Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
forest.exe

Overview

General Information

Sample name:forest.exe
Analysis ID:1513254
MD5:5242f809563eb3764684ef1180adb902
SHA1:491399cc669f92229d4a0c4a418067c5d4a808e8
SHA256:2a3519501362a44a4b122fbf869e195989741525883f07d0fc2d2e5e48fb7fff
Tags:exelibraofficeonline-com
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
AI detected suspicious sample
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to query network adapater information
Contains functionality to record screenshots
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a start menu entry (Start Menu\Programs\Startup)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains an invalid checksum
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: Communication To Uncommon Destination Ports
Sigma detected: Startup Folder File Write
Stores files to the Windows start menu directory

Classification

  • System is w10x64
  • forest.exe (PID: 8152 cmdline: "C:\Users\user\Desktop\forest.exe" MD5: 5242F809563EB3764684EF1180ADB902)
  • forest.exe (PID: 3544 cmdline: "C:\Users\user\Desktop\forest.exe" MD5: 5242F809563EB3764684EF1180ADB902)
  • cleanup
No configs have been found
No yara matches
Source: Network ConnectionAuthor: Florian Roth (Nextron Systems): Data: DestinationIp: 45.66.249.249, DestinationIsIpv6: false, DestinationPort: 8080, EventID: 3, Image: C:\Users\user\Desktop\forest.exe, Initiated: true, ProcessId: 8152, Protocol: tcp, SourceIp: 192.168.2.10, SourceIsIpv6: false, SourcePort: 49707
Source: File createdAuthor: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research): Data: EventID: 11, Image: C:\Users\user\Desktop\forest.exe, ProcessId: 8152, TargetFilename: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WindowsSVC.lnk
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: forest.exeAvira: detected
Source: forest.exeReversingLabs: Detection: 52%
Source: Submited SampleIntegrated Neural Analysis Model: Matched 99.0% probability
Source: forest.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: C:\Users\User\Documents\root\Migratory\Projects\Current\Testing\x64\Release\ClientTest.pdb? source: forest.exe
Source: Binary string: C:\Users\User\Documents\root\Migratory\Projects\Current\Testing\x64\Release\ClientTest.pdb source: forest.exe
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C270D8 FindFirstFileExW,0_2_00007FF7D4C270D8
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BB9C80 GetFullPathNameW,GetFullPathNameW,FindFirstFileExW,GetLastError,FindClose,0_2_00007FF7D4BB9C80
Source: global trafficTCP traffic: 192.168.2.10:49707 -> 45.66.249.249:8080
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: unknownTCP traffic detected without corresponding DNS query: 45.66.249.249
Source: global trafficHTTP traffic detected: GET /sock HTTP/1.1Connection: UpgradeUpgrade: websocketUser-Agent: Where are my socks?Sec-WebSocket-Key: knZ6tsATkpSvprUi2z7eqA==Sec-WebSocket-Version: 13Host: 45.66.249.249:8080
Source: forest.exe, 00000000.00000002.3204034791.000001FB2132E000.00000004.00000020.00020000.00000000.sdmp, 77EC63BDA74BD0D0E0426DC8F80085060.0.drString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
Source: forest.exe, 00000000.00000003.2547402599.000001FB22E13000.00000004.00000020.00020000.00000000.sdmp, forest.exe, 00000000.00000003.2547202351.000001FB22E10000.00000004.00000020.00020000.00000000.sdmp, forest.exe, 00000000.00000002.3204034791.000001FB213EE000.00000004.00000020.00020000.00000000.sdmp, forest.exe, 00000000.00000003.2548428397.000001FB213FB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?87d654460fbca
Source: forest.exe, 00000000.00000002.3204034791.000001FB213EE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en2r
Source: forest.exe, 00000000.00000002.3204034791.000001FB2130B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://45.66.249.249:8443/
Source: forest.exe, 00000000.00000002.3204034791.000001FB213AC000.00000004.00000020.00020000.00000000.sdmp, forest.exe, 00000000.00000002.3204034791.000001FB21365000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://45.66.249.249:8443/bc
Source: forest.exe, 00000000.00000002.3204549332.000001FB22E01000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://45.66.249.249:8443/bc(
Source: forest.exe, 00000000.00000002.3204034791.000001FB2135C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://45.66.249.249:8443/bcG
Source: forest.exe, 00000000.00000002.3204034791.000001FB21365000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://45.66.249.249:8443/bcJ
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BBE9E0 GdiplusStartup,GetDesktopWindow,GetDC,CreateCompatibleDC,GetDesktopWindow,GetClientRect,CreateCompatibleBitmap,SelectObject,BitBlt,GdipAlloc,GdipCreateBitmapFromHBITMAP,GdipGetImageEncodersSize,SelectObject,DeleteObject,DeleteObject,GetDesktopWindow,ReleaseDC,GdiplusShutdown,GdipGetImageEncoders,SelectObject,DeleteObject,DeleteObject,GetDesktopWindow,ReleaseDC,GdiplusShutdown,CreateStreamOnHGlobal,GdipSaveImageToStream,SelectObject,DeleteObject,DeleteObject,GetDesktopWindow,ReleaseDC,GdiplusShutdown,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF7D4BBE9E0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BB46D00_2_00007FF7D4BB46D0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BB5EF00_2_00007FF7D4BB5EF0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BB50400_2_00007FF7D4BB5040
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BC7B000_2_00007FF7D4BC7B00
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BFC59C0_2_00007FF7D4BFC59C
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C165BC0_2_00007FF7D4C165BC
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C205280_2_00007FF7D4C20528
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BF869C0_2_00007FF7D4BF869C
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BEB6640_2_00007FF7D4BEB664
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C0F6880_2_00007FF7D4C0F688
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BFD68C0_2_00007FF7D4BFD68C
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C0262C0_2_00007FF7D4C0262C
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C2C7E80_2_00007FF7D4C2C7E8
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BF68040_2_00007FF7D4BF6804
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BE87FC0_2_00007FF7D4BE87FC
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C2B7BC0_2_00007FF7D4C2B7BC
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BC57800_2_00007FF7D4BC5780
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C101E40_2_00007FF7D4C101E4
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BB92000_2_00007FF7D4BB9200
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BD61C00_2_00007FF7D4BD61C0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C2A1700_2_00007FF7D4C2A170
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C1C1880_2_00007FF7D4C1C188
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C0C1780_2_00007FF7D4C0C178
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BBC3000_2_00007FF7D4BBC300
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C0F2B80_2_00007FF7D4C0F2B8
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C1B2C00_2_00007FF7D4C1B2C0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BB72600_2_00007FF7D4BB7260
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BE22700_2_00007FF7D4BE2270
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C262840_2_00007FF7D4C26284
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BF22300_2_00007FF7D4BF2230
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C202240_2_00007FF7D4C20224
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BF44040_2_00007FF7D4BF4404
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BD53700_2_00007FF7D4BD5370
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C0F4A00_2_00007FF7D4C0F4A0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BF947C0_2_00007FF7D4BF947C
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BFE4480_2_00007FF7D4BFE448
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C22DB80_2_00007FF7D4C22DB8
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BE7D1C0_2_00007FF7D4BE7D1C
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BE0D540_2_00007FF7D4BE0D54
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C23D400_2_00007FF7D4C23D40
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BF0EF00_2_00007FF7D4BF0EF0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BF5EC40_2_00007FF7D4BF5EC4
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C01E600_2_00007FF7D4C01E60
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C18F340_2_00007FF7D4C18F34
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BE9F300_2_00007FF7D4BE9F30
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BEC0D80_2_00007FF7D4BEC0D8
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C270D80_2_00007FF7D4C270D8
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C030F00_2_00007FF7D4C030F0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BBA1100_2_00007FF7D4BBA110
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BF50AC0_2_00007FF7D4BF50AC
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C210580_2_00007FF7D4C21058
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BE80180_2_00007FF7D4BE8018
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BCB0400_2_00007FF7D4BCB040
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BBE9E00_2_00007FF7D4BBE9E0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C209D80_2_00007FF7D4C209D8
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C0D9E40_2_00007FF7D4C0D9E4
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BC09A00_2_00007FF7D4BC09A0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BB69C00_2_00007FF7D4BB69C0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C189D00_2_00007FF7D4C189D0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BB59600_2_00007FF7D4BB5960
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BC49400_2_00007FF7D4BC4940
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BBAAFB0_2_00007FF7D4BBAAFB
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C19B000_2_00007FF7D4C19B00
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C16AB40_2_00007FF7D4C16AB4
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BC3AB00_2_00007FF7D4BC3AB0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BBAACF0_2_00007FF7D4BBAACF
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BE7A440_2_00007FF7D4BE7A44
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BBAA430_2_00007FF7D4BBAA43
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BC2BD00_2_00007FF7D4BC2BD0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BBAB7F0_2_00007FF7D4BBAB7F
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BBAB270_2_00007FF7D4BBAB27
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BBAB530_2_00007FF7D4BBAB53
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BBFD100_2_00007FF7D4BBFD10
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C0FCD00_2_00007FF7D4C0FCD0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C28C740_2_00007FF7D4C28C74
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C00C500_2_00007FF7D4C00C50
Source: C:\Users\user\Desktop\forest.exeCode function: String function: 00007FF7D4BCF390 appears 54 times
Source: C:\Users\user\Desktop\forest.exeCode function: String function: 00007FF7D4BCA750 appears 35 times
Source: forest.exeBinary or memory string: OriginalFilename vs forest.exe
Source: forest.exe, 00000000.00000000.1347704637.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenamewmflJ vs forest.exe
Source: forest.exe, 00000006.00000000.2625471977.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenamewmflJ vs forest.exe
Source: forest.exeBinary or memory string: OriginalFilenamewmflJ vs forest.exe
Source: classification engineClassification label: mal60.winEXE@2/3@0/1
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BC09A0 CreateToolhelp32Snapshot,Process32FirstW,WideCharToMultiByte,WideCharToMultiByte,Process32NextW,CloseHandle,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF7D4BC09A0
Source: C:\Users\user\Desktop\forest.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WindowsSVC.lnkJump to behavior
Source: forest.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\forest.exeFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Users\user\Desktop\forest.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: forest.exeReversingLabs: Detection: 52%
Source: unknownProcess created: C:\Users\user\Desktop\forest.exe "C:\Users\user\Desktop\forest.exe"
Source: unknownProcess created: C:\Users\user\Desktop\forest.exe "C:\Users\user\Desktop\forest.exe"
Source: C:\Users\user\Desktop\forest.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: linkinfo.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: ntshrui.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: cscapi.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: webio.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: winnsi.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: websocket.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: schannel.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: mskeyprotect.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: ncryptsslp.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: cryptnet.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: dhcpcsvc6.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: dhcpcsvc.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: fwpuclnt.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: dpapi.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\Desktop\forest.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32Jump to behavior
Source: WindowsSVC.lnk.0.drLNK file: ..\..\..\..\..\..\..\Desktop\forest.exe
Source: forest.exeStatic PE information: Image base 0x140000000 > 0x60000000
Source: forest.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: forest.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: forest.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: forest.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: forest.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: forest.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: forest.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: forest.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: C:\Users\User\Documents\root\Migratory\Projects\Current\Testing\x64\Release\ClientTest.pdb? source: forest.exe
Source: Binary string: C:\Users\User\Documents\root\Migratory\Projects\Current\Testing\x64\Release\ClientTest.pdb source: forest.exe
Source: forest.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: forest.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: forest.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: forest.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: forest.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: forest.exeStatic PE information: real checksum: 0xacdd8 should be: 0xae09f
Source: forest.exeStatic PE information: section name: _RDATA
Source: C:\Users\user\Desktop\forest.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WindowsSVC.lnkJump to behavior
Source: C:\Users\user\Desktop\forest.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WindowsSVC.lnkJump to behavior
Source: C:\Users\user\Desktop\forest.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
Source: C:\Users\user\Desktop\forest.exeCode function: _invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,GetNetworkParams,GlobalAlloc,GetNetworkParams,GetAdaptersInfo,GlobalAlloc,GetAdaptersInfo,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,Concurrency::cancel_current_task,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF7D4BBA110
Source: C:\Users\user\Desktop\forest.exeAPI coverage: 6.1 %
Source: C:\Users\user\Desktop\forest.exe TID: 8156Thread sleep time: -116397s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\forest.exe TID: 3508Thread sleep time: -105793s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\forest.exeLast function: Thread delayed
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C270D8 FindFirstFileExW,0_2_00007FF7D4C270D8
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BB9C80 GetFullPathNameW,GetFullPathNameW,FindFirstFileExW,GetLastError,FindClose,0_2_00007FF7D4BB9C80
Source: C:\Users\user\Desktop\forest.exeThread delayed: delay time: 116397Jump to behavior
Source: C:\Users\user\Desktop\forest.exeThread delayed: delay time: 105793Jump to behavior
Source: forest.exe, 00000000.00000002.3204034791.000001FB21390000.00000004.00000020.00020000.00000000.sdmp, forest.exe, 00000000.00000002.3204034791.000001FB2132E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
Source: forest.exe, 00000000.00000002.3204034791.000001FB2130B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: VBoxService
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C05968 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF7D4C05968
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C04AA4 GetLastError,IsDebuggerPresent,OutputDebugStringW,0_2_00007FF7D4C04AA4
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C288C8 GetProcessHeap,0_2_00007FF7D4C288C8
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C056B8 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF7D4C056B8
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C05968 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF7D4C05968
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C13BC4 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF7D4C13BC4
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C05B48 SetUnhandledExceptionFilter,0_2_00007FF7D4C05B48
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C30280 cpuid 0_2_00007FF7D4C30280
Source: C:\Users\user\Desktop\forest.exeCode function: TranslateName,TranslateName,GetACP,IsValidCodePage,GetLocaleInfoW,0_2_00007FF7D4C2A714
Source: C:\Users\user\Desktop\forest.exeCode function: EnumSystemLocalesW,0_2_00007FF7D4C1E878
Source: C:\Users\user\Desktop\forest.exeCode function: EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,0_2_00007FF7D4C2B148
Source: C:\Users\user\Desktop\forest.exeCode function: GetLocaleInfoW,0_2_00007FF7D4C2AE14
Source: C:\Users\user\Desktop\forest.exeCode function: GetLocaleInfoW,0_2_00007FF7D4C1EDBC
Source: C:\Users\user\Desktop\forest.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,0_2_00007FF7D4C2AF6C
Source: C:\Users\user\Desktop\forest.exeCode function: GetLocaleInfoW,0_2_00007FF7D4C2B01C
Source: C:\Users\user\Desktop\forest.exeCode function: EnumSystemLocalesW,0_2_00007FF7D4C2AA60
Source: C:\Users\user\Desktop\forest.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,0_2_00007FF7D4C2ABC8
Source: C:\Users\user\Desktop\forest.exeCode function: EnumSystemLocalesW,0_2_00007FF7D4C2AB30
Source: C:\Users\user\Desktop\forest.exeCode function: GetLocaleInfoEx,0_2_00007FF7D4BE5C9C
Source: C:\Users\user\Desktop\forest.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C05BB4 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_00007FF7D4C05BB4
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4BB46D0 SHTestTokenMembership,GetUserNameA,GetComputerNameA,GetModuleFileNameW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF7D4BB46D0
Source: C:\Users\user\Desktop\forest.exeCode function: 0_2_00007FF7D4C1FE9C _get_daylight,GetTimeZoneInformation,0_2_00007FF7D4C1FE9C
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation2
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential Dumping2
System Time Discovery
Remote Services1
Screen Capture
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
2
Registry Run Keys / Startup Folder
11
Virtualization/Sandbox Evasion
LSASS Memory1
Query Registry
Remote Desktop Protocol1
Archive Collected Data
1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
DLL Side-Loading
1
Process Injection
Security Account Manager31
Security Software Discovery
SMB/Windows Admin SharesData from Network Shared Drive1
Ingress Tool Transfer
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Deobfuscate/Decode Files or Information
NTDS11
Virtualization/Sandbox Evasion
Distributed Component Object ModelInput Capture1
Non-Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
Obfuscated Files or Information
LSA Secrets1
Process Discovery
SSHKeylogging1
Application Layer Protocol
Scheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
DLL Side-Loading
Cached Domain Credentials1
Account Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup ItemsCompile After DeliveryDCSync1
System Owner/User Discovery
Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/JobIndicator Removal from ToolsProc Filesystem1
System Network Configuration Discovery
Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAtHTML Smuggling/etc/passwd and /etc/shadow2
File and Directory Discovery
Direct Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
IP AddressesCompromise InfrastructureSupply Chain CompromisePowerShellCronCronDynamic API ResolutionNetwork Sniffing32
System Information Discovery
Shared WebrootLocal Data StagingFile Transfer ProtocolsExfiltration Over Asymmetric Encrypted Non-C2 ProtocolExternal Defacement
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
forest.exe53%ReversingLabsWin64.Hacktool.Sysdupate
forest.exe100%AviraTR/Agent.jqxva
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://45.66.249.249:8443/bc(0%Avira URL Cloudsafe
https://45.66.249.249:8443/bcG0%Avira URL Cloudsafe
https://45.66.249.249:8443/0%Avira URL Cloudsafe
https://45.66.249.249:8443/bcJ0%Avira URL Cloudsafe
https://45.66.249.249:8443/bc0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalse
    unknown
    NameSourceMaliciousAntivirus DetectionReputation
    https://45.66.249.249:8443/bcGforest.exe, 00000000.00000002.3204034791.000001FB2135C000.00000004.00000020.00020000.00000000.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://45.66.249.249:8443/bc(forest.exe, 00000000.00000002.3204549332.000001FB22E01000.00000004.00000020.00020000.00000000.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://45.66.249.249:8443/bcJforest.exe, 00000000.00000002.3204034791.000001FB21365000.00000004.00000020.00020000.00000000.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://45.66.249.249:8443/forest.exe, 00000000.00000002.3204034791.000001FB2130B000.00000004.00000020.00020000.00000000.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://45.66.249.249:8443/bcforest.exe, 00000000.00000002.3204034791.000001FB213AC000.00000004.00000020.00020000.00000000.sdmp, forest.exe, 00000000.00000002.3204034791.000001FB21365000.00000004.00000020.00020000.00000000.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    45.66.249.249
    unknownRussian Federation
    53356FREERANGECLOUDCAfalse
    Joe Sandbox version:41.0.0 Charoite
    Analysis ID:1513254
    Start date and time:2024-09-18 17:08:24 +02:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:0h 5m 41s
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:default.jbs
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Run name:Run with higher sleep bypass
    Number of analysed new started processes analysed:7
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • HCA enabled
    • EGA enabled
    • AMSI enabled
    Analysis Mode:default
    Analysis stop reason:Timeout
    Sample name:forest.exe
    Detection:MAL
    Classification:mal60.winEXE@2/3@0/1
    EGA Information:
    • Successful, ratio: 100%
    HCA Information:
    • Successful, ratio: 100%
    • Number of executed functions: 13
    • Number of non-executed functions: 155
    Cookbook Comments:
    • Found application associated with file extension: .exe
    • Sleeps bigger than 100000000ms are automatically reduced to 1000ms
    • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
    • Excluded IPs from analysis (whitelisted): 2.16.100.168, 88.221.110.91, 93.184.221.240
    • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, hlb.apr-52dd2-0.edgecastdns.net, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-b-net.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net
    • Not all processes where analyzed, report is missing behavior information
    • Report size exceeded maximum capacity and may have missing disassembly code.
    • Report size getting too big, too many NtOpenKeyEx calls found.
    • Report size getting too big, too many NtQueryValueKey calls found.
    • VT rate limit hit for: forest.exe
    TimeTypeDescription
    17:11:22AutostartRun: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WindowsSVC.lnk
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    bg.microsoft.map.fastly.nethttp://www.skystudioselstree.comGet hashmaliciousUnknownBrowse
    • 199.232.214.172
    https://1drv.ms/o/c/8d397705294be844/Ej05S04brJ5Gk0BP_zBxdzgB_4nKyGxS56LL4LZ9Pc6fmQ?e=3DjGg4Get hashmaliciousHtmlDropperBrowse
    • 199.232.210.172
    https://dltxc.s3.ap-southeast-1.amazonaws.com/svs/wx.htm?eml=test@yahoo.comGet hashmaliciousHTMLPhisherBrowse
    • 199.232.210.172
    https://immergut.dotling.comGet hashmaliciousUnknownBrowse
    • 199.232.210.172
    https://abena.dotling.com/Get hashmaliciousUnknownBrowse
    • 199.232.214.172
    Modulo32_.jarGet hashmaliciousUnknownBrowse
    • 199.232.210.172
    Fatura.pdfGet hashmaliciousUnknownBrowse
    • 199.232.214.172
    Adobe.exeGet hashmaliciousRedLineBrowse
    • 199.232.214.172
    https://rb.gy/j709niGet hashmaliciousUnknownBrowse
    • 199.232.210.172
    file.exeGet hashmaliciousPureCrypter, PureLog Stealer, zgRATBrowse
    • 199.232.214.172
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    FREERANGECLOUDCAarm.elfGet hashmaliciousMirai, MoobotBrowse
    • 23.129.35.4
    SecuriteInfo.com.Trojan.PWS.Siggen3.33653.31886.3628.exeGet hashmaliciousRaccoon Stealer v2Browse
    • 193.142.147.59
    SecuriteInfo.com.Trojan.PackedNET.2334.3801.19434.exeGet hashmaliciousPureLog Stealer, Raccoon Stealer v2, SmokeLoaderBrowse
    • 193.142.147.59
    Setup.exeGet hashmaliciousAsyncRAT, HTMLPhisher, Clipboard Hijacker, Phorpiex, PureLog Stealer, Raccoon Stealer v2, RedLineBrowse
    • 193.142.147.59
    http://www.brookskushman.comGet hashmaliciousUnknownBrowse
    • 45.66.248.122
    http://www.prestigetransportation.comGet hashmaliciousUnknownBrowse
    • 45.66.248.122
    https://dutchpopp.comGet hashmaliciousUnknownBrowse
    • 45.66.248.122
    http://muse.krazzykriss.comGet hashmaliciousUnknownBrowse
    • 45.66.248.122
    https://muse.krazzykriss.com/Get hashmaliciousUnknownBrowse
    • 45.66.248.122
    No context
    No context
    Process:C:\Users\user\Desktop\forest.exe
    File Type:Microsoft Cabinet archive data, Windows 2000/XP setup, 71954 bytes, 1 file, at 0x2c +A "authroot.stl", number 1, 6 datablocks, 0x1 compression
    Category:dropped
    Size (bytes):71954
    Entropy (8bit):7.996617769952133
    Encrypted:true
    SSDEEP:1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ
    MD5:49AEBF8CBD62D92AC215B2923FB1B9F5
    SHA1:1723BE06719828DDA65AD804298D0431F6AFF976
    SHA-256:B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F
    SHA-512:BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B
    Malicious:false
    Reputation:high, very likely benign file
    Preview:MSCF............,...................I..................XaK .authroot.stl.[.i..6..CK..<Tk......4.cl!Kg..E..*Y.f_..".$mR"$.J.E.KB."..rKv.."{.g....3.W.....c..9.s...=....y6#..x..........D......\(.#.s.!.A.......cd.c........+^.ov...n.....3BL..0.......BPUR&.X..02.q...R...J.....w.....b.vy>....-.&..(..oe."."...J9...0U.6J..|U..S.....M.F8g...=.......p...........l.?3.J.x.G.Ep..$g..tj......)v]9(:.)W.8.Op.1Q..:.nPd........7.7..M].V F..g.....12..!7(...B.......h.RZ.......l.<.....6..Z^.`p?... .p.Gp.#.'.X..........|!.8.....".m.49r?.I...g...8.v.....a``.g.R4.i...J8q....NFW,E.6Y....!.o5%.Y.....R..<..S9....r....WO...(.....F..Q=*....-..7d..O(....-..+k.........K..........{Q....Z..j._.E...QZ.~.\.^......N.9.k..O.}dD.b1r...[}/....T..E..G..c.|.c.&>?..^t. ..;..X.d.E.0G....[Q.*,*......#.Dp..L.o|#syc.J............}G-.ou6.=52..XWi=...m.....^u......c..fc?&pR7S5....I...j.G........j.j..Tc.El.....B.pQ.,Bp....j...9g.. >..s..m#.Nb.o_u.M.V...........\#...v..Mo\sF..s....Y...
    Process:C:\Users\user\Desktop\forest.exe
    File Type:data
    Category:modified
    Size (bytes):328
    Entropy (8bit):3.144086598890895
    Encrypted:false
    SSDEEP:6:kKvhE9UswDLL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:nhHDnLNkPlE99SNxAhUe/3
    MD5:F81AAEB12EBE0D0D8B426E6AF78ADE64
    SHA1:506BDEB723209D2EDCB4D9B48CB4FBDC567CA86E
    SHA-256:BBE77318EB6D56F60409C9C23B4AB60BBA311A7785179BDBD7577C84BE035EAC
    SHA-512:9B7D56366375470B398D3393E743B4D66457F40C21EFD583EAE2A7B8594B2B7B56E414005F73552B99B8143BBD76764A3872D505DF6604FB2E0414A71D77252E
    Malicious:false
    Reputation:low
    Preview:p...... ........L=......(....................................................... ........G..@.......&...............h.t.t.p.:././.c.t.l.d.l...w.i.n.d.o.w.s.u.p.d.a.t.e...c.o.m./.m.s.d.o.w.n.l.o.a.d./.u.p.d.a.t.e./.v.3./.s.t.a.t.i.c./.t.r.u.s.t.e.d.r./.e.n./.a.u.t.h.r.o.o.t.s.t.l...c.a.b...".a.7.2.8.2.e.b.4.0.b.1.d.a.1.:.0."...
    Process:C:\Users\user\Desktop\forest.exe
    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Oct 5 09:31:42 2023, mtime=Wed Sep 18 14:09:24 2024, atime=Wed Sep 18 14:09:21 2024, length=688128, window=hide
    Category:dropped
    Size (bytes):582
    Entropy (8bit):4.992342607696939
    Encrypted:false
    SSDEEP:6:4xtQl3gr/bK5+ClzeVs+bRLO5xlAKEyZtL5NMwAt0sljAlmdkAV7D6WVMwANu+Qb:89ylzYNbRIxlAKEUVm/jAWD6n/zK2mV
    MD5:3961AD031F8F5E7CA6394ED421EB8FCD
    SHA1:770E3699374D357893AC3C00CB4AEC7637ABD32F
    SHA-256:C35212C6E5EF363DD756225BD86FF9364F50F84F8ABFBD1CBE51E771BD15AF00
    SHA-512:025D94F97430F571CF846F1E1FF86B1D885F519D3F79AD5277B7CDDD66FBBC6FA84EE4977FA9442BD018707302D5A6A09CC92AD3E0F414E42B2373E36F5E4D1C
    Malicious:false
    Reputation:low
    Preview:L..................F.... ...:.!w.../.S.......}..................................P.O. .:i.....+00.:...:..,.LB.)...A&...&......i..5q...i.u#w.....z.......`.2.....2Y+y .forest.exe..F......EW.S2Y+y....:..... ................}Y.f.o.r.e.s.t...e.x.e.......O...............-.......N............\<......C:\Users\user\Desktop\forest.exe..'.....\.....\.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.f.o.r.e.s.t...e.x.e.`.......X.......376483...........hT..CrF.f4... .O.L?.u...+...E...hT..CrF.f4... .O.L?.u...+...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
    File type:PE32+ executable (GUI) x86-64, for MS Windows
    Entropy (8bit):6.412521677726676
    TrID:
    • Win64 Executable GUI (202006/5) 92.65%
    • Win64 Executable (generic) (12005/4) 5.51%
    • Generic Win/DOS Executable (2004/3) 0.92%
    • DOS Executable Generic (2002/1) 0.92%
    • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
    File name:forest.exe
    File size:688'128 bytes
    MD5:5242f809563eb3764684ef1180adb902
    SHA1:491399cc669f92229d4a0c4a418067c5d4a808e8
    SHA256:2a3519501362a44a4b122fbf869e195989741525883f07d0fc2d2e5e48fb7fff
    SHA512:d8ab0ae014be8a70a6ad4c3e4d20dc5816b8a47eebf102b84aea0fcc2f4851f9162aa6fd1fe97d6cbaa213b9f392d679e451ea2ee3d99ea503e313b04a1acc49
    SSDEEP:12288:T8RNDWKhjjr+8M7e0dcrG4e5DNBRfex4d2Ozr3ST80yjlDUjHi8B:YRBBNU7eA+6rs80i1qi8
    TLSH:45E46C1BEAA801ECF27B913D88460516E7F0741B136267CF43E24A561F57AB5AF3E390
    File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........'.~.Fz-.Fz-.Fz-o6y,.Fz-o6.,1Fz-.Fz-.Fz-..~,.Fz-..y,.Fz-...,.Fz-o6~,.Fz-o6|,.Fz-o6{,.Fz-.F{-.Fz-..s,.Fz-..y,.Fz-...-.Fz-..x,.Fz
    Icon Hash:90cececece8e8eb0
    Entrypoint:0x140055310
    Entrypoint Section:.text
    Digitally signed:false
    Imagebase:0x140000000
    Subsystem:windows gui
    Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
    DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
    Time Stamp:0x65DD8785 [Tue Feb 27 06:56:05 2024 UTC]
    TLS Callbacks:
    CLR (.Net) Version:
    OS Version Major:6
    OS Version Minor:0
    File Version Major:6
    File Version Minor:0
    Subsystem Version Major:6
    Subsystem Version Minor:0
    Import Hash:d05eed5b28e2082c65759a421c6f3bfa
    Instruction
    dec eax
    sub esp, 28h
    call 00007FEA74C66620h
    dec eax
    add esp, 28h
    jmp 00007FEA74C65BFFh
    int3
    int3
    dec eax
    sub esp, 28h
    dec ebp
    mov eax, dword ptr [ecx+38h]
    dec eax
    mov ecx, edx
    dec ecx
    mov edx, ecx
    call 00007FEA74C65D92h
    mov eax, 00000001h
    dec eax
    add esp, 28h
    ret
    int3
    int3
    int3
    inc eax
    push ebx
    inc ebp
    mov ebx, dword ptr [eax]
    dec eax
    mov ebx, edx
    inc ecx
    and ebx, FFFFFFF8h
    dec esp
    mov ecx, ecx
    inc ecx
    test byte ptr [eax], 00000004h
    dec esp
    mov edx, ecx
    je 00007FEA74C65D95h
    inc ecx
    mov eax, dword ptr [eax+08h]
    dec ebp
    arpl word ptr [eax+04h], dx
    neg eax
    dec esp
    add edx, ecx
    dec eax
    arpl ax, cx
    dec esp
    and edx, ecx
    dec ecx
    arpl bx, ax
    dec edx
    mov edx, dword ptr [eax+edx]
    dec eax
    mov eax, dword ptr [ebx+10h]
    mov ecx, dword ptr [eax+08h]
    dec eax
    mov eax, dword ptr [ebx+08h]
    test byte ptr [ecx+eax+03h], 0000000Fh
    je 00007FEA74C65D8Dh
    movzx eax, byte ptr [ecx+eax+03h]
    and eax, FFFFFFF0h
    dec esp
    add ecx, eax
    dec esp
    xor ecx, edx
    dec ecx
    mov ecx, ecx
    pop ebx
    jmp 00007FEA74C656F6h
    int3
    dec eax
    mov eax, esp
    dec eax
    mov dword ptr [eax+08h], ebx
    dec eax
    mov dword ptr [eax+10h], ebp
    dec eax
    mov dword ptr [eax+18h], esi
    dec eax
    mov dword ptr [eax+20h], edi
    inc ecx
    push esi
    dec eax
    sub esp, 20h
    dec ecx
    mov ebx, dword ptr [ecx+38h]
    dec eax
    mov esi, edx
    dec ebp
    mov esi, eax
    dec eax
    mov ebp, ecx
    dec ecx
    mov edx, ecx
    dec eax
    mov ecx, esi
    dec ecx
    mov edi, ecx
    dec esp
    lea eax, dword ptr [ebx+04h]
    call 00007FEA74C65CF1h
    NameVirtual AddressVirtual Size Is in Section
    IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
    IMAGE_DIRECTORY_ENTRY_IMPORT0x9ef000xdc.rdata
    IMAGE_DIRECTORY_ENTRY_RESOURCE0xad0000x6a1.rsrc
    IMAGE_DIRECTORY_ENTRY_EXCEPTION0xa70000x4f38.pdata
    IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
    IMAGE_DIRECTORY_ENTRY_BASERELOC0xae0000xeb0.reloc
    IMAGE_DIRECTORY_ENTRY_DEBUG0x93f900x70.rdata
    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
    IMAGE_DIRECTORY_ENTRY_TLS0x00x0
    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x93e500x140.rdata
    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
    IMAGE_DIRECTORY_ENTRY_IAT0x860000x498.rdata
    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
    NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
    .text0x10000x84cbe0x84e00ef82e1bbb6f3bd2c3dc8891f9649858eFalse0.4309791715663217data6.4533863281507715IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
    .rdata0x860000x19e980x1a0002de47c4d6fb81fd4e30da2b81be8f271False0.40442833533653844data5.046197894214373IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
    .data0xa00000x62ac0x24004046c0b27be31192214d9d2827b5b6e9False0.14876302083333334DOS executable (block device driver)3.755771211802524IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
    .pdata0xa70000x4f380x500051bc825de2c686cc52e24e2f2061d81aFalse0.47470703125data5.782404509379289IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
    _RDATA0xac0000x1f40x2002cd34d966d4eb1345d70df222888ef93False0.515625data4.194826601975507IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
    .rsrc0xad0000x6a10x800ed14081ccf3d265a70c0e3cdef8b46f7False0.3896484375data3.578208011982351IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
    .reloc0xae0000xeb00x100008882a3e3c0a0d4ff1f233e521bace2bFalse0.425048828125data5.30487461027706IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
    NameRVASizeTypeLanguageCountryZLIB Complexity
    MUI0xad0f00xc8dataEnglishUnited States0.54
    RT_VERSION0xad1b80x36cdataEnglishUnited States0.4577625570776256
    RT_MANIFEST0xad5240x17dXML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.5931758530183727
    DLLImport
    KERNEL32.dllGetLastError, FileTimeToSystemTime, GlobalAlloc, CloseHandle, DecodePointer, GetFileSize, DeleteCriticalSection, GetProcessHeap, SystemTimeToFileTime, WideCharToMultiByte, SystemTimeToTzSpecificLocalTime, GetComputerNameA, WriteConsoleW, SetEndOfFile, SetEnvironmentVariableW, GetFileInformationByHandle, GetEnvironmentStringsW, GetCommandLineW, GetCommandLineA, Sleep, MultiByteToWideChar, WaitForSingleObject, FindClose, InitializeCriticalSectionEx, CreatePipe, GetModuleFileNameW, FindNextFileW, GetOEMCP, GetACP, IsValidCodePage, HeapSize, SetFilePointerEx, GetFileSizeEx, GetConsoleOutputCP, FlushFileBuffers, ReadConsoleW, GetConsoleMode, SetStdHandle, GetCurrentDirectoryW, GetFullPathNameW, FindFirstFileExW, FreeEnvironmentStringsW, ReadFile, GetTimeZoneInformation, EnumSystemLocalesW, GetUserDefaultLCID, IsValidLocale, GetLocaleInfoW, LCMapStringW, CompareStringW, GetTimeFormatW, GetDateFormatW, FlsFree, FlsSetValue, FlsGetValue, FlsAlloc, HeapReAlloc, HeapFree, HeapAlloc, WriteFile, GetStdHandle, GetStringTypeW, GetLocaleInfoEx, EnterCriticalSection, LeaveCriticalSection, EncodePointer, LocalFree, LCMapStringEx, CompareStringEx, GetCPInfo, IsDebuggerPresent, OutputDebugStringW, RaiseException, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, IsProcessorFeaturePresent, GetStartupInfoW, GetModuleHandleW, QueryPerformanceCounter, GetCurrentProcessId, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, RtlUnwindEx, RtlPcToFileHeader, SetLastError, InitializeCriticalSectionAndSpinCount, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, FreeLibrary, GetProcAddress, LoadLibraryExW, ExitProcess, GetModuleHandleExW, CreateFileW, GetDriveTypeW, GetFileType, PeekNamedPipe, RtlUnwind
    USER32.dllGetClientRect, ReleaseDC, GetDesktopWindow, GetDC
    GDI32.dllSelectObject, CreateCompatibleDC, CreateCompatibleBitmap, BitBlt, DeleteObject
    ADVAPI32.dllGetUserNameA
    SHELL32.dll
    ole32.dllCoCreateInstance, CreateStreamOnHGlobal, CoUninitialize, CoInitialize
    OLEAUT32.dllVariantClear
    IPHLPAPI.DLLGetNetworkParams, GetAdaptersInfo, GetTcpTable
    WS2_32.dllinet_ntoa, ntohs
    gdiplus.dllGdiplusStartup, GdiplusShutdown, GdipSaveImageToStream, GdipGetImageEncodersSize, GdipFree, GdipDisposeImage, GdipCreateBitmapFromHBITMAP, GdipCloneImage, GdipAlloc, GdipGetImageEncoders
    Language of compilation systemCountry where language is spokenMap
    EnglishUnited States
    TimestampSource PortDest PortSource IPDest IP
    Sep 18, 2024 17:11:19.793714046 CEST497078080192.168.2.1045.66.249.249
    Sep 18, 2024 17:11:20.076463938 CEST80804970745.66.249.249192.168.2.10
    Sep 18, 2024 17:11:20.076571941 CEST497078080192.168.2.1045.66.249.249
    Sep 18, 2024 17:11:20.077334881 CEST497078080192.168.2.1045.66.249.249
    Sep 18, 2024 17:11:20.082287073 CEST80804970745.66.249.249192.168.2.10
    Sep 18, 2024 17:11:20.704090118 CEST80804970745.66.249.249192.168.2.10
    Sep 18, 2024 17:11:20.707959890 CEST497078080192.168.2.1045.66.249.249
    Sep 18, 2024 17:11:20.708924055 CEST497088443192.168.2.1045.66.249.249
    Sep 18, 2024 17:11:20.712806940 CEST80804970745.66.249.249192.168.2.10
    Sep 18, 2024 17:11:20.713712931 CEST84434970845.66.249.249192.168.2.10
    Sep 18, 2024 17:11:20.713784933 CEST497088443192.168.2.1045.66.249.249
    Sep 18, 2024 17:11:20.715351105 CEST497088443192.168.2.1045.66.249.249
    Sep 18, 2024 17:11:20.720191956 CEST84434970845.66.249.249192.168.2.10
    Sep 18, 2024 17:11:21.365818024 CEST84434970845.66.249.249192.168.2.10
    Sep 18, 2024 17:11:21.365864038 CEST84434970845.66.249.249192.168.2.10
    Sep 18, 2024 17:11:21.365923882 CEST497088443192.168.2.1045.66.249.249
    Sep 18, 2024 17:11:21.368236065 CEST497088443192.168.2.1045.66.249.249
    Sep 18, 2024 17:11:21.373356104 CEST84434970845.66.249.249192.168.2.10
    Sep 18, 2024 17:11:21.545169115 CEST84434970845.66.249.249192.168.2.10
    Sep 18, 2024 17:11:21.589998960 CEST497088443192.168.2.1045.66.249.249
    Sep 18, 2024 17:11:21.684803009 CEST84434970845.66.249.249192.168.2.10
    Sep 18, 2024 17:11:21.730586052 CEST497088443192.168.2.1045.66.249.249
    Sep 18, 2024 17:11:22.053395033 CEST84434970845.66.249.249192.168.2.10
    Sep 18, 2024 17:11:22.053486109 CEST497088443192.168.2.1045.66.249.249
    Sep 18, 2024 17:11:23.358769894 CEST497088443192.168.2.1045.66.249.249
    Sep 18, 2024 17:11:23.359324932 CEST497108443192.168.2.1045.66.249.249
    Sep 18, 2024 17:11:23.363859892 CEST84434970845.66.249.249192.168.2.10
    Sep 18, 2024 17:11:23.363920927 CEST497088443192.168.2.1045.66.249.249
    Sep 18, 2024 17:11:23.364566088 CEST84434971045.66.249.249192.168.2.10
    Sep 18, 2024 17:11:23.364645958 CEST497108443192.168.2.1045.66.249.249
    Sep 18, 2024 17:11:23.364866972 CEST497108443192.168.2.1045.66.249.249
    Sep 18, 2024 17:11:23.369713068 CEST84434971045.66.249.249192.168.2.10
    Sep 18, 2024 17:11:23.369721889 CEST84434971045.66.249.249192.168.2.10
    Sep 18, 2024 17:11:23.951437950 CEST84434971045.66.249.249192.168.2.10
    Sep 18, 2024 17:11:23.996232986 CEST497108443192.168.2.1045.66.249.249
    Sep 18, 2024 17:11:24.082338095 CEST84434971045.66.249.249192.168.2.10
    Sep 18, 2024 17:11:24.082771063 CEST497108443192.168.2.1045.66.249.249
    Sep 18, 2024 17:11:24.083782911 CEST497108443192.168.2.1045.66.249.249
    Sep 18, 2024 17:11:24.090380907 CEST84434971045.66.249.249192.168.2.10
    Sep 18, 2024 17:11:24.090411901 CEST84434971045.66.249.249192.168.2.10
    Sep 18, 2024 17:11:24.254812956 CEST84434971045.66.249.249192.168.2.10
    Sep 18, 2024 17:11:24.308707952 CEST497108443192.168.2.1045.66.249.249
    Sep 18, 2024 17:11:50.715392113 CEST497078080192.168.2.1045.66.249.249
    Sep 18, 2024 17:11:50.720545053 CEST80804970745.66.249.249192.168.2.10
    Sep 18, 2024 17:12:20.715286970 CEST497078080192.168.2.1045.66.249.249
    Sep 18, 2024 17:12:20.810276985 CEST80804970745.66.249.249192.168.2.10
    Sep 18, 2024 17:12:24.511703014 CEST84434971045.66.249.249192.168.2.10
    Sep 18, 2024 17:12:24.511724949 CEST84434971045.66.249.249192.168.2.10
    Sep 18, 2024 17:12:24.511897087 CEST84434971045.66.249.249192.168.2.10
    Sep 18, 2024 17:12:24.512240887 CEST497108443192.168.2.1045.66.249.249
    Sep 18, 2024 17:12:24.512535095 CEST497108443192.168.2.1045.66.249.249
    Sep 18, 2024 17:12:24.512579918 CEST497108443192.168.2.1045.66.249.249
    Sep 18, 2024 17:12:24.517385960 CEST84434971045.66.249.249192.168.2.10
    Sep 18, 2024 17:12:24.517421961 CEST84434971045.66.249.249192.168.2.10
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    Sep 18, 2024 17:09:40.101671934 CEST1.1.1.1192.168.2.100x1f26No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
    Sep 18, 2024 17:09:40.101671934 CEST1.1.1.1192.168.2.100x1f26No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
    • 45.66.249.249:8080
    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
    0192.168.2.104970745.66.249.24980808152C:\Users\user\Desktop\forest.exe
    TimestampBytes transferredDirectionData
    Sep 18, 2024 17:11:20.077334881 CEST194OUTGET /sock HTTP/1.1
    Connection: Upgrade
    Upgrade: websocket
    User-Agent: Where are my socks?
    Sec-WebSocket-Key: knZ6tsATkpSvprUi2z7eqA==
    Sec-WebSocket-Version: 13
    Host: 45.66.249.249:8080
    Sep 18, 2024 17:11:20.704090118 CEST147INHTTP/1.1 101
    Upgrade: websocket
    Connection: upgrade
    Sec-WebSocket-Accept: f3eq0I1MXjDtACVnS/vIaNSVc/c=
    Date: Wed, 18 Sep 2024 15:11:20 GMT


    Click to jump to process

    Click to jump to process

    Click to jump to process

    Target ID:0
    Start time:11:09:22
    Start date:18/09/2024
    Path:C:\Users\user\Desktop\forest.exe
    Wow64 process (32bit):false
    Commandline:"C:\Users\user\Desktop\forest.exe"
    Imagebase:0x7ff7d4bb0000
    File size:688'128 bytes
    MD5 hash:5242F809563EB3764684EF1180ADB902
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:false

    Target ID:6
    Start time:11:11:30
    Start date:18/09/2024
    Path:C:\Users\user\Desktop\forest.exe
    Wow64 process (32bit):false
    Commandline:"C:\Users\user\Desktop\forest.exe"
    Imagebase:0x7ff7d4bb0000
    File size:688'128 bytes
    MD5 hash:5242F809563EB3764684EF1180ADB902
    Has elevated privileges:false
    Has administrator privileges:false
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:false

    Reset < >

      Execution Graph

      Execution Coverage:1.4%
      Dynamic/Decrypted Code Coverage:0%
      Signature Coverage:32.8%
      Total number of Nodes:393
      Total number of Limit Nodes:19
      execution_graph 50222 7ff7d4bb5ef0 50256 7ff7d4bcf390 50222->50256 50224 7ff7d4bb5f49 50225 7ff7d4bb60d7 50224->50225 50226 7ff7d4bb5f8b 50224->50226 50280 7ff7d4bb2a10 39 API calls 2 library calls 50225->50280 50228 7ff7d4bb5fb2 50226->50228 50229 7ff7d4bb610d 50226->50229 50233 7ff7d4bb6143 50228->50233 50238 7ff7d4bb5ff2 50228->50238 50282 7ff7d4bb2a10 39 API calls 2 library calls 50229->50282 50230 7ff7d4bb60fc 50281 7ff7d4c06e14 RtlPcToFileHeader RaiseException 50230->50281 50284 7ff7d4bb2a10 39 API calls 2 library calls 50233->50284 50234 7ff7d4bb6132 50283 7ff7d4c06e14 RtlPcToFileHeader RaiseException 50234->50283 50237 7ff7d4bb616b 50285 7ff7d4c06e14 RtlPcToFileHeader RaiseException 50237->50285 50241 7ff7d4bb617f 50238->50241 50242 7ff7d4bb603f 50238->50242 50243 7ff7d4bb6065 50238->50243 50239 7ff7d4bb60aa ISource 50271 7ff7d4c04d10 50239->50271 50286 7ff7d4bb2a10 39 API calls 2 library calls 50241->50286 50242->50243 50249 7ff7d4bb61bb 50242->50249 50243->50239 50245 7ff7d4bb61f7 50243->50245 50290 7ff7d4c13eb4 37 API calls 2 library calls 50245->50290 50288 7ff7d4bb2a10 39 API calls 2 library calls 50249->50288 50251 7ff7d4bb61a7 50287 7ff7d4c06e14 RtlPcToFileHeader RaiseException 50251->50287 50254 7ff7d4bb61e3 50289 7ff7d4c06e14 RtlPcToFileHeader RaiseException 50254->50289 50257 7ff7d4bcf3b6 50256->50257 50267 7ff7d4bcf485 50256->50267 50259 7ff7d4bcf3c4 BuildCatchObjectHelperInternal 50257->50259 50261 7ff7d4bcf3ed 50257->50261 50262 7ff7d4bcf43d 50257->50262 50259->50224 50270 7ff7d4bcf47f 50261->50270 50291 7ff7d4c04d38 50261->50291 50265 7ff7d4c04d38 std::_Facet_Register 41 API calls 50262->50265 50268 7ff7d4bcf408 BuildCatchObjectHelperInternal 50262->50268 50265->50268 50302 7ff7d4bb29f0 41 API calls 50267->50302 50268->50224 50301 7ff7d4bb2950 41 API calls 3 library calls 50270->50301 50272 7ff7d4c04d19 50271->50272 50273 7ff7d4bb60c2 50272->50273 50274 7ff7d4c056ec IsProcessorFeaturePresent 50272->50274 50275 7ff7d4c05704 50274->50275 50306 7ff7d4c058e0 RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind 50275->50306 50277 7ff7d4c05717 50307 7ff7d4c056b8 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 50277->50307 50280->50230 50281->50229 50282->50234 50283->50233 50284->50237 50285->50241 50286->50251 50287->50249 50288->50254 50289->50245 50292 7ff7d4c04d43 50291->50292 50293 7ff7d4bcf403 50292->50293 50295 7ff7d4c04d62 50292->50295 50303 7ff7d4c1a7b0 EnterCriticalSection LeaveCriticalSection std::_Facet_Register 50292->50303 50293->50268 50300 7ff7d4c13eb4 37 API calls 2 library calls 50293->50300 50296 7ff7d4c04d6d 50295->50296 50304 7ff7d4bdfc0c RtlPcToFileHeader RaiseException _com_raise_error std::bad_alloc::bad_alloc 50295->50304 50305 7ff7d4bb2950 41 API calls 3 library calls 50296->50305 50299 7ff7d4c04d73 50301->50267 50303->50292 50305->50299 50306->50277 50308 7ff7d4bb5040 50309 7ff7d4bb50a2 50308->50309 50310 7ff7d4bb5667 50308->50310 50390 7ff7d4bd3e80 50309->50390 50418 7ff7d4bb29f0 41 API calls 50310->50418 50313 7ff7d4bb566c 50419 7ff7d4c13eb4 37 API calls 2 library calls 50313->50419 50314 7ff7d4bb50d3 50408 7ff7d4bca750 50314->50408 50317 7ff7d4bb50ee 50319 7ff7d4bca750 41 API calls 50317->50319 50318 7ff7d4bb5672 50420 7ff7d4c13eb4 37 API calls 2 library calls 50318->50420 50321 7ff7d4bb514f 50319->50321 50323 7ff7d4bca750 41 API calls 50321->50323 50322 7ff7d4bb5678 50421 7ff7d4c13eb4 37 API calls 2 library calls 50322->50421 50325 7ff7d4bb51a6 50323->50325 50327 7ff7d4bca750 41 API calls 50325->50327 50326 7ff7d4bb567e 50422 7ff7d4c13eb4 37 API calls 2 library calls 50326->50422 50329 7ff7d4bb51fa 50327->50329 50331 7ff7d4bca750 41 API calls 50329->50331 50330 7ff7d4bb5684 50423 7ff7d4c13eb4 37 API calls 2 library calls 50330->50423 50332 7ff7d4bb5242 50331->50332 50332->50313 50333 7ff7d4bb52a0 ISource 50332->50333 50333->50318 50335 7ff7d4bb52f3 ISource 50333->50335 50335->50322 50337 7ff7d4bb534c ISource 50335->50337 50336 7ff7d4bb568a 50424 7ff7d4bb2a10 39 API calls 2 library calls 50336->50424 50337->50326 50338 7ff7d4bb53a8 ISource 50337->50338 50338->50330 50340 7ff7d4bb5404 ISource 50338->50340 50413 7ff7d4bb4db0 50340->50413 50341 7ff7d4bb569f 50425 7ff7d4c06e14 RtlPcToFileHeader RaiseException 50341->50425 50345 7ff7d4bb56b3 50426 7ff7d4bb2a10 39 API calls 2 library calls 50345->50426 50347 7ff7d4bb56c7 50427 7ff7d4c06e14 RtlPcToFileHeader RaiseException 50347->50427 50348 7ff7d4bb5463 50348->50345 50352 7ff7d4bb548d 50348->50352 50350 7ff7d4bb56db 50428 7ff7d4bb2a10 39 API calls 2 library calls 50350->50428 50352->50350 50356 7ff7d4bb54c7 50352->50356 50353 7ff7d4bb56ef 50429 7ff7d4c06e14 RtlPcToFileHeader RaiseException 50353->50429 50355 7ff7d4bb5703 50430 7ff7d4bb2a10 39 API calls 2 library calls 50355->50430 50356->50355 50360 7ff7d4bb54e2 50356->50360 50358 7ff7d4bb5717 50431 7ff7d4c06e14 RtlPcToFileHeader RaiseException 50358->50431 50361 7ff7d4bb572b 50360->50361 50364 7ff7d4bb550a 50360->50364 50432 7ff7d4bb2a10 39 API calls 2 library calls 50361->50432 50363 7ff7d4bb573f 50433 7ff7d4c06e14 RtlPcToFileHeader RaiseException 50363->50433 50366 7ff7d4bb5753 50364->50366 50368 7ff7d4bb551d 50364->50368 50434 7ff7d4bb2a10 39 API calls 2 library calls 50366->50434 50371 7ff7d4bb577b 50368->50371 50376 7ff7d4bb5535 50368->50376 50369 7ff7d4bb5767 50435 7ff7d4c06e14 RtlPcToFileHeader RaiseException 50369->50435 50436 7ff7d4bb2a10 39 API calls 2 library calls 50371->50436 50373 7ff7d4bb5797 50437 7ff7d4c06e14 RtlPcToFileHeader RaiseException 50373->50437 50375 7ff7d4bb57ab 50438 7ff7d4bb2a10 39 API calls 2 library calls 50375->50438 50376->50375 50378 7ff7d4bb5598 50376->50378 50380 7ff7d4bb55da ISource 50378->50380 50382 7ff7d4bb57dd 50378->50382 50379 7ff7d4bb57c9 50439 7ff7d4c06e14 RtlPcToFileHeader RaiseException 50379->50439 50383 7ff7d4bb5636 ISource 50380->50383 50385 7ff7d4bb57e3 50380->50385 50440 7ff7d4c13eb4 37 API calls 2 library calls 50382->50440 50384 7ff7d4c04d10 ctype 8 API calls 50383->50384 50386 7ff7d4bb564e 50384->50386 50441 7ff7d4c13eb4 37 API calls 2 library calls 50385->50441 50391 7ff7d4bd3ed3 50390->50391 50394 7ff7d4bd3f07 BuildCatchObjectHelperInternal 50390->50394 50392 7ff7d4bd3ee8 50391->50392 50393 7ff7d4bd3f3c 50391->50393 50395 7ff7d4c04d38 std::_Facet_Register 41 API calls 50392->50395 50396 7ff7d4bd3f97 50392->50396 50393->50394 50399 7ff7d4c04d38 std::_Facet_Register 41 API calls 50393->50399 50394->50314 50397 7ff7d4bd3efe 50395->50397 50443 7ff7d4bb2950 41 API calls 3 library calls 50396->50443 50397->50394 50442 7ff7d4c13eb4 37 API calls 2 library calls 50397->50442 50399->50394 50400 7ff7d4bd3f9d 50444 7ff7d4c12d50 13 API calls 2 library calls 50400->50444 50403 7ff7d4bd3fc2 50445 7ff7d4c12d50 13 API calls 2 library calls 50403->50445 50405 7ff7d4bd3fcb 50446 7ff7d4c12d50 13 API calls 2 library calls 50405->50446 50407 7ff7d4bd3fd4 ISource 50407->50314 50409 7ff7d4bca7b2 50408->50409 50411 7ff7d4bca773 BuildCatchObjectHelperInternal 50408->50411 50447 7ff7d4bcf0e0 41 API calls 5 library calls 50409->50447 50411->50317 50412 7ff7d4bca7c8 50412->50317 50448 7ff7d4bca680 50413->50448 50415 7ff7d4bb4e15 50416 7ff7d4bca680 41 API calls 50415->50416 50417 7ff7d4bb4e45 50416->50417 50417->50336 50417->50348 50424->50341 50425->50345 50426->50347 50427->50350 50428->50353 50429->50355 50430->50358 50431->50361 50432->50363 50433->50366 50434->50369 50435->50371 50436->50373 50437->50375 50438->50379 50439->50382 50443->50400 50444->50403 50445->50405 50446->50407 50447->50412 50449 7ff7d4bca68d 50448->50449 50450 7ff7d4bca6a4 50448->50450 50449->50415 50453 7ff7d4bca6be __scrt_get_show_window_mode 50450->50453 50454 7ff7d4bd0350 41 API calls 6 library calls 50450->50454 50452 7ff7d4bca709 50452->50415 50453->50415 50454->50452 50455 7ff7d4c0519c 50480 7ff7d4c04e80 50455->50480 50458 7ff7d4c052e8 50538 7ff7d4c05968 7 API calls 2 library calls 50458->50538 50460 7ff7d4c051b8 __scrt_acquire_startup_lock 50461 7ff7d4c052f2 50460->50461 50463 7ff7d4c051d6 50460->50463 50539 7ff7d4c05968 7 API calls 2 library calls 50461->50539 50464 7ff7d4c051fb 50463->50464 50469 7ff7d4c05218 __scrt_release_startup_lock 50463->50469 50488 7ff7d4c1b8d4 50463->50488 50465 7ff7d4c052fd BuildCatchObjectHelperInternal 50467 7ff7d4c05281 50492 7ff7d4c05ab0 50467->50492 50469->50467 50537 7ff7d4c0bc44 45 API calls __GSHandlerCheck_EH 50469->50537 50470 7ff7d4c05286 50495 7ff7d4c1b864 50470->50495 50481 7ff7d4c04e88 50480->50481 50482 7ff7d4c04e94 __scrt_dllmain_crt_thread_attach 50481->50482 50483 7ff7d4c04ea1 50482->50483 50486 7ff7d4c04e9d 50482->50486 50540 7ff7d4c1b780 50483->50540 50486->50458 50486->50460 50489 7ff7d4c1b8d9 50488->50489 50490 7ff7d4c1b90a 50488->50490 50489->50490 50557 7ff7d4bb1de0 LoadLibraryA 50489->50557 50490->50469 50558 7ff7d4c31650 50492->50558 50494 7ff7d4c05ac7 GetStartupInfoW 50494->50470 50560 7ff7d4c27ed4 50495->50560 50497 7ff7d4c1b873 50498 7ff7d4c0528e 50497->50498 50566 7ff7d4c28210 45 API calls _Wcsftime 50497->50566 50500 7ff7d4bc7b00 50498->50500 50501 7ff7d4bc7b2a _Strcoll 50500->50501 50569 7ff7d4be5bf0 50501->50569 50503 7ff7d4bc7b43 50504 7ff7d4bc7bba SleepEx 50503->50504 50575 7ff7d4bb6660 OpenSCManagerA 50504->50575 50507 7ff7d4bcf390 41 API calls 50508 7ff7d4bc7bf6 50507->50508 50509 7ff7d4bcf390 41 API calls 50508->50509 50510 7ff7d4bc7c1a 50509->50510 50607 7ff7d4bcaaf0 50510->50607 50512 7ff7d4bc7c28 50624 7ff7d4bb4f00 50512->50624 50515 7ff7d4bcaaf0 41 API calls 50516 7ff7d4bc7cf5 50515->50516 50517 7ff7d4bb4f00 41 API calls 50516->50517 50518 7ff7d4bc7d02 50517->50518 50519 7ff7d4c04d38 std::_Facet_Register 41 API calls 50518->50519 50520 7ff7d4bc7dae 50519->50520 50521 7ff7d4bcaaf0 41 API calls 50520->50521 50522 7ff7d4bc7dca 50521->50522 50523 7ff7d4c04d38 std::_Facet_Register 41 API calls 50522->50523 50524 7ff7d4bc7ddc 50523->50524 50636 7ff7d4bb44f0 50524->50636 50526 7ff7d4bc7de8 50527 7ff7d4c04d38 std::_Facet_Register 41 API calls 50526->50527 50528 7ff7d4bc7df5 MultiByteToWideChar 50527->50528 50529 7ff7d4c05084 50528->50529 50530 7ff7d4bc7e42 MultiByteToWideChar MultiByteToWideChar 50529->50530 50531 7ff7d4c05084 50530->50531 50532 7ff7d4bc7ea8 MultiByteToWideChar 50531->50532 50533 7ff7d4c04d38 std::_Facet_Register 41 API calls 50532->50533 50534 7ff7d4bc7ee2 50533->50534 50647 7ff7d4bb46d0 SHTestTokenMembership 50534->50647 50536 7ff7d4bc7eea 50537->50467 50538->50461 50539->50465 50541 7ff7d4c288f0 50540->50541 50542 7ff7d4c04ea6 50541->50542 50545 7ff7d4c21afc 50541->50545 50542->50486 50544 7ff7d4c07120 7 API calls 2 library calls 50542->50544 50544->50486 50556 7ff7d4c14190 EnterCriticalSection 50545->50556 50547 7ff7d4c21b0c 50548 7ff7d4c2218c 43 API calls 50547->50548 50549 7ff7d4c21b15 50548->50549 50550 7ff7d4c21904 45 API calls 50549->50550 50555 7ff7d4c21b23 50549->50555 50552 7ff7d4c21b1e 50550->50552 50551 7ff7d4c141e4 _isindst LeaveCriticalSection 50553 7ff7d4c21b2f 50551->50553 50554 7ff7d4c219f4 GetStdHandle GetFileType 50552->50554 50553->50541 50554->50555 50555->50551 50557->50489 50559 7ff7d4c31640 50558->50559 50559->50494 50559->50559 50561 7ff7d4c27ee1 50560->50561 50565 7ff7d4c27f26 50560->50565 50567 7ff7d4c1e2c4 50 API calls 3 library calls 50561->50567 50563 7ff7d4c27f10 50568 7ff7d4c27bac 65 API calls 3 library calls 50563->50568 50565->50497 50566->50497 50567->50563 50568->50565 50674 7ff7d4c199f0 50569->50674 50572 7ff7d4be5c02 50572->50503 50576 7ff7d4bcf390 41 API calls 50575->50576 50577 7ff7d4bb66e8 50576->50577 50578 7ff7d4bb4f00 41 API calls 50577->50578 50579 7ff7d4bb66f6 50578->50579 50580 7ff7d4bcf390 41 API calls 50579->50580 50581 7ff7d4bb671e 50580->50581 50582 7ff7d4bb4f00 41 API calls 50581->50582 50583 7ff7d4bb672c 50582->50583 50584 7ff7d4c04d38 std::_Facet_Register 41 API calls 50583->50584 50585 7ff7d4bb6741 50584->50585 50586 7ff7d4bcaaf0 41 API calls 50585->50586 50587 7ff7d4bb67a0 50585->50587 50586->50585 50704 7ff7d4bcfda0 50587->50704 50589 7ff7d4bb6820 50709 7ff7d4bce470 50589->50709 50590 7ff7d4bb67ab 50590->50589 50591 7ff7d4bb67e2 OpenServiceA QueryServiceStatusEx 50590->50591 50592 7ff7d4bb67df 50590->50592 50591->50592 50596 7ff7d4bb68a0 50591->50596 50592->50589 50592->50590 50592->50591 50595 7ff7d4c04d10 ctype 8 API calls 50598 7ff7d4bb6887 50595->50598 50599 7ff7d4bb68ab 50596->50599 50597 7ff7d4bcfda0 37 API calls 50600 7ff7d4bb6846 50597->50600 50598->50507 50723 7ff7d4c13eb4 37 API calls 2 library calls 50599->50723 50600->50599 50602 7ff7d4bb6876 ISource 50600->50602 50602->50595 50611 7ff7d4bcab19 50607->50611 50608 7ff7d4bcabfa 50755 7ff7d4bb29f0 41 API calls 50608->50755 50610 7ff7d4bcab41 50610->50512 50611->50608 50611->50610 50612 7ff7d4bcab68 50611->50612 50614 7ff7d4bcabbb 50611->50614 50616 7ff7d4c04d38 std::_Facet_Register 41 API calls 50612->50616 50617 7ff7d4bcabf4 50612->50617 50619 7ff7d4bcab86 BuildCatchObjectHelperInternal 50614->50619 50622 7ff7d4c04d38 std::_Facet_Register 41 API calls 50614->50622 50621 7ff7d4bcab7e 50616->50621 50754 7ff7d4bb2950 41 API calls 3 library calls 50617->50754 50619->50512 50621->50619 50753 7ff7d4c13eb4 37 API calls 2 library calls 50621->50753 50622->50619 50625 7ff7d4bb4f58 50624->50625 50626 7ff7d4bca680 41 API calls 50625->50626 50627 7ff7d4bb4f9c 50626->50627 50628 7ff7d4bca680 41 API calls 50627->50628 50629 7ff7d4bb4fc9 50628->50629 50630 7ff7d4bb4ff8 ISource 50629->50630 50632 7ff7d4bb502f 50629->50632 50631 7ff7d4c04d10 ctype 8 API calls 50630->50631 50633 7ff7d4bb501f 50631->50633 50756 7ff7d4c13eb4 37 API calls 2 library calls 50632->50756 50633->50515 50637 7ff7d4bb4522 MultiByteToWideChar 50636->50637 50638 7ff7d4bb451f 50636->50638 50639 7ff7d4bb455a 50637->50639 50638->50637 50640 7ff7d4bb4567 MultiByteToWideChar MultiByteToWideChar 50639->50640 50641 7ff7d4c05084 50640->50641 50642 7ff7d4bb45be MultiByteToWideChar MultiByteToWideChar 50641->50642 50643 7ff7d4c05084 50642->50643 50644 7ff7d4bb461d MultiByteToWideChar MultiByteToWideChar 50643->50644 50645 7ff7d4c05084 50644->50645 50646 7ff7d4bb467c MultiByteToWideChar 50645->50646 50646->50526 50648 7ff7d4c31650 __scrt_get_show_window_mode 50647->50648 50649 7ff7d4bb4771 GetUserNameA 50648->50649 50650 7ff7d4bb47a5 50649->50650 50650->50650 50651 7ff7d4bcf390 41 API calls 50650->50651 50654 7ff7d4bb47bd ISource 50651->50654 50652 7ff7d4bb485f GetComputerNameA 50653 7ff7d4bb4893 50652->50653 50653->50653 50656 7ff7d4bcf390 41 API calls 50653->50656 50654->50652 50670 7ff7d4bb4aed 50654->50670 50659 7ff7d4bb48ae ISource 50656->50659 50658 7ff7d4bb4955 GetModuleFileNameW 50660 7ff7d4bb49a5 50658->50660 50666 7ff7d4bb4995 50658->50666 50659->50658 50661 7ff7d4bb4ae2 50659->50661 50662 7ff7d4bb4950 ISource 50659->50662 50757 7ff7d4bd4e80 41 API calls 3 library calls 50660->50757 50759 7ff7d4c13eb4 37 API calls 2 library calls 50661->50759 50662->50658 50665 7ff7d4bb4ae7 50760 7ff7d4c13eb4 37 API calls 2 library calls 50665->50760 50672 7ff7d4bb49c8 BuildCatchObjectHelperInternal 50666->50672 50758 7ff7d4bd0210 41 API calls 5 library calls 50666->50758 50669 7ff7d4c04d10 ctype 8 API calls 50671 7ff7d4bb4ac1 50669->50671 50761 7ff7d4c13eb4 37 API calls 2 library calls 50670->50761 50671->50536 50672->50665 50673 7ff7d4bb4a29 ISource 50672->50673 50673->50669 50675 7ff7d4c199f9 50674->50675 50676 7ff7d4c19a10 50674->50676 50692 7ff7d4c11c7c 11 API calls _get_daylight 50675->50692 50687 7ff7d4c1f210 50676->50687 50679 7ff7d4c199fe 50693 7ff7d4c13e94 37 API calls _invalid_parameter_noinfo 50679->50693 50685 7ff7d4be5bfe 50685->50572 50686 7ff7d4bdfc74 41 API calls _com_raise_error 50685->50686 50694 7ff7d4c1e8f4 50687->50694 50692->50679 50693->50685 50695 7ff7d4c1e955 50694->50695 50701 7ff7d4c1e950 __vcrt_FlsAlloc 50694->50701 50703 7ff7d4c1a378 45 API calls 2 library calls 50695->50703 50696 7ff7d4c1e984 LoadLibraryExW 50698 7ff7d4c1ea59 50696->50698 50699 7ff7d4c1e9a9 GetLastError 50696->50699 50697 7ff7d4c1ea79 GetProcAddressForCaller 50697->50695 50698->50697 50700 7ff7d4c1ea70 FreeLibrary 50698->50700 50699->50701 50700->50697 50701->50695 50701->50696 50701->50697 50702 7ff7d4c1e9e3 LoadLibraryExW 50701->50702 50702->50698 50702->50701 50705 7ff7d4bcfda5 ISource 50704->50705 50706 7ff7d4bcfe0e 50704->50706 50705->50706 50724 7ff7d4c13eb4 37 API calls 2 library calls 50705->50724 50706->50590 50710 7ff7d4bce4a0 50709->50710 50712 7ff7d4bce4ee 50710->50712 50729 7ff7d4bcd240 41 API calls 2 library calls 50710->50729 50717 7ff7d4bce524 50712->50717 50725 7ff7d4be0c94 50712->50725 50713 7ff7d4bce6c2 50731 7ff7d4bb40d0 41 API calls 2 library calls 50713->50731 50714 7ff7d4bce684 50715 7ff7d4bb6833 50714->50715 50730 7ff7d4bcd3a0 41 API calls _com_raise_error 50714->50730 50715->50597 50715->50602 50717->50713 50717->50714 50719 7ff7d4bce704 50732 7ff7d4c06e14 RtlPcToFileHeader RaiseException 50719->50732 50721 7ff7d4bce715 50726 7ff7d4be0cbc 50725->50726 50727 7ff7d4be0cc3 BuildCatchObjectHelperInternal 50725->50727 50726->50717 50727->50726 50733 7ff7d4c15238 50727->50733 50729->50712 50730->50715 50731->50719 50732->50721 50734 7ff7d4c15268 50733->50734 50737 7ff7d4c14f9c 50734->50737 50736 7ff7d4c15286 50736->50726 50738 7ff7d4c14fbc 50737->50738 50739 7ff7d4c14fe9 50737->50739 50738->50739 50740 7ff7d4c14ff1 50738->50740 50741 7ff7d4c14fc6 50738->50741 50739->50736 50744 7ff7d4c14edc 50740->50744 50751 7ff7d4c13dc4 37 API calls 2 library calls 50741->50751 50752 7ff7d4c14404 EnterCriticalSection 50744->50752 50746 7ff7d4c14ef9 50747 7ff7d4c14f1c 74 API calls 50746->50747 50748 7ff7d4c14f02 50747->50748 50749 7ff7d4c14410 _fread_nolock LeaveCriticalSection 50748->50749 50750 7ff7d4c14f0d 50749->50750 50750->50739 50751->50739 50754->50608 50757->50666 50758->50672

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 0 7ff7d4bb5040-7ff7d4bb509c 1 7ff7d4bb50a2-7ff7d4bb50a7 0->1 2 7ff7d4bb5667-7ff7d4bb566c call 7ff7d4bb29f0 0->2 4 7ff7d4bb50a9 1->4 5 7ff7d4bb50ac-7ff7d4bb5138 call 7ff7d4bd3e80 call 7ff7d4bca750 1->5 9 7ff7d4bb566d-7ff7d4bb5672 call 7ff7d4c13eb4 2->9 4->5 14 7ff7d4bb513a 5->14 15 7ff7d4bb513e-7ff7d4bb51e6 call 7ff7d4bca750 * 2 5->15 16 7ff7d4bb5673-7ff7d4bb5678 call 7ff7d4c13eb4 9->16 14->15 26 7ff7d4bb51e8 15->26 27 7ff7d4bb51ec-7ff7d4bb5271 call 7ff7d4bca750 * 2 15->27 22 7ff7d4bb5679-7ff7d4bb567e call 7ff7d4c13eb4 16->22 28 7ff7d4bb567f-7ff7d4bb5684 call 7ff7d4c13eb4 22->28 26->27 36 7ff7d4bb52a5-7ff7d4bb52c4 27->36 37 7ff7d4bb5273-7ff7d4bb5285 27->37 35 7ff7d4bb5685-7ff7d4bb568a call 7ff7d4c13eb4 28->35 47 7ff7d4bb568b-7ff7d4bb56ae call 7ff7d4bb2a10 call 7ff7d4c06e14 35->47 41 7ff7d4bb52c6-7ff7d4bb52d8 36->41 42 7ff7d4bb52f8-7ff7d4bb531a 36->42 39 7ff7d4bb52a0 call 7ff7d4c04d30 37->39 40 7ff7d4bb5287-7ff7d4bb529a 37->40 39->36 40->9 40->39 45 7ff7d4bb52f3 call 7ff7d4c04d30 41->45 46 7ff7d4bb52da-7ff7d4bb52ed 41->46 48 7ff7d4bb5351-7ff7d4bb5376 42->48 49 7ff7d4bb531c-7ff7d4bb5331 42->49 45->42 46->16 46->45 69 7ff7d4bb56b3-7ff7d4bb56d6 call 7ff7d4bb2a10 call 7ff7d4c06e14 47->69 50 7ff7d4bb5378-7ff7d4bb538d 48->50 51 7ff7d4bb53ad-7ff7d4bb53d2 48->51 54 7ff7d4bb5333-7ff7d4bb5346 49->54 55 7ff7d4bb534c call 7ff7d4c04d30 49->55 56 7ff7d4bb538f-7ff7d4bb53a2 50->56 57 7ff7d4bb53a8 call 7ff7d4c04d30 50->57 58 7ff7d4bb53d4-7ff7d4bb53e9 51->58 59 7ff7d4bb5409-7ff7d4bb545d call 7ff7d4bb4db0 51->59 54->22 54->55 55->48 56->28 56->57 57->51 63 7ff7d4bb5404 call 7ff7d4c04d30 58->63 64 7ff7d4bb53eb-7ff7d4bb53fe 58->64 59->47 73 7ff7d4bb5463-7ff7d4bb5487 59->73 63->59 64->35 64->63 75 7ff7d4bb56db-7ff7d4bb56fe call 7ff7d4bb2a10 call 7ff7d4c06e14 69->75 73->69 78 7ff7d4bb548d-7ff7d4bb54c1 73->78 82 7ff7d4bb5703-7ff7d4bb5726 call 7ff7d4bb2a10 call 7ff7d4c06e14 75->82 78->75 83 7ff7d4bb54c7-7ff7d4bb54dc 78->83 89 7ff7d4bb572b-7ff7d4bb574e call 7ff7d4bb2a10 call 7ff7d4c06e14 82->89 83->82 88 7ff7d4bb54e2-7ff7d4bb5504 83->88 88->89 93 7ff7d4bb550a-7ff7d4bb5517 88->93 95 7ff7d4bb5753-7ff7d4bb5776 call 7ff7d4bb2a10 call 7ff7d4c06e14 89->95 93->95 98 7ff7d4bb551d-7ff7d4bb552f 93->98 101 7ff7d4bb577b-7ff7d4bb57a6 call 7ff7d4bb2a10 call 7ff7d4c06e14 95->101 98->101 103 7ff7d4bb5535-7ff7d4bb5586 98->103 110 7ff7d4bb57ab-7ff7d4bb57dd call 7ff7d4bb2a10 call 7ff7d4c06e14 101->110 113 7ff7d4bb5590-7ff7d4bb5592 103->113 128 7ff7d4bb57de-7ff7d4bb57e3 call 7ff7d4c13eb4 110->128 113->110 115 7ff7d4bb5598-7ff7d4bb55a8 113->115 117 7ff7d4bb55df-7ff7d4bb5604 115->117 118 7ff7d4bb55aa-7ff7d4bb55bf 115->118 123 7ff7d4bb5606-7ff7d4bb561b 117->123 124 7ff7d4bb563b-7ff7d4bb5666 call 7ff7d4c04d10 117->124 120 7ff7d4bb55c1-7ff7d4bb55d4 118->120 121 7ff7d4bb55da call 7ff7d4c04d30 118->121 120->121 120->128 121->117 125 7ff7d4bb5636 call 7ff7d4c04d30 123->125 126 7ff7d4bb561d-7ff7d4bb5630 123->126 125->124 126->125 130 7ff7d4bb57e4-7ff7d4bb57e9 call 7ff7d4c13eb4 126->130 128->130
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: ", "id":"$GET$Where are my socks?$Winhttp.dll${"n":"
      • API String ID: 3668304517-3084486490
      • Opcode ID: 52c6d12674501996d600ae5c6b18087dcd41be30664ee04f3a59ddbf578eb56f
      • Instruction ID: c2c006744293b1dba37bd192851c4ea945befef69564c87072628133ce49c61e
      • Opcode Fuzzy Hash: 52c6d12674501996d600ae5c6b18087dcd41be30664ee04f3a59ddbf578eb56f
      • Instruction Fuzzy Hash: E3129872A18BC281EA10EF26E4813ADA761FBD57D4FD05233DA9D126A5DF7CE085C720

      Control-flow Graph

      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID: NDUuNjYuMjQ5LjI0OQ==$UXpwY1ZYTmxjbk5j$WEVGd2NFUmhkR0ZjVW05aGJXbHVaMXhOYVdOeWIzTnZablJjVjJsdVpHOTNjMXhUZEdGeWRDQk5aVzUxWEZCeWIyZHlZVzF6WEZOMFlYSjBkWEJjVjJsdVpHOTNjMU5XUXk1c2Jtcz0=$Zm9yZXN0$sock
      • API String ID: 0-1601384142
      • Opcode ID: 838d58c21301ba66f7a004aa24602807d6e513183d783e348904fbaeeaa868b4
      • Instruction ID: 718d455da59b04b631ce1585a9b68cfe886f0088cfa0a73cb1a1dacb995eb83a
      • Opcode Fuzzy Hash: 838d58c21301ba66f7a004aa24602807d6e513183d783e348904fbaeeaa868b4
      • Instruction Fuzzy Hash: F471AF72B0564289EB20EF62E8941EDB7A2FB98384FC04137EA4D57B99EF38D540C710

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 268 7ff7d4bb46d0-7ff7d4bb47a2 SHTestTokenMembership call 7ff7d4c31650 GetUserNameA 271 7ff7d4bb47a5-7ff7d4bb47ad 268->271 271->271 272 7ff7d4bb47af-7ff7d4bb47c5 call 7ff7d4bcf390 271->272 275 7ff7d4bb4822 272->275 276 7ff7d4bb47c7-7ff7d4bb47cf 272->276 279 7ff7d4bb4827-7ff7d4bb482b 275->279 277 7ff7d4bb4801-7ff7d4bb4820 276->277 278 7ff7d4bb47d1-7ff7d4bb47de 276->278 277->279 280 7ff7d4bb47e0-7ff7d4bb47f3 278->280 281 7ff7d4bb47fc call 7ff7d4c04d30 278->281 282 7ff7d4bb485f-7ff7d4bb488e GetComputerNameA 279->282 283 7ff7d4bb482d-7ff7d4bb483f 279->283 285 7ff7d4bb47f9 280->285 286 7ff7d4bb4aee-7ff7d4bb4af3 call 7ff7d4c13eb4 280->286 281->277 284 7ff7d4bb4893-7ff7d4bb489a 282->284 288 7ff7d4bb4841-7ff7d4bb4854 283->288 289 7ff7d4bb485a call 7ff7d4c04d30 283->289 284->284 290 7ff7d4bb489c-7ff7d4bb48b6 call 7ff7d4bcf390 284->290 285->281 288->286 288->289 289->282 296 7ff7d4bb4918 290->296 297 7ff7d4bb48b8-7ff7d4bb48c1 290->297 300 7ff7d4bb491d-7ff7d4bb4921 296->300 298 7ff7d4bb48c3-7ff7d4bb48d1 297->298 299 7ff7d4bb48f4-7ff7d4bb4916 297->299 301 7ff7d4bb48ef call 7ff7d4c04d30 298->301 302 7ff7d4bb48d3-7ff7d4bb48e6 298->302 299->300 303 7ff7d4bb4955-7ff7d4bb4993 GetModuleFileNameW 300->303 304 7ff7d4bb4923-7ff7d4bb4935 300->304 301->299 307 7ff7d4bb4ae2-7ff7d4bb4ae7 call 7ff7d4c13eb4 302->307 308 7ff7d4bb48ec 302->308 305 7ff7d4bb49a5-7ff7d4bb49ba call 7ff7d4bd4e80 303->305 306 7ff7d4bb4995-7ff7d4bb49a3 303->306 310 7ff7d4bb4950 call 7ff7d4c04d30 304->310 311 7ff7d4bb4937-7ff7d4bb494a 304->311 314 7ff7d4bb49bf-7ff7d4bb49c6 305->314 306->314 320 7ff7d4bb4ae8-7ff7d4bb4aed call 7ff7d4c13eb4 307->320 308->301 310->303 311->307 311->310 318 7ff7d4bb49c8-7ff7d4bb49f2 314->318 319 7ff7d4bb4a2e-7ff7d4bb4a43 314->319 321 7ff7d4bb4aaf-7ff7d4bb4ae1 call 7ff7d4c04d10 318->321 322 7ff7d4bb49f8-7ff7d4bb4a0a 318->322 323 7ff7d4bb4a45-7ff7d4bb4a49 319->323 324 7ff7d4bb4a67-7ff7d4bb4a76 call 7ff7d4bd0210 319->324 320->286 327 7ff7d4bb4a10-7ff7d4bb4a23 322->327 328 7ff7d4bb4aa9-7ff7d4bb4aae call 7ff7d4c04d30 322->328 330 7ff7d4bb4a4e-7ff7d4bb4a65 call 7ff7d4c30fb0 323->330 331 7ff7d4bb4a4b 323->331 339 7ff7d4bb4a7b-7ff7d4bb4a7f 324->339 327->320 336 7ff7d4bb4a29 327->336 328->321 330->339 331->330 336->328 339->321 341 7ff7d4bb4a81-7ff7d4bb4a8f 339->341 342 7ff7d4bb4a91-7ff7d4bb4aa4 341->342 343 7ff7d4bb4aa6 341->343 342->320 342->343 343->328
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Name_invalid_parameter_noinfo_noreturn$ComputerFileMembershipModuleTestTokenUser
      • String ID:
      • API String ID: 1487706099-0
      • Opcode ID: a2be92b86f2a76cd6de73feddaf6bbaf57d5d00667dee1a597eb8376ca4a82ac
      • Instruction ID: 1fd03d971dc16d298e4eda58aba7e20c9fcbbb00e30d728fafdb2baeee233f73
      • Opcode Fuzzy Hash: a2be92b86f2a76cd6de73feddaf6bbaf57d5d00667dee1a597eb8376ca4a82ac
      • Instruction Fuzzy Hash: 92C1E662E18B8581EA10DF26D4842ADA761FB657D4FD15223EA9C22ADADF78E1C1C310

      Control-flow Graph

      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: /bc$002$003$GET$pRequest
      • API String ID: 3668304517-2660936391
      • Opcode ID: 6821f11a4b0029687b84fdeaf5abc130de5222e1d40ca23e82932a065d35dbd9
      • Instruction ID: 2601fee43a729031f7434e1b823f38b925e95238ef327e422ef5ee10a0354a5c
      • Opcode Fuzzy Hash: 6821f11a4b0029687b84fdeaf5abc130de5222e1d40ca23e82932a065d35dbd9
      • Instruction Fuzzy Hash: A4816F72A18A8681EA20EF26E5D17ADB361FB947C0FC45133D64D53AA5DF3CE505C720

      Control-flow Graph

      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: ", "v":"$NDUuNjYuMjQ5LjI0OQ==$Zm9yZXN0$invalid stoi argument$sock$stoi argument out of range${"n":"${"status":"004"}${"status":"005"}${"status":"026"}${"status":"105"}
      • API String ID: 3668304517-2369935561
      • Opcode ID: 8d6a0734a1a2f6107b3da3b6a01a667e0bd6b3a308cb62972b779b33c1b19ff9
      • Instruction ID: 3d71b968435596bb5b41da7efb740440292df1b431b7d4b4db8abc578c13d37a
      • Opcode Fuzzy Hash: 8d6a0734a1a2f6107b3da3b6a01a667e0bd6b3a308cb62972b779b33c1b19ff9
      • Instruction Fuzzy Hash: BBF090A1B1474541EA15AF26D0C836D6222DB04FC9FE44433CA5C0A68ACE6DD4868364

      Control-flow Graph

      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: GdipOpenService_invalid_parameter_noinfo_noreturn$DisposeFreeImageManagerQueryStatus
      • String ID: Seems ok$Vk1Ub29scw==$VkJveFNlcnZpY2U=
      • API String ID: 3199510081-3703604791
      • Opcode ID: 540f9263f055597c8382bee0da1726551e37c503f22e868b7c55dda0e55a9baf
      • Instruction ID: a2c12c734fdf0a4da0d55b053bf806d3db96cb68eb5a3173535df21d5c907d70
      • Opcode Fuzzy Hash: 540f9263f055597c8382bee0da1726551e37c503f22e868b7c55dda0e55a9baf
      • Instruction Fuzzy Hash: B6718132F15B4189EB10EF66E8802ADB761FB98798FD44237EA4D13A59EF38D585C310

      Control-flow Graph

      APIs
      • FreeLibrary.KERNEL32(?,?,7FFFFFFFFFFFFFFF,00007FF7D4C1F2BC,?,?,?,?,00007FF7D4C14209,?,?,?,?,00007FF7D4BDFA4C), ref: 00007FF7D4C1EA73
      • GetProcAddressForCaller.KERNELBASE(?,?,7FFFFFFFFFFFFFFF,00007FF7D4C1F2BC,?,?,?,?,00007FF7D4C14209,?,?,?,?,00007FF7D4BDFA4C), ref: 00007FF7D4C1EA7F
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: AddressCallerFreeLibraryProc
      • String ID: api-ms-$ext-ms-
      • API String ID: 3520295827-537541572
      • Opcode ID: 912c94047a0cb9539cafd7d5ce12736182df3d91ecf7096a8cea6366d4922533
      • Instruction ID: dce04f38920b554eee9bbda669f03052bd2538d0d6bf28c4a79afd28fe837c3d
      • Opcode Fuzzy Hash: 912c94047a0cb9539cafd7d5ce12736182df3d91ecf7096a8cea6366d4922533
      • Instruction Fuzzy Hash: 4C419061B19A0281EA55AF17E8941BDABA1BF45BE0FC88137DD1D87784EF3CE4458330

      Control-flow Graph

      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: __scrt_acquire_startup_lock__scrt_dllmain_crt_thread_attach__scrt_get_show_window_mode__scrt_release_startup_lock
      • String ID:
      • API String ID: 3251591375-0
      • Opcode ID: e4a17efe478abd50984052b8a0019fdc49fd87fe32912cdc85873eec47f6ce3e
      • Instruction ID: 4ad1be27efb6c3bca754fb584aa2b17a49b68d079d668586d12780cdd37c3757
      • Opcode Fuzzy Hash: e4a17efe478abd50984052b8a0019fdc49fd87fe32912cdc85873eec47f6ce3e
      • Instruction Fuzzy Hash: BC312820E0910346FA24FF67D4D93BD92919F917C4FC45037DA0E2B2D3DE2CA9058674

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 525 7ff7d4bb1de0-7ff7d4bb1e0c LoadLibraryA
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: LibraryLoad
      • String ID: Winhttp.dll
      • API String ID: 1029625771-1936088768
      • Opcode ID: 7a429ab9266b4f3fffa479279b48a073b534981f8cae20d0d5e5bf2d62eddd7e
      • Instruction ID: 3982cb8a6e37540fe89d97f66a1350a661ca37a3e63f1b83aafdc11a57482f87
      • Opcode Fuzzy Hash: 7a429ab9266b4f3fffa479279b48a073b534981f8cae20d0d5e5bf2d62eddd7e
      • Instruction Fuzzy Hash: 14D0E925F59A02C2EA54BF13ECD503DA2A4BB98791FC40177C04E85225DF2CA5998728

      Control-flow Graph

      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo
      • String ID:
      • API String ID: 3215553584-0
      • Opcode ID: dc89c29555d5d88225e870e6d7040d38a1bbc348fd38f3aaa4cad493a1cad2d3
      • Instruction ID: ee7b7fa0058dbd0d6b7a7e5069a17f12fbc187103d634ca72efb1b3a7cedc422
      • Opcode Fuzzy Hash: dc89c29555d5d88225e870e6d7040d38a1bbc348fd38f3aaa4cad493a1cad2d3
      • Instruction Fuzzy Hash: 67115B3691864282F310AF16E8C067DF7A0BB447C0FD50937E65D676A6EEBDE8108B20

      Control-flow Graph

      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo
      • String ID:
      • API String ID: 3215553584-0
      • Opcode ID: ad82f3d5463a9e98e1552197bf2295ae65c8778a080b52305350446953181a80
      • Instruction ID: 6d5390d6e163998698ea89ac5d116fb48fe604f4519f88efe066e7fd72f573b8
      • Opcode Fuzzy Hash: ad82f3d5463a9e98e1552197bf2295ae65c8778a080b52305350446953181a80
      • Instruction Fuzzy Hash: 17E01A35E0914386FA147FA6C8D23BDA2B09F483C4FD08433E20C462C2CFAD28068739

      Control-flow Graph

      APIs
      • __scrt_dllmain_crt_thread_attach.LIBCMT ref: 00007FF7D4C04E94
        • Part of subcall function 00007FF7D4C07120: __vcrt_uninitialize_ptd.LIBVCRUNTIME ref: 00007FF7D4C07128
        • Part of subcall function 00007FF7D4C07120: __vcrt_uninitialize_locks.LIBVCRUNTIME ref: 00007FF7D4C0712D
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: __scrt_dllmain_crt_thread_attach__vcrt_uninitialize_locks__vcrt_uninitialize_ptd
      • String ID:
      • API String ID: 1208906642-0
      • Opcode ID: 39a315521b5a0a89ce840e419fc18619f359d4d2551cdf961bb8d95cb46cf093
      • Instruction ID: f5b80ec7120100bd2b44381d54d5673dda24137ba02cd8665469ac3df4494a3c
      • Opcode Fuzzy Hash: 39a315521b5a0a89ce840e419fc18619f359d4d2551cdf961bb8d95cb46cf093
      • Instruction Fuzzy Hash: 67E0B610E0D15350FE593E63D6CA2BED2801F253C9ED0047BD92D321C39D5D74561AB5

      Control-flow Graph

      APIs
      • HeapAlloc.KERNEL32(?,?,00000000,00007FF7D4C1E3CA,?,?,8000000000000000,00007FF7D4C11C85,?,?,?,?,00007FF7D4C1DB64), ref: 00007FF7D4C1D64D
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: AllocHeap
      • String ID:
      • API String ID: 4292702814-0
      • Opcode ID: 207747ec03c5779b6438231ab1fa883743136f62b2697e2ac2019a5d10ff2dad
      • Instruction ID: bced15d78ba74968a1d037ec0adce3dee883698947d22b59c0c120126a8af04a
      • Opcode Fuzzy Hash: 207747ec03c5779b6438231ab1fa883743136f62b2697e2ac2019a5d10ff2dad
      • Instruction Fuzzy Hash: BEF0F954F1968781FE557E67D9952BD92B05F88BC0FC84833C90E862D2FE5CB4818230
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$Object$CreateDesktopGdipWindow$BitmapCompatibleDeleteGdiplusSelect$AllocClientEncodersFromImageRectReleaseShutdownSizeStartup
      • String ID: $", "d":"$", "uId":"$", "id":"$105$image/${"n":"${"status":"013"}${"status":"014"}${"status":"103"}
      • API String ID: 149809242-3914048934
      • Opcode ID: ef322a054e7980fd1c65c34188ce0f6eeddda7de61b96defefaa8c2d82c62b78
      • Instruction ID: ce55aa405c07e9af08d50e44c3675477f7046a5804b82855c3f18c07daf19a3d
      • Opcode Fuzzy Hash: ef322a054e7980fd1c65c34188ce0f6eeddda7de61b96defefaa8c2d82c62b78
      • Instruction Fuzzy Hash: 6DA2AE32A14BC585EB20EF26D8843ED6761FB99798FC04233DA5D57AA9DF78E184C310
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID: ", "d":"$", "id":"$", "uId":"$101$invalid stoi argument$stoi argument out of range${"n":"${"status":"010"}${"status":"102"}${"status":"110"}
      • API String ID: 0-3917518979
      • Opcode ID: ee7c6142e077d018a0edae1bb93f682eed05a56daa3bb6535a0af21e663f0f0f
      • Instruction ID: 00ade89ebf8f58469dc9380fabef47024d9a414ef073d5624bbb69c3d80f8567
      • Opcode Fuzzy Hash: ee7c6142e077d018a0edae1bb93f682eed05a56daa3bb6535a0af21e663f0f0f
      • Instruction Fuzzy Hash: 2503E262E19B8645EB10EF36D4843EDA761EB55798FD04233EA6C17ADADF38E480C314
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Lockitstd::_$Lockit::_Lockit::~_$GetcollGetctype
      • String ID: file=
      • API String ID: 19648113-2538679502
      • Opcode ID: 396c6eee7f4c872df5603970c7d1090a95535081cb8cbfcc141ec48a3ca9cc28
      • Instruction ID: 1876bcb6fd0fb64d0d9747dbb97d44d669df1c24d53cfa79417ce227ebe4fc08
      • Opcode Fuzzy Hash: 396c6eee7f4c872df5603970c7d1090a95535081cb8cbfcc141ec48a3ca9cc28
      • Instruction Fuzzy Hash: DA820C21A0BA0245EA55BF23E9D02BCA3E0AF647C4BC84537D94E67796EF3CF5418760
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Lockitstd::_$Lockit::_Lockit::~_$GetcollGetctypeGetvals
      • String ID: file=
      • API String ID: 553569086-2538679502
      • Opcode ID: 67a1c0790ef1249461a340128b7fb1e3b27baf6d4379e39df7b50e971e6fd2f5
      • Instruction ID: e164f577e9cb6d7e927d2407810608ca7cfe9484c4a1564b4f07f08d341789fd
      • Opcode Fuzzy Hash: 67a1c0790ef1249461a340128b7fb1e3b27baf6d4379e39df7b50e971e6fd2f5
      • Instruction Fuzzy Hash: CC822822A0EA0285EA51BF62D8C02BCA3E1AF647C4FC84537D94E57396EF3CF5518760
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$ByteCharMultiWide$Concurrency::cancel_current_task
      • String ID: ", "fid":"1"}$", "flDr":"$&$--------------------------346435246262465368257857$Content-Disposition: form-data; name="f"; filename="$Content-Disposition: form-data; name="fInf"$Content-Disposition: form-data; name="id"$Content-Disposition: form-data; name="m"$Content-Disposition: form-data; name="n"$Content-Type: application/octet-stream$Content-Type: multipart/form-data; boundary = $POST${"status":"008"}${"status":"024"}${"status":"111", "fName":"
      • API String ID: 3480596355-259015812
      • Opcode ID: 0838fe6f16684eb46940be8f1169d7bcf9463f7978d7b620442b91148171e785
      • Instruction ID: bb6c1e7b3d52193e6f91a63adc3388a91ebc101814d3dd306bf8d2ea4e60319c
      • Opcode Fuzzy Hash: 0838fe6f16684eb46940be8f1169d7bcf9463f7978d7b620442b91148171e785
      • Instruction Fuzzy Hash: E4F2F562B19B8185EB00EF76D4C43ADA761FBA5398FC05633EA5D16ADADF38D480C314
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$Tablehtonsinet_ntoa
      • String ID: ", "d":"$", "uId":"$", "id":"$", "uId":"$102$104$106$UXpwY1ZYTmxjbk5j$VUUU${"n":"${"status":"011"}${"status":"012"}${"status":"015"}${"status":"016"}${"status":"103"}
      • API String ID: 2861794738-2026247035
      • Opcode ID: 18c6ea4742a7190a7bc6c5767b69587352ecc130419f13d85746abf318837e22
      • Instruction ID: 57df52fb964d67adceb405696be100d9aab8265e35e92cad56e2aa8fd1664949
      • Opcode Fuzzy Hash: 18c6ea4742a7190a7bc6c5767b69587352ecc130419f13d85746abf318837e22
      • Instruction Fuzzy Hash: 53C2E322A19BC685EB10EF36D4803EDA761EB95794FD08233DA5D17ADADF78E180C310
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Lockitstd::_$Lockit::_Lockit::~_$Getcoll
      • String ID: file=
      • API String ID: 2318601406-2538679502
      • Opcode ID: c4e082c22604d0d01a263d60d7e2b20a58e754c6ccc846a024c985314d72cb5a
      • Instruction ID: 8eb7057ba4c91f47809811cbf871b6b5897799682ba84fffb242455dccdaaed8
      • Opcode Fuzzy Hash: c4e082c22604d0d01a263d60d7e2b20a58e754c6ccc846a024c985314d72cb5a
      • Instruction Fuzzy Hash: A4323B21A0AA1245EE55BF53D8C42BDA7E0AF547C0FC84437EA4E67795EF3CE8428760
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$ByteCharMultiProcess32Wide$CloseCreateFirstHandleNextSnapshotToolhelp32
      • String ID: ", "d":"$", "id":"$", "uId":"$107${"n":"${"status":"016"}${"status":"103"}
      • API String ID: 2079577941-3782765540
      • Opcode ID: 729b7cb32be10c0a944716848bbef28e45815e262deb30b19e7ef0a5808eb1ca
      • Instruction ID: ddf7b8e2cf74fcc56257248044cbb48e41c736759fbf33db0ab172eb05f0f9ac
      • Opcode Fuzzy Hash: 729b7cb32be10c0a944716848bbef28e45815e262deb30b19e7ef0a5808eb1ca
      • Instruction Fuzzy Hash: 93928362A19BC585EB20EF35D8C43EDA361FBA5798F905323D65C16AEADF78D180C310
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: memcpy_s$_invalid_parameter_noinfo
      • String ID: $
      • API String ID: 2880407647-227171996
      • Opcode ID: a3aae9aa187e148188ee3e8d0f716f249af1cb6b6161ada15a895cbeb3ca6e36
      • Instruction ID: daf33756a7952dda1f98c97cf4bcb16435ffc9234438935baeac16c6dd04dd00
      • Opcode Fuzzy Hash: a3aae9aa187e148188ee3e8d0f716f249af1cb6b6161ada15a895cbeb3ca6e36
      • Instruction Fuzzy Hash: 5D03B472A191828BE7759F26D5807FDB7A1FB943C8FC45137EA0E57B44DB389A008B60
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: " , "t":"$", "fid":"0"}$", "uId":"$Content-Type: application/json$GET$POST$file=$filename=$type=${"status":"${"status":"001"}${"status":"007"}${"status":"025"}
      • API String ID: 3668304517-724035736
      • Opcode ID: 57557a2e8098d2de54157b2f1d2863870cfbd18935dff6268356b8b7b29fb187
      • Instruction ID: c994f0576239e8c6d714eda4e5bb7d4d923414f49476889f58535e8e9bf1fe6e
      • Opcode Fuzzy Hash: 57557a2e8098d2de54157b2f1d2863870cfbd18935dff6268356b8b7b29fb187
      • Instruction Fuzzy Hash: E632C362E15B8585EB00EF36D4843ADA721EB957D4FD05323EA6C12AEADF78E5C0C350
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task$CreateErrorFileLast
      • String ID: type=1${"status":"020"}${"status":"022"}${"status":"102"}${"status":"103"}${"status":"108"}${"status":"110"}
      • API String ID: 847724067-3449146413
      • Opcode ID: a7df7adc844e351bbb82ad79d3e5ae8fdcc3bb12ac9e4706d04bc134d0cde42e
      • Instruction ID: 42467299dbca270fe9aa8b1e583737a769e503371b11f07c81d3f932c63eb724
      • Opcode Fuzzy Hash: a7df7adc844e351bbb82ad79d3e5ae8fdcc3bb12ac9e4706d04bc134d0cde42e
      • Instruction Fuzzy Hash: 2792B262F1A74281FA10EF76D4C42BDA361AFA4794FD05233D95D27AE9DE7CE5808310
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$Heap$Process$AllocCreateDestroyEnvironmentFreeParameters
      • String ID: @$\??\${"status":"021"}${"status":"109"}
      • API String ID: 1847043289-3946298159
      • Opcode ID: e90fc13a62e3c3175694a3568c6b7c2ee5b709cc2317347e5b19cb96a7f64993
      • Instruction ID: 7ec0b3f37e41276fabe563d4dd2fbe6d6e623dcdf150b5c3e495918cbdee1d11
      • Opcode Fuzzy Hash: e90fc13a62e3c3175694a3568c6b7c2ee5b709cc2317347e5b19cb96a7f64993
      • Instruction Fuzzy Hash: 94529172A15B4185EB10AF36D8C43ADA361EB907D8FC05237EA6D167EADF78E580C350
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo$memcpy_s$fegetenv
      • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
      • API String ID: 808467561-2761157908
      • Opcode ID: 6cfc1e31ae17e9f123e4776491613748614b580d476c610465501349d2b8f876
      • Instruction ID: aceb074b10ab9b7d7873718e55bdf7776609c075019fce74770d2f2af67b4031
      • Opcode Fuzzy Hash: 6cfc1e31ae17e9f123e4776491613748614b580d476c610465501349d2b8f876
      • Instruction Fuzzy Hash: 71B2B272A192828BE7649F66D4C07FDB6A1FB543C8FD05137DA0D57A84EFB8A900CB50
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Concurrency::cancel_current_task$_invalid_parameter_noinfo_noreturn
      • String ID: %$%.0Lf$+$0123456789-$0123456789-
      • API String ID: 4131450254-1072446943
      • Opcode ID: 7c9b9654659de3135487b461ef231c4f1cf79fe2bc6a67a80590afa68c787f25
      • Instruction ID: 3545ebf7eb7c0ac0adf65b43c5b0b91ce0c0f96186e4adcf39b820a79a049b6b
      • Opcode Fuzzy Hash: 7c9b9654659de3135487b461ef231c4f1cf79fe2bc6a67a80590afa68c787f25
      • Instruction Fuzzy Hash: 7CA2B062B09B8595EB10EFA6D4943BDA3B1EB54BA8FC04233DE5D13B99DE38D485C310
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: Content-Type: application/json$GET$file=$filename=
      • API String ID: 3668304517-3007091521
      • Opcode ID: 564e62709b548e43167a9803115ffd5d0a743548e56cd6dd15194f39d17b631c
      • Instruction ID: b43589967c3c2e36e11b73882711237a6437a75cf5236e56e5117de070b84a30
      • Opcode Fuzzy Hash: 564e62709b548e43167a9803115ffd5d0a743548e56cd6dd15194f39d17b631c
      • Instruction Fuzzy Hash: 44C1D372F15B8185EB10EF76E8802ADA7A1FB54798FD05633EA5C52AD9DF38E480C314
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID: invalid stoi argument$stoi argument out of range${"status":"022"}${"status":"023"}${"status":"102"}${"status":"103"}
      • API String ID: 0-4000889359
      • Opcode ID: b756f211aa819a3d698a959213f879c040ced7da72824270e3a52963b15fbec4
      • Instruction ID: 2f99bad25210a12eef723be14e26c4918fbb157c5807149675e2fbb96104932f
      • Opcode Fuzzy Hash: b756f211aa819a3d698a959213f879c040ced7da72824270e3a52963b15fbec4
      • Instruction Fuzzy Hash: AAF1D662F1974641EA20EF76D4C03BDA361EB957E4FD05233EE6D16ADADE7CE0818210
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: ", "n":"$, "id":"${"d":
      • API String ID: 3668304517-217307741
      • Opcode ID: f19ae3fc870347bc2389a68f26f546bcf0523541b74f8ed576f16b6d4eae24fc
      • Instruction ID: daeff60b7849200bf4c6a19f6f6231d10c679753f815c82d9a4dc2e16ca92fc2
      • Opcode Fuzzy Hash: f19ae3fc870347bc2389a68f26f546bcf0523541b74f8ed576f16b6d4eae24fc
      • Instruction Fuzzy Hash: 5DF1C462E18B8585EB01EF35D4853BDA721EBA57D8F905323EA6C12AD6DF78E4C0C350
      APIs
        • Part of subcall function 00007FF7D4BEE8C8: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF7D4BEE8DD
        • Part of subcall function 00007FF7D4BEE8C8: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF7D4BEE902
        • Part of subcall function 00007FF7D4BEE8C8: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF7D4BEE92C
        • Part of subcall function 00007FF7D4BEE8C8: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF7D4BEE9C4
      • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF7D4BF978D
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Lockitstd::_$Lockit::_Lockit::~_$_invalid_parameter_noinfo_noreturn
      • String ID: %H : %M$%H : %M : %S$%I : %M : %S %p$%b %d %H : %M : %S %Y$%d / %m / %y$%m / %d / %y$:AM:am:PM:pm
      • API String ID: 533778753-2891247106
      • Opcode ID: 026989573ea27209ae04e441fa7fbb74c9798316c8c905b9363d05a5be5fd6f8
      • Instruction ID: d080a64ac31f59c3c8211f0139d64b2259b60f81169abb22cca400295f3e700b
      • Opcode Fuzzy Hash: 026989573ea27209ae04e441fa7fbb74c9798316c8c905b9363d05a5be5fd6f8
      • Instruction Fuzzy Hash: E642AE32A09B4689EB24AF6AD4901BDB7A1FB58B88FC44133DE4D13B69DF39E545C310
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Lockitstd::_$_invalid_parameter_noinfo_noreturn$Lockit::_Lockit::~_$Wcsftime
      • String ID: !%x$%.0Lf$0123456789-
      • API String ID: 3423291586-778084515
      • Opcode ID: 34b021d4a9e562a6ed182eda517adbe2fc1294020da36c2c9d257be05d3169c2
      • Instruction ID: a1a0ec2db1887e6973f5e3d571e2495ad325b663e1deeb0207ec312e4b49937c
      • Opcode Fuzzy Hash: 34b021d4a9e562a6ed182eda517adbe2fc1294020da36c2c9d257be05d3169c2
      • Instruction Fuzzy Hash: 3252C362F09A8589FB11EFA6D4943BCA761AB44BD8FC44233DE5D27BA9DE38D045C310
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo
      • String ID:
      • API String ID: 3215553584-0
      • Opcode ID: f5388ea15350438e8a1582e3d0df842e881fc469dd08d470af3a11267d8be547
      • Instruction ID: 0f6a637a79bbfb552bef224a6b81d2c0550c7f447384d423843a4f898a844ffc
      • Opcode Fuzzy Hash: f5388ea15350438e8a1582e3d0df842e881fc469dd08d470af3a11267d8be547
      • Instruction Fuzzy Hash: CEC1C126A0C68696E761AF22D4D43BDB660FB45BC4FC54133DA4E077A2CFBCE4548724
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: ErrorLastNameTranslate$CodePageValidValue
      • String ID: utf8
      • API String ID: 1791977518-905460609
      • Opcode ID: 62dd0897f3a40bff9230205bb84dd3753ae87d61fcead77b1b4fb739315c740d
      • Instruction ID: eccbfcb22353cb7b01cc7a6db51c4b4c59bd681c39c8cafd788a9f36f9f4b455
      • Opcode Fuzzy Hash: 62dd0897f3a40bff9230205bb84dd3753ae87d61fcead77b1b4fb739315c740d
      • Instruction Fuzzy Hash: C5915A32A0874296E724BF23D5C12ADB2A4EB44BC0FD44133DA4D57686EFBEE9558720
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Value$Locale$CodeErrorInfoLastPageValid$DefaultEnumLocalesProcessSystemUser
      • String ID:
      • API String ID: 2591520935-0
      • Opcode ID: f752fc2ad53d96a5a2cf0e4783939982821df30ecafcf97518e638cf9fd582f7
      • Instruction ID: 9cb8446e7d49768d81c441eee95eabb71c017a472591e8c2f172b32be8e00b8d
      • Opcode Fuzzy Hash: f752fc2ad53d96a5a2cf0e4783939982821df30ecafcf97518e638cf9fd582f7
      • Instruction Fuzzy Hash: 34716922B187528AFB10AF62D8D06BDB3A0BF44B84FD44137CA1D57695EFBCA845C360
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: ExceptionFilterPresentUnhandled$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
      • String ID:
      • API String ID: 3140674995-0
      • Opcode ID: ca9133218e8fd64e453ca13e2065ac02271bf55d4d281d1e59191dc596debb9c
      • Instruction ID: 91b3db8c442d2b92eeaba79dcd8faf782594be320d3360f57177f10bbf847205
      • Opcode Fuzzy Hash: ca9133218e8fd64e453ca13e2065ac02271bf55d4d281d1e59191dc596debb9c
      • Instruction Fuzzy Hash: A6311C72709A818AEB60EF61E8843FDB364FB84794F84403BDA4E57B94DF38D5488720
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: $$+xv$0123456789-
      • API String ID: 3668304517-2753741353
      • Opcode ID: 64dbe46abcd0a748f2301b1c3c723a728d35ddea38314b42eb9914c6443c78c9
      • Instruction ID: d351735b7c2d28c21de7bd43577f647d4be072f166ab0d712d31e82c78037073
      • Opcode Fuzzy Hash: 64dbe46abcd0a748f2301b1c3c723a728d35ddea38314b42eb9914c6443c78c9
      • Instruction Fuzzy Hash: 0ED28062A0AA4699EB54AF66D4D017CB7A0FB64B84FD45033DE4E177A4CF3ED891C320
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: $0123456789-
      • API String ID: 3668304517-700845222
      • Opcode ID: 93c310f1076dfa6572f971a1e162c11640b0d77122258c6e44ead9dc76e54eb7
      • Instruction ID: 16d32edb9ef7ca0988a547510c03c0f810f5a19714657f5c66e319607125228c
      • Opcode Fuzzy Hash: 93c310f1076dfa6572f971a1e162c11640b0d77122258c6e44ead9dc76e54eb7
      • Instruction Fuzzy Hash: 65D28162A0AA4699EB14AF56D4D017CB7B0FB64B84FD46433DE4E177A4CF3AD891C320
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: %$+
      • API String ID: 3668304517-2626897407
      • Opcode ID: aaeac8550ca6e12506b71e98f6b98c11c6615126fb48153819423fe2f66e44ce
      • Instruction ID: 16cecf3bae506fe86f2966f52129733c7b3e473be23c1166a5e4a3ab4c7cf6e1
      • Opcode Fuzzy Hash: aaeac8550ca6e12506b71e98f6b98c11c6615126fb48153819423fe2f66e44ce
      • Instruction Fuzzy Hash: 7712E022B1D6858AFB259F76E4C03FDA761AB64788F844132DE4D17A89DE3CD451CB20
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: memcpy_s
      • String ID:
      • API String ID: 1502251526-3916222277
      • Opcode ID: d5921c5f5581713e7daa7186113356940e2354a9cdd6fd7f83da389ac929e130
      • Instruction ID: d0f2a294013350ac138807fefa2d0c6590575a97074a3a1d45d5592754d99990
      • Opcode Fuzzy Hash: d5921c5f5581713e7daa7186113356940e2354a9cdd6fd7f83da389ac929e130
      • Instruction Fuzzy Hash: 20C1A376A1D68687D774DF16E084A6EB7A1FB94784F848136DB8E43784DB3CE805CB20
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID: ", "d":"$", "id":"$", "uId":"$101${"n":"
      • API String ID: 0-3774563054
      • Opcode ID: 57c6288ed6cea57e80edcc7ecc00a2014172ac291a626356b348743fccb4a816
      • Instruction ID: a111298547371044c330c32f98ef4d3e30c4f92482eb2b6df5aef0a3a7c7ed20
      • Opcode Fuzzy Hash: 57c6288ed6cea57e80edcc7ecc00a2014172ac291a626356b348743fccb4a816
      • Instruction Fuzzy Hash: C3A20362E08B8585EB10DF76D4803ED6761EB957A8FD04323EA6C17AEADF78D080D314
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: ", "d":"$", "id":"$", "uId":"$101${"n":"
      • API String ID: 3668304517-3774563054
      • Opcode ID: 91c75f65d24afd891e359e78c223b4a5d7f9ed4280980d0461f2aa1c3b5be185
      • Instruction ID: 70556f2dcfe4f1d91e22860ecf661f1e37954f316bc0556d1419a1735e596485
      • Opcode Fuzzy Hash: 91c75f65d24afd891e359e78c223b4a5d7f9ed4280980d0461f2aa1c3b5be185
      • Instruction Fuzzy Hash: D0A20362E09B8585EB10DF76D4803AD6761EB957A8FD04323EA6C17AEADF78D080D314
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: ", "d":"$", "id":"$", "uId":"$101${"n":"
      • API String ID: 3668304517-3774563054
      • Opcode ID: 0121a56c495bb3f6a1cc841da0f3e66fd35cafa0e229533a941ae2acd42fdd69
      • Instruction ID: 4b229ff6a6f090b315c2a979b2a2bbdeea09f46429618f7c7a1db03e4090dde8
      • Opcode Fuzzy Hash: 0121a56c495bb3f6a1cc841da0f3e66fd35cafa0e229533a941ae2acd42fdd69
      • Instruction Fuzzy Hash: F8A20362E09B8585EB10DF76D4803AD6761EB957A8FD04323EA6C17AEADF78D0C0D314
      APIs
      Strings
      • ERROR : Unable to initialize critical section in CAtlBaseModule, xrefs: 00007FF7D4C04B27
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: DebugDebuggerErrorLastOutputPresentString
      • String ID: ERROR : Unable to initialize critical section in CAtlBaseModule
      • API String ID: 389471666-631824599
      • Opcode ID: 709f36ce9c18c584a5dd09b511388c37de8f709decbce0009373de8c9d67e20c
      • Instruction ID: 76d39e7a978a97c6a6bae043073c25976c1b6e4284c122a9ab3e73a344c847aa
      • Opcode Fuzzy Hash: 709f36ce9c18c584a5dd09b511388c37de8f709decbce0009373de8c9d67e20c
      • Instruction Fuzzy Hash: F7112832A18B4296E754AF23EA9837DA2A5FB44785FC44137C64D82A50EF3DE4788720
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _isindst$_get_daylight_invalid_parameter_noinfo
      • String ID:
      • API String ID: 2079693926-0
      • Opcode ID: 024d7a2fbe3fa35e71b706349b584e453a738bf18d77ff34baa4f6ded577213b
      • Instruction ID: 807de86031396d601a1b2c798a9ba796c75191464d2bd846008fc5fee91b22a5
      • Opcode Fuzzy Hash: 024d7a2fbe3fa35e71b706349b584e453a738bf18d77ff34baa4f6ded577213b
      • Instruction Fuzzy Hash: ED8193B2B042464BEB589F26C9813BCB2A5EB547C8F849137DB0E8A785EF7CE5418750
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 45e0ad59e8c9e26bcd656274253aea465c3f9b5a8b3e1938740b34708a10c824
      • Instruction ID: 2a53f04a6a8284a8b5aff31b0080768d38535b37edaeca097e539604888324c7
      • Opcode Fuzzy Hash: 45e0ad59e8c9e26bcd656274253aea465c3f9b5a8b3e1938740b34708a10c824
      • Instruction Fuzzy Hash: 6752D462A19A858AEB10DF2AD4845BDB3A1FB64B88FC44133EE8D43B95DF3DD585C310
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: ef44f5b996b0a4c97cd421fa2f7b2eec2c956ec4453700ee090a862ad28ef570
      • Instruction ID: 2db583a02e6b36fc50e5924351bf5475c0dcf78433e2a9c031bfd855a206fe05
      • Opcode Fuzzy Hash: ef44f5b996b0a4c97cd421fa2f7b2eec2c956ec4453700ee090a862ad28ef570
      • Instruction Fuzzy Hash: 2E52D462A19A859AEB10EF2AD4845BDB3A1FB54B88FC44133EE4D13795DF3DD582C310
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Lockitstd::_$Lockit::_Lockit::~_
      • String ID: 0123456789ABCDEFabcdef-+XxPp$gfffffff
      • API String ID: 593203224-1108341528
      • Opcode ID: 4d51fc69ed0aefbb7a54308f17d5018c06b0431565279e3e57718adadde6371e
      • Instruction ID: 9c0f8db43de4e91ca14363e32bb38475123ef5634a0600ca1d5753229f5fd8c6
      • Opcode Fuzzy Hash: 4d51fc69ed0aefbb7a54308f17d5018c06b0431565279e3e57718adadde6371e
      • Instruction Fuzzy Hash: 6EF2B326A0AA4685EB60AF1BD19017DB3A0FFA1B84BD49033DF5E07791CF2DD865D324
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Lockitstd::_$Lockit::_Lockit::~_
      • String ID: 0123456789ABCDEFabcdef-+XxPp$gfffffff
      • API String ID: 593203224-1108341528
      • Opcode ID: 4bff4011c69dc2bffa4ca5d965b1aff102f176220c1171cf0afa2514a101b1f7
      • Instruction ID: 766a331a38e19c5044bb72ff80446ca26aff8169671380d0227b7b3d1e65ff9d
      • Opcode Fuzzy Hash: 4bff4011c69dc2bffa4ca5d965b1aff102f176220c1171cf0afa2514a101b1f7
      • Instruction Fuzzy Hash: 07F2D266A0A6468AEB60DF1BD19013CB764FFA5B84BD49033DB4E07791CF2DE861C724
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Lockitstd::_$Lockit::_Lockit::~_
      • String ID: 0123456789ABCDEFabcdef-+XxPp$gfffffff
      • API String ID: 593203224-1108341528
      • Opcode ID: c421abd8b1227590fafa7866595071cb9ef304930f6dcaa7988eefdff358e5b6
      • Instruction ID: 96249bb505b2f0edf93401b826440278b95c83f0e841e931a1aeea4c35a45b60
      • Opcode Fuzzy Hash: c421abd8b1227590fafa7866595071cb9ef304930f6dcaa7988eefdff358e5b6
      • Instruction Fuzzy Hash: 0AF2B522B0A68589EB519F2BC1D037CB761EBA1B88FE49133CA5D47791CF2DD462C324
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _get_daylight_invalid_parameter_noinfo
      • String ID:
      • API String ID: 474895018-0
      • Opcode ID: 9519d5d6927c0dceee90412c84b97ab75983e3401561576c12abd0c3b33256e1
      • Instruction ID: 30f0c69fbfe245f5af9a663a7de91a9aac550050edcb521a514ad92aae1ba57e
      • Opcode Fuzzy Hash: 9519d5d6927c0dceee90412c84b97ab75983e3401561576c12abd0c3b33256e1
      • Instruction Fuzzy Hash: 6C929C32A0868286E728AF26D4D817DA7A5FB457C4FC44137EB8D27AD5DF3DE5018B20
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: InfoLocale
      • String ID: GetLocaleInfoEx
      • API String ID: 2299586839-2904428671
      • Opcode ID: 45432cefa987a8ddb26bcb9aa938afebbc246bbe92d0c79083534491fcf22730
      • Instruction ID: 0c3197a88a5af92a8a0ffbe0e48ae89bec3ceb4fe14f4c73d5b816c809f75d0b
      • Opcode Fuzzy Hash: 45432cefa987a8ddb26bcb9aa938afebbc246bbe92d0c79083534491fcf22730
      • Instruction Fuzzy Hash: 9A012125B0868185E754BF57E4840BEE660AF84BD0FD84037DE4D43B6ACE2CD5418760
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3668304517-0
      • Opcode ID: 0e8365d8b205fea13b78dd6ceb5cc1ac767074d11a9a9471fc7cb433d0944f90
      • Instruction ID: 60884a6c85ee914c7eeecd67c032666ffd10f791d18bfca4a8ede3452feea04b
      • Opcode Fuzzy Hash: 0e8365d8b205fea13b78dd6ceb5cc1ac767074d11a9a9471fc7cb433d0944f90
      • Instruction Fuzzy Hash: B6F1F752F19A848AFB14AF66D4903FDA3A1AF547D8FC48332EE5D27A99DE2CD141C310
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3668304517-0
      • Opcode ID: 7f3d26e1593e39e1a10a5e8ff1769929c7ce844638a16bdf71775aefefaf4499
      • Instruction ID: 6acb0020352b70d67f69c08153b7dae8a5bcf968ce472105e880d0237b1f5ccc
      • Opcode Fuzzy Hash: 7f3d26e1593e39e1a10a5e8ff1769929c7ce844638a16bdf71775aefefaf4499
      • Instruction Fuzzy Hash: EFF1E852B19A848AFB14AF66D4903FDA3A1AF547D4FC44332EE5C27A99EE2CD145C310
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: ExceptionRaise_clrfp
      • String ID:
      • API String ID: 15204871-0
      • Opcode ID: 39e1f376b379eddbde7b102e04ecedd1f0283ba68647ca32517d18baf4289d42
      • Instruction ID: f1dfbff668cfcda82c15988ce03252d88e8383a339badd827a2f5ba5e00d4173
      • Opcode Fuzzy Hash: 39e1f376b379eddbde7b102e04ecedd1f0283ba68647ca32517d18baf4289d42
      • Instruction Fuzzy Hash: 4BB14973A00B858BEB15DF2AC8C636CB7A0F744B88F958923DA5D877A4CB79D851C710
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: ErrorFreeHeapInformationLastTimeZone_get_daylight
      • String ID:
      • API String ID: 3817840142-0
      • Opcode ID: dcf3cfaab941910156589bad44e65512d7baf0601cf28d33dea5fbd4a63b99ea
      • Instruction ID: 4b36b406660740310691dd3f6ca4f6af9e3146184d6bcd5749389f1a9a71433f
      • Opcode Fuzzy Hash: dcf3cfaab941910156589bad44e65512d7baf0601cf28d33dea5fbd4a63b99ea
      • Instruction Fuzzy Hash: 94411C32A1864286E714FF23E8D15BDB6A0BB487C4FC44537EA4D876A5EF3CE4418B64
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID: e+000$gfff
      • API String ID: 0-3030954782
      • Opcode ID: 9952dff17a6e0b28f1c47ad7625a1f8cb13026598cfda70a363bfcb1f793575a
      • Instruction ID: c0963d5c26aa3cd19d41f091098f9191aa615f752e17d45598301b3a63062650
      • Opcode Fuzzy Hash: 9952dff17a6e0b28f1c47ad7625a1f8cb13026598cfda70a363bfcb1f793575a
      • Instruction Fuzzy Hash: 34512162B186C586E7249E27D8C176DBBA1E744BD4FC88233CBAC4BAD5CEBDD4418710
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Lockitstd::_$Lockit::_Lockit::~_
      • String ID: 0123456789ABCDEFabcdef-+Xx
      • API String ID: 593203224-2799312399
      • Opcode ID: ea9d776c45aea9a44ce6d9e28d219698def782b8cb8146fa504f5756bcf6936f
      • Instruction ID: e176eb2ac8bb8c4d67714b15f94059473e947b167ae670be105f80611dd87525
      • Opcode Fuzzy Hash: ea9d776c45aea9a44ce6d9e28d219698def782b8cb8146fa504f5756bcf6936f
      • Instruction Fuzzy Hash: 62727726A0A68689EB519F2AC09017CB7B1EFA0F88BD49033DE4E17795CF3DD851D724
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Lockitstd::_$Lockit::_Lockit::~_
      • String ID: 0123456789ABCDEFabcdef-+Xx
      • API String ID: 593203224-2799312399
      • Opcode ID: 973f37aa93a0d019f595dddc61c82ec5c018c339e496f414752873abb2b5094c
      • Instruction ID: d324b48f11bafe106bf4700605a0afb9ea765f0a78dc562cc94dce35b93d38f1
      • Opcode Fuzzy Hash: 973f37aa93a0d019f595dddc61c82ec5c018c339e496f414752873abb2b5094c
      • Instruction Fuzzy Hash: 5A724226A0E64689EB51DF26C09027CB7A1EFA0F88BD49033DE4D1B7A5CE3DD841D764
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Lockitstd::_$Lockit::_Lockit::~_
      • String ID: 0123456789ABCDEFabcdef-+Xx
      • API String ID: 593203224-2799312399
      • Opcode ID: 8b0cf6414e84dd9bcc1a7c0fa230220f4878bfbeb7e5d67c0ba136a9a7323d7c
      • Instruction ID: 8bc1cd22603f9993abf43ef4ce47d97ef9d57a9aa0e51d21083f9e22571912b2
      • Opcode Fuzzy Hash: 8b0cf6414e84dd9bcc1a7c0fa230220f4878bfbeb7e5d67c0ba136a9a7323d7c
      • Instruction Fuzzy Hash: 43729722A0A68589EB559F2AC49037CB7B1EBA1F98FD45133CA4D173A5CF3DD842D324
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Info
      • String ID:
      • API String ID: 1807457897-0
      • Opcode ID: 3c6382313bb41b2851cfb189bd452b790050670863c99794003037fc7f0be717
      • Instruction ID: d65cca732eaca25b11f63c2dad36bd3a2fbe477176026ddd87fc67855856918a
      • Opcode Fuzzy Hash: 3c6382313bb41b2851cfb189bd452b790050670863c99794003037fc7f0be717
      • Instruction Fuzzy Hash: 6712B122A08BC186E751DF29D5946FDB7A4FB58788F858237EF8D42652EF39E181C310
      APIs
        • Part of subcall function 00007FF7D4BEE7B0: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF7D4BEE7C5
        • Part of subcall function 00007FF7D4BEE7B0: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF7D4BEE7EA
        • Part of subcall function 00007FF7D4BEE7B0: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF7D4BEE814
        • Part of subcall function 00007FF7D4BEE7B0: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF7D4BEE8AC
      • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF7D4BF89AD
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Lockitstd::_$Lockit::_Lockit::~_$_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 533778753-0
      • Opcode ID: af87c9e842256e83c81d9ee310d1c56a49c79a1967f1ac551558253c834198e5
      • Instruction ID: 68880268cf96055bf96e489e8535b2ede532f6c0faa11e97b06da4d7609019a3
      • Opcode Fuzzy Hash: af87c9e842256e83c81d9ee310d1c56a49c79a1967f1ac551558253c834198e5
      • Instruction Fuzzy Hash: EBD17B22B05B4699EB10EF66D4802ADA7B1FB64B98FC48133DE8D277A9DF39D445C310
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3668304517-0
      • Opcode ID: 5cf1311638112db07b927694fef8e6396ca2c9b095fa6c551ed0c097e664b80b
      • Instruction ID: 6a8be89b5b5d809d15942ade8499ecc0c45a5290202068c5cf85344a6767e49d
      • Opcode Fuzzy Hash: 5cf1311638112db07b927694fef8e6396ca2c9b095fa6c551ed0c097e664b80b
      • Instruction Fuzzy Hash: 53B1132260E68186EF219F1AD09037DBBA1EB61B88FD841B7DA9E077D5CF6CD441C710
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _get_daylight_invalid_parameter_noinfo
      • String ID:
      • API String ID: 474895018-0
      • Opcode ID: 7a04537e4f0c6fc99f1a4c970968e9cdf89bd7abc21a88531081b7fd270944c8
      • Instruction ID: a8b633aba2effd41f6438bd086b355b9670c0619f7a9c8bd69ba930e9b8b66b4
      • Opcode Fuzzy Hash: 7a04537e4f0c6fc99f1a4c970968e9cdf89bd7abc21a88531081b7fd270944c8
      • Instruction Fuzzy Hash: 7161B222F0C6928AFB64AD2AD4C077DF1919F447E0FD54637DA5D866D2FEADE8008720
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: f1e16e5d671d89c29f79eaeb6640cc837820a088961377a8c5a45492aa46f04c
      • Instruction ID: 27aac662ef901639f01f5bb57ff3d40b73d116ffc56bc50cc4d468a8281a5d40
      • Opcode Fuzzy Hash: f1e16e5d671d89c29f79eaeb6640cc837820a088961377a8c5a45492aa46f04c
      • Instruction Fuzzy Hash: CC51E322B0878185EB20AF73E8C45AEBBA0BB407D4F944137EE5D27A99DE7CD001C710
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: ErrorLastValue$InfoLocale
      • String ID:
      • API String ID: 673564084-0
      • Opcode ID: e6cff381f708a6e4bed4a41e6150083fc0489feac95b7f7c59ea85fe37f47e98
      • Instruction ID: 1fee801b429cec3305ec7eb5f4027686ddcb04553c2b22eeae835140cef049f0
      • Opcode Fuzzy Hash: e6cff381f708a6e4bed4a41e6150083fc0489feac95b7f7c59ea85fe37f47e98
      • Instruction Fuzzy Hash: B8318D32A0868297EB64EF26D5C13AEB2A0FB487C4FC48037DA5D87696DF7DE4518710
      APIs
        • Part of subcall function 00007FF7D4C1E1F0: GetLastError.KERNEL32 ref: 00007FF7D4C1E1FF
        • Part of subcall function 00007FF7D4C1E1F0: FlsGetValue.KERNEL32 ref: 00007FF7D4C1E214
        • Part of subcall function 00007FF7D4C1E1F0: SetLastError.KERNEL32 ref: 00007FF7D4C1E29F
      • EnumSystemLocalesW.KERNEL32(?,?,?,00007FF7D4C2B24B,?,00000000,00000092,?,?,00000000,?,00007FF7D4C1C339), ref: 00007FF7D4C2AAFE
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: ErrorLast$EnumLocalesSystemValue
      • String ID:
      • API String ID: 3029459697-0
      • Opcode ID: 9e44754d9577773977ea80c74dd13d3e76b8718e7eff8b86a5b4e7f7b291e66c
      • Instruction ID: f27597645d7744371a276c3e5ff3b510b7f696dc88f270b233a079d8c1ecd559
      • Opcode Fuzzy Hash: 9e44754d9577773977ea80c74dd13d3e76b8718e7eff8b86a5b4e7f7b291e66c
      • Instruction Fuzzy Hash: CA11C067A08645EAEB24AF16D1C06ADBBA1FB40BE0FC48137C62D432C0DA69D9D1CB50
      APIs
        • Part of subcall function 00007FF7D4C1E1F0: GetLastError.KERNEL32 ref: 00007FF7D4C1E1FF
        • Part of subcall function 00007FF7D4C1E1F0: FlsGetValue.KERNEL32 ref: 00007FF7D4C1E214
        • Part of subcall function 00007FF7D4C1E1F0: SetLastError.KERNEL32 ref: 00007FF7D4C1E29F
      • GetLocaleInfoW.KERNEL32(?,?,?,00007FF7D4C2ADC5), ref: 00007FF7D4C2B053
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: ErrorLast$InfoLocaleValue
      • String ID:
      • API String ID: 3796814847-0
      • Opcode ID: 9d0b2ffe273e1f4fed17e8bd1c313f9a0eaebc25c880ac3e083329c0c2e7b654
      • Instruction ID: 4d75a9d0a812d02d6fc23b3394c1dec56620344288a0121555772f69ab53dcec
      • Opcode Fuzzy Hash: 9d0b2ffe273e1f4fed17e8bd1c313f9a0eaebc25c880ac3e083329c0c2e7b654
      • Instruction Fuzzy Hash: E911E772A1859286E765EF23D0C067EB261EB44BA0FD44133EA7D076C5EE79D8818750
      APIs
      • EnumSystemLocalesW.KERNEL32(?,?,00000000,00007FF7D4C1ECCB,?,?,?,?,?,?,?,?,00000000,00007FF7D4C2A0AC), ref: 00007FF7D4C1E8C7
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: EnumLocalesSystem
      • String ID:
      • API String ID: 2099609381-0
      • Opcode ID: a93aaad4e12693b5b086b917930b389686b377b09538789090b40f77a9a41231
      • Instruction ID: fbbf8a9beb0baba233f11505980313253966d746f1469d80f10e105403fa7f79
      • Opcode Fuzzy Hash: a93aaad4e12693b5b086b917930b389686b377b09538789090b40f77a9a41231
      • Instruction Fuzzy Hash: A1F01976B08A4182E604EF1AE9915ADA371FB987C0FD88137DA5D93369CF3CD550C354
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID: gfffffff
      • API String ID: 0-1523873471
      • Opcode ID: 794b6b85d57e6143a27c57cba61a4ebcd47d9c8f9dbfa1945f9a65145824eb81
      • Instruction ID: 643c875b8ba1337dd02c061be7540067d8071c46bb5e84446f42db32b5e3e357
      • Opcode Fuzzy Hash: 794b6b85d57e6143a27c57cba61a4ebcd47d9c8f9dbfa1945f9a65145824eb81
      • Instruction Fuzzy Hash: 4FA11162A087C686EB21DF27E4807AEBBA1AB54BC4F858133CF4D47785EA7DE501C711
      APIs
      • GetLastError.KERNEL32 ref: 00007FF7D4C26329
        • Part of subcall function 00007FF7D4C1D5F8: HeapAlloc.KERNEL32(?,?,00000000,00007FF7D4C1E3CA,?,?,8000000000000000,00007FF7D4C11C85,?,?,?,?,00007FF7D4C1DB64), ref: 00007FF7D4C1D64D
        • Part of subcall function 00007FF7D4C1DB30: HeapFree.KERNEL32 ref: 00007FF7D4C1DB46
        • Part of subcall function 00007FF7D4C1DB30: GetLastError.KERNEL32 ref: 00007FF7D4C1DB50
        • Part of subcall function 00007FF7D4C2E374: _invalid_parameter_noinfo.LIBCMT ref: 00007FF7D4C2E3A7
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: ErrorHeapLast$AllocFree_invalid_parameter_noinfo
      • String ID:
      • API String ID: 916656526-0
      • Opcode ID: f9b88f2107271149bc3535cc48857f35e922378b7ddc4875876bfe8fb7144504
      • Instruction ID: c5032899bab21b01827031914a9fe24a3c4da15cf6164df3577c6893da94c6b7
      • Opcode Fuzzy Hash: f9b88f2107271149bc3535cc48857f35e922378b7ddc4875876bfe8fb7144504
      • Instruction Fuzzy Hash: 80416121B1968241EA60BE27E8D16BEF6907F857C4FC84537DE8D47B85EE7CE4019630
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: HeapProcess
      • String ID:
      • API String ID: 54951025-0
      • Opcode ID: ac1f6705ad9a3939b16cf4e579eb91725149cf93cfec8d41fb06b871f5ffea49
      • Instruction ID: ffc673e93fafba11793ddf6b870e554acf35a393cb18c8bf01710819ef2c0bb6
      • Opcode Fuzzy Hash: ac1f6705ad9a3939b16cf4e579eb91725149cf93cfec8d41fb06b871f5ffea49
      • Instruction Fuzzy Hash: 74B09220F17A02C2EA093F22ACCB22C62A56F88740FD8043BC00D80330DE2C30F95B20
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Lockitstd::_$Lockit::_Lockit::~_
      • String ID:
      • API String ID: 593203224-0
      • Opcode ID: e28e951fa2e8ffb585d96571ab97b3f57ac350516693fce54ef1d3af4be56964
      • Instruction ID: 715d014664d76145a191e9d33a4baf141d26db3e21be0a670b31a58b520d34db
      • Opcode Fuzzy Hash: e28e951fa2e8ffb585d96571ab97b3f57ac350516693fce54ef1d3af4be56964
      • Instruction Fuzzy Hash: 6E22A322F0868686EB21AF26D4883BDA761FB54B88FC54133DE8D27755DE3CE985C710
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo$AllocHeap
      • String ID:
      • API String ID: 443252259-0
      • Opcode ID: 6964823ca8642a5af7a9c54e1d0b42cb12e8f60dbf1da35b588f3f8206867df7
      • Instruction ID: 300a84e5fb15d79cc5620251f404527a933848ca16990bfb8b361dba926473a3
      • Opcode Fuzzy Hash: 6964823ca8642a5af7a9c54e1d0b42cb12e8f60dbf1da35b588f3f8206867df7
      • Instruction Fuzzy Hash: 6102F871F04A9640EF60EE27C9881FDA3A5EB947E4FD45233DE6E573D4EE29D4428220
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 4822b5c2577af7dd3d9ceb3033f2715f059c44100626e067fb054da6d963c7ce
      • Instruction ID: 70e265ddd37a278bc17ab1b1a33513882a8a486dcb6067f6cfc949c60f63f30c
      • Opcode Fuzzy Hash: 4822b5c2577af7dd3d9ceb3033f2715f059c44100626e067fb054da6d963c7ce
      • Instruction Fuzzy Hash: B5D1A426A0864686EB64AF2BC08027DA7B1EB05BC8FD44237DE4D57AD5CF39E442C374
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: ErrorLastNameTranslate$CodePageValidValue_invalid_parameter_noinfo
      • String ID:
      • API String ID: 4023145424-0
      • Opcode ID: ce827e23b5fb9fb048f2fdd3c7457ec4e9fb83c6efa7c177d8ecfdf58fe21a12
      • Instruction ID: 22e68e96e31dfc43b2b97ed9318c50c84af070c538a335d6f372f04cc6d59b82
      • Opcode Fuzzy Hash: ce827e23b5fb9fb048f2fdd3c7457ec4e9fb83c6efa7c177d8ecfdf58fe21a12
      • Instruction Fuzzy Hash: 5DC19665A0868185EB64AF63D4903BEA7B0FB947C8FC04037EE4E97699DE3CD545CB20
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: e9c7b20eb71a5b2964de6ca0bca0f38bfffaca83e06991a8733f1a37c5226840
      • Instruction ID: bccb17884d3f3dcf5cb5c447703f42d0b564a0058e072c8e45f3ea8ad8ed841a
      • Opcode Fuzzy Hash: e9c7b20eb71a5b2964de6ca0bca0f38bfffaca83e06991a8733f1a37c5226840
      • Instruction Fuzzy Hash: 3C910526B1824247FA256E2AD4903BD96A0AF417D8FDC153BDE6E477C0DD3CE9069730
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: ErrorLastValue$CurrentFeatureInfoLocalePresentProcessProcessor
      • String ID:
      • API String ID: 2071376764-0
      • Opcode ID: e12076cdc0c0cdc7fe1b0f0b1b4ad132a50841606ac88c01f83246212a4c5ec9
      • Instruction ID: 57da29bf7a64eb02e32363c9896a64b2a5e85ca5effe1f044b936a9fec78efa8
      • Opcode Fuzzy Hash: e12076cdc0c0cdc7fe1b0f0b1b4ad132a50841606ac88c01f83246212a4c5ec9
      • Instruction Fuzzy Hash: 76B19122A1864697EB64AF22D4C16BEB3A1FB44BC8FC04133DA4D836C5DFBDE5518760
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 1482580fe5820d1ed51b21129fc6c885640b63bc2115ddbd9026485005cb11b0
      • Instruction ID: 0ee4171c8ffa50bd5060b3360c26ff0bab86cae010a063b8793ffa6da2cfac2e
      • Opcode Fuzzy Hash: 1482580fe5820d1ed51b21129fc6c885640b63bc2115ddbd9026485005cb11b0
      • Instruction Fuzzy Hash: C691A022B0AE9289FF10EF66C4901BCA7A1EF94BD8BD48032DE5D17795DF29D491C324
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 64db8b3930721d7cd7e68643915407db51066f5bba8df27865b8459d2248eb55
      • Instruction ID: 9fdd72521a37a1c1656f54e7b85ff84038904cae8de27f5ad58abd8bcb5ec749
      • Opcode Fuzzy Hash: 64db8b3930721d7cd7e68643915407db51066f5bba8df27865b8459d2248eb55
      • Instruction Fuzzy Hash: 2B91A226B0A69295FF10EF66C49017CB7A1EF95B98BD48036DE0E17B94DF39D881C324
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 87f45778ff971aba7ce3f734c2651c6e97fec5afbed90dd1b1c86f56fd86f035
      • Instruction ID: acca2a1b97233c15b54c6492a6fe01bb384c1766026a50182b85b21ca508c0e1
      • Opcode Fuzzy Hash: 87f45778ff971aba7ce3f734c2651c6e97fec5afbed90dd1b1c86f56fd86f035
      • Instruction Fuzzy Hash: 0591A022B0A69689FF11DF77D8902BC6BA1EF95B88FD84032CE4E17795DE28D441C324
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo
      • String ID:
      • API String ID: 3215553584-0
      • Opcode ID: 4ad6b9f4432906f135b8dd3c72e53b1a22c067a589a710dc80522fe65d7b5cdb
      • Instruction ID: a6081b8061982789e90c22c2842ca165e73c77a85320f632ac6b060fb3dea128
      • Opcode Fuzzy Hash: 4ad6b9f4432906f135b8dd3c72e53b1a22c067a589a710dc80522fe65d7b5cdb
      • Instruction Fuzzy Hash: 96818922A04A5286EB64EE26C4C53BDA370FB44BD8F948637EE5E87795CF38D4418360
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: c85187abf30c5ce538421c33984565d9305ba6d6c58eded8eb0eb882ace783bf
      • Instruction ID: 29e9d5de6894f9633231c3f25cacc891cbadcd8bc93b3cdbcf706655c90dde78
      • Opcode Fuzzy Hash: c85187abf30c5ce538421c33984565d9305ba6d6c58eded8eb0eb882ace783bf
      • Instruction Fuzzy Hash: C781BF72A0868186EB64DE1AD4C037EB6A1FB867D4FD44237DA9D43B99CE7DD5008B10
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 89a9baa5c6f6a1324998f8c6abba3616a79418b5feb9c6b3328fbf741c304964
      • Instruction ID: 6162be4404a1f6379fa91c08ecbc4849e82d0fd86e6facbc63ee97c08493c888
      • Opcode Fuzzy Hash: 89a9baa5c6f6a1324998f8c6abba3616a79418b5feb9c6b3328fbf741c304964
      • Instruction Fuzzy Hash: 5151C532A1865182E7299F2AC09937CA760EB55B98FD50137CF4D27798CF68ECC1C7A0
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: b2fc44ad14a614332960738f91919508aaa3738b51a3d202a8b17e26d1b4cd2a
      • Instruction ID: d037b42a833f5fb329893329e4e4cdd7adc5a6b3d661593b322571600501fabb
      • Opcode Fuzzy Hash: b2fc44ad14a614332960738f91919508aaa3738b51a3d202a8b17e26d1b4cd2a
      • Instruction Fuzzy Hash: 75519677A1865182E7689F26C09833CA760EB55BA8FD50137CF4D27795CF68EC81C790
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: e00f397ae338938fd8b8a1234f6058bf6b7253c494a8c7dedd4426e63cb650a7
      • Instruction ID: c60e3c82509bc35c79d1e295cdc34d91754c5fa9071b7ea73c024abe63be8002
      • Opcode Fuzzy Hash: e00f397ae338938fd8b8a1234f6058bf6b7253c494a8c7dedd4426e63cb650a7
      • Instruction Fuzzy Hash: BC51A773A0851182E7299F2AC0D823CA760EB55B98FD50137CF4E67799CF69EC81C760
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: ErrorFreeHeapLast
      • String ID:
      • API String ID: 485612231-0
      • Opcode ID: 9c31f07231d4a45a650701019bc74ff76c00fe044c85a6861c68b665763c22ca
      • Instruction ID: 838276e2ba7c4d5b42fab00e050e16f8729772ad1d34588a0a83af1ca7dbcb56
      • Opcode Fuzzy Hash: 9c31f07231d4a45a650701019bc74ff76c00fe044c85a6861c68b665763c22ca
      • Instruction Fuzzy Hash: F541E122714A5482EF44DF2BD9A416DB3A1BB48FD4BC99037EE0D97B58EE3CD0428310
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: d6493d6e35529629c397c204590ddb3bde36fd56b60c7bb670539de328662dbf
      • Instruction ID: 3788c0bcdc4b6b2e27447ea30a48e4f8616da8dcb007d46572126c2ad1d4e27e
      • Opcode Fuzzy Hash: d6493d6e35529629c397c204590ddb3bde36fd56b60c7bb670539de328662dbf
      • Instruction Fuzzy Hash: 94416733B155548BDB8CCE2AC8656AD73A2F3DC304F89C239DA1AC7385DA359905CB40
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 49246b04862395ee029d2994fd82be78ec5b7bbecae9447cd8274b0296db14a3
      • Instruction ID: 2bb12883db50e5b5c7137d3e0d28714bd0413eb78eaa769e9ea41f9bf219a004
      • Opcode Fuzzy Hash: 49246b04862395ee029d2994fd82be78ec5b7bbecae9447cd8274b0296db14a3
      • Instruction Fuzzy Hash: 4CF0FF72A286958ADBA49F2AE84263DB7A0E7483C4BD0843BD68DC3A14D63C94618F14
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo
      • String ID: 0$0$0$0
      • API String ID: 3215553584-3558443385
      • Opcode ID: e93bfac5235ef71cd426514e060948761f247dc8953c00dea033de83a4a23df1
      • Instruction ID: eca6a4ffe87dd6387a496d42a5c26d89bad0e81ed1ea5332cc901e10edb87492
      • Opcode Fuzzy Hash: e93bfac5235ef71cd426514e060948761f247dc8953c00dea033de83a4a23df1
      • Instruction Fuzzy Hash: ACF1B432A096868AF751AE16C5D42BDBBF1AB15BC0FD84033C78C47795DE2D94558730
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: invalid stoi argument$stoi argument out of range$type=0
      • API String ID: 3668304517-70522167
      • Opcode ID: a09c7e5c2d23c9f4d4aec673c2591103bbc3faef796065eeb9ac9be67246059b
      • Instruction ID: 1a1d61826426d72f71f7a39ebb6801c3fd809bb504df6342aecea38303c48115
      • Opcode Fuzzy Hash: a09c7e5c2d23c9f4d4aec673c2591103bbc3faef796065eeb9ac9be67246059b
      • Instruction Fuzzy Hash: 6171A122F19B4295F710EF72E8C03ADA3B1AB55788FC44537EE4C26A99DE38E555C320
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: ByteCharMultiWide
      • String ID: /fileEndpoint?$/infoEndpoint?$/taskEndpoint?
      • API String ID: 626452242-4035432986
      • Opcode ID: 6dfd119fe7f24439e64abed31e3f9a06fc0040ed8949a8e682c6a5c46fd5acd1
      • Instruction ID: 9fa1092fb158cf1d659a7ae1c1f40ad37e536f1d749fbc8861094e873a5c7bcb
      • Opcode Fuzzy Hash: 6dfd119fe7f24439e64abed31e3f9a06fc0040ed8949a8e682c6a5c46fd5acd1
      • Instruction Fuzzy Hash: 96417D76A09B8182E734EF53F944169B6A2F788BD4F88423BDA8C17B65CF3CD1419704
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Lockit::_$Lockit::~_$Concurrency::cancel_current_taskFacet_Locinfo::_Locinfo_ctorRegister
      • String ID: ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
      • API String ID: 2294326227-1866435925
      • Opcode ID: 86fe1b2093ae2041e83959f1dff7804b2bc232e9e5e410c9bfc820932902e2a8
      • Instruction ID: 84f0ec9984e94d80167c3966bf2156eb0bceb2a876dc037bcdf2b1a596812afb
      • Opcode Fuzzy Hash: 86fe1b2093ae2041e83959f1dff7804b2bc232e9e5e410c9bfc820932902e2a8
      • Instruction Fuzzy Hash: 80913C3260AB8581EA24DF26E4813ADB7A1FB94B84FD48137DA8D43B65DF3CD456C710
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Concurrency::cancel_current_taskstd::_$Lockit$Locinfo::_Locinfo_ctorLockit::_Lockit::~_
      • String ID: bad locale name$false$true
      • API String ID: 4121308752-1062449267
      • Opcode ID: a96fadd14a7eb2f3f58b98dbe9cb50c9b1a43cb1f5cb2863c14212cbc0dac3e7
      • Instruction ID: af0e87ed7f0c0baa5c09d7a5690cc54f7932d2a24f2385d49d347b2f3c1d86a8
      • Opcode Fuzzy Hash: a96fadd14a7eb2f3f58b98dbe9cb50c9b1a43cb1f5cb2863c14212cbc0dac3e7
      • Instruction Fuzzy Hash: 4F618F32A0AB418AEB14EFA2D4903BCB7B1EF54744FC81136DA4D27A96DF38E455C324
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: File$CreateErrorLast_invalid_parameter_noinfo$CloseHandle$Type_get_daylight
      • String ID:
      • API String ID: 1330151763-0
      • Opcode ID: 1ff1ce3bc5de2cde991e5a49a17d146b584b1235a50141dcf283e721ad9a4ef4
      • Instruction ID: 854f4ae967066e44cd4577b03e4f33863473a779ab9bfdda5eed55286d248604
      • Opcode Fuzzy Hash: 1ff1ce3bc5de2cde991e5a49a17d146b584b1235a50141dcf283e721ad9a4ef4
      • Instruction Fuzzy Hash: E0C1C036B28A4285EB10DFAAC4D06AC7761FB49BE8B840237DB1E57394DF78E051C720
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo
      • String ID: 0$f$p$p
      • API String ID: 3215553584-1202675169
      • Opcode ID: 3c7a9cd9be296de5bd08ebe4132baff99b533e7609acdf59f14f58abcc8e45d7
      • Instruction ID: d6ced36f14dbe80af14f547bf4658f97166d2eab2a4c45f553ab62e2c6170c28
      • Opcode Fuzzy Hash: 3c7a9cd9be296de5bd08ebe4132baff99b533e7609acdf59f14f58abcc8e45d7
      • Instruction Fuzzy Hash: A7128D6AA0C14386FB24BE16D08477EF671EB81790FD44033E68E666C4DB3CE9809B71
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
      • String ID: file=
      • API String ID: 2081738530-2538679502
      • Opcode ID: eb3739b5e1fdbb06f111bd2a254998f898f1234b37b19ab848cda24c27d7c5b4
      • Instruction ID: e2c56b0f2750b8f84508d475d39dcebb48128c4c0476730ce0518eb2826193df
      • Opcode Fuzzy Hash: eb3739b5e1fdbb06f111bd2a254998f898f1234b37b19ab848cda24c27d7c5b4
      • Instruction Fuzzy Hash: 59417C22A09A4681EA15BF57E4D42BDA360FB84BE0FC84133DA0D577A6DF7CE4428720
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
      • String ID: file=
      • API String ID: 2081738530-2538679502
      • Opcode ID: 1edb80342092630832c5fb6f55dc38ee63870157e5051224cf635a77ba23c09f
      • Instruction ID: 8c0cf671fea1db2513c08641c6d4c4a1a23d92ca19d467051ba0284f9d04283e
      • Opcode Fuzzy Hash: 1edb80342092630832c5fb6f55dc38ee63870157e5051224cf635a77ba23c09f
      • Instruction Fuzzy Hash: D9314022A09A0291EE25EF17E5801BDA7A0FBA4B94FCC0573DA5E177A5DF3CE4418720
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
      • String ID: file=
      • API String ID: 2081738530-2538679502
      • Opcode ID: 7281c3b0ae52227ce0c1cf18d1da4f5298ab66826f35442084b9449367ac1972
      • Instruction ID: 731434f9a5da64d5649c5c935f6e3c2f95c8a31bbd75faf10bc95828a10301e0
      • Opcode Fuzzy Hash: 7281c3b0ae52227ce0c1cf18d1da4f5298ab66826f35442084b9449367ac1972
      • Instruction Fuzzy Hash: AA317E22A0AA4281EA15BF57D48027DE761EBA4BA0FC80533DA0E57695DF7CE4428724
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
      • String ID: file=
      • API String ID: 2081738530-2538679502
      • Opcode ID: a79b8aa47fa485bbab139914a1b2ad1b3c206d5a57251d70f73a494e315bbdf8
      • Instruction ID: 23828bebf83fdcea31b253164a74923b95ed563304668f33bb4d55f2fbd140fe
      • Opcode Fuzzy Hash: a79b8aa47fa485bbab139914a1b2ad1b3c206d5a57251d70f73a494e315bbdf8
      • Instruction Fuzzy Hash: 44318426A09A4684EA25BF57E8C42BDE361EB54BE0FC80133DA1D576A5DF3CE4428320
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
      • String ID: file=
      • API String ID: 2081738530-2538679502
      • Opcode ID: 7c2c59fa053a96a9ecf4ebc1fe4e55a598fb33aa9990182c37703a59b10f1925
      • Instruction ID: 9e933495425001496644c29c1dd30809d86635852451868da212be2d3bd84d46
      • Opcode Fuzzy Hash: 7c2c59fa053a96a9ecf4ebc1fe4e55a598fb33aa9990182c37703a59b10f1925
      • Instruction Fuzzy Hash: 35317222A0AA4684EE15BF57E48027DE760EBA4BA4FC80133DE4D07795EF3CF4428324
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
      • String ID: file=
      • API String ID: 2081738530-2538679502
      • Opcode ID: 0412f7df46e42df070327a9a1b5083ccedc36c2dba824865371200824fc3f07c
      • Instruction ID: 228dffa68b4865c6da8bd07cf9a2c4b8af84e6eafdcd2e81c861aed9787b2bd6
      • Opcode Fuzzy Hash: 0412f7df46e42df070327a9a1b5083ccedc36c2dba824865371200824fc3f07c
      • Instruction Fuzzy Hash: 53318522A0AA4281FA15BF57E4C01BCE361EBA4BA4FC80133DE5D077A5DF3CE4428724
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
      • String ID: file=
      • API String ID: 2081738530-2538679502
      • Opcode ID: e364a7d37f6e9fbbd1dce1d43802610c092617238c46e8cfe554c601d2725b9b
      • Instruction ID: f9bf7b4e515a27f17b9f15d5f6b8b3ad8df3eece7d0e8db15e1204dc0e954b23
      • Opcode Fuzzy Hash: e364a7d37f6e9fbbd1dce1d43802610c092617238c46e8cfe554c601d2725b9b
      • Instruction Fuzzy Hash: DC316F32A0AA4684EE15BF57D48027CE7A1EB64BA4FC80533DE0D476A6DF3CE442C720
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
      • String ID: file=
      • API String ID: 2081738530-2538679502
      • Opcode ID: c715b6234142cd09e9b106a8f36208cb94172bf7d7ad036fe947d961413caed5
      • Instruction ID: 392eab17baa98de99c14552453d0e45c680ac7da9fea77c4604a5613b6bf71d9
      • Opcode Fuzzy Hash: c715b6234142cd09e9b106a8f36208cb94172bf7d7ad036fe947d961413caed5
      • Instruction Fuzzy Hash: 28318222A0BA4285EA15BF57D4C067CFBA1EB65BA4FC80133DE5D476A5DF3CE4428720
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
      • String ID: file=
      • API String ID: 2081738530-2538679502
      • Opcode ID: 61d1ece634c315a025c50fc175d7199a4b562c3677c0d51e552b046aa0396774
      • Instruction ID: f5bb589e1fdf51d8f7f326144eadb9253b461599382931e5a9985d1f7cbca15d
      • Opcode Fuzzy Hash: 61d1ece634c315a025c50fc175d7199a4b562c3677c0d51e552b046aa0396774
      • Instruction Fuzzy Hash: 2E31A022A09A4281EA15BF57E88427DE761EB54BE8FC80133DA4D577A5DF3CE4428720
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
      • String ID: file=
      • API String ID: 2081738530-2538679502
      • Opcode ID: 48d9c4655d1b26753cda38297b84ee87202d2a335801f716313b61c49757966b
      • Instruction ID: 8b43e8943863243de79d1b35d0e155b33d723fd3b53772524265fffef9405559
      • Opcode Fuzzy Hash: 48d9c4655d1b26753cda38297b84ee87202d2a335801f716313b61c49757966b
      • Instruction Fuzzy Hash: 15317421A0EA4680EA15BF67E4C017CE361EBA4BA4FC80533DE5E077A5DF7CE4428724
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: High$Low${"msg":"
      • API String ID: 3668304517-1891866251
      • Opcode ID: 4a3cfaeab38b78596b3228263cae7344cdeb35620154d9bc2cdc784de1d34b88
      • Instruction ID: d44838229608da31129d6b7eaabf511c8b5fc7a4e86b41c37ae331b741a9ce32
      • Opcode Fuzzy Hash: 4a3cfaeab38b78596b3228263cae7344cdeb35620154d9bc2cdc784de1d34b88
      • Instruction Fuzzy Hash: B471A162F19B8589FB10EF76D4803ACA321AB957D8FC44233DA5C266DADF78E1858350
      APIs
      Strings
      • :Sun:Sunday:Mon:Monday:Tue:Tuesday:Wed:Wednesday:Thu:Thursday:Fri:Friday:Sat:Saturday, xrefs: 00007FF7D4BD6488
      • M:pm, xrefs: 00007FF7D4BD65C1
      • :Jan:January:Feb:February:Mar:March:Apr:April:May:May:Jun:June:Jul:July:Aug:August:Sep:September:Oct:October:Nov:November:Dec:December, xrefs: 00007FF7D4BD6548
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Concurrency::cancel_current_task
      • String ID: :Jan:January:Feb:February:Mar:March:Apr:April:May:May:Jun:June:Jul:July:Aug:August:Sep:September:Oct:October:Nov:November:Dec:December$:Sun:Sunday:Mon:Monday:Tue:Tuesday:Wed:Wednesday:Thu:Thursday:Fri:Friday:Sat:Saturday$M:pm
      • API String ID: 118556049-1862959636
      • Opcode ID: 53820c5083b1a79f781b10075a89789dd2e95327002a2535c902c75b9376703e
      • Instruction ID: 0eb050c1ae06a205e87dceb6f4adf5c38c830d46d0fdc53a87e0a9043988bfe3
      • Opcode Fuzzy Hash: 53820c5083b1a79f781b10075a89789dd2e95327002a2535c902c75b9376703e
      • Instruction Fuzzy Hash: BC519122A0A78645FE01EF16D18437CA7A0AF64B84FCD8177DE5D07796EF2CE4818760
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$GetctypeGetwctypeLocinfo::_Locinfo_ctorLockit::_Lockit::~_
      • String ID: bad locale name
      • API String ID: 1386471777-1405518554
      • Opcode ID: fef943b3e94fe06f291272d72be438a6e3b6cd09b7a1663201a4f2f1369eeb99
      • Instruction ID: 1148050e5a9b4e5e96f03180dbe0fcd97eeeda83991a84f7b7ba8de3ed99ac52
      • Opcode Fuzzy Hash: fef943b3e94fe06f291272d72be438a6e3b6cd09b7a1663201a4f2f1369eeb99
      • Instruction Fuzzy Hash: 5B518D22F0AB418AFB15EFB2D4802AC77B0AF54744F845136DE4D27A96DF38A466C364
      APIs
      • LoadLibraryExW.KERNEL32(?,?,?,00007FF7D4C0A82E,?,?,?,00007FF7D4C0A520,?,?,?,00007FF7D4C07101), ref: 00007FF7D4C0A601
      • GetLastError.KERNEL32(?,?,?,00007FF7D4C0A82E,?,?,?,00007FF7D4C0A520,?,?,?,00007FF7D4C07101), ref: 00007FF7D4C0A60F
      • LoadLibraryExW.KERNEL32(?,?,?,00007FF7D4C0A82E,?,?,?,00007FF7D4C0A520,?,?,?,00007FF7D4C07101), ref: 00007FF7D4C0A639
      • FreeLibrary.KERNEL32(?,?,?,00007FF7D4C0A82E,?,?,?,00007FF7D4C0A520,?,?,?,00007FF7D4C07101), ref: 00007FF7D4C0A6A7
      • GetProcAddress.KERNEL32(?,?,?,00007FF7D4C0A82E,?,?,?,00007FF7D4C0A520,?,?,?,00007FF7D4C07101), ref: 00007FF7D4C0A6B3
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Library$Load$AddressErrorFreeLastProc
      • String ID: api-ms-
      • API String ID: 2559590344-2084034818
      • Opcode ID: 2d5ac74ecc6a100ea38a0b516f94a7f8ad851f9c2de47539d31183b94db67e70
      • Instruction ID: 732f79a36691e45ad9363151e6b1bcf88ff7afecd5d1c25689bdcf88f8ab4fd8
      • Opcode Fuzzy Hash: 2d5ac74ecc6a100ea38a0b516f94a7f8ad851f9c2de47539d31183b94db67e70
      • Instruction Fuzzy Hash: AC31E821B1AA4192EE15AF13E8846BDA3A4FF54BE4FC90537ED5D1A390EF3DE4018320
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Value$ErrorLast
      • String ID:
      • API String ID: 2506987500-0
      • Opcode ID: f5b00e574aa0d888fdfeee6e05e8aa48410a17821f25b7e5bbad88f407bda14a
      • Instruction ID: bf87bc8702bb0fb97918dd5aa325d6d044e44adc54bcece5d5fc3fbd73937d8d
      • Opcode Fuzzy Hash: f5b00e574aa0d888fdfeee6e05e8aa48410a17821f25b7e5bbad88f407bda14a
      • Instruction Fuzzy Hash: C8214C20F0C69242FA597F63EAE517DD2626F447E0FD44637E83E866CADE2CB4014231
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: ByteCharMultiWide$CompareInfoString
      • String ID:
      • API String ID: 2984826149-0
      • Opcode ID: c666564c02407c54345e54014b62058ee8b094e36e91e9a6216927ceb7f195ec
      • Instruction ID: 61c82a34827a8fd306fa9af061b94ff034d7cbdeae7e91293e09b25bd419ad39
      • Opcode Fuzzy Hash: c666564c02407c54345e54014b62058ee8b094e36e91e9a6216927ceb7f195ec
      • Instruction Fuzzy Hash: 23A1C222A0868146EB30EF26D5983BEA695AF457E4FC84633DA5C767D5DF7CE800C324
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: ByteCharMultiStringWide
      • String ID:
      • API String ID: 2829165498-0
      • Opcode ID: 365d1809e1fc97452a50b45ad1143c2e49007afe7a5dee32fe1fa1860b5294e4
      • Instruction ID: 19b851460017c0a1f06d849db57777980ca008dcfe0ea857e8eb1ebd90486628
      • Opcode Fuzzy Hash: 365d1809e1fc97452a50b45ad1143c2e49007afe7a5dee32fe1fa1860b5294e4
      • Instruction Fuzzy Hash: FE817F7270874186EB209F62E48437EA6A1FB847E8F840237EA5D27BD4DF3CD4458724
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
      • String ID:
      • API String ID: 2081738530-0
      • Opcode ID: d39c7b6fc60f21c3df8607624212dac4fb56cbd034ddefb43e8cd75d3152efc0
      • Instruction ID: 896d3b25d6a5dab1361162bc355334fc69901e8a43d10ab7b7bc80b59a2264bd
      • Opcode Fuzzy Hash: d39c7b6fc60f21c3df8607624212dac4fb56cbd034ddefb43e8cd75d3152efc0
      • Instruction Fuzzy Hash: 2B417F22A0AA4281EE15BF57D4801BDA360EFA4BD4FC84133DE5D472A5DF6CE442C734
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
      • String ID:
      • API String ID: 2081738530-0
      • Opcode ID: 2042775240bd6c479fce8bd923c7f62237510e7186632ca0eff0cc3ec857919d
      • Instruction ID: 67cdeac2e4209bb4cfed851d9ce17aaef2ce408a66d60ad2e6783475bf2f2d76
      • Opcode Fuzzy Hash: 2042775240bd6c479fce8bd923c7f62237510e7186632ca0eff0cc3ec857919d
      • Instruction Fuzzy Hash: 01314626A09A42C1EE25BF27E4C01BDA7A4EBA4B94FD80533DA5D076A5DE3CE4418720
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
      • String ID:
      • API String ID: 2081738530-0
      • Opcode ID: b11b7d60a71d5e64724596738f5cf418a9b85c8d5d2b0b66d99383134bd93198
      • Instruction ID: 63afa45fa027aa010d9ef0d518beaef8a5d5766024c85b9d98e4a8f50a03a943
      • Opcode Fuzzy Hash: b11b7d60a71d5e64724596738f5cf418a9b85c8d5d2b0b66d99383134bd93198
      • Instruction Fuzzy Hash: D8316622A09A0181EE11BF17E4801BEA7A0FB68BD8FDC0573DA5E072A5DF7CE4518710
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
      • String ID:
      • API String ID: 2081738530-0
      • Opcode ID: 24d47b9c58b4ac561442a5f8a6a89dda0eda9f481c2d97320db3b7ccf610aeac
      • Instruction ID: 717ebf646c484c4072ac1d7ec0dfdcb6a392a51f28d00c16d08f44cac8b2b078
      • Opcode Fuzzy Hash: 24d47b9c58b4ac561442a5f8a6a89dda0eda9f481c2d97320db3b7ccf610aeac
      • Instruction Fuzzy Hash: 59313622609A0185EA25BF27E4C057DE770FBA4794FDC0633EA5D076A5DF3CE4428720
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
      • String ID:
      • API String ID: 2081738530-0
      • Opcode ID: 3cae802a4357c99cce02824399aa241b436792386caece8917db76d399560e9e
      • Instruction ID: 0c479d96e59d2511efca415ff825aa305fc83464654b6f972cb1383186433bb1
      • Opcode Fuzzy Hash: 3cae802a4357c99cce02824399aa241b436792386caece8917db76d399560e9e
      • Instruction Fuzzy Hash: 8F316621A0AA4685EA15BF57E88017DF761EBA4BA4FC80133DE0D47795DF3CE4428724
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
      • String ID:
      • API String ID: 2081738530-0
      • Opcode ID: e94e0b861b29c27e4889fd7655c754f6b2dc5b8100564e9d521e209e7882ebe0
      • Instruction ID: 16ba08fab48f253001d65d8dbe5e92c7d83fbe48c47537fe3eba08e24dbe4194
      • Opcode Fuzzy Hash: e94e0b861b29c27e4889fd7655c754f6b2dc5b8100564e9d521e209e7882ebe0
      • Instruction Fuzzy Hash: 51317226A0AA4680EB15BF57E48017CE7A1EBA4BA4FC80133DE5D47695DF3CF446C324
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
      • String ID:
      • API String ID: 2081738530-0
      • Opcode ID: eec5043ab38b9151b3457b01f3287d20a57aa9387b6922933c9514c79e264e2a
      • Instruction ID: 4f5466819111f212f8a0650e501c2ab1da69d6e9dcdd942d0581a750e0bb7126
      • Opcode Fuzzy Hash: eec5043ab38b9151b3457b01f3287d20a57aa9387b6922933c9514c79e264e2a
      • Instruction Fuzzy Hash: 34312122A0AA4681EA15BF57E8801BDA761EBA4BA4FC80133DE5D47795DE3CE442C724
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
      • String ID:
      • API String ID: 2081738530-0
      • Opcode ID: c47ac0e8dd3d0c286527649e92f272822709cc0d429192d2b540c2e798ba42d9
      • Instruction ID: 7e929014b24edc7b47e2d144284e2a6be42cf07ef70aa33c6f593471ba33974d
      • Opcode Fuzzy Hash: c47ac0e8dd3d0c286527649e92f272822709cc0d429192d2b540c2e798ba42d9
      • Instruction Fuzzy Hash: 57318626A0AA4281EE55BF57E48027CE3A1EBA47A4FC80133DF5D07795DE3CE4468324
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
      • String ID:
      • API String ID: 2081738530-0
      • Opcode ID: 766bc0b1722455a3eec6d0639954e9c5a2943d8c3e93ed51b5b95f5e5a2d201a
      • Instruction ID: 368c2bb85816ac7c3501f16159ffca81e04edfb8047604735bbe87e66400ab50
      • Opcode Fuzzy Hash: 766bc0b1722455a3eec6d0639954e9c5a2943d8c3e93ed51b5b95f5e5a2d201a
      • Instruction Fuzzy Hash: 90317E22A0DA4285EE15BF57E4C427DE361EB94BE4FC80133DA4D57695DF7CE4828720
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
      • String ID:
      • API String ID: 2081738530-0
      • Opcode ID: 377b59972e5e0ee5b8278c57d5a3dc2c1a202cafcbafdecb7bd9c415f6f64c78
      • Instruction ID: 5eeebc609a4c6793c0c38e38d557e5eec4c0e8a6f2203269ebbb21869ec62ec1
      • Opcode Fuzzy Hash: 377b59972e5e0ee5b8278c57d5a3dc2c1a202cafcbafdecb7bd9c415f6f64c78
      • Instruction Fuzzy Hash: FF318022A09A4685EF15BF57E8C427DE360EB94BE4FC80133DA5E57696DF3CE4428720
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
      • String ID:
      • API String ID: 2081738530-0
      • Opcode ID: 21717bef3686618cd96da9bb82ce299ad44ed5010396f82f6eca78fbaf962fb2
      • Instruction ID: 9cd84c51f8babed7f1781641759d2c805794bc6c7a6b2e3500062d7151fe6830
      • Opcode Fuzzy Hash: 21717bef3686618cd96da9bb82ce299ad44ed5010396f82f6eca78fbaf962fb2
      • Instruction Fuzzy Hash: 84317822A0AA4281EA15BF57E48067CE7A1EBA47A4FC80133DE4D07695EF3CE4468334
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
      • String ID:
      • API String ID: 2081738530-0
      • Opcode ID: 9c406dcfc41f0356f12bc71b5c6d240ac8f6804b0cb7f11da5ef4b535cedcd89
      • Instruction ID: e1a929b276b5a6eeaa472812302449302a9ee5765be0d96e7b6744c4495f2f1e
      • Opcode Fuzzy Hash: 9c406dcfc41f0356f12bc71b5c6d240ac8f6804b0cb7f11da5ef4b535cedcd89
      • Instruction Fuzzy Hash: 76316F22A0AA4680EA15BF57E4C017DA7A1FBA4BA4FC81137DE0D477A5DF3CE4428724
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID: %$+
      • API String ID: 0-2626897407
      • Opcode ID: be3d1e85cf96b28ac0a17ea4137767ce67214e1e92dfd20f534a1827cba5f10e
      • Instruction ID: 7a260c9b4cf55826542c185f809079e8ee9fd0392951f026a6780247f2a09af1
      • Opcode Fuzzy Hash: be3d1e85cf96b28ac0a17ea4137767ce67214e1e92dfd20f534a1827cba5f10e
      • Instruction Fuzzy Hash: BFD1E462B09B8585EB11DFAAD4802ADB3A1AB58BD8FC44233DE5C27B99DF3DD045C310
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Is_bad_exception_allowedstd::bad_alloc::bad_alloc
      • String ID: csm$csm$csm
      • API String ID: 3523768491-393685449
      • Opcode ID: 890515245bb3702dda5d83861889bf4967c74efe4f362a51c3ffa88499933ad7
      • Instruction ID: 957bafed1d764401cc52baede15b518964cdd67c3de98666e8b12ebb1a80bf8e
      • Opcode Fuzzy Hash: 890515245bb3702dda5d83861889bf4967c74efe4f362a51c3ffa88499933ad7
      • Instruction Fuzzy Hash: 53E1A6729087828AEB60AF66D4C43BDB7A0FB45798FD44137DE8D67695CE38E441C720
      APIs
      • GetLastError.KERNEL32(?,?,8000000000000000,00007FF7D4C11C85,?,?,?,?,00007FF7D4C1DB64), ref: 00007FF7D4C1E377
      • FlsSetValue.KERNEL32(?,?,8000000000000000,00007FF7D4C11C85,?,?,?,?,00007FF7D4C1DB64), ref: 00007FF7D4C1E3AD
      • FlsSetValue.KERNEL32(?,?,8000000000000000,00007FF7D4C11C85,?,?,?,?,00007FF7D4C1DB64), ref: 00007FF7D4C1E3DA
      • FlsSetValue.KERNEL32(?,?,8000000000000000,00007FF7D4C11C85,?,?,?,?,00007FF7D4C1DB64), ref: 00007FF7D4C1E3EB
      • FlsSetValue.KERNEL32(?,?,8000000000000000,00007FF7D4C11C85,?,?,?,?,00007FF7D4C1DB64), ref: 00007FF7D4C1E3FC
      • SetLastError.KERNEL32(?,?,8000000000000000,00007FF7D4C11C85,?,?,?,?,00007FF7D4C1DB64), ref: 00007FF7D4C1E417
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Value$ErrorLast
      • String ID:
      • API String ID: 2506987500-0
      • Opcode ID: 98384f26327f76579ed9f630f10178bdb8d09822ebacc95e52f3561bd0bb9469
      • Instruction ID: 0e935efd430e42279617dcbaf5caa3a3eed32bea847b9aa79b3165439b1d447a
      • Opcode Fuzzy Hash: 98384f26327f76579ed9f630f10178bdb8d09822ebacc95e52f3561bd0bb9469
      • Instruction Fuzzy Hash: 24114A20E0C29242FA68BF27EAD517DE1626F847E0FD44637E92E867C6DE2CB4014231
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID: ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
      • API String ID: 0-1866435925
      • Opcode ID: e8fc301ee92d7accb233e5a65c4cc3912e36ef04512fb8064d0719e2c12e0876
      • Instruction ID: 593e08b1cade988bbe7fd8b95742288f4dcbac2f8299c17614e0b75e0ca7f80d
      • Opcode Fuzzy Hash: e8fc301ee92d7accb233e5a65c4cc3912e36ef04512fb8064d0719e2c12e0876
      • Instruction Fuzzy Hash: 4781B02260AA8582EF24EF26D0C037DA7A1EB84F94F948533DA5D47799DF3DD845C310
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$GetctypeLocinfo::_Locinfo_ctorLockit::_Lockit::~_
      • String ID: bad locale name
      • API String ID: 2967684691-1405518554
      • Opcode ID: a608f9e962290028e7dcc6ab05cafac44368563cf0e660048a16c5bacd16331e
      • Instruction ID: faec5ec53c55cf64445ba722a2473f8ff7b661a0c3681578a496edb8f0ef91c2
      • Opcode Fuzzy Hash: a608f9e962290028e7dcc6ab05cafac44368563cf0e660048a16c5bacd16331e
      • Instruction Fuzzy Hash: 22417C22B0AB4189FB10EFB2D4902BCA7B4AF54784FC84436DE4E26A95DF38D516D364
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Concurrency::cancel_current_task$std::bad_alloc::bad_alloc
      • String ID: false$true
      • API String ID: 1173176844-2658103896
      • Opcode ID: a0548538b1f2a7caf437fa2082cbfdfde99cd727c9bf5cef349941922eb6682d
      • Instruction ID: de840aaf879f0726b0f4d4b7ae6c21e98ebd0d533c7fcb341ee4801c0ebd37fa
      • Opcode Fuzzy Hash: a0548538b1f2a7caf437fa2082cbfdfde99cd727c9bf5cef349941922eb6682d
      • Instruction Fuzzy Hash: FF41A32250A78249EB11EF66E4802ADB7A0EF64B94FD84536DE9D03395EF3CE451C360
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task
      • String ID:
      • API String ID: 3936042273-0
      • Opcode ID: e7fa8e4a899329e984c1acece99ca774f877e1b28c68e86b264a1d9f6202f99f
      • Instruction ID: 5b852c6c2dc5cd7209f957b802eee079efcc53e9cbf8a7900dae19c441b1ee80
      • Opcode Fuzzy Hash: e7fa8e4a899329e984c1acece99ca774f877e1b28c68e86b264a1d9f6202f99f
      • Instruction Fuzzy Hash: FDC19162F15B4186FB20EFBAD0842BC6375ABA8798FC05632DE5D23B98DE38D041C754
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: AdjustPointer
      • String ID:
      • API String ID: 1740715915-0
      • Opcode ID: f49579f6f4c693db4c0587241cba271d48c05cfce4442a5e01e519973c885395
      • Instruction ID: 579e154ad847d537af0a09d94cfb6b37e4774fccfb7cfcfccaf90bbd35917bb5
      • Opcode Fuzzy Hash: f49579f6f4c693db4c0587241cba271d48c05cfce4442a5e01e519973c885395
      • Instruction Fuzzy Hash: 7AB19E22B0B64281EE6ABF17D5C867CE694AF44BC4FD98437DE4D27795DE2CE4428320
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task
      • String ID:
      • API String ID: 3936042273-0
      • Opcode ID: bcead0ba50dd890a7dbadb4ee972e07d315b1ca9652fd7eddeed071f19e576e3
      • Instruction ID: a14e8fe8a60fa72ae02bdaae9fdca38cb23371a188700f4a5892d1d6e41a797e
      • Opcode Fuzzy Hash: bcead0ba50dd890a7dbadb4ee972e07d315b1ca9652fd7eddeed071f19e576e3
      • Instruction Fuzzy Hash: 0AB1C062B1AB418AEB20EF76D0C42BDA372AB65798FC04232DE5D17B99DE38D055C710
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _set_statfp
      • String ID:
      • API String ID: 1156100317-0
      • Opcode ID: 77b3e33a6f5132d0789f4973ca5980c7032235896e2b77d186fa7528dd25f978
      • Instruction ID: 0e180b50c61fd9246fcf3bc6d75e22a1b8cfb04d5a0c721a4c06be2a2ebff980
      • Opcode Fuzzy Hash: 77b3e33a6f5132d0789f4973ca5980c7032235896e2b77d186fa7528dd25f978
      • Instruction Fuzzy Hash: A681E522908A4649F236AF36E4D037EF650AF553D4FC44337EA5E265E4DFBCA481CA20
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo
      • String ID:
      • API String ID: 3215553584-0
      • Opcode ID: 492b45dcdfc681ab09788500166ca94a443063352cf3c2ab544e14c454973447
      • Instruction ID: 92ac88961c73f9a3132b28951bb37f5a975e1d9bd53b19076480a0e120dc69f2
      • Opcode Fuzzy Hash: 492b45dcdfc681ab09788500166ca94a443063352cf3c2ab544e14c454973447
      • Instruction Fuzzy Hash: 15514126A09B8686E752AF26D4D027DBBB5AF05BC4FD98033C68D47342DE2D9445C335
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _set_statfp
      • String ID:
      • API String ID: 1156100317-0
      • Opcode ID: b5f862fb55466f104c7638c26c27eae1ccad5020b215a080a91550ad010d465e
      • Instruction ID: c11c3ac2ba6d1996ceced64d3dac93e27e628ac72ba4413f0326df0ed18ab561
      • Opcode Fuzzy Hash: b5f862fb55466f104c7638c26c27eae1ccad5020b215a080a91550ad010d465e
      • Instruction Fuzzy Hash: D911C823E4CE0301F6583B6BD5D93BDA5406F543F8FC50637E96E162EE8E9CA8825130
      APIs
      • FlsGetValue.KERNEL32(?,?,?,00007FF7D4C13B53,?,?,00000000,00007FF7D4C13DEE,?,?,?,?,8000000000000000,00007FF7D4C13D7A), ref: 00007FF7D4C1E44F
      • FlsSetValue.KERNEL32(?,?,?,00007FF7D4C13B53,?,?,00000000,00007FF7D4C13DEE,?,?,?,?,8000000000000000,00007FF7D4C13D7A), ref: 00007FF7D4C1E46E
      • FlsSetValue.KERNEL32(?,?,?,00007FF7D4C13B53,?,?,00000000,00007FF7D4C13DEE,?,?,?,?,8000000000000000,00007FF7D4C13D7A), ref: 00007FF7D4C1E496
      • FlsSetValue.KERNEL32(?,?,?,00007FF7D4C13B53,?,?,00000000,00007FF7D4C13DEE,?,?,?,?,8000000000000000,00007FF7D4C13D7A), ref: 00007FF7D4C1E4A7
      • FlsSetValue.KERNEL32(?,?,?,00007FF7D4C13B53,?,?,00000000,00007FF7D4C13DEE,?,?,?,?,8000000000000000,00007FF7D4C13D7A), ref: 00007FF7D4C1E4B8
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Value
      • String ID:
      • API String ID: 3702945584-0
      • Opcode ID: c1f80a57214fa9314f74c4b30dc64759b56f05021f72730d0f25618e90a88899
      • Instruction ID: 72a908a2053d1954108f05864f8de20322b3ad72d547d6dfb06753eaf57d8ab9
      • Opcode Fuzzy Hash: c1f80a57214fa9314f74c4b30dc64759b56f05021f72730d0f25618e90a88899
      • Instruction Fuzzy Hash: 8F112920E0869241FA58BF67E9D117DE1626F847E0FC44277E82E866DADE2CB4028231
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Value
      • String ID:
      • API String ID: 3702945584-0
      • Opcode ID: 664d4be6e4d57da178c0bd4b1e2dd36a93d6030a558b2ea56983ac91fc98f45f
      • Instruction ID: 44f8473113772871c706740bba08839c4a8583dafcd4f09e13aa21b9f56b2f41
      • Opcode Fuzzy Hash: 664d4be6e4d57da178c0bd4b1e2dd36a93d6030a558b2ea56983ac91fc98f45f
      • Instruction Fuzzy Hash: EF11D620E0929742F9697E27D8E257DD1616F453F0FD80737E93E8A2C6ED2CB4414232
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo
      • String ID: UTF-16LEUNICODE$UTF-8$ccs
      • API String ID: 3215553584-1196891531
      • Opcode ID: 9786d68c7eed2349fa8e9c8b660a2a1167aaa83090c5916e364db7622d5a1be9
      • Instruction ID: f7393d57823a12fd56918b6d8b19e1a6694f59fd3367dd66919ff6645b6f12a9
      • Opcode Fuzzy Hash: 9786d68c7eed2349fa8e9c8b660a2a1167aaa83090c5916e364db7622d5a1be9
      • Instruction Fuzzy Hash: A0818162D0C2C289F7A5AE2AD2D423CEBB09B127C4FD59037CA0E56295EE1DB9418771
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: CallEncodePointerTranslator
      • String ID: MOC$RCC
      • API String ID: 3544855599-2084237596
      • Opcode ID: 4570207b4165d0635ac4a3fd3d64531da63560077cbea117cab5ba90e919dedc
      • Instruction ID: 2a4da838184eb913dc8bba6e57356e25b1b75c2ba1f8f8d912d5155d6bce155c
      • Opcode Fuzzy Hash: 4570207b4165d0635ac4a3fd3d64531da63560077cbea117cab5ba90e919dedc
      • Instruction Fuzzy Hash: CB919373A087858AE710EF66D8842ADBBA0FB447C8F94813BEA8D27B55DF38D155C710
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: {"msg":"
      • API String ID: 3668304517-2882747944
      • Opcode ID: 5d06d9a251fd8b4a576a19a10e83e4d40e5508396f1b958b033d9f2b6b30e06f
      • Instruction ID: 0f7fd957ede4c592726ce623e5b493f204327ca4929b794ba277291cb51ba649
      • Opcode Fuzzy Hash: 5d06d9a251fd8b4a576a19a10e83e4d40e5508396f1b958b033d9f2b6b30e06f
      • Instruction Fuzzy Hash: AA51D322B15A415AFB10AF36D0C43ADA361AB557E8FC45732DD6C26BDADF38D5418320
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: CurrentImageNonwritableUnwind__except_validate_context_record
      • String ID: csm
      • API String ID: 2395640692-1018135373
      • Opcode ID: 96d482e54c2ff74a9578f97a2d3b0353fcb5dd65390cdded8450e2fed95d9ab2
      • Instruction ID: 056eb2ee56384ee2a509f398836c05b40dfd5cf627b1cc856eb78b9617fab061
      • Opcode Fuzzy Hash: 96d482e54c2ff74a9578f97a2d3b0353fcb5dd65390cdded8450e2fed95d9ab2
      • Instruction Fuzzy Hash: 3151A132B1A6028ADF58AF56D488A7CA391EB44BD8FD44237EA4E53784DF7DE8418710
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: CallEncodePointerTranslator
      • String ID: MOC$RCC
      • API String ID: 3544855599-2084237596
      • Opcode ID: 2b5b42315b3b38cd90a5c931a26b3be2eb898fc97ebece708dba4641e3ddee3e
      • Instruction ID: d61648b03fd9aeaf1b87cb618ff40f44d50951e36372c344f12cbb18d392ce83
      • Opcode Fuzzy Hash: 2b5b42315b3b38cd90a5c931a26b3be2eb898fc97ebece708dba4641e3ddee3e
      • Instruction Fuzzy Hash: 33615F72908B8586DA70AF16E4843AEB7A0FB857D4F848226EB9C17755DF7CD190CB20
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Frame$EmptyHandler3::StateUnwind__except_validate_context_record
      • String ID: csm$csm
      • API String ID: 3896166516-3733052814
      • Opcode ID: 56963d72e84833e31defc41a0a330777e341b24c38b4c4f77a0b573189b86a8c
      • Instruction ID: 38c192684dec20675e723d9c5034ea5cafed4ef84204ba4dfefb77e3e63d7c5a
      • Opcode Fuzzy Hash: 56963d72e84833e31defc41a0a330777e341b24c38b4c4f77a0b573189b86a8c
      • Instruction Fuzzy Hash: 5851843290864286EB74AF22D48836CB6A1EB54BD4FD48137EB9C67AD5CF3CE450C721
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Locinfo::_Locinfo_ctorLockit::_Lockit::~_
      • String ID: bad locale name
      • API String ID: 2775327233-1405518554
      • Opcode ID: 3931c185ac249372042b0835e728ec539ad978b651a92cbfb8180ec839c4395c
      • Instruction ID: 16a9b6eca58d4889f5ecc461041a10b7c91d217a5d2f6d06f99a8d16bf6ae726
      • Opcode Fuzzy Hash: 3931c185ac249372042b0835e728ec539ad978b651a92cbfb8180ec839c4395c
      • Instruction Fuzzy Hash: 0E51AF32A0AB418AEB10EFB1D4903AC63B0EF54748F885136DE4E23A99DF389165D324
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Lockit$Locinfo::_Locinfo_ctorLockit::_Lockit::~_
      • String ID: bad locale name
      • API String ID: 2775327233-1405518554
      • Opcode ID: 8a1433ced35edaf2e3bf14674eb29a9f84b432830e307e1ef4c60def5f2e697f
      • Instruction ID: ecd2bec0e1269d258f4ce1c6c850fbe5b24012802d2b1b818ea9e8a3b7b9595e
      • Opcode Fuzzy Hash: 8a1433ced35edaf2e3bf14674eb29a9f84b432830e307e1ef4c60def5f2e697f
      • Instruction Fuzzy Hash: B4417E32B0AA41C9EB10EFB2D4903ECA3B4EF54748FC84476DA4E26A56CF38D516D324
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Getvals
      • String ID: $+xv$$+xv$+v$x+v$xv$+xv+$xv$+x+$vx+$vx$v+x+$vx$+vx+v $+v $v $+v +$v $++$ v+$ v$ v++$ v$+ v+xv$+ v$v$ +v+ $v$ ++x$v+ $v$v ++ $v$ +v
      • API String ID: 1336808981-3573081731
      • Opcode ID: 6c2677962067f2fa1c951a5da5b2b474ecb5c2e7cdb0c6e2cf76ea76a8af39f9
      • Instruction ID: 024500069426637fff85ffb69fa1b8a8de62e402f932b803aa00d6548d713065
      • Opcode Fuzzy Hash: 6c2677962067f2fa1c951a5da5b2b474ecb5c2e7cdb0c6e2cf76ea76a8af39f9
      • Instruction Fuzzy Hash: 5541AC72A09B918BE724EF22D18036DBBE0FB65B81FC55266CB4D43A41DB2DF465C700
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: FileWrite$ConsoleErrorLastOutput
      • String ID:
      • API String ID: 2718003287-0
      • Opcode ID: 767b7117d63aae9f51616854b4116fa608bdc1094623500c77e6c8594bac8a16
      • Instruction ID: 02dba8fcb16449fddec463fedb4622fbcd92c772a66736f38b336d305857c893
      • Opcode Fuzzy Hash: 767b7117d63aae9f51616854b4116fa608bdc1094623500c77e6c8594bac8a16
      • Instruction Fuzzy Hash: 72D12432B08A818AE710DF7AD4801ACBBB5F7067D8B944233DE5D67B99DE78D006C314
      APIs
      • GetConsoleMode.KERNEL32(?,?,?,?,?,?,?,?,?,?,00000000,00000000,00007FF7D4C25000), ref: 00007FF7D4C25183
      • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,00000000,00000000,00007FF7D4C25000), ref: 00007FF7D4C2520D
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: ConsoleErrorLastMode
      • String ID:
      • API String ID: 953036326-0
      • Opcode ID: b24a8eab074577c162c6cdbd7e1523746b621e7fdef98cc78988dc972daca678
      • Instruction ID: 78c93339601db94c5217d86dd9bf62302557ffe8468f55f619648afdb97f62d2
      • Opcode Fuzzy Hash: b24a8eab074577c162c6cdbd7e1523746b621e7fdef98cc78988dc972daca678
      • Instruction Fuzzy Hash: F591BF62A1865285EB50AF66D4C06BEBBA0FB44BCCFC41137DE0E67694DFB8E441C720
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo$_get_daylight
      • String ID:
      • API String ID: 72036449-0
      • Opcode ID: 6ee7f3f5d77d3d1bc48d53be37883cc5b81d2d73ff0743d23d12e10b1a6c0d1e
      • Instruction ID: b1f94240de6f041942a95f6a9915c8ce36f45eb8beb4dc75c74cc8d8f16d44cc
      • Opcode Fuzzy Hash: 6ee7f3f5d77d3d1bc48d53be37883cc5b81d2d73ff0743d23d12e10b1a6c0d1e
      • Instruction Fuzzy Hash: F551D232E0C6038AF7686D2AD0C537DF590EB40794FD94437DA4D462EAEEACEA409631
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: File$ErrorHandleInformationLastNamedPeekPipeType
      • String ID:
      • API String ID: 2780335769-0
      • Opcode ID: 3b67d254175e1356448e30113c7945dcc594d42a4af4fb0ebecbdf82148d1320
      • Instruction ID: 52ac6c1ac5c73c8ea12805c1973b348fe06d6af483dc24dd7b83eee692f87c36
      • Opcode Fuzzy Hash: 3b67d254175e1356448e30113c7945dcc594d42a4af4fb0ebecbdf82148d1320
      • Instruction Fuzzy Hash: E6517E62A086418AFB50EF72D4903BDA3B1EB48B98F95803BDE0E47688DF3CD4418760
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo
      • String ID:
      • API String ID: 3215553584-0
      • Opcode ID: aa8d8d6ef9abf4a7f6b39118007aba560a03b250cad3e0274fea527eecee2a0e
      • Instruction ID: 7adf9e509855244fa57645afcd8cee700d513875e22ee23edf96f08c7cd81ac7
      • Opcode Fuzzy Hash: aa8d8d6ef9abf4a7f6b39118007aba560a03b250cad3e0274fea527eecee2a0e
      • Instruction Fuzzy Hash: 1B415036908BC685E762EF26D4A027DBBA4AF05B84FC88073D68C07746DE3D9405C732
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: CloseCreateFileHandle_invalid_parameter_noinfo
      • String ID:
      • API String ID: 1279662727-0
      • Opcode ID: e4876973aa477c234093ca3bb4f84cb558b2507fe2f53346e19c8feeadb19f6c
      • Instruction ID: 1c7dfea047b74cc8db389c5113c1cbbe0e2104e01ac793540514e69c5b6e6584
      • Opcode Fuzzy Hash: e4876973aa477c234093ca3bb4f84cb558b2507fe2f53346e19c8feeadb19f6c
      • Instruction Fuzzy Hash: 44417222D1878283E750AF22D59036DA270FB997E4F909337D69C03AD5DF6CA5A18724
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID: invalid stoull argument
      • API String ID: 0-2058699613
      • Opcode ID: eaed5e95d4f30143368ef6ed9d0a8950138a867b4e377591b662461e9a27bce8
      • Instruction ID: fc9bb3cec9b66564cb810171ad73b33ce4445f27ca054c14e81c723bf9fb0e6a
      • Opcode Fuzzy Hash: eaed5e95d4f30143368ef6ed9d0a8950138a867b4e377591b662461e9a27bce8
      • Instruction Fuzzy Hash: C171C232A09B8582DB10EF16E4C42AEB3A4FB95784FD19037EA8E57664DF3CE545CB10
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: __except_validate_context_record
      • String ID: csm$csm
      • API String ID: 1467352782-3733052814
      • Opcode ID: 0aab2139d8ff1db06bd9a7db1baed0bb2163b038a6bcbeb200c170c991ea75bc
      • Instruction ID: 144d968d7eca96bbb41f991bdfb1d0027678c0c3ff7eaaa8190452d369763326
      • Opcode Fuzzy Hash: 0aab2139d8ff1db06bd9a7db1baed0bb2163b038a6bcbeb200c170c991ea75bc
      • Instruction Fuzzy Hash: FB71A372A0868286DB60AF16D4887BDFBA0FB15BC8FD48137DA8C27A95CF2CD5518750
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
      • String ID: ios_base::failbit set
      • API String ID: 73155330-3924258884
      • Opcode ID: 9c02fc629e10953d4ed5b5a927573ce6e66b272ca667a73eda632291441204c6
      • Instruction ID: 32e531ded3299c18b17b0de7fee79aecf12a2107e4e3d013dcf5b697609003e7
      • Opcode Fuzzy Hash: 9c02fc629e10953d4ed5b5a927573ce6e66b272ca667a73eda632291441204c6
      • Instruction Fuzzy Hash: CD41BF61B0A64285EE14AF12D48416DE365AB54BF8FD84732EEBE077D5DF3CE0528314
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: FileFindNext
      • String ID: ?
      • API String ID: 2029273394-1684325040
      • Opcode ID: 0b0d1ef25a6ea251f3bac5d6ad2d25f3f707807f81456704ba133931aaa77369
      • Instruction ID: 5d630567f9b16f9baf1d7006b87670e95255af0641d07086e391f9de0314c77e
      • Opcode Fuzzy Hash: 0b0d1ef25a6ea251f3bac5d6ad2d25f3f707807f81456704ba133931aaa77369
      • Instruction Fuzzy Hash: A351E372A0AA4186E7909F26D58437CBBE1FB58B88FD48037DA4D4B294DF3DE492C714
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: CreateFrameInfo__except_validate_context_record
      • String ID: csm
      • API String ID: 2558813199-1018135373
      • Opcode ID: f861e7d98ba89d51eb38520f4733ed51dad1eec037d35169d73173b26955cc4e
      • Instruction ID: 657f05fd4280678797036b0c11dc3fc2a1c0f6bc0de7045e6f0ca865779dbd7e
      • Opcode Fuzzy Hash: f861e7d98ba89d51eb38520f4733ed51dad1eec037d35169d73173b26955cc4e
      • Instruction Fuzzy Hash: 89516D36A1978286DA60FF16E48426DB7A4F789BD4F840136DF8D17B95CF38D450CB10
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Getvals
      • String ID: false$true
      • API String ID: 1336808981-2658103896
      • Opcode ID: 4d8fda1b01b9643ae2a486ea9dc5a8a8fd1bc9e164a5f98692e17afe343b8da4
      • Instruction ID: 6cf92b20dc63dbf3dc39f96e6d64c4098f25ba5ee366777a72e96e18de85e1d7
      • Opcode Fuzzy Hash: 4d8fda1b01b9643ae2a486ea9dc5a8a8fd1bc9e164a5f98692e17afe343b8da4
      • Instruction Fuzzy Hash: 53418C22B09B8199E710DF71E4801EC73B1FB98788B845237EE4E27A59EF38D556C354
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: ErrorFileLastWrite
      • String ID: U
      • API String ID: 442123175-4171548499
      • Opcode ID: 1132b2b49b48c2597eacc499dc815d14bcebaaae66ec285487d91b8d70e04cea
      • Instruction ID: 5c7b1a64299c329a0a99ccdd2f4237791fba9bd1e25c857ce3e68e858be1e787
      • Opcode Fuzzy Hash: 1132b2b49b48c2597eacc499dc815d14bcebaaae66ec285487d91b8d70e04cea
      • Instruction Fuzzy Hash: EA418F22618A4192EB60EF26E4843ADB660FB95BC4FC44133EE4D97794EF7CD441C754
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: FileFindHeaderInstanceTargetType
      • String ID: Bad dynamic_cast!
      • API String ID: 746355257-2956939130
      • Opcode ID: 61c36b307e33985b0d8f6c98740969c9a90600ed5136c011a00d70231ba89d9f
      • Instruction ID: c9994b30d2da0c991531134d80917452dc59fee191fe4c5fa5d26388082c89f3
      • Opcode Fuzzy Hash: 61c36b307e33985b0d8f6c98740969c9a90600ed5136c011a00d70231ba89d9f
      • Instruction Fuzzy Hash: 71315E23718A8686EA60EF57E4846AEA3A0BB44FC5F908537DE8D43B58DF3CE145C710
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
      • String ID: ios_base::badbit set
      • API String ID: 73155330-3882152299
      • Opcode ID: 8d7ede1257be8a6d326046e293ce6e78ea5ce23a2a85ad897d997926aed4ceee
      • Instruction ID: 36fe989c0c36dc0d69c284cb19331b166663207aea6ff960d2d3eddaa6730037
      • Opcode Fuzzy Hash: 8d7ede1257be8a6d326046e293ce6e78ea5ce23a2a85ad897d997926aed4ceee
      • Instruction Fuzzy Hash: AA31C026B0778551E924EF2BD1C827DE2559B54BE4FD40632DE6D07BC4EE6CE4928320
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID: V2luaHR0cC5kbGw=
      • API String ID: 0-322140799
      • Opcode ID: cef76e8e8240fbdba4cbd0c9edfa7cee544b0aca40b0040f7b36dab85f5469c0
      • Instruction ID: 3fbeaf0fa770739c7b137644ce871d1fa74791f32513370a496ad67ecc28af32
      • Opcode Fuzzy Hash: cef76e8e8240fbdba4cbd0c9edfa7cee544b0aca40b0040f7b36dab85f5469c0
      • Instruction Fuzzy Hash: E621C122E0A74245FE25AF66E0C43BCA6909F24BA4FE44732DB7C067C2DF2CE4918314
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID:
      • String ID: invalid stoi argument$stoi argument out of range
      • API String ID: 0-1606216832
      • Opcode ID: 7459996af044bcc1df2c0d35d30503d29db3ad35883df7ef00a7cf41bae90e41
      • Instruction ID: 0efab0d277eab0f3fe112b1771c7ed00f215015d559f781aed0a439ad961fb71
      • Opcode Fuzzy Hash: 7459996af044bcc1df2c0d35d30503d29db3ad35883df7ef00a7cf41bae90e41
      • Instruction Fuzzy Hash: FF219222B19B4198F700EFB2D8857EC73B5AB18788FD94437EE4C27645EE38A419C354
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: _set_errno_from_matherr
      • String ID: exp
      • API String ID: 1187470696-113136155
      • Opcode ID: d7c5f8fd6198134743ea40bd6589e46bc0623e8d67f78ee984f86d8a58bb9fa2
      • Instruction ID: 31b6e2e12cc56063d732d5a8b0589665fa45141df7548b04deed376717ef6d39
      • Opcode Fuzzy Hash: d7c5f8fd6198134743ea40bd6589e46bc0623e8d67f78ee984f86d8a58bb9fa2
      • Instruction Fuzzy Hash: 54213936F056158EE740EF79D4802AD73B0EB48388B801537EA0D96B5ADE38E5418B64
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: std::_$Locinfo::_Locinfo_ctorLockitLockit::_
      • String ID: bad locale name
      • API String ID: 3988782225-1405518554
      • Opcode ID: d2642994a7d4360568344dba662e43fc99c418791ae7fedf961662c9b87a45e1
      • Instruction ID: 625383535a6a6a384769f735bc17d76f12cb6736ce7eae933a681e1768a7b416
      • Opcode Fuzzy Hash: d2642994a7d4360568344dba662e43fc99c418791ae7fedf961662c9b87a45e1
      • Instruction Fuzzy Hash: 8101862350AB8189C755EFB5E88015CB7F5FB68B84B98513ACB8C8371AEF38C4A0C354
      APIs
      • RtlPcToFileHeader.KERNEL32(?,?,?,?,?,?,?,?,7FFFFFFFFFFFFFFF,00007FF7D4BDFC72), ref: 00007FF7D4C06E64
      • RaiseException.KERNEL32(?,?,?,?,?,?,?,?,7FFFFFFFFFFFFFFF,00007FF7D4BDFC72), ref: 00007FF7D4C06EA5
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.3204733828.00007FF7D4BB1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7D4BB0000, based on PE: true
      • Associated: 00000000.00000002.3204716756.00007FF7D4BB0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204797263.00007FF7D4C36000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204819665.00007FF7D4C50000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204834749.00007FF7D4C51000.00000008.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C52000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204851669.00007FF7D4C55000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.3204902935.00007FF7D4C57000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff7d4bb0000_forest.jbxd
      Similarity
      • API ID: ExceptionFileHeaderRaise
      • String ID: csm
      • API String ID: 2573137834-1018135373
      • Opcode ID: e0bdc04f18cc49368113b74b752c60fcff594d11a7e9e9945e316941cafad2da
      • Instruction ID: c6854ac1d2361e54eae6a95062a542771b68cbdf9bbbbb7ed767da9b1ce0a262
      • Opcode Fuzzy Hash: e0bdc04f18cc49368113b74b752c60fcff594d11a7e9e9945e316941cafad2da
      • Instruction Fuzzy Hash: 51112B32618B4182EB619F16E48426DB7E5FB88BD4F984236EA9C17758DF3CD551CB00