:8c4ac7W7ZteR6Kc6XyNtQUAauUDfau/bUGZdJ9Gprkh7qyFm:8c4RKUR6UX2aCDzbUGjJ9G9koyF
                                                    MD5:C7F3BD3221EB06B4E8E8AB129C7D2CA8
                                                    SHA1:D501FDC11E313DFF4EA9978E6A3EB6038F5D276E
                                                    SHA-256:49A372F1DBD6E38EE47500ED981C41726BB8418C1B053418CE2DEEEB13D1C7EC
                                                    SHA-512:013336B9E6692A47A098FCC8981B857514C2BE371807AD662012E007CCB7A935285D73F3247A765837C1961DD9E04839099C9025AB7DB2515FF1CDBA3F0F3A7B
                                                    Malicious:false
                                                    Preview:L..................F.... ....e.C+....Y......e.C+...p.......................<.:..DG..Yr?.D..U..k0.&...&......vk.v....#.E....9.p........t...CFSF..1.....CW.^..AppData...t.Y^...H.g.3..(.....gVA.G..k...@......CW.^.X.K...........................%..A.p.p.D.a.t.a...B.P.1......X.K..Local.<......CW.^.X.K....b.......................a.L.o.c.a.l.....Z.1......X.K..Programs..B......X.K.X.K..............................P.r.o.g.r.a.m.s.....`.1......X.K..CISCOS~1..H......X.K.X.K....i.......................>.C.i.s.c.o. .S.p.a.r.k.....t.2.p....Xo. .CISCOC~1.EXE..X......Xo..X.K.....4........................C.i.s.c.o.C.o.l.l.a.b.H.o.s.t...e.x.e.......t...............-.......s..............).....C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exe..;..... . . . . . . . .C.l.o.u.d. .b.a.s.e.d. .t.e.a.m. .c.o.l.l.a.b.o.r.a.t.i.o.n. .a.p.p.l.i.c.a.t.i.o.n....... . . . .9.....\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.P.r.o.g.r.a.m.s.\.C.i.s.c.o. .S.p.a.r.k.\.C.i.s.c.o.C.o.l.l.a.b.H.o.s.t...e.x.
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Webex, Author: Cisco Systems, Inc, Keywords: Installer, Comments: Version: 44.5.0.29672, Template: x64;1033, Revision Number: {CB8E6878-4597-4DED-84BE-E35CC89B823D}, Create Time/Date: Tue May 14 14:20:42 2024, Last Saved Time/Date: Tue May 14 14:20:42 2024, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2
                                                    Category:dropped
                                                    Size (bytes):1073152
                                                    Entropy (8bit):4.449313621140226
                                                    Encrypted:false
                                                    SSDEEP:6144:VGxFRhoHXeA7CG/mZE1jOZy2KL4GBiwQtEa4L2sLO2aZ/tmWlidnap2rr22:Go3D/+8jOZy2KsGU6a4KsLO2QYB
                                                    MD5:734D89F77EBC27C4746992FB0BC8D77A
                                                    SHA1:893AAD691AD3ECB9CCE30F340E8752C57123A7CA
                                                    SHA-256:73EFF87365E6852F71186D6E9B6B616FD730C016C7E76667090779ACB194CEB0
                                                    SHA-512:7579DF9062DC7D7F6E1355BCA666FFB17898CB6A14BEC38CB0620266834E61EB0B3B43955F9EBEC6254DAEC2645C22108AC943C7B0F2B43DA74BA18CB140AA77
                                                    Malicious:false
                                                    Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Webex, Author: Cisco Systems, Inc, Keywords: Installer, Comments: Version: 44.5.0.29672, Template: x64;1033, Revision Number: {CB8E6878-4597-4DED-84BE-E35CC89B823D}, Create Time/Date: Tue May 14 14:20:42 2024, Last Saved Time/Date: Tue May 14 14:20:42 2024, Number of Pages: 200, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2
                                                    Category:dropped
                                                    Size (bytes):1073152
                                                    Entropy (8bit):4.449313621140226
                                                    Encrypted:false
                                                    SSDEEP:6144:VGxFRhoHXeA7CG/mZE1jOZy2KL4GBiwQtEa4L2sLO2aZ/tmWlidnap2rr22:Go3D/+8jOZy2KsGU6a4KsLO2QYB
                                                    MD5:734D89F77EBC27C4746992FB0BC8D77A
                                                    SHA1:893AAD691AD3ECB9CCE30F340E8752C57123A7CA
                                                    SHA-256:73EFF87365E6852F71186D6E9B6B616FD730C016C7E76667090779ACB194CEB0
                                                    SHA-512:7579DF9062DC7D7F6E1355BCA666FFB17898CB6A14BEC38CB0620266834E61EB0B3B43955F9EBEC6254DAEC2645C22108AC943C7B0F2B43DA74BA18CB140AA77
                                                    Malicious:false
                                                    Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):216496
                                                    Entropy (8bit):6.646208142644182
                                                    Encrypted:false
                                                    SSDEEP:3072:/Jz/kyKA1X1dxbOZU32KndB4GLvyui2lhQtEaY4IDflQn0xHuudQ+cxEHSiZxaQ:/t/kE1jOZy2KL4GBiwQtEa4L2sV
                                                    MD5:A3AE5D86ECF38DB9427359EA37A5F646
                                                    SHA1:EB4CB5FF520717038ADADCC5E1EF8F7C24B27A90
                                                    SHA-256:C8D190D5BE1EFD2D52F72A72AE9DFA3940AB3FACEB626405959349654FE18B74
                                                    SHA-512:96ECB3BC00848EEB2836E289EF7B7B2607D30790FFD1AE0E0ACFC2E14F26A991C6E728B8DC67280426E478C70231F9E13F514E52C8CE7D956C1FAD0E322D98E0
                                                    Malicious:false
                                                    Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$........................^.......\......].........................,.......<.........L...'.....'.....'.P.......8.....'.....Rich............................PE..L...Ap.]...........!.........P............................................................@.........................@................P..x....................`..........T...............................@...............<............................text...[........................... ..`.rdata..............................@..@.data...."... ......................@....rsrc...x....P......................@..@.reloc.......`......................@..B........................................................................................................................................................................................................................................................................
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):216496
                                                    Entropy (8bit):6.646208142644182
                                                    Encrypted:false
                                                    SSDEEP:3072:/Jz/kyKA1X1dxbOZU32KndB4GLvyui2lhQtEaY4IDflQn0xHuudQ+cxEHSiZxaQ:/t/kE1jOZy2KL4GBiwQtEa4L2sV
                                                    MD5:A3AE5D86ECF38DB9427359EA37A5F646
                                                    SHA1:EB4CB5FF520717038ADADCC5E1EF8F7C24B27A90
                                                    SHA-256:C8D190D5BE1EFD2D52F72A72AE9DFA3940AB3FACEB626405959349654FE18B74
                                                    SHA-512:96ECB3BC00848EEB2836E289EF7B7B2607D30790FFD1AE0E0ACFC2E14F26A991C6E728B8DC67280426E478C70231F9E13F514E52C8CE7D956C1FAD0E322D98E0
                                                    Malicious:false
                                                    Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$........................^.......\......].........................,.......<.........L...'.....'.....'.P.......8.....'.....Rich............................PE..L...Ap.]...........!.........P............................................................@.........................@................P..x....................`..........T...............................@...............<............................text...[........................... ..`.rdata..............................@..@.data...."... ......................@....rsrc...x....P......................@..@.reloc.......`......................@..B........................................................................................................................................................................................................................................................................
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:data
                                                    Category:dropped
                                                    Size (bytes):115265
                                                    Entropy (8bit):7.200719142519917
                                                    Encrypted:false
                                                    SSDEEP:1536:5umfWlHLXYAcNG6d2vlvPahT21HXNMMUpOh1lyDi8zruI:5um+raZ2AtmXmpXDi0uI
                                                    MD5:ED5E4E5F524921B8BC7FF3F9DF29E8E8
                                                    SHA1:C95A77CFB8D717F1FA7E9710BF0F779EFDB798CB
                                                    SHA-256:30C7E63F0E050E3D5CF1B017CFC8A2D349C0A15D1E5058607A8BD62E28021138
                                                    SHA-512:9C7042C67638A1F15B73BACF0069D95D52CE4D4CB01993D8E1AB74038665E44B8675F2DECD3340015A20F631AE695F918A73DF9DBEB4721881E89582DE33E3B8
                                                    Malicious:false
                                                    Preview:...@IXOS.@.....@.+.X.@.....@.....@.....@.....@.....@......&.{4A82B9CC-F7B3-5000-9CA4-89764C5A9DA4}..Webex(.c64e3759-805b-47c0-b4ab-a6ec7fecd393.msi.@.....@...,.@.....@......ProductIcon.ico..&.{CB8E6878-4597-4DED-84BE-E35CC89B823D}.....@.....@.....@.....@.......@.....@.....@.......@......Webex......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........RollbackLPRFirewallRules....J...RollbackLPRFirewallRules.@F.....Const HKEY_LOCAL_MACHINE = &H80000002..Const msiDoActionStatusSuccess = 1..const vbQuote = """"..Const WebexProgram = "CiscoCollabHost.exe"..Const ProductWebex = "Webex"..Const ProductMeetings = "Cisco Webex Meetings"....Dim LPRAllUsers, NotInstalled, RemoveAll, InstallFolder, IsWebexBundle....Function UpdateLPRFirewallRules().... On Error Resume Next.....call GetMsiProperties()......If LPRAllUsers and NotInstalled Then....call AddWebexLPRFirewallRules()....call AddMeetingsLPRFirewallRules()...End If.....If LPRAllUsers and
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:Composite Document File V2 Document, Cannot read section info
                                                    Category:dropped
                                                    Size (bytes):20480
                                                    Entropy (8bit):1.1792183680745967
                                                    Encrypted:false
                                                    SSDEEP:12:JSbX72FjsiAGiLIlHVRpTh/7777777777777777777777777vDHFuNIxZ/DYs58z:J1QI5XvH/DYszF
                                                    MD5:917718BA2B47D83766A995A90077BF69
                                                    SHA1:22B713FDF5054CB17BB19A735CDA89E0639325A0
                                                    SHA-256:4A0ECC2D03B57930D878257F0196ACB7C3BBA400FD7F90AC09E3A051C7036D08
                                                    SHA-512:B2AAC7AD8B9440BBFBAA53574FC53C1DA512DFCD29CF04ACA2BDAAF2855C4BF72DBE82B0DF66074F8EC91F24A2C18013A124714D532EA2095AB13359EE1FF85A
                                                    Malicious:false
                                                    Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:Composite Document File V2 Document, Cannot read section info
                                                    Category:dropped
                                                    Size (bytes):20480
                                                    Entropy (8bit):1.5599819611560442
                                                    Encrypted:false
                                                    SSDEEP:48:hk8PhzuRc06WX4uFT5/89ayeZkS9GWSJ6W9G0LARo9Ei9GWSI0Df:h7hz1eFTFGmgvb0f
                                                    MD5:156ED3A24190278946921DD5C671025A
                                                    SHA1:A100492426177A7FE8BED54F8DE5DB1CB0E4B591
                                                    SHA-256:E9C16F28625508C562B4273977291ECEFF56C73454C267C6F3E0B4E9725CEAAC
                                                    SHA-512:315118E907900DC4B539BCE571E67D623A02D3045149B35122B003D2205D2B1712F8065C45B980ECD9F680C91C6E081570CDCFC9E10B5A2033B3D27E61292BEB
                                                    Malicious:false
                                                    Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):432221
                                                    Entropy (8bit):5.375181154963886
                                                    Encrypted:false
                                                    SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26Kgauh:zTtbmkExhMJCIpErM
                                                    MD5:FF2E435EB6B644826F704A53FEE4F326
                                                    SHA1:637C97FAFFAB9ACC1CB4817C7E28183BFC613777
                                                    SHA-256:5DA7ED0E632FF88165ADB8217C05A8691AEB16E8DD71A1FD702B9908E9152E05
                                                    SHA-512:A668493430748A635ECED6458DEE96B1D769A355052DE5931E8A14392D6DFA56B62E030321AF826580183146319F50A0412B901BE8348FF9AB9AC0D0328F7CA1
                                                    Malicious:false
                                                    Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:data
                                                    Category:dropped
                                                    Size (bytes):512
                                                    Entropy (8bit):0.0
                                                    Encrypted:false
                                                    SSDEEP:3::
                                                    MD5:BF619EAC0CDF3F68D496EA9344137E8B
                                                    SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                                                    SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                                                    SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                                                    Malicious:false
                                                    Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:data
                                                    Category:dropped
                                                    Size (bytes):32768
                                                    Entropy (8bit):0.08232090909522025
                                                    Encrypted:false
                                                    SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOuNZiJxTiiZ/C4JWs/toVky6l8:2F0i8n0itFzDHFuNIxZ/DYs58
                                                    MD5:06ED3A048F00E7C1EE24DC6DB809112B
                                                    SHA1:D149F7A3FC2181A313D2C3A8E1EFB2A5D45C2966
                                                    SHA-256:EB8A4359B0AA472A28B784680B2ABF50C219DDFC2BE3AE90510B324E29BF6121
                                                    SHA-512:017630D9DD611D2CC89C8D1DD6322F5BF80D36CA9E213ABC0CE4FF6C6102F93C7426869882123B052AB1E18011F61A3395BBF57CE13C1B68994F56D2A64A3023
                                                    Malicious:false
                                                    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:data
                                                    Category:dropped
                                                    Size (bytes):512
                                                    Entropy (8bit):0.0
                                                    Encrypted:false
                                                    SSDEEP:3::
                                                    MD5:BF619EAC0CDF3F68D496EA9344137E8B
                                                    SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                                                    SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                                                    SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                                                    Malicious:false
                                                    Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:Composite Document File V2 Document, Cannot read section info
                                                    Category:dropped
                                                    Size (bytes):32768
                                                    Entropy (8bit):1.2484754219404324
                                                    Encrypted:false
                                                    SSDEEP:48:ZsruUO+xFX4vT5NA89ayeZkS9GWSJ6W9G0LARo9Ei9GWSI0Df:+rdsTAGmgvb0f
                                                    MD5:0F096DA93FEA7D4798C5EA22AC42A6EB
                                                    SHA1:13DC1093F1227AA6157644CA9867DD1D87E63AF8
                                                    SHA-256:036E73E4D570452DD942F2452BB24989D53E0543D45AAFEC8BCE7DB825B3FBAB
                                                    SHA-512:9FC333B5582AD8C667621DB55D1BA48EF3C939B0FE332B0CE1C578E675FF5B99B476135999E081487D4DD4769B5ABF5F9987D2C73C5D5023E57B052B44751C62
                                                    Malicious:false
                                                    Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:data
                                                    Category:dropped
                                                    Size (bytes):512
                                                    Entropy (8bit):0.0
                                                    Encrypted:false
                                                    SSDEEP:3::
                                                    MD5:BF619EAC0CDF3F68D496EA9344137E8B
                                                    SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                                                    SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                                                    SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                                                    Malicious:false
                                                    Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:Composite Document File V2 Document, Cannot read section info
                                                    Category:dropped
                                                    Size (bytes):20480
                                                    Entropy (8bit):1.5599819611560442
                                                    Encrypted:false
                                                    SSDEEP:48:hk8PhzuRc06WX4uFT5/89ayeZkS9GWSJ6W9G0LARo9Ei9GWSI0Df:h7hz1eFTFGmgvb0f
                                                    MD5:156ED3A24190278946921DD5C671025A
                                                    SHA1:A100492426177A7FE8BED54F8DE5DB1CB0E4B591
                                                    SHA-256:E9C16F28625508C562B4273977291ECEFF56C73454C267C6F3E0B4E9725CEAAC
                                                    SHA-512:315118E907900DC4B539BCE571E67D623A02D3045149B35122B003D2205D2B1712F8065C45B980ECD9F680C91C6E081570CDCFC9E10B5A2033B3D27E61292BEB
                                                    Malicious:false
                                                    Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:data
                                                    Category:dropped
                                                    Size (bytes):512
                                                    Entropy (8bit):0.0
                                                    Encrypted:false
                                                    SSDEEP:3::
                                                    MD5:BF619EAC0CDF3F68D496EA9344137E8B
                                                    SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                                                    SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                                                    SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                                                    Malicious:false
                                                    Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:Composite Document File V2 Document, Cannot read section info
                                                    Category:dropped
                                                    Size (bytes):32768
                                                    Entropy (8bit):1.2484754219404324
                                                    Encrypted:false
                                                    SSDEEP:48:ZsruUO+xFX4vT5NA89ayeZkS9GWSJ6W9G0LARo9Ei9GWSI0Df:+rdsTAGmgvb0f
                                                    MD5:0F096DA93FEA7D4798C5EA22AC42A6EB
                                                    SHA1:13DC1093F1227AA6157644CA9867DD1D87E63AF8
                                                    SHA-256:036E73E4D570452DD942F2452BB24989D53E0543D45AAFEC8BCE7DB825B3FBAB
                                                    SHA-512:9FC333B5582AD8C667621DB55D1BA48EF3C939B0FE332B0CE1C578E675FF5B99B476135999E081487D4DD4769B5ABF5F9987D2C73C5D5023E57B052B44751C62
                                                    Malicious:false
                                                    Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:data
                                                    Category:dropped
                                                    Size (bytes):69632
                                                    Entropy (8bit):0.1415437939993556
                                                    Encrypted:false
                                                    SSDEEP:48:mf/0b9GWSD9GWSJ6W9G0LARo9E5BD79ayJ:mfiigvQ1
                                                    MD5:AF287F47975F682C4B6217DA7F23CF4F
                                                    SHA1:C38838D563490EE88C8D49387F728A827161C394
                                                    SHA-256:C1EB650BDB0F6EE510023E53F03665C2AFDC8F0F63D6FEFA634AD1DD148C9ECD
                                                    SHA-512:380A3A3596F40E1B28D26A885B2D5E3A63829D888EA603B831CFBC6F6ADAF16F0D31A240387C7C93D91104DE333B7C0415C731EF56E3330DAEAF360D1D5A49AF
                                                    Malicious:false
                                                    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:data
                                                    Category:dropped
                                                    Size (bytes):512
                                                    Entropy (8bit):0.0
                                                    Encrypted:false
                                                    SSDEEP:3::
                                                    MD5:BF619EAC0CDF3F68D496EA9344137E8B
                                                    SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                                                    SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                                                    SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                                                    Malicious:false
                                                    Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:Composite Document File V2 Document, Cannot read section info
                                                    Category:dropped
                                                    Size (bytes):20480
                                                    Entropy (8bit):1.5599819611560442
                                                    Encrypted:false
                                                    SSDEEP:48:hk8PhzuRc06WX4uFT5/89ayeZkS9GWSJ6W9G0LARo9Ei9GWSI0Df:h7hz1eFTFGmgvb0f
                                                    MD5:156ED3A24190278946921DD5C671025A
                                                    SHA1:A100492426177A7FE8BED54F8DE5DB1CB0E4B591
                                                    SHA-256:E9C16F28625508C562B4273977291ECEFF56C73454C267C6F3E0B4E9725CEAAC
                                                    SHA-512:315118E907900DC4B539BCE571E67D623A02D3045149B35122B003D2205D2B1712F8065C45B980ECD9F680C91C6E081570CDCFC9E10B5A2033B3D27E61292BEB
                                                    Malicious:false
                                                    Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Windows\System32\msiexec.exe
                                                    File Type:Composite Document File V2 Document, Cannot read section info
                                                    Category:dropped
                                                    Size (bytes):32768
                                                    Entropy (8bit):1.2484754219404324
                                                    Encrypted:false
                                                    SSDEEP:48:ZsruUO+xFX4vT5NA89ayeZkS9GWSJ6W9G0LARo9Ei9GWSI0Df:+rdsTAGmgvb0f
                                                    MD5:0F096DA93FEA7D4798C5EA22AC42A6EB
                                                    SHA1:13DC1093F1227AA6157644CA9867DD1D87E63AF8
                                                    SHA-256:036E73E4D570452DD942F2452BB24989D53E0543D45AAFEC8BCE7DB825B3FBAB
                                                    SHA-512:9FC333B5582AD8C667621DB55D1BA48EF3C939B0FE332B0CE1C578E675FF5B99B476135999E081487D4DD4769B5ABF5F9987D2C73C5D5023E57B052B44751C62
                                                    Malicious:false
                                                    Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Windows\SysWOW64\timeout.exe
                                                    File Type:ASCII text, with CRLF line terminators, with overstriking
                                                    Category:dropped
                                                    Size (bytes):57
                                                    Entropy (8bit):4.643864794676717
                                                    Encrypted:false
                                                    SSDEEP:3:hYFqdLGARcWmFsFJQZ30sn:hYFqVmFSQZksn
                                                    MD5:132D0D71AE5F297CFD95EA9DA0CCC7A7
                                                    SHA1:72EADE70CA2B65C3854B51F6C78EB934970E846F
                                                    SHA-256:881FA93CCB7C77E4512523E82FBB3C7EA02AD1D834011C8359B87B4371D9DA17
                                                    SHA-512:301F4F272F82AE8018776D2B553B0477E939F9F4ED1D0281C083A715D6828B26C9D53A9DF93CFE8DA442FA9AA8F4C0FC686D9011F7AC3156E75113CB80D5AF07
                                                    Malicious:false
                                                    Preview:..Waiting for 3 seconds, press CTRL+C to quit ....2.1.0..
                                                    File type:PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
                                                    Entropy (8bit):7.997226353337529
                                                    TrID:
                                                    • Win32 Executable (generic) a (10002005/4) 99.66%
                                                    • UPX compressed Win32 Executable (30571/9) 0.30%
                                                    • Generic Win/DOS Executable (2004/3) 0.02%
                                                    • DOS Executable Generic (2002/1) 0.02%
                                                    • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                    File name:webex.exe
                                                    File size:1'485'096 bytes
                                                    MD5:253d21dbe18ed326858237394b988416
                                                    SHA1:77a49051e8869eceb9a7babb8908d4177cf26a16
                                                    SHA256:c4a6bf1fabb7eec2f96b59691d28812f798974a7f8ebcf8fd314135e2eb55a4b
                                                    SHA512:4eadabb2f76d4c9b339ee5be9358891059ae016659fc840e7b2fe95a70e4b8bd23e6c6403bc0e834ba8dae7f67677edb0cbf1bf61c9c31d2f71011c8e5acb932
                                                    SSDEEP:24576:Y3RvAs/CI0VR/LkzpZ9rGBFXECQ8qpL2idZLaFEPl3xEPBtFnpk1DUXd801:YBIsKtR41Z9CBFLQ8qp1LaeNGPxoDUXr
                                                    TLSH:786533928E74CCB7C6C6F6B454647174F40DBFE4F6CE066265303DA96E3AB29A4C801B
                                                    File Content Preview:MZ......................@...................................0...........!..L.!This program cannot be run in DOS mode....$.......D..,.mu..mu..mu...v~.mu...p~.mu...r~.mu...q~.mu...v~.mu...q~.mu...t~.mu...s~.mu...q~.mu..mu..mu...q~.lu..mt."ou...p~.mu...|~.mu
                                                    Icon Hash:55ecd292964c6c45
                                                    Entrypoint:0x80f760
                                                    Entrypoint Section:UPX1
                                                    Digitally signed:true
                                                    Imagebase:0x400000
                                                    Subsystem:windows gui
                                                    Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                                    DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                                                    Time Stamp:0x65DE20A0 [Tue Feb 27 17:49:20 2024 UTC]
                                                    TLS Callbacks:0x81033d
                                                    CLR (.Net) Version:
                                                    OS Version Major:6
                                                    OS Version Minor:0
                                                    File Version Major:6
                                                    File Version Minor:0
                                                    Subsystem Version Major:6
                                                    Subsystem Version Minor:0
                                                    Import Hash:6ed4f5f04d62b18d96b26d6db7c18840
                                                    Signature Valid:true
                                                    Signature Issuer:CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
                                                    Signature Validation Error:The operation completed successfully
                                                    Error Number:0
                                                    Not Before, Not After
                                                    • 07/08/2023 01:00:00 07/08/2024 00:59:59
                                                    Subject Chain
                                                    • CN=Cisco WebEx LLC, O=Cisco WebEx LLC, L=San Jose, S=California, C=US
                                                    Version:3
                                                    Thumbprint MD5:0B724F730FF9DF09B378185A223DE29B
                                                    Thumbprint SHA-1:05885C6DBFB9CD55D565E1010730172454389F18
                                                    Thumbprint SHA-256:529A6986A4B145951570AB70F76A278216FB8CAC99D09E13EDA9A14C27FFE7E4
                                                    Serial:0F7BEFFAA97B2C43523985E648B34FB3
                                                    Instruction
                                                    pushad
                                                    mov esi, 006B3000h
                                                    lea edi, dword ptr [esi-002B2000h]
                                                    mov dword ptr [edi+0039058Ch], B54A8094h
                                                    push edi
                                                    mov ebp, esp
                                                    lea ebx, dword ptr [esp-00003E80h]
                                                    xor eax, eax
                                                    push eax
                                                    cmp esp, ebx
                                                    jne 00007F326CDFFC4Dh
                                                    inc esi
                                                    inc esi
                                                    push ebx
                                                    push 0040D527h
                                                    push edi
                                                    add ebx, 04h
                                                    push ebx
                                                    push 0015C754h
                                                    push esi
                                                    add ebx, 04h
                                                    push ebx
                                                    push eax
                                                    mov dword ptr [ebx], 00020003h
                                                    push ebp
                                                    push edi
                                                    push esi
                                                    push ebx
                                                    sub esp, 7Ch
                                                    mov edx, dword ptr [esp+00000090h]
                                                    mov dword ptr [esp+74h], 00000000h
                                                    mov byte ptr [esp+73h], 00000000h
                                                    mov ebp, dword ptr [esp+0000009Ch]
                                                    lea eax, dword ptr [edx+04h]
                                                    mov dword ptr [esp+78h], eax
                                                    mov eax, 00000001h
                                                    movzx ecx, byte ptr [edx+02h]
                                                    mov ebx, eax
                                                    shl ebx, cl
                                                    mov ecx, ebx
                                                    dec ecx
                                                    mov dword ptr [esp+6Ch], ecx
                                                    movzx ecx, byte ptr [edx+01h]
                                                    shl eax, cl
                                                    dec eax
                                                    mov dword ptr [esp+68h], eax
                                                    mov eax, dword ptr [esp+000000A8h]
                                                    movzx esi, byte ptr [edx]
                                                    mov dword ptr [ebp+00h], 00000000h
                                                    mov dword ptr [esp+60h], 00000000h
                                                    mov dword ptr [eax], 00000000h
                                                    mov eax, 00000300h
                                                    mov dword ptr [esp+64h], esi
                                                    mov dword ptr [esp+5Ch], 00000001h
                                                    mov dword ptr [esp+58h], 00000001h
                                                    mov dword ptr [esp+00h], 00000000h
                                                    NameVirtual AddressVirtual Size Is in Section
                                                    IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_IMPORT0x41d0300x88.rsrc
                                                    IMAGE_DIRECTORY_ENTRY_RESOURCE0x4110000xc030.rsrc
                                                    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_SECURITY0x169d780xbb0UPX0
                                                    IMAGE_DIRECTORY_ENTRY_BASERELOC0x41d0b80x2c.rsrc
                                                    IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_TLS0x41035c0x18UPX1
                                                    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x4104500xc0UPX1
                                                    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_IAT0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x35480c0x280UPX1
                                                    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                    NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                    UPX00x10000x2b20000x0d41d8cd98f00b204e9800998ecf8427eunknownunknownunknownunknownIMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                    UPX10x2b30000x15e0000x15d600bfc5a6c06955d26a0d605ded12779fc6False0.9990817866726297ARC archive data, packed7.999786004444184IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                    .rsrc0x4110000xd0000xc2002a8f858408cbfbb24d6263967f6b99adFalse0.8208158827319587data7.497011411634941IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                    NameRVASizeTypeLanguageCountryZLIB Complexity
                                                    RT_ICON0x41132c0x468Device independent bitmap graphic, 16 x 32 x 32, image size 1024, resolution 2835 x 2835 px/mEnglishUnited States0.726063829787234
                                                    RT_ICON0x4117980x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4096, resolution 2835 x 2835 px/mEnglishUnited States0.5405722326454033
                                                    RT_ICON0x4128440x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9216, resolution 2835 x 2835 px/mEnglishUnited States0.4266597510373444
                                                    RT_ICON0x414df00x7dafPNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0004972804972805
                                                    RT_STRING0x3d56380x2adataEnglishUnited States1.2619047619047619
                                                    RT_RCDATA0x3a3bd80x5c7adataEnglishUnited States1.0006758469206725
                                                    RT_RCDATA0x3a98580x2f28dataEnglishUnited States1.0009111994698476
                                                    RT_RCDATA0x3ac7800x23f3dataEnglishUnited States1.00119526241443
                                                    RT_RCDATA0x3aeb780x321cdataEnglishUnited States1.0008574992204553
                                                    RT_GROUP_ICON0x41cba40x3edataEnglishUnited States0.7903225806451613
                                                    RT_VERSION0x41cbe80x2c4dataEnglishUnited States0.4788135593220339
                                                    RT_HTML0x3b1d980x235d8dataEnglishUnited States1.0003520737836196
                                                    RT_MANIFEST0x41ceb00x17dXML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.5931758530183727
                                                    DLLImport
                                                    KERNEL32.DLLLoadLibraryA, ExitProcess, GetProcAddress, VirtualProtect
                                                    Language of compilation systemCountry where language is spokenMap
                                                    EnglishUnited States
                                                    Skipped network analysis since the amount of network traffic is too extensive. Please download the PCAP and check manually.

                                                    Click to jump to process

                                                    Click to jump to process

                                                    Click to dive into process behavior distribution

                                                    Click to jump to process

                                                    Target ID:0
                                                    Start time:05:28:49
                                                    Start date:24/05/2024
                                                    Path:C:\Users\user\Desktop\webex.exe
                                                    Wow64 process (32bit):true
                                                    Commandline:"C:\Users\user\Desktop\webex.exe"
                                                    Imagebase:0x820000
                                                    File size:1'485'096 bytes
                                                    MD5 hash:253D21DBE18ED326858237394B988416
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:low
                                                    Has exited:true

                                                    Target ID:2
                                                    Start time:05:28:53
                                                    Start date:24/05/2024
                                                    Path:C:\Windows\SysWOW64\msiexec.exe
                                                    Wow64 process (32bit):true
                                                    Commandline:msiexec.exe /i "C:\Users\user\AppData\Local\Temp\c64e3759-805b-47c0-b4ab-a6ec7fecd393.msi" /quiet /norestart AUTOSTART_WITH_WINDOWS=false
                                                    Imagebase:0xcd0000
                                                    File size:59'904 bytes
                                                    MD5 hash:9D09DC1EDA745A5F87553048E57620CF
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:high
                                                    Has exited:true

                                                    Target ID:3
                                                    Start time:05:28:53
                                                    Start date:24/05/2024
                                                    Path:C:\Windows\System32\msiexec.exe
                                                    Wow64 process (32bit):false
                                                    Commandline:C:\Windows\system32\msiexec.exe /V
                                                    Imagebase:0x7ff675160000
                                                    File size:69'632 bytes
                                                    MD5 hash:E5DA170027542E25EDE42FC54C929077
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:high
                                                    Has exited:false

                                                    Target ID:4
                                                    Start time:05:28:54
                                                    Start date:24/05/2024
                                                    Path:C:\Windows\SysWOW64\msiexec.exe
                                                    Wow64 process (32bit):true
                                                    Commandline:C:\Windows\syswow64\MsiExec.exe -Embedding 305732C6DAD0EE72C0E34B949704E1E8
                                                    Imagebase:0xcd0000
                                                    File size:59'904 bytes
                                                    MD5 hash:9D09DC1EDA745A5F87553048E57620CF
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:high
                                                    Has exited:true

                                                    Target ID:5
                                                    Start time:05:28:54
                                                    Start date:24/05/2024
                                                    Path:C:\Windows\SysWOW64\taskkill.exe
                                                    Wow64 process (32bit):true
                                                    Commandline:"C:\Windows\system32\\taskkill.exe" /F /IM CiscoCollabHost.exe /T
                                                    Imagebase:0x2b0000
                                                    File size:74'240 bytes
                                                    MD5 hash:CA313FD7E6C2A778FFD21CFB5C1C56CD
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:moderate
                                                    Has exited:true

                                                    Target ID:6
                                                    Start time:05:28:54
                                                    Start date:24/05/2024
                                                    Path:C:\Windows\System32\conhost.exe
                                                    Wow64 process (32bit):false
                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                    Imagebase:0x7ff7699e0000
                                                    File size:862'208 bytes
                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:high
                                                    Has exited:true

                                                    Target ID:8
                                                    Start time:05:28:56
                                                    Start date:24/05/2024
                                                    Path:C:\Windows\System32\msiexec.exe
                                                    Wow64 process (32bit):false
                                                    Commandline:C:\Windows\System32\MsiExec.exe -Embedding 80617056B0CA03034534C28A67086463
                                                    Imagebase:0x7ff675160000
                                                    File size:69'632 bytes
                                                    MD5 hash:E5DA170027542E25EDE42FC54C929077
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:high
                                                    Has exited:true

                                                    Target ID:15
                                                    Start time:05:31:31
                                                    Start date:24/05/2024
                                                    Path:C:\Windows\SysWOW64\cmd.exe
                                                    Wow64 process (32bit):true
                                                    Commandline:cmd.exe /c timeout /NOBREAK /T 3 > nul & del /f /q "C:\Users\user\Desktop\webex.exe"
                                                    Imagebase:0x240000
                                                    File size:236'544 bytes
                                                    MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:high
                                                    Has exited:true

                                                    Target ID:16
                                                    Start time:05:31:32
                                                    Start date:24/05/2024
                                                    Path:C:\Windows\System32\conhost.exe
                                                    Wow64 process (32bit):false
                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                    Imagebase:0x7ff7699e0000
                                                    File size:862'208 bytes
                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:high
                                                    Has exited:true

                                                    Target ID:17
                                                    Start time:05:31:33
                                                    Start date:24/05/2024
                                                    Path:C:\Windows\SysWOW64\timeout.exe
                                                    Wow64 process (32bit):true
                                                    Commandline:timeout /NOBREAK /T 3
                                                    Imagebase:0x6c0000
                                                    File size:25'088 bytes
                                                    MD5 hash:976566BEEFCCA4A159ECBDB2D4B1A3E3
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:high
                                                    Has exited:true

                                                    Target ID:18
                                                    Start time:05:31:34
                                                    Start date:24/05/2024
                                                    Path:C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exe
                                                    Wow64 process (32bit):false
                                                    Commandline:"C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exe" /protocolUri="webex://meet/?bt=12&bv=121&cr=065f9a40-5723-45ab-9507-cf2766bb45fe&dns=appleinc.webex.com&en=3&flag=17&jointxid=x7Pbq0RE2n&jt=eyJkdDAiOjE3MTY1NDg2NDIsImR0MSI6Nzk4LCJkdDIiOjIxODUsImR0MyI6MzUzNSwiZHQ0IjoyNDEyODMsImR0NSI6MzcxODI4NTUxLCJkdDYiOjE3MTY5MjA3MjEsImZ0IjoxLCJ0IjoyNSwidXAiOjF9&mtid=m547a808dce8d2d3d893e20fa794cb8a1&od=6f783f73-9637-4b83-90b9-434a5fccb49d&rc=4&sip=24877802128@appleinc.webex.com&siteurl=appleinc&tr=7A2D3FEB1EC64A498D4F669177387376_1709540815837&uuid=04485f8191de4a7c891a7dfe933370dc&vp=0"
                                                    Imagebase:0x7ff7ec6b0000
                                                    File size:122'480 bytes
                                                    MD5 hash:309513CE428B34A3FE286DBD4E56539B
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:low
                                                    Has exited:true

                                                    Target ID:19
                                                    Start time:05:31:34
                                                    Start date:24/05/2024
                                                    Path:C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe
                                                    Wow64 process (32bit):false
                                                    Commandline:"C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoCollabHost.exe" "C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1" spark-windows-app.dll /Hosted=true "C:\Users\user\AppData\Local\Programs\Cisco Spark\CiscoCollabHost.exe" /protocolUri="webex://meet/?bt=12&bv=121&cr=065f9a40-5723-45ab-9507-cf2766bb45fe&dns=appleinc.webex.com&en=3&flag=17&jointxid=x7Pbq0RE2n&jt=eyJkdDAiOjE3MTY1NDg2NDIsImR0MSI6Nzk4LCJkdDIiOjIxODUsImR0MyI6MzUzNSwiZHQ0IjoyNDEyODMsImR0NSI6MzcxODI4NTUxLCJkdDYiOjE3MTY5MjA3MjEsImZ0IjoxLCJ0IjoyNSwidXAiOjF9&mtid=m547a808dce8d2d3d893e20fa794cb8a1&od=6f783f73-9637-4b83-90b9-434a5fccb49d&rc=4&sip=24877802128@appleinc.webex.com&siteurl=appleinc&tr=7A2D3FEB1EC64A498D4F669177387376_1709540815837&uuid=04485f8191de4a7c891a7dfe933370dc&vp=0"
                                                    Imagebase:0x7ff6f8010000
                                                    File size:122'480 bytes
                                                    MD5 hash:309513CE428B34A3FE286DBD4E56539B
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:low
                                                    Has exited:false

                                                    Reset < >
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000003.1713612449.0000000003349000.00000004.00000020.00020000.00000000.sdmp, Offset: 0334B000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_3_3349000_webex.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 3a84613c2e0e63939a3315d9f58603c81f6f9033debd5d972ad6d8b16db109f4
                                                      • Instruction ID: c53473536c599f338022de18d1d90e2fa0d52ba7dfcdcb0f1ff1d5018dae2327
                                                      • Opcode Fuzzy Hash: 3a84613c2e0e63939a3315d9f58603c81f6f9033debd5d972ad6d8b16db109f4
                                                      • Instruction Fuzzy Hash: 96A13AD3893302BBEE45D57A98453DBE3C96A53790F5B7427C618CEA20F6151A0BBE80
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000003.1713612449.0000000003349000.00000004.00000020.00020000.00000000.sdmp, Offset: 03349000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_3_3349000_webex.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 3a84613c2e0e63939a3315d9f58603c81f6f9033debd5d972ad6d8b16db109f4
                                                      • Instruction ID: c53473536c599f338022de18d1d90e2fa0d52ba7dfcdcb0f1ff1d5018dae2327
                                                      • Opcode Fuzzy Hash: 3a84613c2e0e63939a3315d9f58603c81f6f9033debd5d972ad6d8b16db109f4
                                                      • Instruction Fuzzy Hash: 96A13AD3893302BBEE45D57A98453DBE3C96A53790F5B7427C618CEA20F6151A0BBE80
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000003.1713612449.0000000003349000.00000004.00000020.00020000.00000000.sdmp, Offset: 0334B000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_3_3349000_webex.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 30b9666287d38d593dc1758befece36201a71c2ce0aa09ca2f0b0fb41936a81e
                                                      • Instruction ID: 5d7e59ec0315f23828af6292913370cf5d7671b686239fc70a89643eb06f0df1
                                                      • Opcode Fuzzy Hash: 30b9666287d38d593dc1758befece36201a71c2ce0aa09ca2f0b0fb41936a81e
                                                      • Instruction Fuzzy Hash: 26E0A486FE3326399E60D53289080CBC7C6A3A7752B5FB83BC012DF4132061124F7982
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000003.1713612449.0000000003349000.00000004.00000020.00020000.00000000.sdmp, Offset: 0334B000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_3_3349000_webex.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 8f86d94e304ce84c8d016983f781d006814d4c8aeb2e1662aba581276b899706
                                                      • Instruction ID: 83a9a76422535a2021790a56935a9d5d72c56540e0e6dfaacf1e2d3195432038
                                                      • Opcode Fuzzy Hash: 8f86d94e304ce84c8d016983f781d006814d4c8aeb2e1662aba581276b899706
                                                      • Instruction Fuzzy Hash: DFE06286AE33253BBE60D53A89080CBC7C6A067771B7FB82BC011DF4112061124F7B81
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000003.1713612449.0000000003349000.00000004.00000020.00020000.00000000.sdmp, Offset: 03349000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_3_3349000_webex.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 30b9666287d38d593dc1758befece36201a71c2ce0aa09ca2f0b0fb41936a81e
                                                      • Instruction ID: 5d7e59ec0315f23828af6292913370cf5d7671b686239fc70a89643eb06f0df1
                                                      • Opcode Fuzzy Hash: 30b9666287d38d593dc1758befece36201a71c2ce0aa09ca2f0b0fb41936a81e
                                                      • Instruction Fuzzy Hash: 26E0A486FE3326399E60D53289080CBC7C6A3A7752B5FB83BC012DF4132061124F7982
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000003.1713612449.0000000003349000.00000004.00000020.00020000.00000000.sdmp, Offset: 03349000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_3_3349000_webex.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 8f86d94e304ce84c8d016983f781d006814d4c8aeb2e1662aba581276b899706
                                                      • Instruction ID: 83a9a76422535a2021790a56935a9d5d72c56540e0e6dfaacf1e2d3195432038
                                                      • Opcode Fuzzy Hash: 8f86d94e304ce84c8d016983f781d006814d4c8aeb2e1662aba581276b899706
                                                      • Instruction Fuzzy Hash: DFE06286AE33253BBE60D53A89080CBC7C6A067771B7FB82BC011DF4112061124F7B81

                                                      Execution Graph

                                                      Execution Coverage:37%
                                                      Dynamic/Decrypted Code Coverage:0%
                                                      Signature Coverage:14%
                                                      Total number of Nodes:100
                                                      Total number of Limit Nodes:8
                                                      execution_graph 390 7ff7ec6b10c0 GetCommandLineW CommandLineToArgvW 391 7ff7ec6b1222 SHGetKnownFolderPath 390->391 394 7ff7ec6b1109 390->394 405 7ff7ec6b1261 391->405 392 7ff7ec6b1111 lstrlenW lstrlenW 392->394 394->391 394->392 395 7ff7ec6b1160 CharLowerW CharLowerW 394->395 395->394 396 7ff7ec6b1680 CreateFileW 474 7ff7ec6b2300 396->474 398 7ff7ec6b170c 399 7ff7ec6b2300 11 API calls 398->399 400 7ff7ec6b1726 399->400 402 7ff7ec6b2300 11 API calls 400->402 401 7ff7ec6b16c6 401->398 403 7ff7ec6b2300 11 API calls 401->403 404 7ff7ec6b1740 402->404 403->401 406 7ff7ec6b1758 404->406 407 7ff7ec6b1b6c 404->407 405->396 408 7ff7ec6b2300 11 API calls 406->408 409 7ff7ec6b2300 11 API calls 407->409 410 7ff7ec6b1764 SHGetKnownFolderPath 408->410 427 7ff7ec6b1a07 409->427 411 7ff7ec6b1b34 410->411 420 7ff7ec6b178b 410->420 412 7ff7ec6b2300 11 API calls 411->412 413 7ff7ec6b1b58 CloseHandle ExitProcess 412->413 414 7ff7ec6b2300 11 API calls 415 7ff7ec6b1a8c 414->415 416 7ff7ec6b2300 11 API calls 415->416 417 7ff7ec6b1aa7 416->417 418 7ff7ec6b2300 11 API calls 417->418 419 7ff7ec6b1abe 418->419 421 7ff7ec6b2300 11 API calls 419->421 420->411 424 7ff7ec6b18d0 PathFileExistsW 420->424 422 7ff7ec6b1ad5 421->422 423 7ff7ec6b2300 11 API calls 422->423 425 7ff7ec6b1aef PathIsDirectoryW 423->425 426 7ff7ec6b18e1 424->426 424->427 428 7ff7ec6b1b00 425->428 429 7ff7ec6b1cd7 SetDllDirectoryW 425->429 430 7ff7ec6b2300 11 API calls 426->430 427->414 431 7ff7ec6b2300 11 API calls 428->431 432 7ff7ec6b1ce4 429->432 433 7ff7ec6b1d18 LoadLibraryW 429->433 445 7ff7ec6b18fc 430->445 436 7ff7ec6b1b1a GetLastError CloseHandle ExitProcess 431->436 437 7ff7ec6b2300 11 API calls 432->437 434 7ff7ec6b1d29 433->434 435 7ff7ec6b1d5b GetProcAddress 433->435 439 7ff7ec6b2300 11 API calls 434->439 440 7ff7ec6b1d82 435->440 441 7ff7ec6b1da6 435->441 438 7ff7ec6b1cfe GetLastError CloseHandle ExitProcess 437->438 442 7ff7ec6b1d43 GetLastError CloseHandle ExitProcess 439->442 443 7ff7ec6b2300 11 API calls 440->443 444 7ff7ec6b2300 11 API calls 441->444 446 7ff7ec6b1d8e GetLastError CloseHandle ExitProcess 443->446 447 7ff7ec6b1db2 444->447 445->445 448 7ff7ec6b192d GetModuleFileNameW 445->448 449 7ff7ec6b2300 11 API calls 447->449 450 7ff7ec6b1941 PathRemoveFileSpecW 448->450 451 7ff7ec6b19d8 448->451 453 7ff7ec6b1dcd FindCloseChangeNotification 449->453 450->451 462 7ff7ec6b1952 450->462 452 7ff7ec6b2300 11 API calls 451->452 454 7ff7ec6b19f3 CloseHandle ExitProcess 452->454 455 7ff7ec6b1ddf 453->455 456 7ff7ec6b1e2f CreateFileW 455->456 457 7ff7ec6b1dfd CreateFileW 455->457 459 7ff7ec6b1e2d 456->459 458 7ff7ec6b2300 11 API calls 457->458 458->459 460 7ff7ec6b2300 11 API calls 459->460 461 7ff7ec6b1e60 460->461 463 7ff7ec6b2300 11 API calls 461->463 462->427 462->451 464 7ff7ec6b1e7b FreeLibrary 463->464 465 7ff7ec6b1e8b 464->465 466 7ff7ec6b1ebc 464->466 467 7ff7ec6b2300 11 API calls 465->467 488 7ff7ec6b22e0 466->488 469 7ff7ec6b1ea2 GetLastError CloseHandle ExitProcess 467->469 471 7ff7ec6b2300 11 API calls 472 7ff7ec6b1edc 471->472 473 7ff7ec6b1ee4 ExitProcess 472->473 477 7ff7ec6b2340 474->477 475 7ff7ec6b24ac 475->401 476 7ff7ec6b23a0 476->475 479 7ff7ec6b23bf GetUserNameW 476->479 477->475 477->476 478 7ff7ec6b2398 477->478 495 7ff7ec6b1fe0 GetSystemTime GetDateFormatEx GetTimeFormatEx 478->495 479->475 481 7ff7ec6b23d9 SHGetKnownFolderPath 479->481 481->475 482 7ff7ec6b2402 481->482 491 7ff7ec6b1ef0 lstrlenW lstrlenW 482->491 485 7ff7ec6b1ef0 4 API calls 486 7ff7ec6b241b 485->486 487 7ff7ec6b2485 lstrlenW WriteFile 486->487 487->475 489 7ff7ec6b2300 11 API calls 488->489 490 7ff7ec6b1ec1 489->490 490->471 492 7ff7ec6b1fbf 491->492 494 7ff7ec6b1f27 491->494 492->485 493 7ff7ec6b1f60 CharLowerW CharLowerW 493->494 494->492 494->493 496 7ff7ec6b2119 495->496 496->476

                                                      Callgraph

                                                      • Executed
                                                      • Not Executed
                                                      • Opacity -> Relevance
                                                      • Disassembly available
                                                      callgraph 0 Function_00007FF7EC6B10C0 1 Function_00007FF7EC6B2300 0->1 2 Function_00007FF7EC6B22E0 0->2 3 Function_00007FF7EC6B1000 0->3 1->3 4 Function_00007FF7EC6B1EF0 1->4 5 Function_00007FF7EC6B1FE0 1->5 2->1 5->3
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000012.00000002.3326380333.00007FF7EC6B1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FF7EC6B0000, based on PE: true
                                                      • Associated: 00000012.00000002.3326182929.00007FF7EC6B0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                      • Associated: 00000012.00000002.3326490032.00007FF7EC6B3000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                      • Associated: 00000012.00000002.3326579261.00007FF7EC6B5000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                      • Associated: 00000012.00000002.3326697992.00007FF7EC6C6000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_18_2_7ff7ec6b0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: FilePath$CharCommandFolderKnownLineLowerlstrlen$ArgvCloseCreateExistsExitHandleModuleNameProcessRemoveSpec
                                                      • String ID: ... AFTER ENTRY POINT ...$... BEFORE ENTRY POINT ...$.txt$/protocolUri$ACTION Calling the entry point.$ACTION Exited from the entry point.$C:\Users\user\AppData\Local\CiscoSparkLauncher$C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoSparkLauncher.dll$C:\Users\user\AppData\Local\CiscoSparkLauncher\CiscoSparkLauncher.dll$C:\Users\user\AppData\Local\CiscoSparkLauncher\spark-windows-host-log.txt$Command line: $ERROR can't free the library!$ERROR can't get an entry point:$ERROR can't load library!$ERROR can't set dll directory!$ERROR path not a directory!$Error getting current directory path!$Error getting launcher paths!$Finished successfully, exiting.$Params selected:$SparkEntryPoint$Started in the app loader mode.$Started in the launcher mode.$Trying the launcher in the current directory next!$\CiscoSparkLauncher$\CiscoSparkLauncher.dll$spark-windows-host-log$yyyy'-'MM'-'dd
                                                      • API String ID: 2637395849-467304128
                                                      • Opcode ID: 16c1fe0253baf6c1b6441cc9425430b8c7279993d53a67c79acf9d13edb0a8e2
                                                      • Instruction ID: 8df12357da1339ea3a5c6f6aaeaa0bde23e87b9623cee3e410e7e9019d7540b3
                                                      • Opcode Fuzzy Hash: 16c1fe0253baf6c1b6441cc9425430b8c7279993d53a67c79acf9d13edb0a8e2
                                                      • Instruction Fuzzy Hash: 7D82A06AB18656A1EE66AF25951437BE3B2BF55B84FC44032EA0D07790EF3DE504C322

                                                      Control-flow Graph

                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000012.00000002.3326380333.00007FF7EC6B1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FF7EC6B0000, based on PE: true
                                                      • Associated: 00000012.00000002.3326182929.00007FF7EC6B0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                      • Associated: 00000012.00000002.3326490032.00007FF7EC6B3000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                      • Associated: 00000012.00000002.3326579261.00007FF7EC6B5000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                      • Associated: 00000012.00000002.3326697992.00007FF7EC6C6000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_18_2_7ff7ec6b0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: FileFolderKnownNamePathUserWritelstrlen
                                                      • String ID: 2024-05-24 09:31:34.238 Command line: ****************************\Programs\Cisco Spark\CiscoCollabHost.exe /protocolUri=webex://m$user
                                                      • API String ID: 992006388-2031296764
                                                      • Opcode ID: 6dc9ffa8ca8a6af00f3eac1d72b88296e795163228cb48cadefe63f6b994adec
                                                      • Instruction ID: 56328fdb9597095857f33e67fab078ff0401950c63303b628276324ec56f3105
                                                      • Opcode Fuzzy Hash: 6dc9ffa8ca8a6af00f3eac1d72b88296e795163228cb48cadefe63f6b994adec
                                                      • Instruction Fuzzy Hash: 43419129B1864291E752EF11E9403ABF3A2FF45B94FC44132EA8D43AA5DF3CE445C761

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 323 7ff7ec6b1fe0-7ff7ec6b2113 GetSystemTime GetDateFormatEx GetTimeFormatEx 324 7ff7ec6b22d6-7ff7ec6b22df 323->324 325 7ff7ec6b2119-7ff7ec6b211c 323->325 325->324 326 7ff7ec6b2122-7ff7ec6b215a call 7ff7ec6b1000 325->326 329 7ff7ec6b2160-7ff7ec6b2163 326->329 330 7ff7ec6b216f-7ff7ec6b2188 329->330 331 7ff7ec6b2165-7ff7ec6b216d 329->331 332 7ff7ec6b21cf-7ff7ec6b21e2 call 7ff7ec6b1000 330->332 333 7ff7ec6b218a-7ff7ec6b2194 330->333 331->329 331->330 339 7ff7ec6b21e5-7ff7ec6b21e8 332->339 335 7ff7ec6b21c1-7ff7ec6b21cc 333->335 336 7ff7ec6b2196-7ff7ec6b219e 333->336 335->332 338 7ff7ec6b21a0-7ff7ec6b21a3 336->338 338->335 340 7ff7ec6b21a5-7ff7ec6b21ae 338->340 341 7ff7ec6b21f4-7ff7ec6b2201 339->341 342 7ff7ec6b21ea-7ff7ec6b21f2 339->342 340->335 343 7ff7ec6b21b0-7ff7ec6b21bf 340->343 344 7ff7ec6b224f-7ff7ec6b2265 call 7ff7ec6b1000 341->344 345 7ff7ec6b2203-7ff7ec6b220d 341->345 342->339 342->341 343->335 343->338 352 7ff7ec6b2268-7ff7ec6b226b 344->352 346 7ff7ec6b2241-7ff7ec6b224c 345->346 347 7ff7ec6b220f-7ff7ec6b221c 345->347 346->344 349 7ff7ec6b2220-7ff7ec6b2223 347->349 349->346 351 7ff7ec6b2225-7ff7ec6b222e 349->351 351->346 353 7ff7ec6b2230-7ff7ec6b223f 351->353 354 7ff7ec6b2277-7ff7ec6b2284 352->354 355 7ff7ec6b226d-7ff7ec6b2275 352->355 353->346 353->349 356 7ff7ec6b2286-7ff7ec6b228d 354->356 357 7ff7ec6b22be-7ff7ec6b22ce 354->357 355->352 355->354 358 7ff7ec6b228f 356->358 359 7ff7ec6b22b0-7ff7ec6b22bb 356->359 357->324 360 7ff7ec6b2292-7ff7ec6b2295 358->360 359->357 360->359 361 7ff7ec6b2297-7ff7ec6b229e 360->361 361->359 362 7ff7ec6b22a0-7ff7ec6b22ae 361->362 362->359 362->360
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000012.00000002.3326380333.00007FF7EC6B1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FF7EC6B0000, based on PE: true
                                                      • Associated: 00000012.00000002.3326182929.00007FF7EC6B0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                      • Associated: 00000012.00000002.3326490032.00007FF7EC6B3000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                      • Associated: 00000012.00000002.3326579261.00007FF7EC6B5000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                      • Associated: 00000012.00000002.3326697992.00007FF7EC6C6000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_18_2_7ff7ec6b0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: FormatTime$DateSystem
                                                      • String ID: 2024-05-24 09:31:34.238 Command line: ****************************\Programs\Cisco Spark\CiscoCollabHost.exe /protocolUri=webex://m$Command line: $HH':'mm':'ss$yyyy'-'MM'-'dd
                                                      • API String ID: 1287002481-1393603062
                                                      • Opcode ID: decc9423b643febfd1fd6e913434b86d0734c1dafc43bd95b90f999db1a7dfb7
                                                      • Instruction ID: d441f948ba46839978618ad7057543be7c6276b6ef9c38053605fad12b29e891
                                                      • Opcode Fuzzy Hash: decc9423b643febfd1fd6e913434b86d0734c1dafc43bd95b90f999db1a7dfb7
                                                      • Instruction Fuzzy Hash: 8971A22AB18B8141DA169F64A4143BBB3A1FF94780FD48136DB4D47754EF3DE505C721

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 363 7ff7ec6b1ef0-7ff7ec6b1f21 lstrlenW * 2 364 7ff7ec6b1fd3-7ff7ec6b1fdd 363->364 365 7ff7ec6b1f27-7ff7ec6b1f33 363->365 366 7ff7ec6b1f39-7ff7ec6b1f4c 365->366 367 7ff7ec6b1fce 365->367 368 7ff7ec6b1f50-7ff7ec6b1f54 366->368 367->364 369 7ff7ec6b1f56-7ff7ec6b1f59 368->369 370 7ff7ec6b1fb9-7ff7ec6b1fbd 368->370 371 7ff7ec6b1f60-7ff7ec6b1f96 CharLowerW * 2 369->371 370->368 372 7ff7ec6b1fbf-7ff7ec6b1fc9 370->372 371->370 373 7ff7ec6b1f98-7ff7ec6b1f9d 371->373 372->367 374 7ff7ec6b1faf-7ff7ec6b1fb7 373->374 375 7ff7ec6b1f9f 373->375 374->370 374->371 376 7ff7ec6b1fa1-7ff7ec6b1fad 375->376 376->374 376->376
                                                      APIs
                                                      Strings
                                                      • 2024-05-24 09:31:34.238 Command line: ****************************\Programs\Cisco Spark\CiscoCollabHost.exe /protocolUri=webex://m, xrefs: 00007FF7EC6B1EFF
                                                      Memory Dump Source
                                                      • Source File: 00000012.00000002.3326380333.00007FF7EC6B1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FF7EC6B0000, based on PE: true
                                                      • Associated: 00000012.00000002.3326182929.00007FF7EC6B0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                      • Associated: 00000012.00000002.3326490032.00007FF7EC6B3000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                      • Associated: 00000012.00000002.3326579261.00007FF7EC6B5000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                      • Associated: 00000012.00000002.3326697992.00007FF7EC6C6000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_18_2_7ff7ec6b0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: CharLowerlstrlen
                                                      • String ID: 2024-05-24 09:31:34.238 Command line: ****************************\Programs\Cisco Spark\CiscoCollabHost.exe /protocolUri=webex://m
                                                      • API String ID: 1209591262-3915043629
                                                      • Opcode ID: c1cf02e9cc5d1723317c7d3565c6da6131a0355b74d2a8d859d15882c53e57fc
                                                      • Instruction ID: c0277aa917b195d29e7ff10cc85883810657afe08214f319ace7ec71c15adb66
                                                      • Opcode Fuzzy Hash: c1cf02e9cc5d1723317c7d3565c6da6131a0355b74d2a8d859d15882c53e57fc
                                                      • Instruction Fuzzy Hash: 0121713BA1874596D711AB51E44422BF7FAFB88B84F800132FE8943664EF3CE555CB15

                                                      Execution Graph

                                                      Execution Coverage:16%
                                                      Dynamic/Decrypted Code Coverage:0%
                                                      Signature Coverage:19.2%
                                                      Total number of Nodes:1533
                                                      Total number of Limit Nodes:176
                                                      execution_graph 7994 7ffde6625bd0 7995 7ffde66283f0 7994->7995 7996 7ffde6625bf7 GetDC EnumFontFamiliesExW ReleaseDC 7995->7996 7997 7ffde6629e70 7996->7997 7998 7ffde6625c43 ?family@QFont@@QEBA?AVQString@ ??1QFont@@QEAA ?resolveFontFamilyAlias@QPlatformFontDatabase@@UEBA?AVQString@@AEBV2@ ??8@YA_NAEBVQString@@0 ??1?$QVector@VQPointF@@@@QEAA 7997->7998 7999 7ffde6625c8f ?registerFontFamily@QPlatformFontDatabase@@SAXAEBVQString@@ 7998->7999 8000 7ffde6625c9a 7998->8000 7999->8000 8004 7ffde66259b0 ??0QWinRegistryKey@@QEAA@PEAUHKEY__@@VQStringView@@KK ?stringValue@QWinRegistryKey@@QEBA?AVQString@@VQStringView@@ ??1QWinRegistryKey@@QEAA 8000->8004 8002 7ffde6625ca2 ??1?$QVector@VQPointF@@@@QEAA 8003 7ffde6625cbd 8002->8003 8005 7ffde6625baf ??1?$QVector@VQPointF@@@@QEAA 8004->8005 8006 7ffde6625a46 ??0QFile@@QEAA@AEBVQString@@ ?open@QFile@@UEAA_NV?$QFlags@W4OpenModeFlag@QIODevice@@@@ 8004->8006 8005->8002 8007 7ffde6625a67 8006->8007 8008 7ffde6625adc ?readAll@QIODevice@@QEAA?AVQByteArray@ 8006->8008 8009 7ffde6625a6c ?isWarningEnabled@QLoggingCategory@ 8007->8009 8015 7ffde6625b10 8008->8015 8010 7ffde6625acd ??1QFile@@UEAA 8009->8010 8011 7ffde6625a79 8009->8011 8010->8005 8012 7ffde6625a7e ??0QMessageLogger@@QEAA@PEBDH00 ?warning@QMessageLogger@@QEBA?AVQDebug@ ??6QDebug@@QEAAAEAV0@PEBD ??6QDebug@@QEAAAEAV0@AEBVQString@@ ??1QDebug@@QEAA 8011->8012 8012->8010 8013 7ffde6625b93 ??1?$QVector@VQPointF@@@@QEAA ??1QFile@@UEAA 8013->8005 8014 7ffde6625b82 ?dispose@QListData@@SAXPEAUData@1@ 8014->8013 8015->8013 8015->8014 9588 7ffde626fc90 9591 7ffde626fda0 9588->9591 9592 7ffde626fdcc 9591->9592 9594 7ffde626fcaf 9591->9594 9599 7ffde64dba08 9592->9599 9595 7ffde626fde4 9596 7ffde626fda0 2 API calls 9595->9596 9597 7ffde626fe1b 9596->9597 9598 7ffde626fda0 2 API calls 9597->9598 9598->9594 9600 7ffde64dba22 malloc 9599->9600 9601 7ffde64dba2c 9600->9601 9602 7ffde64dba13 9600->9602 9601->9595 9602->9600 9603 7ffde64dba32 9602->9603 9604 7ffde64dc984 Concurrency::cancel_current_task _CxxThrowException 9603->9604 9605 7ffde64dba3d 9603->9605 9604->9605 9605->9595 8045 7ffde65d2cc1 IsIconic 8046 7ffde65d2cd3 8045->8046 8048 7ffde65d23ae 8045->8048 8046->8048 8049 7ffde65c7ff0 8046->8049 8065 7ffde65c4160 8049->8065 8051 7ffde65c8011 ?marginsRemoved@QRect@@QEBA?AV1@AEBVQMargins@@ 8053 7ffde65c8086 ?window@QPlatformWindow@@QEBAPEAVQWindow@ ??$handleGeometryChange@UDefaultDelivery@QWindowSystemInterface@@@QWindowSystemInterface@@SAXPEAVQWindow@@AEBVQRect@@ 8051->8053 8056 7ffde65c8050 8051->8056 8054 7ffde65c80a6 8053->8054 8055 7ffde65c80e4 8053->8055 8054->8055 8057 7ffde65c80bd ?size@QRect@@QEBA?AVQSize@ 8054->8057 8058 7ffde65c812c ?flushWindowSystemEvents@QWindowSystemInterface@@SA_NV?$QFlags@W4ProcessEventsFlag@QEventLoop@@@@ 8055->8058 8059 7ffde65c8137 8055->8059 8056->8053 8060 7ffde65c820f 8056->8060 8057->8055 8058->8059 8061 7ffde65c8147 ?isDebugEnabled@QLoggingCategory@ 8059->8061 8060->8048 8061->8060 8062 7ffde65c8158 ?window@QPlatformWindow@@QEBAPEAVQWindow@ 8061->8062 8063 7ffde65cf540 8062->8063 8064 7ffde65c8169 8 API calls 8063->8064 8064->8060 8066 7ffde65c4199 8065->8066 8067 7ffde65c4238 GetWindowRect GetParent 8066->8067 8068 7ffde65c41bf GetWindowPlacement 8066->8068 8070 7ffde65c4256 8067->8070 8071 7ffde65c42b1 ??0QRect@@QEAA@AEBVQPoint@@AEBVQSize@@ 8067->8071 8068->8067 8069 7ffde65c41d9 ??0QRect@@QEAA@AEBVQPoint@@AEBVQSize@@ 8068->8069 8074 7ffde65c1bf0 8069->8074 8070->8071 8072 7ffde65c425b ScreenToClient GetWindowLongPtrW 8070->8072 8076 7ffde65c4305 8071->8076 8072->8071 8075 7ffde65c429c GetClientRect 8072->8075 8077 7ffde65c4223 ?translated@QRect@@QEBA?AV1@AEBVQPoint@@ 8074->8077 8075->8071 8076->8051 8077->8076 8078 7ffde65cdcc2 8081 7ffde66090a0 8078->8081 8080 7ffde65cdcc9 8082 7ffde6609103 8081->8082 8083 7ffde66090d3 ??0QMessageLogger@@QEAA@PEBDH0 ?warning@QMessageLogger@ 8081->8083 8111 7ffde6608bf0 8082->8111 8085 7ffde6609260 8083->8085 8085->8080 8086 7ffde660910f 8087 7ffde6609143 8086->8087 8088 7ffde6609113 ??0QMessageLogger@@QEAA@PEBDH0 ?warning@QMessageLogger@ 8086->8088 8089 7ffde6609160 ?isDebugEnabled@QLoggingCategory@ 8087->8089 8088->8085 8090 7ffde660916d 8089->8090 8091 7ffde66091c1 ?fromLatin1@QString@@SA?AV1@PEBDH ?utf16@QString@ LoadLibraryW ??1?$QVector@VQPointF@@@@QEAA 8089->8091 8095 7ffde6609172 ??0QMessageLogger@@QEAA@PEBDH00 ?debug@QMessageLogger@@QEBA?AVQDebug@ ??6QDebug@@QEAAAEAV0@PEBD ??6QDebug@@QEAAAEAV0@PEBD ??1QDebug@@QEAA 8090->8095 8092 7ffde660921e GetLastError ?qErrnoWarning@ 8091->8092 8093 7ffde6609291 GetProcAddress 8091->8093 8096 7ffde6609237 ??0QMessageLogger@@QEAA@PEBDH0 8092->8096 8094 7ffde66092b8 GetProcAddress 8093->8094 8100 7ffde6609306 8093->8100 8097 7ffde66092d4 GetProcAddress 8094->8097 8094->8100 8095->8091 8098 7ffde6609250 ?warning@QMessageLogger@ 8096->8098 8099 7ffde66092f0 GetProcAddress 8097->8099 8097->8100 8098->8085 8099->8100 8100->8096 8110 7ffde6609336 8100->8110 8101 7ffde6609501 8103 7ffde660958f 8101->8103 8105 7ffde660952a ??0QMessageLogger@@QEAA@PEBDH0 ?warning@QMessageLogger@ 8101->8105 8102 7ffde66094e3 ??0QMessageLogger@@QEAA@PEBDH0 8102->8098 8104 7ffde6609594 ?isDebugEnabled@QLoggingCategory@ 8103->8104 8104->8085 8106 7ffde66095a5 8104->8106 8105->8085 8109 7ffde6609571 ??0QMessageLogger@@QEAA@PEBDH0 8105->8109 8108 7ffde66095aa 10 API calls 8106->8108 8108->8085 8109->8098 8110->8101 8110->8102 8112 7ffde65cf5d0 8111->8112 8113 7ffde6608c2e ?isDebugEnabled@QLoggingCategory@ 8112->8113 8114 7ffde6608c93 ?fromLatin1@QString@@SA?AV1@PEBDH ?utf16@QString@ LoadLibraryW ??1?$QVector@VQPointF@@@@QEAA 8113->8114 8115 7ffde6608c3b 8113->8115 8116 7ffde6608d08 GetProcAddress 8114->8116 8117 7ffde6608cd9 GetLastError ?qErrnoWarning@ 8114->8117 8121 7ffde6608c40 ??0QMessageLogger@@QEAA@PEBDH00 ?debug@QMessageLogger@@QEBA?AVQDebug@ ??6QDebug@@QEAAAEAV0@PEBD ??6QDebug@@QEAAAEAV0@PEBD ??1QDebug@@QEAA 8115->8121 8119 7ffde6608d33 8116->8119 8120 7ffde6608d24 GetProcAddress 8116->8120 8118 7ffde6608cf3 8117->8118 8118->8086 8122 7ffde6608d54 8119->8122 8123 7ffde6608d45 GetProcAddress 8119->8123 8120->8119 8121->8114 8124 7ffde6608d75 8122->8124 8125 7ffde6608d66 GetProcAddress 8122->8125 8123->8122 8126 7ffde6608d96 8124->8126 8127 7ffde6608d87 GetProcAddress 8124->8127 8125->8124 8128 7ffde6608db7 8126->8128 8129 7ffde6608da8 GetProcAddress 8126->8129 8127->8126 8130 7ffde6608dd8 8128->8130 8131 7ffde6608dc9 GetProcAddress 8128->8131 8129->8128 8132 7ffde6608df9 8130->8132 8133 7ffde6608dea GetProcAddress 8130->8133 8131->8130 8134 7ffde6608e1a 8132->8134 8135 7ffde6608e0b GetProcAddress 8132->8135 8133->8132 8136 7ffde6608e3b 8134->8136 8137 7ffde6608e2c GetProcAddress 8134->8137 8135->8134 8138 7ffde6608e4d GetProcAddress 8136->8138 8139 7ffde6608e5c 8136->8139 8137->8136 8138->8139 8140 7ffde6608e7d 8139->8140 8141 7ffde6608e6e GetProcAddress 8139->8141 8142 7ffde6608e9e 8140->8142 8143 7ffde6608e8f GetProcAddress 8140->8143 8141->8140 8144 7ffde6608ebf 8142->8144 8145 7ffde6608eb0 GetProcAddress 8142->8145 8143->8142 8146 7ffde6608ee0 8144->8146 8147 7ffde6608ed1 GetProcAddress 8144->8147 8145->8144 8148 7ffde6608f01 8146->8148 8149 7ffde6608ef2 GetProcAddress 8146->8149 8147->8146 8150 7ffde6608f13 GetProcAddress 8148->8150 8151 7ffde6608f22 8148->8151 8149->8148 8150->8151 8152 7ffde6608f46 8151->8152 8153 7ffde6608f37 GetProcAddress 8151->8153 8154 7ffde6608f5b GetProcAddress 8152->8154 8155 7ffde6608f6a 8152->8155 8153->8152 8154->8155 8155->8086 8155->8118 8173 7ffde65ce5c0 ??8QString@@QEBA_NVQLatin1String@@ 8174 7ffde65ce605 8173->8174 8175 7ffde65ce6a3 ?createPlatformTheme@QPlatformIntegration@@UEBAPEAVQPlatformTheme@@AEBVQString@@ 8173->8175 8176 7ffde65ce60f ??0QPlatformTheme@@QEAA memset 8174->8176 8177 7ffde65ce685 8176->8177 8180 7ffde65f0120 8177->8180 8179 7ffde65ce68d 8181 7ffde65efec0 8180->8181 8182 7ffde65f014b ?desktopSettingsAware@QGuiApplication@ 8181->8182 8183 7ffde65f086c 8182->8183 8184 7ffde65f0159 8182->8184 8183->8179 8230 7ffde65d1f20 8184->8230 8186 7ffde65f01b2 8236 7ffde65cf4b0 8186->8236 8188 7ffde65f01b7 ?isDebugEnabled@QLoggingCategory@ 8189 7ffde65f01c4 8188->8189 8190 7ffde65f0230 ?fromWCharArray@QString@@SA?AV1@PEB_WH ??0QFont@@QEAA@AEBVQString@@HH_N ??1?$QVector@VQPointF@@@@QEAA ?setItalic@QFont@@QEAAX_N 8188->8190 8191 7ffde65cf4b0 2 API calls 8189->8191 8192 7ffde65f02a5 8 API calls 8190->8192 8193 7ffde65f0292 ?weightFromInteger@QPlatformFontDatabase@@SA?AW4Weight@QFont@@H ?setWeight@QFont@@QEAAXH 8190->8193 8195 7ffde65f01c9 ??0QMessageLogger@@QEAA@PEBDH00 ?debug@QMessageLogger@@QEBA?AVQDebug@ ??6QDebug@@QEAAAEAV0@PEBD 8191->8195 8196 7ffde65f0384 8 API calls 8192->8196 8197 7ffde65f0371 ?weightFromInteger@QPlatformFontDatabase@@SA?AW4Weight@QFont@@H ?setWeight@QFont@@QEAAXH 8192->8197 8193->8192 8198 7ffde65eff40 8195->8198 8201 7ffde65f045b 8 API calls 8196->8201 8202 7ffde65f0448 ?weightFromInteger@QPlatformFontDatabase@@SA?AW4Weight@QFont@@H ?setWeight@QFont@@QEAAXH 8196->8202 8197->8196 8200 7ffde65f021c ??1QDebug@@QEAA ??1QDebug@@QEAA 8198->8200 8200->8190 8204 7ffde65f0532 13 API calls 8201->8204 8205 7ffde65f051f ?weightFromInteger@QPlatformFontDatabase@@SA?AW4Weight@QFont@@H ?setWeight@QFont@@QEAAXH 8201->8205 8202->8201 8207 7ffde65f064a ?weightFromInteger@QPlatformFontDatabase@@SA?AW4Weight@QFont@@H ?setWeight@QFont@@QEAAXH 8204->8207 8209 7ffde65f065d ?setPointSizeF@QFont@@QEAAXN ?setUnderline@QFont@@QEAAX_N ?setOverline@QFont@@QEAAX_N ?setStrikeOut@QFont@@QEAAX_N 8204->8209 8205->8204 8207->8209 8210 7ffde65f06c5 8209->8210 8211 7ffde65f06de ??0QFont@@QEAA@AEBV0@ 8210->8211 8212 7ffde66c5438 8211->8212 8213 7ffde65f06fd ??0QFont@@QEAA@AEBV0@ 8212->8213 8214 7ffde66c5438 8213->8214 8215 7ffde65f071c ??0QFont@@QEAA@AEBV0@ 8214->8215 8216 7ffde66c5438 8215->8216 8217 7ffde65f073b ??0QFont@@QEAA@AEBV0@ 8216->8217 8218 7ffde66c5438 8217->8218 8219 7ffde65f075a ??0QFont@@QEAA@AEBV0@ 8218->8219 8220 7ffde66c5438 8219->8220 8221 7ffde65f0779 ??0QFont@@QEAA@AEBV0@ 8220->8221 8222 7ffde66c5438 8221->8222 8223 7ffde65f0798 ??0QFont@@QEAA@AEBV0@ 8222->8223 8224 7ffde66c5438 8223->8224 8225 7ffde65f07b7 ??0QFont@@QEAA@AEBV0@ 8224->8225 8226 7ffde66c5438 8225->8226 8227 7ffde65f07d6 7 API calls 8226->8227 8228 7ffde65f0849 8227->8228 8229 7ffde65f085a ?deallocate@QArrayData@@SAXPEAU1@_K1 8227->8229 8228->8183 8228->8229 8229->8183 8231 7ffde65d1f35 memset 8230->8231 8233 7ffde65d1fb5 8231->8233 8234 7ffde65d1fe3 SystemParametersInfoW 8231->8234 8233->8234 8235 7ffde65d1fb9 SystemParametersInfoForDpi 8233->8235 8234->8186 8235->8186 8237 7ffde65cf4d9 8236->8237 8238 7ffde65cf4e6 8236->8238 8237->8188 8238->8237 8239 7ffde65cf4fb ??0QLoggingCategory@@QEAA@PEBD 8238->8239 8240 7ffde66c57dc 8239->8240 8241 7ffde65cf51e _Init_thread_footer 8240->8241 8241->8188 8242 7ffde6620bc0 ?compare@QString@@SAHAEBV1@VQLatin1String@@W4CaseSensitivity@Qt@@ 8243 7ffde6620cad 8242->8243 8244 7ffde6620c04 8242->8244 8252 7ffde65ccbd0 8244->8252 8250 7ffde6620c5b 8251 7ffde6620c85 ??0QPlatformNativeInterface@@QEAA 8250->8251 8253 7ffde65ccbf8 8252->8253 8318 7ffde65d02e0 ??0QLocale@@QEAA memset 8253->8318 8256 7ffde65ccc59 9 API calls 8258 7ffde65ccd84 8256->8258 8257 7ffde65ccc2c ?fromLocal8Bit@QString@@SA?AV1@AEBVQByteArray@@ ?setFilterRules@QLoggingCategory@@SAXAEBVQString@@ ??1?$QVector@VQPointF@@@@QEAA 8257->8256 8259 7ffde65ccd9f ?current@QOperatingSystemVersion@@SA?AV1 8258->8259 8262 7ffde65cce40 8258->8262 8260 7ffde65ccdc7 8259->8260 8261 7ffde65ccdb7 ?compare@QOperatingSystemVersion@@CAHAEBV1@0 8259->8261 8260->8262 8278 7ffde65cce2b ?setAttribute@QCoreApplication@@SAXW4ApplicationAttribute@Qt@@_N 8260->8278 8261->8260 8261->8262 8263 7ffde65cce90 8262->8263 8264 7ffde65cce60 DestroyWindow 8262->8264 8265 7ffde65cceba ?testAttribute@QCoreApplication@@SA_NW4ApplicationAttribute@Qt@@ 8263->8265 8266 7ffde65ccfa1 8263->8266 8270 7ffde65cce83 8264->8270 8265->8266 8269 7ffde65ccecd 8265->8269 8352 7ffde65d0ac0 8266->8352 8334 7ffde65d0f20 8269->8334 8270->8263 8271 7ffde65ccfb3 ?setCapability@QPlatformCursor@@SAXW4Capability@1@ 8365 7ffde65d0d90 8271->8365 8275 7ffde65ccfc6 8284 7ffde660e3f0 8275->8284 8276 7ffde65cf4b0 2 API calls 8277 7ffde65ccee0 ?isDebugEnabled@QLoggingCategory@ 8276->8277 8277->8266 8279 7ffde65ccef1 8277->8279 8278->8263 8280 7ffde65cf4b0 2 API calls 8279->8280 8281 7ffde65ccef6 6 API calls 8280->8281 8282 7ffde65ccf88 ??6QDebug@@QEAAAEAV0@H ??1QDebug@@QEAA 8281->8282 8283 7ffde65ccf6d 8281->8283 8282->8266 8283->8282 8419 7ffde65d1b10 8284->8419 8286 7ffde660e42c ??1?$QVector@VQPointF@@@@QEAA 8287 7ffde660e474 8286->8287 8291 7ffde660e447 8286->8291 8288 7ffde660e488 8287->8288 8289 7ffde660e47a SetClipboardViewer 8287->8289 8290 7ffde660e48d ?isDebugEnabled@QLoggingCategory@ 8288->8290 8289->8288 8292 7ffde660e49e 8290->8292 8293 7ffde660e53f 8290->8293 8291->8287 8294 7ffde660e467 ?qErrnoWarning@ 8291->8294 8295 7ffde660e4a3 10 API calls 8292->8295 8296 7ffde65d66a0 EnumDisplayMonitors 8293->8296 8294->8287 8295->8293 8314 7ffde65d66ec 8296->8314 8297 7ffde65d6af3 8298 7ffde65d6b1b ?updateHighDpiScaling@QHighDpiScaling@ 8297->8298 8300 7ffde65f0120 83 API calls 8297->8300 8302 7ffde65d6b2f 8298->8302 8299 7ffde65d6780 ??8@YA_NAEBVQString@@0 8299->8314 8300->8298 8301 7ffde65d6b98 8301->8250 8302->8301 8303 7ffde65d6b86 ?deallocate@QArrayData@@SAXPEAU1@_K1 8302->8303 8306 7ffde65d6b70 ??1?$QVector@VQPointF@@@@QEAA 8302->8306 8303->8301 8304 7ffde65d67c0 ??0QPlatformScreen@@QEAA 8304->8314 8305 7ffde65d6aa0 ??8@YA_NAEBVQString@@0 8308 7ffde65d6a31 8305->8308 8306->8303 8306->8306 8307 7ffde65d67ec ??0QPlatformCursor@@QEAA ??0QPixmap@@QEAA ??0QPixmap@@QEAA ??0QPixmap@@QEAA ??0QPixmap@@QEAA 8307->8314 8308->8297 8308->8305 8309 7ffde65d686c ?qRegisterResourceData@@YA_NHPEBE00 _Init_thread_footer 8309->8314 8310 7ffde65d691a ?handleScreenAdded@QWindowSystemInterface@@SAXPEAVQPlatformScreen@@_N 8311 7ffde65cf4b0 2 API calls 8310->8311 8312 7ffde65d6949 ?isDebugEnabled@QLoggingCategory@ 8311->8312 8312->8314 8313 7ffde65d69ab ??0QMessageLogger@@QEAA@PEBDH00 ?debug@QMessageLogger@@QEBA?AVQDebug@ ??6QDebug@@QEAAAEAV0@PEBD 8313->8314 8314->8299 8314->8304 8314->8307 8314->8308 8314->8309 8314->8310 8314->8313 8315 7ffde65d6a05 ??1QDebug@@QEAA ??1QDebug@@QEAA 8314->8315 8316 7ffde65d697f ??0QLoggingCategory@@QEAA@PEBD 8314->8316 8317 7ffde65d699f _Init_thread_footer 8314->8317 8315->8314 8316->8314 8317->8313 8319 7ffde66c5438 8318->8319 8320 7ffde65d0370 ?connectImpl@QObject@@CA?AVConnection@QMetaObject@@PEBV1@PEAPEAX01PEAVQSlotObjectBase@QtPrivate@@W4ConnectionType@Qt@@PEBHPEBU3@ ??1Connection@QMetaObject@@QEAA 8319->8320 8321 7ffde65d7950 8320->8321 8322 7ffde65d03d7 OleInitializeWOW 8321->8322 8323 7ffde65d04ee 8322->8323 8324 7ffde65d0509 GetDC GetDeviceCaps GetKeyboardLayoutList 8323->8324 8325 7ffde65d0538 8324->8325 8332 7ffde65d0565 8324->8332 8327 7ffde65d0553 GetKeyboardLayoutList 8325->8327 8327->8332 8329 7ffde65ccc00 ?qgetenv@@YA?AVQByteArray@@PEBD 8329->8256 8329->8257 8330 7ffde65d05c3 ??0QMessageLogger@@QEAA@PEBDH0 ?warning@QMessageLogger@@QEBA?AVQDebug@ ??6QDebug@@QEAAAEAV0@PEBD 8331 7ffde65d1c30 8330->8331 8333 7ffde65d060e ??6QDebug@@QEAAAEAV0@AEBVQByteArray@@ ??1?$QVector@VQPointF@@@@QEAA ??1QDebug@@QEAA 8331->8333 8374 7ffde65f1f00 ??0QOperatingSystemVersion@@QEAA@W4OSType@0@HHH ?current@QOperatingSystemVersion@@SA?AV1 8332->8374 8333->8329 8335 7ffde65cf4b0 2 API calls 8334->8335 8336 7ffde65d0f31 ?isDebugEnabled@QLoggingCategory@ 8335->8336 8337 7ffde65d0f93 8336->8337 8338 7ffde65d0f3e 8336->8338 8341 7ffde65d10cd 8337->8341 8342 7ffde65d0fbf 8337->8342 8339 7ffde65cf4b0 2 API calls 8338->8339 8340 7ffde65d0f43 ??0QMessageLogger@@QEAA@PEBDH00 ?debug@QMessageLogger@@QEBA?AVQDebug@ ??6QDebug@@QEAAAEAV0@PEBD ??6QDebug@@QEAAAEAV0@H ??1QDebug@@QEAA 8339->8340 8340->8337 8343 7ffde65ccedb 8341->8343 8344 7ffde65d10e7 ?qErrnoWarning@ 8341->8344 8342->8343 8345 7ffde65d0ff3 6 API calls 8342->8345 8346 7ffde65cf4b0 2 API calls 8342->8346 8343->8276 8347 7ffde65d1c30 8345->8347 8348 7ffde65d0fe2 ?isDebugEnabled@QLoggingCategory@ 8346->8348 8349 7ffde65d105e ??6QDebug@@QEAAAEAV0@AEBVQByteArray@@ ??6QDebug@@QEAAAEAV0@PEBD 8347->8349 8348->8343 8348->8345 8350 7ffde65d1089 ??6QDebug@@QEAAAEAV0@H ??1?$QVector@VQPointF@@@@QEAA ??1QDebug@@QEAA 8349->8350 8350->8343 8353 7ffde65d0ae1 8352->8353 8362 7ffde65d0ba2 8352->8362 8354 7ffde65d0ae5 8353->8354 8355 7ffde65d0b04 8353->8355 8358 7ffde65d0af4 8354->8358 8380 7ffde65d9b30 GetSystemMetrics 8354->8380 8357 7ffde65d9b30 24 API calls 8355->8357 8355->8358 8357->8358 8359 7ffde65d0b26 8358->8359 8360 7ffde65d0b5a ?registerTouchDevice@QWindowSystemInterface@@SAXPEBVQTouchDevice@@ 8358->8360 8361 7ffde65d0b3e ?options@QSurfaceFormat@@QEBA?AV?$QFlags@W4FormatOption@QSurfaceFormat@@@ ?setCapabilities@QTouchDevice@@QEAAXV?$QFlags@W4CapabilityFlag@QTouchDevice@@@@ 8358->8361 8359->8271 8360->8362 8363 7ffde65d0b75 8360->8363 8361->8360 8362->8271 8363->8362 8364 7ffde65d0bbf ?nextNode@QHashData@@SAPEAUNode@1@PEAU21@ 8363->8364 8364->8362 8364->8363 8366 7ffde65d0f09 8365->8366 8367 7ffde65d0dad 8365->8367 8366->8275 8368 7ffde65d0dc5 ??0QByteArray@@QEAA@AEBV0@ ??YQString@@QEAAAEAV0@AEBV0@ 8367->8368 8389 7ffde65d14c0 GetModuleHandleW ?utf16@QString@ GetClassInfoW 8368->8389 8370 7ffde65d0e1b 6 API calls 8370->8366 8371 7ffde65d0ecc RegisterPowerSettingNotification 8370->8371 8372 7ffde65d0f12 8371->8372 8373 7ffde65d0ef2 DestroyWindow 8371->8373 8372->8275 8373->8366 8375 7ffde65f1f4c SystemParametersInfoW 8374->8375 8376 7ffde65f1f38 ?compare@QOperatingSystemVersion@@CAHAEBV1@0 8374->8376 8378 7ffde65f1f73 ??0QWinRegistryKey@@QEAA@PEAUHKEY__@@VQStringView@@KK ?dwordValue@QWinRegistryKey@@QEBA?AU?$QPair@K_N@@VQStringView@@ ??1QWinRegistryKey@@QEAA 8375->8378 8379 7ffde65f1f63 8375->8379 8376->8375 8377 7ffde65d05b3 8376->8377 8377->8329 8377->8330 8378->8377 8379->8377 8379->8378 8381 7ffde65d9b47 8380->8381 8382 7ffde65d9b4f GetSystemMetrics GetSystemMetrics 8380->8382 8381->8358 8383 7ffde65cf540 8382->8383 8384 7ffde65d9b78 ?isDebugEnabled@QLoggingCategory@ 8383->8384 8385 7ffde65d9b89 8384->8385 8386 7ffde65d9c79 8384->8386 8387 7ffde65d9b8e 15 API calls 8385->8387 8388 7ffde65d9c83 ??0QTouchDevice@@QEAA ?setType@QTouchDevice@@QEAAXW4DeviceType@1@ ?type@QTouchDevice@@QEBA?AW4DeviceType@1 ?setCapabilities@QTouchDevice@@QEAAXV?$QFlags@W4CapabilityFlag@QTouchDevice@@@@ ?setMaximumTouchPoints@QTouchDevice@@QEAAXH 8386->8388 8387->8386 8388->8358 8390 7ffde65d1573 8389->8390 8391 7ffde65d153e 8389->8391 8393 7ffde65d1583 ?qHash@@YAIAEBVQString@@I 8390->8393 8395 7ffde65d1592 8390->8395 8391->8390 8392 7ffde65d1544 ?createUuid@QUuid@@SA?AV1 ?toString@QUuid@@QEBA?AVQString@ ??YQString@@QEAAAEAV0@AEBV0@ ??1?$QVector@VQPointF@@@@QEAA 8391->8392 8392->8390 8393->8395 8394 7ffde65d18d4 ??0QByteArray@@QEAA@$$QEAV0@ ??1?$QVector@VQPointF@@@@QEAA 8400 7ffde65d18f8 8394->8400 8395->8394 8396 7ffde65d15e6 LoadImageW 8395->8396 8399 7ffde65d1678 8395->8399 8397 7ffde65d1614 GetSystemMetrics GetSystemMetrics LoadImageW 8396->8397 8398 7ffde65d1650 LoadImageW 8396->8398 8401 7ffde65d1681 ?utf16@QString@ RegisterClassExW 8397->8401 8398->8399 8399->8401 8400->8370 8402 7ffde65d16a6 ?toLocal8Bit@QString@@QEGBA?AVQByteArray@ ?constData@QString@@QEBAPEBVQChar@ ?qErrnoWarning@ ??1?$QVector@VQPointF@@@@QEAA 8401->8402 8403 7ffde65d16d8 8401->8403 8402->8403 8404 7ffde65d16e7 ?detach_helper@QHashData@@QEAAPEAU1@P6AXPEAUNode@1@PEAX@ZP6AX0@ZHH 8403->8404 8405 7ffde65d1744 ?qHash@@YAIAEBVQString@@I 8403->8405 8407 7ffde65d171b 8404->8407 8408 7ffde65d172f ?free_helper@QHashData@@QEAAXP6AXPEAUNode@1@@Z 8404->8408 8406 7ffde65d1766 8405->8406 8410 7ffde65d17c1 8406->8410 8411 7ffde65d1772 ?willGrow@QHashData@ 8406->8411 8407->8408 8409 7ffde65d1740 8407->8409 8408->8409 8409->8405 8414 7ffde65cf4b0 2 API calls 8410->8414 8412 7ffde65d177c 8411->8412 8413 7ffde65d178e ?allocateNode@QHashData@@QEAAPEAXH ??0QByteArray@@QEAA@AEBV0@ 8411->8413 8412->8413 8413->8410 8415 7ffde65d17c6 ?isDebugEnabled@QLoggingCategory@ 8414->8415 8415->8394 8416 7ffde65d17d7 8415->8416 8417 7ffde65cf4b0 2 API calls 8416->8417 8418 7ffde65d17dc 16 API calls 8417->8418 8418->8394 8420 7ffde65d1100 8419->8420 8421 7ffde65d1b43 ??0QByteArray@@QEAA@AEBV0@ ??YQString@@QEAAAEAV0@AEBV0@ 8420->8421 8422 7ffde65d14c0 46 API calls 8421->8422 8423 7ffde65d1b8f ??1?$QVector@VQPointF@@@@QEAA GetModuleHandleW ?utf16@QString@ CreateWindowExW ??1?$QVector@VQPointF@@@@QEAA 8422->8423 8423->8286 8718 7ffde660c2b0 8719 7ffde65cf9c0 8718->8719 8720 7ffde660c2cc ?isDebugEnabled@QLoggingCategory@ 8719->8720 8721 7ffde660c2dd 8720->8721 8722 7ffde660c383 ?cacheKey@QIcon@ ?cacheKey@QIcon@ 8720->8722 8724 7ffde660c2e2 6 API calls 8721->8724 8723 7ffde660c3a2 ?isNull@QIcon@ 8722->8723 8734 7ffde660c5ce 8722->8734 8725 7ffde660c43f 8723->8725 8726 7ffde660c3c3 GetSystemMetrics GetSystemMetrics ?actualSize@QIcon@@QEBA?AVQSize@@AEBV2@W4Mode@1@W4State@1@ ?pixmap@QIcon@@QEBA?AVQPixmap@@AEBVQSize@@W4Mode@1@W4State@1@ ?isNull@QPixmap@ 8723->8726 8727 7ffde660d6c0 8724->8727 8730 7ffde660c5b3 8725->8730 8733 7ffde660c5c0 8725->8733 8748 7ffde660bdc0 8725->8748 8728 7ffde660c435 ??1QPixmap@@UEAA 8726->8728 8729 7ffde660c427 ?qt_pixmapToWinHICON@@YAPEAUHICON__@@AEBVQPixmap@@ 8726->8729 8731 7ffde660c365 ??1QDebug@@QEAA ??1QDebug@@QEAA ??1QDebug@@QEAA 8727->8731 8728->8725 8729->8728 8732 7ffde660d300 7 API calls 8730->8732 8731->8722 8732->8733 8733->8734 8735 7ffde660c5c5 DestroyCursor 8733->8735 8735->8734 8737 7ffde660c45a 8737->8733 8738 7ffde660c471 RegisterWindowMessageW 8737->8738 8739 7ffde660c484 ChangeWindowMessageFilterEx 8737->8739 8738->8739 8740 7ffde65cf9c0 8739->8740 8741 7ffde660c49c ?isDebugEnabled@QLoggingCategory@ 8740->8741 8742 7ffde660c4ad 8741->8742 8746 7ffde660c537 8741->8746 8743 7ffde660c4b2 ??0QMessageLogger@@QEAA@PEBDH00 ?debug@QMessageLogger@@QEBA?AVQDebug@ ??6QDebug@@QEAAAEAV0@PEBD 8742->8743 8744 7ffde660d6c0 8743->8744 8745 7ffde660c504 ??6QDebug@@QEAAAEAV0@PEBD ??6QDebug@@QEAAAEAV0@I ??1QDebug@@QEAA ??1QDebug@@QEAA 8744->8745 8745->8746 8754 7ffde660d300 memset 8746->8754 8749 7ffde660bde7 8748->8749 8750 7ffde660bdee 8748->8750 8749->8737 8751 7ffde660be0c ??0QByteArray@@QEAA@AEBV0@ ??YQString@@QEAAAEAV0@AEBV0@ 8750->8751 8752 7ffde65d14c0 46 API calls 8751->8752 8753 7ffde660be53 6 API calls 8752->8753 8753->8749 8755 7ffde660d3cf 8754->8755 8756 7ffde660d46c Shell_NotifyIconW 8754->8756 8755->8756 8759 7ffde660d3f1 ??0QByteArray@@QEAA@AEBV0@ 8755->8759 8757 7ffde660d48d 8756->8757 8758 7ffde660d4a3 8756->8758 8757->8758 8760 7ffde660d491 Shell_NotifyIconW 8757->8760 8758->8730 8761 7ffde660d444 ?toWCharArray@QString@@QEBAHPEA_W ??1?$QVector@VQPointF@@@@QEAA 8759->8761 8762 7ffde660d439 ?truncate@QString@@QEAAXH 8759->8762 8760->8758 8761->8756 8762->8761 9114 7ffde6632da0 9115 7ffde6632db5 9114->9115 9116 7ffde6632dd0 malloc 9115->9116 9119 7ffde6632de8 9115->9119 9116->9119 9117 7ffde6632e77 9120 7ffde6632f7f ?qErrnoWarning@ 9117->9120 9125 7ffde6632eb7 9117->9125 9118 7ffde6632e4a malloc 9118->9117 9119->9117 9119->9118 9119->9119 9120->9125 9121 7ffde6632fae 9123 7ffde6632fbd free 9121->9123 9124 7ffde6632fc3 9121->9124 9122 7ffde6632fa8 free 9122->9121 9123->9124 9125->9121 9125->9122 9125->9125 9231 7ffde65cd2b8 ?type@QWindow@@QEBA?AW4WindowType@Qt@ 9232 7ffde65cd315 9231->9232 9233 7ffde65cd478 ?flags@QWindow@@QEBA?AV?$QFlags@W4WindowType@Qt@@@ ?isTopLevel@QWindow@ 9231->9233 9237 7ffde65cd31d ??0QPlatformWindow@@QEAA@PEAVQWindow@@ GetDesktopWindow 9232->9237 9234 7ffde65cd509 ?geometry@QWindow@@QEBA?AVQRect@ ?scaleAndOrigin@QHighDpiScaling@@SA?AUScaleAndOrigin@1@PEBVQWindow@@PEAVQPoint@@ 9233->9234 9235 7ffde65cd4ca ?geometry@QWindow@@QEBA?AVQRect@ ?scaleAndOrigin@QHighDpiScaling@@SA?AUScaleAndOrigin@1@PEBVQWindow@@PEAVQPoint@@ 9233->9235 9236 7ffde65cd503 9234->9236 9235->9236 9239 7ffde65cd545 ?property@QObject@@QEBA?AVQVariant@@PEBD 9236->9239 9238 7ffde65cf4b0 2 API calls 9237->9238 9240 7ffde65cd345 ?isDebugEnabled@QLoggingCategory@ 9238->9240 9241 7ffde65cd5b9 ?title@QWindow@@QEBA?AVQString@ ?formatWindowTitle@QPlatformWindow@@KA?AVQString@@AEBV2@0 ??1?$QVector@VQPointF@@@@QEAA 9239->9241 9242 7ffde65cd56b 9239->9242 9243 7ffde65cd356 9240->9243 9244 7ffde65cd470 9240->9244 9264 7ffde65c6660 9241->9264 9247 7ffde65cd570 ?userType@QVariant@ 9242->9247 9251 7ffde65cf4b0 2 API calls 9243->9251 9249 7ffde65cd586 ?constData@QVariant@ 9247->9249 9250 7ffde65cd591 ?convert@QVariant@@QEBA_NHPEAX 9247->9250 9248 7ffde65cf4b0 2 API calls 9252 7ffde65cd65c ?isDebugEnabled@QLoggingCategory@ 9248->9252 9253 7ffde65cd5ab 9249->9253 9250->9253 9254 7ffde65cd373 6 API calls 9251->9254 9255 7ffde65cd8d1 9252->9255 9256 7ffde65cd66d 9252->9256 9253->9241 9259 7ffde65cd401 7 API calls 9254->9259 9258 7ffde65cd92c ??1QVariant@@QEAA 9255->9258 9284 7ffde65c50e0 ??0QPlatformWindow@@QEAA@PEAVQWindow@@ 9255->9284 9257 7ffde65cf4b0 2 API calls 9256->9257 9260 7ffde65cd672 32 API calls 9257->9260 9258->9244 9259->9244 9260->9255 9262 7ffde65cd901 9262->9258 9334 7ffde65c2730 ?property@QObject@@QEBA?AVQVariant@@PEBD 9264->9334 9266 7ffde65c66a9 ??0QByteArray@@QEAA@AEBV0@ 9351 7ffde65c2a50 GetModuleHandleW 9266->9351 9268 7ffde65c66d2 9269 7ffde65c6818 SetWindowPos 9268->9269 9270 7ffde65c6714 9268->9270 9283 7ffde65c6816 ??1?$QVector@VQPointF@@@@QEAA ??1?$QVector@VQPointF@@@@QEAA 9268->9283 9269->9283 9271 7ffde65c6778 SetWindowPos 9270->9271 9274 7ffde65c6728 9270->9274 9272 7ffde65c67c6 9271->9272 9273 7ffde65c67a3 ??0QMessageLogger@@QEAA@PEBDH0 ?warning@QMessageLogger@ 9271->9273 9275 7ffde65c67d0 GetSystemMenu 9272->9275 9276 7ffde65c67fe 9272->9276 9273->9272 9277 7ffde65c672e SetWindowPos 9274->9277 9278 7ffde65c6751 9274->9278 9280 7ffde65c67ed EnableMenuItem 9275->9280 9393 7ffde65c1f70 9276->9393 9277->9272 9278->9272 9279 7ffde65c6755 SetWindowPos 9278->9279 9279->9272 9280->9276 9283->9248 9285 7ffde65c517c 9284->9285 9286 7ffde65c5237 ?willGrow@QHashData@ 9285->9286 9287 7ffde65c522e 9285->9287 9288 7ffde65c5281 ?allocateNode@QHashData@@QEAAPEAXH 9286->9288 9291 7ffde65c5244 9286->9291 9289 7ffde65c52a9 ?type@QWindow@@QEBA?AW4WindowType@Qt@ 9287->9289 9288->9289 9290 7ffde65c52cb 9289->9290 9319 7ffde65c5745 ?isTopLevel@QWindow@ 9289->9319 9292 7ffde65c531c ?window@QPlatformWindow@@QEBAPEAVQWindow@ ?isTopLevel@QWindow@ 9290->9292 9293 7ffde65c5304 ?openGLModuleType@QOpenGLContext@@SA?AW4OpenGLModuleType@1 9290->9293 9291->9288 9295 7ffde65c5339 9292->9295 9294 7ffde65c5311 9293->9294 9294->9292 9296 7ffde65c5344 ?qt_window_private@@YAPEAVQWindowPrivate@@PEAVQWindow@@ 9295->9296 9297 7ffde65c537e 9296->9297 9298 7ffde65c54af ?window@QPlatformWindow@@QEBAPEAVQWindow@ ?window@QPlatformWindow@@QEBAPEAVQWindow@ ?mask@QWindow@@QEBA?AVQRegion@ ?scaleAndOrigin@QHighDpiScaling@@SA?AUScaleAndOrigin@1@PEBVQWindow@@PEAVQPoint@@ 9297->9298 9299 7ffde65cf4b0 2 API calls 9297->9299 9300 7ffde65c551c ??0QRegion@@QEAA ?begin@QRegion@@QEBAPEBVQRect@ ?end@QRegion@@QEBAPEBVQRect@ 9298->9300 9301 7ffde65c550a ??0QRegion@@QEAA@AEBV0@ 9298->9301 9302 7ffde65c53ac ?isDebugEnabled@QLoggingCategory@ 9299->9302 9304 7ffde65c55a9 ??1QRegion@@QEAA 9300->9304 9305 7ffde65c5543 ??0QRectF@@QEAA@AEBVQRect@@ ??0QRectF@@QEAA@AEBVQPointF@@AEBVQSizeF@@ ?toRect@QRectF@@QEBA?AVQRect@ ??YQRegion@@QEAAAEAV0@AEBVQRect@@ 9300->9305 9303 7ffde65c55c6 9301->9303 9306 7ffde65c53b9 9302->9306 9314 7ffde65c540c 9302->9314 9308 7ffde65c55d2 ??1QRegion@@QEAA ??1QRegion@@QEAA ?isTopLevel@QWindow@ 9303->9308 9304->9303 9305->9304 9305->9305 9307 7ffde65cf4b0 2 API calls 9306->9307 9309 7ffde65c53be ??0QMessageLogger@@QEAA@PEBDH00 ?debug@QMessageLogger@@QEBA?AVQDebug@ ??6QDebug@@QEAAAEAV0@PEBD ??6QDebug@@QEAAAEAV0@N ??1QDebug@@QEAA 9307->9309 9310 7ffde65c5607 ?icon@QWindow@@QEBA?AVQIcon@ 9308->9310 9311 7ffde65c56fd 9308->9311 9309->9314 9315 7ffde65c56f3 ??1QIcon@@QEAA 9310->9315 9316 7ffde65c5621 9310->9316 9312 7ffde65c5706 ?property@QObject@@QEBA?AVQVariant@@PEBD ?toBool@QVariant@ 9311->9312 9313 7ffde65c572e 9311->9313 9312->9313 9313->9319 9320 7ffde65c573a ??1QVariant@@QEAA 9313->9320 9314->9298 9321 7ffde65c545a ?window@QPlatformWindow@@QEBAPEAVQWindow@ 9314->9321 9315->9311 9317 7ffde65c563a 9316->9317 9318 7ffde65c562d DestroyCursor 9316->9318 9322 7ffde65c5646 DestroyCursor 9317->9322 9323 7ffde65c5653 GetSystemMetrics GetSystemMetrics 9317->9323 9318->9317 9319->9262 9320->9319 9325 7ffde65c547c ?hasAlpha@QSurfaceFormat@ 9321->9325 9322->9323 9484 7ffde65cb960 ?isNull@QIcon@ 9323->9484 9327 7ffde65c1e40 9325->9327 9326 7ffde65c5678 GetSystemMetrics GetSystemMetrics 9328 7ffde65cb960 7 API calls 9326->9328 9329 7ffde65c54a5 ??1QSurfaceFormat@@QEAA 9327->9329 9330 7ffde65c56a4 9328->9330 9329->9298 9331 7ffde65c56c3 SendMessageW 9330->9331 9332 7ffde65c56d2 SendMessageW 9330->9332 9333 7ffde65c56df SendMessageW 9331->9333 9332->9333 9333->9315 9335 7ffde65c276f ?userType@QVariant@ 9334->9335 9336 7ffde65c27ae 9334->9336 9337 7ffde65c2788 ?constData@QVariant@ 9335->9337 9338 7ffde65c2793 ?convert@QVariant@@QEBA_NHPEAX 9335->9338 9339 7ffde65c27d4 ?isTopLevel@QWindow@ 9336->9339 9342 7ffde65c27b8 ?layoutDirection@QGuiApplication@@SA?AW4LayoutDirection@Qt@ 9336->9342 9337->9336 9338->9336 9339->9342 9341 7ffde65c285e 9343 7ffde65c2895 ?transientParent@QWindow@@QEBAPEAV1 9341->9343 9344 7ffde65c289d ?parent@QWindow@@QEBAPEAV1 9341->9344 9348 7ffde65c287e 9341->9348 9342->9341 9345 7ffde65c28a3 9343->9345 9344->9345 9346 7ffde65c28a8 ?mimeData@QDrag@@QEBAPEAVQMimeData@ 9345->9346 9345->9348 9346->9348 9347 7ffde65c2a2a ??1QVariant@@QEAA 9347->9266 9348->9347 9349 7ffde65c29da ?maximumSize@QWindow@@QEBA?AVQSize@ 9348->9349 9350 7ffde65c293e 9348->9350 9349->9350 9350->9347 9401 7ffde65d1210 ?flags@QWindow@@QEBA?AV?$QFlags@W4WindowType@Qt@@@ 9351->9401 9353 7ffde65c2aed ?initialGeometry@QPlatformWindow@@SA?AVQRect@@PEBVQWindow@@AEBV2@HHPEAPEBVQScreen@@ 9354 7ffde65c2b70 ?utf16@QString@ ?utf16@QString@ 9353->9354 9355 7ffde65c2b22 9353->9355 9359 7ffde65c2b96 9354->9359 9355->9354 9356 7ffde65c2b4d ?objectName@QObject@@QEBA?AVQString@ ??4QUrl@@QEAAAEAV0@$$QEAV0@ 9355->9356 9357 7ffde65c2b31 ?qAppName@@YA?AVQString@ ??4QUrl@@QEAAAEAV0@$$QEAV0@ 9355->9357 9358 7ffde65c2b6a ??1?$QVector@VQPointF@@@@QEAA 9356->9358 9357->9358 9358->9354 9360 7ffde65c2ce8 ?qt_window_private@@YAPEAVQWindowPrivate@@PEAVQWindow@@ 9359->9360 9363 7ffde65c2cfa 9359->9363 9360->9363 9361 7ffde65cf4b0 2 API calls 9362 7ffde65c2d38 ?isDebugEnabled@QLoggingCategory@ 9361->9362 9364 7ffde65c2d49 9362->9364 9365 7ffde65c2f30 9362->9365 9363->9361 9366 7ffde65cf4b0 2 API calls 9364->9366 9421 7ffde65c2370 9365->9421 9368 7ffde65c2d4e 9 API calls 9366->9368 9370 7ffde65c2170 9368->9370 9369 7ffde65c2f45 ?isTopLevel@QWindow@ 9371 7ffde65c2f86 CreateWindowExW 9369->9371 9372 7ffde65c2f54 GetWindowLongPtrW 9369->9372 9374 7ffde65c2e0b 20 API calls 9370->9374 9376 7ffde65cf4b0 2 API calls 9371->9376 9372->9371 9375 7ffde65c2f6a GetClientRect 9372->9375 9374->9365 9375->9371 9377 7ffde65c300f ?isDebugEnabled@QLoggingCategory@ 9376->9377 9378 7ffde65c314b 9377->9378 9379 7ffde65c3020 9377->9379 9381 7ffde65c316b 9378->9381 9382 7ffde65c3152 ?qErrnoWarning@ 9378->9382 9380 7ffde65c3047 15 API calls 9379->9380 9388 7ffde65c3286 ??0QLoggingCategory@@QEAA@PEBD 9379->9388 9380->9378 9383 7ffde65c31aa 9381->9383 9384 7ffde65c3187 ?isTopLevel@QWindow@ 9381->9384 9389 7ffde65c3205 9382->9389 9385 7ffde65c31c7 ??0QRect@@QEAA@AEBVQPoint@@AEBVQSize@@ 9383->9385 9384->9383 9387 7ffde65c3194 ?flags@QWindow@@QEBA?AV?$QFlags@W4WindowType@Qt@@@ 9384->9387 9385->9389 9386 7ffde65c3232 ??1?$QVector@VQPointF@@@@QEAA ??1?$QVector@VQPointF@@@@QEAA 9390 7ffde65c3259 9386->9390 9387->9383 9391 7ffde66c57dc 9388->9391 9389->9386 9390->9268 9392 7ffde65c32a6 _Init_thread_footer 9391->9392 9392->9380 9394 7ffde65c1faa 9393->9394 9395 7ffde65c1fb4 ?hasAlpha@QSurfaceFormat@ ??1QSurfaceFormat@@QEAA 9394->9395 9396 7ffde65c1fbe ?qt_window_private@@YAPEAVQWindowPrivate@@PEAVQWindow@@ 9394->9396 9398 7ffde65c2011 9395->9398 9399 7ffde65c2004 9395->9399 9396->9395 9398->9283 9399->9398 9400 7ffde65c1d10 4 API calls 9399->9400 9400->9398 9402 7ffde65d1261 9401->9402 9403 7ffde65d12aa 9402->9403 9404 7ffde65d1283 ?property@QObject@@QEBA?AVQVariant@@PEBD ?toBool@QVariant@ 9402->9404 9405 7ffde65d12b8 ??1QVariant@@QEAA 9403->9405 9407 7ffde65d12c2 9403->9407 9404->9403 9405->9407 9406 7ffde65d1326 9409 7ffde65d1385 ??YQString@@QEAAAEAV0@VQLatin1String@@ 9406->9409 9410 7ffde65d13a0 9406->9410 9407->9406 9408 7ffde65d12f8 ??YQString@@QEAAAEAV0@VQLatin1String@@ 9407->9408 9408->9406 9409->9410 9411 7ffde65d13a6 ??YQString@@QEAAAEAV0@VQLatin1String@@ 9410->9411 9412 7ffde65d13cf 9410->9412 9411->9412 9413 7ffde65d13d5 ??YQString@@QEAAAEAV0@VQLatin1String@@ 9412->9413 9414 7ffde65d13fe 9412->9414 9413->9414 9415 7ffde65d1404 ??YQString@@QEAAAEAV0@VQLatin1String@@ 9414->9415 9416 7ffde65d142d 9414->9416 9415->9416 9417 7ffde65d145b GetSysColorBrush ??0QByteArray@@QEAA@AEBV0@ 9416->9417 9418 7ffde65d1432 ??YQString@@QEAAAEAV0@VQLatin1String@@ 9416->9418 9419 7ffde65d14c0 46 API calls 9417->9419 9418->9417 9420 7ffde65d149a ??1?$QVector@VQPointF@@@@QEAA 9419->9420 9420->9353 9422 7ffde65c270f 9421->9422 9423 7ffde65c23b2 ?isTopLevel@QWindow@ 9421->9423 9422->9369 9424 7ffde65c23bf 9423->9424 9424->9422 9444 7ffde65c6290 9424->9444 9426 7ffde65c23e2 9426->9422 9427 7ffde65c23ee ?handle@QScreen@@QEBAPEAVQPlatformScreen@ 9426->9427 9428 7ffde65c2429 ?contains@QRect@@QEBA_NAEBVQPoint@@_N 9427->9428 9428->9422 9429 7ffde65c2443 ?contains@QRect@@QEBA_NAEBVQPoint@@_N 9428->9429 9430 7ffde65c2459 9429->9430 9431 7ffde65c2473 ?virtualSiblings@QScreen@@QEBA?AV?$QList@PEAVQScreen@@@ 9429->9431 9430->9369 9432 7ffde65c2505 ?center@QRect@@QEBA?AVQPoint@ ?center@QRect@@QEBA?AVQPoint@ 9431->9432 9442 7ffde65c24bc 9431->9442 9433 7ffde65c2582 ?handle@QScreen@@QEBAPEAVQPlatformScreen@ 9432->9433 9434 7ffde65c2631 9432->9434 9436 7ffde65c25a2 ??0QRect@@QEAA@AEBVQPoint@@AEBVQSize@@ ??0QRect@@QEAA@AEBVQPoint@@0 ?center@QRect@@QEBA?AVQPoint@ ?center@QRect@@QEBA?AVQPoint@ 9433->9436 9437 7ffde65c26e2 ?dispose@QListData@@SAXPEAUData@1@ 9434->9437 9441 7ffde65c26ec 9434->9441 9435 7ffde65c24c0 ?handle@QScreen@@QEBAPEAVQPlatformScreen@ 9438 7ffde65c24e3 ?contains@QRect@@QEBA_NAEBVQPoint@@_N 9435->9438 9439 7ffde65c2629 9436->9439 9440 7ffde65c263d ?contains@QRect@@QEBA_NAEBVQPoint@@_N 9436->9440 9437->9441 9438->9442 9443 7ffde65c2500 9438->9443 9439->9434 9439->9440 9440->9434 9441->9369 9442->9435 9442->9443 9443->9432 9446 7ffde65c62cb 9444->9446 9447 7ffde65c64bf 9444->9447 9445 7ffde65c6319 9448 7ffde65c632c 9445->9448 9450 7ffde65c634b ?primaryScreen@QGuiApplication@@SAPEAVQScreen@ 9445->9450 9451 7ffde65c6340 ?screen@QWindow@@QEBAPEAVQScreen@ 9445->9451 9446->9445 9469 7ffde6601f30 ??0?$QVector@VQPointF@@@@QEAA ??0?$QVector@VQPointF@@@@QEAA ??0?$QVector@VQPointF@@@@QEAA 9446->9469 9447->9446 9453 7ffde65c64d8 ??0?$QVector@VQPointF@@@@QEAA 9447->9453 9448->9426 9455 7ffde65c6351 9450->9455 9451->9455 9452 7ffde65c62dd ??4QUrl@@QEAAAEAV0@$$QEAV0@ ??1?$QVector@VQPointF@@@@QEAA ??1?$QVector@VQPointF@@@@QEAA ??1?$QVector@VQPointF@@@@QEAA 9452->9445 9454 7ffde66c57dc 9453->9454 9456 7ffde65c64f1 _Init_thread_footer 9454->9456 9457 7ffde65c6383 9455->9457 9458 7ffde65c6359 ?name@QScreen@@QEBA?AVQString@ ??8@YA_NAEBVQString@@0 9455->9458 9456->9446 9459 7ffde65c6390 ??1?$QVector@VQPointF@@@@QEAA 9457->9459 9460 7ffde65c639e 9457->9460 9458->9457 9459->9460 9461 7ffde65c646a 9460->9461 9462 7ffde65c63b1 ?virtualSiblings@QScreen@@QEBA?AV?$QList@PEAVQScreen@@@ 9460->9462 9461->9426 9463 7ffde65c63e7 9462->9463 9464 7ffde65c6433 9462->9464 9463->9464 9466 7ffde65c63f0 ?name@QScreen@@QEBA?AVQString@ ??8@YA_NAEBVQString@@0 ??1?$QVector@VQPointF@@@@QEAA 9463->9466 9464->9461 9465 7ffde65c645c ?dispose@QListData@@SAXPEAUData@1@ 9464->9465 9465->9461 9466->9463 9467 7ffde65c6483 9466->9467 9467->9461 9468 7ffde65c64ac ?dispose@QListData@@SAXPEAUData@1@ 9467->9468 9468->9461 9481 7ffde6601e80 ??0?$QVector@VQPointF@@@@QEAA ??4QByteArray@@QEAAAEAV0@AEBV0@ ??1?$QVector@VQPointF@@@@QEAA ?utf16@QString@ ?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N 9469->9481 9471 7ffde6602187 ??1?$QVector@VQPointF@@@@QEAA 9472 7ffde66021a4 9471->9472 9472->9452 9473 7ffde6601fa0 9473->9471 9474 7ffde6601fed 6 API calls 9473->9474 9475 7ffde66020e4 9473->9475 9476 7ffde660206e 9474->9476 9475->9471 9476->9475 9477 7ffde66020fa EnumDisplayDevicesW 9476->9477 9477->9475 9478 7ffde6602116 9477->9478 9479 7ffde6602138 ?fromWCharArray@QString@@SA?AV1@PEB_WH ??4QUrl@@QEAAAEAV0@$$QEAV0@ ??1?$QVector@VQPointF@@@@QEAA 9478->9479 9480 7ffde660211f EnumDisplayDevicesW 9478->9480 9479->9475 9480->9475 9480->9478 9482 7ffde6601f06 9481->9482 9483 7ffde6601ef1 GetProcAddress 9481->9483 9482->9473 9483->9482 9485 7ffde65cb985 ?actualSize@QIcon@@QEBA?AVQSize@@AEBV2@W4Mode@1@W4State@1@ ?pixmap@QIcon@@QEBA?AVQPixmap@@AEBVQSize@@W4Mode@1@W4State@1@ ?isNull@QPixmap@ 9484->9485 9486 7ffde65cba11 9484->9486 9487 7ffde65cba0b ??1QPixmap@@UEAA 9485->9487 9488 7ffde65cb9e4 ?qt_pixmapToWinHICON@@YAPEAUHICON__@@AEBVQPixmap@@ ??1QPixmap@@UEAA 9485->9488 9486->9326 9487->9486 9488->9326 9489 7ffde65c6ab0 GetForegroundWindow 9490 7ffde65c6ae9 9489->9490 9491 7ffde65c6ac4 9489->9491 9492 7ffde65c6acd IsChild 9491->9492 9493 7ffde65c6ae1 9491->9493 7962 7ffde65d2e89 7963 7ffde65c7cb0 7962->7963 7964 7ffde65d2e93 ?window@QPlatformWindow@@QEBAPEAVQWindow@ 7963->7964 7967 7ffde65d41e0 7964->7967 7966 7ffde65d2ea7 7968 7ffde65d9cf0 7967->7968 7969 7ffde65d4210 ?mouseButtons@QGuiApplication@@SA?AV?$QFlags@W4MouseButton@Qt@@@ 7968->7969 7970 7ffde65d4226 GetKeyState GetKeyState 7969->7970 7973 7ffde65d43c6 7969->7973 7971 7ffde65d426c 7970->7971 7972 7ffde65d4270 GetKeyState 7970->7972 7971->7972 7974 7ffde65d4284 GetKeyState 7972->7974 7975 7ffde65d4280 7972->7975 7973->7966 7976 7ffde65d42a4 7974->7976 7977 7ffde65d4294 GetKeyState 7974->7977 7975->7974 7978 7ffde65d42a8 GetCursorPos ?mimeData@QDrag@@QEBAPEAVQMimeData@ 7976->7978 7977->7976 7977->7978 7979 7ffde65d42e1 ?contains@QRect@@QEBA_NAEBVQPoint@@_N 7978->7979 7981 7ffde65d4332 7979->7981 7981->7973 7982 7ffde65d4355 ??$handleMouseEvent@UDefaultDelivery@QWindowSystemInterface@@@QWindowSystemInterface@@SA_NPEAVQWindow@@AEBVQPointF@@1V?$QFlags@W4MouseButton@Qt@@@@W4MouseButton@Qt@@W4Type@QEvent@@V?$QFlags@W4KeyboardModifier@Qt@@@@W4MouseEventSource@5@ 7981->7982 7982->7981 7983 7ffde6633390 7984 7ffde66333de 7983->7984 7985 7ffde6633503 ?qErrnoWarning@ ??0glyph_metrics_t@@QEAA 7984->7985 7986 7ffde66333e6 7984->7986 7985->7986 7987 7ffde6634790 7988 7ffde6634805 7987->7988 7989 7ffde663482b ?boundingBox@QFontEngine@@UEAA?AUglyph_metrics_t@@IAEBVQTransform@@ 7987->7989 7988->7989 7990 7ffde6634809 ?scale@QTransform@@QEAAAEAV1@NN 7988->7990 7993 7ffde6634909 7989->7993 7990->7989 7991 7ffde6634a1f ??0glyph_metrics_t@@QEAA 7992 7ffde66349e5 7991->7992 7993->7991 7993->7992 8156 7ffde65eb580 ?focusObject@QGuiApplication@@SAPEAVQObject@ 8157 7ffde65eb598 ?focusWindow@QGuiApplication@@SAPEAVQWindow@ 8156->8157 8163 7ffde65eb728 8156->8163 8158 7ffde65eb5af ?mimeData@QDrag@@QEBAPEAVQMimeData@ 8157->8158 8157->8163 8159 7ffde65eb5c1 ?type@QWindow@@QEBA?AW4WindowType@Qt@ 8158->8159 8158->8163 8160 7ffde65eb5d3 ?mimeData@QDrag@@QEBAPEAVQMimeData@ 8159->8160 8159->8163 8161 7ffde65eb5f2 8160->8161 8162 7ffde65eb5fa ?mimeData@QDrag@@QEBAPEAVQMimeData@ 8161->8162 8161->8163 8162->8163 8164 7ffde65eb614 ?inputMethodAccepted@QPlatformInputContext@ 8162->8164 8165 7ffde65eb6eb 8164->8165 8166 7ffde65eb62d 8164->8166 8169 7ffde65eb708 ImmAssociateContextEx 8165->8169 8170 7ffde65eb722 ImmAssociateContext 8165->8170 8167 7ffde65eb632 ?isDebugEnabled@QLoggingCategory@ 8166->8167 8167->8165 8168 7ffde65eb643 ?window@QPlatformWindow@@QEBAPEAVQWindow@ 8167->8168 8171 7ffde65cf6f0 8168->8171 8169->8170 8170->8163 8172 7ffde65eb654 8 API calls 8171->8172 8172->8165 8648 7ffde65d5190 ??0?$QVector@VQPointF@@@@QEAA 8660 7ffde65d4da0 GetMonitorInfoW 8648->8660 8650 7ffde65d5222 8651 7ffde65d53c6 ??1?$QVector@VQPointF@@@@QEAA 8650->8651 8652 7ffde65d5235 8650->8652 8653 7ffde65d5288 8650->8653 8655 7ffde65d5248 ?allocate@QArrayData@@SAPEAU1@_K00V?$QFlags@W4AllocationOption@QArrayData@@@@ 8652->8655 8657 7ffde65d5261 8652->8657 8654 7ffde65d5314 ??0QByteArray@@QEAA@AEBV0@ 8653->8654 8656 7ffde65d52a5 ??0QByteArray@@QEAA@AEBV0@ 8653->8656 8658 7ffde65d537d 8654->8658 8655->8657 8656->8657 8657->8651 8659 7ffde65d53ae ??1?$QVector@VQPointF@@@@QEAA 8658->8659 8659->8657 8661 7ffde65d4e01 ?fromWCharArray@QString@@SA?AV1@PEB_WH ??4QUrl@@QEAAAEAV0@$$QEAV0@ ??1?$QVector@VQPointF@@@@QEAA ?isNull@QString@ 8660->8661 8662 7ffde65d4f30 8660->8662 8663 7ffde65d4ed7 ?constData@QString@@QEBAPEBVQChar@ 8661->8663 8664 7ffde65d4ed3 8661->8664 8662->8650 8663->8664 8665 7ffde65d4f39 CreateDCW 8664->8665 8666 7ffde65d4f00 ?compareStrings@QtPrivate@@YAHVQStringView@@0W4CaseSensitivity@Qt@@ 8664->8666 8667 7ffde65d5094 7 API calls 8665->8667 8668 7ffde65d4f5f 8665->8668 8666->8662 8666->8665 8667->8662 8669 7ffde65d4fcf GetDeviceCaps GetDeviceCaps 8668->8669 8673 7ffde65d4fc3 8668->8673 8670 7ffde65d5007 GetDeviceCaps GetDeviceCaps GetDeviceCaps GetDeviceCaps 8669->8670 8671 7ffde65d5089 DeleteDC 8670->8671 8672 7ffde65d507c 8670->8672 8671->8662 8672->8671 8673->8670 8687 7ffde6634570 ??0QColor@@QEAA 8688 7ffde66345d2 8687->8688 8695 7ffde6633890 8688->8695 8690 7ffde66345f3 ?depth@QImage@ 8691 7ffde6634603 ??0QImage@@QEAA@AEBV0@ ??0QImage@@QEAA@$$QEAV0@ 8690->8691 8692 7ffde6634626 ?convertToFormat_helper@QImage@@IEBA?AV1@W4Format@1@V?$QFlags@W4ImageConversionFlag@Qt@@@@ ??0QImage@@QEAA@$$QEAV0@ 8690->8692 8693 7ffde6634659 ??1QImage@@UEAA ??1QImage@@UEAA 8691->8693 8692->8693 8694 7ffde663467d 8693->8694 8696 7ffde6633981 8695->8696 8698 7ffde66339ab 8695->8698 8697 7ffde6633985 ?scale@QTransform@@QEAAAEAV1@NN 8696->8697 8696->8698 8697->8698 8699 7ffde6633aad 8698->8699 8700 7ffde6633fbe ?qErrnoWarning@ 8698->8700 8701 7ffde6633fd4 ??0QImage@@QEAA 8699->8701 8703 7ffde6633af4 ??0QImage@@QEAA 8699->8703 8700->8701 8702 7ffde6633fdd 8701->8702 8702->8690 8704 7ffde6633e90 ??0QImage@@QEAA@HHW4Format@0@ ??4QPixmap@@QEAAAEAV0@$$QEAV0@ ??1QImage@@UEAA ?fill@QImage@@QEAAXI 8703->8704 8705 7ffde6633b76 8703->8705 8706 7ffde6633ed0 8704->8706 8705->8704 8708 7ffde6633ba3 ??0QImage@@QEAA@HHW4Format@0@ ??4QPixmap@@QEAAAEAV0@$$QEAV0@ ??1QImage@@UEAA ?fill@QImage@@QEAAXI 8705->8708 8707 7ffde6633eda ?redF@QColor@ ?greenF@QColor@ ?blueF@QColor@ ?alphaF@QColor@ 8706->8707 8709 7ffde6633f1e 8706->8709 8707->8709 8708->8706 8715 7ffde6633c23 8708->8715 8711 7ffde6633f69 ??0QImage@@QEAA@$$QEAV0@ ??1QImage@@UEAA 8709->8711 8711->8702 8712 7ffde6633e75 ?qErrnoWarning@ 8712->8709 8713 7ffde6633e5a ?qErrnoWarning@ 8713->8709 8714 7ffde6633cd0 ?redF@QColor@ ?greenF@QColor@ ?blueF@QColor@ ?alphaF@QColor@ 8714->8715 8715->8709 8715->8712 8715->8713 8715->8714 8716 7ffde6633e3f ?qErrnoWarning@ 8715->8716 8716->8709 8784 7ffde65c6860 ?window@QPlatformWindow@@QEBAPEAVQWindow@ 8785 7ffde65cf4b0 2 API calls 8784->8785 8786 7ffde65c6880 ?isDebugEnabled@QLoggingCategory@ 8785->8786 8787 7ffde65c6941 8786->8787 8788 7ffde65c6891 8786->8788 8790 7ffde65c6a9c 8787->8790 8792 7ffde65c69c7 GetCapture 8787->8792 8808 7ffde65c6ee0 ?window@QPlatformWindow@@QEBAPEAVQWindow@ ?flags@QWindow@@QEBA?AV?$QFlags@W4WindowType@Qt@@@ ?type@QWindow@@QEBA?AW4WindowType@Qt@ ?isTopLevel@QWindow@ 8787->8808 8789 7ffde65cf4b0 2 API calls 8788->8789 8791 7ffde65c6896 9 API calls 8789->8791 8791->8787 8793 7ffde65c69e8 ?window@QPlatformWindow@@QEBAPEAVQWindow@ ?flags@QWindow@@QEBA?AV?$QFlags@W4WindowType@Qt@@@ 8792->8793 8794 7ffde65c69d3 8792->8794 8796 7ffde65c6a07 ShowWindow 8793->8796 8797 7ffde65c6a15 SetWindowPos 8793->8797 8794->8793 8799 7ffde65c6a4b ??0QRegion@@QEAA ?isEmpty@QRegion@ 8796->8799 8797->8799 8798 7ffde65c6959 GetWindowLongPtrW 8800 7ffde65c697a ?type@QWindow@@QEBA?AW4WindowType@Qt@ 8798->8800 8801 7ffde65c6970 8798->8801 8803 7ffde65c6a6c ?window@QPlatformWindow@@QEBAPEAVQWindow@ ??$handleExposeEvent@UDefaultDelivery@QWindowSystemInterface@@@QWindowSystemInterface@@SAXPEAVQWindow@@AEBVQRegion@@ ??1QRegion@@QEAA 8799->8803 8800->8790 8804 7ffde65c698c ?parent@QWindow@@QEBAPEAV1 8800->8804 8801->8800 8803->8790 8804->8790 8805 7ffde65c699e ?focusWindow@QGuiApplication@@SAPEAVQWindow@ 8804->8805 8805->8790 8807 7ffde65c69ad SetForegroundWindow 8805->8807 8807->8792 8809 7ffde65c6f77 8808->8809 8810 7ffde65c6f4f ?windowStates@QWindow@@QEBA?AV?$QFlags@W4WindowState@Qt@@@ 8808->8810 8811 7ffde65c7000 ?property@QObject@@QEBA?AVQVariant@@PEBD 8809->8811 8814 7ffde65c7039 8809->8814 8812 7ffde65c6f9a 8810->8812 8813 7ffde65c6f64 8810->8813 8815 7ffde65c7040 ??1QVariant@@QEAA 8811->8815 8816 7ffde65c701f ?toBool@QVariant@ 8811->8816 8812->8809 8829 7ffde65c6fd5 GetWindowLongPtrW 8812->8829 8813->8809 8817 7ffde65c6f6d IsWindowVisible 8813->8817 8819 7ffde65c704b ?windowStates@QWindow@@QEBA?AV?$QFlags@W4WindowState@Qt@@@ 8814->8819 8815->8819 8816->8815 8818 7ffde65c702e ??1QVariant@@QEAA 8816->8818 8817->8809 8818->8814 8820 7ffde65c7065 ShowWindow 8819->8820 8821 7ffde65c705e 8819->8821 8822 7ffde65c70d0 8820->8822 8823 7ffde65c707d GetWindowLongPtrW 8820->8823 8821->8820 8824 7ffde65c7106 8822->8824 8825 7ffde65c70d5 GetWindowPlacement 8822->8825 8828 7ffde65c9e60 8823->8828 8824->8798 8825->8824 8826 7ffde65c70f3 SetWindowPlacement 8825->8826 8826->8824 8830 7ffde65c70ac SetWindowPos 8828->8830 8829->8809 8830->8822 9137 7ffde65cdf7b 9138 7ffde65cf5d0 9137->9138 9139 7ffde65cdfc2 ?isDebugEnabled@QLoggingCategory@ 9138->9139 9140 7ffde65cdfd3 ?format@QOpenGLContext@@QEBA?AVQSurfaceFormat@ 9139->9140 9141 7ffde65ce06e 9139->9141 9142 7ffde65cf5d0 9140->9142 9148 7ffde65ce110 9141->9148 9144 7ffde65cdfe9 7 API calls 9142->9144 9144->9141 9145 7ffde65ce073 9146 7ffde65ce08e 9145->9146 9153 7ffde6609660 9145->9153 9149 7ffde65ce12a ??0QMutexLocker@@QEAA@PEAVQBasicMutex@@ 9148->9149 9150 7ffde65ce122 9148->9150 9151 7ffde65ce178 ??1QMutexLocker@@QEAA 9149->9151 9152 7ffde65ce14a 9149->9152 9150->9145 9151->9145 9152->9151 9154 7ffde66c5438 9153->9154 9155 7ffde6609684 ?shareHandle@QOpenGLContext@@QEBAPEAVQPlatformOpenGLContext@ ?format@QOpenGLContext@@QEBA?AVQSurfaceFormat@ 9154->9155 9158 7ffde66099b0 ??0QPlatformOpenGLContext@@QEAA ??0QSurfaceFormat@@QEAA 9155->9158 9157 7ffde66096b2 ??1QSurfaceFormat@@QEAA 9157->9146 9159 7ffde6609f3a 9158->9159 9160 7ffde6609a23 9158->9160 9159->9157 9161 7ffde6609a50 ??4QSurfaceFormat@@QEAAAEAV0@AEBV0@ ??1QSurfaceFormat@@QEAA 9160->9161 9162 7ffde6609a70 ?majorVersion@QSurfaceFormat@ ?minorVersion@QSurfaceFormat@ 9161->9162 9164 7ffde6609aaf ??0QMessageLogger@@QEAA@PEBDH0 ?warning@QMessageLogger@ 9162->9164 9165 7ffde6609aa9 9162->9165 9166 7ffde6609ad1 9164->9166 9165->9164 9165->9166 9167 7ffde6609d23 ??0QMessageLogger@@QEAA@PEBDH0 ?warning@QMessageLogger@ 9166->9167 9172 7ffde6609da6 9166->9172 9169 7ffde6609d62 ??0QMessageLogger@@QEAA@PEBDH0 ?warning@QMessageLogger@ 9167->9169 9171 7ffde6609d84 9167->9171 9169->9171 9170 7ffde6609f25 ?deallocate@QArrayData@@SAXPEAU1@_K1 9170->9159 9171->9159 9171->9170 9172->9171 9173 7ffde6609e72 ??0QByteArray@@QEAA@PEBDH ?parseOpenGLVersion@QPlatformOpenGLContext@@SA_NAEBVQByteArray@@AEAH1 9172->9173 9174 7ffde6609ec3 ?setProfile@QSurfaceFormat@@QEAAXW4OpenGLContextProfile@1@ ?setOptions@QSurfaceFormat@@QEAAXV?$QFlags@W4FormatOption@QSurfaceFormat@@@@ 9172->9174 9175 7ffde6609eb8 ??1?$QVector@VQPointF@@@@QEAA 9173->9175 9176 7ffde6609e9c ?setMajorVersion@QSurfaceFormat@@QEAAXH ?setMinorVersion@QSurfaceFormat@@QEAAXH 9173->9176 9174->9171 9175->9174 9176->9175 9178 7ffde660c060 9179 7ffde65cf9c0 9178->9179 9180 7ffde660c093 ?isDebugEnabled@QLoggingCategory@ 9179->9180 9181 7ffde660c0a0 9180->9181 9182 7ffde660c112 9180->9182 9184 7ffde660c0a5 ??0QMessageLogger@@QEAA@PEBDH00 ?debug@QMessageLogger@@QEBA?AVQDebug@ ??6QDebug@@QEAAAEAV0@PEBD 9181->9184 9183 7ffde660c123 memset memset Shell_NotifyIconW 9182->9183 9186 7ffde660c1e0 9182->9186 9183->9186 9185 7ffde660d6c0 9184->9185 9187 7ffde660c0fc ??1QDebug@@QEAA ??1QDebug@@QEAA 9185->9187 9187->9182 9494 7ffde65c5770 9495 7ffde65c57ae 9494->9495 9496 7ffde65c57a4 UnregisterTouchWindow 9494->9496 9505 7ffde65c5b10 9495->9505 9496->9495 9499 7ffde65c57c4 DestroyCursor 9500 7ffde65c57d1 9499->9500 9501 7ffde65c57dd DestroyCursor 9500->9501 9503 7ffde65c57ea 9500->9503 9501->9503 9502 7ffde65c5847 ??1QPlatformWindow@@UEAA 9504 7ffde65c5856 9502->9504 9503->9502 9506 7ffde65cf4b0 2 API calls 9505->9506 9507 7ffde65c5b25 ?isDebugEnabled@QLoggingCategory@ 9506->9507 9508 7ffde65c5b36 ?window@QPlatformWindow@@QEBAPEAVQWindow@ 9507->9508 9509 7ffde65c5be5 9507->9509 9512 7ffde65cf4b0 2 API calls 9508->9512 9510 7ffde65c57b6 9509->9510 9511 7ffde65c5bf0 ?topLevelWindows@QGuiApplication@@SA?AV?$QList@PEAVQWindow@@@ 9509->9511 9510->9499 9510->9500 9514 7ffde65c5c46 9511->9514 9516 7ffde65c5dec ?window@QPlatformWindow@@QEBAPEAVQWindow@ 9511->9516 9513 7ffde65c5b47 8 API calls 9512->9513 9513->9509 9515 7ffde65c5c50 ?transientParent@QWindow@@QEBAPEAV1 ?window@QPlatformWindow@@QEBAPEAVQWindow@ 9514->9515 9514->9516 9518 7ffde65c5c7a ?mimeData@QDrag@@QEBAPEAVQMimeData@ 9514->9518 9527 7ffde65c5cc2 ?mimeData@QDrag@@QEBAPEAVQMimeData@ 9514->9527 9534 7ffde65c5dcd SetWindowLongPtrW 9514->9534 9538 7ffde65c5d6b ?mimeData@QDrag@@QEBAPEAVQMimeData@ 9514->9538 9539 7ffde65c5da2 GetWindowLongPtrW 9514->9539 9515->9514 9519 7ffde65c5e5a 9516->9519 9520 7ffde65c5ea3 GetCapture 9516->9520 9518->9514 9521 7ffde65c5c8c ?type@QWindow@@QEBA?AW4WindowType@Qt@ 9518->9521 9519->9520 9523 7ffde65c5eaf 9520->9523 9521->9514 9522 7ffde65c5c9e ?mimeData@QDrag@@QEBAPEAVQMimeData@ 9521->9522 9522->9514 9541 7ffde65c6050 9523->9541 9526 7ffde65c5f00 DestroyWindow 9535 7ffde65c5f16 9526->9535 9527->9514 9529 7ffde65c5cd7 ?window@QPlatformWindow@@QEBAPEAVQWindow@ ?type@QWindow@@QEBA?AW4WindowType@Qt@ 9527->9529 9528 7ffde65ce110 2 API calls 9530 7ffde65c5edd 9528->9530 9529->9514 9531 7ffde65c5cf2 GetWindow ?window@QPlatformWindow@@QEBAPEAVQWindow@ ?transientParent@QWindow@@QEBAPEAV1 9529->9531 9530->9526 9531->9514 9533 7ffde65c5d24 ?mimeData@QDrag@@QEBAPEAVQMimeData@ 9531->9533 9532 7ffde65c5f4d ?dispose@QListData@@SAXPEAUData@1@ 9532->9510 9533->9514 9536 7ffde65c5d36 ?type@QWindow@@QEBA?AW4WindowType@Qt@ 9533->9536 9534->9514 9535->9510 9535->9532 9536->9514 9537 7ffde65c5d48 ?mimeData@QDrag@@QEBAPEAVQMimeData@ 9536->9537 9537->9514 9538->9514 9539->9514 9540 7ffde65c5db7 GetParent 9539->9540 9540->9514 9540->9539 9542 7ffde65c5ece 9541->9542 9543 7ffde65c6070 9541->9543 9542->9526 9542->9528 9544 7ffde65c607a ?isDebugEnabled@QLoggingCategory@ 9543->9544 9545 7ffde65c608b ?window@QPlatformWindow@@QEBAPEAVQWindow@ 9544->9545 9549 7ffde65c6123 9544->9549 9546 7ffde65cf660 9545->9546 9548 7ffde65c609c 7 API calls 9546->9548 9547 7ffde65c6246 CoLockObjectExternal 9550 7ffde65c626d RevokeDragDrop 9547->9550 9548->9549 9549->9547 9551 7ffde65c6136 ?window@QPlatformWindow@@QEBAPEAVQWindow@ 9549->9551 9550->9542 9552 7ffde65cf660 9551->9552 9553 7ffde65c6175 ?isDebugEnabled@QLoggingCategory@ 9552->9553 9554 7ffde65c6186 9553->9554 9555 7ffde65c6211 RegisterDragDrop CoLockObjectExternal 9553->9555 9556 7ffde65c618b 7 API calls 9554->9556 9555->9547 9556->9555 9557 7ffde65cd070 ?requested@QPlatformInputContextFactory@@SA?AVQString@ ?isNull@QString@ 9558 7ffde65cd0a4 9557->9558 9559 7ffde65cd1ff ?create@QPlatformInputContextFactory@@SAPEAVQPlatformInputContext@@AEBVQString@@ 9557->9559 9562 7ffde65cd0b8 7 API calls 9558->9562 9560 7ffde65cd1f6 9559->9560 9561 7ffde65cd237 ??1?$QVector@VQPointF@@@@QEAA 9559->9561 9560->9561 9563 7ffde66c5438 9562->9563 9564 7ffde65cd182 ?connectImpl@QObject@@CA?AVConnection@QMetaObject@@PEBV1@PEAPEAX01PEAVQSlotObjectBase@QtPrivate@@W4ConnectionType@Qt@@PEBHPEBU3@ ??1Connection@QMetaObject@@QEAA 9563->9564 9564->9560 9564->9561 8016 7ffde660e150 8017 7ffde660e183 8016->8017 8018 7ffde660e1a8 DefWindowProcW 8016->8018 8022 7ffde660e660 8017->8022 8020 7ffde660e1a1 8018->8020 8021 7ffde660e19d 8021->8018 8021->8020 8023 7ffde660e72b 8022->8023 8024 7ffde660e69c 8022->8024 8025 7ffde660e84f 8023->8025 8029 7ffde660e736 8023->8029 8026 7ffde660e6a1 ?isDebugEnabled@QLoggingCategory@ 8024->8026 8027 7ffde660e858 OleIsCurrentClipboard 8025->8027 8043 7ffde660e747 8025->8043 8026->8023 8032 7ffde660e6ae 8026->8032 8028 7ffde660e862 8027->8028 8027->8043 8033 7ffde660e867 ?isDebugEnabled@QLoggingCategory@ 8028->8033 8030 7ffde660e795 8029->8030 8031 7ffde660e78b OleIsCurrentClipboard 8029->8031 8029->8043 8036 7ffde660e7a2 ?isDebugEnabled@QLoggingCategory@ 8030->8036 8031->8030 8034 7ffde660e6b3 ??0QMessageLogger@@QEAA@PEBDH00 ?debug@QMessageLogger@@QEBA?AVQDebug@ ??6QDebug@@QEAAAEAV0@PEBD ??6QDebug@@QEAAAEAV0@PEBX ??6QDebug@@QEAAAEAV0@I 8032->8034 8037 7ffde660e8c4 OleFlushClipboard 8033->8037 8038 7ffde660e874 8033->8038 8035 7ffde6622e40 8034->8035 8039 7ffde660e711 ??6QDebug@@QEAAAEAV0@PEBD ??1QDebug@@QEAA 8035->8039 8040 7ffde660e7af 8036->8040 8041 7ffde660e80c ?emitChanged@QPlatformClipboard@@QEAAXW4Mode@QClipboard@@ 8036->8041 8037->8043 8042 7ffde660e879 ??0QMessageLogger@@QEAA@PEBDH00 ?debug@QMessageLogger@@QEBA?AVQDebug@ ??6QDebug@@QEAAAEAV0@PEBD ??1QDebug@@QEAA 8038->8042 8039->8023 8044 7ffde660e7b4 ??0QMessageLogger@@QEAA@PEBDH00 ?debug@QMessageLogger@@QEBA?AVQDebug@ ??6QDebug@@QEAAAEAV0@PEBD ??6QDebug@@QEAAAEAV0@_N ??1QDebug@@QEAA 8040->8044 8041->8043 8042->8037 8043->8021 8044->8041 8539 7ff6f80110c0 GetCommandLineW CommandLineToArgvW 8540 7ff6f8011109 8539->8540 8544 7ff6f8011222 SHGetKnownFolderPath 8539->8544 8541 7ff6f8011111 lstrlenW lstrlenW 8540->8541 8543 7ff6f8011160 CharLowerW CharLowerW 8540->8543 8540->8544 8541->8540 8543->8540 8554 7ff6f8011261 8544->8554 8545 7ff6f8011680 CreateFileW 8625 7ff6f8012300 8545->8625 8547 7ff6f801170c 8548 7ff6f8012300 11 API calls 8547->8548 8549 7ff6f8011726 8548->8549 8551 7ff6f8012300 11 API calls 8549->8551 8550 7ff6f80116c6 8550->8547 8552 7ff6f8012300 11 API calls 8550->8552 8553 7ff6f8011740 8551->8553 8552->8550 8555 7ff6f8011758 8553->8555 8556 7ff6f8011b6c 8553->8556 8554->8545 8557 7ff6f8012300 11 API calls 8555->8557 8558 7ff6f8012300 11 API calls 8556->8558 8559 7ff6f8011764 SHGetKnownFolderPath 8557->8559 8563 7ff6f8011a72 8558->8563 8560 7ff6f8011b34 8559->8560 8567 7ff6f801178b 8559->8567 8561 7ff6f8012300 11 API calls 8560->8561 8562 7ff6f8011b58 CloseHandle ExitProcess 8561->8562 8564 7ff6f8012300 11 API calls 8563->8564 8565 7ff6f8011a8c 8564->8565 8566 7ff6f8012300 11 API calls 8565->8566 8568 7ff6f8011aa7 8566->8568 8567->8560 8570 7ff6f80118b6 8567->8570 8569 7ff6f8012300 11 API calls 8568->8569 8571 7ff6f8011abe 8569->8571 8570->8560 8575 7ff6f80118d0 PathFileExistsW 8570->8575 8572 7ff6f8012300 11 API calls 8571->8572 8573 7ff6f8011ad5 8572->8573 8574 7ff6f8012300 11 API calls 8573->8574 8576 7ff6f8011aef PathIsDirectoryW 8574->8576 8577 7ff6f80118e1 8575->8577 8589 7ff6f8011a07 8575->8589 8578 7ff6f8011cd7 SetDllDirectoryW 8576->8578 8579 7ff6f8011b00 8576->8579 8580 7ff6f8012300 11 API calls 8577->8580 8582 7ff6f8011d18 LoadLibraryW 8578->8582 8583 7ff6f8011ce4 8578->8583 8581 7ff6f8012300 11 API calls 8579->8581 8596 7ff6f80118fc 8580->8596 8587 7ff6f8011b1a GetLastError CloseHandle ExitProcess 8581->8587 8585 7ff6f8011d29 8582->8585 8586 7ff6f8011d5b GetProcAddress 8582->8586 8584 7ff6f8012300 11 API calls 8583->8584 8588 7ff6f8011cfe GetLastError CloseHandle ExitProcess 8584->8588 8590 7ff6f8012300 11 API calls 8585->8590 8591 7ff6f8011da6 8586->8591 8592 7ff6f8011d82 8586->8592 8589->8563 8593 7ff6f8011d43 GetLastError CloseHandle ExitProcess 8590->8593 8595 7ff6f8012300 11 API calls 8591->8595 8594 7ff6f8012300 11 API calls 8592->8594 8597 7ff6f8011d8e GetLastError CloseHandle ExitProcess 8594->8597 8598 7ff6f8011db2 8595->8598 8596->8596 8599 7ff6f801192d GetModuleFileNameW 8596->8599 8600 7ff6f8012300 11 API calls 8598->8600 8601 7ff6f80119d8 8599->8601 8602 7ff6f8011941 PathRemoveFileSpecW 8599->8602 8604 7ff6f8011dcd CloseHandle 8600->8604 8603 7ff6f8012300 11 API calls 8601->8603 8602->8601 8613 7ff6f8011952 8602->8613 8605 7ff6f80119f3 CloseHandle ExitProcess 8603->8605 8606 7ff6f8011ddf 8604->8606 8607 7ff6f8011dfd CreateFileW 8606->8607 8608 7ff6f8011e2f CreateFileW 8606->8608 8609 7ff6f8012300 11 API calls 8607->8609 8610 7ff6f8011e2d 8608->8610 8609->8610 8611 7ff6f8012300 11 API calls 8610->8611 8612 7ff6f8011e60 8611->8612 8614 7ff6f8012300 11 API calls 8612->8614 8613->8589 8613->8601 8615 7ff6f8011e7b FreeLibrary 8614->8615 8616 7ff6f8011e8b 8615->8616 8617 7ff6f8011ebc 8615->8617 8618 7ff6f8012300 11 API calls 8616->8618 8639 7ff6f80122e0 8617->8639 8620 7ff6f8011ea2 GetLastError CloseHandle ExitProcess 8618->8620 8622 7ff6f8012300 11 API calls 8623 7ff6f8011edc 8622->8623 8624 7ff6f8011ee4 ExitProcess 8623->8624 8628 7ff6f8012340 8625->8628 8626 7ff6f80124ac 8626->8550 8627 7ff6f80123a0 8627->8626 8631 7ff6f80123bf GetUserNameW 8627->8631 8628->8626 8628->8627 8629 7ff6f8012398 8628->8629 8646 7ff6f8011fe0 GetSystemTime GetDateFormatEx GetTimeFormatEx 8629->8646 8631->8626 8632 7ff6f80123d9 SHGetKnownFolderPath 8631->8632 8632->8626 8633 7ff6f8012402 8632->8633 8642 7ff6f8011ef0 lstrlenW lstrlenW 8633->8642 8636 7ff6f8011ef0 4 API calls 8637 7ff6f801241b 8636->8637 8638 7ff6f8012485 lstrlenW WriteFile 8637->8638 8638->8626 8640 7ff6f8012300 11 API calls 8639->8640 8641 7ff6f8011ec1 8640->8641 8641->8622 8643 7ff6f8011fbf 8642->8643 8644 7ff6f8011f27 8642->8644 8643->8636 8644->8643 8645 7ff6f8011f60 CharLowerW CharLowerW 8644->8645 8645->8644 8647 7ff6f8012119 8646->8647 8647->8627 8763 7ffde660bc30 8764 7ffde660bc5e ?topLevelWindows@QGuiApplication@@SA?AV?$QList@PEAVQWindow@@@ 8763->8764 8766 7ffde660bc7b 8763->8766 8764->8766 8765 7ffde660bcb5 8768 7ffde65d66a0 106 API calls 8765->8768 8771 7ffde660bccf 8765->8771 8766->8765 8767 7ffde660bcaa ?dispose@QListData@@SAXPEAUData@1@ 8766->8767 8767->8765 8768->8771 8769 7ffde660bd23 DefWindowProcW 8770 7ffde660bd34 8769->8770 8771->8769 8771->8770 9177 7ffde6622e20 ?sendPostedEvents@QEventDispatcherWin32@ ?sendWindowSystemEvents@QWindowSystemInterface@@SA_NV?$QFlags@W4ProcessEventsFlag@QEventLoop@@@@ 9574 7ffde65cba30 9575 7ffde65cbb29 9574->9575 9576 7ffde65cba4b 9574->9576 9577 7ffde65cba6b 9576->9577 9578 7ffde65cba5e DestroyCursor 9576->9578 9579 7ffde65cba77 DestroyCursor 9577->9579 9580 7ffde65cba84 GetSystemMetrics GetSystemMetrics 9577->9580 9578->9577 9579->9580 9581 7ffde65cb960 7 API calls 9580->9581 9582 7ffde65cbaa9 GetSystemMetrics GetSystemMetrics 9581->9582 9583 7ffde65cb960 7 API calls 9582->9583 9584 7ffde65cbad5 9583->9584 9585 7ffde65cbaf9 SendMessageW 9584->9585 9586 7ffde65cbb08 SendMessageW 9584->9586 9587 7ffde65cbb15 SendMessageW 9585->9587 9586->9587 9587->9575 8424 7ffde6626400 ??0QString@@QEAA@PEBVQChar@@H 8425 7ffde662643e 8424->8425 8434 7ffde66294c0 8425->8434 8427 7ffde6626458 8428 7ffde6626494 ?isDebugEnabled@QLoggingCategory@ 8427->8428 8429 7ffde662653f ??1?$QVector@VQPointF@@@@QEAA 8428->8429 8430 7ffde66264a5 8428->8430 8431 7ffde66264aa ??0QMessageLogger@@QEAA@PEBDH00 ?debug@QMessageLogger@@QEBA?AVQDebug@ ??6QDebug@@QEAAAEAV0@PEBD ??6QDebug@@QEAAAEAV0@PEBD 8430->8431 8432 7ffde6623e30 8431->8432 8433 7ffde6626511 ??6QDebug@@QEAAAEAV0@PEBX ??6QDebug@@QEAAAEAV0@PEBX ??1QDebug@@QEAA ??1QDebug@@QEAA 8432->8433 8433->8429 8435 7ffde6629515 8434->8435 8436 7ffde662961f 8435->8436 8437 7ffde6629573 CreateFontIndirectW 8435->8437 8480 7ffde6623db0 8436->8480 8438 7ffde66295a1 SelectObject GetTextMetricsW 8437->8438 8439 7ffde6629585 ?qErrnoWarning@ 8437->8439 8442 7ffde66295cf ?qErrnoWarning@ 8438->8442 8443 7ffde66295e5 8438->8443 8441 7ffde662959e 8439->8441 8441->8438 8445 7ffde6629603 SelectObject DeleteObject 8442->8445 8443->8445 8445->8436 8446 7ffde6629643 ?fromWCharArray@QString@@SA?AV1@PEB_WH ??0QWinRegistryKey@@QEAA@PEAUHKEY__@@VQStringView@@KK ?isNull@QString@ 8447 7ffde66296b4 8446->8447 8448 7ffde66296b9 ?constData@QString@@QEBAPEBVQChar@ 8446->8448 8449 7ffde66296c4 ?stringValue@QWinRegistryKey@@QEBA?AVQString@@VQStringView@@ ??1QWinRegistryKey@@QEAA ??0QByteArray@@QEAA@AEBV0@ ??1?$QVector@VQPointF@@@@QEAA ??8@YA_NAEBVQString@@0 8447->8449 8448->8449 8450 7ffde662976e CreateFontIndirectW 8449->8450 8451 7ffde6629737 ?utf16@QString@ memmove 8449->8451 8452 7ffde6629782 ?qErrnoWarning@ 8450->8452 8453 7ffde662979b SelectObject 8450->8453 8451->8450 8454 7ffde6629c91 ??1?$QVector@VQPointF@@@@QEAA ??1?$QVector@VQPointF@@@@QEAA 8452->8454 8455 7ffde66297ca ?startsWith@QString@@QEBA_NVQLatin1String@@W4CaseSensitivity@Qt@@ 8453->8455 8457 7ffde66297c5 8453->8457 8456 7ffde6629cb4 8454->8456 8463 7ffde6629cac 8454->8463 8455->8457 8458 7ffde6629d27 SelectObject GetTextFaceW ?fromWCharArray@QString@@SA?AV1@PEB_WH ??4QUrl@@QEAAAEAV0@$$QEAV0@ ??1?$QVector@VQPointF@@@@QEAA 8456->8458 8459 7ffde6629b72 8457->8459 8466 7ffde6629844 8457->8466 8458->8463 8460 7ffde6629c72 SelectObject DeleteObject 8459->8460 8461 7ffde6629b7b 7 API calls 8459->8461 8460->8454 8462 7ffde6623e30 8461->8462 8464 7ffde6629c02 ??6QDebug@@QEAAAEAV0@D 8462->8464 8463->8427 8465 7ffde6623fc0 8464->8465 8467 7ffde6629c2b 6 API calls 8465->8467 8468 7ffde66298d4 ?isDebugEnabled@QLoggingCategory@ 8466->8468 8467->8460 8469 7ffde66298e5 8468->8469 8472 7ffde6629a08 8468->8472 8471 7ffde66298ea 17 API calls 8469->8471 8470 7ffde6629b56 8470->8460 8471->8472 8472->8470 8473 7ffde6629a31 GetTextFaceW 8472->8473 8474 7ffde6622f00 8473->8474 8475 7ffde6629a59 ?fromWCharArray@QString@@SA?AV1@PEB_WH ??4QUrl@@QEAAAEAV0@$$QEAV0@ ??1?$QVector@VQPointF@@@@QEAA 8474->8475 8476 7ffde6629a8b 8475->8476 8477 7ffde6629b39 ??1?$QVector@VQPointF@@@@QEAA 8476->8477 8478 7ffde65ce830 8477->8478 8479 7ffde6629b4c ??1?$QVector@VQPointF@@@@QEAA 8478->8479 8479->8470 8481 7ffde6623dc9 8480->8481 8482 7ffde6623dd5 8480->8482 8486 7ffde6623170 8481->8486 8483 7ffde6623e16 8482->8483 8485 7ffde6623e02 ?qErrnoWarning@ 8482->8485 8483->8446 8483->8456 8485->8483 8488 7ffde6623216 8486->8488 8489 7ffde66231a3 8486->8489 8487 7ffde6623208 8487->8482 8488->8489 8490 7ffde6623234 _Init_thread_footer 8488->8490 8489->8487 8491 7ffde66231f5 ?qErrnoWarning@ 8489->8491 8490->8489 8491->8482 8492 7ffde65c7b10 ?window@QPlatformWindow@@QEBAPEAVQWindow@ ?qt_window_private@@YAPEAVQWindowPrivate@@PEAVQWindow@@ 8493 7ffde65c7b40 ?moveTopLeft@QRect@@QEAAXAEBVQPoint@@ 8492->8493 8494 7ffde65c7b7d 8492->8494 8493->8494 8496 7ffde65c7c88 ?setGeometry@QPlatformWindow@@UEAAXAEBVQRect@@ 8494->8496 8497 7ffde65c7bad 8494->8497 8498 7ffde65c7c8e 8496->8498 8505 7ffde65c8220 8497->8505 8500 7ffde65c7bb6 8500->8498 8501 7ffde65c7bea IsWindowVisible 8500->8501 8502 7ffde65c7bf4 ?qResourceFeatureZlib@ 8500->8502 8501->8502 8503 7ffde65c7c02 8501->8503 8502->8498 8502->8503 8504 7ffde65c7c27 6 API calls 8503->8504 8504->8498 8506 7ffde65c825d 8505->8506 8507 7ffde65cf4b0 2 API calls 8506->8507 8508 7ffde65c828e ?isDebugEnabled@QLoggingCategory@ 8507->8508 8509 7ffde65c843f GetWindowPlacement 8508->8509 8510 7ffde65c829f 8508->8510 8514 7ffde65c847e 8509->8514 8515 7ffde65c8471 IsWindowVisible 8509->8515 8511 7ffde65c4160 9 API calls 8510->8511 8512 7ffde65c82ab ?marginsRemoved@QRect@@QEBA?AV1@AEBVQMargins@@ ?window@QPlatformWindow@@QEBAPEAVQWindow@ 8511->8512 8520 7ffde65cf4b0 2 API calls 8512->8520 8517 7ffde65c8514 ?window@QPlatformWindow@@QEBAPEAVQWindow@ ?isTopLevel@QWindow@ 8514->8517 8521 7ffde65c848a 8514->8521 8515->8514 8515->8521 8518 7ffde65c8536 GetParent GetWindowLongPtrW 8517->8518 8519 7ffde65c857e 8517->8519 8518->8519 8522 7ffde65c8558 GetClientRect 8518->8522 8523 7ffde65c8587 MoveWindow 8519->8523 8524 7ffde65c82e6 19 API calls 8520->8524 8525 7ffde65c84ac ?translated@QRect@@QEBA?AV1@AEBVQPoint@@ SetWindowPlacement 8521->8525 8522->8523 8526 7ffde65c85ba 8523->8526 8524->8509 8525->8526 8527 7ffde65cf4b0 2 API calls 8526->8527 8528 7ffde65c85c5 ?isDebugEnabled@QLoggingCategory@ 8527->8528 8529 7ffde65c85d6 8528->8529 8530 7ffde65c8701 8528->8530 8531 7ffde65c4160 9 API calls 8529->8531 8530->8500 8532 7ffde65c85e2 ?marginsRemoved@QRect@@QEBA?AV1@AEBVQMargins@@ ?window@QPlatformWindow@@QEBAPEAVQWindow@ 8531->8532 8534 7ffde65c863f 11 API calls 8532->8534 8535 7ffde65c8720 8532->8535 8534->8530 8535->8534 8536 7ffde65c8739 ??0QLoggingCategory@@QEAA@PEBD 8535->8536 8537 7ffde66c57dc 8536->8537 8538 7ffde65c8759 _Init_thread_footer 8537->8538 8538->8534 8674 7ffde65c8a10 ?formatWindowTitle@QPlatformWindow@@KA?AVQString@@AEBV2@0 ??1?$QVector@VQPointF@@@@QEAA 8677 7ffde65c46c0 8674->8677 8678 7ffde65cf4b0 2 API calls 8677->8678 8679 7ffde65c46d2 ?isDebugEnabled@QLoggingCategory@ 8678->8679 8680 7ffde65c47c0 ?utf16@QString@ 8679->8680 8681 7ffde65c46e3 ?window@QPlatformWindow@@QEBAPEAVQWindow@ 8679->8681 8683 7ffde65c47df SetWindowTextW 8680->8683 8682 7ffde65c471b 8 API calls 8681->8682 8685 7ffde65c47f2 8681->8685 8682->8680 8683->8685 8684 7ffde65c480b ??0QLoggingCategory@@QEAA@PEBD 8684->8685 8685->8682 8685->8684 8686 7ffde65c482b _Init_thread_footer 8685->8686 8686->8682 8717 7ffde6622df0 ?processEvents@QEventDispatcherWin32@@UEAA_NV?$QFlags@W4ProcessEventsFlag@QEventLoop@@@@ 8772 7ffde660c5f0 8773 7ffde65cf9c0 8772->8773 8774 7ffde660c603 ?isDebugEnabled@QLoggingCategory@ 8773->8774 8775 7ffde660c6b4 ??8@YA_NAEBVQString@@0 8774->8775 8776 7ffde660c614 8774->8776 8777 7ffde660c6c5 ??4QByteArray@@QEAAAEAV0@AEBV0@ 8775->8777 8778 7ffde660c6e6 8775->8778 8780 7ffde660c619 6 API calls 8776->8780 8777->8778 8779 7ffde660c6d9 8777->8779 8781 7ffde660d300 7 API calls 8779->8781 8782 7ffde660d6c0 8780->8782 8781->8778 8783 7ffde660c698 ??1QDebug@@QEAA ??1QDebug@@QEAA 8782->8783 8783->8775 8831 7ffde65d44e0 8832 7ffde65d451f 8831->8832 8852 7ffde65d20e0 8832->8852 8834 7ffde65d4577 8835 7ffde65d4721 8834->8835 8838 7ffde65d458d ?isDebugEnabled@QLoggingCategory@ 8834->8838 8836 7ffde65d473b 8835->8836 8837 7ffde65d4726 DefWindowProcW 8835->8837 8839 7ffde65d4766 GetWindowLongPtrW 8836->8839 8843 7ffde65d4896 8836->8843 8837->8836 8838->8835 8841 7ffde65d459e 8838->8841 8840 7ffde65d4782 GetWindowPlacement 8839->8840 8839->8843 8842 7ffde65d479a 8840->8842 8841->8835 8844 7ffde65d45d5 ?isDebugEnabled@QLoggingCategory@ 8841->8844 8842->8843 8845 7ffde65cf4b0 2 API calls 8842->8845 8844->8835 8846 7ffde65d45e6 8844->8846 8847 7ffde65d47fb ?isDebugEnabled@QLoggingCategory@ 8845->8847 8849 7ffde65d45eb 21 API calls 8846->8849 8847->8843 8848 7ffde65d480c 8847->8848 8850 7ffde65cf4b0 2 API calls 8848->8850 8849->8835 8851 7ffde65d4811 8 API calls 8850->8851 8851->8843 8853 7ffde65d216b 8852->8853 8854 7ffde65d21c7 GetCursorPos 8852->8854 8853->8854 8855 7ffde65d2174 8853->8855 8861 7ffde65d21d1 8854->8861 8856 7ffde65d218d GetWindowLongPtrW 8855->8856 8855->8861 8857 7ffde65d21b8 ClientToScreen 8856->8857 8858 7ffde65d21a2 GetClientRect 8856->8858 8857->8861 8858->8857 8859 7ffde65d22b5 ?window@QPlatformWindow@@QEBAPEAVQWindow@ ?handleNativeEvent@QWindowSystemInterface@@SA_NPEAVQWindow@@AEBVQByteArray@@PEAXPEAJ ??1?$QVector@VQPointF@@@@QEAA 8860 7ffde65d230d 8859->8860 8924 7ffde65d22f9 8859->8924 8865 7ffde65d2330 ?cast@QMetaObject@@QEBAPEAVQObject@@PEAV2@ 8860->8865 8871 7ffde65d2371 8860->8871 8861->8859 8861->8860 8861->8924 8862 7ffde65d23fa 8863 7ffde65d27ea 8862->8863 8864 7ffde65d2400 8862->8864 8868 7ffde65d2845 8863->8868 8869 7ffde65d27f3 GetCursor 8863->8869 8866 7ffde65d240b 8864->8866 8867 7ffde65d27c6 8864->8867 8870 7ffde65d2345 8865->8870 8865->8871 8875 7ffde65d2799 8866->8875 8876 7ffde65d2417 8866->8876 8867->8868 8874 7ffde65d27cf 8867->8874 8873 7ffde65d284e 8868->8873 8889 7ffde65d2a5d 8868->8889 8877 7ffde65d2809 SetCursor 8869->8877 8869->8924 8882 7ffde65d2361 ImmAssociateContext 8870->8882 8870->8924 8871->8862 8872 7ffde65d2816 8871->8872 8871->8924 8872->8868 8878 7ffde65d3ea4 ?setActive@QPlatformAccessibility@@QEAAX_N ?startingUp@QCoreApplication@ 8872->8878 8872->8924 8879 7ffde65d2a11 ??0QMessageLogger@@QEAA@PEBDH0 8873->8879 8884 7ffde65d286e 8873->8884 8873->8924 8959 7ffde65d2964 8873->8959 8892 7ffde65d27dc ?window@QPlatformWindow@@QEBAPEAVQWindow@ 8874->8892 8874->8924 8887 7ffde65d66a0 106 API calls 8875->8887 8880 7ffde65d255c 8876->8880 8881 7ffde65d2420 8876->8881 8877->8924 8899 7ffde65d3ed7 ?closingDown@QCoreApplication@ 8878->8899 8878->8924 8885 7ffde6622e40 8879->8885 8883 7ffde65f1f00 7 API calls 8880->8883 8881->8868 8893 7ffde65d2435 8881->8893 8881->8924 8882->8924 8987 7ffde65d2568 8883->8987 8884->8879 8884->8924 8888 7ffde65d2a2f ?warning@QMessageLogger@ 8885->8888 8886 7ffde65d2b05 8890 7ffde65d2c9d 8886->8890 8898 7ffde65d35ca ?window@QPlatformWindow@@QEBAPEAVQWindow@ 8886->8898 8906 7ffde65d2b23 8886->8906 8887->8924 8888->8924 8889->8886 8895 7ffde65d2a7e ?isDebugEnabled@QLoggingCategory@ 8889->8895 8889->8924 8896 7ffde65d31e4 8890->8896 8897 7ffde65d393d 8890->8897 8890->8924 8892->8924 8900 7ffde65d244d 17 API calls 8893->8900 8893->8924 8894 7ffde65d2784 8905 7ffde65d66a0 106 API calls 8894->8905 8895->8886 8902 7ffde65d2a8b ?window@QPlatformWindow@@QEBAPEAVQWindow@ 8895->8902 8903 7ffde65d31ea 8896->8903 8904 7ffde65d38cd ?get@QObjectPrivate@@SAPEAV1@PEAVQObject@@ ?get@QObjectPrivate@@SAPEAV1@PEAVQObject@@ 8896->8904 8907 7ffde65d3949 8897->8907 8908 7ffde65d3cae 8897->8908 8901 7ffde65d35df 8898->8901 8898->8924 8909 7ffde65d3ee5 8899->8909 8899->8924 8900->8924 8912 7ffde65d35e0 ?flags@QWindow@@QEBA?AV?$QFlags@W4WindowType@Qt@@@ 8901->8912 8913 7ffde65cf540 8902->8913 8914 7ffde65d31f6 8903->8914 8915 7ffde65d383e 8903->8915 8916 7ffde65d38f4 ?get@QObjectPrivate@@SAPEAV1@PEAVQObject@@ ?commitData@QGuiApplicationPrivate@ 8904->8916 8904->8924 8905->8924 8917 7ffde65d2b29 8906->8917 8918 7ffde65d2c86 8906->8918 8919 7ffde65d3c72 8907->8919 8920 7ffde65d394f 8907->8920 8910 7ffde65d3cba 8908->8910 8911 7ffde65d3dff ?window@QPlatformWindow@@QEBAPEAVQWindow@ 8908->8911 8909->8924 8939 7ffde65d3f02 ?window@QPlatformWindow@@QEBAPEAVQWindow@ 8909->8939 8921 7ffde65d3d73 8910->8921 8964 7ffde65d3cc6 8910->8964 8934 7ffde65d3e1d 8911->8934 8912->8924 8925 7ffde65d35f6 ?parent@QWindow@@QEBAPEAV1 8912->8925 8926 7ffde65d2a9c 6 API calls 8913->8926 8927 7ffde65d31fc 8914->8927 8928 7ffde65d36c2 ?cast@QMetaObject@@QEBAPEAVQObject@@PEAV2@ 8914->8928 8922 7ffde65d321c 8915->8922 8974 7ffde65d3862 8915->8974 8916->8924 8929 7ffde65d391e fflush 8916->8929 8917->8924 8930 7ffde65d2b32 ?window@QPlatformWindow@@QEBAPEAVQWindow@ 8917->8930 9017 7ffde65c8820 8918->9017 8919->8924 8933 7ffde65d3c82 ?window@QPlatformWindow@@QEBAPEAVQWindow@ 8919->8933 8931 7ffde65d395b 8920->8931 8932 7ffde65d3bd3 ?get@QObjectPrivate@@SAPEAV1@PEAVQObject@@ ?get@QObjectPrivate@@SAPEAV1@PEAVQObject@@ 8920->8932 8921->8924 8965 7ffde65d3d8d ?window@QPlatformWindow@@QEBAPEAVQWindow@ 8921->8965 8922->8924 8956 7ffde65d3235 ?window@QPlatformWindow@@QEBAPEAVQWindow@ 8922->8956 8924->8834 8925->8912 8925->8924 8926->8886 8927->8898 8935 7ffde65d3208 8927->8935 8928->8922 8960 7ffde65d36f2 8928->8960 8929->8924 8936 7ffde65d2b56 ScreenToClient GetWindowLongPtrW 8930->8936 8937 7ffde65d2bfd GetKeyState GetKeyState 8930->8937 8931->8922 8938 7ffde65d3964 8931->8938 8945 7ffde65d3c05 ?get@QObjectPrivate@@SAPEAV1@PEAVQObject@@ 8932->8945 8940 7ffde65d3c96 8933->8940 8968 7ffde65d3e51 ?hasAlpha@QSurfaceFormat@ 8934->8968 8973 7ffde65d3e5e 8934->8973 8943 7ffde65d3395 ?window@QPlatformWindow@@QEBAPEAVQWindow@ ?isTopLevel@QWindow@ 8935->8943 8944 7ffde65d3214 8935->8944 8946 7ffde65d2b9c GetClientRect 8936->8946 8947 7ffde65d2bb4 GetClientRect 8936->8947 8941 7ffde65d2c29 GetKeyState 8937->8941 8942 7ffde65d2c24 8937->8942 8948 7ffde65d3ba2 8938->8948 8949 7ffde65d396d 8938->8949 8939->8924 8951 7ffde65f0120 83 API calls 8940->8951 8952 7ffde65d2c39 8941->8952 8953 7ffde65d2c3e GetKeyState 8941->8953 8942->8941 8943->8924 8954 7ffde65d33c0 8943->8954 8944->8922 8955 7ffde65d3267 8944->8955 8945->8924 8957 7ffde65d3c1e 8945->8957 8946->8947 8947->8937 8958 7ffde65d2bd1 8947->8958 8948->8924 8975 7ffde65d0ac0 28 API calls 8948->8975 9011 7ffde65d3976 8949->9011 9012 7ffde65d3aa6 8949->9012 8961 7ffde65d3c9e ??$handleThemeChange@UDefaultDelivery@QWindowSystemInterface@@@QWindowSystemInterface@@SAXPEAVQWindow@@ 8951->8961 8952->8953 8962 7ffde65d2c5e 8953->8962 8963 7ffde65d2c4e GetKeyState 8953->8963 8954->8924 8989 7ffde65d33f6 ?minimumSize@QWindow@@QEBA?AVQSize@ 8954->8989 8966 7ffde65d3331 8955->8966 8982 7ffde65d328f 8955->8982 8956->8924 8957->8924 8969 7ffde65d3c2b ?indexOfSignal@QMetaObject@@QEBAHPEBD 8957->8969 8958->8924 8958->8937 8959->8924 8999 7ffde65d29db GetLastError ?qErrnoWarning@ 8959->8999 8960->8922 8967 7ffde65d3703 ?qt_localeFromLCID@@YA?AVQLocale@@K ??4QUrl@@QEAAAEAV0@$$QEAV0@ ??1QLocale@@QEAA ?emitLocaleChanged@QPlatformInputContext@ 8960->8967 8961->8924 8970 7ffde65d2c63 ?handleContextMenuEvent@QWindowSystemInterface@@SAXPEAVQWindow@@_NAEBVQPoint@@2V?$QFlags@W4KeyboardModifier@Qt@@@@ 8962->8970 8963->8962 8963->8970 8964->8924 8976 7ffde65d3d13 ?window@QPlatformWindow@@QEBAPEAVQWindow@ 8964->8976 8988 7ffde65d3da8 8965->8988 8966->8924 8984 7ffde65d333e ?window@QPlatformWindow@@QEBAPEAVQWindow@ 8966->8984 8972 7ffde65cf6f0 8967->8972 8968->8973 8981 7ffde65d3c65 ?quit@QCoreApplication@ 8969->8981 8970->8924 8971 7ffde65d26ec 8971->8894 8978 7ffde65f0120 83 API calls 8971->8978 8979 7ffde65d3737 ?isDebugEnabled@QLoggingCategory@ 8972->8979 8973->8924 8980 7ffde65d3e70 ??1QSurfaceFormat@@QEAA 8973->8980 8974->8924 8985 7ffde65d3888 ?window@QPlatformWindow@@QEBAPEAVQWindow@ 8974->8985 8975->8924 8976->8964 8977 7ffde65d3dd5 ?pos@QCursor@@SA?AVQPoint@ 8977->8924 9006 7ffde65d2711 8978->9006 8979->8922 8983 7ffde65d3748 8979->8983 8980->8924 8986 7ffde65d3e82 8980->8986 8981->8924 8982->8924 8993 7ffde65d329c ?window@QPlatformWindow@@QEBAPEAVQWindow@ 8982->8993 8990 7ffde65d374d 15 API calls 8983->8990 8984->8924 8985->8924 9085 7ffde65c1d10 DwmIsCompositionEnabled 8986->9085 8987->8894 8987->8971 8992 7ffde65d2610 ?window@QPlatformWindow@@QEBAPEAVQWindow@ ?isTopLevel@QWindow@ 8987->8992 8988->8924 8988->8977 8989->8924 8991 7ffde65d340f 8989->8991 8990->8922 8991->8924 8995 7ffde65d341a ?maximumSize@QWindow@@QEBA?AVQSize@ 8991->8995 8996 7ffde65d2639 ?flags@QWindow@@QEBA?AV?$QFlags@W4WindowType@Qt@@@ 8992->8996 8997 7ffde65d26d7 ?nextNode@QHashData@@SAPEAUNode@1@PEAU21@ 8992->8997 9034 7ffde65de930 8993->9034 9000 7ffde65d3448 8995->9000 9001 7ffde65d3451 ?scaleAndOrigin@QHighDpiScaling@@SA?AUScaleAndOrigin@1@PEBVQWindow@@PEAVQPoint@@ 8995->9001 8996->8997 9002 7ffde65d2653 DwmGetWindowAttribute 8996->9002 8997->8971 8997->8992 8999->8924 9000->8924 9000->9001 9003 7ffde65d34ae ?mapFromGlobal@QWindow@@QEBA?AVQPoint@@AEBV2@ 9001->9003 9004 7ffde65d2678 DwmGetWindowAttribute 9002->9004 9005 7ffde65d26bd 9002->9005 9003->8924 9004->9005 9007 7ffde65d2694 ??0QMessageLogger@@QEAA@PEBDH0 ?warning@QMessageLogger@ 9004->9007 9005->8997 9006->8894 9008 7ffde65d2760 ?window@QPlatformWindow@@QEBAPEAVQWindow@ ??$handleThemeChange@UDefaultDelivery@QWindowSystemInterface@@@QWindowSystemInterface@@SAXPEAVQWindow@@ ?nextNode@QHashData@@SAPEAUNode@1@PEAU21@ 9006->9008 9007->9005 9008->8894 9008->9008 9010 7ffde65d3b92 ?aboutToShow@QPlatformMenu@ 9010->8924 9011->8924 9013 7ffde65d3a23 ?isDebugEnabled@QLoggingCategory@ 9011->9013 9012->8924 9012->9010 9014 7ffde65d3a92 ?activated@QPlatformMenuItem@ 9013->9014 9015 7ffde65d3a30 9013->9015 9014->8924 9016 7ffde65d3a35 6 API calls 9015->9016 9016->9014 9018 7ffde65c884e ?window@QPlatformWindow@@QEBAPEAVQWindow@ ?isVisible@QWindow@ 9017->9018 9023 7ffde65c888a 9017->9023 9019 7ffde65c8875 GetUpdateRect 9018->9019 9020 7ffde65c8861 GetWindowLongW 9018->9020 9021 7ffde65c8891 9019->9021 9019->9023 9020->9019 9020->9023 9022 7ffde65c88dc BeginPaint DwmIsCompositionEnabled 9021->9022 9024 7ffde65c88b7 DwmIsCompositionEnabled 9021->9024 9025 7ffde65c88ad ?openGLModuleType@QOpenGLContext@@SA?AW4OpenGLModuleType@1 9021->9025 9026 7ffde65c88fa 9022->9026 9023->8924 9027 7ffde65c88ce InvalidateRect 9024->9027 9028 7ffde65c88c8 9024->9028 9025->9024 9025->9027 9029 7ffde65c8920 6 API calls 9026->9029 9030 7ffde65c8914 SelectClipRgn 9026->9030 9027->9022 9028->9022 9028->9027 9031 7ffde65c89bc 9029->9031 9032 7ffde65c89df EndPaint 9029->9032 9030->9029 9031->9032 9033 7ffde65c89d4 ?flushWindowSystemEvents@QWindowSystemInterface@@SA_NV?$QFlags@W4ProcessEventsFlag@QEventLoop@@@@ 9031->9033 9032->9023 9033->9032 9035 7ffde65de9b2 GetWindowLongPtrW 9034->9035 9036 7ffde65de9e0 9034->9036 9035->9036 9038 7ffde65de9c6 GetClientRect 9035->9038 9037 7ffde65dea46 ScreenToClient GetWindowLongPtrW 9036->9037 9039 7ffde65de9ec GetWindowLongPtrW 9036->9039 9040 7ffde65dea79 GetClientRect 9037->9040 9041 7ffde65dea96 9037->9041 9038->9036 9042 7ffde65dea0a GetClientRect 9039->9042 9043 7ffde65dea22 ClientToScreen 9039->9043 9040->9041 9044 7ffde65deaa3 GetKeyState GetKeyState 9041->9044 9042->9043 9043->9044 9045 7ffde65deacb 9044->9045 9046 7ffde65deacf GetKeyState 9044->9046 9045->9046 9047 7ffde65deae3 GetKeyState 9046->9047 9048 7ffde65deadf 9046->9048 9049 7ffde65deb03 9047->9049 9050 7ffde65deaf3 GetKeyState 9047->9050 9048->9047 9051 7ffde65deb07 ?mimeData@QDrag@@QEBAPEAVQMimeData@ GetCapture 9049->9051 9050->9049 9050->9051 9052 7ffde65deb28 9051->9052 9053 7ffde65deb76 ??0QRect@@QEAA@AEBVQPoint@@AEBVQSize@@ ?contains@QRect@@QEBA_NAEBVQPoint@@_N 9052->9053 9054 7ffde65deb50 ?flags@QWindow@@QEBA?AV?$QFlags@W4WindowType@Qt@@@ 9052->9054 9055 7ffde65debba 9053->9055 9054->9055 9056 7ffde65deb65 ?parent@QWindow@@QEBAPEAV1 9054->9056 9059 7ffde65ded01 GetMessageExtraInfo 9055->9059 9060 7ffde65debc8 9055->9060 9056->9053 9056->9054 9062 7ffde65ded78 9059->9062 9066 7ffde65dec2a ?mimeData@QDrag@@QEBAPEAVQMimeData@ 9060->9066 9067 7ffde65dec3b ScreenToClient GetWindowLongPtrW 9060->9067 9083 7ffde65df07f 9060->9083 9061 7ffde65df005 9063 7ffde65df01c ?handleFrameStrutMouseEvent@QWindowSystemInterface@@SA_NPEAVQWindow@@AEBVQPointF@@1V?$QFlags@W4MouseButton@Qt@@@@W4MouseButton@Qt@@W4Type@QEvent@@V?$QFlags@W4KeyboardModifier@Qt@@@@W4MouseEventSource@6@ 9061->9063 9064 7ffde65df086 9061->9064 9062->9061 9068 7ffde65defd7 ??$handleMouseEvent@UDefaultDelivery@QWindowSystemInterface@@@QWindowSystemInterface@@SA_NPEAVQWindow@@AEBVQPointF@@1V?$QFlags@W4MouseButton@Qt@@@@W4MouseButton@Qt@@W4Type@QEvent@@V?$QFlags@W4KeyboardModifier@Qt@@@@W4MouseEventSource@5@ 9062->9068 9069 7ffde65defa7 ?handleFrameStrutMouseEvent@QWindowSystemInterface@@SA_NPEAVQWindow@@AEBVQPointF@@1V?$QFlags@W4MouseButton@Qt@@@@W4MouseButton@Qt@@W4Type@QEvent@@V?$QFlags@W4KeyboardModifier@Qt@@@@W4MouseEventSource@6@ 9062->9069 9062->9083 9063->9083 9065 7ffde65df1d4 9064->9065 9079 7ffde65df094 9064->9079 9093 7ffde65dd0a0 ?mimeData@QDrag@@QEBAPEAVQMimeData@ GetCapture 9065->9093 9066->9067 9071 7ffde65dec99 9067->9071 9072 7ffde65dec7f GetClientRect 9067->9072 9068->9061 9069->9061 9074 7ffde65dec9d ?handleWheelEvent@QWindowSystemInterface@@SA_NPEAVQWindow@@AEBVQPointF@@1VQPoint@@2V?$QFlags@W4KeyboardModifier@Qt@@@@W4ScrollPhase@Qt@@W4MouseEventSource@7@ 9071->9074 9072->9074 9074->9083 9075 7ffde65df207 9076 7ffde65df277 9075->9076 9077 7ffde65df212 ??$handleMouseEvent@UDefaultDelivery@QWindowSystemInterface@@@QWindowSystemInterface@@SA_NPEAVQWindow@@AEBVQPointF@@1V?$QFlags@W4MouseButton@Qt@@@@W4MouseButton@Qt@@W4Type@QEvent@@V?$QFlags@W4KeyboardModifier@Qt@@@@W4MouseEventSource@5@ 9075->9077 9078 7ffde65df285 ?flushWindowSystemEvents@QWindowSystemInterface@@SA_NV?$QFlags@W4ProcessEventsFlag@QEventLoop@@@@ 9076->9078 9076->9083 9077->9076 9078->9083 9080 7ffde65df0fa ?isDebugEnabled@QLoggingCategory@ 9079->9080 9079->9083 9081 7ffde65df179 ??$handleLeaveEvent@UDefaultDelivery@QWindowSystemInterface@@@QWindowSystemInterface@@SAXPEAVQWindow@@ 9080->9081 9082 7ffde65df107 9080->9082 9081->9083 9084 7ffde65df10c 6 API calls 9082->9084 9083->8924 9084->9081 9086 7ffde65c1d28 9085->9086 9087 7ffde65c1d30 9085->9087 9086->8924 9088 7ffde65c1d6b 9087->9088 9089 7ffde65c1d41 CreateRectRgn 9087->9089 9090 7ffde65c1d74 DwmEnableBlurBehindWindow 9088->9090 9089->9090 9091 7ffde65c1d97 9090->9091 9092 7ffde65c1d91 DeleteObject 9090->9092 9091->8924 9092->9091 9094 7ffde65dd0ea 9093->9094 9100 7ffde65dd478 9094->9100 9103 7ffde65dd1b6 ?isDebugEnabled@QLoggingCategory@ 9094->9103 9113 7ffde65dd274 9094->9113 9095 7ffde65dd468 9096 7ffde65dd46d ?getAndRef@ExternalRefCountData@QtSharedPointer@@SAPEAU12@PEBVQObject@@ 9095->9096 9095->9100 9096->9100 9097 7ffde65dd2f0 ?mimeData@QDrag@@QEBAPEAVQMimeData@ 9098 7ffde65dd305 ?type@QWindow@@QEBA?AW4WindowType@Qt@ 9097->9098 9108 7ffde65dd351 9097->9108 9099 7ffde65dd313 ?mimeData@QDrag@@QEBAPEAVQMimeData@ 9098->9099 9098->9108 9101 7ffde65dd332 9099->9101 9100->9075 9105 7ffde65dd336 ?mimeData@QDrag@@QEBAPEAVQMimeData@ 9101->9105 9101->9108 9102 7ffde65dd39a ?isDebugEnabled@QLoggingCategory@ 9106 7ffde65dd416 ??$handleEnterEvent@UDefaultDelivery@QWindowSystemInterface@@@QWindowSystemInterface@@SAXPEAVQWindow@@AEBVQPointF@@1 9102->9106 9107 7ffde65dd3a7 9102->9107 9104 7ffde65dd250 ??$handleLeaveEvent@UDefaultDelivery@QWindowSystemInterface@@@QWindowSystemInterface@@SAXPEAVQWindow@@ 9103->9104 9111 7ffde65dd1c7 9103->9111 9104->9113 9105->9108 9106->9095 9110 7ffde65dd3ac 6 API calls 9107->9110 9108->9102 9110->9106 9112 7ffde65dd1e5 6 API calls 9111->9112 9112->9104 9113->9095 9113->9096 9113->9097 9113->9100 9126 7ffde6632fe0 9127 7ffde663301a malloc malloc malloc 9126->9127 9128 7ffde6633081 9126->9128 9127->9128 9128->9128 9129 7ffde66331de 9128->9129 9130 7ffde66331ca ?qErrnoWarning@ 9128->9130 9131 7ffde66331f1 free 9129->9131 9132 7ffde66331f7 9129->9132 9130->9129 9131->9132 9133 7ffde6633210 9132->9133 9134 7ffde663320a free 9132->9134 9135 7ffde663321d free 9133->9135 9136 7ffde6633223 9133->9136 9134->9133 9135->9136 9188 7ffde6609fe0 9189 7ffde660a005 9188->9189 9190 7ffde660a049 9189->9190 9191 7ffde65ce110 2 API calls 9189->9191 9192 7ffde660a064 9190->9192 9206 7ffde660a193 9190->9206 9193 7ffde660a025 9191->9193 9194 7ffde660a06f 9192->9194 9195 7ffde660a0f1 9192->9195 9193->9190 9216 7ffde66096e0 9193->9216 9196 7ffde660a078 ?isDebugEnabled@QLoggingCategory@ 9194->9196 9197 7ffde660a101 ?isDebugEnabled@QLoggingCategory@ 9195->9197 9199 7ffde660a164 9195->9199 9196->9199 9200 7ffde660a089 9196->9200 9198 7ffde660a10e 9197->9198 9197->9199 9204 7ffde660a113 ??0QMessageLogger@@QEAA@PEBDH00 ?debug@QMessageLogger@@QEBA?AVQDebug@ ??6QDebug@@QEAAAEAV0@PEBD ??6QDebug@@QEAAAEAV0@PEBX ??1QDebug@@QEAA 9198->9204 9201 7ffde660a08e ??0QMessageLogger@@QEAA@PEBDH00 ?debug@QMessageLogger@@QEBA?AVQDebug@ ??6QDebug@@QEAAAEAV0@PEBD ??6QDebug@@QEAAAEAV0@PEBX ??1QDebug@@QEAA 9200->9201 9202 7ffde660a21e ?swapInterval@QSurfaceFormat@ ??1QSurfaceFormat@@QEAA 9210 7ffde660a251 9202->9210 9203 7ffde660a288 9207 7ffde660a2a4 9203->9207 9208 7ffde660a33b ??0QMessageLogger@@QEAA@PEBDH0 ?warning@QMessageLogger@ 9203->9208 9204->9199 9206->9202 9206->9203 9211 7ffde660a1e7 9206->9211 9209 7ffde660a2b1 ?isDebugEnabled@QLoggingCategory@ 9207->9209 9208->9210 9212 7ffde660a2be 9209->9212 9213 7ffde660a314 9209->9213 9214 7ffde660a2c3 ??0QMessageLogger@@QEAA@PEBDH00 ?debug@QMessageLogger@@QEBA?AVQDebug@ ??6QDebug@@QEAAAEAV0@PEBD ??6QDebug@@QEAAAEAV0@PEBX ??1QDebug@@QEAA 9212->9214 9214->9213 9217 7ffde6609711 9216->9217 9218 7ffde6609758 9217->9218 9219 7ffde6609726 ??0QMessageLogger@@QEAA@PEBDH0 ?warning@QMessageLogger@ 9217->9219 9218->9190 9219->9218 9220 7ffde64dba08 9221 7ffde64dba22 malloc 9220->9221 9222 7ffde64dba2c 9221->9222 9223 7ffde64dba13 9221->9223 9223->9221 9224 7ffde64dba32 9223->9224 9226 7ffde64dba3d 9224->9226 9227 7ffde64dc984 9224->9227 9230 7ffde64dc874 9227->9230 9229 7ffde64dc992 _CxxThrowException 9230->9229 9565 7ffde65ce4f0 9566 7ffde65ce4fe 9565->9566 9567 7ffde6622d50 ??0QEventDispatcherWin32@@QEAA@PEAVQObject@@ ?setObjectName@QObject@@QEAAXAEBVQString@@ ??1?$QVector@VQPointF@@@@QEAA ?createInternalHwnd@QEventDispatcherWin32@ 9566->9567 9568 7ffde65d2cf0 9569 7ffde65d2d67 9568->9569 9570 7ffde65d2cf4 9568->9570 9571 7ffde65c7ff0 24 API calls 9569->9571 9572 7ffde65c7ff0 24 API calls 9570->9572 9573 7ffde65d23ae 9570->9573 9571->9573 9572->9573
                                                      APIs
                                                      • GetWindowLongPtrW.USER32 ref: 00007FFDE65D2194
                                                      • GetClientRect.USER32 ref: 00007FFDE65D21A9
                                                        • Part of subcall function 00007FFDE65EC760: ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65D23C2), ref: 00007FFDE65EC776
                                                        • Part of subcall function 00007FFDE65EC760: ??0QMessageLogger@@QEAA@PEBDH00@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65D23C2), ref: 00007FFDE65EC79B
                                                        • Part of subcall function 00007FFDE65EC760: ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65D23C2), ref: 00007FFDE65EC7AC
                                                        • Part of subcall function 00007FFDE65EC760: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65D23C2), ref: 00007FFDE65EC7BC
                                                        • Part of subcall function 00007FFDE65EC760: ??6QDebug@@QEAAAEAV0@_N@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65D23C2), ref: 00007FFDE65EC7C9
                                                        • Part of subcall function 00007FFDE65EC760: ??6QDebug@@QEAAAEAV0@PEBX@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65D23C2), ref: 00007FFDE65EC7D5
                                                        • Part of subcall function 00007FFDE65EC760: ??1QDebug@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65D23C2), ref: 00007FFDE65EC7E3
                                                        • Part of subcall function 00007FFDE65EC760: ?language@QLocale@@QEBA?AW4Language@1@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65D23C2), ref: 00007FFDE65EC824
                                                        • Part of subcall function 00007FFDE65EC760: ?queryKeyboardModifiers@QGuiApplication@@SA?AV?$QFlags@W4KeyboardModifier@Qt@@@@XZ.QT5GUI(?,?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65D23C2), ref: 00007FFDE65EC837
                                                        • Part of subcall function 00007FFDE65CFA50: ?get@QObjectPrivate@@SAPEAV1@PEAVQObject@@@Z.QT5CORE ref: 00007FFDE65CFA5E
                                                        • Part of subcall function 00007FFDE65CFA50: ?get@QObjectPrivate@@SAPEAV1@PEAVQObject@@@Z.QT5CORE ref: 00007FFDE65CFA6B
                                                      • ClientToScreen.USER32 ref: 00007FFDE65D21BF
                                                      • GetCursorPos.USER32 ref: 00007FFDE65D21CB
                                                      • ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ.QT5GUI ref: 00007FFDE65D22B8
                                                      • ?handleNativeEvent@QWindowSystemInterface@@SA_NPEAVQWindow@@AEBVQByteArray@@PEAXPEAJ@Z.QT5GUI ref: 00007FFDE65D22E1
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65D22EF
                                                      • ?cast@QMetaObject@@QEBAPEAVQObject@@PEAV2@@Z.QT5CORE ref: 00007FFDE65D233A
                                                      • ImmAssociateContext.IMM32 ref: 00007FFDE65D2366
                                                      • ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ.QT5GUI ref: 00007FFDE65D323C
                                                      • ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ.QT5GUI ref: 00007FFDE65D3353
                                                      • ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ.QT5GUI ref: 00007FFDE65D33A6
                                                      • ?isTopLevel@QWindow@@QEBA_NXZ.QT5GUI ref: 00007FFDE65D33B2
                                                      • ?minimumSize@QWindow@@QEBA?AVQSize@@XZ.QT5GUI ref: 00007FFDE65D33FE
                                                      • ?maximumSize@QWindow@@QEBA?AVQSize@@XZ.QT5GUI ref: 00007FFDE65D3422
                                                      • ?scaleAndOrigin@QHighDpiScaling@@SA?AUScaleAndOrigin@1@PEBVQWindow@@PEAVQPoint@@@Z.QT5GUI ref: 00007FFDE65D3465
                                                      • ?mapFromGlobal@QWindow@@QEBA?AVQPoint@@AEBV2@@Z.QT5GUI ref: 00007FFDE65D3535
                                                      • ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ.QT5GUI ref: 00007FFDE65D35CD
                                                      • ?flags@QWindow@@QEBA?AV?$QFlags@W4WindowType@Qt@@@@XZ.QT5GUI ref: 00007FFDE65D35E8
                                                      • ?parent@QWindow@@QEBAPEAV1@XZ.QT5GUI ref: 00007FFDE65D35F9
                                                      • ?cast@QMetaObject@@QEBAPEAVQObject@@PEAV2@@Z.QT5CORE ref: 00007FFDE65D36E0
                                                      • ?qt_localeFromLCID@@YA?AVQLocale@@K@Z.QT5CORE ref: 00007FFDE65D370C
                                                      • ??4QUrl@@QEAAAEAV0@$$QEAV0@@Z.QT5CORE ref: 00007FFDE65D3719
                                                      • ??1QLocale@@QEAA@XZ.QT5CORE ref: 00007FFDE65D3723
                                                      • ?emitLocaleChanged@QPlatformInputContext@@QEAAXXZ.QT5GUI ref: 00007FFDE65D372C
                                                      • ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ.QT5CORE ref: 00007FFDE65D373A
                                                      • ??0QMessageLogger@@QEAA@PEBDH00@Z.QT5CORE ref: 00007FFDE65D3762
                                                      • ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ.QT5CORE ref: 00007FFDE65D3770
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE65D3780
                                                      • ??6QDebug@@QEAAAEAV0@P6AAEAVQTextStream@@AEAV1@@Z@Z.QT5CORE ref: 00007FFDE65D3790
                                                      • ??6QDebug@@QEAAAEAV0@P6AAEAVQTextStream@@AEAV1@@Z@Z.QT5CORE ref: 00007FFDE65D37A0
                                                      • ??6QDebug@@QEAAAEAV0@I@Z.QT5CORE ref: 00007FFDE65D37AC
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE65D37BC
                                                      • ??6QDebug@@QEAAAEAV0@I@Z.QT5CORE ref: 00007FFDE65D37C7
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE65D37D7
                                                      • ??6QDebug@@QEAAAEAV0@I@Z.QT5CORE ref: 00007FFDE65D37E2
                                                      • ??6QDebug@@QEAAAEAV0@P6AAEAVQTextStream@@AEAV1@@Z@Z.QT5CORE ref: 00007FFDE65D37F2
                                                      • ??6QDebug@@QEAAAEAV0@P6AAEAVQTextStream@@AEAV1@@Z@Z.QT5CORE ref: 00007FFDE65D3802
                                                      • ??6@YA?AVQDebug@@V0@AEBVQLocale@@@Z.QT5CORE ref: 00007FFDE65D381E
                                                      • ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE65D3828
                                                      • ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE65D3833
                                                      • ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ.QT5GUI ref: 00007FFDE65D389D
                                                      • ?get@QObjectPrivate@@SAPEAV1@PEAVQObject@@@Z.QT5CORE ref: 00007FFDE65D38D7
                                                      • ?get@QObjectPrivate@@SAPEAV1@PEAVQObject@@@Z.QT5CORE ref: 00007FFDE65D38E4
                                                      • ?get@QObjectPrivate@@SAPEAV1@PEAVQObject@@@Z.QT5CORE ref: 00007FFDE65D3908
                                                      • ?commitData@QGuiApplicationPrivate@@QEAAXXZ.QT5GUI ref: 00007FFDE65D3911
                                                      • fflush.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 00007FFDE65D3920
                                                      • ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ.QT5CORE ref: 00007FFDE65D3A26
                                                      • ??0QMessageLogger@@QEAA@PEBDH00@Z.QT5CORE ref: 00007FFDE65D3A4A
                                                      • ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ.QT5CORE ref: 00007FFDE65D3A57
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE65D3A67
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE65D3A77
                                                      • ??6QDebug@@QEAAAEAV0@I@Z.QT5CORE ref: 00007FFDE65D3A82
                                                      • ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE65D3A8C
                                                      • ?activated@QPlatformMenuItem@@QEAAXXZ.QT5GUI ref: 00007FFDE65D3A95
                                                      • ?aboutToShow@QPlatformMenu@@QEAAXXZ.QT5GUI ref: 00007FFDE65D3B95
                                                      • ?get@QObjectPrivate@@SAPEAV1@PEAVQObject@@@Z.QT5CORE ref: 00007FFDE65D3BDD
                                                      • ?get@QObjectPrivate@@SAPEAV1@PEAVQObject@@@Z.QT5CORE ref: 00007FFDE65D3BEA
                                                      • ?get@QObjectPrivate@@SAPEAV1@PEAVQObject@@@Z.QT5CORE ref: 00007FFDE65D3C0F
                                                      • ?indexOfSignal@QMetaObject@@QEBAHPEBD@Z.QT5CORE ref: 00007FFDE65D3C40
                                                      • ?quit@QCoreApplication@@SAXXZ.QT5CORE ref: 00007FFDE65D3C65
                                                      • ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ.QT5GUI ref: 00007FFDE65D3C85
                                                      • ??$handleThemeChange@UDefaultDelivery@QWindowSystemInterface@@@QWindowSystemInterface@@SAXPEAVQWindow@@@Z.QT5GUI ref: 00007FFDE65D3CA1
                                                      • ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ.QT5GUI ref: 00007FFDE65D3D28
                                                        • Part of subcall function 00007FFDE65DC600: ??0QMessageLogger@@QEAA@PEBDH0@Z.QT5CORE ref: 00007FFDE65DC679
                                                        • Part of subcall function 00007FFDE65DC600: ?warning@QMessageLogger@@QEBA?AVQDebug@@XZ.QT5CORE ref: 00007FFDE65DC689
                                                        • Part of subcall function 00007FFDE65DC600: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE65DC699
                                                        • Part of subcall function 00007FFDE65DC600: ?qt_error_string@@YA?AVQString@@H@Z.QT5CORE ref: 00007FFDE65DC6AE
                                                        • Part of subcall function 00007FFDE65DC600: ??6QDebug@@QEAAAEAV0@AEBVQString@@@Z.QT5CORE ref: 00007FFDE65DC6BA
                                                        • Part of subcall function 00007FFDE65DC600: ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65DC6C7
                                                        • Part of subcall function 00007FFDE65DC600: ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE65DC6D4
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$Window@@$Platform$Private@@$?get@?window@Logger@@MessageObjectObject@@@$Object@@Window$Stream@@TextV1@@$?debug@Category@@DebugEnabled@H00@Locale@@LoggingMetaSystemV2@@$??1?$?cast@Application@@ClientF@@@@Flags@FromInterface@@KeyboardPointQt@@@@Size@Size@@Vector@$??$handle??6@?about?activated@?commit?emit?flags@?handle?index?language@?map?maximum?minimum?parent@?qt_error_string@@?qt_locale?query?quit@?scale?warning@ApplicationArray@@AssociateByteChange@Changed@ContextContext@@CoreCursorData@DefaultDelivery@Event@Global@HighInputInterface@@@Item@@Language@1@Level@LocaleLocale@@@LongMenuMenu@@Modifier@Modifiers@NativeOrigin@Origin@1@Point@@Point@@@RectScaleScaling@@ScreenShow@Signal@String@@String@@@ThemeType@Url@@V0@$$V0@@V0@_Window@@@fflush
                                                      • String ID: %s: No Qt Window found for event 0x%x (%s), hwnd=0x%p.$%s: Unable to retrieve dark window border setting.$, parent: $, transient parent: $Character set:$EnableNonClientDpiScaling() failed for HWND %p (%lu)$Event window: $External WM_DESTROY received for $QWindowsContext::windowsProc$QWindowsInputContext::handleInputLanguageChanged$QWindowsMenuBar::notifyTriggered$aboutToQuit()$id=$queryDarkBorder
                                                      • API String ID: 972920150-3461297862
                                                      • Opcode ID: 099e89f3ceb5742226654282a8ce6c541295897a68023f6a14e079a1a04667cf
                                                      • Instruction ID: 78ada3198538635e2abc2054a39d17063dbb6a2c12a8fd7a887ba3ef14a12130
                                                      • Opcode Fuzzy Hash: 099e89f3ceb5742226654282a8ce6c541295897a68023f6a14e079a1a04667cf
                                                      • Instruction Fuzzy Hash: 73E28331F28A8281EB1A9B69E8643BE67A0FF95B84F054135DE4E477A4DF3CE445C702

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 447 7ffde66294c0-7ffde662956d call 7ffde6628890 450 7ffde662961f-7ffde662963d call 7ffde6623db0 447->450 451 7ffde6629573-7ffde6629583 CreateFontIndirectW 447->451 461 7ffde6629643-7ffde66296b2 ?fromWCharArray@QString@@SA?AV1@PEB_WH@Z ??0QWinRegistryKey@@QEAA@PEAUHKEY__@@VQStringView@@KK@Z ?isNull@QString@@QEBA_NXZ 450->461 462 7ffde6629cb4-7ffde6629d0f call 7ffde66c5438 call 7ffde662ea10 450->462 452 7ffde66295a1-7ffde66295cd SelectObject GetTextMetricsW 451->452 453 7ffde6629585-7ffde662959e ?qErrnoWarning@@YAXPEBDZZ call 7ffde6628820 451->453 456 7ffde66295cf-7ffde66295e3 ?qErrnoWarning@@YAXPEBDZZ 452->456 457 7ffde66295e5-7ffde6629600 452->457 453->452 460 7ffde6629603-7ffde6629619 SelectObject DeleteObject 456->460 457->460 460->450 464 7ffde66296b4-7ffde66296b7 461->464 465 7ffde66296b9-7ffde66296be ?constData@QString@@QEBAPEBVQChar@@XZ 461->465 477 7ffde6629d11 462->477 478 7ffde6629d1b-7ffde6629da8 call 7ffde6631bd0 SelectObject GetTextFaceW ?fromWCharArray@QString@@SA?AV1@PEB_WH@Z ??4QUrl@@QEAAAEAV0@$$QEAV0@@Z ??1?$QVector@VQPointF@@@@QEAA@XZ 462->478 466 7ffde66296c4-7ffde6629735 ?stringValue@QWinRegistryKey@@QEBA?AVQString@@VQStringView@@@Z ??1QWinRegistryKey@@QEAA@XZ ??0QByteArray@@QEAA@AEBV0@@Z ??1?$QVector@VQPointF@@@@QEAA@XZ ??8@YA_NAEBVQString@@0@Z 464->466 465->466 468 7ffde662976e-7ffde6629780 CreateFontIndirectW 466->468 469 7ffde6629737-7ffde6629769 ?utf16@QString@@QEBAPEBGXZ memmove 466->469 471 7ffde6629782-7ffde6629796 ?qErrnoWarning@@YAXPEBDZZ 468->471 472 7ffde662979b-7ffde66297c3 SelectObject 468->472 469->468 474 7ffde6629c91-7ffde6629caa ??1?$QVector@VQPointF@@@@QEAA@XZ * 2 471->474 475 7ffde66297c5-7ffde66297c8 472->475 476 7ffde66297ca-7ffde66297fc ?startsWith@QString@@QEBA_NVQLatin1String@@W4CaseSensitivity@Qt@@@Z 472->476 474->462 483 7ffde6629cac-7ffde6629caf 474->483 480 7ffde6629814-7ffde662983e 475->480 481 7ffde66297fe-7ffde6629801 476->481 482 7ffde6629811 476->482 477->478 487 7ffde6629dc7-7ffde6629dd4 478->487 488 7ffde6629daa-7ffde6629dc5 478->488 492 7ffde6629844-7ffde662986b 480->492 493 7ffde6629b72-7ffde6629b75 480->493 481->482 485 7ffde6629803-7ffde6629806 481->485 482->480 486 7ffde6629e2f-7ffde6629e64 call 7ffde66c51b0 483->486 485->482 489 7ffde6629808-7ffde662980a 485->489 494 7ffde6629e2c 487->494 495 7ffde6629dd6 487->495 488->494 489->482 496 7ffde662980c-7ffde662980f 489->496 505 7ffde662986d-7ffde6629884 492->505 506 7ffde66298b3-7ffde66298b6 492->506 498 7ffde6629c72-7ffde6629c8b SelectObject DeleteObject 493->498 499 7ffde6629b7b-7ffde6629c6c ?qt_error_string@@YA?AVQString@@H@Z ??0QMessageLogger@@QEAA@PEBDH0@Z ?warning@QMessageLogger@@QEBA?AVQDebug@@XZ ?noquote@QDebug@@QEAAAEAV1@XZ ??6QDebug@@QEAAAEAV0@PEBD@Z ??6QDebug@@QEAAAEAV0@AEBVQString@@@Z ??6QDebug@@QEAAAEAV0@PEBD@Z call 7ffde6623e30 ??6QDebug@@QEAAAEAV0@D@Z call 7ffde6623fc0 ??6QDebug@@QEAAAEAV0@PEBD@Z ??6QDebug@@QEAAAEAV0@H@Z ??1QDebug@@QEAA@XZ * 3 ??1?$QVector@VQPointF@@@@QEAA@XZ 493->499 494->486 495->494 500 7ffde6629dd8-7ffde6629dee 495->500 496->480 498->474 499->498 503 7ffde6629df0-7ffde6629df8 500->503 504 7ffde6629dfa-7ffde6629e1d 500->504 508 7ffde6629e1f-7ffde6629e27 503->508 504->508 517 7ffde66298a1-7ffde66298a9 505->517 518 7ffde6629886-7ffde662989d 505->518 510 7ffde66298b8-7ffde66298ca call 7ffde6623250 506->510 511 7ffde66298cc 506->511 508->494 510->511 512 7ffde66298cf-7ffde66298df call 7ffde6623010 ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ 510->512 511->512 521 7ffde6629a08-7ffde6629a0b 512->521 522 7ffde66298e5-7ffde6629a02 call 7ffde6623010 ??0QMessageLogger@@QEAA@PEBDH00@Z ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ ??6QDebug@@QEAAAEAV0@PEBD@Z ??6QDebug@@QEAAAEAV0@AEBVQString@@@Z ??6QDebug@@QEAAAEAV0@N@Z ??6QDebug@@QEAAAEAV0@PEBD@Z * 2 ?qt_QMetaEnum_debugOperator@@YA?AVQDebug@@AEAV1@HPEBUQMetaObject@@PEBD@Z ??1QDebug@@QEAA@XZ ??6QDebug@@QEAAAEAV0@PEBD@Z ??6QDebug@@QEAAAEAV0@_N@Z ??6QDebug@@QEAAAEAV0@H@Z ??6QDebug@@QEAAAEAV0@PEBD@Z * 2 ??6QDebug@@QEAAAEAV0@_N@Z ??1QDebug@@QEAA@XZ * 2 512->522 517->506 518->517 525 7ffde6629a11-7ffde6629a54 call 7ffde66c5438 call 7ffde6631f70 GetTextFaceW call 7ffde6622f00 521->525 526 7ffde6629b56-7ffde6629b6d 521->526 522->521 534 7ffde6629a59-7ffde6629a89 ?fromWCharArray@QString@@SA?AV1@PEB_WH@Z ??4QUrl@@QEAAAEAV0@$$QEAV0@@Z ??1?$QVector@VQPointF@@@@QEAA@XZ 525->534 526->498 535 7ffde6629a95-7ffde6629aac call 7ffde6631bd0 534->535 536 7ffde6629a8b 534->536 539 7ffde6629aae-7ffde6629ac9 535->539 540 7ffde6629acb-7ffde6629ad8 535->540 536->535 541 7ffde6629b30-7ffde6629b50 call 7ffde65ce830 ??1?$QVector@VQPointF@@@@QEAA@XZ call 7ffde65ce830 ??1?$QVector@VQPointF@@@@QEAA@XZ 539->541 540->541 542 7ffde6629ada 540->542 541->526 542->541 543 7ffde6629adc-7ffde6629af2 542->543 545 7ffde6629afe-7ffde6629b21 543->545 546 7ffde6629af4-7ffde6629afc 543->546 548 7ffde6629b23-7ffde6629b2b 545->548 546->548 548->541
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$String@@$??1?$F@@@@PointVector@$Object$Select$Logger@@MessageV0@@$?fromArray@CharErrnoKey@@RegistryTextWarning@@$Array@@ByteCreateDeleteFaceFontIndirectMetaStringString@@@Url@@V0@$$V0@_$??8@?const?debug@?noquote@?qt_?qt_error_string@@?starts?string?utf16@?warning@CaseCategory@@Char@@Data@DebugEnabled@Enum_debugH00@Latin1LoggingMetricsNull@Object@@Operator@@Qt@@@Sensitivity@String@@0@Value@View@@View@@@With@Y__@@memmove
                                                      • String ID: dpi=$%s: CreateFontIndirect failed$%s: GetTextMetrics failed$) for $<$DirectWrite: CreateFontFaceFromHDC() failed ($HintingPreference$MingLiU$QWindowsFontDatabase::createEngine$Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes$color=$dpi$hintingPreference=$useDirectWrite=
                                                      • API String ID: 3409923752-3805862585
                                                      • Opcode ID: 4e1a66988d13864a25dcb76bcf4ed2102b03b2963aedf7093d636897579204af
                                                      • Instruction ID: dd5125057bcec6b1eb800e726b244a0719d4b3d1574aba133b8935432a5440a4
                                                      • Opcode Fuzzy Hash: 4e1a66988d13864a25dcb76bcf4ed2102b03b2963aedf7093d636897579204af
                                                      • Instruction Fuzzy Hash: 8252B022B38E4286EB19DF25E8642B97770FF94B94F00527ADA4E17664EF3CE445CB01

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 551 7ffde65c2a50-7ffde65c2b20 GetModuleHandleW call 7ffde65d1210 ?initialGeometry@QPlatformWindow@@SA?AVQRect@@PEBVQWindow@@AEBV2@HHPEAPEBVQScreen@@@Z 554 7ffde65c2b70-7ffde65c2c37 ?utf16@QString@@QEBAPEBGXZ * 2 call 7ffde66c5438 call 7ffde65c4c50 call 7ffde66c5438 call 7ffde65c1210 * 2 551->554 555 7ffde65c2b22-7ffde65c2b28 551->555 570 7ffde65c2c39-7ffde65c2c3c 554->570 571 7ffde65c2c40-7ffde65c2c62 554->571 555->554 556 7ffde65c2b2a-7ffde65c2b2f 555->556 559 7ffde65c2b4d-7ffde65c2b66 ?objectName@QObject@@QEBA?AVQString@@XZ ??4QUrl@@QEAAAEAV0@$$QEAV0@@Z 556->559 560 7ffde65c2b31-7ffde65c2b4b ?qAppName@@YA?AVQString@@XZ ??4QUrl@@QEAAAEAV0@$$QEAV0@@Z 556->560 562 7ffde65c2b6a ??1?$QVector@VQPointF@@@@QEAA@XZ 559->562 560->562 562->554 570->571 572 7ffde65c2c95-7ffde65c2c98 571->572 573 7ffde65c2c64-7ffde65c2c70 571->573 574 7ffde65c2cc8-7ffde65c2ce2 572->574 575 7ffde65c2c9a-7ffde65c2ca5 572->575 576 7ffde65c2c7f-7ffde65c2c8b 573->576 577 7ffde65c2c72-7ffde65c2c76 573->577 580 7ffde65c2d1a-7ffde65c2d24 574->580 581 7ffde65c2ce4-7ffde65c2ce6 574->581 578 7ffde65c2ca7-7ffde65c2cab 575->578 579 7ffde65c2cb4-7ffde65c2cbe 575->579 576->572 582 7ffde65c2c8d-7ffde65c2c90 call 7ffde66c57f4 576->582 577->576 578->579 579->574 584 7ffde65c2cc0-7ffde65c2cc3 call 7ffde66c57f4 579->584 586 7ffde65c2d2c-7ffde65c2d43 call 7ffde65cf4b0 ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ 580->586 581->580 585 7ffde65c2ce8-7ffde65c2cf8 ?qt_window_private@@YAPEAVQWindowPrivate@@PEAVQWindow@@@Z 581->585 582->572 584->574 585->580 589 7ffde65c2cfa-7ffde65c2d18 call 7ffde65c2050 585->589 592 7ffde65c2d49-7ffde65c2f2a call 7ffde65cf4b0 ??0QMessageLogger@@QEAA@PEBDH00@Z ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ ??6QDebug@@QEAAAEAV0@PEBD@Z ??6@YA?AVQDebug@@V0@PEBVQWindow@@@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6QDebug@@QEAAAEAV0@AEBVQString@@@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6QDebug@@QEAAAEAV0@AEBVQString@@@Z ??6QDebug@@QEAAAEAV0@D@Z call 7ffde65c2170 ??6QDebug@@QEAAAEAV0@PEBD@Z ??6@YA?AVQDebug@@V0@AEBVQRect@@@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6QDebug@@QEAAAEAV0@H@Z ??6QDebug@@QEAAAEAV0@D@Z ??6QDebug@@QEAAAEAV0@H@Z ??6QDebug@@QEAAAEAV0@D@Z ??6QDebug@@QEAAAEAV0@H@Z ??6QDebug@@QEAAAEAV0@D@Z ??6QDebug@@QEAAAEAV0@H@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6@YA?AVQDebug@@V0@AEBVQMargins@@@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6@YA?AVQDebug@@V0@AEBVQMargins@@@Z ??1QDebug@@QEAA@XZ * 6 586->592 593 7ffde65c2f30-7ffde65c2f52 call 7ffde65c2370 ?isTopLevel@QWindow@@QEBA_NXZ 586->593 589->586 592->593 600 7ffde65c2fac 593->600 601 7ffde65c2f54-7ffde65c2f68 GetWindowLongPtrW 593->601 602 7ffde65c2fb0-7ffde65c301a CreateWindowExW call 7ffde65cf4b0 ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ 600->602 601->600 604 7ffde65c2f6a-7ffde65c2f84 GetClientRect 601->604 609 7ffde65c314b-7ffde65c3150 602->609 610 7ffde65c3020-7ffde65c3041 602->610 604->600 606 7ffde65c2f86-7ffde65c2f90 604->606 606->602 608 7ffde65c2f92-7ffde65c2f9c 606->608 608->602 611 7ffde65c2f9e-7ffde65c2faa 608->611 614 7ffde65c316b-7ffde65c3172 609->614 615 7ffde65c3152-7ffde65c3166 ?qErrnoWarning@@YAXPEBDZZ 609->615 612 7ffde65c3047-7ffde65c3145 ??0QMessageLogger@@QEAA@PEBDH00@Z ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ ??6QDebug@@QEAAAEAV0@PEBD@Z ??6@YA?AVQDebug@@V0@PEBVQWindow@@@Z ??6QDebug@@QEAAAEAV0@D@Z ??6QDebug@@QEAAAEAV0@PEBX@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6@YA?AVQDebug@@V0@AEBVQPoint@@@Z ??6@YA?AVQDebug@@V0@AEBVQSize@@@Z ??6QDebug@@QEAAAEAV0@D@Z ??6@YA?AVQDebug@@V0@AEBVQMargins@@@Z ??1QDebug@@QEAA@XZ * 4 610->612 613 7ffde65c326d-7ffde65c3280 call 7ffde66c5328 610->613 611->602 612->609 613->612 629 7ffde65c3286-7ffde65c32b2 ??0QLoggingCategory@@QEAA@PEBD@Z call 7ffde66c57dc _Init_thread_footer 613->629 617 7ffde65c31b5-7ffde65c31bf 614->617 618 7ffde65c3174-7ffde65c3185 614->618 616 7ffde65c3205-7ffde65c3210 615->616 620 7ffde65c321f-7ffde65c3228 616->620 621 7ffde65c3212-7ffde65c3216 616->621 624 7ffde65c31c7-7ffde65c3201 ??0QRect@@QEAA@AEBVQPoint@@AEBVQSize@@@Z 617->624 625 7ffde65c31c1-7ffde65c31c5 617->625 618->617 622 7ffde65c3187-7ffde65c3192 ?isTopLevel@QWindow@@QEBA_NXZ 618->622 626 7ffde65c322a-7ffde65c322d call 7ffde66c57f4 620->626 627 7ffde65c3232-7ffde65c326c ??1?$QVector@VQPointF@@@@QEAA@XZ * 2 call 7ffde66c51b0 620->627 621->620 622->617 628 7ffde65c3194-7ffde65c31a8 ?flags@QWindow@@QEBA?AV?$QFlags@W4WindowType@Qt@@@@XZ 622->628 624->616 625->624 626->627 628->617 632 7ffde65c31aa-7ffde65c31b0 call 7ffde65cbb80 628->632 629->612 632->617
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$??6@$String@@$Window@@$String@@@Window$Logger@@Message$??1?$Category@@F@@@@Latin1LoggingMargins@@@PointVariant@@Vector@Window@@@$?debug@?flags@?utf16@DebugEnabled@Flags@H00@Level@Object@@Qt@@@@Rect@@Size@@@Type@Url@@V0@$$V0@@$?initial?object?property@?qt_window_private@@Bool@ClientCreateCriticalEnterErrnoGeometry@HandleInit_thread_footerLongModuleName@Name@@PlatformPoint@@Point@@@Private@@RectRect@@@Screen@@@SectionWarning@@
                                                      • String ID: requested: $ class=$ custom margins: $ invisible margins: $ obtained geometry: $ title=$%s: CreateWindowEx failed$CreateWindowEx: $CreateWindowEx: returns $WindowCreationData::create$qt.qpa.windows
                                                      • API String ID: 1247539359-549300269
                                                      • Opcode ID: 5b57ecdac2e29d266d2f446aca85aa8a6d451eed4a2036ee483128a3dccd131d
                                                      • Instruction ID: 58e6a2aa11ec3046105bb4b634826708ef6d3771532753c2fa3da6fea86289af
                                                      • Opcode Fuzzy Hash: 5b57ecdac2e29d266d2f446aca85aa8a6d451eed4a2036ee483128a3dccd131d
                                                      • Instruction Fuzzy Hash: 17427D76B24F4286EB18EF65E8642AD3760FB84B98F41413ADA0E43764DF3CD589CB41

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 637 7ffde65f0120-7ffde65f0153 call 7ffde65efec0 ?desktopSettingsAware@QGuiApplication@@SA_NXZ 640 7ffde65f0159-7ffde65f019b call 7ffde65cc190 637->640 641 7ffde65f0874-7ffde65f088c call 7ffde66c51b0 637->641 646 7ffde65f01a1-7ffde65f01a5 640->646 647 7ffde65f019d-7ffde65f019f 640->647 648 7ffde65f01a9-7ffde65f01ad call 7ffde65d1f20 646->648 647->648 650 7ffde65f01b2-7ffde65f01c2 call 7ffde65cf4b0 ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ 648->650 653 7ffde65f01c4-7ffde65f022a call 7ffde65cf4b0 ??0QMessageLogger@@QEAA@PEBDH00@Z ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ ??6QDebug@@QEAAAEAV0@PEBD@Z call 7ffde65eff40 ??1QDebug@@QEAA@XZ * 2 650->653 654 7ffde65f0230-7ffde65f0290 ?fromWCharArray@QString@@SA?AV1@PEB_WH@Z ??0QFont@@QEAA@AEBVQString@@HH_N@Z ??1?$QVector@VQPointF@@@@QEAA@XZ ?setItalic@QFont@@QEAAX_N@Z 650->654 653->654 656 7ffde65f02a5-7ffde65f02ad 654->656 657 7ffde65f0292-7ffde65f029f ?weightFromInteger@QPlatformFontDatabase@@SA?AW4Weight@QFont@@H@Z ?setWeight@QFont@@QEAAXH@Z 654->657 658 7ffde65f02b1-7ffde65f036f ?setPointSizeF@QFont@@QEAAXN@Z ?setUnderline@QFont@@QEAAX_N@Z ?setOverline@QFont@@QEAAX_N@Z ?setStrikeOut@QFont@@QEAAX_N@Z ?fromWCharArray@QString@@SA?AV1@PEB_WH@Z ??0QFont@@QEAA@AEBVQString@@HH_N@Z ??1?$QVector@VQPointF@@@@QEAA@XZ ?setItalic@QFont@@QEAAX_N@Z 656->658 659 7ffde65f02af 656->659 657->656 661 7ffde65f0384-7ffde65f038c 658->661 662 7ffde65f0371-7ffde65f037e ?weightFromInteger@QPlatformFontDatabase@@SA?AW4Weight@QFont@@H@Z ?setWeight@QFont@@QEAAXH@Z 658->662 659->658 664 7ffde65f0390-7ffde65f0446 ?setPointSizeF@QFont@@QEAAXN@Z ?setUnderline@QFont@@QEAAX_N@Z ?setOverline@QFont@@QEAAX_N@Z ?setStrikeOut@QFont@@QEAAX_N@Z ?fromWCharArray@QString@@SA?AV1@PEB_WH@Z ??0QFont@@QEAA@AEBVQString@@HH_N@Z ??1?$QVector@VQPointF@@@@QEAA@XZ ?setItalic@QFont@@QEAAX_N@Z 661->664 665 7ffde65f038e 661->665 662->661 667 7ffde65f045b-7ffde65f0463 664->667 668 7ffde65f0448-7ffde65f0455 ?weightFromInteger@QPlatformFontDatabase@@SA?AW4Weight@QFont@@H@Z ?setWeight@QFont@@QEAAXH@Z 664->668 665->664 669 7ffde65f0467-7ffde65f051d ?setPointSizeF@QFont@@QEAAXN@Z ?setUnderline@QFont@@QEAAX_N@Z ?setOverline@QFont@@QEAAX_N@Z ?setStrikeOut@QFont@@QEAAX_N@Z ?fromWCharArray@QString@@SA?AV1@PEB_WH@Z ??0QFont@@QEAA@AEBVQString@@HH_N@Z ??1?$QVector@VQPointF@@@@QEAA@XZ ?setItalic@QFont@@QEAAX_N@Z 667->669 670 7ffde65f0465 667->670 668->667 671 7ffde65f0532-7ffde65f0537 669->671 672 7ffde65f051f-7ffde65f052c ?weightFromInteger@QPlatformFontDatabase@@SA?AW4Weight@QFont@@H@Z ?setWeight@QFont@@QEAAXH@Z 669->672 670->669 673 7ffde65f053b-7ffde65f0648 ?setPointSizeF@QFont@@QEAAXN@Z ?setUnderline@QFont@@QEAAX_N@Z ?setOverline@QFont@@QEAAX_N@Z ?setStrikeOut@QFont@@QEAAX_N@Z ?pointSize@QFont@@QEBAHXZ ??0QFont@@QEAA@AEBVQString@@HH_N@Z ??1?$QVector@VQPointF@@@@QEAA@XZ ?setStyleHint@QFont@@QEAAXW4StyleHint@1@W4StyleStrategy@1@@Z SystemParametersInfoW ?fromWCharArray@QString@@SA?AV1@PEB_WH@Z ??0QFont@@QEAA@AEBVQString@@HH_N@Z ??1?$QVector@VQPointF@@@@QEAA@XZ ?setItalic@QFont@@QEAAX_N@Z 671->673 674 7ffde65f0539 671->674 672->671 675 7ffde65f064a-7ffde65f0657 ?weightFromInteger@QPlatformFontDatabase@@SA?AW4Weight@QFont@@H@Z ?setWeight@QFont@@QEAAXH@Z 673->675 676 7ffde65f065d-7ffde65f0662 673->676 674->673 675->676 677 7ffde65f0666-7ffde65f0847 ?setPointSizeF@QFont@@QEAAXN@Z ?setUnderline@QFont@@QEAAX_N@Z ?setOverline@QFont@@QEAAX_N@Z ?setStrikeOut@QFont@@QEAAX_N@Z call 7ffde66c5438 call 7ffde6629e70 call 7ffde66c5438 ??0QFont@@QEAA@AEBV0@@Z call 7ffde66c5438 ??0QFont@@QEAA@AEBV0@@Z call 7ffde66c5438 ??0QFont@@QEAA@AEBV0@@Z call 7ffde66c5438 ??0QFont@@QEAA@AEBV0@@Z call 7ffde66c5438 ??0QFont@@QEAA@AEBV0@@Z call 7ffde66c5438 ??0QFont@@QEAA@AEBV0@@Z call 7ffde66c5438 ??0QFont@@QEAA@AEBV0@@Z call 7ffde66c5438 ??0QFont@@QEAA@AEBV0@@Z call 7ffde66c5438 ??0QFont@@QEAA@AEBV0@@Z ??1QFont@@QEAA@XZ * 6 676->677 678 7ffde65f0664 676->678 701 7ffde65f0849-7ffde65f084b 677->701 702 7ffde65f085a-7ffde65f0866 ?deallocate@QArrayData@@SAXPEAU1@_K1@Z 677->702 678->677 703 7ffde65f086c 701->703 704 7ffde65f084d-7ffde65f0858 701->704 702->703 703->641 704->702 704->703
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Font@@$?set$PointString@@$Weight@$V0@@$??1?$F@@@@Vector@$?from?weightArray@CharDatabase@@FontFromInteger@Italic@Out@Overline@PlatformSizeStrikeUnderline@$Debug@@$ArrayStyle$Data@@Logger@@MessageU1@_$?allocate@?deallocate@?debug@?desktop?pointAllocationApplication@@Aware@Category@@Data@@@@@DebugEnabled@Flags@H00@Hint@Hint@1@InfoLoggingOption@ParametersSettingsSize@Strategy@1@@Systemmemmove
                                                      • String ID: QWindowsTheme::refreshFonts
                                                      • API String ID: 2577113376-1170079781
                                                      • Opcode ID: 577a9a8e3dffc3004ab1e43969390e49b6c22d92dda4f1e0006268163b7345c0
                                                      • Instruction ID: 080f8640522381c1e57e20b7f07c62d3cf8d8a3d1320a01eaaee171b944f3c3f
                                                      • Opcode Fuzzy Hash: 577a9a8e3dffc3004ab1e43969390e49b6c22d92dda4f1e0006268163b7345c0
                                                      • Instruction Fuzzy Hash: D3228C31B38E8286EB15EB34E8643A97760FF84B55F404279D64E43A59EF3CE549CB02

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 705 7ffde65cd2b8-7ffde65cd30f ?type@QWindow@@QEBA?AW4WindowType@Qt@@XZ 706 7ffde65cd315-7ffde65cd350 call 7ffde66c5438 ??0QPlatformWindow@@QEAA@PEAVQWindow@@@Z GetDesktopWindow call 7ffde65cf4b0 ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ 705->706 707 7ffde65cd478-7ffde65cd4c8 ?flags@QWindow@@QEBA?AV?$QFlags@W4WindowType@Qt@@@@XZ ?isTopLevel@QWindow@@QEBA_NXZ 705->707 721 7ffde65cd356-7ffde65cd46a call 7ffde65cf4b0 ??0QMessageLogger@@QEAA@PEBDH00@Z ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ ??6QDebug@@QEAAAEAV0@PEBD@Z ??6@YA?AVQDebug@@V0@PEBVQWindow@@@Z ??6QDebug@@QEAAAEAV0@P6AAEAVQTextStream@@AEAV1@@Z@Z * 2 ??6QDebug@@QEAAAEAV0@_K@Z ??6QDebug@@QEAAAEAV0@P6AAEAVQTextStream@@AEAV1@@Z@Z * 2 ??6@YA?AVQDebug@@V0@AEBVQRect@@@Z ??1QDebug@@QEAA@XZ * 3 706->721 722 7ffde65cd470-7ffde65cd473 706->722 708 7ffde65cd509-7ffde65cd541 ?geometry@QWindow@@QEBA?AVQRect@@XZ ?scaleAndOrigin@QHighDpiScaling@@SA?AUScaleAndOrigin@1@PEBVQWindow@@PEAVQPoint@@@Z call 7ffde65c1610 707->708 709 7ffde65cd4ca-7ffde65cd507 ?geometry@QWindow@@QEBA?AVQRect@@XZ ?scaleAndOrigin@QHighDpiScaling@@SA?AUScaleAndOrigin@1@PEBVQWindow@@PEAVQPoint@@@Z call 7ffde65c1610 707->709 717 7ffde65cd545-7ffde65cd569 ?property@QObject@@QEBA?AVQVariant@@PEBD@Z 708->717 709->717 719 7ffde65cd5b9-7ffde65cd667 ?title@QWindow@@QEBA?AVQString@@XZ ?formatWindowTitle@QPlatformWindow@@KA?AVQString@@AEBV2@0@Z ??1?$QVector@VQPointF@@@@QEAA@XZ call 7ffde65c6660 ??1?$QVector@VQPointF@@@@QEAA@XZ * 2 call 7ffde65cf4b0 ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ 717->719 720 7ffde65cd56b-7ffde65cd584 call 7ffde65ced20 ?userType@QVariant@@QEBAHXZ 717->720 738 7ffde65cd8d1-7ffde65cd8d5 719->738 739 7ffde65cd66d-7ffde65cd8cb call 7ffde65cf4b0 ??0QMessageLogger@@QEAA@PEBDH00@Z ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ ??6QDebug@@QEAAAEAV0@PEBD@Z ??6QDebug@@QEAAAEAV0@D@Z ??6@YA?AVQDebug@@V0@PEBVQWindow@@@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6@YA?AVQDebug@@V0@AEBVQRect@@@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ?qt_window_private@@YAPEAVQWindowPrivate@@PEAVQWindow@@@Z ??6QDebug@@QEAAAEAV0@_N@Z ??6QDebug@@QEAAAEAV0@D@Z ?qt_QMetaEnum_flagDebugOperator@@YA?AVQDebug@@AEAV1@_KPEBUQMetaObject@@PEBD@Z ??1QDebug@@QEAA@XZ * 2 ??6QDebug@@QEAAAEAV0@PEBD@Z ??6@YA?AVQDebug@@V0@AEBVQRect@@@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6@YA?AVQDebug@@V0@AEBVQMargins@@@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6QDebug@@QEAAAEAV0@PEBX@Z ??6QDebug@@QEAAAEAV0@D@Z ?qt_QMetaEnum_flagDebugOperator@@YA?AVQDebug@@AEAV1@_KPEBUQMetaObject@@PEBD@Z ??1QDebug@@QEAA@XZ * 2 ??6QDebug@@QEAAAEAV0@D@Z ??1QDebug@@QEAA@XZ * 7 719->739 730 7ffde65cd586-7ffde65cd58f ?constData@QVariant@@QEBAPEBXXZ 720->730 731 7ffde65cd591-7ffde65cd5a9 ?convert@QVariant@@QEBA_NHPEAX@Z 720->731 721->722 723 7ffde65cd93a-7ffde65cd951 722->723 734 7ffde65cd5b5 730->734 736 7ffde65cd5ab-7ffde65cd5b0 731->736 737 7ffde65cd5b2 731->737 734->719 736->734 737->734 741 7ffde65cd92c-7ffde65cd937 ??1QVariant@@QEAA@XZ 738->741 742 7ffde65cd8d7-7ffde65cd8eb call 7ffde65c50e0 738->742 739->738 741->723 745 7ffde65cd8f1-7ffde65cd8ff ?isTopLevel@QWindow@@QEBA_NXZ 742->745 746 7ffde65cd901-7ffde65cd90b call 7ffde65d2010 745->746 747 7ffde65cd914-7ffde65cd91f call 7ffde65f6ed0 745->747 746->747 752 7ffde65cd90d 746->752 747->741 753 7ffde65cd921-7ffde65cd927 call 7ffde65f6fb0 747->753 752->747 753->741
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$Window@@$Variant@@$??6@$Window$DebugLogger@@MessageMetaObject@@Stream@@TextType@V1@@Window@@@$??1?$Category@@F@@@@Level@LoggingPointRect@@Rect@@@Vector@$?debug@?geometry@?property@?qt_?scaleEnabled@Enum_flagH00@HighModuleOpenOperatingOperator@@Origin@Origin@1@PlatformPoint@@@ScaleScaling@@String@@SystemV0@_V1@_Version@@$?compare@?const?convert@?current@?flags@?format?open?qt_window_private@@?title@?type@?userContext@@Data@DesktopFlags@Init_thread_footerMargins@@@Point@@Private@@Qt@@Qt@@@@Size@@@Title@Type@1@V1@0@V2@0@malloc
                                                      • String ID: Obtained : $ Requested: $ frame incl.=$ handle=$ margins=$Desktop window:$QWindowsIntegration::createPlatformWindow$WindowType$_q_windowsCustomMargins
                                                      • API String ID: 4258386443-792223184
                                                      • Opcode ID: 70fc9a79057f3a9fbb48c4491927698e4f7f38fe4276e1719655cf1842e8e1b1
                                                      • Instruction ID: aec03844314839ab5380c598b519ad5fea71a69961c92a30b5381f0c4db1aff8
                                                      • Opcode Fuzzy Hash: 70fc9a79057f3a9fbb48c4491927698e4f7f38fe4276e1719655cf1842e8e1b1
                                                      • Instruction Fuzzy Hash: D9126F32B38F8286EB14EF64E8642A83770FB84B99F41517ADA4E43624DF3CD549CB01
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3555456661.00007FF6F8011000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00007FF6F8010000, based on PE: true
                                                      • Associated: 00000013.00000002.3555389094.00007FF6F8010000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                      • Associated: 00000013.00000002.3555496022.00007FF6F8013000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                      • Associated: 00000013.00000002.3555543118.00007FF6F8015000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                      • Associated: 00000013.00000002.3555583685.00007FF6F8026000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ff6f8010000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: FilePath$CharCommandFolderKnownLineLowerlstrlen$ArgvCloseCreateExistsExitHandleModuleNameProcessRemoveSpec
                                                      • String ID: ... AFTER ENTRY POINT ...$... BEFORE ENTRY POINT ...$.txt$/protocolUri$ACTION Calling the entry point.$ACTION Exited from the entry point.$C:\Users\user\AppData\Local\CiscoSparkLauncher\44.5.0.29672_fd820904-d9be-4b15-8bfd-e6f6b0f45db1\spark-windows-app.dll$C:\Users\user\AppData\Local\CiscoSparkLauncher\spark-windows-host-log-spark-windows-app-impl.dll.txt$Command line: $ERROR can't free the library!$ERROR can't get an entry point:$ERROR can't load library!$ERROR can't set dll directory!$ERROR path not a directory!$Error getting current directory path!$Error getting launcher paths!$Finished successfully, exiting.$Params selected:$SparkEntryPoint$Started in the app loader mode.$Started in the launcher mode.$Trying the launcher in the current directory next!$\CiscoSparkLauncher$\CiscoSparkLauncher.dll$spark-windows-host-log$yyyy'-'MM'-'dd
                                                      • API String ID: 2637395849-3081818713
                                                      • Opcode ID: 116e4ff526568ee6c2b38b14981a675db6d7ce349a94bc02585a06ba648135ea
                                                      • Instruction ID: cc5d28c7f14b17fb53393d5c6f25b9e71efae8a988e76bcdd03cf37566b230ca
                                                      • Opcode Fuzzy Hash: 116e4ff526568ee6c2b38b14981a675db6d7ce349a94bc02585a06ba648135ea
                                                      • Instruction Fuzzy Hash: 6082E322B09A4282EF698F75941027A63A1FF55BACFC450B1DA2D877D4FF3DE504A318

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1084 7ffde6608bf0-7ffde6608c39 call 7ffde65cf5d0 ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ 1087 7ffde6608c93-7ffde6608cd7 ?fromLatin1@QString@@SA?AV1@PEBDH@Z ?utf16@QString@@QEBAPEBGXZ LoadLibraryW ??1?$QVector@VQPointF@@@@QEAA@XZ 1084->1087 1088 7ffde6608c3b-7ffde6608c8d call 7ffde65cf5d0 ??0QMessageLogger@@QEAA@PEBDH00@Z ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ ??6QDebug@@QEAAAEAV0@PEBD@Z * 2 ??1QDebug@@QEAA@XZ 1084->1088 1089 7ffde6608d08-7ffde6608d22 GetProcAddress 1087->1089 1090 7ffde6608cd9-7ffde6608ced GetLastError ?qErrnoWarning@@YAXHPEBDZZ 1087->1090 1088->1087 1093 7ffde6608d33 1089->1093 1094 7ffde6608d24-7ffde6608d31 GetProcAddress 1089->1094 1092 7ffde6608cf3-7ffde6608d07 call 7ffde66c51b0 1090->1092 1097 7ffde6608d35-7ffde6608d43 1093->1097 1094->1097 1099 7ffde6608d54 1097->1099 1100 7ffde6608d45-7ffde6608d52 GetProcAddress 1097->1100 1101 7ffde6608d56-7ffde6608d64 1099->1101 1100->1101 1102 7ffde6608d75 1101->1102 1103 7ffde6608d66-7ffde6608d73 GetProcAddress 1101->1103 1104 7ffde6608d77-7ffde6608d85 1102->1104 1103->1104 1105 7ffde6608d96 1104->1105 1106 7ffde6608d87-7ffde6608d94 GetProcAddress 1104->1106 1107 7ffde6608d98-7ffde6608da6 1105->1107 1106->1107 1108 7ffde6608db7 1107->1108 1109 7ffde6608da8-7ffde6608db5 GetProcAddress 1107->1109 1110 7ffde6608db9-7ffde6608dc7 1108->1110 1109->1110 1111 7ffde6608dd8 1110->1111 1112 7ffde6608dc9-7ffde6608dd6 GetProcAddress 1110->1112 1113 7ffde6608dda-7ffde6608de8 1111->1113 1112->1113 1114 7ffde6608df9 1113->1114 1115 7ffde6608dea-7ffde6608df7 GetProcAddress 1113->1115 1116 7ffde6608dfb-7ffde6608e09 1114->1116 1115->1116 1117 7ffde6608e1a 1116->1117 1118 7ffde6608e0b-7ffde6608e18 GetProcAddress 1116->1118 1119 7ffde6608e1c-7ffde6608e2a 1117->1119 1118->1119 1120 7ffde6608e3b 1119->1120 1121 7ffde6608e2c-7ffde6608e39 GetProcAddress 1119->1121 1122 7ffde6608e3d-7ffde6608e4b 1120->1122 1121->1122 1123 7ffde6608e4d-7ffde6608e5a GetProcAddress 1122->1123 1124 7ffde6608e5c 1122->1124 1125 7ffde6608e5e-7ffde6608e6c 1123->1125 1124->1125 1126 7ffde6608e7d 1125->1126 1127 7ffde6608e6e-7ffde6608e7b GetProcAddress 1125->1127 1128 7ffde6608e7f-7ffde6608e8d 1126->1128 1127->1128 1129 7ffde6608e9e 1128->1129 1130 7ffde6608e8f-7ffde6608e9c GetProcAddress 1128->1130 1131 7ffde6608ea0-7ffde6608eae 1129->1131 1130->1131 1132 7ffde6608ebf 1131->1132 1133 7ffde6608eb0-7ffde6608ebd GetProcAddress 1131->1133 1134 7ffde6608ec1-7ffde6608ecf 1132->1134 1133->1134 1135 7ffde6608ee0 1134->1135 1136 7ffde6608ed1-7ffde6608ede GetProcAddress 1134->1136 1137 7ffde6608ee2-7ffde6608ef0 1135->1137 1136->1137 1138 7ffde6608f01 1137->1138 1139 7ffde6608ef2-7ffde6608eff GetProcAddress 1137->1139 1140 7ffde6608f03-7ffde6608f11 1138->1140 1139->1140 1141 7ffde6608f22 1140->1141 1142 7ffde6608f13-7ffde6608f20 GetProcAddress 1140->1142 1143 7ffde6608f24-7ffde6608f35 1141->1143 1142->1143 1144 7ffde6608f46 1143->1144 1145 7ffde6608f37-7ffde6608f44 GetProcAddress 1143->1145 1146 7ffde6608f48-7ffde6608f59 1144->1146 1145->1146 1147 7ffde6608f6a 1146->1147 1148 7ffde6608f5b-7ffde6608f68 GetProcAddress 1146->1148 1149 7ffde6608f6c-7ffde6608f77 1147->1149 1148->1149 1149->1092 1150 7ffde6608f7d-7ffde6608f82 1149->1150 1150->1092 1151 7ffde6608f88-7ffde6608f8d 1150->1151 1151->1092 1152 7ffde6608f93-7ffde6608f96 1151->1152 1152->1092 1153 7ffde6608f9c-7ffde6608fcf call 7ffde66c51b0 1152->1153
                                                      APIs
                                                      • ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608C31
                                                      • ??0QMessageLogger@@QEAA@PEBDH00@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608C56
                                                      • ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608C64
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608C74
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608C82
                                                      • ??1QDebug@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608C8D
                                                      • ?fromLatin1@QString@@SA?AV1@PEBDH@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608CA3
                                                      • ?utf16@QString@@QEBAPEBGXZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608CAC
                                                      • LoadLibraryW.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608CB5
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608CC7
                                                      • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608CD9
                                                      • ?qErrnoWarning@@YAXHPEBDZZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608CED
                                                        • Part of subcall function 00007FFDE65CF5D0: ??0QLoggingCategory@@QEAA@PEBD@Z.QT5CORE(?,?,?,00007FFDE6604E70,?,?,?,?,?,?,?,?,?,?,000001EFB0646808,?), ref: 00007FFDE65CF62C
                                                        • Part of subcall function 00007FFDE65CF5D0: _Init_thread_footer.LIBCMT ref: 00007FFDE65CF645
                                                      • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608D0F
                                                      • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608D2B
                                                      • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608D4C
                                                      • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608D6D
                                                      • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608D8E
                                                      • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608DAF
                                                      • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608DD0
                                                      • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608DF1
                                                      • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608E12
                                                      • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608E33
                                                      • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608E54
                                                      • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608E75
                                                      • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608E96
                                                      • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608EB7
                                                      • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608ED8
                                                      • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608EF9
                                                      • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608F1A
                                                      • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608F3E
                                                      • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FFDE660910F), ref: 00007FFDE6608F62
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: AddressProc$Debug@@$Category@@Logger@@LoggingMessageString@@$??1?$?debug@?from?utf16@DebugEnabled@ErrnoErrorF@@@@H00@Init_thread_footerLastLatin1@LibraryLoadPointVector@Warning@@
                                                      • String ID: Failed to load %s$Qt: Using EGL from$eglBindAPI$eglChooseConfig$eglCreateContext$eglCreatePbufferSurface$eglCreateWindowSurface$eglDestroyContext$eglDestroySurface$eglGetConfigAttrib$eglGetCurrentContext$eglGetCurrentDisplay$eglGetCurrentSurface$eglGetDisplay$eglGetError$eglGetPlatformDisplayEXT$eglGetProcAddress$eglInitialize$eglMakeCurrent$eglSwapBuffers$eglSwapInterval$eglTerminate$libEGL
                                                      • API String ID: 2446833387-2774468275
                                                      • Opcode ID: e5853f962b079bc16fb07befd6961e37641482692e4eeebf5126c4918ab9fc40
                                                      • Instruction ID: ea0868a3ee1520a4fb948440f30d13efe636285c2e6fcd5ebd9df165de7c8fda
                                                      • Opcode Fuzzy Hash: e5853f962b079bc16fb07befd6961e37641482692e4eeebf5126c4918ab9fc40
                                                      • Instruction Fuzzy Hash: 1FC1E925B3AF4285EBA9DF24E87037827A0FF55B54F4405BDC94E866A5EF6CE404CB02

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1157 7ffde65d14c0-7ffde65d153c GetModuleHandleW ?utf16@QString@@QEBAPEBGXZ GetClassInfoW 1158 7ffde65d1573-7ffde65d1581 1157->1158 1159 7ffde65d153e-7ffde65d1542 1157->1159 1161 7ffde65d1592-7ffde65d15a8 call 7ffde65d4bf0 1158->1161 1162 7ffde65d1583-7ffde65d158f ?qHash@@YAIAEBVQString@@I@Z 1158->1162 1159->1158 1160 7ffde65d1544-7ffde65d156d ?createUuid@QUuid@@SA?AV1@XZ ?toString@QUuid@@QEBA?AVQString@@XZ ??YQString@@QEAAAEAV0@AEBV0@@Z ??1?$QVector@VQPointF@@@@QEAA@XZ 1159->1160 1160->1158 1165 7ffde65d18d4-7ffde65d190b ??0QByteArray@@QEAA@$$QEAV0@@Z ??1?$QVector@VQPointF@@@@QEAA@XZ call 7ffde66c51b0 1161->1165 1166 7ffde65d15ae-7ffde65d15e0 1161->1166 1162->1161 1167 7ffde65d15e6-7ffde65d1612 LoadImageW 1166->1167 1168 7ffde65d1678 1166->1168 1170 7ffde65d1614-7ffde65d164e GetSystemMetrics * 2 LoadImageW 1167->1170 1171 7ffde65d1650-7ffde65d1676 LoadImageW 1167->1171 1172 7ffde65d167d 1168->1172 1174 7ffde65d1681-7ffde65d16a4 ?utf16@QString@@QEBAPEBGXZ RegisterClassExW 1170->1174 1171->1172 1172->1174 1175 7ffde65d16a6-7ffde65d16d2 ?toLocal8Bit@QString@@QEGBA?AVQByteArray@@XZ ?constData@QString@@QEBAPEBVQChar@@XZ ?qErrnoWarning@@YAXPEBDZZ ??1?$QVector@VQPointF@@@@QEAA@XZ 1174->1175 1176 7ffde65d16d8-7ffde65d16e5 1174->1176 1175->1176 1177 7ffde65d16e7-7ffde65d1719 ?detach_helper@QHashData@@QEAAPEAU1@P6AXPEAUNode@1@PEAX@ZP6AX0@ZHH@Z 1176->1177 1178 7ffde65d1744-7ffde65d1770 ?qHash@@YAIAEBVQString@@I@Z call 7ffde65d4bf0 1176->1178 1180 7ffde65d171b-7ffde65d171e 1177->1180 1181 7ffde65d172f-7ffde65d173a ?free_helper@QHashData@@QEAAXP6AXPEAUNode@1@@Z@Z 1177->1181 1185 7ffde65d17c1-7ffde65d17d1 call 7ffde65cf4b0 ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ 1178->1185 1186 7ffde65d1772-7ffde65d177a ?willGrow@QHashData@@QEAA_NXZ 1178->1186 1183 7ffde65d1740 1180->1183 1184 7ffde65d1720-7ffde65d172d 1180->1184 1181->1183 1183->1178 1184->1181 1184->1183 1185->1165 1193 7ffde65d17d7-7ffde65d18ce call 7ffde65cf4b0 ??0QMessageLogger@@QEAA@PEBDH00@Z ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ ??6QDebug@@QEAAAEAV0@PEBD@Z ??6QDebug@@QEAAAEAV0@D@Z ??6QDebug@@QEAAAEAV0@AEBVQString@@@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6QDebug@@QEAAAEAV0@P6AAEAVQTextStream@@AEAV1@@Z@Z ??6QDebug@@QEAAAEAV0@I@Z ??6QDebug@@QEAAAEAV0@P6AAEAVQTextStream@@AEAV1@@Z@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6QDebug@@QEAAAEAV0@PEBX@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6QDebug@@QEAAAEAV0@_N@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6QDebug@@QEAAAEAV0@G@Z ??1QDebug@@QEAA@XZ 1185->1193 1187 7ffde65d177c-7ffde65d178b call 7ffde65d4bf0 1186->1187 1188 7ffde65d178e-7ffde65d17be ?allocateNode@QHashData@@QEAAPEAXH@Z ??0QByteArray@@QEAA@AEBV0@@Z 1186->1188 1187->1188 1188->1185 1193->1165
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$String@@$Data@@Hash$??1?$Array@@ByteF@@@@ImageLoadPointV0@@Vector@$?utf16@ClassHash@@Logger@@MessageMetricsStream@@SystemTextUuid@@V1@@$?allocate?const?create?debug@?detach_helper@?free_helper@?willA@$$Bit@Category@@Char@@Data@DebugEnabled@ErrnoGrow@H00@HandleInfoLocal8LoggingModuleNode@Node@1@Node@1@@RegisterString@String@@@Uuid@V0@_Warning@@
                                                      • String ID: atom=$ brush=$ icon=$ style=0x$@$IDI_ICON1$P$QApplication::regClass: Registering window class '%s' failed.$QWindowsContext::registerWindowClass
                                                      • API String ID: 2116993788-2709297162
                                                      • Opcode ID: 964cf0c80670ec85e3953d78c59d0c9c71e0a7e90ee74c7ae9bedc9fca68d852
                                                      • Instruction ID: d3ac52eeb8236640d6932e8fb767d7598417bc6474aaa74635bb3edb4f7675ba
                                                      • Opcode Fuzzy Hash: 964cf0c80670ec85e3953d78c59d0c9c71e0a7e90ee74c7ae9bedc9fca68d852
                                                      • Instruction Fuzzy Hash: 7CC13E35B29A4286EB18AF25E86826D77A0FB88B94F005179DE4E03B64DF3CD545CB41

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1196 7ffde66090a0-7ffde66090d1 1197 7ffde6609103-7ffde6609111 call 7ffde6608bf0 1196->1197 1198 7ffde66090d3-7ffde66090fe ??0QMessageLogger@@QEAA@PEBDH0@Z ?warning@QMessageLogger@@QEBAXPEBDZZ 1196->1198 1204 7ffde6609143-7ffde660916b call 7ffde65cf5d0 ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ 1197->1204 1205 7ffde6609113-7ffde660913e ??0QMessageLogger@@QEAA@PEBDH0@Z ?warning@QMessageLogger@@QEBAXPEBDZZ 1197->1205 1199 7ffde660927a-7ffde6609290 call 7ffde66c51b0 1198->1199 1208 7ffde660916d-7ffde66091bb call 7ffde65cf5d0 ??0QMessageLogger@@QEAA@PEBDH00@Z ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ ??6QDebug@@QEAAAEAV0@PEBD@Z * 2 ??1QDebug@@QEAA@XZ 1204->1208 1209 7ffde66091c1-7ffde660921c ?fromLatin1@QString@@SA?AV1@PEBDH@Z ?utf16@QString@@QEBAPEBGXZ LoadLibraryW ??1?$QVector@VQPointF@@@@QEAA@XZ 1204->1209 1205->1199 1208->1209 1211 7ffde660921e-7ffde6609231 GetLastError ?qErrnoWarning@@YAXHPEBDZZ 1209->1211 1212 7ffde6609291-7ffde66092b6 GetProcAddress 1209->1212 1216 7ffde6609237-7ffde6609249 ??0QMessageLogger@@QEAA@PEBDH0@Z 1211->1216 1213 7ffde6609306 1212->1213 1214 7ffde66092b8-7ffde66092d2 GetProcAddress 1212->1214 1218 7ffde6609309 1213->1218 1217 7ffde66092d4-7ffde66092ee GetProcAddress 1214->1217 1214->1218 1219 7ffde6609250-7ffde660925a ?warning@QMessageLogger@@QEBAXPEBDZZ 1216->1219 1220 7ffde66092f0-7ffde6609304 GetProcAddress 1217->1220 1221 7ffde660930c 1217->1221 1218->1221 1222 7ffde6609260 1219->1222 1223 7ffde6609313-7ffde660931e 1220->1223 1221->1223 1224 7ffde6609262-7ffde6609272 1222->1224 1223->1216 1225 7ffde6609324-7ffde6609327 1223->1225 1224->1199 1225->1216 1226 7ffde660932d-7ffde6609330 1225->1226 1226->1216 1227 7ffde6609336-7ffde660934a 1226->1227 1228 7ffde6609350-7ffde6609353 1227->1228 1229 7ffde66094cb-7ffde66094e1 1227->1229 1228->1229 1230 7ffde6609359-7ffde660939c 1228->1230 1234 7ffde6609501-7ffde6609506 1229->1234 1235 7ffde66094e3-7ffde66094fc ??0QMessageLogger@@QEAA@PEBDH0@Z 1229->1235 1232 7ffde660939e-7ffde66093a2 1230->1232 1233 7ffde66093a4-7ffde66093a7 1230->1233 1236 7ffde66093bc-7ffde66093e9 1232->1236 1237 7ffde66093af-7ffde66093b2 1233->1237 1238 7ffde66093a9-7ffde66093ad 1233->1238 1240 7ffde660958f-7ffde660959f call 7ffde65cf5d0 ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ 1234->1240 1241 7ffde660950c-7ffde660951d 1234->1241 1235->1219 1250 7ffde66093ef-7ffde660940c 1236->1250 1251 7ffde66094c6-7ffde66094c9 1236->1251 1237->1229 1239 7ffde66093b8 1237->1239 1238->1236 1239->1236 1248 7ffde66095a5-7ffde6609634 call 7ffde65cf5d0 ??0QMessageLogger@@QEAA@PEBDH00@Z ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ ??6QDebug@@QEAAAEAV0@PEBD@Z * 2 ??6QDebug@@QEAAAEAV0@PEBX@Z ??6QDebug@@QEAAAEAV0@D@Z ??6QDebug@@QEAAAEAV0@H@Z ??6QDebug@@QEAAAEAV0@D@Z ??6QDebug@@QEAAAEAV0@H@Z ??1QDebug@@QEAA@XZ 1240->1248 1249 7ffde660963a-7ffde6609652 call 7ffde66c5438 1240->1249 1245 7ffde6609526-7ffde6609528 1241->1245 1245->1240 1246 7ffde660952a-7ffde660956b ??0QMessageLogger@@QEAA@PEBDH0@Z ?warning@QMessageLogger@@QEBAXPEBDZZ 1245->1246 1246->1222 1257 7ffde6609571-7ffde660958a ??0QMessageLogger@@QEAA@PEBDH0@Z 1246->1257 1248->1249 1249->1224 1250->1229 1259 7ffde6609412-7ffde660941c 1250->1259 1251->1229 1251->1234 1257->1219 1259->1229 1260 7ffde6609422-7ffde6609425 1259->1260 1260->1229 1261 7ffde660942b-7ffde660946a 1260->1261 1262 7ffde6609472-7ffde6609475 1261->1262 1263 7ffde660946c-7ffde6609470 1261->1263 1262->1229 1265 7ffde6609477 1262->1265 1264 7ffde660947b-7ffde66094a8 1263->1264 1264->1251 1268 7ffde66094aa-7ffde66094c4 1264->1268 1265->1264 1268->1229
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Logger@@Message$Debug@@$?warning@AddressProc$?debug@Category@@DebugEnabled@H00@Logging
                                                      • String ID: %s: Could not initialize EGL display: error 0x%x$%s: Could not obtain EGL display$%s: Failed to load and resolve libEGL functions$%s: Failed to load and resolve libGLESv2 functions$%s: No Display$%s: When using ANGLE, check if d3dcompiler_4x.dll is available$Created EGL display$Failed to load %s$QWindowsEGLStaticContext::create$Qt: Using OpenGL ES 2.0 from$glBindTexture$glClearDepthf$glCreateShader$glGetString
                                                      • API String ID: 4042461579-2245312251
                                                      • Opcode ID: c9593ff4f3d0d35b67f05c8dbb5ff715539d6e67baa5b1d0ee9e69853b1d87d3
                                                      • Instruction ID: 7b5e52f350dc5c46c6adeaa693278ecd0bb303aa2bdfa59cd582e874fa89fb14
                                                      • Opcode Fuzzy Hash: c9593ff4f3d0d35b67f05c8dbb5ff715539d6e67baa5b1d0ee9e69853b1d87d3
                                                      • Instruction Fuzzy Hash: B2F18E65B39A4285EB699F65E8743B933A1BF89B84F406179DD4E03A64DF3CD408CB02

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1270 7ffde65c50e0-7ffde65c51f4 ??0QPlatformWindow@@QEAA@PEAVQWindow@@@Z call 7ffde66c5438 call 7ffde65cc260 call 7ffde65d4a00 1277 7ffde65c51f6-7ffde65c520b 1270->1277 1278 7ffde65c5234 1270->1278 1279 7ffde65c5226-7ffde65c522c 1277->1279 1280 7ffde65c520d 1277->1280 1281 7ffde65c5237-7ffde65c5242 ?willGrow@QHashData@@QEAA_NXZ 1278->1281 1279->1281 1283 7ffde65c522e-7ffde65c5232 1279->1283 1282 7ffde65c5210-7ffde65c5213 1280->1282 1284 7ffde65c5244-7ffde65c524d 1281->1284 1285 7ffde65c5281-7ffde65c52a6 ?allocateNode@QHashData@@QEAAPEAXH@Z 1281->1285 1287 7ffde65c5215-7ffde65c5219 1282->1287 1288 7ffde65c521b-7ffde65c5224 1282->1288 1286 7ffde65c52a9-7ffde65c52c5 ?type@QWindow@@QEBA?AW4WindowType@Qt@@XZ 1283->1286 1289 7ffde65c524f-7ffde65c5264 1284->1289 1290 7ffde65c527e 1284->1290 1285->1286 1291 7ffde65c5757-7ffde65c5769 1286->1291 1292 7ffde65c52cb-7ffde65c5302 1286->1292 1287->1279 1287->1288 1288->1279 1288->1282 1289->1285 1293 7ffde65c5266-7ffde65c5269 1289->1293 1290->1285 1298 7ffde65c531c-7ffde65c537c ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ ?isTopLevel@QWindow@@QEBA_NXZ call 7ffde65c5f70 call 7ffde65cbe80 ?qt_window_private@@YAPEAVQWindowPrivate@@PEAVQWindow@@@Z 1292->1298 1299 7ffde65c5304-7ffde65c530f ?openGLModuleType@QOpenGLContext@@SA?AW4OpenGLModuleType@1@XZ 1292->1299 1294 7ffde65c526b-7ffde65c526f 1293->1294 1295 7ffde65c5271-7ffde65c527a 1293->1295 1294->1285 1294->1295 1295->1293 1297 7ffde65c527c 1295->1297 1297->1285 1307 7ffde65c537e-7ffde65c5381 1298->1307 1308 7ffde65c5383 1298->1308 1300 7ffde65c5316 1299->1300 1301 7ffde65c5311-7ffde65c5314 1299->1301 1303 7ffde65c5319 1300->1303 1301->1303 1303->1298 1309 7ffde65c5387-7ffde65c538b 1307->1309 1308->1309 1310 7ffde65c538d 1309->1310 1311 7ffde65c5391-7ffde65c53a1 1309->1311 1310->1311 1312 7ffde65c53a7-7ffde65c53b7 call 7ffde65cf4b0 ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ 1311->1312 1313 7ffde65c54af-7ffde65c5508 ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ * 2 ?mask@QWindow@@QEBA?AVQRegion@@XZ ?scaleAndOrigin@QHighDpiScaling@@SA?AUScaleAndOrigin@1@PEBVQWindow@@PEAVQPoint@@@Z 1311->1313 1321 7ffde65c540c-7ffde65c541f 1312->1321 1322 7ffde65c53b9-7ffde65c5406 call 7ffde65cf4b0 ??0QMessageLogger@@QEAA@PEBDH00@Z ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ ??6QDebug@@QEAAAEAV0@PEBD@Z ??6QDebug@@QEAAAEAV0@N@Z ??1QDebug@@QEAA@XZ 1312->1322 1315 7ffde65c551c-7ffde65c5541 ??0QRegion@@QEAA@XZ ?begin@QRegion@@QEBAPEBVQRect@@XZ ?end@QRegion@@QEBAPEBVQRect@@XZ 1313->1315 1316 7ffde65c550a-7ffde65c5517 ??0QRegion@@QEAA@AEBV0@@Z 1313->1316 1319 7ffde65c55a9-7ffde65c55c0 ??1QRegion@@QEAA@XZ 1315->1319 1320 7ffde65c5543-7ffde65c55a7 ??0QRectF@@QEAA@AEBVQRect@@@Z ??0QRectF@@QEAA@AEBVQPointF@@AEBVQSizeF@@@Z ?toRect@QRectF@@QEBA?AVQRect@@XZ ??YQRegion@@QEAAAEAV0@AEBVQRect@@@Z 1315->1320 1318 7ffde65c55c6-7ffde65c5601 call 7ffde65ca830 ??1QRegion@@QEAA@XZ * 2 ?isTopLevel@QWindow@@QEBA_NXZ 1316->1318 1331 7ffde65c5607-7ffde65c561b ?icon@QWindow@@QEBA?AVQIcon@@XZ 1318->1331 1332 7ffde65c56fd-7ffde65c5704 1318->1332 1319->1318 1320->1319 1320->1320 1325 7ffde65c5425-7ffde65c5429 1321->1325 1326 7ffde65c5421 1321->1326 1322->1321 1329 7ffde65c542b 1325->1329 1330 7ffde65c542f-7ffde65c5433 1325->1330 1326->1325 1329->1330 1335 7ffde65c5435 1330->1335 1336 7ffde65c5439-7ffde65c544a 1330->1336 1337 7ffde65c56f3-7ffde65c56f7 ??1QIcon@@QEAA@XZ 1331->1337 1338 7ffde65c5621-7ffde65c562b 1331->1338 1333 7ffde65c5706-7ffde65c572c ?property@QObject@@QEBA?AVQVariant@@PEBD@Z ?toBool@QVariant@@QEBA_NXZ 1332->1333 1334 7ffde65c5732 1332->1334 1333->1334 1339 7ffde65c572e-7ffde65c5730 1333->1339 1340 7ffde65c5734-7ffde65c5738 1334->1340 1335->1336 1336->1313 1341 7ffde65c544c-7ffde65c5458 1336->1341 1337->1332 1342 7ffde65c563a-7ffde65c5644 1338->1342 1343 7ffde65c562d-7ffde65c5633 DestroyCursor 1338->1343 1339->1340 1344 7ffde65c5745-7ffde65c5747 1340->1344 1345 7ffde65c573a-7ffde65c573f ??1QVariant@@QEAA@XZ 1340->1345 1341->1313 1346 7ffde65c545a-7ffde65c54a9 ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ ?hasAlpha@QSurfaceFormat@@QEBA_NXZ call 7ffde65c1e40 ??1QSurfaceFormat@@QEAA@XZ 1341->1346 1347 7ffde65c5646-7ffde65c564c DestroyCursor 1342->1347 1348 7ffde65c5653-7ffde65c56c1 GetSystemMetrics * 2 call 7ffde65cb960 GetSystemMetrics * 2 call 7ffde65cb960 1342->1348 1343->1342 1349 7ffde65c5749 1344->1349 1350 7ffde65c5750 1344->1350 1345->1344 1346->1313 1347->1348 1358 7ffde65c56c3-7ffde65c56d0 SendMessageW 1348->1358 1359 7ffde65c56d2-7ffde65c56d8 SendMessageW 1348->1359 1349->1350 1350->1291 1360 7ffde65c56df-7ffde65c56ed SendMessageW 1358->1360 1359->1360 1360->1337
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Window@@$Region@@$MessagePlatform$?window@Data@@Debug@@HashMetricsSystem$RectRect@@SendVariant@@$CursorDestroyFormat@@Icon@@Level@Logger@@ModuleOpenRect@@@SurfaceType@WindowWindow@@@$?allocate?begin@?debug@?detach_helper@?end@?free_helper@?has?icon@?mask@?open?property@?qt_window_private@@?scale?type@?willAlpha@Bool@Category@@Context@@DebugEnabled@F@@@Grow@H00@HighLoggingNode@Node@1@Node@1@@Object@@Origin@Origin@1@PointPoint@@@Private@@Qt@@Rect@ScaleScaling@@SizeType@1@V0@@malloc
                                                      • String ID: QWindowsWindow::setOpacity$_q_has_border_in_fullscreen
                                                      • API String ID: 1094466914-4210031702
                                                      • Opcode ID: 8c838a51704ab7f0b960679d27db789e76a56e2a530fb493c9b0f1a3add8e702
                                                      • Instruction ID: df61c99e49aa74eaeda9056b37669810409288ad3fa1ea5d27f347ec7c31ca5c
                                                      • Opcode Fuzzy Hash: 8c838a51704ab7f0b960679d27db789e76a56e2a530fb493c9b0f1a3add8e702
                                                      • Instruction Fuzzy Hash: 4F12AB22B28F4282EB1A9F65D8643B973A4FF95B84F004276DA4E13761DF3CE0A5C701

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1361 7ffde65d44e0-7ffde65d4537 call 7ffde65cef80 1364 7ffde65d4539-7ffde65d453c 1361->1364 1365 7ffde65d4546-7ffde65d4582 call 7ffde65d20e0 1361->1365 1364->1365 1367 7ffde65d453e-7ffde65d4541 1364->1367 1369 7ffde65d4588-7ffde65d4598 call 7ffde65cf540 ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ 1365->1369 1370 7ffde65d4721-7ffde65d4724 1365->1370 1367->1365 1369->1370 1380 7ffde65d459e-7ffde65d45a8 1369->1380 1371 7ffde65d473b-7ffde65d4741 1370->1371 1372 7ffde65d4726-7ffde65d4737 DefWindowProcW 1370->1372 1374 7ffde65d4747-7ffde65d475b 1371->1374 1375 7ffde65d4932-7ffde65d4955 call 7ffde66c51b0 1371->1375 1372->1371 1377 7ffde65d4766-7ffde65d477c GetWindowLongPtrW 1374->1377 1378 7ffde65d475d-7ffde65d4760 1374->1378 1377->1375 1382 7ffde65d4782-7ffde65d4798 GetWindowPlacement 1377->1382 1378->1375 1378->1377 1383 7ffde65d45b0-7ffde65d45b3 1380->1383 1384 7ffde65d479a-7ffde65d479e 1382->1384 1385 7ffde65d47a4-7ffde65d47af 1382->1385 1386 7ffde65d48a9-7ffde65d48b4 1383->1386 1387 7ffde65d45b9-7ffde65d45c7 1383->1387 1384->1375 1384->1385 1390 7ffde65d47b8-7ffde65d47e5 1385->1390 1391 7ffde65d47b1-7ffde65d47b4 1385->1391 1388 7ffde65d45c9 1386->1388 1389 7ffde65d48ba-7ffde65d48c1 1386->1389 1387->1383 1387->1388 1393 7ffde65d45d0-7ffde65d45e0 call 7ffde65cf540 ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ 1388->1393 1389->1370 1392 7ffde65d48c7 1389->1392 1390->1375 1394 7ffde65d47eb-7ffde65d47f0 1390->1394 1391->1390 1392->1393 1393->1370 1404 7ffde65d45e6-7ffde65d471b call 7ffde65cf540 ??0QMessageLogger@@QEAA@PEBDH00@Z ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ ??6QDebug@@QEAAAEAV0@PEBD@Z ??6QDebug@@QEAAAEAV0@PEBX@Z ??6QDebug@@QEAAAEAV0@D@Z ??6QDebug@@QEAAAEAV0@PEBD@Z * 2 ??6QDebug@@QEAAAEAV0@P6AAEAVQTextStream@@AEAV1@@Z@Z ??6QDebug@@QEAAAEAV0@I@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6QDebug@@QEAAAEAV0@H@Z ??6QDebug@@QEAAAEAV0@P6AAEAVQTextStream@@AEAV1@@Z@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6QDebug@@QEAAAEAV0@H@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6QDebug@@QEAAAEAV0@H@Z ??6QDebug@@QEAAAEAV0@D@Z ??6QDebug@@QEAAAEAV0@H@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6QDebug@@QEAAAEAV0@_N@Z ??1QDebug@@QEAA@XZ 1393->1404 1396 7ffde65d48cc-7ffde65d48e7 1394->1396 1397 7ffde65d47f6-7ffde65d4806 call 7ffde65cf4b0 ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ 1394->1397 1398 7ffde65d48e9-7ffde65d48ec 1396->1398 1399 7ffde65d48f0-7ffde65d48f3 1396->1399 1408 7ffde65d480c-7ffde65d4890 call 7ffde65cf4b0 ??0QMessageLogger@@QEAA@PEBDH00@Z ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ ??6QDebug@@QEAAAEAV0@PEBD@Z * 2 ??6QDebug@@QEAAAEAV0@PEBX@Z ??6@YA?AVQDebug@@V0@AEBVQMargins@@@Z ??1QDebug@@QEAA@XZ * 2 1397->1408 1409 7ffde65d4896-7ffde65d48a4 call 7ffde65ca390 1397->1409 1398->1399 1402 7ffde65d48f5-7ffde65d48fa 1399->1402 1403 7ffde65d48fe-7ffde65d4901 1399->1403 1402->1403 1403->1375 1406 7ffde65d4903-7ffde65d4912 1403->1406 1404->1370 1411 7ffde65d4921-7ffde65d4928 1406->1411 1412 7ffde65d4914-7ffde65d4918 1406->1412 1408->1409 1409->1375 1411->1375 1415 7ffde65d492a-7ffde65d492d call 7ffde66c57f4 1411->1415 1412->1411 1415->1375
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$Logger@@Message$Category@@DebugEnabled@LoggingWindow$?debug@H00@Stream@@TextV1@@$??6@LongMargins@@@PlacementProcV0@_
                                                      • String ID: at $ et=0x$ handled=$ msg=0x$ wp=$EVENT: hwd=$Unknown$WM_NCCALCSIZE for$qWindowsWndProc
                                                      • API String ID: 941681750-549090479
                                                      • Opcode ID: dac83c1674f8896767c7313b38aeb0884baead90b9a8ad41bbbfad310ddd1736
                                                      • Instruction ID: 76286ceaaef30511f174d793cb861eeedb69f640ae9a0d2cc20d96e65789b433
                                                      • Opcode Fuzzy Hash: dac83c1674f8896767c7313b38aeb0884baead90b9a8ad41bbbfad310ddd1736
                                                      • Instruction Fuzzy Hash: AEC1CF22B28E4286EB19AF65E8743BD27A1FF85B94F045139CE4E03764DE3CE445CB42

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1419 7ffde65de930-7ffde65de9b0 1420 7ffde65de9b2-7ffde65de9c4 GetWindowLongPtrW 1419->1420 1421 7ffde65de9e0-7ffde65de9e6 1419->1421 1420->1421 1424 7ffde65de9c6-7ffde65de9dc GetClientRect 1420->1424 1422 7ffde65dea46-7ffde65dea77 ScreenToClient GetWindowLongPtrW 1421->1422 1423 7ffde65de9e8-7ffde65de9ea 1421->1423 1426 7ffde65dea79-7ffde65dea94 GetClientRect 1422->1426 1427 7ffde65dea96 1422->1427 1423->1422 1425 7ffde65de9ec-7ffde65dea08 GetWindowLongPtrW 1423->1425 1424->1421 1428 7ffde65dea0a-7ffde65dea1e GetClientRect 1425->1428 1429 7ffde65dea22-7ffde65dea44 ClientToScreen 1425->1429 1430 7ffde65dea9b-7ffde65dea9f 1426->1430 1427->1430 1428->1429 1431 7ffde65deaa3-7ffde65deac9 GetKeyState * 2 1429->1431 1430->1431 1432 7ffde65deacb 1431->1432 1433 7ffde65deacf-7ffde65deadd GetKeyState 1431->1433 1432->1433 1434 7ffde65deae3-7ffde65deaf1 GetKeyState 1433->1434 1435 7ffde65deadf 1433->1435 1436 7ffde65deb03 1434->1436 1437 7ffde65deaf3-7ffde65deb01 GetKeyState 1434->1437 1435->1434 1438 7ffde65deb07-7ffde65deb26 ?mimeData@QDrag@@QEBAPEAVQMimeData@@XZ GetCapture 1436->1438 1437->1436 1437->1438 1439 7ffde65deb28-7ffde65deb3b call 7ffde65d5a40 1438->1439 1440 7ffde65deb3d-7ffde65deb42 1438->1440 1442 7ffde65deb45-7ffde65deb48 1439->1442 1440->1442 1444 7ffde65deb4a 1442->1444 1445 7ffde65deb76-7ffde65debb6 ??0QRect@@QEAA@AEBVQPoint@@AEBVQSize@@@Z ?contains@QRect@@QEBA_NAEBVQPoint@@_N@Z 1442->1445 1446 7ffde65deb50-7ffde65deb63 ?flags@QWindow@@QEBA?AV?$QFlags@W4WindowType@Qt@@@@XZ 1444->1446 1447 7ffde65debba-7ffde65debc2 1445->1447 1446->1447 1448 7ffde65deb65-7ffde65deb74 ?parent@QWindow@@QEBAPEAV1@XZ 1446->1448 1450 7ffde65debc8-7ffde65debf4 call 7ffde65db330 * 2 1447->1450 1451 7ffde65ded01-7ffde65ded18 1447->1451 1448->1445 1448->1446 1475 7ffde65debfa-7ffde65dec0d 1450->1475 1476 7ffde65df295 1450->1476 1452 7ffde65ded1a-7ffde65ded1f 1451->1452 1453 7ffde65ded58-7ffde65ded76 GetMessageExtraInfo 1451->1453 1455 7ffde65ded51 1452->1455 1456 7ffde65ded21-7ffde65ded28 1452->1456 1457 7ffde65ded9b-7ffde65deda4 1453->1457 1458 7ffde65ded78-7ffde65ded7d 1453->1458 1455->1453 1460 7ffde65ded2a-7ffde65ded2f 1456->1460 1461 7ffde65ded4c 1456->1461 1463 7ffde65dedaa 1457->1463 1464 7ffde65dee35-7ffde65dee3d 1457->1464 1458->1457 1462 7ffde65ded7f-7ffde65ded8d 1458->1462 1460->1461 1469 7ffde65ded31-7ffde65ded36 1460->1469 1461->1455 1470 7ffde65ded93 1462->1470 1471 7ffde65df07f-7ffde65df081 1462->1471 1472 7ffde65deeda-7ffde65deee5 1463->1472 1473 7ffde65dedb0-7ffde65dedb8 1463->1473 1467 7ffde65deed8 1464->1467 1468 7ffde65dee43-7ffde65dee51 1464->1468 1467->1472 1468->1467 1469->1461 1477 7ffde65ded38-7ffde65ded3e 1469->1477 1470->1457 1478 7ffde65df297-7ffde65df2bd call 7ffde66c51b0 1471->1478 1479 7ffde65deee7-7ffde65deeed 1472->1479 1480 7ffde65deefd-7ffde65def36 1472->1480 1473->1467 1474 7ffde65dedbe-7ffde65dedcc 1473->1474 1474->1464 1481 7ffde65dec15-7ffde65dec19 1475->1481 1482 7ffde65dec0f-7ffde65dec13 1475->1482 1476->1478 1477->1455 1483 7ffde65ded40-7ffde65ded4a 1477->1483 1479->1480 1484 7ffde65deeef-7ffde65deefb call 7ffde65dcd00 1479->1484 1485 7ffde65def3a-7ffde65def42 1480->1485 1487 7ffde65dec23 1481->1487 1488 7ffde65dec1b-7ffde65dec21 1481->1488 1482->1481 1482->1487 1483->1455 1483->1461 1484->1485 1490 7ffde65df005-7ffde65df01a 1485->1490 1491 7ffde65def48-7ffde65def4e 1485->1491 1495 7ffde65dec25-7ffde65dec28 1487->1495 1488->1495 1493 7ffde65df01c-7ffde65df079 ?handleFrameStrutMouseEvent@QWindowSystemInterface@@SA_NPEAVQWindow@@AEBVQPointF@@1V?$QFlags@W4MouseButton@Qt@@@@W4MouseButton@Qt@@W4Type@QEvent@@V?$QFlags@W4KeyboardModifier@Qt@@@@W4MouseEventSource@6@@Z 1490->1493 1494 7ffde65df086-7ffde65df08e 1490->1494 1497 7ffde65def59-7ffde65def60 1491->1497 1498 7ffde65def50-7ffde65def53 1491->1498 1493->1471 1500 7ffde65df1d4-7ffde65df202 call 7ffde65dcde0 call 7ffde65dd0a0 1494->1500 1501 7ffde65df094-7ffde65df09b 1494->1501 1502 7ffde65dec2a-7ffde65dec39 ?mimeData@QDrag@@QEBAPEAVQMimeData@@XZ 1495->1502 1503 7ffde65dec53 1495->1503 1497->1490 1499 7ffde65def66-7ffde65defa5 1497->1499 1498->1490 1498->1497 1504 7ffde65defd7-7ffde65defff ??$handleMouseEvent@UDefaultDelivery@QWindowSystemInterface@@@QWindowSystemInterface@@SA_NPEAVQWindow@@AEBVQPointF@@1V?$QFlags@W4MouseButton@Qt@@@@W4MouseButton@Qt@@W4Type@QEvent@@V?$QFlags@W4KeyboardModifier@Qt@@@@W4MouseEventSource@5@@Z 1499->1504 1505 7ffde65defa7-7ffde65defd5 ?handleFrameStrutMouseEvent@QWindowSystemInterface@@SA_NPEAVQWindow@@AEBVQPointF@@1V?$QFlags@W4MouseButton@Qt@@@@W4MouseButton@Qt@@W4Type@QEvent@@V?$QFlags@W4KeyboardModifier@Qt@@@@W4MouseEventSource@6@@Z 1499->1505 1520 7ffde65df207-7ffde65df20c 1500->1520 1507 7ffde65df0ad-7ffde65df0b0 1501->1507 1508 7ffde65df09d-7ffde65df0a2 1501->1508 1502->1503 1509 7ffde65dec3b-7ffde65dec51 1502->1509 1510 7ffde65dec56-7ffde65dec7d ScreenToClient GetWindowLongPtrW 1503->1510 1504->1490 1505->1490 1513 7ffde65df0b3-7ffde65df0b8 1507->1513 1508->1507 1512 7ffde65df0a4-7ffde65df0ab 1508->1512 1509->1510 1514 7ffde65dec99 1510->1514 1515 7ffde65dec7f-7ffde65dec97 GetClientRect 1510->1515 1512->1513 1513->1476 1518 7ffde65df0be-7ffde65df0c5 1513->1518 1519 7ffde65dec9d-7ffde65decfc ?handleWheelEvent@QWindowSystemInterface@@SA_NPEAVQWindow@@AEBVQPointF@@1VQPoint@@2V?$QFlags@W4KeyboardModifier@Qt@@@@W4ScrollPhase@Qt@@W4MouseEventSource@7@@Z 1514->1519 1515->1519 1521 7ffde65df0d9 1518->1521 1522 7ffde65df0c7-7ffde65df0cc 1518->1522 1519->1476 1524 7ffde65df277-7ffde65df283 1520->1524 1525 7ffde65df20e-7ffde65df210 1520->1525 1523 7ffde65df0dd-7ffde65df0e3 1521->1523 1522->1521 1526 7ffde65df0ce-7ffde65df0d7 1522->1526 1527 7ffde65df0e5-7ffde65df0ea 1523->1527 1528 7ffde65df0f2 1523->1528 1524->1476 1530 7ffde65df285-7ffde65df28f ?flushWindowSystemEvents@QWindowSystemInterface@@SA_NV?$QFlags@W4ProcessEventsFlag@QEventLoop@@@@@Z 1524->1530 1525->1524 1529 7ffde65df212-7ffde65df271 ??$handleMouseEvent@UDefaultDelivery@QWindowSystemInterface@@@QWindowSystemInterface@@SA_NPEAVQWindow@@AEBVQPointF@@1V?$QFlags@W4MouseButton@Qt@@@@W4MouseButton@Qt@@W4Type@QEvent@@V?$QFlags@W4KeyboardModifier@Qt@@@@W4MouseEventSource@5@@Z 1525->1529 1526->1521 1526->1523 1527->1528 1531 7ffde65df0ec-7ffde65df0f0 1527->1531 1532 7ffde65df0f5-7ffde65df105 call 7ffde65cf540 ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ 1528->1532 1529->1524 1530->1471 1530->1476 1531->1532 1535 7ffde65df179-7ffde65df196 ??$handleLeaveEvent@UDefaultDelivery@QWindowSystemInterface@@@QWindowSystemInterface@@SAXPEAVQWindow@@@Z 1532->1535 1536 7ffde65df107-7ffde65df173 call 7ffde65cf540 ??0QMessageLogger@@QEAA@PEBDH00@Z ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ ??6QDebug@@QEAAAEAV0@PEBD@Z ??6@YA?AVQDebug@@V0@PEBVQWindow@@@Z ??1QDebug@@QEAA@XZ * 2 1532->1536 1538 7ffde65df1a8-7ffde65df1b7 1535->1538 1539 7ffde65df198-7ffde65df1a1 1535->1539 1536->1535 1538->1476 1542 7ffde65df1bd-7ffde65df1c4 1538->1542 1539->1538 1541 7ffde65df1a3 call 7ffde66c57f4 1539->1541 1541->1538 1542->1476 1543 7ffde65df1ca-7ffde65df1cf call 7ffde66c57f4 1542->1543 1543->1476
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Client$Window$State$LongRect$ScreenWindow@@$?mimeData@Data@@Drag@@Flags@MimeQt@@@@Rect@@$?contains@?flags@?handle?parent@CaptureEventEvent@ExtraF@@1InfoInterface@@KeyboardMessageModifier@MousePhase@PointPoint@@Point@@2Point@@_Qt@@ScrollSize@@@Source@7@@SystemType@Wheel
                                                      • String ID: Leaving window
                                                      • API String ID: 4266745907-3785056027
                                                      • Opcode ID: ffa91c8b475e38878c0c9a3782e628b653c8dd7cc7f14518b2e482e4902af6ec
                                                      • Instruction ID: f559348752b3ffe5011c6c25725a93a83b53efc63ce8b8d99fe70be6488839d4
                                                      • Opcode Fuzzy Hash: ffa91c8b475e38878c0c9a3782e628b653c8dd7cc7f14518b2e482e4902af6ec
                                                      • Instruction Fuzzy Hash: 9342A032B28B8286EB19DF64D86436E77B4FB89798F100235EA4E53694DF3CE445CB01

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1713 7ffde6633890-7ffde663397f 1714 7ffde6633981-7ffde6633983 1713->1714 1715 7ffde66339ab-7ffde6633a25 1713->1715 1714->1715 1716 7ffde6633985-7ffde66339a7 ?scale@QTransform@@QEAAAEAV1@NN@Z 1714->1716 1717 7ffde6633a27-7ffde6633a29 1715->1717 1718 7ffde6633a2b-7ffde6633a2d 1715->1718 1716->1715 1717->1718 1719 7ffde6633a41 1717->1719 1718->1719 1720 7ffde6633a2f-7ffde6633a31 1718->1720 1721 7ffde6633a46-7ffde6633a98 1719->1721 1722 7ffde6633a33-7ffde6633a38 1720->1722 1723 7ffde6633a3a-7ffde6633a3f 1720->1723 1724 7ffde6633aa5-7ffde6633aa7 1721->1724 1722->1721 1723->1721 1725 7ffde6633aad-7ffde6633ad8 1724->1725 1726 7ffde6633fbe-7ffde6633fce ?qErrnoWarning@@YAXHPEBDZZ 1724->1726 1727 7ffde6633fd4-7ffde6633fd7 ??0QImage@@QEAA@XZ 1725->1727 1730 7ffde6633ade-7ffde6633aee 1725->1730 1726->1727 1729 7ffde6633fdd-7ffde663400f call 7ffde66c51b0 1727->1729 1730->1727 1732 7ffde6633af4-7ffde6633b70 ??0QImage@@QEAA@XZ 1730->1732 1734 7ffde6633e90-7ffde6633ecc ??0QImage@@QEAA@HHW4Format@0@@Z ??4QPixmap@@QEAAAEAV0@$$QEAV0@@Z ??1QImage@@UEAA@XZ ?fill@QImage@@QEAAXI@Z 1732->1734 1735 7ffde6633b76-7ffde6633b9d 1732->1735 1736 7ffde6633ed0-7ffde6633ed8 1734->1736 1735->1734 1741 7ffde6633ba3-7ffde6633c1d ??0QImage@@QEAA@HHW4Format@0@@Z ??4QPixmap@@QEAAAEAV0@$$QEAV0@@Z ??1QImage@@UEAA@XZ ?fill@QImage@@QEAAXI@Z 1735->1741 1737 7ffde6633f1e-7ffde6633f25 1736->1737 1738 7ffde6633eda-7ffde6633f1c ?redF@QColor@@QEBANXZ ?greenF@QColor@@QEBANXZ ?blueF@QColor@@QEBANXZ ?alphaF@QColor@@QEBANXZ 1736->1738 1740 7ffde6633f28-7ffde6633f52 call 7ffde6634010 1737->1740 1738->1740 1743 7ffde6633f57-7ffde6633fbc ??0QImage@@QEAA@$$QEAV0@@Z ??1QImage@@UEAA@XZ 1740->1743 1741->1736 1745 7ffde6633c23-7ffde6633c3f 1741->1745 1743->1729 1747 7ffde6633c40-7ffde6633c42 1745->1747 1747->1743 1748 7ffde6633c48-7ffde6633c67 1747->1748 1750 7ffde6633c6d-7ffde6633cbe 1748->1750 1751 7ffde6633e75-7ffde6633e8b ?qErrnoWarning@@YAXHPEBDZZ 1748->1751 1753 7ffde6633cc4-7ffde6633cce 1750->1753 1754 7ffde6633e5a-7ffde6633e70 ?qErrnoWarning@@YAXHPEBDZZ 1750->1754 1751->1743 1755 7ffde6633cd0-7ffde6633d14 ?redF@QColor@@QEBANXZ ?greenF@QColor@@QEBANXZ ?blueF@QColor@@QEBANXZ ?alphaF@QColor@@QEBANXZ 1753->1755 1756 7ffde6633d19-7ffde6633d40 1753->1756 1754->1743 1757 7ffde6633dc5-7ffde6633dc8 1755->1757 1758 7ffde6633d42 1756->1758 1759 7ffde6633d46-7ffde6633d6d 1756->1759 1760 7ffde6633dcf-7ffde6633dd2 1757->1760 1761 7ffde6633dca-7ffde6633dcd 1757->1761 1758->1759 1762 7ffde6633d6f 1759->1762 1763 7ffde6633d73-7ffde6633d98 1759->1763 1764 7ffde6633dd6-7ffde6633dda 1760->1764 1761->1764 1762->1763 1765 7ffde6633d9d-7ffde6633dc0 1763->1765 1766 7ffde6633d9a 1763->1766 1767 7ffde6633e0b-7ffde6633e34 1764->1767 1768 7ffde6633ddc-7ffde6633e06 call 7ffde6634010 1764->1768 1765->1761 1769 7ffde6633dc2 1765->1769 1766->1765 1773 7ffde6633e3f-7ffde6633e55 ?qErrnoWarning@@YAXHPEBDZZ 1767->1773 1774 7ffde6633e36-7ffde6633e3a 1767->1774 1768->1767 1769->1757 1773->1743 1774->1747
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Image@@$Color@@$ErrnoWarning@@$V0@@$?alpha?blue?fill@?green?red?scale@A@$$Format@0@@Pixmap@@Transform@@V0@$$
                                                      • String ID: %s: CreateGlyphRunAnalysis failed$%s: CreateGlyphRunAnalysis failed for color run$%s: IDWriteColorGlyphRunEnumerator::GetCurrentRun failed$%s: IDWriteColorGlyphRunEnumerator::MoveNext failed$QWindowsFontEngineDirectWrite::imageForGlyph
                                                      • API String ID: 389426866-4098578670
                                                      • Opcode ID: 34f8f2b335a6eec3e585c8ee48bc881aba266680311b300e8f5c02fe1a0e8267
                                                      • Instruction ID: ce555eb51c498e63024284062c0a086a27aa9de86572c101e437554054558ae2
                                                      • Opcode Fuzzy Hash: 34f8f2b335a6eec3e585c8ee48bc881aba266680311b300e8f5c02fe1a0e8267
                                                      • Instruction Fuzzy Hash: 1B227132B28BC58AE7158F36D4502A97770FF99B88F54833ADA4D27664DF38E585CB00
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$Logger@@Message$Window@@$?debug@Category@@DebugEnabled@H00@Logging$?window@Format@@PlatformSurface$?qt_window_private@@?swap?warning@Interval@Private@@WindowWindow@@@
                                                      • String ID: %s: Failed to make surface current. eglError: %x, this: %p$Bad access (missing device?) in createWindowSurface() for context$Got EGL context lost in createWindowSurface() for context$Got EGL context lost in makeCurrent() for context$QWindowsEGLContext::makeCurrent
                                                      • API String ID: 4157114250-3749793317
                                                      • Opcode ID: 7083cc8060c0810fc5ce3b93af2df4d90369167fde6c58e6f9e5485f688b016a
                                                      • Instruction ID: d1c5830def036f15fce80aef2ce5023dae9d1e62e143aa7c9272feb3a1bcb6f6
                                                      • Opcode Fuzzy Hash: 7083cc8060c0810fc5ce3b93af2df4d90369167fde6c58e6f9e5485f688b016a
                                                      • Instruction Fuzzy Hash: 7AA16D31B38A4282EB18AF26E86436977A0FF85F94F04417ADA4E43769DE3CE445CB41
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: CapsDeviceString@@$??1?$F@@@@PointVector@$?const?fromArray@CharChar@@Data@Logger@@Message$?compare?warning@Array@@Bit@ByteCaseCreateDeleteInfoLocal8MonitorNull@Private@@Qt@@@Sensitivity@StringStrings@Url@@V0@$$V0@@View@@0
                                                      • String ID: %s: Unable to obtain handle for monitor '%s', defaulting to %g DPI.$WinDisc$h$monitorData
                                                      • API String ID: 2185404562-425584237
                                                      • Opcode ID: dca0f5ddfd65ac1e7753e31e903a24ab3673d970de2b8d37cc0861687113d42e
                                                      • Instruction ID: b967cb4f879e2e7ba9043e0360d7489223c5327162b20db1df7672c5e6e12c01
                                                      • Opcode Fuzzy Hash: dca0f5ddfd65ac1e7753e31e903a24ab3673d970de2b8d37cc0861687113d42e
                                                      • Instruction Fuzzy Hash: F0B18032F38E8287E715DF25E4606AE77A0FB99744F105239EA4A53A54EF3CE494CB00
                                                      APIs
                                                      • ??0QPlatformOpenGLContext@@QEAA@XZ.QT5GUI ref: 00007FFDE66099E1
                                                      • ??0QSurfaceFormat@@QEAA@XZ.QT5GUI ref: 00007FFDE6609A01
                                                        • Part of subcall function 00007FFDE6609790: ??0QSurfaceFormat@@QEAA@XZ.QT5GUI(?,?,?,?,?,?,?,?,?,00007FFDE6609A50), ref: 00007FFDE66097B0
                                                        • Part of subcall function 00007FFDE6609790: ?setRenderableType@QSurfaceFormat@@QEAAXW4RenderableType@1@@Z.QT5GUI(?,?,?,?,?,?,?,?,?,00007FFDE6609A50), ref: 00007FFDE66098AE
                                                        • Part of subcall function 00007FFDE6609790: ?minorVersion@QSurfaceFormat@@QEBAHXZ.QT5GUI(?,?,?,?,?,?,?,?,?,00007FFDE6609A50), ref: 00007FFDE66098BF
                                                        • Part of subcall function 00007FFDE6609790: ?majorVersion@QSurfaceFormat@@QEBAHXZ.QT5GUI(?,?,?,?,?,?,?,?,?,00007FFDE6609A50), ref: 00007FFDE66098CA
                                                        • Part of subcall function 00007FFDE6609790: ?setVersion@QSurfaceFormat@@QEAAXHH@Z.QT5GUI(?,?,?,?,?,?,?,?,?,00007FFDE6609A50), ref: 00007FFDE66098D8
                                                        • Part of subcall function 00007FFDE6609790: ?profile@QSurfaceFormat@@QEBA?AW4OpenGLContextProfile@1@XZ.QT5GUI(?,?,?,?,?,?,?,?,?,00007FFDE6609A50), ref: 00007FFDE66098E1
                                                        • Part of subcall function 00007FFDE6609790: ?setProfile@QSurfaceFormat@@QEAAXW4OpenGLContextProfile@1@@Z.QT5GUI(?,?,?,?,?,?,?,?,?,00007FFDE6609A50), ref: 00007FFDE66098EC
                                                        • Part of subcall function 00007FFDE6609790: ?options@QSurfaceFormat@@QEBA?AV?$QFlags@W4FormatOption@QSurfaceFormat@@@@XZ.QT5GUI(?,?,?,?,?,?,?,?,?,00007FFDE6609A50), ref: 00007FFDE66098FA
                                                        • Part of subcall function 00007FFDE6609790: ?setOptions@QSurfaceFormat@@QEAAXV?$QFlags@W4FormatOption@QSurfaceFormat@@@@@Z.QT5GUI(?,?,?,?,?,?,?,?,?,00007FFDE6609A50), ref: 00007FFDE6609905
                                                        • Part of subcall function 00007FFDE6609790: ?setRedBufferSize@QSurfaceFormat@@QEAAXH@Z.QT5GUI(?,?,?,?,?,?,?,?,?,00007FFDE6609A50), ref: 00007FFDE6609912
                                                        • Part of subcall function 00007FFDE6609790: ?setGreenBufferSize@QSurfaceFormat@@QEAAXH@Z.QT5GUI(?,?,?,?,?,?,?,?,?,00007FFDE6609A50), ref: 00007FFDE660991F
                                                        • Part of subcall function 00007FFDE6609790: ?setBlueBufferSize@QSurfaceFormat@@QEAAXH@Z.QT5GUI(?,?,?,?,?,?,?,?,?,00007FFDE6609A50), ref: 00007FFDE660992C
                                                        • Part of subcall function 00007FFDE6609790: ?setAlphaBufferSize@QSurfaceFormat@@QEAAXH@Z.QT5GUI(?,?,?,?,?,?,?,?,?,00007FFDE6609A50), ref: 00007FFDE6609939
                                                        • Part of subcall function 00007FFDE6609790: ?setDepthBufferSize@QSurfaceFormat@@QEAAXH@Z.QT5GUI(?,?,?,?,?,?,?,?,?,00007FFDE6609A50), ref: 00007FFDE6609946
                                                      • ??4QSurfaceFormat@@QEAAAEAV0@AEBV0@@Z.QT5GUI ref: 00007FFDE6609A57
                                                      • ??1QSurfaceFormat@@QEAA@XZ.QT5GUI ref: 00007FFDE6609A62
                                                      • ?majorVersion@QSurfaceFormat@@QEBAHXZ.QT5GUI ref: 00007FFDE6609A8D
                                                      • ?minorVersion@QSurfaceFormat@@QEBAHXZ.QT5GUI ref: 00007FFDE6609A9A
                                                      • ??0QMessageLogger@@QEAA@PEBDH0@Z.QT5CORE ref: 00007FFDE6609ABB
                                                      • ?warning@QMessageLogger@@QEBAXPEBDZZ.QT5CORE ref: 00007FFDE6609ACB
                                                      • ??0QMessageLogger@@QEAA@PEBDH0@Z.QT5CORE ref: 00007FFDE6609D3E
                                                      • ?warning@QMessageLogger@@QEBAXPEBDZZ.QT5CORE ref: 00007FFDE6609D54
                                                      • ??0QMessageLogger@@QEAA@PEBDH0@Z.QT5CORE ref: 00007FFDE6609D6E
                                                      • ?warning@QMessageLogger@@QEBAXPEBDZZ.QT5CORE ref: 00007FFDE6609D7E
                                                      • ??0QByteArray@@QEAA@PEBDH@Z.QT5CORE ref: 00007FFDE6609E7D
                                                      • ?parseOpenGLVersion@QPlatformOpenGLContext@@SA_NAEBVQByteArray@@AEAH1@Z.QT5GUI ref: 00007FFDE6609E92
                                                      • ?setMajorVersion@QSurfaceFormat@@QEAAXH@Z.QT5GUI ref: 00007FFDE6609EA4
                                                      • ?setMinorVersion@QSurfaceFormat@@QEAAXH@Z.QT5GUI ref: 00007FFDE6609EB2
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE6609EBD
                                                      • ?setProfile@QSurfaceFormat@@QEAAXW4OpenGLContextProfile@1@@Z.QT5GUI ref: 00007FFDE6609EC9
                                                      • ?setOptions@QSurfaceFormat@@QEAAXV?$QFlags@W4FormatOption@QSurfaceFormat@@@@@Z.QT5GUI ref: 00007FFDE6609ED5
                                                      • ?deallocate@QArrayData@@SAXPEAU1@_K1@Z.QT5CORE ref: 00007FFDE6609F34
                                                      Strings
                                                      • QWindowsEGLContext: Graphics device lost. (Did the adapter get disabled?), xrefs: 00007FFDE6609D77
                                                      • QWindowsEGLContext: Failed to create context, eglError: %x, this: %p, xrefs: 00007FFDE6609D47
                                                      • QWindowsEGLContext: ANGLE only partially supports OpenGL ES > 3.0, xrefs: 00007FFDE6609AC4
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Surface$Format@@$?set$Version@$Logger@@MessageOpen$BufferSize@$?warning@ContextFlags@FormatOption@$?major?minorArray@@ByteContext@@Format@@@@@Options@PlatformProfile@Profile@1@@Renderable$??1?$?deallocate@?options@?parse?profile@AlphaArrayBlueData@@DepthF@@@@Format@@@@GreenMajorMinorPointProfile@1@Type@Type@1@@U1@_V0@@Vector@
                                                      • String ID: QWindowsEGLContext: ANGLE only partially supports OpenGL ES > 3.0$QWindowsEGLContext: Failed to create context, eglError: %x, this: %p$QWindowsEGLContext: Graphics device lost. (Did the adapter get disabled?)
                                                      • API String ID: 3934667544-243647430
                                                      • Opcode ID: e269cfc882f51b9f7f66e2a0bfa897c32fc8bee0b92df5ee4d1188e8f10e0374
                                                      • Instruction ID: 1825bd84f7cc66b87cdacf2fa4fd23f0dfbf9872f1ef72bce79fee8dbc3e1497
                                                      • Opcode Fuzzy Hash: e269cfc882f51b9f7f66e2a0bfa897c32fc8bee0b92df5ee4d1188e8f10e0374
                                                      • Instruction Fuzzy Hash: 8A029232B34A4286EB789F15E8A066E77A1FB85B44F50A179DA4F03B54DF3CE445CB01
                                                      APIs
                                                        • Part of subcall function 00007FFDE65D1B10: ??0QByteArray@@QEAA@AEBV0@@Z.QT5CORE ref: 00007FFDE65D1B4E
                                                        • Part of subcall function 00007FFDE65D1B10: ??YQString@@QEAAAEAV0@AEBV0@@Z.QT5CORE ref: 00007FFDE65D1B5F
                                                        • Part of subcall function 00007FFDE65D1B10: ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000,00007FFDE660702A), ref: 00007FFDE65D1B94
                                                        • Part of subcall function 00007FFDE65D1B10: GetModuleHandleW.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000,00007FFDE660702A), ref: 00007FFDE65D1B9C
                                                        • Part of subcall function 00007FFDE65D1B10: ?utf16@QString@@QEBAPEBGXZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000,00007FFDE660702A), ref: 00007FFDE65D1BAA
                                                        • Part of subcall function 00007FFDE65D1B10: CreateWindowExW.USER32 ref: 00007FFDE65D1BF8
                                                        • Part of subcall function 00007FFDE65D1B10: ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FFDE65D1C06
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE660E435
                                                      • ?qErrnoWarning@@YAXPEBDZZ.QT5CORE ref: 00007FFDE660E46E
                                                      • SetClipboardViewer.USER32 ref: 00007FFDE660E47E
                                                      • ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ.QT5CORE ref: 00007FFDE660E490
                                                      • ??0QMessageLogger@@QEAA@PEBDH00@Z.QT5CORE ref: 00007FFDE660E4B9
                                                      • ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ.QT5CORE ref: 00007FFDE660E4C7
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE660E4D7
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE660E4E7
                                                      • ??6QDebug@@QEAAAEAV0@PEBX@Z.QT5CORE ref: 00007FFDE660E4F4
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE660E504
                                                      • ??6QDebug@@QEAAAEAV0@_N@Z.QT5CORE ref: 00007FFDE660E511
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE660E521
                                                      • ??6QDebug@@QEAAAEAV0@PEBX@Z.QT5CORE ref: 00007FFDE660E52E
                                                      • ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE660E539
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$??1?$F@@@@PointVector@$Logger@@MessageString@@V0@@$?debug@?utf16@Array@@ByteCategory@@ClipboardCreateDebugEnabled@ErrnoH00@HandleLoggingModuleV0@_ViewerWarning@@Window
                                                      • String ID: AddClipboardFormatListener() failed.$QWindowsClipboard::registerViewer$QtClipboardView$format listener:$m_clipboardViewer:$next:
                                                      • API String ID: 3704394836-864732125
                                                      • Opcode ID: 4e3e64a02b74432b4d8aee5af457b0f229f29299599a70eb6a848f7c4f878ee7
                                                      • Instruction ID: 685d5e272c648347c0b31ad71f68e46397e95e5a3db65985aa04ec03a513e8da
                                                      • Opcode Fuzzy Hash: 4e3e64a02b74432b4d8aee5af457b0f229f29299599a70eb6a848f7c4f878ee7
                                                      • Instruction Fuzzy Hash: 774118A1B38E4282EB28EF65E87437937A1FF85B54F411179D98D02665DF3CE448CB42
                                                      APIs
                                                      • ??0QLocale@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65CCC00), ref: 00007FFDE65D0320
                                                      • memset.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65CCC00), ref: 00007FFDE65D0343
                                                        • Part of subcall function 00007FFDE66C5438: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,00007FFDE6601D3E,?,?,?,00007FFDE6601FED), ref: 00007FFDE66C5452
                                                      • ?connectImpl@QObject@@CA?AVConnection@QMetaObject@@PEBV1@PEAPEAX01PEAVQSlotObjectBase@QtPrivate@@W4ConnectionType@Qt@@PEBHPEBU3@@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65CCC00), ref: 00007FFDE65D03BA
                                                      • ??1Connection@QMetaObject@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65CCC00), ref: 00007FFDE65D03C8
                                                        • Part of subcall function 00007FFDE65D7950: GetKeyboardLayout.USER32 ref: 00007FFDE65D798E
                                                        • Part of subcall function 00007FFDE65D7950: GetLocaleInfoW.KERNEL32(?,?,?,?,?,?,?,?,?,00007FFDE65D03D7), ref: 00007FFDE65D79A5
                                                      • OleInitializeWOW.OLE32 ref: 00007FFDE65D04C0
                                                        • Part of subcall function 00007FFDE65CFA80: ??0?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65D04EE), ref: 00007FFDE65CFAA6
                                                        • Part of subcall function 00007FFDE65CFA80: ??4QByteArray@@QEAAAEAV0@AEBV0@@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65D04EE), ref: 00007FFDE65CFAB4
                                                        • Part of subcall function 00007FFDE65CFA80: ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65D04EE), ref: 00007FFDE65CFAC7
                                                        • Part of subcall function 00007FFDE65CFA80: ?utf16@QString@@QEBAPEBGXZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65D04EE), ref: 00007FFDE65CFAD9
                                                        • Part of subcall function 00007FFDE65CFA80: ?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65D04EE), ref: 00007FFDE65CFAE4
                                                        • Part of subcall function 00007FFDE65CFA80: ?utf16@QString@@QEBAPEBGXZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65D04EE), ref: 00007FFDE65CFB2D
                                                        • Part of subcall function 00007FFDE65CFA80: ?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65D04EE), ref: 00007FFDE65CFB38
                                                        • Part of subcall function 00007FFDE65CFA80: ?utf16@QString@@QEBAPEBGXZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65D04EE), ref: 00007FFDE65CFB7B
                                                        • Part of subcall function 00007FFDE65CFA80: ?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65D04EE), ref: 00007FFDE65CFB86
                                                        • Part of subcall function 00007FFDE65CFA80: ?utf16@QString@@QEBAPEBGXZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65D04EE), ref: 00007FFDE65CFBC9
                                                        • Part of subcall function 00007FFDE65CFA80: ?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65D04EE), ref: 00007FFDE65CFBD4
                                                        • Part of subcall function 00007FFDE65CFA80: ?utf16@QString@@QEBAPEBGXZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65D04EE), ref: 00007FFDE65CFC17
                                                        • Part of subcall function 00007FFDE65CFA80: ?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65D04EE), ref: 00007FFDE65CFC22
                                                        • Part of subcall function 00007FFDE65CFA80: ?current@QOperatingSystemVersion@@SA?AV1@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65D04EE), ref: 00007FFDE65CFC5C
                                                        • Part of subcall function 00007FFDE65D0170: ?current@QOperatingSystemVersion@@SA?AV1@XZ.QT5CORE(?,?,?,?,?,?,?,?,00000000,00007FFDE65D04F3), ref: 00007FFDE65D018D
                                                        • Part of subcall function 00007FFDE65D0170: ?compare@QOperatingSystemVersion@@CAHAEBV1@0@Z.QT5CORE(?,?,?,?,?,?,?,?,00000000,00007FFDE65D04F3), ref: 00007FFDE65D019F
                                                        • Part of subcall function 00007FFDE65D0170: ??0?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,00000000,00007FFDE65D04F3), ref: 00007FFDE65D01BC
                                                        • Part of subcall function 00007FFDE65D0170: ??4QByteArray@@QEAAAEAV0@AEBV0@@Z.QT5CORE(?,?,?,?,?,?,?,?,00000000,00007FFDE65D04F3), ref: 00007FFDE65D01CA
                                                        • Part of subcall function 00007FFDE65D0170: ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,00000000,00007FFDE65D04F3), ref: 00007FFDE65D01DD
                                                        • Part of subcall function 00007FFDE65D0170: ?utf16@QString@@QEBAPEBGXZ.QT5CORE(?,?,?,?,?,?,?,?,00000000,00007FFDE65D04F3), ref: 00007FFDE65D01EF
                                                        • Part of subcall function 00007FFDE65D0170: ?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z.QT5CORE(?,?,?,?,?,?,?,?,00000000,00007FFDE65D04F3), ref: 00007FFDE65D01FA
                                                        • Part of subcall function 00007FFDE65D0170: ?utf16@QString@@QEBAPEBGXZ.QT5CORE(?,?,?,?,?,?,?,?,00000000,00007FFDE65D04F3), ref: 00007FFDE65D0243
                                                        • Part of subcall function 00007FFDE65D0170: ?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z.QT5CORE(?,?,?,?,?,?,?,?,00000000,00007FFDE65D04F3), ref: 00007FFDE65D024E
                                                        • Part of subcall function 00007FFDE65D0170: ?utf16@QString@@QEBAPEBGXZ.QT5CORE(?,?,?,?,?,?,?,?,00000000,00007FFDE65D04F3), ref: 00007FFDE65D0291
                                                        • Part of subcall function 00007FFDE65D0170: ?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z.QT5CORE(?,?,?,?,?,?,?,?,00000000,00007FFDE65D04F3), ref: 00007FFDE65D029C
                                                        • Part of subcall function 00007FFDE65D0170: GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,00000000,00007FFDE65D04F3), ref: 00007FFDE65D02B9
                                                        • Part of subcall function 00007FFDE65D0170: ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,00000000,00007FFDE65D04F3), ref: 00007FFDE65D02CD
                                                      • GetDC.USER32 ref: 00007FFDE65D050B
                                                      • GetDeviceCaps.GDI32 ref: 00007FFDE65D051D
                                                      • GetKeyboardLayoutList.USER32(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65CCC00), ref: 00007FFDE65D052B
                                                      • GetKeyboardLayoutList.USER32(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65CCC00), ref: 00007FFDE65D055B
                                                      • ??0QMessageLogger@@QEAA@PEBDH0@Z.QT5CORE ref: 00007FFDE65D05D0
                                                      • ?warning@QMessageLogger@@QEBA?AVQDebug@@XZ.QT5CORE ref: 00007FFDE65D05E1
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE65D05F1
                                                      • ??6QDebug@@QEAAAEAV0@AEBVQByteArray@@@Z.QT5CORE ref: 00007FFDE65D0614
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65D0622
                                                      • ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE65D0630
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: System$?load@?utf16@E__@@Library@@String@@$F@@@@PointVector@$??1?$Debug@@$ByteKeyboardLayoutObject@@OperatingVersion@@$??0?$?current@Array@@Connection@ListLogger@@MessageMetaV0@@$?compare@?connect?warning@AddressArray@@@Base@CapsConnectionDeviceImpl@InfoInitializeLocaleLocale@@ObjectPrivate@@ProcQt@@SlotType@U3@@V1@0@mallocmemset
                                                      • String ID: QWindowsContext: OleInitialize() failed:
                                                      • API String ID: 3907262406-1565728777
                                                      • Opcode ID: e418cc685b2c510b8d394b8eda7e1040f2cfa7b2b831eb64218a5d2a07345099
                                                      • Instruction ID: 860177889c3e6d8bf7d88d7bcd7250c5aa70f8dd41b93bcb48bcd25fb81c92d7
                                                      • Opcode Fuzzy Hash: e418cc685b2c510b8d394b8eda7e1040f2cfa7b2b831eb64218a5d2a07345099
                                                      • Instruction Fuzzy Hash: E9914D72728BA685E719EF15F868BAE37A8FB48B48F01413ADE4D43790DF389455C702
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Window@@$Window$System$Region@@$?window@CompositionEnabledInterface@@ModuleOpenPaintPlatformRectRect@@$??$handle?flush?openBeginClipContext@@DefaultDelivery@Empty@EventEvent@EventsEvents@ExposeFlag@Flags@Interface@@@InvalidateLongLoop@@@@@Point@@ProcessRegionRegion@@@SelectSize@@@Type@Type@0@@Type@1@UpdateVisible@
                                                      • String ID:
                                                      • API String ID: 2946135873-0
                                                      • Opcode ID: 9742b1c8b134252aba3988331e3a3f4699a2dcf2a813f70b918a00d51a8c6489
                                                      • Instruction ID: 51206d490fb1ce62578f0f7fda2f3be9591706f5a695d55649ac9f4b8bd1289d
                                                      • Opcode Fuzzy Hash: 9742b1c8b134252aba3988331e3a3f4699a2dcf2a813f70b918a00d51a8c6489
                                                      • Instruction Fuzzy Hash: 03515E32B28A028AFB19DF79D4647BC37A1BB45758F450279CA0E57A58DF3CE409CB02
                                                      APIs
                                                      • ??0?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE6601F7C
                                                      • ??0?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE6601F86
                                                      • ??0?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE6601F90
                                                        • Part of subcall function 00007FFDE6601E80: ??0?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,00000001,00007FFDE6601FA0), ref: 00007FFDE6601E9D
                                                        • Part of subcall function 00007FFDE6601E80: ??4QByteArray@@QEAAAEAV0@AEBV0@@Z.QT5CORE(?,?,00000001,00007FFDE6601FA0), ref: 00007FFDE6601EAC
                                                        • Part of subcall function 00007FFDE6601E80: ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,00000001,00007FFDE6601FA0), ref: 00007FFDE6601EC2
                                                        • Part of subcall function 00007FFDE6601E80: ?utf16@QString@@QEBAPEBGXZ.QT5CORE(?,?,00000001,00007FFDE6601FA0), ref: 00007FFDE6601ED4
                                                        • Part of subcall function 00007FFDE6601E80: ?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z.QT5CORE(?,?,00000001,00007FFDE6601FA0), ref: 00007FFDE6601EDF
                                                        • Part of subcall function 00007FFDE6601E80: GetProcAddress.KERNEL32(?,?,00000001,00007FFDE6601FA0), ref: 00007FFDE6601EFB
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE660218C
                                                        • Part of subcall function 00007FFDE6601AC0: ??0?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,?,00007FFDE6601FED), ref: 00007FFDE6601AFA
                                                        • Part of subcall function 00007FFDE6601AC0: ??0?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,?,00007FFDE6601FED), ref: 00007FFDE6601B04
                                                        • Part of subcall function 00007FFDE6601AC0: ??0?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,?,00007FFDE6601FED), ref: 00007FFDE6601B0E
                                                        • Part of subcall function 00007FFDE6601AC0: ?allocate@QArrayData@@SAPEAU1@_K00V?$QFlags@W4AllocationOption@QArrayData@@@@@Z.QT5CORE(?,?,?,00007FFDE6601FED), ref: 00007FFDE6601B4D
                                                        • Part of subcall function 00007FFDE6601AC0: ?allocate@QArrayData@@SAPEAU1@_K00V?$QFlags@W4AllocationOption@QArrayData@@@@@Z.QT5CORE(?,?,?,00007FFDE6601FED), ref: 00007FFDE6601BB6
                                                        • Part of subcall function 00007FFDE6601AC0: ?allocate@QArrayData@@SAPEAU1@_K00V?$QFlags@W4AllocationOption@QArrayData@@@@@Z.QT5CORE(?,?,?,00007FFDE6601FED), ref: 00007FFDE6601C05
                                                        • Part of subcall function 00007FFDE6601AC0: ?allocate@QArrayData@@SAPEAU1@_K00V?$QFlags@W4AllocationOption@QArrayData@@@@@Z.QT5CORE(?,?,?,00007FFDE6601FED), ref: 00007FFDE6601C55
                                                      • ??4QUrl@@QEAAAEAV0@$$QEAV0@@Z.QT5CORE ref: 00007FFDE6602022
                                                      • ??4QUrl@@QEAAAEAV0@$$QEAV0@@Z.QT5CORE ref: 00007FFDE6602030
                                                      • ??4QUrl@@QEAAAEAV0@$$QEAV0@@Z.QT5CORE ref: 00007FFDE660203E
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE6602048
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE6602053
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE660205E
                                                        • Part of subcall function 00007FFDE65C15A0: ?deallocate@QArrayData@@SAXPEAU1@_K1@Z.QT5CORE ref: 00007FFDE65C15E2
                                                      • EnumDisplayDevicesW.USER32 ref: 00007FFDE660210C
                                                      • EnumDisplayDevicesW.USER32 ref: 00007FFDE660212C
                                                      • ?fromWCharArray@QString@@SA?AV1@PEB_WH@Z.QT5CORE ref: 00007FFDE6602147
                                                      • ??4QUrl@@QEAAAEAV0@$$QEAV0@@Z.QT5CORE ref: 00007FFDE6602154
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE660215F
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: F@@@@PointVector@$Array$??0?$$??1?$$Data@@U1@_V0@@$?allocate@AllocationData@@@@@Flags@Option@Url@@V0@$$$DevicesDisplayEnumString@@$?deallocate@?from?load@?utf16@AddressArray@Array@@ByteCharE__@@Library@@ProcSystem
                                                      • String ID:
                                                      • API String ID: 1497531401-0
                                                      • Opcode ID: 46fcff97cfda3788f26d359fff1d458eed926f66a5b612029ee1f484ca231451
                                                      • Instruction ID: f2067ede1f0a8759b4f5cd26c98dea713fb1f0b6f16a275198df4065f664f499
                                                      • Opcode Fuzzy Hash: 46fcff97cfda3788f26d359fff1d458eed926f66a5b612029ee1f484ca231451
                                                      • Instruction Fuzzy Hash: EC71AF32B28A4282EB64DF25D8687AD77A4FB84B88F41407ADE4E47664DF3DD446CB40
                                                      APIs
                                                        • Part of subcall function 00007FFDE65C2730: ?property@QObject@@QEBA?AVQVariant@@PEBD@Z.QT5CORE ref: 00007FFDE65C275D
                                                        • Part of subcall function 00007FFDE65C2730: ?userType@QVariant@@QEBAHXZ.QT5CORE ref: 00007FFDE65C2778
                                                        • Part of subcall function 00007FFDE65C2730: ?constData@QVariant@@QEBAPEBXXZ.QT5CORE ref: 00007FFDE65C2788
                                                        • Part of subcall function 00007FFDE65C2730: ?layoutDirection@QGuiApplication@@SA?AW4LayoutDirection@Qt@@XZ.QT5GUI ref: 00007FFDE65C2853
                                                        • Part of subcall function 00007FFDE65C2730: ??1QVariant@@QEAA@XZ.QT5CORE ref: 00007FFDE65C2A2F
                                                      • ??0QByteArray@@QEAA@AEBV0@@Z.QT5CORE ref: 00007FFDE65C66B4
                                                        • Part of subcall function 00007FFDE65C2A50: GetModuleHandleW.KERNEL32 ref: 00007FFDE65C2ACE
                                                        • Part of subcall function 00007FFDE65C2A50: ?initialGeometry@QPlatformWindow@@SA?AVQRect@@PEBVQWindow@@AEBV2@HHPEAPEBVQScreen@@@Z.QT5GUI ref: 00007FFDE65C2B13
                                                        • Part of subcall function 00007FFDE65C2A50: ?qAppName@@YA?AVQString@@XZ.QT5CORE ref: 00007FFDE65C2B35
                                                        • Part of subcall function 00007FFDE65C2A50: ??4QUrl@@QEAAAEAV0@$$QEAV0@@Z.QT5CORE ref: 00007FFDE65C2B41
                                                        • Part of subcall function 00007FFDE65C2A50: ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65C2B6A
                                                        • Part of subcall function 00007FFDE65C2A50: ?utf16@QString@@QEBAPEBGXZ.QT5CORE ref: 00007FFDE65C2B73
                                                        • Part of subcall function 00007FFDE65C2A50: ?utf16@QString@@QEBAPEBGXZ.QT5CORE ref: 00007FFDE65C2B82
                                                      • SetWindowPos.USER32 ref: 00007FFDE65C6749
                                                      • SetWindowPos.USER32 ref: 00007FFDE65C6770
                                                      • SetWindowPos.USER32 ref: 00007FFDE65C6793
                                                      • ??0QMessageLogger@@QEAA@PEBDH0@Z.QT5CORE ref: 00007FFDE65C67B0
                                                      • ?warning@QMessageLogger@@QEBAXPEBDZZ.QT5CORE ref: 00007FFDE65C67C0
                                                      • GetSystemMenu.USER32 ref: 00007FFDE65C67D5
                                                      • EnableMenuItem.USER32 ref: 00007FFDE65C67F8
                                                      • SetWindowPos.USER32 ref: 00007FFDE65C6831
                                                      Strings
                                                      • QWidget: Incompatible window flags: the window can't be on top and on bottom at the same time, xrefs: 00007FFDE65C67B9
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Variant@@Window$String@@$?utf16@Direction@Logger@@MenuMessageV0@@Window@@$??1?$?const?initial?layout?property@?user?warning@Application@@Array@@ByteData@EnableF@@@@Geometry@HandleItemLayoutModuleName@@Object@@PlatformPointQt@@Rect@@Screen@@@SystemType@Url@@V0@$$Vector@
                                                      • String ID: QWidget: Incompatible window flags: the window can't be on top and on bottom at the same time
                                                      • API String ID: 1271469047-2631108776
                                                      • Opcode ID: 04d2d1c250b3f1d785645228929d441ac4553fe85bc5701fd6c6837834a690a0
                                                      • Instruction ID: ae285ccbe7ed8867d1ac091994e68c5ba425f6140cf1724249ab79b4c825ab66
                                                      • Opcode Fuzzy Hash: 04d2d1c250b3f1d785645228929d441ac4553fe85bc5701fd6c6837834a690a0
                                                      • Instruction Fuzzy Hash: DD51B136B3868287E779CF25E464B6A76A1FB84B84F04513ADE4913A54CF3CE115DF02
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: State$AsyncMouse$Button@Flags@Qt@@@@System$Window$??$handle?contains@?mime?mouseApplication@@Buttons@CursorData@Data@@DefaultDelivery@Drag@@EventEvent@Event@@F@@1Interface@@Interface@@@KeyboardMetricsMimeModifier@PointPoint@@_Qt@@Rect@@Source@5@@Type@Window@@
                                                      • String ID:
                                                      • API String ID: 1675694426-0
                                                      • Opcode ID: 0849f311cc743d799a858dae6a646c961620726082876239ee44c6a9e0cadb0b
                                                      • Instruction ID: c67c20c2113c162ae6ef68de2c4d820dfa3e71ec40e7d52e6395c278e050be1c
                                                      • Opcode Fuzzy Hash: 0849f311cc743d799a858dae6a646c961620726082876239ee44c6a9e0cadb0b
                                                      • Instruction Fuzzy Hash: 2F516E36B24B818AEB19DF64D4647BD3375FB98B88F404139DE4A23784DF38A545C701
                                                      APIs
                                                      • IsIconic.USER32 ref: 00007FFDE65D2CC5
                                                      • ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ.QT5GUI ref: 00007FFDE65D3353
                                                      • ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ.QT5GUI ref: 00007FFDE65D33A6
                                                      • ?isTopLevel@QWindow@@QEBA_NXZ.QT5GUI ref: 00007FFDE65D33B2
                                                      • ?minimumSize@QWindow@@QEBA?AVQSize@@XZ.QT5GUI ref: 00007FFDE65D33FE
                                                      • ?maximumSize@QWindow@@QEBA?AVQSize@@XZ.QT5GUI ref: 00007FFDE65D3422
                                                      • ?scaleAndOrigin@QHighDpiScaling@@SA?AUScaleAndOrigin@1@PEBVQWindow@@PEAVQPoint@@@Z.QT5GUI ref: 00007FFDE65D3465
                                                        • Part of subcall function 00007FFDE65C7FF0: ?marginsRemoved@QRect@@QEBA?AV1@AEBVQMargins@@@Z.QT5CORE ref: 00007FFDE65C8037
                                                        • Part of subcall function 00007FFDE65C7FF0: ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ.QT5GUI ref: 00007FFDE65C8089
                                                        • Part of subcall function 00007FFDE65C7FF0: ??$handleGeometryChange@UDefaultDelivery@QWindowSystemInterface@@@QWindowSystemInterface@@SAXPEAVQWindow@@AEBVQRect@@@Z.QT5GUI ref: 00007FFDE65C8096
                                                        • Part of subcall function 00007FFDE65C7FF0: ?size@QRect@@QEBA?AVQSize@@XZ.QT5CORE ref: 00007FFDE65C80CA
                                                        • Part of subcall function 00007FFDE65C7FF0: ?flushWindowSystemEvents@QWindowSystemInterface@@SA_NV?$QFlags@W4ProcessEventsFlag@QEventLoop@@@@@Z.QT5GUI ref: 00007FFDE65C8131
                                                        • Part of subcall function 00007FFDE65C7FF0: ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ.QT5CORE ref: 00007FFDE65C814A
                                                        • Part of subcall function 00007FFDE65C7FF0: ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ.QT5GUI ref: 00007FFDE65C815B
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Window@@$?window@PlatformSystemWindow$Size@@$Interface@@Rect@@Size@$??$handle?flush?margins?maximum?minimum?scale?size@Category@@Change@DebugDefaultDelivery@Enabled@EventEventsEvents@Flag@Flags@GeometryHighIconicInterface@@@Level@LoggingLoop@@@@@Margins@@@Origin@Origin@1@Point@@@ProcessRect@@@Removed@ScaleScaling@@
                                                      • String ID:
                                                      • API String ID: 785407567-0
                                                      • Opcode ID: 76ec745e5ec8c3a3691713e33198f706661cf22f47b40ece557d2d61752aa06e
                                                      • Instruction ID: fdd1f7b0200558b56425c70f3da21b57a19dfa2a424b797740e79ab8652f5521
                                                      • Opcode Fuzzy Hash: 76ec745e5ec8c3a3691713e33198f706661cf22f47b40ece557d2d61752aa06e
                                                      • Instruction Fuzzy Hash: 10F0B432B284C540F6279B1CE4253FE6390AFA9359F400135CEA926191DE38D1839701

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1044 7ffde65c8220-7ffde65c8299 call 7ffde65cf4b0 ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ 1048 7ffde65c843f-7ffde65c846f GetWindowPlacement 1044->1048 1049 7ffde65c829f-7ffde65c8439 call 7ffde65c4160 ?marginsRemoved@QRect@@QEBA?AV1@AEBVQMargins@@@Z ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ call 7ffde65cf4b0 ??0QMessageLogger@@QEAA@PEBDH00@Z ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ ??6QDebug@@QEAAAEAV0@D@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6@YA?AVQDebug@@V0@PEBVQWindow@@@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6@YA?AVQDebug@@V0@AEBVQRect@@@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6@YA?AVQDebug@@V0@AEBVQMargins@@@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6@YA?AVQDebug@@V0@AEBVQRect@@@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6@YA?AVQDebug@@V0@AEBVQRect@@@Z ??1QDebug@@QEAA@XZ * 6 1044->1049 1053 7ffde65c8481-7ffde65c8484 1048->1053 1054 7ffde65c8471-7ffde65c847c IsWindowVisible 1048->1054 1049->1048 1056 7ffde65c848a-7ffde65c850f call 7ffde65c1bf0 ?translated@QRect@@QEBA?AV1@AEBVQPoint@@@Z SetWindowPlacement 1053->1056 1058 7ffde65c8514-7ffde65c8534 ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ ?isTopLevel@QWindow@@QEBA_NXZ 1053->1058 1054->1056 1057 7ffde65c847e 1054->1057 1067 7ffde65c85ba-7ffde65c85d0 call 7ffde65cf4b0 ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ 1056->1067 1057->1053 1059 7ffde65c8536-7ffde65c8556 GetParent GetWindowLongPtrW 1058->1059 1060 7ffde65c857e-7ffde65c8583 1058->1060 1059->1060 1063 7ffde65c8558-7ffde65c857c GetClientRect 1059->1063 1064 7ffde65c8587-7ffde65c85b2 MoveWindow 1060->1064 1063->1064 1064->1067 1070 7ffde65c85d6-7ffde65c8639 call 7ffde65c4160 ?marginsRemoved@QRect@@QEBA?AV1@AEBVQMargins@@@Z ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ 1067->1070 1071 7ffde65c8701-7ffde65c871f call 7ffde66c51b0 1067->1071 1077 7ffde65c863f-7ffde65c86fb ??0QMessageLogger@@QEAA@PEBDH00@Z ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ ??6QDebug@@QEAAAEAV0@D@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6@YA?AVQDebug@@V0@PEBVQWindow@@@Z ??6QDebug@@QEAAAEAV0@PEBD@Z ??6QDebug@@QEAAAEAV0@_N@Z ??6@YA?AVQDebug@@V0@AEBVQRect@@@Z ??1QDebug@@QEAA@XZ * 3 1070->1077 1078 7ffde65c8720-7ffde65c8733 call 7ffde66c5328 1070->1078 1077->1071 1078->1077 1081 7ffde65c8739-7ffde65c8765 ??0QLoggingCategory@@QEAA@PEBD@Z call 7ffde66c57dc _Init_thread_footer 1078->1081 1081->1077
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$??6@Window@@$Window$Rect@@$Category@@Logger@@LoggingMessageRect@@@$?window@Margins@@@PlacementPlatform$?debug@?margins?translated@DebugEnabled@H00@Init_thread_footerPoint@@@Removed@Window@@@$ClientLevel@LongMoveParentPoint@@RectSize@@@V0@_Visible
                                                      • String ID: from $ resulting $ frame: $ new frame: $ to $QWindowsBaseWindow::setGeometry_sys$qt.qpa.windows
                                                      • API String ID: 1848587063-576288940
                                                      • Opcode ID: b4adfad42499152bac2e174a4184a604a3f4fa01b46c246ca392ff83277b7535
                                                      • Instruction ID: 4e4d41f986a49a8ead66b0cc409b7edd73d8b40dd07fc86679f0509366aa1da3
                                                      • Opcode Fuzzy Hash: b4adfad42499152bac2e174a4184a604a3f4fa01b46c246ca392ff83277b7535
                                                      • Instruction Fuzzy Hash: 1BF16076B28E4286DB18EF65E8642AD7770FB84B94F40503ADA4E43728DF3CD449CB41

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1547 7ffde660c2b0-7ffde660c2d7 call 7ffde65cf9c0 ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ 1550 7ffde660c2dd-7ffde660c37d call 7ffde65cf9c0 ??0QMessageLogger@@QEAA@PEBDH00@Z ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ ??6QDebug@@QEAAAEAV0@PEBD@Z ??6QDebug@@QEAAAEAV0@D@Z ??6@YA?AVQDebug@@V0@AEBVQIcon@@@Z ??6QDebug@@QEAAAEAV0@D@Z call 7ffde660d6c0 ??1QDebug@@QEAA@XZ * 3 1547->1550 1551 7ffde660c383-7ffde660c39c ?cacheKey@QIcon@@QEBA_JXZ * 2 1547->1551 1550->1551 1553 7ffde660c3a2-7ffde660c3c1 ?isNull@QIcon@@QEBA_NXZ 1551->1553 1554 7ffde660c5d6-7ffde660c5e1 1551->1554 1556 7ffde660c43f-7ffde660c444 1553->1556 1557 7ffde660c3c3-7ffde660c425 GetSystemMetrics * 2 ?actualSize@QIcon@@QEBA?AVQSize@@AEBV2@W4Mode@1@W4State@1@@Z ?pixmap@QIcon@@QEBA?AVQPixmap@@AEBVQSize@@W4Mode@1@W4State@1@@Z ?isNull@QPixmap@@QEBA_NXZ 1553->1557 1561 7ffde660c5b3-7ffde660c5bb call 7ffde660d300 1556->1561 1562 7ffde660c44a-7ffde660c44f 1556->1562 1559 7ffde660c435-7ffde660c439 ??1QPixmap@@UEAA@XZ 1557->1559 1560 7ffde660c427-7ffde660c431 ?qt_pixmapToWinHICON@@YAPEAUHICON__@@AEBVQPixmap@@@Z 1557->1560 1559->1556 1560->1559 1565 7ffde660c5c0-7ffde660c5c3 1561->1565 1562->1565 1566 7ffde660c455-7ffde660c461 call 7ffde660bdc0 1562->1566 1567 7ffde660c5ce 1565->1567 1568 7ffde660c5c5-7ffde660c5c8 DestroyCursor 1565->1568 1566->1565 1571 7ffde660c467-7ffde660c46f 1566->1571 1567->1554 1568->1567 1572 7ffde660c471-7ffde660c47e RegisterWindowMessageW 1571->1572 1573 7ffde660c484-7ffde660c4a7 ChangeWindowMessageFilterEx call 7ffde65cf9c0 ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ 1571->1573 1572->1573 1576 7ffde660c4ad-7ffde660c531 call 7ffde65cf9c0 ??0QMessageLogger@@QEAA@PEBDH00@Z ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ ??6QDebug@@QEAAAEAV0@PEBD@Z call 7ffde660d6c0 ??6QDebug@@QEAAAEAV0@PEBD@Z ??6QDebug@@QEAAAEAV0@I@Z ??1QDebug@@QEAA@XZ * 2 1573->1576 1577 7ffde660c537-7ffde660c559 call 7ffde660d8b0 1573->1577 1576->1577 1583 7ffde660c562 1577->1583 1584 7ffde660c55b-7ffde660c55e 1577->1584 1585 7ffde660c565-7ffde660c570 1583->1585 1584->1585 1587 7ffde660c560 1584->1587 1589 7ffde660c572-7ffde660c577 1585->1589 1590 7ffde660c579-7ffde660c57c 1585->1590 1588 7ffde660c58b-7ffde660c5ae call 7ffde660d300 1587->1588 1588->1561 1591 7ffde660c580-7ffde660c586 call 7ffde660d950 1589->1591 1590->1591 1591->1588
                                                      APIs
                                                      • ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ.QT5CORE ref: 00007FFDE660C2CF
                                                      • ??0QMessageLogger@@QEAA@PEBDH00@Z.QT5CORE ref: 00007FFDE660C2F7
                                                      • ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ.QT5CORE ref: 00007FFDE660C304
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE660C314
                                                      • ??6QDebug@@QEAAAEAV0@D@Z.QT5CORE ref: 00007FFDE660C31F
                                                      • ??6@YA?AVQDebug@@V0@AEBVQIcon@@@Z.QT5GUI ref: 00007FFDE660C33A
                                                      • ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE660C369
                                                      • ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE660C373
                                                      • ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE660C37D
                                                      • ??6QDebug@@QEAAAEAV0@D@Z.QT5CORE ref: 00007FFDE660C345
                                                        • Part of subcall function 00007FFDE660D6C0: ??0QDebugStateSaver@@QEAA@AEAVQDebug@@@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D6D6
                                                        • Part of subcall function 00007FFDE660D6C0: ?noquote@QDebug@@QEAAAEAV1@XZ.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D6E6
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D6F6
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBX@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D728
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D738
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@AEBVQString@@@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D745
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D755
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBX@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D762
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D772
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBX@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D77F
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D78F
                                                        • Part of subcall function 00007FFDE660D6C0: ??0QDebugStateSaver@@QEAA@AEAVQDebug@@@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D7AA
                                                        • Part of subcall function 00007FFDE660D6C0: ?noquote@QDebug@@QEAAAEAV1@XZ.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D7BE
                                                        • Part of subcall function 00007FFDE660D6C0: ?className@QMetaObject@@QEBAPEBDXZ.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D7DB
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D7E9
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@D@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D7F4
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@D@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D80E
                                                        • Part of subcall function 00007FFDE660D6C0: ??0QDebug@@QEAA@$$QEAV0@@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D832
                                                        • Part of subcall function 00007FFDE660D6C0: ??1QDebugStateSaver@@QEAA@XZ.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D83D
                                                        • Part of subcall function 00007FFDE660D6C0: ??1QDebug@@QEAA@XZ.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D848
                                                        • Part of subcall function 00007FFDE660D6C0: ??1QDebug@@QEAA@XZ.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D853
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@D@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D870
                                                        • Part of subcall function 00007FFDE660D6C0: ??0QDebug@@QEAA@$$QEAV0@@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D87C
                                                      • ?cacheKey@QIcon@@QEBA_JXZ.QT5GUI ref: 00007FFDE660C387
                                                      • ?cacheKey@QIcon@@QEBA_JXZ.QT5GUI ref: 00007FFDE660C393
                                                      • ?isNull@QIcon@@QEBA_NXZ.QT5GUI ref: 00007FFDE660C3B9
                                                      • GetSystemMetrics.USER32 ref: 00007FFDE660C3C8
                                                      • GetSystemMetrics.USER32 ref: 00007FFDE660C3D5
                                                      • ?actualSize@QIcon@@QEBA?AVQSize@@AEBV2@W4Mode@1@W4State@1@@Z.QT5GUI ref: 00007FFDE660C3F7
                                                      • ?pixmap@QIcon@@QEBA?AVQPixmap@@AEBVQSize@@W4Mode@1@W4State@1@@Z.QT5GUI ref: 00007FFDE660C413
                                                      • ?isNull@QPixmap@@QEBA_NXZ.QT5GUI ref: 00007FFDE660C41D
                                                      • ?qt_pixmapToWinHICON@@YAPEAUHICON__@@AEBVQPixmap@@@Z.QT5GUI ref: 00007FFDE660C42B
                                                      • ??1QPixmap@@UEAA@XZ.QT5GUI ref: 00007FFDE660C439
                                                      • RegisterWindowMessageW.USER32 ref: 00007FFDE660C478
                                                      • ChangeWindowMessageFilterEx.USER32 ref: 00007FFDE660C491
                                                      • ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ.QT5CORE ref: 00007FFDE660C49F
                                                      • ??0QMessageLogger@@QEAA@PEBDH00@Z.QT5CORE ref: 00007FFDE660C4C7
                                                      • ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ.QT5CORE ref: 00007FFDE660C4D4
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE660C4E4
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE660C50E
                                                      • ??6QDebug@@QEAAAEAV0@I@Z.QT5CORE ref: 00007FFDE660C51D
                                                      • ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE660C527
                                                      • ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE660C531
                                                        • Part of subcall function 00007FFDE65CF9C0: ??0QLoggingCategory@@QEAA@PEBD@Z.QT5CORE ref: 00007FFDE65CFA1C
                                                        • Part of subcall function 00007FFDE65CF9C0: _Init_thread_footer.LIBCMT ref: 00007FFDE65CFA35
                                                      • DestroyCursor.USER32 ref: 00007FFDE660C5C8
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$Message$DebugIcon@@$Logger@@$Category@@LoggingPixmap@@Saver@@State$?cache?debug@?noquote@A@$$Debug@@@Enabled@H00@Key@MetricsMode@1@Null@Size@@State@1@@SystemV0@@Window$??6@?actual?class?pixmap@?qt_pixmapChangeCursorDestroyFilterIcon@@@Init_thread_footerMetaN__@@Name@Object@@Pixmap@@@RegisterSize@String@@@
                                                      • String ID: MYWM_TASKBARCREATED=$QWindowsSystemTrayIcon::ensureInstalled$QWindowsSystemTrayIcon::updateIcon$TaskbarCreated
                                                      • API String ID: 458300882-3985456195
                                                      • Opcode ID: 3056fe9db55573666be7be34ec1646862dfec1dcfe465af2cf472126c57ee9df
                                                      • Instruction ID: 492f11146ab7262316c12bb35eafb88b1d700dbe1a2feed04371dc99f51b8571
                                                      • Opcode Fuzzy Hash: 3056fe9db55573666be7be34ec1646862dfec1dcfe465af2cf472126c57ee9df
                                                      • Instruction Fuzzy Hash: 61914E36B34E0296EB68AF65E8647BC3360FB85B84F405179CA0E43A65DF3CE459CB41

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1594 7ffde65c5b10-7ffde65c5b30 call 7ffde65cf4b0 ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ 1597 7ffde65c5b36-7ffde65c5bdf ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ call 7ffde65cf4b0 ??0QMessageLogger@@QEAA@PEBDH00@Z ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ ??6QDebug@@QEAAAEAV0@PEBD@Z ??6@YA?AVQDebug@@V0@PEBVQPlatformSurface@@@Z ??6@YA?AVQDebug@@V0@PEBVQWindow@@@Z ??6QDebug@@QEAAAEAV0@PEBX@Z ??1QDebug@@QEAA@XZ * 2 1594->1597 1598 7ffde65c5be5-7ffde65c5bea 1594->1598 1597->1598 1599 7ffde65c5f5b-7ffde65c5f67 1598->1599 1600 7ffde65c5bf0-7ffde65c5c40 ?topLevelWindows@QGuiApplication@@SA?AV?$QList@PEAVQWindow@@@@XZ 1598->1600 1603 7ffde65c5df8-7ffde65c5e05 1600->1603 1604 7ffde65c5c46-7ffde65c5c4b 1600->1604 1606 7ffde65c5e07-7ffde65c5e11 1603->1606 1607 7ffde65c5e23-7ffde65c5e2d 1603->1607 1605 7ffde65c5c50-7ffde65c5c6b ?transientParent@QWindow@@QEBAPEAV1@XZ ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ 1604->1605 1611 7ffde65c5ddf-7ffde65c5de6 1605->1611 1612 7ffde65c5c71-7ffde65c5c74 1605->1612 1608 7ffde65c5e3f 1606->1608 1609 7ffde65c5e13-7ffde65c5e18 1606->1609 1607->1608 1610 7ffde65c5e2f-7ffde65c5e34 1607->1610 1615 7ffde65c5e42-7ffde65c5e58 ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ 1608->1615 1609->1608 1613 7ffde65c5e1a-7ffde65c5e21 1609->1613 1610->1608 1614 7ffde65c5e36-7ffde65c5e3d 1610->1614 1611->1605 1617 7ffde65c5dec-7ffde65c5df3 1611->1617 1612->1611 1616 7ffde65c5c7a-7ffde65c5c86 ?mimeData@QDrag@@QEBAPEAVQMimeData@@XZ 1612->1616 1613->1615 1614->1615 1618 7ffde65c5e5a-7ffde65c5e60 1615->1618 1619 7ffde65c5ea3-7ffde65c5ead GetCapture 1615->1619 1616->1611 1620 7ffde65c5c8c-7ffde65c5c98 ?type@QWindow@@QEBA?AW4WindowType@Qt@@XZ 1616->1620 1617->1603 1621 7ffde65c5e79-7ffde65c5e87 1618->1621 1622 7ffde65c5e62-7ffde65c5e77 1618->1622 1624 7ffde65c5eaf-7ffde65c5eb7 1619->1624 1625 7ffde65c5ec4-7ffde65c5ed6 call 7ffde65c6050 1619->1625 1620->1611 1623 7ffde65c5c9e-7ffde65c5cbc ?mimeData@QDrag@@QEBAPEAVQMimeData@@XZ 1620->1623 1627 7ffde65c5e8e-7ffde65c5e91 1621->1627 1622->1627 1623->1611 1633 7ffde65c5cc2-7ffde65c5cd1 ?mimeData@QDrag@@QEBAPEAVQMimeData@@XZ 1623->1633 1624->1625 1631 7ffde65c5ed8-7ffde65c5ee3 call 7ffde65ce110 1625->1631 1632 7ffde65c5f00-7ffde65c5f11 DestroyWindow call 7ffde65d1910 1625->1632 1627->1619 1630 7ffde65c5e93-7ffde65c5e9c 1627->1630 1630->1619 1634 7ffde65c5e9e call 7ffde66c57f4 1630->1634 1642 7ffde65c5ee5-7ffde65c5eec 1631->1642 1643 7ffde65c5ef9 1631->1643 1640 7ffde65c5f16-7ffde65c5f36 1632->1640 1633->1611 1637 7ffde65c5cd7-7ffde65c5cec ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ ?type@QWindow@@QEBA?AW4WindowType@Qt@@XZ 1633->1637 1634->1619 1637->1611 1641 7ffde65c5cf2-7ffde65c5d1e GetWindow ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ ?transientParent@QWindow@@QEBAPEAV1@XZ 1637->1641 1644 7ffde65c5f38-7ffde65c5f3a 1640->1644 1645 7ffde65c5f4d-7ffde65c5f55 ?dispose@QListData@@SAXPEAUData@1@@Z 1640->1645 1646 7ffde65c5dc8-7ffde65c5dcb 1641->1646 1647 7ffde65c5d24-7ffde65c5d30 ?mimeData@QDrag@@QEBAPEAVQMimeData@@XZ 1641->1647 1642->1643 1643->1632 1644->1599 1649 7ffde65c5f3c-7ffde65c5f4b 1644->1649 1645->1599 1646->1611 1648 7ffde65c5dcd-7ffde65c5dd9 SetWindowLongPtrW 1646->1648 1647->1646 1650 7ffde65c5d36-7ffde65c5d42 ?type@QWindow@@QEBA?AW4WindowType@Qt@@XZ 1647->1650 1648->1611 1649->1599 1649->1645 1650->1646 1651 7ffde65c5d48-7ffde65c5d69 ?mimeData@QDrag@@QEBAPEAVQMimeData@@XZ 1650->1651 1651->1646 1653 7ffde65c5d6b-7ffde65c5d7a ?mimeData@QDrag@@QEBAPEAVQMimeData@@XZ 1651->1653 1653->1646 1654 7ffde65c5d7c-7ffde65c5d85 1653->1654 1654->1646 1655 7ffde65c5d87-7ffde65c5da0 1654->1655 1655->1646 1657 7ffde65c5da2-7ffde65c5db5 GetWindowLongPtrW 1655->1657 1657->1646 1658 7ffde65c5db7-7ffde65c5dc6 GetParent 1657->1658 1658->1646 1658->1657
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Window@@$Data@@Debug@@Window$?mimeData@Drag@@MimePlatform$?window@$?type@Qt@@Type@$??6@?transientCategory@@Logger@@LoggingLongMessageParent@$?debug@?dispose@?topApplication@@CaptureData@1@@DebugDestroyEnabled@H00@Init_thread_footerLevelListList@ParentSurface@@@Window@@@Window@@@@Windows@
                                                      • String ID: QWindowsWindow::destroyWindow
                                                      • API String ID: 2481748728-853541204
                                                      • Opcode ID: f9ec3c7c14b1efb65dd5b33bc9f0c26a0185703f721fd457a426b24adc3078b5
                                                      • Instruction ID: f3afde3c7391266121eea2e065de00943f63bd548894ed5a19dc1730e5c495c7
                                                      • Opcode Fuzzy Hash: f9ec3c7c14b1efb65dd5b33bc9f0c26a0185703f721fd457a426b24adc3078b5
                                                      • Instruction Fuzzy Hash: 13C15921B29F8285EB69AB55E86837923A1FF84F80F484179CE0E477A5DF3CE455C702

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1659 7ffde65ccbd0-7ffde65ccc2a call 7ffde66c5438 call 7ffde65d02e0 ?qgetenv@@YA?AVQByteArray@@PEBD@Z 1664 7ffde65ccc59-7ffde65ccd99 ??1?$QVector@VQPointF@@@@QEAA@XZ ??0QInternalMimeData@@QEAA@XZ ?qAddPostRoutine@@YAXP6AXXZ@Z ??0QPlatformDrag@@QEAA@XZ ??0QInternalMimeData@@QEAA@XZ ??0QUrl@@QEAA@XZ ??0QPlatformAccessibility@@QEAA@XZ ??0QPlatformServices@@QEAA@XZ ?qRegisterResourceData@@YA_NHPEBE00@Z call 7ffde65cc370 1659->1664 1665 7ffde65ccc2c-7ffde65ccc53 ?fromLocal8Bit@QString@@SA?AV1@AEBVQByteArray@@@Z ?setFilterRules@QLoggingCategory@@SAXAEBVQString@@@Z ??1?$QVector@VQPointF@@@@QEAA@XZ 1659->1665 1668 7ffde65ccd9f-7ffde65ccdb5 ?current@QOperatingSystemVersion@@SA?AV1@XZ 1664->1668 1669 7ffde65cce40-7ffde65cce52 call 7ffde6612db0 1664->1669 1665->1664 1671 7ffde65ccdc7-7ffde65ccdcf 1668->1671 1672 7ffde65ccdb7-7ffde65ccdc5 ?compare@QOperatingSystemVersion@@CAHAEBV1@0@Z 1668->1672 1676 7ffde65cce54-7ffde65cce5e 1669->1676 1677 7ffde65cce90-7ffde65cce99 1669->1677 1671->1669 1673 7ffde65ccdd1-7ffde65ccdd9 1671->1673 1672->1669 1672->1671 1673->1669 1675 7ffde65ccddb-7ffde65ccde3 1673->1675 1675->1669 1678 7ffde65ccde5-7ffde65ccded 1675->1678 1676->1677 1681 7ffde65cce60-7ffde65cce8b DestroyWindow call 7ffde66149f0 call 7ffde66c57fc 1676->1681 1679 7ffde65cce9b-7ffde65ccea8 1677->1679 1680 7ffde65ccead-7ffde65cceb4 1677->1680 1678->1669 1682 7ffde65ccdef-7ffde65ccdf7 1678->1682 1679->1680 1683 7ffde65cceaa 1679->1683 1684 7ffde65cceba-7ffde65ccec7 ?testAttribute@QCoreApplication@@SA_NW4ApplicationAttribute@Qt@@@Z 1680->1684 1685 7ffde65ccfa8-7ffde65ccfdc call 7ffde65d0ac0 ?setCapability@QPlatformCursor@@SAXW4Capability@1@@Z call 7ffde65d0d90 1680->1685 1681->1677 1682->1669 1687 7ffde65ccdf9-7ffde65cce01 1682->1687 1683->1680 1689 7ffde65ccfa1 1684->1689 1690 7ffde65ccecd-7ffde65cced6 call 7ffde65d0f20 1684->1690 1687->1669 1692 7ffde65cce03-7ffde65cce0b 1687->1692 1689->1685 1698 7ffde65ccedb-7ffde65cceeb call 7ffde65cf4b0 ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ 1690->1698 1692->1669 1696 7ffde65cce0d-7ffde65cce15 1692->1696 1696->1669 1700 7ffde65cce17-7ffde65cce1f 1696->1700 1698->1689 1706 7ffde65ccef1-7ffde65ccf6b call 7ffde65cf4b0 ??0QMessageLogger@@QEAA@PEBDH00@Z ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ ??6QDebug@@QEAAAEAV0@PEBD@Z * 2 ??6QDebug@@QEAAAEAV0@H@Z ??6QDebug@@QEAAAEAV0@PEBD@Z 1698->1706 1700->1669 1703 7ffde65cce21-7ffde65cce29 1700->1703 1703->1669 1705 7ffde65cce2b-7ffde65cce3e ?setAttribute@QCoreApplication@@SAXW4ApplicationAttribute@Qt@@_N@Z 1703->1705 1705->1680 1709 7ffde65ccf88-7ffde65ccf9b ??6QDebug@@QEAAAEAV0@H@Z ??1QDebug@@QEAA@XZ 1706->1709 1710 7ffde65ccf6d-7ffde65ccf7f 1706->1710 1709->1689 1710->1709 1712 7ffde65ccf81 1710->1712 1712->1709
                                                      APIs
                                                        • Part of subcall function 00007FFDE66C5438: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,00007FFDE6601D3E,?,?,?,00007FFDE6601FED), ref: 00007FFDE66C5452
                                                        • Part of subcall function 00007FFDE65D02E0: ??0QLocale@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65CCC00), ref: 00007FFDE65D0320
                                                        • Part of subcall function 00007FFDE65D02E0: memset.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65CCC00), ref: 00007FFDE65D0343
                                                        • Part of subcall function 00007FFDE65D02E0: ?connectImpl@QObject@@CA?AVConnection@QMetaObject@@PEBV1@PEAPEAX01PEAVQSlotObjectBase@QtPrivate@@W4ConnectionType@Qt@@PEBHPEBU3@@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65CCC00), ref: 00007FFDE65D03BA
                                                        • Part of subcall function 00007FFDE65D02E0: ??1Connection@QMetaObject@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDE65CCC00), ref: 00007FFDE65D03C8
                                                        • Part of subcall function 00007FFDE65D02E0: OleInitializeWOW.OLE32 ref: 00007FFDE65D04C0
                                                      • ?qgetenv@@YA?AVQByteArray@@PEBD@Z.QT5CORE ref: 00007FFDE65CCC19
                                                      • ?fromLocal8Bit@QString@@SA?AV1@AEBVQByteArray@@@Z.QT5CORE ref: 00007FFDE65CCC3C
                                                      • ?setFilterRules@QLoggingCategory@@SAXAEBVQString@@@Z.QT5CORE ref: 00007FFDE65CCC45
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65CCC53
                                                        • Part of subcall function 00007FFDE6612DB0: ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE6612E24
                                                        • Part of subcall function 00007FFDE6612DB0: ?isWarningEnabled@QLoggingCategory@@QEBA_NXZ.QT5CORE ref: 00007FFDE6612E37
                                                        • Part of subcall function 00007FFDE6612DB0: ??0QMessageLogger@@QEAA@PEBDH00@Z.QT5CORE ref: 00007FFDE6612E5B
                                                        • Part of subcall function 00007FFDE6612DB0: ?warning@QMessageLogger@@QEBA?AVQDebug@@XZ.QT5CORE ref: 00007FFDE6612E69
                                                        • Part of subcall function 00007FFDE6612DB0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE6612E79
                                                        • Part of subcall function 00007FFDE6612DB0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE6612E89
                                                        • Part of subcall function 00007FFDE6612DB0: ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE6612E94
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65CCC61
                                                      • ??0QInternalMimeData@@QEAA@XZ.QT5GUI ref: 00007FFDE65CCC7D
                                                      • ?qAddPostRoutine@@YAXP6AXXZ@Z.QT5CORE ref: 00007FFDE65CCCAC
                                                      • ??0QPlatformDrag@@QEAA@XZ.QT5GUI ref: 00007FFDE65CCCB6
                                                      • ??0QInternalMimeData@@QEAA@XZ.QT5GUI ref: 00007FFDE65CCCCB
                                                      • ??0QUrl@@QEAA@XZ.QT5CORE ref: 00007FFDE65CCCEB
                                                      • ??0QPlatformAccessibility@@QEAA@XZ.QT5GUI ref: 00007FFDE65CCD06
                                                      • ??0QPlatformServices@@QEAA@XZ.QT5GUI ref: 00007FFDE65CCD21
                                                      • ?qRegisterResourceData@@YA_NHPEBE00@Z.QT5CORE ref: 00007FFDE65CCD4F
                                                      • ?current@QOperatingSystemVersion@@SA?AV1@XZ.QT5CORE ref: 00007FFDE65CCDAB
                                                      • ?compare@QOperatingSystemVersion@@CAHAEBV1@0@Z.QT5CORE ref: 00007FFDE65CCDBD
                                                      • ?setAttribute@QCoreApplication@@SAXW4ApplicationAttribute@Qt@@_N@Z.QT5CORE ref: 00007FFDE65CCE38
                                                      • DestroyWindow.USER32 ref: 00007FFDE65CCE74
                                                      • ?testAttribute@QCoreApplication@@SA_NW4ApplicationAttribute@Qt@@@Z.QT5CORE ref: 00007FFDE65CCEBF
                                                      • ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ.QT5CORE ref: 00007FFDE65CCEE3
                                                      • ??0QMessageLogger@@QEAA@PEBDH00@Z.QT5CORE ref: 00007FFDE65CCF0C
                                                      • ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ.QT5CORE ref: 00007FFDE65CCF1D
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE65CCF2D
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE65CCF3D
                                                      • ??6QDebug@@QEAAAEAV0@H@Z.QT5CORE ref: 00007FFDE65CCF48
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE65CCF58
                                                      • ??6QDebug@@QEAAAEAV0@H@Z.QT5CORE ref: 00007FFDE65CCF8D
                                                      • ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE65CCF9B
                                                      • ?setCapability@QPlatformCursor@@SAXW4Capability@1@@Z.QT5GUI ref: 00007FFDE65CCFB8
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$Attribute@Logger@@MessagePlatform$??1?$?setCategory@@Data@@F@@@@LoggingObject@@PointVector@$ApplicationApplication@@ByteConnection@CoreEnabled@H00@InternalMetaMimeOperatingSystemVersion@@$?compare@?connect?current@?debug@?from?qgetenv@@?test?warning@Accessibility@@Array@@Array@@@Base@Bit@Capability@Capability@1@@ConnectionCursor@@DebugDestroyDrag@@E00@FilterImpl@InitializeLocal8Locale@@ObjectPostPrivate@@Qt@@Qt@@@Qt@@_RegisterResourceRoutine@@Rules@Services@@SlotString@@String@@@Type@U3@@Url@@V1@0@WarningWindowmallocmemset
                                                      • String ID: DpiAwareness=$QT_QPA_VERBOSE$QWindowsIntegrationPrivate::QWindowsIntegrationPrivate$effective process DPI awareness=
                                                      • API String ID: 2654353571-3376649801
                                                      • Opcode ID: 53a7d202722e1f4e827775ec7df0d39a29b5d051c28286cf61a57e1e2f532180
                                                      • Instruction ID: 3429d9c0047aa078623f33c7d687988b74eb395c0b36df8897d4740814cbf667
                                                      • Opcode Fuzzy Hash: 53a7d202722e1f4e827775ec7df0d39a29b5d051c28286cf61a57e1e2f532180
                                                      • Instruction Fuzzy Hash: 40C14A71B38A8285EB29EF14E8787A937A1FF85B44F445079CA4D436A0DF3CE459CB42
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$Touch$Device@@$Stream@@TextV1@@$?setMetricsSystem$DeviceLogger@@Message$?debug@?type@Capabilities@CapabilityCategory@@DebugDevice@@@@@Enabled@Flag@Flags@H00@LoggingMaximumPoints@Type@Type@1@Type@1@@
                                                      • String ID: Digitizers:$Max touch points:$Ready:$Tablet PC:
                                                      • API String ID: 1074269435-3611611755
                                                      • Opcode ID: a487e41affbc0517bb561d97c4475e5cd3a506fbf4ab194feaa3a0303a426643
                                                      • Instruction ID: 3cae16902952f1957dbd59db402cdb549f2cf650f35ad035ae3f0541e3018b6d
                                                      • Opcode Fuzzy Hash: a487e41affbc0517bb561d97c4475e5cd3a506fbf4ab194feaa3a0303a426643
                                                      • Instruction Fuzzy Hash: B8412424B39E0282EB18AB65E87837927A1FF88B91F41507DDD4E03765DE3CE449CB42
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Window@@$Debug@@$Window$Platform$?window@Region@@$??6@Category@@Logger@@LoggingMessageSystemType@$??$handle?debug@?flags@?focus?parent@?type@Application@@CaptureDebugDefaultDelivery@Empty@Enabled@Event@ExposeFlags@H00@Init_thread_footerInterface@@Interface@@@LongQt@@Qt@@@@Region@@@ShowSurface@@@V0@_Window@Window@@@
                                                      • String ID: QWindowsWindow::setVisible
                                                      • API String ID: 299874392-973687656
                                                      • Opcode ID: 3fe14d6b875fc532aa956ff4120e1608ec133bf7f89f70051e515abe9e0a2125
                                                      • Instruction ID: 2e052b1affdea64052475dc322ec5e20df7ee2d95de4282ca3d56342d9a52cd8
                                                      • Opcode Fuzzy Hash: 3fe14d6b875fc532aa956ff4120e1608ec133bf7f89f70051e515abe9e0a2125
                                                      • Instruction Fuzzy Hash: C4514C21B28E5282EB29AF25E8643B963A1FF85F85F044179CE4E43765DF3CD549CB02
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@Pixmap@@$Platform$??8@Category@@Data@@HighInit_thread_footerLogger@@LoggingMessageString@@0@$??1?$?deallocate@?debug@?handle?updateAdded@ArrayCursor@@DebugDisplayE00@Enabled@EnumF@@@@H00@Interface@@MonitorsPointRegisterResourceScaling@Scaling@@ScreenScreen@@Screen@@_SystemU1@_Vector@Window
                                                      • String ID: New Monitor: $qt.qpa.windows
                                                      • API String ID: 35602243-3622556350
                                                      • Opcode ID: 97c01b6008a49ca163d0cbbfb90af77d7079cbd9985538dfdeee5f18d54ed639
                                                      • Instruction ID: 5cc69a82f0949a488a5afcce04cba1bde1f33bc74511ecd5ceeda17794f2b2ce
                                                      • Opcode Fuzzy Hash: 97c01b6008a49ca163d0cbbfb90af77d7079cbd9985538dfdeee5f18d54ed639
                                                      • Instruction Fuzzy Hash: 69E16032B28A82C2EB28DF15E4A03B97761FB85B54F448136DA5E037A5DF3CE456C702
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$Data@Window$?mimeData@@Drag@@Logger@@MessageMimeSystem$Window@@@$??$handle??6@?debug@Category@@DebugDefaultDelivery@Enabled@Event@H00@Interface@@Interface@@@LoggingWindow@@$?get?type@CaptureCountEnterExternalF@@1@LeaveObject@@@PointPointer@@Qt@@Ref@SharedType@U12@
                                                      • String ID: Entering window $Leaving window
                                                      • API String ID: 97815722-614860069
                                                      • Opcode ID: 68c442143b51326a934107e359a3effb56658d5ea6bac99b17da2281104ee1d5
                                                      • Instruction ID: 6f16e5e52549bceabd465d8a05f663559a46a4885b3f365b590fad2eda3ed663
                                                      • Opcode Fuzzy Hash: 68c442143b51326a934107e359a3effb56658d5ea6bac99b17da2281104ee1d5
                                                      • Instruction Fuzzy Hash: 99C15D32B29B8286EB6ADF65D96037A23A4EF85B88F044235CD0D57794DF3CE845C742
                                                      APIs
                                                      • ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FFDE65C607D
                                                      • ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ.QT5GUI(?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FFDE65C608E
                                                        • Part of subcall function 00007FFDE65CF660: ??0QLoggingCategory@@QEAA@PEBD@Z.QT5CORE(?,?,?,00007FFDE65C607A,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FFDE65CF6BC
                                                        • Part of subcall function 00007FFDE65CF660: _Init_thread_footer.LIBCMT ref: 00007FFDE65CF6D5
                                                      • ??0QMessageLogger@@QEAA@PEBDH00@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FFDE65C60B2
                                                      • ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FFDE65C60C3
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FFDE65C60D3
                                                      • ??6@YA?AVQDebug@@V0@PEBVQWindow@@@Z.QT5GUI(?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FFDE65C60F4
                                                      • ??6QDebug@@QEAAAEAV0@_N@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FFDE65C6101
                                                      • ??1QDebug@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FFDE65C610F
                                                      • ??1QDebug@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FFDE65C611D
                                                      • ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ.QT5GUI(?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FFDE65C613C
                                                      • ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FFDE65C6178
                                                      • ??0QMessageLogger@@QEAA@PEBDH00@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FFDE65C61A1
                                                      • ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FFDE65C61B2
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FFDE65C61C2
                                                      • ??6QDebug@@QEAAAEAV0@PEBX@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FFDE65C61CE
                                                      • ??6@YA?AVQDebug@@V0@PEBVQWindow@@@Z.QT5GUI(?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FFDE65C61EF
                                                      • ??1QDebug@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FFDE65C61FD
                                                      • ??1QDebug@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FFDE65C620B
                                                      • RegisterDragDrop.OLE32 ref: 00007FFDE65C621F
                                                      • CoLockObjectExternal.OLE32(?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FFDE65C6253
                                                      • RevokeDragDrop.OLE32 ref: 00007FFDE65C6271
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$Logger@@MessageWindow@@$Category@@Logging$??6@?debug@?window@DebugDragDropEnabled@H00@PlatformWindow@@@$ExternalInit_thread_footerLockObjectRegisterRevokeV0@_
                                                      • String ID: QWindowsOleDropTarget::QWindowsOleDropTarget$QWindowsWindow::setDropSiteEnabled
                                                      • API String ID: 3023581799-300198654
                                                      • Opcode ID: f4cb23b6391f5ea9583363adae2a4bf833a69666014dc58ff641cf5b99f1705c
                                                      • Instruction ID: ab7f7b7f8630ac2daa0878ae4c95b6c3e61f37a56d1895d5a894c5d8a68713c0
                                                      • Opcode Fuzzy Hash: f4cb23b6391f5ea9583363adae2a4bf833a69666014dc58ff641cf5b99f1705c
                                                      • Instruction Fuzzy Hash: E1513C35B28F4682DB18AF65E8643A97360FF88B95F44413ACA8E43764DF3CD459CB01
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$Logger@@Message$Category@@Logging$DebugEnabled@$??1?$?debug@?noquote@?warning@Array@@@ByteF@@@@H00@Init_thread_footerPointVector@
                                                      • String ID: ) failed: $, using $QWindowsContext::setProcessDpiAwareness$SetProcessDPIAware() failed$SetProcessDpiAwareness(
                                                      • API String ID: 1975971543-2330795746
                                                      • Opcode ID: 29e9f17026c7702030dc27f07677852490ae8c0de69f46286ef1ed0daa52dd3e
                                                      • Instruction ID: e5f91ac5ceb4e03cf1d9041de4860d84b7081465d5b54ccc2b3f9fddf4e85de2
                                                      • Opcode Fuzzy Hash: 29e9f17026c7702030dc27f07677852490ae8c0de69f46286ef1ed0daa52dd3e
                                                      • Instruction Fuzzy Hash: B7514121B38E8382EA19AB15E87837A27E1EF84B95F04517DD90E437A4DF3CE445CB42
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Latin1String@@String@@@$Variant@@$??1?$?flags@?property@Array@@Bool@BrushByteColorF@@@@Flags@Object@@PointQt@@@@Type@V0@@Vector@WindowWindow@@
                                                      • String ID: DropShadow$Icon$OwnDC$Popup$QWindow$SaveBits$Tool$ToolTip$_q_windowsDropShadow
                                                      • API String ID: 2308565342-930079803
                                                      • Opcode ID: 3f8d73a7cddca88ae164e8c42ecc7ab7831e02db0c6f630ed5dd32d3c4d23ecd
                                                      • Instruction ID: 5405643477bd721bd3643e0835435659d77e961bfa225f21bcc1b840be341149
                                                      • Opcode Fuzzy Hash: 3f8d73a7cddca88ae164e8c42ecc7ab7831e02db0c6f630ed5dd32d3c4d23ecd
                                                      • Instruction Fuzzy Hash: F2819E32B24B4299F7299F65D8A43BD3771FB44358F40093ADE5C52AA8EF78D288C741
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@File@@$Key@@Registry$??1?$Category@@F@@@@Logger@@LoggingMessagePointStringString@@@Vector@$?dispose@?open@?read?string?warning@All@Array@@ByteData@1@@Data@@Device@@Device@@@@@Enabled@Flag@Flags@H00@Init_thread_footerListModeOpenString@@Value@View@@View@@@WarningY__@@
                                                      • String ID: EUDC\1252$SystemDefaultEUDCFont$Unable to open default EUDC font:
                                                      • API String ID: 2527835536-3770364387
                                                      • Opcode ID: f2b33f2aa260a144ffcc5550cec3ecebb04d4883fef2f5b270babbb5c1beb178
                                                      • Instruction ID: 17281845773073718b3edfc13f7c6144c396775c5d2de7532fbb629e4741b44e
                                                      • Opcode Fuzzy Hash: f2b33f2aa260a144ffcc5550cec3ecebb04d4883fef2f5b270babbb5c1beb178
                                                      • Instruction Fuzzy Hash: 8D517C32B35E4689EB249F24E8603EC3760FB54B59F40417ADA4E13AA8EF3CD549CB11
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$Window@@$?mimeData@Data@@Drag@@Mime$?focusApplication@@Category@@Logger@@LoggingMessagePlatform$??6@?debug@?input?type@?window@Accepted@AssociateContextContext@@DebugEnabled@H00@Init_thread_footerInputMethodObject@Object@@Qt@@Type@V0@_WindowWindow@Window@@@
                                                      • String ID: QWindowsInputContext::updateEnabled$accepted=
                                                      • API String ID: 1867459339-1051743838
                                                      • Opcode ID: 7f26bb50eeb0e31bfbb3766c7de56eb2cf8de8bdbc9e69aff0a67905e0988996
                                                      • Instruction ID: b784e9286a5ce2ebf97fe4d38fa392cf19183f971f39f1a27b3f41cf522eb5e3
                                                      • Opcode Fuzzy Hash: 7f26bb50eeb0e31bfbb3766c7de56eb2cf8de8bdbc9e69aff0a67905e0988996
                                                      • Instruction Fuzzy Hash: 90414B65B29E4282EF19AB56E87437963A0FF84B95F44507ACA4E03B64DE3CE449CB01
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Window$Window@@$Variant@@$Flags@Qt@@@@$?windowLongPlacementState@States@Type@$?flags@?property@?type@?window@Bool@Level@Object@@PlatformQt@@ShowVisible
                                                      • String ID: ,$_q_showWithoutActivating
                                                      • API String ID: 3956286184-3675458727
                                                      • Opcode ID: 55c3829bb877226a8834f6eb5a45c9250e74c9f0932cc530f2f1ed5e9e151777
                                                      • Instruction ID: 8432eb0461290a2bd11f26f343138a33e1c7778b6cc9f0139938952e00c21789
                                                      • Opcode Fuzzy Hash: 55c3829bb877226a8834f6eb5a45c9250e74c9f0932cc530f2f1ed5e9e151777
                                                      • Instruction Fuzzy Hash: 9661A022B28A4286EB19EF25E46437A77A0FF84B94F444179DE4E437A8DF3CD449CB01
                                                      APIs
                                                        • Part of subcall function 00007FFDE65C4160: GetWindowPlacement.USER32 ref: 00007FFDE65C41CD
                                                        • Part of subcall function 00007FFDE65C4160: ??0QRect@@QEAA@AEBVQPoint@@AEBVQSize@@@Z.QT5CORE ref: 00007FFDE65C4201
                                                        • Part of subcall function 00007FFDE65C4160: ?translated@QRect@@QEBA?AV1@AEBVQPoint@@@Z.QT5CORE ref: 00007FFDE65C422D
                                                      • ?marginsRemoved@QRect@@QEBA?AV1@AEBVQMargins@@@Z.QT5CORE ref: 00007FFDE65C8037
                                                      • ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ.QT5GUI ref: 00007FFDE65C8089
                                                      • ??$handleGeometryChange@UDefaultDelivery@QWindowSystemInterface@@@QWindowSystemInterface@@SAXPEAVQWindow@@AEBVQRect@@@Z.QT5GUI ref: 00007FFDE65C8096
                                                      • ?size@QRect@@QEBA?AVQSize@@XZ.QT5CORE ref: 00007FFDE65C80CA
                                                      • ?flushWindowSystemEvents@QWindowSystemInterface@@SA_NV?$QFlags@W4ProcessEventsFlag@QEventLoop@@@@@Z.QT5GUI ref: 00007FFDE65C8131
                                                      • ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ.QT5CORE ref: 00007FFDE65C814A
                                                      • ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ.QT5GUI ref: 00007FFDE65C815B
                                                      • ??0QMessageLogger@@QEAA@PEBDH00@Z.QT5CORE ref: 00007FFDE65C817F
                                                      • ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ.QT5CORE ref: 00007FFDE65C8190
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE65C81A0
                                                      • ??6@YA?AVQDebug@@V0@PEBVQPlatformSurface@@@Z.QT5GUI ref: 00007FFDE65C81C7
                                                      • ??6@YA?AVQDebug@@V0@PEBVQWindow@@@Z.QT5GUI ref: 00007FFDE65C81D8
                                                      • ??6@YA?AVQDebug@@V0@AEBVQRect@@@Z.QT5CORE ref: 00007FFDE65C81ED
                                                      • ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE65C81FB
                                                      • ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE65C8209
                                                        • Part of subcall function 00007FFDE65D6C50: MonitorFromWindow.USER32 ref: 00007FFDE65D6C61
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$Window$Window@@$Rect@@System$??6@Platform$?window@Interface@@Logger@@MessageRect@@@$??$handle?debug@?flush?margins?size@?translated@Category@@Change@DebugDefaultDelivery@Enabled@EventEventsEvents@Flag@Flags@FromGeometryH00@Interface@@@LoggingLoop@@@@@Margins@@@MonitorPlacementPoint@@Point@@@ProcessRemoved@Size@@Size@@@Surface@@@Window@@@
                                                      • String ID: QWindowsWindow::handleGeometryChange
                                                      • API String ID: 2383832787-3577234724
                                                      • Opcode ID: 15a6849af679a4ed72dcb1b21ab528cb07b5c7203412826a7ab901c8fed3864f
                                                      • Instruction ID: c70bcd8c20e782eb1ebfe26331e978abdebcd919dfe8e26680c378b030bd1e6d
                                                      • Opcode Fuzzy Hash: 15a6849af679a4ed72dcb1b21ab528cb07b5c7203412826a7ab901c8fed3864f
                                                      • Instruction Fuzzy Hash: 88519332B28A4687DB19EB29E9A43B977A1FB84B94F008135CB4E07B55DF3CE455CB01
                                                      APIs
                                                      • ??4QUrl@@QEAAAEAV0@$$QEAV0@@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65C23E2), ref: 00007FFDE65C62E8
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65C23E2), ref: 00007FFDE65C62F3
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65C23E2), ref: 00007FFDE65C62FE
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65C23E2), ref: 00007FFDE65C6309
                                                      • ?screen@QWindow@@QEBAPEAVQScreen@@XZ.QT5GUI(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65C23E2), ref: 00007FFDE65C6343
                                                      • ?primaryScreen@QGuiApplication@@SAPEAVQScreen@@XZ.QT5GUI(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65C23E2), ref: 00007FFDE65C634B
                                                      • ?name@QScreen@@QEBA?AVQString@@XZ.QT5GUI(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65C23E2), ref: 00007FFDE65C6364
                                                      • ??8@YA_NAEBVQString@@0@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65C23E2), ref: 00007FFDE65C6379
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65C23E2), ref: 00007FFDE65C6398
                                                      • ?virtualSiblings@QScreen@@QEBA?AV?$QList@PEAVQScreen@@@@XZ.QT5GUI(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65C23E2), ref: 00007FFDE65C63BC
                                                      • ?name@QScreen@@QEBA?AVQString@@XZ.QT5GUI(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65C23E2), ref: 00007FFDE65C63FE
                                                      • ??8@YA_NAEBVQString@@0@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65C23E2), ref: 00007FFDE65C640E
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65C23E2), ref: 00007FFDE65C641F
                                                      • ?dispose@QListData@@SAXPEAUData@1@@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65C23E2), ref: 00007FFDE65C6464
                                                      • ?dispose@QListData@@SAXPEAUData@1@@Z.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65C23E2), ref: 00007FFDE65C64B4
                                                      • ??0?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE65C23E2), ref: 00007FFDE65C64DF
                                                      • _Init_thread_footer.LIBCMT ref: 00007FFDE65C64F8
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: F@@@@PointVector@$??1?$Screen@@$??8@?dispose@?name@Data@1@@Data@@ListString@@String@@0@$??0?$?primary?screen@?virtualApplication@@Init_thread_footerList@Screen@Screen@@@@Siblings@Url@@V0@$$V0@@Window@@
                                                      • String ID:
                                                      • API String ID: 590706928-0
                                                      • Opcode ID: bc2ff9afaa1d3f16acbcdf64aa2da471e775e1054ecf5704ff56e8e7039ba041
                                                      • Instruction ID: c541704a8d0c37bc0e0be6d4fb619620f3deed7a0fbf513dd6501b4dd17fbd11
                                                      • Opcode Fuzzy Hash: bc2ff9afaa1d3f16acbcdf64aa2da471e775e1054ecf5704ff56e8e7039ba041
                                                      • Instruction Fuzzy Hash: 8C617271B38E4285EB69AB14E8B03B97360FF85B65F844136D94E436A4DF3CE549CB02
                                                      APIs
                                                      • ?requested@QPlatformInputContextFactory@@SA?AVQString@@XZ.QT5GUI ref: 00007FFDE65CD084
                                                      • ?isNull@QString@@QEBA_NXZ.QT5CORE ref: 00007FFDE65CD092
                                                      • ??0QPlatformInputContext@@QEAA@XZ.QT5GUI ref: 00007FFDE65CD0BE
                                                      • RegisterWindowMessageW.USER32 ref: 00007FFDE65CD0D5
                                                      • ??0?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65CD0EE
                                                      • GetKeyboardLayout.USER32 ref: 00007FFDE65CD10A
                                                      • ?qt_localeFromLCID@@YA?AVQLocale@@K@Z.QT5CORE ref: 00007FFDE65CD11B
                                                      • CreateBitmap.GDI32 ref: 00007FFDE65CD145
                                                      • ?inputMethod@QGuiApplication@@SAPEAVQInputMethod@@XZ.QT5GUI ref: 00007FFDE65CD16A
                                                        • Part of subcall function 00007FFDE66C5438: Concurrency::cancel_current_task.LIBCPMT ref: 00007FFDE66C5468
                                                        • Part of subcall function 00007FFDE66C5438: Concurrency::cancel_current_task.LIBCPMT ref: 00007FFDE66C546E
                                                      • ?connectImpl@QObject@@CA?AVConnection@QMetaObject@@PEBV1@PEAPEAX01PEAVQSlotObjectBase@QtPrivate@@W4ConnectionType@Qt@@PEBHPEBU3@@Z.QT5CORE ref: 00007FFDE65CD1CF
                                                      • ??1Connection@QMetaObject@@QEAA@XZ.QT5CORE ref: 00007FFDE65CD1DA
                                                      • ?create@QPlatformInputContextFactory@@SAPEAVQPlatformInputContext@@AEBVQString@@@Z.QT5GUI ref: 00007FFDE65CD207
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65CD23F
                                                        • Part of subcall function 00007FFDE66C5438: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,00007FFDE6601D3E,?,?,?,00007FFDE6601FED), ref: 00007FFDE66C5452
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Input$Platform$Object@@$Concurrency::cancel_current_taskConnection@ContextContext@@F@@@@Factory@@MetaPointString@@Vector@$??0?$??1?$?connect?create@?input?qt_locale?requested@Application@@Base@BitmapConnectionCreateFromImpl@KeyboardLayoutLocale@@MessageMethod@Method@@Null@ObjectPrivate@@Qt@@RegisterSlotString@@@Type@U3@@Windowmalloc
                                                      • String ID: MSIMEMouseOperation
                                                      • API String ID: 834861323-1919246749
                                                      • Opcode ID: d14bee79be3b54da6ecc9c7b67a086fb67261a1ff3653f572f248f0dbcb69393
                                                      • Instruction ID: 8fef9d9fefcc7b61ae10d6a9d00ddb0bb2002cd3aa760bb0fd34f5f1fbb6721c
                                                      • Opcode Fuzzy Hash: d14bee79be3b54da6ecc9c7b67a086fb67261a1ff3653f572f248f0dbcb69393
                                                      • Instruction Fuzzy Hash: A8516932728F828ADB28DF11E8647A9B7A4FB85B54F444179CA8E43B64DF3CD049CB01
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Window@@$??1?$F@@@@Logger@@MessagePlatformPointString@@Vector@Window$?const?move?qt_window_private@@?set?warning@?window@Array@@Bit@ByteChar@@Data@FeatureGeometry@Left@Local8Point@@@Private@@Rect@@Rect@@@ResourceVisibleWindow@@@Zlib@@
                                                      • String ID: %s: %s$QWindowsWindow::setGeometry
                                                      • API String ID: 1584011364-1033964765
                                                      • Opcode ID: 0a72b22dde17bf3ca4691bd3a13885ef9e1e99a23e9095114cb49f66678fe6da
                                                      • Instruction ID: b2c7a485159280052dba0892aebea23cf454e483ff1229100eba86b4c9bdaef9
                                                      • Opcode Fuzzy Hash: 0a72b22dde17bf3ca4691bd3a13885ef9e1e99a23e9095114cb49f66678fe6da
                                                      • Instruction Fuzzy Hash: 64416132B28A42C7EB589F24E46476977A0FB84B48F445139EB8E43A68DF3CE545CF01
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Rect@@$Screen@@$Point@@$?center@?contains@Point@@_$?handle@Platform$?dispose@?virtualData@1@@Data@@Level@ListList@Point@@0@Screen@@@@Siblings@Size@@@Window@@
                                                      • String ID:
                                                      • API String ID: 2129943404-0
                                                      • Opcode ID: 1d5a70235534111115fc52974c6be85a95d007c4bae8179dd3575cde60adb42d
                                                      • Instruction ID: 83facdda18bf02634b1e36233b34ae8bd2af10ed1aa4f76a3536c2c7b6e96617
                                                      • Opcode Fuzzy Hash: 1d5a70235534111115fc52974c6be85a95d007c4bae8179dd3575cde60adb42d
                                                      • Instruction Fuzzy Hash: 98C17E77B14A458BEB18DF78D4A46AC37B1F788B98B01452ADE0E57B58DF38E449CB00
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$Object$CreateErrnoLogger@@MessageSelectString@@Warning@@$??1?$?debug@?from?get@Array@Category@@CharChar@@CompatibleData@@DebugDeleteEnabled@F@@@@FontH00@IndirectInfoKey@@LoggingMetricsParametersPointRegistryReleaseStorageStringSystemTextThreadVector@View@@Y__@@
                                                      • String ID: FONTDEF$QWindowsFontDatabase::fontEngine
                                                      • API String ID: 13663010-296183570
                                                      • Opcode ID: 39ccdf7943e8c23ad195c5d156cec2f6fba55e6da56c914d99bc554e6909a980
                                                      • Instruction ID: 3feef621c595843050ae505aed102b92cf58bfdf8b5a45e64e682b8ec1ed39e6
                                                      • Opcode Fuzzy Hash: 39ccdf7943e8c23ad195c5d156cec2f6fba55e6da56c914d99bc554e6909a980
                                                      • Instruction Fuzzy Hash: 0F318031B38A8282DA58AF12E8307B97760FB84F94F048079DE8E47765DE3CD849CB41
                                                      APIs
                                                      • ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ.QT5CORE ref: 00007FFDE660C606
                                                      • ??0QMessageLogger@@QEAA@PEBDH00@Z.QT5CORE ref: 00007FFDE660C62F
                                                      • ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ.QT5CORE ref: 00007FFDE660C640
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE660C650
                                                      • ??6QDebug@@QEAAAEAV0@D@Z.QT5CORE ref: 00007FFDE660C65B
                                                      • ??6QDebug@@QEAAAEAV0@AEBVQString@@@Z.QT5CORE ref: 00007FFDE660C667
                                                      • ??6QDebug@@QEAAAEAV0@D@Z.QT5CORE ref: 00007FFDE660C672
                                                        • Part of subcall function 00007FFDE660D6C0: ??0QDebugStateSaver@@QEAA@AEAVQDebug@@@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D6D6
                                                        • Part of subcall function 00007FFDE660D6C0: ?noquote@QDebug@@QEAAAEAV1@XZ.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D6E6
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D6F6
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBX@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D728
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D738
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@AEBVQString@@@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D745
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D755
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBX@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D762
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D772
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBX@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D77F
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D78F
                                                        • Part of subcall function 00007FFDE660D6C0: ??0QDebugStateSaver@@QEAA@AEAVQDebug@@@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D7AA
                                                        • Part of subcall function 00007FFDE660D6C0: ?noquote@QDebug@@QEAAAEAV1@XZ.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D7BE
                                                        • Part of subcall function 00007FFDE660D6C0: ?className@QMetaObject@@QEBAPEBDXZ.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D7DB
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D7E9
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@D@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D7F4
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@D@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D80E
                                                        • Part of subcall function 00007FFDE660D6C0: ??0QDebug@@QEAA@$$QEAV0@@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D832
                                                        • Part of subcall function 00007FFDE660D6C0: ??1QDebugStateSaver@@QEAA@XZ.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D83D
                                                        • Part of subcall function 00007FFDE660D6C0: ??1QDebug@@QEAA@XZ.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D848
                                                        • Part of subcall function 00007FFDE660D6C0: ??1QDebug@@QEAA@XZ.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D853
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@D@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D870
                                                        • Part of subcall function 00007FFDE660D6C0: ??0QDebug@@QEAA@$$QEAV0@@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D87C
                                                      • ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE660C6A0
                                                      • ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE660C6AE
                                                      • ??8@YA_NAEBVQString@@0@Z.QT5CORE ref: 00007FFDE660C6BB
                                                      • ??4QByteArray@@QEAAAEAV0@AEBV0@@Z.QT5CORE ref: 00007FFDE660C6CC
                                                        • Part of subcall function 00007FFDE65CF9C0: ??0QLoggingCategory@@QEAA@PEBD@Z.QT5CORE ref: 00007FFDE65CFA1C
                                                        • Part of subcall function 00007FFDE65CF9C0: _Init_thread_footer.LIBCMT ref: 00007FFDE65CFA35
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$Debug$Saver@@StateV0@@$?noquote@A@$$Category@@Debug@@@Logger@@LoggingMessageString@@@$??8@?class?debug@Array@@ByteEnabled@H00@Init_thread_footerMetaName@Object@@String@@0@
                                                      • String ID: QWindowsSystemTrayIcon::updateToolTip
                                                      • API String ID: 2288539016-921702367
                                                      • Opcode ID: f668d0110e864e64a4714212362d5f169c89c65d0570c8d203a314ff4f2744f8
                                                      • Instruction ID: ccb6813b17fa3816fe0d868a972d3fdb890e32145e29727a4deded705ceb096d
                                                      • Opcode Fuzzy Hash: f668d0110e864e64a4714212362d5f169c89c65d0570c8d203a314ff4f2744f8
                                                      • Instruction Fuzzy Hash: 4D219F21B38E4282EB68AF21E8643B92761EF95F94F41517DCD4E42665EE3CD889CB01
                                                      APIs
                                                        • Part of subcall function 00007FFDE65D1100: ??0QTextStream@@QEAA@PEAVQString@@V?$QFlags@W4OpenModeFlag@QIODevice@@@@@Z.QT5CORE(?,?,?,?,?,00007FFDE65D12F8), ref: 00007FFDE65D1150
                                                        • Part of subcall function 00007FFDE65D1100: ??6QTextStream@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,00007FFDE65D12F8), ref: 00007FFDE65D1162
                                                        • Part of subcall function 00007FFDE65D1100: ??6QTextStream@@QEAAAEAV0@H@Z.QT5CORE(?,?,?,?,?,00007FFDE65D12F8), ref: 00007FFDE65D1170
                                                        • Part of subcall function 00007FFDE65D1100: ??6QTextStream@@QEAAAEAV0@H@Z.QT5CORE(?,?,?,?,?,00007FFDE65D12F8), ref: 00007FFDE65D117E
                                                        • Part of subcall function 00007FFDE65D1100: ??6QTextStream@@QEAAAEAV0@H@Z.QT5CORE(?,?,?,?,?,00007FFDE65D12F8), ref: 00007FFDE65D118C
                                                        • Part of subcall function 00007FFDE65D1100: ?qResourceFeatureZlib@@YAEXZ.QT5CORE(?,?,?,?,?,00007FFDE65D12F8), ref: 00007FFDE65D1192
                                                        • Part of subcall function 00007FFDE65D1100: ??6QTextStream@@QEAAAEAV0@D@Z.QT5CORE(?,?,?,?,?,00007FFDE65D12F8), ref: 00007FFDE65D11A3
                                                        • Part of subcall function 00007FFDE65D1100: ??1QTextStream@@UEAA@XZ.QT5CORE(?,?,?,?,?,00007FFDE65D12F8), ref: 00007FFDE65D11AE
                                                        • Part of subcall function 00007FFDE65D1100: ??0QByteArray@@QEAA@AEBV0@@Z.QT5CORE(?,?,?,?,?,00007FFDE65D12F8), ref: 00007FFDE65D11BE
                                                      • ??0QByteArray@@QEAA@AEBV0@@Z.QT5CORE ref: 00007FFDE65D0DD0
                                                      • ??YQString@@QEAAAEAV0@AEBV0@@Z.QT5CORE ref: 00007FFDE65D0DE6
                                                        • Part of subcall function 00007FFDE65D14C0: GetModuleHandleW.KERNEL32 ref: 00007FFDE65D1518
                                                        • Part of subcall function 00007FFDE65D14C0: ?utf16@QString@@QEBAPEBGXZ.QT5CORE ref: 00007FFDE65D1524
                                                        • Part of subcall function 00007FFDE65D14C0: GetClassInfoW.USER32 ref: 00007FFDE65D1534
                                                        • Part of subcall function 00007FFDE65D14C0: ?createUuid@QUuid@@SA?AV1@XZ.QT5CORE ref: 00007FFDE65D1548
                                                        • Part of subcall function 00007FFDE65D14C0: ?toString@QUuid@@QEBA?AVQString@@XZ.QT5CORE ref: 00007FFDE65D1556
                                                        • Part of subcall function 00007FFDE65D14C0: ??YQString@@QEAAAEAV0@AEBV0@@Z.QT5CORE ref: 00007FFDE65D1562
                                                        • Part of subcall function 00007FFDE65D14C0: ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65D156D
                                                        • Part of subcall function 00007FFDE65D14C0: ?qHash@@YAIAEBVQString@@I@Z.QT5CORE ref: 00007FFDE65D1589
                                                        • Part of subcall function 00007FFDE65D14C0: LoadImageW.USER32 ref: 00007FFDE65D1604
                                                        • Part of subcall function 00007FFDE65D14C0: GetSystemMetrics.USER32 ref: 00007FFDE65D1618
                                                        • Part of subcall function 00007FFDE65D14C0: GetSystemMetrics.USER32 ref: 00007FFDE65D1624
                                                        • Part of subcall function 00007FFDE65D14C0: LoadImageW.USER32 ref: 00007FFDE65D1644
                                                        • Part of subcall function 00007FFDE65D14C0: ?utf16@QString@@QEBAPEBGXZ.QT5CORE ref: 00007FFDE65D1688
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65D0E23
                                                      • GetModuleHandleW.KERNEL32 ref: 00007FFDE65D0E2B
                                                      • ?utf16@QString@@QEBAPEBGXZ.QT5CORE ref: 00007FFDE65D0E3C
                                                      • CreateWindowExW.USER32 ref: 00007FFDE65D0E89
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65D0E9A
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65D0EB2
                                                      • RegisterPowerSettingNotification.USER32 ref: 00007FFDE65D0ED6
                                                      • DestroyWindow.USER32 ref: 00007FFDE65D0EF9
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: String@@$Stream@@Text$??1?$F@@@@PointV0@@Vector@$?utf16@$Array@@ByteHandleImageLoadMetricsModuleSystemUuid@@Window$?createClassCreateDestroyDevice@@@@@FeatureFlag@Flags@Hash@@InfoModeNotificationOpenPowerRegisterResourceSettingString@Uuid@Zlib@@
                                                      • String ID: QtPowerDummyWindow
                                                      • API String ID: 765717870-1433576009
                                                      • Opcode ID: 1b86cfdd4ea8fc488075c99b58a5f5e4bb184f7cd9a8758934c8039833179add
                                                      • Instruction ID: 73c8183073e8f8f83166c5fb15e5bb668f511ad4cd29a08a74793b046059f057
                                                      • Opcode Fuzzy Hash: 1b86cfdd4ea8fc488075c99b58a5f5e4bb184f7cd9a8758934c8039833179add
                                                      • Instruction Fuzzy Hash: 1A414D36728B8282DB64DF14F8683AA7760FB84B94F50413ADA8D47BA4DF3CC559CB41
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: System$Key@@OperatingRegistryVersion@@$String$?compare@?current@?dwordInfoPair@ParametersType@0@V1@0@Value@View@@View@@@Y__@@
                                                      • String ID: <$AppsUseLightTheme$Software\Microsoft\Windows\CurrentVersion\Themes\Personalize$cE
                                                      • API String ID: 3870276128-341702153
                                                      • Opcode ID: 53f0231c730d678290bfc8282b40ed0f96ee9cc6bc4180897020430dd8f6cd2b
                                                      • Instruction ID: 017c3cbd3e4444b041ac5e0413745dd098f78a00cf194dac0cadb99984550850
                                                      • Opcode Fuzzy Hash: 53f0231c730d678290bfc8282b40ed0f96ee9cc6bc4180897020430dd8f6cd2b
                                                      • Instruction Fuzzy Hash: 7631A172B38B8682EB558F10F4647AAB760FBD4744F401139EA8D03A98DF3CE148CB01
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$Surface$Category@@Format@@Logger@@LoggingMessage$??6@?debug@?format@Context@@DebugEnabled@Format@@@H00@Init_thread_footerOpen
                                                      • String ID: QWindowsIntegration::createPlatformOpenGLContext
                                                      • API String ID: 392674411-2509909389
                                                      • Opcode ID: 47f31358bceabb229ac8f79140d073ac9c7896eb0086c6c5e54f0ef9adfc98f5
                                                      • Instruction ID: cd318455596ff9ba6dff41d10da59a578481d7086fa63ba325f1706580c9ce54
                                                      • Opcode Fuzzy Hash: 47f31358bceabb229ac8f79140d073ac9c7896eb0086c6c5e54f0ef9adfc98f5
                                                      • Instruction Fuzzy Hash: A8314D32B28B4683DB559F29E8643A973A0FF88F94F449035DA4E47768DE3CD449CB02
                                                      APIs
                                                      • ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ.QT5CORE ref: 00007FFDE660C096
                                                      • ??0QMessageLogger@@QEAA@PEBDH00@Z.QT5CORE ref: 00007FFDE660C0BB
                                                      • ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ.QT5CORE ref: 00007FFDE660C0C9
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE660C0D9
                                                        • Part of subcall function 00007FFDE660D6C0: ??0QDebugStateSaver@@QEAA@AEAVQDebug@@@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D6D6
                                                        • Part of subcall function 00007FFDE660D6C0: ?noquote@QDebug@@QEAAAEAV1@XZ.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D6E6
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D6F6
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBX@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D728
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D738
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@AEBVQString@@@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D745
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D755
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBX@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D762
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D772
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBX@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D77F
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D78F
                                                        • Part of subcall function 00007FFDE660D6C0: ??0QDebugStateSaver@@QEAA@AEAVQDebug@@@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D7AA
                                                        • Part of subcall function 00007FFDE660D6C0: ?noquote@QDebug@@QEAAAEAV1@XZ.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D7BE
                                                        • Part of subcall function 00007FFDE660D6C0: ?className@QMetaObject@@QEBAPEBDXZ.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D7DB
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D7E9
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@D@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D7F4
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@D@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D80E
                                                        • Part of subcall function 00007FFDE660D6C0: ??0QDebug@@QEAA@$$QEAV0@@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D832
                                                        • Part of subcall function 00007FFDE660D6C0: ??1QDebugStateSaver@@QEAA@XZ.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D83D
                                                        • Part of subcall function 00007FFDE660D6C0: ??1QDebug@@QEAA@XZ.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D848
                                                        • Part of subcall function 00007FFDE660D6C0: ??1QDebug@@QEAA@XZ.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D853
                                                        • Part of subcall function 00007FFDE660D6C0: ??6QDebug@@QEAAAEAV0@D@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D870
                                                        • Part of subcall function 00007FFDE660D6C0: ??0QDebug@@QEAA@$$QEAV0@@Z.QT5CORE(?,?,?,?,?,00007FFDE660BFD7), ref: 00007FFDE660D87C
                                                      • ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE660C101
                                                      • ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE660C10C
                                                      • memset.VCRUNTIME140 ref: 00007FFDE660C135
                                                      • memset.VCRUNTIME140 ref: 00007FFDE660C149
                                                      • Shell_NotifyIconW.SHELL32 ref: 00007FFDE660C1D5
                                                        • Part of subcall function 00007FFDE65CF9C0: ??0QLoggingCategory@@QEAA@PEBD@Z.QT5CORE ref: 00007FFDE65CFA1C
                                                        • Part of subcall function 00007FFDE65CF9C0: _Init_thread_footer.LIBCMT ref: 00007FFDE65CFA35
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$Debug$Saver@@State$?noquote@A@$$Category@@Debug@@@Logger@@LoggingMessageV0@@memset$?class?debug@Enabled@H00@IconInit_thread_footerMetaName@NotifyObject@@Shell_String@@@
                                                      • String ID: QWindowsSystemTrayIcon::init
                                                      • API String ID: 1063904315-3400831550
                                                      • Opcode ID: 39bf0a5bfba129b654e6ec174d7776f0a71c9f17177c2d571ec21d4c0546219b
                                                      • Instruction ID: d715fe7a2040de17d93298ac52b83e33a3313efb1b0f9b69ea00b19cddacc88b
                                                      • Opcode Fuzzy Hash: 39bf0a5bfba129b654e6ec174d7776f0a71c9f17177c2d571ec21d4c0546219b
                                                      • Instruction Fuzzy Hash: F3418232B28BC18AE734DF25D9543E937A4FB99748F40517ADA4D46A29EF38D284CB01
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: freemalloc$ErrnoWarning@@
                                                      • String ID: %s: GetGlyphRunOutline failed$QWindowsFontEngineDirectWrite::addGlyphsToPath
                                                      • API String ID: 113164508-412874508
                                                      • Opcode ID: 2d483151f7bc12be60c898ce39d26863d6fd8d94c2af3e32844eea0a64fa1c26
                                                      • Instruction ID: 7dee6cd03b22d6d0528c464210a22ea5b742184408d554ca4e3be602dbeed76a
                                                      • Opcode Fuzzy Hash: 2d483151f7bc12be60c898ce39d26863d6fd8d94c2af3e32844eea0a64fa1c26
                                                      • Instruction Fuzzy Hash: AC614A32A25FC58DE721CF31D8502E977A4FB99788F10422ADA4D57B28EF78D185CB01
                                                      APIs
                                                        • Part of subcall function 00007FFDE66283F0: RemoveFontMemResourceEx.GDI32(?,?,?,00007FFDE6625BF7), ref: 00007FFDE662843B
                                                        • Part of subcall function 00007FFDE66283F0: ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,?,00007FFDE6625BF7), ref: 00007FFDE66284D1
                                                        • Part of subcall function 00007FFDE66283F0: ?dispose@QListData@@SAXPEAUData@1@@Z.QT5CORE(?,?,?,00007FFDE6625BF7), ref: 00007FFDE66284EC
                                                        • Part of subcall function 00007FFDE66283F0: ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,?,00007FFDE6625BF7), ref: 00007FFDE6628541
                                                        • Part of subcall function 00007FFDE66283F0: ?dispose@QListData@@SAXPEAUData@1@@Z.QT5CORE(?,?,?,00007FFDE6625BF7), ref: 00007FFDE662855C
                                                      • GetDC.USER32 ref: 00007FFDE6625BF9
                                                      • EnumFontFamiliesExW.GDI32 ref: 00007FFDE6625C28
                                                      • ReleaseDC.USER32 ref: 00007FFDE6625C33
                                                        • Part of subcall function 00007FFDE6629E70: GetObjectW.GDI32 ref: 00007FFDE6629EA7
                                                        • Part of subcall function 00007FFDE6629E70: ?family@QFont@@QEBA?AVQString@@XZ.QT5GUI ref: 00007FFDE6629EC8
                                                        • Part of subcall function 00007FFDE6629E70: ??8QString@@QEBA_NVQLatin1String@@@Z.QT5CORE ref: 00007FFDE6629EF5
                                                        • Part of subcall function 00007FFDE6629E70: ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE6629F03
                                                        • Part of subcall function 00007FFDE6629E70: ?setFamily@QFont@@QEAAXAEBVQString@@@Z.QT5GUI ref: 00007FFDE6629F21
                                                        • Part of subcall function 00007FFDE6629E70: ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE6629F2C
                                                        • Part of subcall function 00007FFDE6629E70: ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ.QT5CORE ref: 00007FFDE6629F3A
                                                        • Part of subcall function 00007FFDE6629E70: ??0QMessageLogger@@QEAA@PEBDH00@Z.QT5CORE ref: 00007FFDE6629F5F
                                                        • Part of subcall function 00007FFDE6629E70: ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ.QT5CORE ref: 00007FFDE6629F6D
                                                        • Part of subcall function 00007FFDE6629E70: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE6629F7D
                                                        • Part of subcall function 00007FFDE6629E70: ??6@YA?AVQDebug@@V0@AEBVQFont@@@Z.QT5GUI ref: 00007FFDE6629F9B
                                                        • Part of subcall function 00007FFDE6629E70: ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE6629FA6
                                                        • Part of subcall function 00007FFDE6629E70: ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE6629FB1
                                                      • ?family@QFont@@QEBA?AVQString@@XZ.QT5GUI ref: 00007FFDE6625C4B
                                                      • ??1QFont@@QEAA@XZ.QT5GUI ref: 00007FFDE6625C56
                                                      • ?resolveFontFamilyAlias@QPlatformFontDatabase@@UEBA?AVQString@@AEBV2@@Z.QT5GUI ref: 00007FFDE6625C69
                                                      • ??8@YA_NAEBVQString@@0@Z.QT5CORE ref: 00007FFDE6625C77
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE6625C85
                                                      • ?registerFontFamily@QPlatformFontDatabase@@SAXAEBVQString@@@Z.QT5GUI ref: 00007FFDE6625C94
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE6625CA7
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: ??1?$F@@@@FontPointVector@$Debug@@$Font@@String@@$String@@@$?dispose@?family@Data@1@@Data@@Database@@Family@ListLogger@@MessagePlatform$??6@??8@?debug@?register?resolve?setAlias@Category@@DebugEnabled@EnumFamiliesFamilyFont@@@H00@Latin1LoggingObjectReleaseRemoveResourceString@@0@V2@@
                                                      • String ID:
                                                      • API String ID: 3532881911-0
                                                      • Opcode ID: 632596c564f5045559f57f6ed6f764fb79a41eae53109536be6fd8a7845392b9
                                                      • Instruction ID: 753231fcc3316818fe69a29adb4a488e38e17a508d2c91e164a579b4fad928d2
                                                      • Opcode Fuzzy Hash: 632596c564f5045559f57f6ed6f764fb79a41eae53109536be6fd8a7845392b9
                                                      • Instruction Fuzzy Hash: 43213021B39F8291EB58AF64F8643AA7760FF84B84F40117AE98E47655DF3CD108CB42
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Window$Rect@@$ClientLongPoint@@RectSize@@@$?translated@ParentPlacementPoint@@@Screen
                                                      • String ID:
                                                      • API String ID: 103376119-0
                                                      • Opcode ID: 5eb99d093ce5d77b1b9a4b4e683aaffc7253e4f5d47a4f6990f71f45710030c3
                                                      • Instruction ID: fd81191f648493a3a7ad002824614c4a192e733f6eea527655711791089257a1
                                                      • Opcode Fuzzy Hash: 5eb99d093ce5d77b1b9a4b4e683aaffc7253e4f5d47a4f6990f71f45710030c3
                                                      • Instruction Fuzzy Hash: A7511976F24A058EE718DFB9D4646EC37B1FB48788B404539DE0E63B58DE389509CB50
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: MetricsSystem$MessageSend$CursorDestroy
                                                      • String ID:
                                                      • API String ID: 1564967684-0
                                                      • Opcode ID: 38a828ed9fef737168efd9fbde9d9cf4b6a0d23438b3a4594ed2b2959f7eaffd
                                                      • Instruction ID: 5dae65ab5afeb0cfabd0327dd50e6456c0a33cfad771c5d2dcd240232474b493
                                                      • Opcode Fuzzy Hash: 38a828ed9fef737168efd9fbde9d9cf4b6a0d23438b3a4594ed2b2959f7eaffd
                                                      • Instruction Fuzzy Hash: 63213C25B26F4183FB4C9BA1E8A4B696360FF88BC4F104179DA4E43754CF3CE4698742
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: freemalloc$ErrnoWarning@@
                                                      • String ID: %s: GetDesignGlyphMetrics failed$QWindowsFontEngineDirectWrite::recalcAdvances
                                                      • API String ID: 113164508-2792955
                                                      • Opcode ID: fda4e861837a2fc947640658ab044112b6d4842523097a0e7220920451c409d2
                                                      • Instruction ID: 2079ba4604739bbfd3b96ef3760f801e5a35d3253e94f718a1369a7bea335c70
                                                      • Opcode Fuzzy Hash: fda4e861837a2fc947640658ab044112b6d4842523097a0e7220920451c409d2
                                                      • Instruction Fuzzy Hash: 74518E72B79A828AD7658F25E55176DB3A4FBC4B84F00827AEA4E43764CF3CE445CB01
                                                      APIs
                                                      • ??0?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,00000001,00007FFDE6601FA0), ref: 00007FFDE6601E9D
                                                      • ??4QByteArray@@QEAAAEAV0@AEBV0@@Z.QT5CORE(?,?,00000001,00007FFDE6601FA0), ref: 00007FFDE6601EAC
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,00000001,00007FFDE6601FA0), ref: 00007FFDE6601EC2
                                                      • ?utf16@QString@@QEBAPEBGXZ.QT5CORE(?,?,00000001,00007FFDE6601FA0), ref: 00007FFDE6601ED4
                                                      • ?load@QSystemLibrary@@SAPEAUHINSTANCE__@@PEB_W_N@Z.QT5CORE(?,?,00000001,00007FFDE6601FA0), ref: 00007FFDE6601EDF
                                                      • GetProcAddress.KERNEL32(?,?,00000001,00007FFDE6601FA0), ref: 00007FFDE6601EFB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: F@@@@PointVector@$??0?$??1?$?load@?utf16@AddressArray@@ByteE__@@Library@@ProcString@@SystemV0@@
                                                      • String ID: Direct3DCreate9
                                                      • API String ID: 76665892-2790205071
                                                      • Opcode ID: 379684cc7bb6779c028e5def2ccb9e56e6ea646f8f1635004ea92a67f90aacbf
                                                      • Instruction ID: 219efb7e021768ea4902faa786036bf29a0bb074745e8b0301d880d6ea850533
                                                      • Opcode Fuzzy Hash: 379684cc7bb6779c028e5def2ccb9e56e6ea646f8f1635004ea92a67f90aacbf
                                                      • Instruction Fuzzy Hash: FC115A31B39F4292EB889B50E56836837A0FB94745F400078DA4E03B60DF7CE1A8CB81
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: ??1?$F@@@@PointVector@$String@@V0@@$?utf16@Array@@ByteCreateHandleModuleWindow
                                                      • String ID:
                                                      • API String ID: 2439629798-0
                                                      • Opcode ID: f2087c96846c6fdbbc289e6e3326951b3f0ab4b54dd8284987c8abbf6a20d282
                                                      • Instruction ID: d03d94072cce551511343f23a4ba044a28b449215f6377b8527e16f681df1977
                                                      • Opcode Fuzzy Hash: f2087c96846c6fdbbc289e6e3326951b3f0ab4b54dd8284987c8abbf6a20d282
                                                      • Instruction Fuzzy Hash: FE413272A3CB8686E7249F24F4643AAB7A0FB99744F401139DA8D42A69DF3CD144CF41
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Image@@$V0@@$A@$$$?convert?depth@?scale@Color@@ConversionFlag@Flags@Format@1@Format_helper@ImageQt@@@@@Transform@@
                                                      • String ID:
                                                      • API String ID: 2161299910-0
                                                      • Opcode ID: 0805d92f76f90213e1afe06ecaac3985aab19e3a0e8da0a748e2805ed3fd42c0
                                                      • Instruction ID: 7010ec1c677afccffada5e76e5d3fc213c38dd1dc7f7b3e565a88e6d8677be9c
                                                      • Opcode Fuzzy Hash: 0805d92f76f90213e1afe06ecaac3985aab19e3a0e8da0a748e2805ed3fd42c0
                                                      • Instruction Fuzzy Hash: 47318232728A8291DB64AF15F8607AA7760FB85BC5F808075DE8D43B64EF3CD549CB01
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3555456661.00007FF6F8011000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00007FF6F8010000, based on PE: true
                                                      • Associated: 00000013.00000002.3555389094.00007FF6F8010000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                      • Associated: 00000013.00000002.3555496022.00007FF6F8013000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                      • Associated: 00000013.00000002.3555543118.00007FF6F8015000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                      • Associated: 00000013.00000002.3555583685.00007FF6F8026000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ff6f8010000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: FileFolderKnownNamePathUserWritelstrlen
                                                      • String ID: 2024-05-24 09:31:34.372 Command line: ****************************\CiscoSparkLauncher\CiscoCollabHost.exe ************************$user
                                                      • API String ID: 992006388-672875127
                                                      • Opcode ID: 6dc9ffa8ca8a6af00f3eac1d72b88296e795163228cb48cadefe63f6b994adec
                                                      • Instruction ID: 31046b433bbbfdfdcab74b53fb083c9e06b09ae4f2253f9bdc4a59bcf4f8dd6e
                                                      • Opcode Fuzzy Hash: 6dc9ffa8ca8a6af00f3eac1d72b88296e795163228cb48cadefe63f6b994adec
                                                      • Instruction Fuzzy Hash: 2D41C522A18E4292E750DB21E9403A973A0FB44BA8FC45171EEAD836E5EF3CD445E748
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: IconNotifyShell_String@@$??1?$?truncate@Array@Array@@ByteCharF@@@@PointV0@@Vector@memset
                                                      • String ID:
                                                      • API String ID: 2454839999-0
                                                      • Opcode ID: d9457b334d51f1fff7d4e2eec35605652db5c337efdb54a8a6ff09ad10f6d735
                                                      • Instruction ID: cc228b61e90e6741a75f1ce8bd657c968898c096563cbd13c12376f432197e23
                                                      • Opcode Fuzzy Hash: d9457b334d51f1fff7d4e2eec35605652db5c337efdb54a8a6ff09ad10f6d735
                                                      • Instruction Fuzzy Hash: 3141D472B29BC28AE774DF20D9543ED77A4F799788F005239DA8C47A14EF78E5908B00
                                                      APIs
                                                        • Part of subcall function 00007FFDE65D1100: ??0QTextStream@@QEAA@PEAVQString@@V?$QFlags@W4OpenModeFlag@QIODevice@@@@@Z.QT5CORE(?,?,?,?,?,00007FFDE65D12F8), ref: 00007FFDE65D1150
                                                        • Part of subcall function 00007FFDE65D1100: ??6QTextStream@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,00007FFDE65D12F8), ref: 00007FFDE65D1162
                                                        • Part of subcall function 00007FFDE65D1100: ??6QTextStream@@QEAAAEAV0@H@Z.QT5CORE(?,?,?,?,?,00007FFDE65D12F8), ref: 00007FFDE65D1170
                                                        • Part of subcall function 00007FFDE65D1100: ??6QTextStream@@QEAAAEAV0@H@Z.QT5CORE(?,?,?,?,?,00007FFDE65D12F8), ref: 00007FFDE65D117E
                                                        • Part of subcall function 00007FFDE65D1100: ??6QTextStream@@QEAAAEAV0@H@Z.QT5CORE(?,?,?,?,?,00007FFDE65D12F8), ref: 00007FFDE65D118C
                                                        • Part of subcall function 00007FFDE65D1100: ?qResourceFeatureZlib@@YAEXZ.QT5CORE(?,?,?,?,?,00007FFDE65D12F8), ref: 00007FFDE65D1192
                                                        • Part of subcall function 00007FFDE65D1100: ??6QTextStream@@QEAAAEAV0@D@Z.QT5CORE(?,?,?,?,?,00007FFDE65D12F8), ref: 00007FFDE65D11A3
                                                        • Part of subcall function 00007FFDE65D1100: ??1QTextStream@@UEAA@XZ.QT5CORE(?,?,?,?,?,00007FFDE65D12F8), ref: 00007FFDE65D11AE
                                                        • Part of subcall function 00007FFDE65D1100: ??0QByteArray@@QEAA@AEBV0@@Z.QT5CORE(?,?,?,?,?,00007FFDE65D12F8), ref: 00007FFDE65D11BE
                                                      • ??0QByteArray@@QEAA@AEBV0@@Z.QT5CORE ref: 00007FFDE65D1B4E
                                                      • ??YQString@@QEAAAEAV0@AEBV0@@Z.QT5CORE ref: 00007FFDE65D1B5F
                                                        • Part of subcall function 00007FFDE65D14C0: GetModuleHandleW.KERNEL32 ref: 00007FFDE65D1518
                                                        • Part of subcall function 00007FFDE65D14C0: ?utf16@QString@@QEBAPEBGXZ.QT5CORE ref: 00007FFDE65D1524
                                                        • Part of subcall function 00007FFDE65D14C0: GetClassInfoW.USER32 ref: 00007FFDE65D1534
                                                        • Part of subcall function 00007FFDE65D14C0: ?createUuid@QUuid@@SA?AV1@XZ.QT5CORE ref: 00007FFDE65D1548
                                                        • Part of subcall function 00007FFDE65D14C0: ?toString@QUuid@@QEBA?AVQString@@XZ.QT5CORE ref: 00007FFDE65D1556
                                                        • Part of subcall function 00007FFDE65D14C0: ??YQString@@QEAAAEAV0@AEBV0@@Z.QT5CORE ref: 00007FFDE65D1562
                                                        • Part of subcall function 00007FFDE65D14C0: ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65D156D
                                                        • Part of subcall function 00007FFDE65D14C0: ?qHash@@YAIAEBVQString@@I@Z.QT5CORE ref: 00007FFDE65D1589
                                                        • Part of subcall function 00007FFDE65D14C0: LoadImageW.USER32 ref: 00007FFDE65D1604
                                                        • Part of subcall function 00007FFDE65D14C0: GetSystemMetrics.USER32 ref: 00007FFDE65D1618
                                                        • Part of subcall function 00007FFDE65D14C0: GetSystemMetrics.USER32 ref: 00007FFDE65D1624
                                                        • Part of subcall function 00007FFDE65D14C0: LoadImageW.USER32 ref: 00007FFDE65D1644
                                                        • Part of subcall function 00007FFDE65D14C0: ?utf16@QString@@QEBAPEBGXZ.QT5CORE ref: 00007FFDE65D1688
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000,00007FFDE660702A), ref: 00007FFDE65D1B94
                                                      • GetModuleHandleW.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000,00007FFDE660702A), ref: 00007FFDE65D1B9C
                                                      • ?utf16@QString@@QEBAPEBGXZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000,00007FFDE660702A), ref: 00007FFDE65D1BAA
                                                      • CreateWindowExW.USER32 ref: 00007FFDE65D1BF8
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00007FFDE65D1C06
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: String@@$Stream@@Text$V0@@$??1?$?utf16@F@@@@PointVector@$Array@@ByteHandleImageLoadMetricsModuleSystemUuid@@$?createClassCreateDevice@@@@@FeatureFlag@Flags@Hash@@InfoModeOpenResourceString@Uuid@WindowZlib@@
                                                      • String ID:
                                                      • API String ID: 3280711510-0
                                                      • Opcode ID: ceac300315069c64962ec41517cd49f6d04aafe8509cb4a4fc428d20f9a54cf2
                                                      • Instruction ID: 65f26fd5e0dcca596493c25114b7d5a6ff3a83d1ca05cf762cf6be44fa6e25ae
                                                      • Opcode Fuzzy Hash: ceac300315069c64962ec41517cd49f6d04aafe8509cb4a4fc428d20f9a54cf2
                                                      • Instruction Fuzzy Hash: 71215E32728B8296DB209F11F46879ABB60F789BA4F540239EE9D57B58CF3CD145CB40
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Pixmap@@$Icon@@$Mode@1@Null@Size@@State@1@@$?actual?pixmap@?qt_pixmapN__@@Pixmap@@@Size@
                                                      • String ID:
                                                      • API String ID: 3674238903-0
                                                      • Opcode ID: 3c8dff903607e1b53151d58e2ed3d798eed479b5cda9fc7c29a4fb54ba0ac7a6
                                                      • Instruction ID: 660784c28856502f0137fe2a7d208f30362ea2df7e8661f84b64ba6fb3cb8e31
                                                      • Opcode Fuzzy Hash: 3c8dff903607e1b53151d58e2ed3d798eed479b5cda9fc7c29a4fb54ba0ac7a6
                                                      • Instruction Fuzzy Hash: 96112172B28A82C2EB549F15F85429A77A0FBC8B94F445175EA8E43B18DF3CD185CF00
                                                      APIs
                                                      • ??0?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65D51F3
                                                        • Part of subcall function 00007FFDE65D4DA0: GetMonitorInfoW.USER32 ref: 00007FFDE65D4DF3
                                                        • Part of subcall function 00007FFDE65D4DA0: ?fromWCharArray@QString@@SA?AV1@PEB_WH@Z.QT5CORE ref: 00007FFDE65D4E86
                                                        • Part of subcall function 00007FFDE65D4DA0: ??4QUrl@@QEAAAEAV0@$$QEAV0@@Z.QT5CORE ref: 00007FFDE65D4E93
                                                        • Part of subcall function 00007FFDE65D4DA0: ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65D4E9E
                                                        • Part of subcall function 00007FFDE65D4DA0: ?isNull@QString@@QEBA_NXZ.QT5CORE ref: 00007FFDE65D4EC7
                                                        • Part of subcall function 00007FFDE65D4DA0: ?compareStrings@QtPrivate@@YAHVQStringView@@0W4CaseSensitivity@Qt@@@Z.QT5CORE ref: 00007FFDE65D4F26
                                                      • ?allocate@QArrayData@@SAPEAU1@_K00V?$QFlags@W4AllocationOption@QArrayData@@@@@Z.QT5CORE ref: 00007FFDE65D5256
                                                      • ??0QByteArray@@QEAA@AEBV0@@Z.QT5CORE ref: 00007FFDE65D52F1
                                                      • ??0QByteArray@@QEAA@AEBV0@@Z.QT5CORE ref: 00007FFDE65D534F
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65D53B2
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65D53CA
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: F@@@@PointVector@$??1?$V0@@$ArrayArray@@ByteString@@$??0?$?allocate@?compare?fromAllocationArray@CaseCharData@@Data@@@@@Flags@InfoMonitorNull@Option@Private@@Qt@@@Sensitivity@StringStrings@U1@_Url@@V0@$$View@@0
                                                      • String ID:
                                                      • API String ID: 4195334077-0
                                                      • Opcode ID: 3ae9f7c562d7a580643f0724e5382043cb8679de9a79715e036aed15d11eed9e
                                                      • Instruction ID: 048ad1e29d0d127a2cf75d842fbfcfa3c03016d56d23ee487ea347ff347b0642
                                                      • Opcode Fuzzy Hash: 3ae9f7c562d7a580643f0724e5382043cb8679de9a79715e036aed15d11eed9e
                                                      • Instruction Fuzzy Hash: A6818A32B18A818AE715CF78D4913ECB3B0FB58748F045225EF4927A59EF38D596CB80
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: ??0glyph_metrics_t@@ErrnoWarning@@
                                                      • String ID: %s: GetDesignGlyphMetrics failed$QWindowsFontEngineDirectWrite::boundingBox
                                                      • API String ID: 2049762950-3682458546
                                                      • Opcode ID: 85d358e7cb156b55061e20b8f7bb2627472aadf0e3953f6c26f401c26da9eadd
                                                      • Instruction ID: 46e8955d25373398be7aa29f1db3d413c71ddcec64721aedea62a4a168805905
                                                      • Opcode Fuzzy Hash: 85d358e7cb156b55061e20b8f7bb2627472aadf0e3953f6c26f401c26da9eadd
                                                      • Instruction Fuzzy Hash: 3941A972A39F404ED307CF35A561716E725AFA6BC4B55C326B90B72E15DB38E0918E00
                                                      APIs
                                                      • ??8QString@@QEBA_NVQLatin1String@@@Z.QT5CORE ref: 00007FFDE65CE5F7
                                                        • Part of subcall function 00007FFDE66C5438: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,00007FFDE6601D3E,?,?,?,00007FFDE6601FED), ref: 00007FFDE66C5452
                                                      • ??0QPlatformTheme@@QEAA@XZ.QT5GUI ref: 00007FFDE65CE615
                                                      • memset.VCRUNTIME140 ref: 00007FFDE65CE649
                                                        • Part of subcall function 00007FFDE65EFAF0: ?desktopSettingsAware@QGuiApplication@@SA_NXZ.QT5GUI ref: 00007FFDE65EFB10
                                                        • Part of subcall function 00007FFDE65EFAF0: SystemParametersInfoW.USER32 ref: 00007FFDE65EFBC0
                                                        • Part of subcall function 00007FFDE65EFAF0: ??0QPalette@@QEAA@AEBV0@@Z.QT5GUI ref: 00007FFDE65EFBEA
                                                        • Part of subcall function 00007FFDE65EFAF0: GetSysColor.USER32 ref: 00007FFDE65EFBFC
                                                        • Part of subcall function 00007FFDE65EFAF0: ??0QColor@@QEAA@HHHH@Z.QT5GUI ref: 00007FFDE65EFC22
                                                        • Part of subcall function 00007FFDE65EFAF0: ??0QBrush@@QEAA@AEBVQColor@@W4BrushStyle@Qt@@@Z.QT5GUI ref: 00007FFDE65EFC62
                                                        • Part of subcall function 00007FFDE65EFAF0: ?setBrush@QPalette@@QEAAXW4ColorGroup@1@W4ColorRole@1@AEBVQBrush@@@Z.QT5GUI ref: 00007FFDE65EFC74
                                                        • Part of subcall function 00007FFDE65EFAF0: ??1QBrush@@QEAA@XZ.QT5GUI ref: 00007FFDE65EFC7E
                                                        • Part of subcall function 00007FFDE65EFAF0: ??0QBrush@@QEAA@AEBVQColor@@W4BrushStyle@Qt@@@Z.QT5GUI ref: 00007FFDE65EFC92
                                                        • Part of subcall function 00007FFDE65F0120: ?desktopSettingsAware@QGuiApplication@@SA_NXZ.QT5GUI ref: 00007FFDE65F014B
                                                        • Part of subcall function 00007FFDE65F0120: ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ.QT5CORE ref: 00007FFDE65F01BA
                                                        • Part of subcall function 00007FFDE65F0120: ??0QMessageLogger@@QEAA@PEBDH00@Z.QT5CORE ref: 00007FFDE65F01DE
                                                        • Part of subcall function 00007FFDE65F0120: ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ.QT5CORE ref: 00007FFDE65F01EB
                                                        • Part of subcall function 00007FFDE65F0120: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE65F01FB
                                                        • Part of subcall function 00007FFDE65F0120: ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE65F0220
                                                        • Part of subcall function 00007FFDE65F0120: ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE65F022A
                                                        • Part of subcall function 00007FFDE65F0120: ?fromWCharArray@QString@@SA?AV1@PEB_WH@Z.QT5CORE ref: 00007FFDE65F024A
                                                        • Part of subcall function 00007FFDE65F0120: ??0QFont@@QEAA@AEBVQString@@HH_N@Z.QT5GUI ref: 00007FFDE65F0263
                                                        • Part of subcall function 00007FFDE65F0120: ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65F026D
                                                        • Part of subcall function 00007FFDE65F0120: ?setItalic@QFont@@QEAAX_N@Z.QT5GUI ref: 00007FFDE65F0282
                                                        • Part of subcall function 00007FFDE65F0120: ?weightFromInteger@QPlatformFontDatabase@@SA?AW4Weight@QFont@@H@Z.QT5GUI ref: 00007FFDE65F0292
                                                        • Part of subcall function 00007FFDE65F0120: ?setWeight@QFont@@QEAAXH@Z.QT5GUI ref: 00007FFDE65F029F
                                                        • Part of subcall function 00007FFDE65F0120: ?setPointSizeF@QFont@@QEAAXN@Z.QT5GUI ref: 00007FFDE65F02D7
                                                        • Part of subcall function 00007FFDE65F0120: ?setUnderline@QFont@@QEAAX_N@Z.QT5GUI ref: 00007FFDE65F02EC
                                                        • Part of subcall function 00007FFDE65F09D0: GetSystemMetrics.USER32 ref: 00007FFDE65F09E8
                                                        • Part of subcall function 00007FFDE65F09D0: GetSystemMetrics.USER32 ref: 00007FFDE65F09F9
                                                        • Part of subcall function 00007FFDE65F09D0: ?dispose@QListData@@SAXPEAUData@1@@Z.QT5CORE ref: 00007FFDE65F0A69
                                                        • Part of subcall function 00007FFDE65F09D0: ?dispose@QListData@@SAXPEAUData@1@@Z.QT5CORE ref: 00007FFDE65F0A8E
                                                        • Part of subcall function 00007FFDE65F09D0: ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ.QT5CORE ref: 00007FFDE65F0A9C
                                                        • Part of subcall function 00007FFDE65F09D0: ??0QMessageLogger@@QEAA@PEBDH00@Z.QT5CORE ref: 00007FFDE65F0ACC
                                                        • Part of subcall function 00007FFDE65F09D0: ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ.QT5CORE ref: 00007FFDE65F0AD9
                                                        • Part of subcall function 00007FFDE65F09D0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE65F0AE9
                                                        • Part of subcall function 00007FFDE65F09D0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE65F0B17
                                                        • Part of subcall function 00007FFDE65F09D0: ??6QDebug@@QEAAAEAV0@D@Z.QT5CORE ref: 00007FFDE65F0B22
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$Font@@$?set$Logger@@Message$Brush@@ColorColor@@String@@System$?debug@?desktop?dispose@Application@@Aware@BrushCategory@@Data@1@@Data@@DebugEnabled@H00@ListLoggingMetricsPalette@@PlatformPointQt@@@SettingsStyle@Weight@$??1?$?from?weightArray@Brush@Brush@@@CharDatabase@@F@@@@FontFromGroup@1@InfoInteger@Italic@Latin1ParametersRole@1@SizeString@@@Theme@@Underline@V0@@Vector@mallocmemset
                                                      • String ID: windows
                                                      • API String ID: 250645261-3823601051
                                                      • Opcode ID: b2e1a00dea626da5eda00ed2ea7d4bab45e9dee6c738dd80072490d36ec4fa94
                                                      • Instruction ID: 5de34f2dbc2c91dd58661da37fe72fe432a560bd5ac390c4e793853b10a9b6de
                                                      • Opcode Fuzzy Hash: b2e1a00dea626da5eda00ed2ea7d4bab45e9dee6c738dd80072490d36ec4fa94
                                                      • Instruction Fuzzy Hash: EB210122F28B8282E715DF25E9203B96360FBD9B88F445339DE8C46666EF7CD1958701
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Logger@@Message$?warning@
                                                      • String ID: %s: Could not create the EGL window surface: 0x%x$QWindowsEGLStaticContext::createWindowSurface
                                                      • API String ID: 3543197520-1328596389
                                                      • Opcode ID: 462740fdfcd476f25f7533cc109454d289b2628156fe8496cbbdfa654ebd0f8e
                                                      • Instruction ID: 5db94f8631e2e09e5391c3cc4994677b6764c00b760202eace7263d6cf374890
                                                      • Opcode Fuzzy Hash: 462740fdfcd476f25f7533cc109454d289b2628156fe8496cbbdfa654ebd0f8e
                                                      • Instruction Fuzzy Hash: F7012872B38B4682EB149F26F86876937A1BB99B84F459039DE0D47B20DE3CE014CB01
                                                      APIs
                                                      • ?options@QSurfaceFormat@@QEBA?AV?$QFlags@W4FormatOption@QSurfaceFormat@@@@XZ.QT5GUI ref: 00007FFDE65D0B46
                                                      • ?setCapabilities@QTouchDevice@@QEAAXV?$QFlags@W4CapabilityFlag@QTouchDevice@@@@@Z.QT5GUI ref: 00007FFDE65D0B54
                                                      • ?registerTouchDevice@QWindowSystemInterface@@SAXPEBVQTouchDevice@@@Z.QT5GUI ref: 00007FFDE65D0B5D
                                                        • Part of subcall function 00007FFDE65D9B30: GetSystemMetrics.USER32 ref: 00007FFDE65D9B3B
                                                        • Part of subcall function 00007FFDE65CBE80: IsTouchWindow.USER32 ref: 00007FFDE65CBEC1
                                                        • Part of subcall function 00007FFDE65CBE80: RegisterTouchWindow.USER32 ref: 00007FFDE65CBED7
                                                      • ?nextNode@QHashData@@SAPEAUNode@1@PEAU21@@Z.QT5CORE ref: 00007FFDE65D0BC2
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Touch$Window$Flags@SurfaceSystem$?next?options@?register?setCapabilities@CapabilityData@@Device@Device@@Device@@@Device@@@@@Flag@FormatFormat@@Format@@@@HashInterface@@MetricsNode@Node@1@Option@RegisterU21@@
                                                      • String ID:
                                                      • API String ID: 4257462213-0
                                                      • Opcode ID: 5316ae84cb4ff3c5837d7fdd21ca74e4fd707ae9453c8a2e0a61cffbcab3c39e
                                                      • Instruction ID: 245df1f51d84bdfd6b083ff977dfc1af0e0d14052652ce0e6d200f90c49bfa6f
                                                      • Opcode Fuzzy Hash: 5316ae84cb4ff3c5837d7fdd21ca74e4fd707ae9453c8a2e0a61cffbcab3c39e
                                                      • Instruction Fuzzy Hash: 44313B22B29B8181FB599F22E5643AE23A0FB58B98F485471DE4D473C5CF3CE891C711
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: CursorDestroy$PlatformTouchUnregisterWindowWindow@@
                                                      • String ID:
                                                      • API String ID: 2606880673-0
                                                      • Opcode ID: aa09f44f959c502092edd8d92dd301a9e3bd12d04c931004e637499fc140a400
                                                      • Instruction ID: 499150f00e220f01112bcf3db69670703de7e9a8baa0c77ff56d0b395b59f240
                                                      • Opcode Fuzzy Hash: aa09f44f959c502092edd8d92dd301a9e3bd12d04c931004e637499fc140a400
                                                      • Instruction Fuzzy Hash: 7D314135B29B4182EB499F65E96073863A0FF84F94F184134DE4E47756CF2CE865CB41
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: BehindBlurCompositionCreateDeleteEnableEnabledObjectRectWindow
                                                      • String ID:
                                                      • API String ID: 511322073-0
                                                      • Opcode ID: d8dc608101fc5882060ab7fa8f2141140f153e488909f8ef117527d338fc113f
                                                      • Instruction ID: 68aee0500444cc648b5f4c9610f22c016aed0facb39443d680de461b2c3ea686
                                                      • Opcode Fuzzy Hash: d8dc608101fc5882060ab7fa8f2141140f153e488909f8ef117527d338fc113f
                                                      • Instruction Fuzzy Hash: 98017571B29F4186EB759B21F42873A77A0FB84795F084235D98E86A94DF3CD144DF01
                                                      APIs
                                                        • Part of subcall function 00007FFDE66C5438: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,00007FFDE6601D3E,?,?,?,00007FFDE6601FED), ref: 00007FFDE66C5452
                                                      • ??0QEventDispatcherWin32@@QEAA@PEAVQObject@@@Z.QT5CORE ref: 00007FFDE6622D5F
                                                      • ?setObjectName@QObject@@QEAAXAEBVQString@@@Z.QT5CORE ref: 00007FFDE6622D8A
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE6622D95
                                                      • ?createInternalHwnd@QEventDispatcherWin32@@IEAAXXZ.QT5CORE ref: 00007FFDE6622D9E
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: DispatcherEventWin32@@$??1?$?create?setF@@@@Hwnd@InternalName@ObjectObject@@Object@@@PointString@@@Vector@malloc
                                                      • String ID:
                                                      • API String ID: 4015998498-0
                                                      • Opcode ID: 8905c76f6c51a78d60ef4feb64d45750813ac506efe83f64fc70dad27e2415dd
                                                      • Instruction ID: 5949db543368027131301baf59940e140d135114ead7ec9e7bc9fca01eb9436c
                                                      • Opcode Fuzzy Hash: 8905c76f6c51a78d60ef4feb64d45750813ac506efe83f64fc70dad27e2415dd
                                                      • Instruction Fuzzy Hash: E1F04F60B38F0681EB08AF12F8642696B64FB89745F405078D94E06364DE3CD2AA8B41
                                                      APIs
                                                      • ?compare@QString@@SAHAEBV1@VQLatin1String@@W4CaseSensitivity@Qt@@@Z.QT5CORE ref: 00007FFDE6620BF6
                                                        • Part of subcall function 00007FFDE66C5438: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,00007FFDE6601D3E,?,?,?,00007FFDE6601FED), ref: 00007FFDE66C5452
                                                        • Part of subcall function 00007FFDE66C5438: Concurrency::cancel_current_task.LIBCPMT ref: 00007FFDE66C5468
                                                        • Part of subcall function 00007FFDE66C5438: Concurrency::cancel_current_task.LIBCPMT ref: 00007FFDE66C546E
                                                        • Part of subcall function 00007FFDE65CCBD0: ?qgetenv@@YA?AVQByteArray@@PEBD@Z.QT5CORE ref: 00007FFDE65CCC19
                                                        • Part of subcall function 00007FFDE65CCBD0: ?fromLocal8Bit@QString@@SA?AV1@AEBVQByteArray@@@Z.QT5CORE ref: 00007FFDE65CCC3C
                                                        • Part of subcall function 00007FFDE65CCBD0: ?setFilterRules@QLoggingCategory@@SAXAEBVQString@@@Z.QT5CORE ref: 00007FFDE65CCC45
                                                        • Part of subcall function 00007FFDE65CCBD0: ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65CCC53
                                                        • Part of subcall function 00007FFDE65CCBD0: ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65CCC61
                                                        • Part of subcall function 00007FFDE65CCBD0: ??0QInternalMimeData@@QEAA@XZ.QT5GUI ref: 00007FFDE65CCC7D
                                                        • Part of subcall function 00007FFDE65CCBD0: ?qAddPostRoutine@@YAXP6AXXZ@Z.QT5CORE ref: 00007FFDE65CCCAC
                                                        • Part of subcall function 00007FFDE65CCBD0: ??0QPlatformDrag@@QEAA@XZ.QT5GUI ref: 00007FFDE65CCCB6
                                                        • Part of subcall function 00007FFDE65CCBD0: ??0QInternalMimeData@@QEAA@XZ.QT5GUI ref: 00007FFDE65CCCCB
                                                        • Part of subcall function 00007FFDE65CCBD0: ??0QUrl@@QEAA@XZ.QT5CORE ref: 00007FFDE65CCCEB
                                                        • Part of subcall function 00007FFDE65CCBD0: ??0QPlatformAccessibility@@QEAA@XZ.QT5GUI ref: 00007FFDE65CCD06
                                                        • Part of subcall function 00007FFDE65CCBD0: ??0QPlatformServices@@QEAA@XZ.QT5GUI ref: 00007FFDE65CCD21
                                                        • Part of subcall function 00007FFDE65CCBD0: ?qRegisterResourceData@@YA_NHPEBE00@Z.QT5CORE ref: 00007FFDE65CCD4F
                                                        • Part of subcall function 00007FFDE65CCBD0: ?current@QOperatingSystemVersion@@SA?AV1@XZ.QT5CORE ref: 00007FFDE65CCDAB
                                                        • Part of subcall function 00007FFDE65CCBD0: ?compare@QOperatingSystemVersion@@CAHAEBV1@0@Z.QT5CORE ref: 00007FFDE65CCDBD
                                                        • Part of subcall function 00007FFDE660E3F0: ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE660E435
                                                        • Part of subcall function 00007FFDE660E3F0: ?qErrnoWarning@@YAXPEBDZZ.QT5CORE ref: 00007FFDE660E46E
                                                        • Part of subcall function 00007FFDE660E3F0: SetClipboardViewer.USER32 ref: 00007FFDE660E47E
                                                        • Part of subcall function 00007FFDE660E3F0: ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ.QT5CORE ref: 00007FFDE660E490
                                                        • Part of subcall function 00007FFDE660E3F0: ??0QMessageLogger@@QEAA@PEBDH00@Z.QT5CORE ref: 00007FFDE660E4B9
                                                        • Part of subcall function 00007FFDE660E3F0: ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ.QT5CORE ref: 00007FFDE660E4C7
                                                        • Part of subcall function 00007FFDE660E3F0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE660E4D7
                                                        • Part of subcall function 00007FFDE660E3F0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE660E4E7
                                                        • Part of subcall function 00007FFDE660E3F0: ??6QDebug@@QEAAAEAV0@PEBX@Z.QT5CORE ref: 00007FFDE660E4F4
                                                        • Part of subcall function 00007FFDE660E3F0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE660E504
                                                        • Part of subcall function 00007FFDE660E3F0: ??6QDebug@@QEAAAEAV0@_N@Z.QT5CORE ref: 00007FFDE660E511
                                                        • Part of subcall function 00007FFDE660E3F0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE660E521
                                                        • Part of subcall function 00007FFDE660E3F0: ??6QDebug@@QEAAAEAV0@PEBX@Z.QT5CORE ref: 00007FFDE660E52E
                                                        • Part of subcall function 00007FFDE660E3F0: ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE660E539
                                                        • Part of subcall function 00007FFDE65D66A0: EnumDisplayMonitors.USER32 ref: 00007FFDE65D66D4
                                                        • Part of subcall function 00007FFDE65D66A0: ??8@YA_NAEBVQString@@0@Z.QT5CORE ref: 00007FFDE65D679B
                                                        • Part of subcall function 00007FFDE65D66A0: ??0QPlatformScreen@@QEAA@XZ.QT5GUI ref: 00007FFDE65D67C6
                                                        • Part of subcall function 00007FFDE65D66A0: ??0QPlatformCursor@@QEAA@XZ.QT5GUI ref: 00007FFDE65D67F2
                                                        • Part of subcall function 00007FFDE65D66A0: ??0QPixmap@@QEAA@XZ.QT5GUI ref: 00007FFDE65D6820
                                                        • Part of subcall function 00007FFDE65D66A0: ??0QPixmap@@QEAA@XZ.QT5GUI ref: 00007FFDE65D682A
                                                        • Part of subcall function 00007FFDE65D66A0: ??0QPixmap@@QEAA@XZ.QT5GUI ref: 00007FFDE65D6834
                                                        • Part of subcall function 00007FFDE65D66A0: ??0QPixmap@@QEAA@XZ.QT5GUI ref: 00007FFDE65D6841
                                                      • ??0QPlatformNativeInterface@@QEAA@XZ.QT5GUI ref: 00007FFDE6620C8B
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$Platform$Pixmap@@$??1?$Data@@F@@@@PointString@@Vector@$?compare@ByteCategory@@Concurrency::cancel_current_taskInternalLogger@@LoggingMessageMimeOperatingSystemVersion@@$??8@?current@?debug@?from?qgetenv@@?setAccessibility@@Array@@Array@@@Bit@CaseClipboardCursor@@DebugDisplayDrag@@E00@Enabled@EnumErrnoFilterH00@Interface@@Latin1Local8MonitorsNativePostQt@@@RegisterResourceRoutine@@Rules@Screen@@Sensitivity@Services@@String@@0@String@@@Url@@V0@_V1@0@ViewerWarning@@malloc
                                                      • String ID: windows
                                                      • API String ID: 649254184-3823601051
                                                      • Opcode ID: 7575995001da6b48c088f08e9a0b6800724cea074633f86045df9205197bcedc
                                                      • Instruction ID: 11bc635da2d2a0013d53f4a14b918f4e189d82f0eb15144dfc789975e8043ea5
                                                      • Opcode Fuzzy Hash: 7575995001da6b48c088f08e9a0b6800724cea074633f86045df9205197bcedc
                                                      • Instruction Fuzzy Hash: B2216035B25B4582EB18DB15E8603ADB7A0FB99B84F844139DB8D47761EF3CE1A1CB01
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: ErrnoInit_thread_footerWarning@@
                                                      • String ID: DWriteCreateFactory failed
                                                      • API String ID: 1977386182-439803201
                                                      • Opcode ID: dfe923a12fdaefa33a05b7dcd2b498a249d0ad20de03b02f0b8cab2101c887ac
                                                      • Instruction ID: 342353809649439b8574a47470fc670adf5cad5730bbf990aacdb21fb9cc2846
                                                      • Opcode Fuzzy Hash: dfe923a12fdaefa33a05b7dcd2b498a249d0ad20de03b02f0b8cab2101c887ac
                                                      • Instruction Fuzzy Hash: 362149A0F39B02C2EB49AF24E87436533A0EB54B11F5041B9D90E46AA1DF3CE495CB42
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: ErrnoWarning@@
                                                      • String ID: %s: GetGdiInterop failed$initDirectWrite
                                                      • API String ID: 3819680178-3227400310
                                                      • Opcode ID: 79f155389e56fdec51139836eebdcdb35b0269b76a50a9989e5cbfd745a25d96
                                                      • Instruction ID: 0c6325e51d00ed52770a7b0932a970184644c3291748ae86b1b2d2234467a82d
                                                      • Opcode Fuzzy Hash: 79f155389e56fdec51139836eebdcdb35b0269b76a50a9989e5cbfd745a25d96
                                                      • Instruction Fuzzy Hash: D4014F62B3894691EF4CCF25E5A03B82360FB54B84F849079DA5D47260DF28E8E58B01
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Category@@Init_thread_footerLogging
                                                      • String ID: qt.qpa.windows
                                                      • API String ID: 189896515-1025278669
                                                      • Opcode ID: 941edff3d6c6cdc9a24d020290589781265611e5ca4f10abadbf096eec31aae2
                                                      • Instruction ID: b5c8428a6d82f94d20894e9165abfd71b6a3d6497b60ce922711b37988d4b8d8
                                                      • Opcode Fuzzy Hash: 941edff3d6c6cdc9a24d020290589781265611e5ca4f10abadbf096eec31aae2
                                                      • Instruction Fuzzy Hash: 40014FA1F78942C2EB18EF15EDB17B43320AF45760F842236C80D026A1DE3CE9A5C702
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: ??0glyph_metrics_t@@?bounding?scale@Box@Engine@@FontTransform@@Transform@@@Uglyph_metrics_t@@
                                                      • String ID:
                                                      • API String ID: 1453275203-0
                                                      • Opcode ID: e86ac7ccc1b10b3a302a6c46af90d4f71fedfcc80bef3918b1a844ec347ba73e
                                                      • Instruction ID: e430227ce8a187af94869867c57b4be38373d81d584c57a2beee25c5b52d4872
                                                      • Opcode Fuzzy Hash: e86ac7ccc1b10b3a302a6c46af90d4f71fedfcc80bef3918b1a844ec347ba73e
                                                      • Instruction Fuzzy Hash: DE818732A24B858AE715CF35E4507ADB770FB99788F048225EB4D17B64DF38D495CB00
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: ?dispose@?topApplication@@Data@1@@Data@@LevelListList@ProcWindowWindow@@@@Windows@
                                                      • String ID:
                                                      • API String ID: 4119622827-0
                                                      • Opcode ID: 28ae677817da4ce10941dfef15bb1b488935818469b6152699bccce94b7ef127
                                                      • Instruction ID: 77c3a02e0eef39a3c9cbfd48fb6ca9bbdc740a9ef8afd0297387e77aba48a6f3
                                                      • Opcode Fuzzy Hash: 28ae677817da4ce10941dfef15bb1b488935818469b6152699bccce94b7ef127
                                                      • Instruction Fuzzy Hash: C4414D32B2864586E7B88F16D4B037D63A1FB86B90F54817ADA4D43794CE3ED8468F01
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: InfoParametersSystem$memset
                                                      • String ID:
                                                      • API String ID: 1286410875-0
                                                      • Opcode ID: e44ec2be6f3118a8dd4ff12cd29a88f8288f48b184e9148483e3cd3e0426b2f6
                                                      • Instruction ID: e780bd036ad7af256c70c4646b61f80b9c7531526f6c5baeceb83a61717d6df5
                                                      • Opcode Fuzzy Hash: e44ec2be6f3118a8dd4ff12cd29a88f8288f48b184e9148483e3cd3e0426b2f6
                                                      • Instruction Fuzzy Hash: 12212562B38B828AE7569F71E5646BA6310FF957C0F048336DA0E536A5EF3CD481C601
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Format@@Surface$?has?qt_window_private@@Alpha@Private@@WindowWindow@@@
                                                      • String ID:
                                                      • API String ID: 2148967132-0
                                                      • Opcode ID: a2b6e0dba2f2cd503aee322edd1a4181b1e084a73adc8e307d9233a24995805f
                                                      • Instruction ID: 3a884f96d51643a8767b5aaed7295bf3c55a7b2eee9cbe347c5ce3999436a5ec
                                                      • Opcode Fuzzy Hash: a2b6e0dba2f2cd503aee322edd1a4181b1e084a73adc8e307d9233a24995805f
                                                      • Instruction Fuzzy Hash: 6B21C632B2CB9286EB299F1AE46527AA760FF84BC5F044131EE8E03765CF2CD442C711
                                                      APIs
                                                        • Part of subcall function 00007FFDE66C5438: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,00007FFDE6601D3E,?,?,?,00007FFDE6601FED), ref: 00007FFDE66C5452
                                                      • ?shareHandle@QOpenGLContext@@QEBAPEAVQPlatformOpenGLContext@@XZ.QT5GUI ref: 00007FFDE660968A
                                                      • ?format@QOpenGLContext@@QEBA?AVQSurfaceFormat@@XZ.QT5GUI ref: 00007FFDE660969B
                                                        • Part of subcall function 00007FFDE66099B0: ??0QPlatformOpenGLContext@@QEAA@XZ.QT5GUI ref: 00007FFDE66099E1
                                                        • Part of subcall function 00007FFDE66099B0: ??0QSurfaceFormat@@QEAA@XZ.QT5GUI ref: 00007FFDE6609A01
                                                        • Part of subcall function 00007FFDE66099B0: ??4QSurfaceFormat@@QEAAAEAV0@AEBV0@@Z.QT5GUI ref: 00007FFDE6609A57
                                                        • Part of subcall function 00007FFDE66099B0: ??1QSurfaceFormat@@QEAA@XZ.QT5GUI ref: 00007FFDE6609A62
                                                        • Part of subcall function 00007FFDE66099B0: ?majorVersion@QSurfaceFormat@@QEBAHXZ.QT5GUI ref: 00007FFDE6609A8D
                                                        • Part of subcall function 00007FFDE66099B0: ?minorVersion@QSurfaceFormat@@QEBAHXZ.QT5GUI ref: 00007FFDE6609A9A
                                                        • Part of subcall function 00007FFDE66099B0: ??0QMessageLogger@@QEAA@PEBDH0@Z.QT5CORE ref: 00007FFDE6609ABB
                                                        • Part of subcall function 00007FFDE66099B0: ?warning@QMessageLogger@@QEBAXPEBDZZ.QT5CORE ref: 00007FFDE6609ACB
                                                      • ??1QSurfaceFormat@@QEAA@XZ.QT5GUI ref: 00007FFDE66096BA
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Format@@Surface$Context@@Open$Logger@@MessagePlatformVersion@$?format@?major?minor?share?warning@Handle@V0@@malloc
                                                      • String ID:
                                                      • API String ID: 2180580702-0
                                                      • Opcode ID: 596f8952e4bb5d73bfd5cef66d0b0214319bac7651d0922c452e6b5805acfcbd
                                                      • Instruction ID: 3ed6a5582d4018937d5d5e540dcf19c5f3cddeaed59e9ec42b0f74da41eece4e
                                                      • Opcode Fuzzy Hash: 596f8952e4bb5d73bfd5cef66d0b0214319bac7651d0922c452e6b5805acfcbd
                                                      • Instruction Fuzzy Hash: 7BF06221B29B8185DB04AB42F9541A9A371FB89FC0F884178EF4D47B59DF3CD155CB00
                                                      APIs
                                                      • ?formatWindowTitle@QPlatformWindow@@KA?AVQString@@AEBV2@0@Z.QT5GUI ref: 00007FFDE65C8A2F
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65C8A3A
                                                        • Part of subcall function 00007FFDE65C46C0: ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ.QT5CORE ref: 00007FFDE65C46D5
                                                        • Part of subcall function 00007FFDE65C46C0: ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ.QT5GUI ref: 00007FFDE65C46EB
                                                        • Part of subcall function 00007FFDE65C46C0: ??0QMessageLogger@@QEAA@PEBDH00@Z.QT5CORE ref: 00007FFDE65C4734
                                                        • Part of subcall function 00007FFDE65C46C0: ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ.QT5CORE ref: 00007FFDE65C4745
                                                        • Part of subcall function 00007FFDE65C46C0: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE ref: 00007FFDE65C4755
                                                        • Part of subcall function 00007FFDE65C46C0: ??6@YA?AVQDebug@@V0@PEBVQPlatformSurface@@@Z.QT5GUI ref: 00007FFDE65C4779
                                                        • Part of subcall function 00007FFDE65C46C0: ??6@YA?AVQDebug@@V0@PEBVQWindow@@@Z.QT5GUI ref: 00007FFDE65C478D
                                                        • Part of subcall function 00007FFDE65C46C0: ??6QDebug@@QEAAAEAV0@AEBVQString@@@Z.QT5CORE ref: 00007FFDE65C4799
                                                        • Part of subcall function 00007FFDE65C46C0: ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE65C47A7
                                                        • Part of subcall function 00007FFDE65C46C0: ??1QDebug@@QEAA@XZ.QT5CORE ref: 00007FFDE65C47B5
                                                        • Part of subcall function 00007FFDE65C46C0: ?utf16@QString@@QEBAPEBGXZ.QT5CORE ref: 00007FFDE65C47C3
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65C8A52
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$PlatformWindow@@$??1?$??6@F@@@@Logger@@MessagePointString@@Vector@$?debug@?format?utf16@?window@Category@@DebugEnabled@H00@LoggingString@@@Surface@@@Title@V2@0@WindowWindow@@@
                                                      • String ID:
                                                      • API String ID: 291269221-0
                                                      • Opcode ID: 029b53536b1ea568c88798745a62f61859a4898cedd47eeca0ae926b488d10e8
                                                      • Instruction ID: e57bb09498d18e3969550b99eabc9488b7b849a170cc85fc47b72d3d50c8e2ea
                                                      • Opcode Fuzzy Hash: 029b53536b1ea568c88798745a62f61859a4898cedd47eeca0ae926b488d10e8
                                                      • Instruction Fuzzy Hash: C6E06D61B38D0292DB14AB10F8641A9B330FBC5340F500036D78D02624EF3DC59DCB40
                                                      APIs
                                                      • malloc.API-MS-WIN-CRT-HEAP-L1-1-0 ref: 00007FFDE64DBA22
                                                      • Concurrency::cancel_current_task.LIBCPMT ref: 00007FFDE64DBA38
                                                        • Part of subcall function 00007FFDE64DC984: std::bad_alloc::bad_alloc.LIBCMT ref: 00007FFDE64DC98D
                                                        • Part of subcall function 00007FFDE64DC984: _CxxThrowException.VCRUNTIME140(?,?,?,?,00007FFDE64DBA3D), ref: 00007FFDE64DC99E
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3555720521.00007FFDE6261000.00000020.00000001.01000000.0000004B.sdmp, Offset: 00007FFDE6260000, based on PE: true
                                                      • Associated: 00000013.00000002.3555627293.00007FFDE6260000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556069538.00007FFDE64E9000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556171294.00007FFDE658C000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556216248.00007FFDE658D000.00000008.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556258974.00007FFDE6597000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE659A000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE65B1000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde6260000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Concurrency::cancel_current_taskExceptionThrowmallocstd::bad_alloc::bad_alloc
                                                      • String ID:
                                                      • API String ID: 514126270-0
                                                      • Opcode ID: e0a41e9e1c817caded6259df2d816321365f7074e501092f8fc553581fbd9cf8
                                                      • Instruction ID: 835c840401b341d393a5a4a4b97009cfdc9eb961a392ef3d5a63fe24e08b59a2
                                                      • Opcode Fuzzy Hash: e0a41e9e1c817caded6259df2d816321365f7074e501092f8fc553581fbd9cf8
                                                      • Instruction Fuzzy Hash: 72F08C90F7D70B81FE6D26A624727B401484F097B0F581230DDBD097C2EE1CA49E8212
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Locker@@Mutex$BasicMutex@@@
                                                      • String ID:
                                                      • API String ID: 3817361708-0
                                                      • Opcode ID: 7802b24bcf47b61930f2fe5ebf90211d724929a7d7150a1e422998b969c96c4f
                                                      • Instruction ID: 276363987a00445c0c7152afb4a2760a5a75da5e39bc0859b8958bf443e844b8
                                                      • Opcode Fuzzy Hash: 7802b24bcf47b61930f2fe5ebf90211d724929a7d7150a1e422998b969c96c4f
                                                      • Instruction Fuzzy Hash: 82016D31B2594681EF599F29D4A03B823A0FF84F48F9C9035CE5D4B664DE2CD499C711
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: ChildForegroundWindow
                                                      • String ID:
                                                      • API String ID: 2801720684-0
                                                      • Opcode ID: 26b5bc5100834bfd0020484f5f822c229d46b0f455182c442028c8d505e910b2
                                                      • Instruction ID: c13b88fc8858ac35a57f04c8dab466bf982014cf4e89e20603b082114cc1759d
                                                      • Opcode Fuzzy Hash: 26b5bc5100834bfd0020484f5f822c229d46b0f455182c442028c8d505e910b2
                                                      • Instruction Fuzzy Hash: 21E0EC91F26602C2EF2A5BB2A4562391391AF58B91B4C9079CD1D0A380EE1CD9F69B15
                                                      APIs
                                                      • DefWindowProcW.USER32 ref: 00007FFDE660E1B3
                                                        • Part of subcall function 00007FFDE660E660: ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ.QT5CORE(?,?,?,?,?,?,?,?,?,00007FFDE660E19D), ref: 00007FFDE660E6A4
                                                        • Part of subcall function 00007FFDE660E660: ??0QMessageLogger@@QEAA@PEBDH00@Z.QT5CORE(?,?,?,?,?,?,?,?,?,00007FFDE660E19D), ref: 00007FFDE660E6C9
                                                        • Part of subcall function 00007FFDE660E660: ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,00007FFDE660E19D), ref: 00007FFDE660E6DA
                                                        • Part of subcall function 00007FFDE660E660: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,?,?,?,?,00007FFDE660E19D), ref: 00007FFDE660E6EA
                                                        • Part of subcall function 00007FFDE660E660: ??6QDebug@@QEAAAEAV0@PEBX@Z.QT5CORE(?,?,?,?,?,?,?,?,?,00007FFDE660E19D), ref: 00007FFDE660E6F6
                                                        • Part of subcall function 00007FFDE660E660: ??6QDebug@@QEAAAEAV0@I@Z.QT5CORE(?,?,?,?,?,?,?,?,?,00007FFDE660E19D), ref: 00007FFDE660E701
                                                        • Part of subcall function 00007FFDE660E660: ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,?,?,?,?,00007FFDE660E19D), ref: 00007FFDE660E717
                                                        • Part of subcall function 00007FFDE660E660: ??1QDebug@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,00007FFDE660E19D), ref: 00007FFDE660E725
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$Logger@@Message$?debug@Category@@DebugEnabled@H00@LoggingProcWindow
                                                      • String ID:
                                                      • API String ID: 4190882994-0
                                                      • Opcode ID: f237070b9c2fedb484a0c3b0116f8de235f850488dc1c3847ace52c3b67d6e98
                                                      • Instruction ID: 86686554c95814d154703e5dd4e48598bedd9628e6bb0f7b9f91cb138b5d1736
                                                      • Opcode Fuzzy Hash: f237070b9c2fedb484a0c3b0116f8de235f850488dc1c3847ace52c3b67d6e98
                                                      • Instruction Fuzzy Hash: 7701AD31B38B5184EB588F03A8587697364BB89FD0F1840B4EF6D07745CF39D8518780
                                                      APIs
                                                        • Part of subcall function 00007FFDE65C7CB0: ?parent@QPlatformWindow@@QEBAPEAV1@XZ.QT5GUI ref: 00007FFDE65C7CCA
                                                        • Part of subcall function 00007FFDE65C7CB0: ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ.QT5CORE ref: 00007FFDE65C7E19
                                                        • Part of subcall function 00007FFDE65C7CB0: ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ.QT5GUI ref: 00007FFDE65C7E32
                                                        • Part of subcall function 00007FFDE65C7CB0: ??0QMessageLogger@@QEAA@PEBDH00@Z.QT5CORE ref: 00007FFDE65C7E56
                                                      • ?window@QPlatformWindow@@QEBAPEAVQWindow@@XZ.QT5GUI ref: 00007FFDE65D2E96
                                                        • Part of subcall function 00007FFDE65D41E0: ?mouseButtons@QGuiApplication@@SA?AV?$QFlags@W4MouseButton@Qt@@@@XZ.QT5GUI ref: 00007FFDE65D4214
                                                        • Part of subcall function 00007FFDE65D41E0: GetKeyState.USER32 ref: 00007FFDE65D424B
                                                        • Part of subcall function 00007FFDE65D41E0: GetKeyState.USER32 ref: 00007FFDE65D4261
                                                        • Part of subcall function 00007FFDE65D41E0: GetKeyState.USER32 ref: 00007FFDE65D4275
                                                        • Part of subcall function 00007FFDE65D41E0: GetKeyState.USER32 ref: 00007FFDE65D4289
                                                        • Part of subcall function 00007FFDE65D41E0: GetKeyState.USER32 ref: 00007FFDE65D4299
                                                        • Part of subcall function 00007FFDE65D41E0: GetCursorPos.USER32 ref: 00007FFDE65D42AC
                                                        • Part of subcall function 00007FFDE65D41E0: ?mimeData@QDrag@@QEBAPEAVQMimeData@@XZ.QT5GUI ref: 00007FFDE65D42BD
                                                        • Part of subcall function 00007FFDE65D41E0: ?contains@QRect@@QEBA_NAEBVQPoint@@_N@Z.QT5CORE ref: 00007FFDE65D42FF
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: StateWindow@@$Platform$?window@$?contains@?mime?mouse?parent@Application@@Button@Buttons@Category@@CursorData@Data@@DebugDrag@@Enabled@Flags@H00@Logger@@LoggingMessageMimeMousePoint@@_Qt@@@@Rect@@
                                                      • String ID:
                                                      • API String ID: 392526624-0
                                                      • Opcode ID: d26f8b45ceaf17bdd7dbdac9dc026e61c66c7a2169e4f1363112d32ee66bbddc
                                                      • Instruction ID: 3d5a386885a505a8e4bddccc6b212b765253daa113c3c5a6e2bad6a50ce7c641
                                                      • Opcode Fuzzy Hash: d26f8b45ceaf17bdd7dbdac9dc026e61c66c7a2169e4f1363112d32ee66bbddc
                                                      • Instruction Fuzzy Hash: 00E02B27F188C640F61BA729B8223FAA3507FDD399F444531CE4D16691DD3C52C38601
                                                      APIs
                                                      • ?processEvents@QEventDispatcherWin32@@UEAA_NV?$QFlags@W4ProcessEventsFlag@QEventLoop@@@@@Z.QT5CORE ref: 00007FFDE6622E03
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Event$?processDispatcherEventsEvents@Flag@Flags@Loop@@@@@ProcessWin32@@
                                                      • String ID:
                                                      • API String ID: 2620541275-0
                                                      • Opcode ID: 8ff145d08129beb539db3cb25845c5ac3e69f4d3d0fee210a184e1f1fa45f2bb
                                                      • Instruction ID: 72d3bcd37d8e09214d4b8a9fac86ad2e849cae28fc417658b7cc3a38dcffe58c
                                                      • Opcode Fuzzy Hash: 8ff145d08129beb539db3cb25845c5ac3e69f4d3d0fee210a184e1f1fa45f2bb
                                                      • Instruction Fuzzy Hash: 3AD05272A28780C7DB088F2AF1800287A30F74CB84B248528EB680B714CB38C4A28B00
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: ?sendDispatcherEventEvents@PostedWin32@@
                                                      • String ID:
                                                      • API String ID: 1915275062-0
                                                      • Opcode ID: 8f887733a229c8b6779a9907fe956cc205143ba2c7ac6bdae95a8b486f16abf4
                                                      • Instruction ID: e4ce9a8a3d0bf890445bd0ee71eeadcca5f2d2864889a7bc346241ba092edc95
                                                      • Opcode Fuzzy Hash: 8f887733a229c8b6779a9907fe956cc205143ba2c7ac6bdae95a8b486f16abf4
                                                      • Instruction Fuzzy Hash: 18C04C61B35A4AC2E72C6B65A4655242B20FB5CB19B041478CA1509251CE38A4A58B45
                                                      APIs
                                                      • ??0QMessageLogger@@QEAA@PEBDH00@Z.QT5CORE(?,?,?,?,?,?,?,?,?,00007FFDE660E19D), ref: 00007FFDE660E6C9
                                                      • ?debug@QMessageLogger@@QEBA?AVQDebug@@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,00007FFDE660E19D), ref: 00007FFDE660E6DA
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,?,?,?,?,00007FFDE660E19D), ref: 00007FFDE660E6EA
                                                      • ??6QDebug@@QEAAAEAV0@PEBX@Z.QT5CORE(?,?,?,?,?,?,?,?,?,00007FFDE660E19D), ref: 00007FFDE660E6F6
                                                      • ??6QDebug@@QEAAAEAV0@I@Z.QT5CORE(?,?,?,?,?,?,?,?,?,00007FFDE660E19D), ref: 00007FFDE660E701
                                                      • ??6QDebug@@QEAAAEAV0@PEBD@Z.QT5CORE(?,?,?,?,?,?,?,?,?,00007FFDE660E19D), ref: 00007FFDE660E717
                                                      • ??1QDebug@@QEAA@XZ.QT5CORE(?,?,?,?,?,?,?,?,?,00007FFDE660E19D), ref: 00007FFDE660E725
                                                        • Part of subcall function 00007FFDE660E550: IsHungAppWindow.USER32 ref: 00007FFDE660E576
                                                        • Part of subcall function 00007FFDE660E550: ??0QMessageLogger@@QEAA@PEBDH0@Z.QT5CORE(?,?,?,?,?,?,?,00000000,?,00007FFDE660E84A), ref: 00007FFDE660E58D
                                                        • Part of subcall function 00007FFDE660E550: ?warning@QMessageLogger@@QEBAXPEBDZZ.QT5CORE(?,?,?,?,?,?,?,00000000,?,00007FFDE660E84A), ref: 00007FFDE660E59D
                                                      • ?isDebugEnabled@QLoggingCategory@@QEBA_NXZ.QT5CORE(?,?,?,?,?,?,?,?,?,00007FFDE660E19D), ref: 00007FFDE660E6A4
                                                        • Part of subcall function 00007FFDE65CF660: ??0QLoggingCategory@@QEAA@PEBD@Z.QT5CORE(?,?,?,00007FFDE65C607A,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FFDE65CF6BC
                                                        • Part of subcall function 00007FFDE65CF660: _Init_thread_footer.LIBCMT ref: 00007FFDE65CF6D5
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$Logger@@Message$Category@@Logging$?debug@?warning@DebugEnabled@H00@HungInit_thread_footerWindow
                                                      • String ID: Clipboard changed owned $Clipboard owner on shutdown, releasing.$QWindowsClipboard::clipboardViewerWndProc
                                                      • API String ID: 25918406-242487968
                                                      • Opcode ID: 766005927125d58005963d78d461a855204763d2a3d634e5866878825affa51f
                                                      • Instruction ID: 5aad43b21d609437a4b6a90efdd551f86c2f4d489c988aa7efe3b6b275c3e212
                                                      • Opcode Fuzzy Hash: 766005927125d58005963d78d461a855204763d2a3d634e5866878825affa51f
                                                      • Instruction Fuzzy Hash: C5617D25B38A5281EAB8AF65E8347792790FF85F90F40507ED98E43765DE3CE844CB42
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3555720521.00007FFDE6261000.00000020.00000001.01000000.0000004B.sdmp, Offset: 00007FFDE6260000, based on PE: true
                                                      • Associated: 00000013.00000002.3555627293.00007FFDE6260000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556069538.00007FFDE64E9000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556171294.00007FFDE658C000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556216248.00007FFDE658D000.00000008.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556258974.00007FFDE6597000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE659A000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE65B1000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde6260000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: floorf$floorlogfpowf
                                                      • String ID:
                                                      • API String ID: 3428271397-0
                                                      • Opcode ID: 98ac8c8522d400f3b130bdd1033d7cd3e38392ea000e329d33c3aa889c20f390
                                                      • Instruction ID: 5833f9a7be564d5461b0fa8f9114f513bd24ff5946a17c1c2372d3ed63ecd2e6
                                                      • Opcode Fuzzy Hash: 98ac8c8522d400f3b130bdd1033d7cd3e38392ea000e329d33c3aa889c20f390
                                                      • Instruction Fuzzy Hash: A041C222E34ACD05E203573A94426E5E2A59FBE3D5B2DD332F90AB2372EF5475E38150
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Image@@$Buffer@@$ByteF@@@@PointVector@$??1?$$Array@@ImageVariant@@$DataFlag@Flags@Stream@@V0@@Writer@@$Data@Device@@@@@ModeOpen$??0?$?close@?const?open@Data@@Device@@Format@1@Logger@@MessageMimeObject@@@$?can?clear@?convert?convert@?format@?has?image?save@?set?user?warning@?write@A@$$AllocArray@@@Char@@ConversionFormat_helper@GlobalImage@Image@@@Null@Order@Order@1@@Pixmap@@Qt@@@@@String@@Type@V0@$$Write@
                                                      • String ID: PNG$dib$writeDib
                                                      • API String ID: 3715147426-3426277346
                                                      • Opcode ID: d5148702817e0146e2b42edb9c72295da388acf90c45fa1d4d473ca6c62917af
                                                      • Instruction ID: 250761777726b295be70dbb7eff7aa4da06a1b20cd95069bcc1828148575f651
                                                      • Opcode Fuzzy Hash: d5148702817e0146e2b42edb9c72295da388acf90c45fa1d4d473ca6c62917af
                                                      • Instruction Fuzzy Hash: 0FB1FA32B38D439AEF18EF61E8A42BC2771EF51B49B804079D90E569A4DF3CE549C742
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: F@@@@PointVector@$??0?$??1?$$Url@@V0@$$V0@@$FontObject$Array@@ByteDataReleaseSelect$?const?data@?resize@Char@@CreateData@DeleteIndirectString@@
                                                      • String ID: name$name
                                                      • API String ID: 408362490-2543285679
                                                      • Opcode ID: f202047968cc1ddeb5b80e25316a4fc69dd555c24d125bc2644021c6544f4455
                                                      • Instruction ID: f1a6a453ae9856466124e66ad7efaf1d3798ae2e651c894c96415d0505c8cd2f
                                                      • Opcode Fuzzy Hash: f202047968cc1ddeb5b80e25316a4fc69dd555c24d125bc2644021c6544f4455
                                                      • Instruction Fuzzy Hash: 8E419131738D4392EB28AF21E8787696720FF94B95F404179C94E47A64DF3CD44ACB81
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Variant@@$AccessibleDebug@@Double@Interface@@$Category@@Interface@Logger@@LoggingMessageString@@$??1?$?accessible?debug@?from?valueAccessible@@DebugEnabled@F@@@@H00@Init_thread_footerPointUtf16@ValueVector@
                                                      • String ID: QWindowsUiaValueProvider::SetValue
                                                      • API String ID: 3285102841-968588182
                                                      • Opcode ID: dfd4eac8e00a229b9fce59fe1f6bb281211395d040fff2786ddf9ad696dd22c3
                                                      • Instruction ID: 3ec3b63b86333799210a788f1989cb49bb4b175bc5fbb479adfc82680f3eb306
                                                      • Opcode Fuzzy Hash: dfd4eac8e00a229b9fce59fe1f6bb281211395d040fff2786ddf9ad696dd22c3
                                                      • Instruction Fuzzy Hash: 4551A321B38F8681EB24AB25E4643B96360FFC8B95F45517ADA8E03764DF3CD449CB01
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$??6@Category@@Logger@@LoggingMessagePlatformWindow@@$?debug@?utf16@?window@DebugEnabled@H00@Init_thread_footerString@@String@@@Surface@@@Window@@@
                                                      • String ID: QWindowsBaseWindow::setWindowTitle_sys$qt.qpa.windows
                                                      • API String ID: 814419906-904038653
                                                      • Opcode ID: 48c28d6347392fdda280da1208468e51f24131fea4aafe5e37b78308e14344cb
                                                      • Instruction ID: dcb16d074085782b1530c77d929962423e98691299f515c3022adf666b2ba0bb
                                                      • Opcode Fuzzy Hash: 48c28d6347392fdda280da1208468e51f24131fea4aafe5e37b78308e14344cb
                                                      • Instruction Fuzzy Hash: 02415965B38E82C1EA18EB11E8747B93361FB89B95F40517AC90E43B65DE3CE449CB02
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Variant@@$Window@@$Data@Direction@$?const?convert@?layout?maximum?mime?parent@?property@?transient?userApplication@@Data@@Drag@@LayoutLevel@MimeObject@@Parent@Qt@@Size@Size@@Type@
                                                      • String ID: _q_embedded_native_parent_handle
                                                      • API String ID: 1057164265-2428979625
                                                      • Opcode ID: c674e6ab1bb6eed441568cc88b754450df16efd0611285cc4150083117391a2d
                                                      • Instruction ID: 177fdb0e8e3215791cdba58a98605bfe619eed4bd774f590ed4d32210b080a3c
                                                      • Opcode Fuzzy Hash: c674e6ab1bb6eed441568cc88b754450df16efd0611285cc4150083117391a2d
                                                      • Instruction Fuzzy Hash: E0A18C32F2874296FB2E8B15D5643383AA0FB95750F548839C74E43AD0CF7CA5A5CB52
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$Logger@@Message$?debug@AddressCategory@@DebugEnabled@H00@LoggingProc
                                                      • String ID: QWindowsGLContext::getProcAddress$returns
                                                      • API String ID: 1793023957-3961840436
                                                      • Opcode ID: eab044d0b9a8caff55ddd265622ac5dd9825c4339ce591fd5981e90f438bfce2
                                                      • Instruction ID: aa349ae4410c2d6e3c83199a45e6a488e97ad25941d324bf6d76bf2dd1c09619
                                                      • Opcode Fuzzy Hash: eab044d0b9a8caff55ddd265622ac5dd9825c4339ce591fd5981e90f438bfce2
                                                      • Instruction Fuzzy Hash: 45215C64B39A4281EE58AB21E9382797361BF89FE1B00917DDD1E03769DE3CE4048B02
                                                      APIs
                                                        • Part of subcall function 00007FFDE65FEFD0: ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE(?,?,?,00007FFDE65FA749), ref: 00007FFDE65FF058
                                                        • Part of subcall function 00007FFDE65FEFD0: ?dispose@QListData@@SAXPEAUData@1@@Z.QT5CORE(?,?,?,00007FFDE65FA749), ref: 00007FFDE65FF066
                                                        • Part of subcall function 00007FFDE65FA2A0: ?detach@QListData@@QEAAPEAUData@1@H@Z.QT5CORE ref: 00007FFDE65FA2FC
                                                        • Part of subcall function 00007FFDE65FA2A0: ?dispose@QListData@@SAXPEAUData@1@@Z.QT5CORE ref: 00007FFDE65FA363
                                                        • Part of subcall function 00007FFDE65FA2A0: ??0QRegularExpression@@QEAA@AEBVQString@@V?$QFlags@W4PatternOption@QRegularExpression@@@@@Z.QT5CORE ref: 00007FFDE65FA38E
                                                        • Part of subcall function 00007FFDE65FA2A0: ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65FA398
                                                        • Part of subcall function 00007FFDE65FA2A0: ?lastIndexOf@QString@@QEBAHVQChar@@HW4CaseSensitivity@Qt@@@Z.QT5CORE ref: 00007FFDE65FA3F0
                                                        • Part of subcall function 00007FFDE65FA2A0: ?indexOf@QString@@QEBAHVQChar@@HW4CaseSensitivity@Qt@@@Z.QT5CORE ref: 00007FFDE65FA40F
                                                        • Part of subcall function 00007FFDE65FA2A0: ??0?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65FA41C
                                                      • ??0QByteArray@@QEAA@AEBV0@@Z.QT5CORE ref: 00007FFDE65FA809
                                                      • ?startsWith@QString@@QEBA_NVQStringView@@W4CaseSensitivity@Qt@@@Z.QT5CORE ref: 00007FFDE65FA852
                                                      • ?lastIndexOf@QString@@QEBAHVQChar@@HW4CaseSensitivity@Qt@@@Z.QT5CORE ref: 00007FFDE65FA875
                                                      • ?truncate@QString@@QEAAXH@Z.QT5CORE ref: 00007FFDE65FA889
                                                      • ?back@QString@@QEAA?AVQCharRef@@XZ.QT5CORE ref: 00007FFDE65FA8AD
                                                      • ?isSpace@QCharRef@@QEBA_NXZ.QT5CORE ref: 00007FFDE65FA8B6
                                                      • ?chop@QString@@QEAAXH@Z.QT5CORE ref: 00007FFDE65FA8CD
                                                      • ?toWCharArray@QString@@QEBAHPEA_W@Z.QT5CORE ref: 00007FFDE65FA8EF
                                                      • ?toWCharArray@QString@@QEBAHPEA_W@Z.QT5CORE ref: 00007FFDE65FA921
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65FA93F
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65FAA01
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE65FAA0A
                                                      • ?dispose@QListData@@SAXPEAUData@1@@Z.QT5CORE ref: 00007FFDE65FAA25
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: String@@$F@@@@PointVector@$??1?$$CaseCharData@@ListQt@@@Sensitivity@$?dispose@Char@@Data@1@@$?lastArray@IndexRef@@Regular$??0?$?back@?chop@?detach@?index?starts?truncate@Array@@ByteData@1@Expression@@Expression@@@@@Flags@Option@PatternSpace@StringV0@@View@@With@
                                                      • String ID:
                                                      • API String ID: 1882552654-0
                                                      • Opcode ID: 41a27e97afb371eb4631539d6c597fbc78f9dd5e04ef922690a3c9a2cffb5187
                                                      • Instruction ID: 3c3714c01d9b56836f3c19dcb1a04571bffc4a1414fc6108c198a3ced7f3fec0
                                                      • Opcode Fuzzy Hash: 41a27e97afb371eb4631539d6c597fbc78f9dd5e04ef922690a3c9a2cffb5187
                                                      • Instruction Fuzzy Hash: 2A819232729E85C2EB249F15E8643AE7BA0FB84B95F444135DA8E47B58DF3CD445CB01
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3555720521.00007FFDE6261000.00000020.00000001.01000000.0000004B.sdmp, Offset: 00007FFDE6260000, based on PE: true
                                                      • Associated: 00000013.00000002.3555627293.00007FFDE6260000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556069538.00007FFDE64E9000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556171294.00007FFDE658C000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556216248.00007FFDE658D000.00000008.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556258974.00007FFDE6597000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE659A000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE65B1000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde6260000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: a79a5ff50307944fc6d0220d9787cba067e800f32f91107e73bf16f9512f53f2
                                                      • Instruction ID: 40537a0c0d4b8544baff20952b8c2b1682588523740a21945b39c1f902124cf8
                                                      • Opcode Fuzzy Hash: a79a5ff50307944fc6d0220d9787cba067e800f32f91107e73bf16f9512f53f2
                                                      • Instruction Fuzzy Hash: D4E11462B2E6C681EB288B15D9283BD6361EB44BE0F844672DB6D077C5DF7CE485C302
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3555720521.00007FFDE6261000.00000020.00000001.01000000.0000004B.sdmp, Offset: 00007FFDE6260000, based on PE: true
                                                      • Associated: 00000013.00000002.3555627293.00007FFDE6260000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556069538.00007FFDE64E9000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556171294.00007FFDE658C000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556216248.00007FFDE658D000.00000008.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556258974.00007FFDE6597000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE659A000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE65B1000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde6260000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: floor$floorf$logfpowf
                                                      • String ID:
                                                      • API String ID: 1730306193-0
                                                      • Opcode ID: f6d712cd39dfaa8be2724d63b4306e89799e1521505ceaba7c931f6ca30a3628
                                                      • Instruction ID: 03429a999147f4c0dbb1694a9262cb8466b8d20940017e5709a9574466c0a54b
                                                      • Opcode Fuzzy Hash: f6d712cd39dfaa8be2724d63b4306e89799e1521505ceaba7c931f6ca30a3628
                                                      • Instruction Fuzzy Hash: DEA18A32F18FC985E2179B35A4413FAB364FFA9384F149731EA8962665DF38A191CA01
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3555720521.00007FFDE6261000.00000020.00000001.01000000.0000004B.sdmp, Offset: 00007FFDE6260000, based on PE: true
                                                      • Associated: 00000013.00000002.3555627293.00007FFDE6260000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556069538.00007FFDE64E9000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556171294.00007FFDE658C000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556216248.00007FFDE658D000.00000008.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556258974.00007FFDE6597000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE659A000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE65B1000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde6260000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: floor$floorf$logfpowf
                                                      • String ID:
                                                      • API String ID: 1730306193-0
                                                      • Opcode ID: 6e6eaeb269294beaac16cfc76d1458edf140a37eae3ff75d24be23ec9b5f8488
                                                      • Instruction ID: fbc42f827c6f0f8ee2cfe593ad5d9b571e6bffcd4e89c531138953fa77f2e91f
                                                      • Opcode Fuzzy Hash: 6e6eaeb269294beaac16cfc76d1458edf140a37eae3ff75d24be23ec9b5f8488
                                                      • Instruction Fuzzy Hash: 5C51C122F28F8948F203973694526F9B3549FBE395F099732F94D72172EF2875D68600
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Data@@List$memmove$?dispose@Data@1@Data@1@@$?append@?detach@?detach_grow@U1@@
                                                      • String ID:
                                                      • API String ID: 2768188747-0
                                                      • Opcode ID: d984d501428f855fdd8163f92890c8896e846a38dbed9a549d4327fffc26c634
                                                      • Instruction ID: 6bab3c458d3fa671de575faa2ea87ee6d6762da65f5577b7524e8b1ad0217875
                                                      • Opcode Fuzzy Hash: d984d501428f855fdd8163f92890c8896e846a38dbed9a549d4327fffc26c634
                                                      • Instruction Fuzzy Hash: 5E71BD72B24A8682DA54CF59D4A03BC7361EB80B99F54813ADB1D433A5DF3DE886CB01
                                                      APIs
                                                      • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FFDE62643CA
                                                      • ?good@ios_base@std@@QEBA_NXZ.MSVCP140 ref: 00007FFDE6264459
                                                      • ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ.MSVCP140 ref: 00007FFDE6264479
                                                      • ?good@ios_base@std@@QEBA_NXZ.MSVCP140 ref: 00007FFDE6264489
                                                      • ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP140 ref: 00007FFDE62644D1
                                                      • ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z.MSVCP140 ref: 00007FFDE62644F4
                                                      • ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP140 ref: 00007FFDE6264515
                                                        • Part of subcall function 00007FFDE64DBA08: malloc.API-MS-WIN-CRT-HEAP-L1-1-0 ref: 00007FFDE64DBA22
                                                      • ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z.MSVCP140 ref: 00007FFDE6264551
                                                      • ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ.MSVCP140 ref: 00007FFDE626455B
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3555720521.00007FFDE6261000.00000020.00000001.01000000.0000004B.sdmp, Offset: 00007FFDE6260000, based on PE: true
                                                      • Associated: 00000013.00000002.3555627293.00007FFDE6260000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556069538.00007FFDE64E9000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556171294.00007FFDE658C000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556216248.00007FFDE658D000.00000008.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556258974.00007FFDE6597000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE659A000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE65B1000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde6260000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: D@std@@@std@@U?$char_traits@$?good@ios_base@std@@?sputc@?$basic_streambuf@$?flush@?$basic_ostream@?setstate@?$basic_ios@?sputn@?$basic_streambuf@Osfx@?$basic_ostream@V12@_invalid_parameter_noinfo_noreturnmalloc
                                                      • String ID:
                                                      • API String ID: 927227905-0
                                                      • Opcode ID: 8fa1d60bfa98db925c56696be776bf558fcef409ebe262be8d96dfd661eb5e40
                                                      • Instruction ID: df08d9b087572dc22e34907311da8a2dcd820bef7891690a66b6c9357aee3c71
                                                      • Opcode Fuzzy Hash: 8fa1d60bfa98db925c56696be776bf558fcef409ebe262be8d96dfd661eb5e40
                                                      • Instruction Fuzzy Hash: 84616D22F29A4181EE188F15D1A037D67A0FF85B95F988632CB6E47BE0CF2CD8568341
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3555456661.00007FF6F8011000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00007FF6F8010000, based on PE: true
                                                      • Associated: 00000013.00000002.3555389094.00007FF6F8010000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                      • Associated: 00000013.00000002.3555496022.00007FF6F8013000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                      • Associated: 00000013.00000002.3555543118.00007FF6F8015000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                      • Associated: 00000013.00000002.3555583685.00007FF6F8026000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ff6f8010000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: FormatTime$DateSystem
                                                      • String ID: 2024-05-24 09:31:34.372 Command line: ****************************\CiscoSparkLauncher\CiscoCollabHost.exe ************************$Command line: $HH':'mm':'ss$yyyy'-'MM'-'dd
                                                      • API String ID: 1287002481-4110069246
                                                      • Opcode ID: decc9423b643febfd1fd6e913434b86d0734c1dafc43bd95b90f999db1a7dfb7
                                                      • Instruction ID: ddeace1b4dfd72518b1052145a89206bd8533464077e42572510f638b8092cf0
                                                      • Opcode Fuzzy Hash: decc9423b643febfd1fd6e913434b86d0734c1dafc43bd95b90f999db1a7dfb7
                                                      • Instruction Fuzzy Hash: 5B71BF22B18B8246DB55CB74A4142BAB3A0FF947A4FD48136DA5C837D4EF3CE504D704
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Debug@@$Category@@Logger@@LoggingMessage$?accessible?debug@AccessibleAccessible@@DebugEnabled@H00@Init_thread_footerInterface@Interface@@
                                                      • String ID: QWindowsUiaSelectionProvider::get_CanSelectMultiple
                                                      • API String ID: 1214595972-2130606954
                                                      • Opcode ID: 32e724feca2e2fdc9325cfb10fc830a1323be3cf8c7c453088dcbe6630985c1d
                                                      • Instruction ID: 0e6abb9c9f224766b2f2cf7919a615ce88252108ee4325b57abb5b0d30326362
                                                      • Opcode Fuzzy Hash: 32e724feca2e2fdc9325cfb10fc830a1323be3cf8c7c453088dcbe6630985c1d
                                                      • Instruction Fuzzy Hash: BB213B32B28B4282EB09DF19F4642697761EB88F98F48507ADA4E07765DE3CE445CB01
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3555720521.00007FFDE6261000.00000020.00000001.01000000.0000004B.sdmp, Offset: 00007FFDE6260000, based on PE: true
                                                      • Associated: 00000013.00000002.3555627293.00007FFDE6260000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556069538.00007FFDE64E9000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556171294.00007FFDE658C000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556216248.00007FFDE658D000.00000008.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556258974.00007FFDE6597000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE659A000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE65B1000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde6260000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: _invalid_parameter_noinfo_noreturn$mbstowcs_smemcpymemset
                                                      • String ID:
                                                      • API String ID: 3596927127-0
                                                      • Opcode ID: acb2c82ff6aaf669b8f37382a796be984200b49636989b34d88b75611b354fb7
                                                      • Instruction ID: a73d5eafe530568400cd12b4051548c6d411075cd9808ca41473240cd9a110c3
                                                      • Opcode Fuzzy Hash: acb2c82ff6aaf669b8f37382a796be984200b49636989b34d88b75611b354fb7
                                                      • Instruction Fuzzy Hash: 7581CE32B29B8185EB08DB12E55836DB3A9FB44BD4F948635DF9C07B84DF38D4958340
                                                      APIs
                                                      • ?good@ios_base@std@@QEBA_NXZ.MSVCP140 ref: 00007FFDE626288E
                                                      • ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ.MSVCP140 ref: 00007FFDE62628AE
                                                      • ?good@ios_base@std@@QEBA_NXZ.MSVCP140 ref: 00007FFDE62628BE
                                                      • ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP140 ref: 00007FFDE6262905
                                                      • ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z.MSVCP140 ref: 00007FFDE626292A
                                                      • ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP140 ref: 00007FFDE6262951
                                                      • ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z.MSVCP140 ref: 00007FFDE626298F
                                                      • ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ.MSVCP140 ref: 00007FFDE6262999
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3555720521.00007FFDE6261000.00000020.00000001.01000000.0000004B.sdmp, Offset: 00007FFDE6260000, based on PE: true
                                                      • Associated: 00000013.00000002.3555627293.00007FFDE6260000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556069538.00007FFDE64E9000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556171294.00007FFDE658C000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556216248.00007FFDE658D000.00000008.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556258974.00007FFDE6597000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE659A000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE65B1000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde6260000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: D@std@@@std@@U?$char_traits@$?good@ios_base@std@@?sputc@?$basic_streambuf@$?flush@?$basic_ostream@?setstate@?$basic_ios@?sputn@?$basic_streambuf@Osfx@?$basic_ostream@V12@
                                                      • String ID:
                                                      • API String ID: 1128654252-0
                                                      • Opcode ID: b2d070b1dc154a650f852213fa5daa4b5319097cceee56e7b37b6ee88805e840
                                                      • Instruction ID: ea1bf906c2d514ebf6c40616f57bc2decda31d22d150a7f573bd022aa9629af6
                                                      • Opcode Fuzzy Hash: b2d070b1dc154a650f852213fa5daa4b5319097cceee56e7b37b6ee88805e840
                                                      • Instruction Fuzzy Hash: 9651542271AA8581EB188B1AD6E037CA760FF85FD5B688571CF2E47BE1CF2DD4568301
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Data@@$MimeUrl@@$?dispose@?hasData@1@@ListUrls@$?urls@File@List@LocalUrl@@@@
                                                      • String ID:
                                                      • API String ID: 3266116029-0
                                                      • Opcode ID: da112a5648e50a3df5c5332a4bd219ee44ea3d4c3863c08699f01e09b9f77195
                                                      • Instruction ID: aeedbbbaacddc1debd62756a9818b61d71e694d641b07b8c3fe892ef8e6055eb
                                                      • Opcode Fuzzy Hash: da112a5648e50a3df5c5332a4bd219ee44ea3d4c3863c08699f01e09b9f77195
                                                      • Instruction Fuzzy Hash: 8F41E532B29B4282EE29CF11E4602BDB761FB90BF0B594535DA4E07698CF7CE845C701
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3555720521.00007FFDE6261000.00000020.00000001.01000000.0000004B.sdmp, Offset: 00007FFDE6260000, based on PE: true
                                                      • Associated: 00000013.00000002.3555627293.00007FFDE6260000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556069538.00007FFDE64E9000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556171294.00007FFDE658C000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556216248.00007FFDE658D000.00000008.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556258974.00007FFDE6597000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE659A000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE65B1000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde6260000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: memcpy$_invalid_parameter_noinfo_noreturn
                                                      • String ID:
                                                      • API String ID: 2665656946-0
                                                      • Opcode ID: a6166477727ae10502613f9f9774a576fa2dfbb00f93f5fcca5f1912db5f90f4
                                                      • Instruction ID: e9d88143c7fd05a77222a1393712a1e0d71bcace9378999d70f6a39b51e36aa2
                                                      • Opcode Fuzzy Hash: a6166477727ae10502613f9f9774a576fa2dfbb00f93f5fcca5f1912db5f90f4
                                                      • Instruction Fuzzy Hash: CA61E2B2B18A8181EA189F26E4542AEA361FB44FD0F940631EF5D1BB96DE7CD051C305
                                                      APIs
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: floormallocmemset
                                                      • String ID: Out of memory
                                                      • API String ID: 1159027212-696950042
                                                      • Opcode ID: 459777760f1d6226caff6737066808972053db47eaddedb874dd08c9aa63e8d4
                                                      • Instruction ID: f8322d700a15ec96cb607fa4a6add310a541135a95a84a931a11727d5d75026a
                                                      • Opcode Fuzzy Hash: 459777760f1d6226caff6737066808972053db47eaddedb874dd08c9aa63e8d4
                                                      • Instruction Fuzzy Hash: 1B514F21B38B8586FB1D8B2A9464379B291FFD4BC8F045239DE8A17794DF3DE4428B01
                                                      APIs
                                                      • ?detach_helper@QHashData@@QEAAPEAU1@P6AXPEAUNode@1@PEAX@ZP6AX0@ZHH@Z.QT5CORE ref: 00007FFDE662A70F
                                                      • ?free_helper@QHashData@@QEAAXP6AXPEAUNode@1@@Z@Z.QT5CORE ref: 00007FFDE662A742
                                                      • ??4QByteArray@@QEAAAEAV0@AEBV0@@Z.QT5CORE(?,?,00000000,00000000,?,00007FFDE66266B0), ref: 00007FFDE662A7AB
                                                      • ?willGrow@QHashData@@QEAA_NXZ.QT5CORE(?,?,00000000,00000000,?,00007FFDE66266B0), ref: 00007FFDE662A7C3
                                                      • ?allocateNode@QHashData@@QEAAPEAXH@Z.QT5CORE(?,?,00000000,00000000,?,00007FFDE66266B0), ref: 00007FFDE662A819
                                                      • ??0QByteArray@@QEAA@AEBV0@@Z.QT5CORE(?,?,00000000,00000000,?,00007FFDE66266B0), ref: 00007FFDE662A839
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Data@@Hash$Array@@ByteV0@@$?allocate?detach_helper@?free_helper@?willGrow@Node@Node@1@Node@1@@
                                                      • String ID:
                                                      • API String ID: 308495327-0
                                                      • Opcode ID: e41b4222d9f26eb018a50fd5ab2389ac9d5f6ac2f34e66938019a7548dbe06fd
                                                      • Instruction ID: 61301ab0e7b8a0487618aed38e59e4ae20a617a05d834af47abd706b25eaa051
                                                      • Opcode Fuzzy Hash: e41b4222d9f26eb018a50fd5ab2389ac9d5f6ac2f34e66938019a7548dbe06fd
                                                      • Instruction Fuzzy Hash: 3151A136B24A4182DB58CF06E86413873B1FB88F80B45817ADE5E477A4CF7CE446CB01
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3555720521.00007FFDE6261000.00000020.00000001.01000000.0000004B.sdmp, Offset: 00007FFDE6260000, based on PE: true
                                                      • Associated: 00000013.00000002.3555627293.00007FFDE6260000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556069538.00007FFDE64E9000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556171294.00007FFDE658C000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556216248.00007FFDE658D000.00000008.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556258974.00007FFDE6597000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE659A000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE65B1000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde6260000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: memcpy$memchr
                                                      • String ID:
                                                      • API String ID: 1523488950-0
                                                      • Opcode ID: 273747d02d11efa69633734580752f96f6e010a8f6b5e193a972ef27e900965c
                                                      • Instruction ID: 057e9d36295c55c630e947c7e6f7cfdf982bc484d55f617eba211573b1fb8f70
                                                      • Opcode Fuzzy Hash: 273747d02d11efa69633734580752f96f6e010a8f6b5e193a972ef27e900965c
                                                      • Instruction Fuzzy Hash: A3511462F28B9685EA08DF26E5542AD6764FB44FC4FA88531EF8D17B86DE3CE101C341
                                                      APIs
                                                      Strings
                                                      • 2024-05-24 09:31:34.372 Command line: ****************************\CiscoSparkLauncher\CiscoCollabHost.exe ************************, xrefs: 00007FF6F8011EFF
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3555456661.00007FF6F8011000.00000020.00000001.01000000.0000000A.sdmp, Offset: 00007FF6F8010000, based on PE: true
                                                      • Associated: 00000013.00000002.3555389094.00007FF6F8010000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                      • Associated: 00000013.00000002.3555496022.00007FF6F8013000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                      • Associated: 00000013.00000002.3555543118.00007FF6F8015000.00000004.00000001.01000000.0000000A.sdmpDownload File
                                                      • Associated: 00000013.00000002.3555583685.00007FF6F8026000.00000002.00000001.01000000.0000000A.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ff6f8010000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: CharLowerlstrlen
                                                      • String ID: 2024-05-24 09:31:34.372 Command line: ****************************\CiscoSparkLauncher\CiscoCollabHost.exe ************************
                                                      • API String ID: 1209591262-3518477478
                                                      • Opcode ID: c1cf02e9cc5d1723317c7d3565c6da6131a0355b74d2a8d859d15882c53e57fc
                                                      • Instruction ID: 6abe24854b5a72be778242823e10e79a6f7f932d537d243b67a350d2b3e003ef
                                                      • Opcode Fuzzy Hash: c1cf02e9cc5d1723317c7d3565c6da6131a0355b74d2a8d859d15882c53e57fc
                                                      • Instruction Fuzzy Hash: 09219133A18B4582D7208B61F44402AB7E4FB88BA8F811175EE9D836D4FF3CE545DB08
                                                      APIs
                                                        • Part of subcall function 00007FFDE6264210: ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ.MSVCP140 ref: 00007FFDE626423F
                                                        • Part of subcall function 00007FFDE6264210: ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z.MSVCP140 ref: 00007FFDE626425B
                                                        • Part of subcall function 00007FFDE6264210: ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ.MSVCP140 ref: 00007FFDE6264289
                                                        • Part of subcall function 00007FFDE6262820: ?good@ios_base@std@@QEBA_NXZ.MSVCP140 ref: 00007FFDE626288E
                                                        • Part of subcall function 00007FFDE6262820: ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ.MSVCP140 ref: 00007FFDE62628AE
                                                        • Part of subcall function 00007FFDE6262820: ?good@ios_base@std@@QEBA_NXZ.MSVCP140 ref: 00007FFDE62628BE
                                                        • Part of subcall function 00007FFDE6262820: ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z.MSVCP140 ref: 00007FFDE626298F
                                                        • Part of subcall function 00007FFDE6262820: ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ.MSVCP140 ref: 00007FFDE6262999
                                                        • Part of subcall function 00007FFDE6262820: ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP140 ref: 00007FFDE6262905
                                                        • Part of subcall function 00007FFDE6262820: ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z.MSVCP140 ref: 00007FFDE626292A
                                                        • Part of subcall function 00007FFDE6262820: ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP140 ref: 00007FFDE6262951
                                                      • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z.MSVCP140 ref: 00007FFDE626F4E9
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3555720521.00007FFDE6261000.00000020.00000001.01000000.0000004B.sdmp, Offset: 00007FFDE6260000, based on PE: true
                                                      • Associated: 00000013.00000002.3555627293.00007FFDE6260000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556069538.00007FFDE64E9000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556171294.00007FFDE658C000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556216248.00007FFDE658D000.00000008.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556258974.00007FFDE6597000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE659A000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE65B1000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde6260000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: U?$char_traits@$D@std@@@std@@$?good@ios_base@std@@?sputc@?$basic_streambuf@$??0?$basic_ios@??0?$basic_ostream@??0?$basic_streambuf@??6?$basic_ostream@?flush@?$basic_ostream@?setstate@?$basic_ios@?sputn@?$basic_streambuf@D@std@@@1@_Osfx@?$basic_ostream@V01@V12@V?$basic_streambuf@
                                                      • String ID: ): $6$Unhandled internal error: $gl::RefCountObjectNoID::release
                                                      • API String ID: 1878008128-816516541
                                                      • Opcode ID: cc72bfa7b5969da904a805edf5544738c0f340da32429961d5203d7d2960ee48
                                                      • Instruction ID: b6ba99068cd38388e2cfc1ab850fd2975d34f465f45f3124e16117144871dcab
                                                      • Opcode Fuzzy Hash: cc72bfa7b5969da904a805edf5544738c0f340da32429961d5203d7d2960ee48
                                                      • Instruction Fuzzy Hash: 54318E31B2DA4582EB19DB11E4A43AE6360FB84B84F809031E74E07BA9DF3CD909CB41
                                                      APIs
                                                        • Part of subcall function 00007FFDE6262820: ?good@ios_base@std@@QEBA_NXZ.MSVCP140 ref: 00007FFDE626288E
                                                        • Part of subcall function 00007FFDE6262820: ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ.MSVCP140 ref: 00007FFDE62628AE
                                                        • Part of subcall function 00007FFDE6262820: ?good@ios_base@std@@QEBA_NXZ.MSVCP140 ref: 00007FFDE62628BE
                                                        • Part of subcall function 00007FFDE6262820: ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z.MSVCP140 ref: 00007FFDE626298F
                                                        • Part of subcall function 00007FFDE6262820: ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ.MSVCP140 ref: 00007FFDE6262999
                                                        • Part of subcall function 00007FFDE6262820: ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP140 ref: 00007FFDE6262905
                                                        • Part of subcall function 00007FFDE6262820: ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z.MSVCP140 ref: 00007FFDE626292A
                                                        • Part of subcall function 00007FFDE6262820: ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP140 ref: 00007FFDE6262951
                                                      • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z.MSVCP140 ref: 00007FFDE626416C
                                                      • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z.MSVCP140 ref: 00007FFDE626417C
                                                      • ?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z.MSVCP140 ref: 00007FFDE626418F
                                                      • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@J@Z.MSVCP140 ref: 00007FFDE62641BD
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3555720521.00007FFDE6261000.00000020.00000001.01000000.0000004B.sdmp, Offset: 00007FFDE6260000, based on PE: true
                                                      • Associated: 00000013.00000002.3555627293.00007FFDE6260000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556069538.00007FFDE64E9000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556171294.00007FFDE658C000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556216248.00007FFDE658D000.00000008.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556258974.00007FFDE6597000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE659A000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE65B1000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde6260000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: D@std@@@std@@U?$char_traits@$??6?$basic_ostream@V01@$?good@ios_base@std@@?sputc@?$basic_streambuf@V21@@Vios_base@1@$?flush@?$basic_ostream@?setstate@?$basic_ios@?setw@std@@?sputn@?$basic_streambuf@J@1@_Osfx@?$basic_ostream@Smanip@_U?$_V12@
                                                      • String ID: HRESULT:
                                                      • API String ID: 2062176068-1546305134
                                                      • Opcode ID: 0ded6884a57b0e72f8db3b3fdee80d67f669bc483cb740f57ffb77c006706754
                                                      • Instruction ID: 7a5e2db9401cd85a17a6eb9162da71df2f6696804cda6166f2a85e791d14bd2f
                                                      • Opcode Fuzzy Hash: 0ded6884a57b0e72f8db3b3fdee80d67f669bc483cb740f57ffb77c006706754
                                                      • Instruction Fuzzy Hash: 6D214B26718A8181DB04CF56E8E426DBBB0FB88F91B5AC522DE4D43764CF3CD45AC341
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3555720521.00007FFDE6261000.00000020.00000001.01000000.0000004B.sdmp, Offset: 00007FFDE6260000, based on PE: true
                                                      • Associated: 00000013.00000002.3555627293.00007FFDE6260000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556069538.00007FFDE64E9000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556171294.00007FFDE658C000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556216248.00007FFDE658D000.00000008.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556258974.00007FFDE6597000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE659A000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE65B1000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde6260000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: free$memset
                                                      • String ID:
                                                      • API String ID: 2717317152-0
                                                      • Opcode ID: 715d13fd6216564ad0a86f862e55cd40732c2d79c8975cba59d5eb083b3ea72c
                                                      • Instruction ID: 4c631d0246b7f138ee3f133ce69fb780683103d32a4ca2aa17c2701b371a2592
                                                      • Opcode Fuzzy Hash: 715d13fd6216564ad0a86f862e55cd40732c2d79c8975cba59d5eb083b3ea72c
                                                      • Instruction Fuzzy Hash: 26319F72B18B818AE629CF16E5502ADB7A4FB58B94B488036DF9D47790DF3CE4A5C340
                                                      APIs
                                                        • Part of subcall function 00007FFDE662AEB0: ??M@YA_NAEBVQString@@0@Z.QT5CORE(?,?,FFFFFFFF00000060,00007FFDE662A5BE), ref: 00007FFDE662AEE7
                                                        • Part of subcall function 00007FFDE662AEB0: ??M@YA_NAEBVQString@@0@Z.QT5CORE(?,?,FFFFFFFF00000060,00007FFDE662A5BE), ref: 00007FFDE662AF0F
                                                        • Part of subcall function 00007FFDE662A5A0: ??M@YA_NAEBVQString@@0@Z.QT5CORE ref: 00007FFDE662A60A
                                                        • Part of subcall function 00007FFDE662A5A0: ??M@YA_NAEBVQString@@0@Z.QT5CORE ref: 00007FFDE662A638
                                                        • Part of subcall function 00007FFDE662A5A0: ?createNode@QMapDataBase@@QEAAPEAUQMapNodeBase@@HHPEAU2@_N@Z.QT5CORE ref: 00007FFDE662A661
                                                        • Part of subcall function 00007FFDE662A5A0: ??0QByteArray@@QEAA@AEBV0@@Z.QT5CORE ref: 00007FFDE662A671
                                                      • RemoveFontMemResourceEx.GDI32 ref: 00007FFDE6628789
                                                        • Part of subcall function 00007FFDE662ADA0: ?createData@QMapDataBase@@SAPEAU1@XZ.QT5CORE(?,?,?,00007FFDE662A5B3), ref: 00007FFDE662ADB8
                                                        • Part of subcall function 00007FFDE662ADA0: ?recalcMostLeftNode@QMapDataBase@@QEAAXXZ.QT5CORE(?,?,?,00007FFDE662A5B3), ref: 00007FFDE662AE0E
                                                      • ??M@YA_NAEBVQString@@0@Z.QT5CORE ref: 00007FFDE66287B7
                                                      • ??M@YA_NAEBVQString@@0@Z.QT5CORE ref: 00007FFDE66287DF
                                                      • ??1?$QVector@VQPointF@@@@QEAA@XZ.QT5CORE ref: 00007FFDE66287F0
                                                      • ?freeNodeAndRebalance@QMapDataBase@@QEAAXPEAUQMapNodeBase@@@Z.QT5CORE ref: 00007FFDE66287FC
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: String@@0@$Base@@$Data$Node$?createNode@$??1?$?free?recalcArray@@Base@@@ByteData@F@@@@FontLeftMostPointRebalance@RemoveResourceU2@_V0@@Vector@
                                                      • String ID:
                                                      • API String ID: 1151704109-0
                                                      • Opcode ID: 7211b0835ff32432ff2993d2e5509ebce5cd98dd6148770e9300d73a4884695d
                                                      • Instruction ID: a40ce76ac5238fc5ae68e8123f79c09c75ff61b784599a620573f5ad7e47cd45
                                                      • Opcode Fuzzy Hash: 7211b0835ff32432ff2993d2e5509ebce5cd98dd6148770e9300d73a4884695d
                                                      • Instruction Fuzzy Hash: 3B216D21B38A4192EF589F12D864279A761FF89FE0B488079DE0D07795DF3CE446CB01
                                                      APIs
                                                      • memcpy.VCRUNTIME140 ref: 00007FFDE6263D27
                                                      • memcpy.VCRUNTIME140 ref: 00007FFDE6263DE3
                                                      • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FFDE6263E3E
                                                      • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FFDE6263509), ref: 00007FFDE6263EDD
                                                        • Part of subcall function 00007FFDE64DBA08: malloc.API-MS-WIN-CRT-HEAP-L1-1-0 ref: 00007FFDE64DBA22
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3555720521.00007FFDE6261000.00000020.00000001.01000000.0000004B.sdmp, Offset: 00007FFDE6260000, based on PE: true
                                                      • Associated: 00000013.00000002.3555627293.00007FFDE6260000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556069538.00007FFDE64E9000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556171294.00007FFDE658C000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556216248.00007FFDE658D000.00000008.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556258974.00007FFDE6597000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE659A000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE65B1000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde6260000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: _invalid_parameter_noinfo_noreturnmemcpy$malloc
                                                      • String ID:
                                                      • API String ID: 3903695586-0
                                                      • Opcode ID: 421bcb884b86acf8ea6c2f2361bb51554efe7a0662e03c6fe490d60487f519e1
                                                      • Instruction ID: b09bf883da767987555040ef322e10a545a7ad0e0e6704743400aabfab801037
                                                      • Opcode Fuzzy Hash: 421bcb884b86acf8ea6c2f2361bb51554efe7a0662e03c6fe490d60487f519e1
                                                      • Instruction Fuzzy Hash: A451ED22B29A8684EA189F15E1643BD62A1EF18FD4F949531DB5D07BC9DF3CD8908381
                                                      APIs
                                                        • Part of subcall function 00007FFDE6262820: ?good@ios_base@std@@QEBA_NXZ.MSVCP140 ref: 00007FFDE626288E
                                                        • Part of subcall function 00007FFDE6262820: ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ.MSVCP140 ref: 00007FFDE62628AE
                                                        • Part of subcall function 00007FFDE6262820: ?good@ios_base@std@@QEBA_NXZ.MSVCP140 ref: 00007FFDE62628BE
                                                        • Part of subcall function 00007FFDE6262820: ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z.MSVCP140 ref: 00007FFDE626298F
                                                        • Part of subcall function 00007FFDE6262820: ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ.MSVCP140 ref: 00007FFDE6262999
                                                      • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z.MSVCP140 ref: 00007FFDE62913EA
                                                      • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z.MSVCP140 ref: 00007FFDE62913FA
                                                      • ?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z.MSVCP140 ref: 00007FFDE629140D
                                                      • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@I@Z.MSVCP140 ref: 00007FFDE629143B
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3555720521.00007FFDE6261000.00000020.00000001.01000000.0000004B.sdmp, Offset: 00007FFDE6260000, based on PE: true
                                                      • Associated: 00000013.00000002.3555627293.00007FFDE6260000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556069538.00007FFDE64E9000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556171294.00007FFDE658C000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556216248.00007FFDE658D000.00000008.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556258974.00007FFDE6597000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE659A000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE65B1000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde6260000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: D@std@@@std@@U?$char_traits@$??6?$basic_ostream@V01@$?good@ios_base@std@@V21@@Vios_base@1@$?flush@?$basic_ostream@?setstate@?$basic_ios@?setw@std@@J@1@_Osfx@?$basic_ostream@Smanip@_U?$_V12@
                                                      • String ID:
                                                      • API String ID: 2636829267-0
                                                      • Opcode ID: d1c900090ce04fbb96a3a8d1d6bfa3f30079b0b3117ef2dad099226df89c2c56
                                                      • Instruction ID: e2213df784367d9169f8f998bd1fe37a502f7fc53667789f448364dae7b02b09
                                                      • Opcode Fuzzy Hash: d1c900090ce04fbb96a3a8d1d6bfa3f30079b0b3117ef2dad099226df89c2c56
                                                      • Instruction Fuzzy Hash: 68211626718B8182DB04CF5AE8A426DBBB0FB88F91B568522DE4D43768DF38D44AC341
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3555720521.00007FFDE6261000.00000020.00000001.01000000.0000004B.sdmp, Offset: 00007FFDE6260000, based on PE: true
                                                      • Associated: 00000013.00000002.3555627293.00007FFDE6260000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556069538.00007FFDE64E9000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556171294.00007FFDE658C000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556216248.00007FFDE658D000.00000008.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556258974.00007FFDE6597000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE659A000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE65B1000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde6260000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                      • String ID:
                                                      • API String ID: 2933794660-0
                                                      • Opcode ID: 24619ff1d7d6ae63b54812296c237713ede2f56038a43d14f6d9ca25984233e3
                                                      • Instruction ID: 0c645aa6f7ea5ff2f035b1aceb75c2f105a9b70a1a6426bbf1e88e9ef9d8295e
                                                      • Opcode Fuzzy Hash: 24619ff1d7d6ae63b54812296c237713ede2f56038a43d14f6d9ca25984233e3
                                                      • Instruction Fuzzy Hash: 33111C66B28B018AEB008F60E8643A833A4F759758F840E31DA6D46BA4DF78E1588741
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3555720521.00007FFDE6261000.00000020.00000001.01000000.0000004B.sdmp, Offset: 00007FFDE6260000, based on PE: true
                                                      • Associated: 00000013.00000002.3555627293.00007FFDE6260000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556069538.00007FFDE64E9000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556171294.00007FFDE658C000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556216248.00007FFDE658D000.00000008.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556258974.00007FFDE6597000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE659A000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE65B1000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde6260000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID: 0-3916222277
                                                      • Opcode ID: 9cd5680b68dab259abaf7fa77bed9bbb4c299d9ff391b99ce4d90ed3295c5bde
                                                      • Instruction ID: aa2a26428121a8ea51466e1145c48b39ba49b447aff461354419079a92360cab
                                                      • Opcode Fuzzy Hash: 9cd5680b68dab259abaf7fa77bed9bbb4c299d9ff391b99ce4d90ed3295c5bde
                                                      • Instruction Fuzzy Hash: D251B362F29A8582EA189F26E55436DA361FB44FD4F988131DBAC07B8ADF7CD4D1C301
                                                      APIs
                                                      • ?xHeight@QFontEngine@@UEBA?AUQFixed@@XZ.QT5GUI ref: 00007FFDE66387C4
                                                        • Part of subcall function 00007FFDE663B1F0: ?lock@QMutex@@QEAAXXZ.QT5CORE(?,?,?,?,00000000,00007FFDE6636D9B), ref: 00007FFDE663B212
                                                      • ?unlock@QMutex@@QEAAXXZ.QT5CORE ref: 00007FFDE663879E
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3556474603.00007FFDE65C1000.00000020.00000001.01000000.00000048.sdmp, Offset: 00007FFDE65C0000, based on PE: true
                                                      • Associated: 00000013.00000002.3556417371.00007FFDE65C0000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556621994.00007FFDE66C7000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556697302.00007FFDE672A000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556745168.00007FFDE672D000.00000008.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556821722.00007FFDE672E000.00000004.00000001.01000000.00000048.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556862263.00007FFDE6732000.00000002.00000001.01000000.00000048.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde65c0000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: Mutex@@$?lock@?unlock@Engine@@Fixed@@FontHeight@
                                                      • String ID: sfnt-table
                                                      • API String ID: 1682554711-2280818369
                                                      • Opcode ID: 3ecd1b6add57de7350a4e7febb8b4b166191cce6e0a67b9b171463892b19600f
                                                      • Instruction ID: b5540a3a9fd19708f1693d89a50027855ca8daec3f0bd13bd314fc0911750c4a
                                                      • Opcode Fuzzy Hash: 3ecd1b6add57de7350a4e7febb8b4b166191cce6e0a67b9b171463892b19600f
                                                      • Instruction Fuzzy Hash: E6318D22728B4581EF198B1AE8903AD63A2FB88FD4F088179DE4D47795DF3CE441CB01
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000013.00000002.3555720521.00007FFDE6261000.00000020.00000001.01000000.0000004B.sdmp, Offset: 00007FFDE6260000, based on PE: true
                                                      • Associated: 00000013.00000002.3555627293.00007FFDE6260000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556069538.00007FFDE64E9000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556171294.00007FFDE658C000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556216248.00007FFDE658D000.00000008.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556258974.00007FFDE6597000.00000004.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE659A000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      • Associated: 00000013.00000002.3556303755.00007FFDE65B1000.00000002.00000001.01000000.0000004B.sdmpDownload File
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_19_2_7ffde6260000_CiscoCollabHost.jbxd
                                                      Similarity
                                                      • API ID: freemalloc
                                                      • String ID:
                                                      • API String ID: 3061335427-0
                                                      • Opcode ID: ba5379d92e6af001b8a9ed08aa4bfac1f474b6f3d5e4aa54eb01904bffed157c
                                                      • Instruction ID: 2735744e0284bb23a98eb705bd591801fc0bfff97153ff6e9a9e7a31ab7336f9
                                                      • Opcode Fuzzy Hash: ba5379d92e6af001b8a9ed08aa4bfac1f474b6f3d5e4aa54eb01904bffed157c
                                                      • Instruction Fuzzy Hash: E1115E72B28B8081DB448F16E56036CA3A0FB98FC8F589031DB5C4BB58EF38D995C781