Edit tour

Windows Analysis Report
SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exe

Overview

General Information

Sample name:SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exe
Analysis ID:1530463
MD5:0cf6e58863853ae6163cf20cfe99379c
SHA1:4284de670984d557dd6d4e1091c9eeaa089aad05
SHA256:78a93828c62d7c6883a4121374937fbbeaec7a7f383f7fe756673859b9254821
Tags:exe
Infos:

Detection

Score:27
Range:0 - 100
Whitelisted:false
Confidence:20%

Signatures

Potentially malicious time measurement code found
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to call native functions
Creates a DirectInput object (often for capturing keystrokes)
Detected potential crypto function
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
Installs a global mouse hook
Installs a raw input device (often for capturing keystrokes)
PE file contains more sections than normal
PE file contains sections with non-standard names
Potential time zone aware malware
Program does not show much activity (idle)
Queries the volume information (name, serial number etc) of a device

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: /tmp/go-build2872068834/b001/exe/a.out.pdb source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exe
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 4x nop then shr rdi, 0Dh0_2_00007FF61017B800
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 4x nop then cmp rdx, 40h0_2_00007FF610170960
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 4x nop then shr r10, 0Dh0_2_00007FF61017CC80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 4x nop then cmp rdx, rbx0_2_00007FF61015BDA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 4x nop then lock or byte ptr [rdx], r8L0_2_00007FF6101710A0
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: http://dejavu.sourceforge.net
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: http://dejavu.sourceforge.net/wiki/index.php/License
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: http://dejavu.sourceforge.net/wiki/index.php/Licensehttp://dejavu.sourceforge.net/wiki/index.php/Lic
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: http://dejavu.sourceforge.nethttp://dejavu.sourceforge.netFonts
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: http://emojione.com/licensingColor
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: http://emojione.comEmojiOne
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: http://ocsp.thawte.com0
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: http://s.symcb.com/pca3-g5.crl0
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: http://s.symcd.com0_
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: http://scripts.sil.org/OFL
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: http://scripts.sil.org/OFLhttp://scripts.sil.org/OFL
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: http://sw.symcb.com/sw.crl0
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: http://sw.symcd.com0
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: http://sw1.symcb.com/sw.crt0
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: http://ts-ocsp.ws.symantec.com07
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: http://www.ascendercorp.com/
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: http://www.ascendercorp.com/http://www.ascendercorp.com/http://www.ascendercorp.com/typedesigners.ht
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: http://www.ascendercorp.com/typedesigners.html
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: http://www.gimp.org/xmp/
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: https://api.transmeter.nz2006-01-02T15:04:05Z07:00Time:
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: https://d.symcb.com/cps0%
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: https://d.symcb.com/rpa0
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: https://d.symcb.com/rpa0)
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: https://github.com/ziglang/zig-bootstrap
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeBinary or memory string: DirectInput8Create
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeWindows user hook set: 0 mouse low level C:\Windows\SYSTEM32\dinput8.dllJump to behavior
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeBinary or memory string: GetRawInputData
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF610182D80 RtlAddVectoredContinueHandler,NtWaitForSingleObject,RtlGetCurrentPeb,RtlGetNtVersionNumbers,timeBeginPeriod,timeEndPeriod,WSAGetOverlappedResult,0_2_00007FF610182D80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF610195E00 NtWaitForSingleObject,0_2_00007FF610195E00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF61018C3C0 NtWaitForSingleObject,0_2_00007FF61018C3C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF61018C4A0 NtWaitForSingleObject,0_2_00007FF61018C4A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF61018C580 NtWaitForSingleObject,0_2_00007FF61018C580
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF61018C660 NtWaitForSingleObject,0_2_00007FF61018C660
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101B9F60 NtWaitForSingleObject,0_2_00007FF6101B9F60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF61018F2A00_2_00007FF61018F2A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF61015D7C00_2_00007FF61015D7C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101859200_2_00007FF610185920
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101959600_2_00007FF610195960
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF610175B200_2_00007FF610175B20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF61015CC200_2_00007FF61015CC20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF61018FCA00_2_00007FF61018FCA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF610178D000_2_00007FF610178D00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF610188FC00_2_00007FF610188FC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101780600_2_00007FF610178060
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF61016B1400_2_00007FF61016B140
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF61015E2C00_2_00007FF61015E2C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101B23200_2_00007FF6101B2320
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101713000_2_00007FF610171300
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101994200_2_00007FF610199420
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101CC4200_2_00007FF6101CC420
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101A74400_2_00007FF6101A7440
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF61016B4E00_2_00007FF61016B4E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101B54C90_2_00007FF6101B54C9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101A15C00_2_00007FF6101A15C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101C56600_2_00007FF6101C5660
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF61015A6400_2_00007FF61015A640
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101C87000_2_00007FF6101C8700
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101898000_2_00007FF610189800
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF61017B8000_2_00007FF61017B800
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101C18400_2_00007FF6101C1840
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF61016E9600_2_00007FF61016E960
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF61019C9800_2_00007FF61019C980
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101C6A000_2_00007FF6101C6A00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF610190A600_2_00007FF610190A60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF610172A800_2_00007FF610172A80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF61016AB200_2_00007FF61016AB20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF61018CBE00_2_00007FF61018CBE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF610165BE00_2_00007FF610165BE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101CBC000_2_00007FF6101CBC00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF61017CC800_2_00007FF61017CC80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101AACC00_2_00007FF6101AACC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF61017BCC00_2_00007FF61017BCC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF61019FD200_2_00007FF61019FD20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101C8DC00_2_00007FF6101C8DC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101C3E000_2_00007FF6101C3E00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101C1F800_2_00007FF6101C1F80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101C8FC00_2_00007FF6101C8FC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF61017E0A00_2_00007FF61017E0A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101820C00_2_00007FF6101820C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: String function: 00007FF6101882A0 appears 587 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: String function: 00007FF6101A0880 appears 37 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: String function: 00007FF610189D40 appears 53 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: String function: 00007FF61018A560 appears 548 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: String function: 00007FF610188380 appears 34 times
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeStatic PE information: Number of sections : 12 > 10
Source: classification engineClassification label: sus27.evad.winEXE@1/0@0/0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeFile created: C:\Users\user\AppData\Roaming\fyneJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeFile opened: C:\Windows\system32\f6c90f171ff4f54575ee89dd3874d18bf95e6dcbd1df116ec56bdd9cc6153f36AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJump to behavior
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.(*Loader).RawTable
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.(*Loader).HasTable
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: net/addrselect.go
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting@v0.1.0/opentype/loader/opentype.go
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting@v0.1.0/opentype/loader/reader_woff.go
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting@v0.1.0/opentype/loader/reader.go
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting@v0.1.0/opentype/loader/reader_otf.go
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.NewTag
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.NewLoader
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.Tag.String
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.(*Loader).findTableBuffer
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.(*Loader).RawTableTo
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.parseOneFont
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.(*Loader).findTableBuffer.func1
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.readWOFFHeader
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.readWOFFEntry
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.readOTFHeader
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.parseOTF
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.readOTFEntry
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.MustNewTag
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.(*Tag).String
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.parseWOFF
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.init
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: \"/[]?=menu-expand.svgcontent-add.svgcontent-cut.svgfolder-open.svgmedia-music.svgmedia-photo.svgmedia-video.svgmedia-pause.svgvolume-down.svgvolume-mute.svgmediaFastRewindselectionRadiusnot a valid URIRegCreateKeyExWRegDeleteValueWreflectlite.Setbad IHDR leng
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: d more dataREQUEST_METHODarrow-back.svgarrow-down.svgfile-audio.svgfile-image.svgfile-video.svgfolder-new.svgmail-reply.svgmedia-play.svgmedia-stop.svgvisibility.svgdisabledButtonmenuBackgrounddocumentCreatemoreHorizontalmailAttachmentviewFullScreenscrollBarSm
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: on zero Valueunknown methodAccept-CharsetDkim-Signatureneed more dataREQUEST_METHODarrow-back.svgarrow-down.svgfile-audio.svgfile-image.svgfile-video.svgfolder-new.svgmail-reply.svgmedia-play.svgmedia-stop.svgvisibility.svgdisabledButtonmenuBackgrounddocument
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: unknown methodAccept-CharsetDkim-Signatureneed more dataREQUEST_METHODarrow-back.svgarrow-down.svgfile-audio.svgfile-image.svgfile-video.svgfolder-new.svgmail-reply.svgmedia-play.svgmedia-stop.svgvisibility.svgdisabledButtonmenuBackgrounddocumentCreatemoreHori
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: .github.com/go-text/typesetting/opentype/loader
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: .github.com/go-text/typesetting/opentype/loader
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: StrokeWidth!xml:"stroke-width,attr,omitempty"-*struct { F uintptr; covs []tables.Coverage }-golang.org/x/text/encoding/traditionalchinese.*func(*big.Int, *big.Int) (*big.Int, *big.Int).*func(bool, func(int32) bool) ([]uint8, error).*map[http.connectMethodKey][]*http.persistConn.*map[http.http2FrameType]http.http2frameParser.*struct { F uintptr; R *http.http2ClientConn }.*struct { F uintptr; .autotmp_60 *time.Timer }.*struct { F uintptr; snapshot strings.Reader }.*struct { F uintptr; .autotmp_1 *glfw.window }.*struct { F uintptr; .autotmp_5 *glfw.window }.*func(ast.NodeKind, renderer.NodeRendererFunc).github.com/go-text/typesetting/opentype/loader.*func(vg.Canvas, string, text.Style, vg.Point).*struct { F uintptr; table tables.GPOSLookup }.*struct { F uintptr; table tables.GSUBLookup }.github.com/go-text/typesetting/opentype/tables.*struct { F uintptr; num int; ranges []uint8 }
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: stopm spinning nmidlelocked= needspinning=store64 failedsemaRoot queuebad allocCountbad span statestack overflow untyped args out of range no module data in goroutine .WithDeadline(<not Stringer>getprotobynameunknown mode: data truncatedfile too largelevel 2 haltedlevel 3 haltedtoo many linksno such deviceprotocol errortext file busytoo many usersCryptGenRandomCertCloseStoreCreateProcessWFindFirstFileWFormatMessageWGetConsoleModeGetProcAddressProcess32NextWSetFilePointerNetUserGetInfoGetUserNameExWTranslateNameW procedure in winapi error #unsafe.Pointer on zero Valueunknown methodAccept-CharsetDkim-Signatureneed more dataREQUEST_METHODarrow-back.svgarrow-down.svgfile-audio.svgfile-image.svgfile-video.svgfolder-new.svgmail-reply.svgmedia-play.svgmedia-stop.svgvisibility.svgdisabledButtonmenuBackgrounddocumentCreatemoreHorizontalmailAttachmentviewFullScreenscrollBarSmallSystrayMonitorFyne error: %vRegSetValueExWunknown markerbad RST markernot a PNG fileInstEmptyWidth%%EndComments
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: morebuf={pc:: no frame (sp=runtime: frame runtimer: bad ptraceback stuckmissing address/etc/mdns.allowunknown network0601021504Z0700invalid booleannon-minimal tagunknown Go typeadvertise errorkey has expirednetwork is downno medium foundno such processGetAdaptersInfoCreateHardLinkWDeviceIoControlFlushViewOfFileGetCommandLineWGetStartupInfoWProcess32FirstWUnmapViewOfFileFailed to load Failed to find invalid argSize<invalid Value>Hanifi_RohingyaPsalter_PahlaviAccept-LanguageX-Forwarded-For()<>@,;:\"/[]?=menu-expand.svgcontent-add.svgcontent-cut.svgfolder-open.svgmedia-music.svgmedia-photo.svgmedia-video.svgmedia-pause.svgvolume-down.svgvolume-mute.svgmediaFastRewindselectionRadiusnot a valid URIRegCreateKeyExWRegDeleteValueWreflectlite.Setbad IHDR lengthbad PLTE lengthbad tRNS lengthbad filter typebad IEND lengthFencedCodeBlockfont load errorImpersonateSelfOpenThreadTokenjstmpllitinterptarinsecurepathzipinsecurepathavx512vpopcntdqinvalid pointerNoWindowContextCreatePopupMenuCreateWindowExWInsertMenuItemWPostQuitMessageround_rectangleGetSecurityInfoSetSecurityInfoFindNextVolumeWFindVolumeCloseGetCommTimeoutsIsWow64Process2QueryDosDeviceWSetCommTimeoutsSetVolumeLabelWRtlDefaultNpAclCLSIDFromStringStringFromGUID2IsWindowUnicodeIsWindowVisibletimeBeginPeriodAddDllDirectory (no semicolon)unknown commandAddTo: bad path^[ ]{0,3}<!\-\-sfnt: not foundCIDFontRevisionExpansionFactor\hookrightarrow\leftrightarrow\longrightarrow\rightharpoonup\Leftrightarrow\Longrightarrow/Subtype /Type1/CIDSystemInfo /Subtype /Image/ColorSpace /%s/Encrypt %d 0 Rnot supported
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.Tag.String
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.(*Loader).findTableBuffer
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.(*Loader).findTableBuffer.func1
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.(*Loader).RawTableTo
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.parseOneFont
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.readOTFHeader
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.readOTFEntry
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.parseOTF
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.readWOFFHeader
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.readWOFFEntry
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.parseWOFF
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.init
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.MustNewTag
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.(*Tag).String
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.(*Loader).RawTable
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.(*Loader).HasTable
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.NewTag
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting/opentype/loader.NewLoader
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: net/addrselect.go
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting@v0.1.0/opentype/loader/opentype.go
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting@v0.1.0/opentype/loader/reader.go
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting@v0.1.0/opentype/loader/reader_otf.go
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeString found in binary or memory: github.com/go-text/typesetting@v0.1.0/opentype/loader/reader_woff.go
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeFile read: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: opengl32.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: glu32.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: winmm.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: dinput8.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: xinput1_4.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: devobj.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: inputhost.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: hid.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: appxdeploymentclient.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25E609E4-B259-11CF-BFC7-444553540000}\InProcServer32Jump to behavior
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeStatic PE information: Image base 0x140000000 > 0x60000000
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeStatic file information: File size 24577536 > 1048576
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x584200
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeStatic PE information: Raw size of .rdata is bigger than: 0x100000 < 0x569600
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeStatic PE information: Raw size of .data is bigger than: 0x100000 < 0xc43200
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: /tmp/go-build2872068834/b001/exe/a.out.pdb source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exe
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeStatic PE information: section name: .buildid
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeStatic PE information: section name: /4
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeStatic PE information: section name: /18
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeStatic PE information: section name: /33
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeStatic PE information: section name: /45
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101B8200 rdtscp0_2_00007FF6101B8200
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeAPI coverage: 5.9 %
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeSystem information queried: CurrentTimeZoneInformationJump to behavior
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exe, 00000000.00000002.2231395061.00000219F6EE2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeBinary or memory string: zJVSk/BwJVmcIGfE7vmLV2H0knZ9P4SNVbfo5azV8fUZVqZa+5Acr5Pr5RzUZ5dd

Anti Debugging

barindex
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101B8200 Start: 00007FF6101B8209 End: 00007FF6101B821F0_2_00007FF6101B8200
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6101B8200 rdtscp0_2_00007FF6101B8200
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeCode function: 0_2_00007FF6106AA070 GetStartupInfoA,Sleep,Sleep,_amsg_exit,_initterm,SetUnhandledExceptionFilter,malloc,strlen,malloc,_cexit,0_2_00007FF6106AA070
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeQueries volume information: C:\Users\user\AppData\Roaming\fyne\nz.transmeter.app VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exeQueries volume information: C:\Users\user\AppData\Roaming\fyne VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
Command and Scripting Interpreter
1
DLL Side-Loading
1
DLL Side-Loading
1
Masquerading
31
Input Capture
1
System Time Discovery
Remote Services31
Input Capture
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Deobfuscate/Decode Files or Information
LSASS Memory11
Security Software Discovery
Remote Desktop Protocol1
Archive Collected Data
Junk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
DLL Side-Loading
Security Account Manager12
System Information Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook2
Obfuscated Files or Information
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1530463 Sample: SecuriteInfo.com.Trojan-Dro... Startdate: 10/10/2024 Architecture: WINDOWS Score: 27 4 SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exe 7 2 2->4         started        signatures3 7 Potentially malicious time measurement code found 4->7

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exe4%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
SourceDetectionScannerLabelLink
http://crl.thawte.com/ThawteTimestampingCA.crl00%URL Reputationsafe
http://crl.thawte.com/ThawteTimestampingCA.crl00%URL Reputationsafe
http://ocsp.thawte.com00%URL Reputationsafe
http://ocsp.thawte.com00%URL Reputationsafe
http://www.gimp.org/xmp/0%URL Reputationsafe
http://scripts.sil.org/OFL0%URL Reputationsafe
http://www.ascendercorp.com/http://www.ascendercorp.com/http://www.ascendercorp.com/typedesigners.ht0%VirustotalBrowse
http://www.ascendercorp.com/0%VirustotalBrowse
http://dejavu.sourceforge.net/wiki/index.php/Licensehttp://dejavu.sourceforge.net/wiki/index.php/Lic0%VirustotalBrowse
http://www.ascendercorp.com/typedesigners.html0%VirustotalBrowse
https://github.com/ziglang/zig-bootstrap0%VirustotalBrowse
http://emojione.com/licensingColor0%VirustotalBrowse
http://dejavu.sourceforge.net/wiki/index.php/License0%VirustotalBrowse
http://dejavu.sourceforge.net0%VirustotalBrowse
http://scripts.sil.org/OFLhttp://scripts.sil.org/OFL0%VirustotalBrowse
NameIPActiveMaliciousAntivirus DetectionReputation
fp2e7a.wpc.phicdn.net
192.229.221.95
truefalseunknown
NameSourceMaliciousAntivirus DetectionReputation
http://www.ascendercorp.com/http://www.ascendercorp.com/http://www.ascendercorp.com/typedesigners.htSecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exefalseunknown
http://www.ascendercorp.com/SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exefalseunknown
http://crl.thawte.com/ThawteTimestampingCA.crl0SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exefalse
  • URL Reputation: safe
  • URL Reputation: safe
unknown
http://ocsp.thawte.com0SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exefalse
  • URL Reputation: safe
  • URL Reputation: safe
unknown
http://www.gimp.org/xmp/SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exefalse
  • URL Reputation: safe
unknown
https://api.transmeter.nz2006-01-02T15:04:05Z07:00Time:SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exefalse
    unknown
    https://github.com/ziglang/zig-bootstrapSecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exefalseunknown
    http://emojione.comEmojiOneSecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exefalse
      unknown
      http://dejavu.sourceforge.net/wiki/index.php/Licensehttp://dejavu.sourceforge.net/wiki/index.php/LicSecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exefalseunknown
      http://www.ascendercorp.com/typedesigners.htmlSecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exefalseunknown
      http://scripts.sil.org/OFLhttp://scripts.sil.org/OFLSecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exefalseunknown
      http://scripts.sil.org/OFLSecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exefalse
      • URL Reputation: safe
      unknown
      http://dejavu.sourceforge.net/wiki/index.php/LicenseSecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exefalseunknown
      http://emojione.com/licensingColorSecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exefalseunknown
      http://dejavu.sourceforge.nethttp://dejavu.sourceforge.netFontsSecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exefalse
        unknown
        http://dejavu.sourceforge.netSecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exefalseunknown
        No contacted IP infos
        Joe Sandbox version:41.0.0 Charoite
        Analysis ID:1530463
        Start date and time:2024-10-10 06:29:15 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 4m 9s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:default.jbs
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:2
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Sample name:SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exe
        Detection:SUS
        Classification:sus27.evad.winEXE@1/0@0/0
        EGA Information:
        • Successful, ratio: 100%
        HCA Information:
        • Successful, ratio: 83%
        • Number of executed functions: 13
        • Number of non-executed functions: 48
        Cookbook Comments:
        • Found application associated with file extension: .exe
        • Stop behavior analysis, all processes terminated
        • Exclude process from analysis (whitelisted): dllhost.exe
        • Excluded IPs from analysis (whitelisted): 20.190.160.22, 40.126.32.74, 20.190.160.20, 40.126.32.134, 40.126.32.138, 40.126.32.76, 40.126.32.72, 20.190.160.17, 93.184.221.240, 20.12.23.50
        • Excluded domains from analysis (whitelisted): client.wns.windows.com, prdv4a.aadg.msidentity.com, otelrules.azureedge.net, ctldl.windowsupdate.com.delivery.microsoft.com, slscr.update.microsoft.com, wu.ec.azureedge.net, www.tm.v4.a.prd.aadg.trafficmanager.net, ctldl.windowsupdate.com, wu.azureedge.net, login.msa.msidentity.com, ocsp.digicert.com, login.live.com, ocsp.edge.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, hlb.apr-52dd2-0.edgecastdns.net, sls.update.microsoft.com, wu-b-net.trafficmanager.net, www.tm.lg.prod.aadmsa.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
        No simulations
        No context
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        fp2e7a.wpc.phicdn.nethttp://blacksaltys.comGet hashmaliciousUnknownBrowse
        • 192.229.221.95
        https://embassyatlantahub.com/res444.php?4-68747470733a2f2f632e7468696d65726e65742e636f6d2f623174462f-#mGet hashmaliciousUnknownBrowse
        • 192.229.221.95
        http://www.cottesloecounselling.com.au/anna-amhrose.htmlGet hashmaliciousUnknownBrowse
        • 192.229.221.95
        https://dlce.cc/fbacdcb212bcbb323077d5a99ef04c07Get hashmaliciousUnknownBrowse
        • 192.229.221.95
        https://dlce.cc/fbacdcb212bcbb323077d5a99ef04c07Get hashmaliciousUnknownBrowse
        • 192.229.221.95
        2efOvyn28p.exeGet hashmaliciousStealc, VidarBrowse
        • 192.229.221.95
        https://urlr.me/mqbyfGet hashmaliciousUnknownBrowse
        • 192.229.221.95
        https://link.edgepilot.com/s/66670586/vw0py2v3TkuVLaWS3JAaPg?u=https://bharatgroup.net/Get hashmaliciousUnknownBrowse
        • 192.229.221.95
        https://subsale24h.com/Get hashmaliciousUnknownBrowse
        • 192.229.221.95
        https://unscsupply.goshopgaming.com/?bypass-cdn=1Get hashmaliciousUnknownBrowse
        • 192.229.211.108
        No context
        No context
        No context
        No created / dropped files found
        File type:PE32+ executable (GUI) x86-64, for MS Windows
        Entropy (8bit):6.854442945845822
        TrID:
        • Win64 Executable GUI (202006/5) 92.65%
        • Win64 Executable (generic) (12005/4) 5.51%
        • Generic Win/DOS Executable (2004/3) 0.92%
        • DOS Executable Generic (2002/1) 0.92%
        • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
        File name:SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exe
        File size:24'577'536 bytes
        MD5:0cf6e58863853ae6163cf20cfe99379c
        SHA1:4284de670984d557dd6d4e1091c9eeaa089aad05
        SHA256:78a93828c62d7c6883a4121374937fbbeaec7a7f383f7fe756673859b9254821
        SHA512:cfdf37ea43df46b821cd382372bf253d471e2fb61001e8db49e2ae9e1b823f4c91464ffc47d7e7a0244f00ac91942b537210788c5e479b8d3fcea39794bcaef7
        SSDEEP:393216:NWJ1gXPwcLoYJFKP1JnB3Zdp1uPGiSPWw1J:A1gXJFKPVfp1uVS+w1
        TLSH:E637BE07FA525BE8C46A9834C67153967732BC48AB2A13C77F84B7686E777D08E34390
        File Content Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d...E..f..w......."......BX.........P.U........@............................. ~...........`........................................
        Icon Hash:860404d5d591d555
        Entrypoint:0x14055a050
        Entrypoint Section:.text
        Digitally signed:false
        Imagebase:0x140000000
        Subsystem:windows gui
        Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
        DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
        Time Stamp:0x66909B45 [Fri Jul 12 02:56:05 2024 UTC]
        TLS Callbacks:0x4055a4e0, 0x1, 0x4055a560, 0x1
        CLR (.Net) Version:
        OS Version Major:6
        OS Version Minor:1
        File Version Major:6
        File Version Minor:1
        Subsystem Version Major:6
        Subsystem Version Minor:1
        Import Hash:c882abb81c8df1cca45c830fbfb17df0
        Instruction
        dec eax
        sub esp, 28h
        dec eax
        mov eax, dword ptr [0058BF3Dh]
        mov dword ptr [eax], 00000001h
        call 00007F11B50A89BFh
        nop
        nop
        nop
        dec eax
        add esp, 28h
        ret
        nop
        inc ecx
        push edi
        inc ecx
        push esi
        push esi
        push edi
        push ebx
        dec eax
        sub esp, 00000090h
        xorps xmm0, xmm0
        movaps esp+70h, dqword ptr [xmm0]
        movaps esp+60h, dqword ptr [xmm0]
        movaps esp+50h, dqword ptr [xmm0]
        movaps esp+40h, dqword ptr [xmm0]
        movaps esp+30h, dqword ptr [xmm0]
        movaps esp+20h, dqword ptr [xmm0]
        dec eax
        mov dword ptr [esp+00000080h], 00000000h
        dec eax
        mov esi, dword ptr [0058BEE6h]
        cmp dword ptr [esi], 00000000h
        je 00007F11B50A89BDh
        dec eax
        lea ecx, dword ptr [esp+20h]
        call dword ptr [0059007Eh]
        dec eax
        mov eax, dword ptr [00000030h]
        dec esp
        mov esi, dword ptr [eax+08h]
        dec eax
        mov edi, dword ptr [0058BEEAh]
        xor eax, eax
        dec esp
        cmpxchg dword ptr [edi], esi
        sete bl
        je 00007F11B50A89D9h
        dec ecx
        cmp esi, eax
        je 00007F11B50A89D4h
        dec esp
        mov edi, dword ptr [0059013Ah]
        nop
        mov ecx, 000003E8h
        inc ecx
        call edi
        xor eax, eax
        dec esp
        cmpxchg dword ptr [edi], esi
        sete bl
        je 00007F11B50A89B7h
        dec ecx
        cmp esi, eax
        jne 00007F11B50A8999h
        dec esp
        mov esi, dword ptr [0058BEB8h]
        inc ecx
        mov eax, dword ptr [esi]
        cmp eax, 01h
        jne 00007F11B50A89BEh
        NameVirtual AddressVirtual Size Is in Section
        IMAGE_DIRECTORY_ENTRY_EXPORT0xae95e80x259.rdata
        IMAGE_DIRECTORY_ENTRY_IMPORT0xae98410x8c.rdata
        IMAGE_DIRECTORY_ENTRY_RESOURCE0x17c00000x1410.rsrc
        IMAGE_DIRECTORY_ENTRY_EXCEPTION0x179d0000x21a5c.pdata
        IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
        IMAGE_DIRECTORY_ENTRY_BASERELOC0x17c20000x1b65c.reloc
        IMAGE_DIRECTORY_ENTRY_DEBUG0xaf00000x1c.buildid
        IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
        IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
        IMAGE_DIRECTORY_ENTRY_TLS0xae60180x28.rdata
        IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
        IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
        IMAGE_DIRECTORY_ENTRY_IAT0xaea0000x730.rdata
        IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
        IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
        IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
        NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
        .text0x10000x5840f60x5842006eb05eed2eeae6eafddf44bcc1d2fdf7unknownunknownunknownunknownIMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
        .rdata0x5860000x5695e00x5696004dee9f1f96b473829b43d0021ea57a7dunknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
        .buildid0xaf00000x5f0x200ae5b372deb6a118c0ebd120ea40c9445False0.19921875data1.3813656052918593IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
        .data0xaf10000xcab2400xc4320053747ba7b5b14b25e3c44763f3b2e50dunknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
        .pdata0x179d0000x21a5c0x21c007685a1f0b23f0abbd77242a09edacad8False0.4155743634259259data5.745936750518542IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
        .tls0x17bf0000x100x200bf619eac0cdf3f68d496ea9344137e8bFalse0.02734375data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
        .rsrc0x17c00000x14100x1600dc872626d18820e1fa5d06a5c40bb1a3False0.7595880681818182data7.04684586071524IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
        .reloc0x17c20000x1b65c0x1b8000212db2ac8a7646e7b1244659c1cb534False0.19723899147727272data5.438393937858197IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
        /40x17de0000x210x20085d33ba7e7f24db7ea62dab6fa35c2d0False0.083984375data0.4932472998872501IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
        /180x17df0000x300x2002e4bd0cd591d66e4563d7290d074399cFalse0.05859375data0.1833387916558982IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
        /330x17e00000xd60x2000e9e6ac4c56f2660eb16b4c97f4f9330False0.369140625data2.8560749639908205IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
        /450x17e10000x4f0x200eee64425652dac312de3c9cb5d45fc9eFalse0.146484375data0.9348086305266713IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
        NameRVASizeTypeLanguageCountryZLIB Complexity
        RT_ICON0x17c01300x101cPNG image data, 200 x 150, 8-bit/color RGB, non-interlacedEnglishUnited States0.9080989330746848
        RT_GROUP_ICON0x17c11500x14dataEnglishUnited States1.25
        RT_VERSION0x17c11680x188Alpha compressed COFFEnglishUnited States0.47959183673469385
        RT_MANIFEST0x17c12f00x11bXML 1.0 document, ASCII textEnglishUnited States0.657243816254417
        DLLImport
        GDI32.dllChoosePixelFormat, CreateBitmap, CreateDCW, CreateDIBSection, CreateRectRgn, DeleteDC, DeleteObject, DescribePixelFormat, GetDeviceCaps, GetDeviceGammaRamp, SetDeviceGammaRamp, SetPixelFormat, SwapBuffers
        OPENGL32.dllwglGetProcAddress
        KERNEL32.dllAddVectoredExceptionHandler, CloseHandle, CreateEventA, CreateFileA, CreateIoCompletionPort, CreateThread, CreateWaitableTimerExW, DeleteCriticalSection, DuplicateHandle, EnterCriticalSection, ExitProcess, FormatMessageW, FreeEnvironmentStringsW, FreeLibrary, GetConsoleMode, GetCurrentThreadId, GetEnvironmentStringsW, GetErrorMode, GetLastError, GetModuleHandleExW, GetModuleHandleW, GetProcAddress, GetProcessAffinityMask, GetQueuedCompletionStatusEx, GetStartupInfoA, GetStdHandle, GetSystemDirectoryA, GetSystemInfo, GetThreadContext, GlobalAlloc, GlobalFree, GlobalLock, GlobalUnlock, InitializeCriticalSection, IsDBCSLeadByteEx, LeaveCriticalSection, LoadLibraryA, LoadLibraryExW, LoadLibraryW, MultiByteToWideChar, PostQueuedCompletionStatus, QueryPerformanceCounter, QueryPerformanceFrequency, RaiseFailFastException, ResumeThread, SetConsoleCtrlHandler, SetErrorMode, SetEvent, SetProcessPriorityBoost, SetThreadContext, SetThreadExecutionState, SetUnhandledExceptionFilter, SetWaitableTimer, Sleep, SuspendThread, SwitchToThread, TlsAlloc, TlsFree, TlsGetValue, TlsSetValue, VerSetConditionMask, VirtualAlloc, VirtualFree, VirtualProtect, VirtualQuery, WaitForMultipleObjects, WaitForSingleObject, WerGetFlags, WerSetFlags, WideCharToMultiByte, WriteConsoleW, WriteFile, __C_specific_handler
        msvcrt.dll___lc_codepage_func, ___mb_cur_max_func, __getmainargs, __initenv, __iob_func, __set_app_type, __setusermatherr, _acmdln, _amsg_exit, _beginthread, _cexit, _commode, _errno, _fmode, _initterm, _lock, _onexit, _unlock, abort, calloc, exit, fprintf, fputc, free, fwrite, getc, islower, isspace, isupper, isxdigit, localeconv, malloc, qsort, realloc, signal, strcmp, strcpy, strcspn, strerror, strlen, strncmp, strncpy, strspn, strstr, strtok, strtol, strtoul, tolower, ungetc, vfprintf, wcscmp, wcscpy, wcslen
        SHELL32.dllDragAcceptFiles, DragFinish, DragQueryFileW, DragQueryPoint
        USER32.dllAdjustWindowRectEx, BringWindowToTop, ChangeDisplaySettingsExW, ClientToScreen, ClipCursor, CloseClipboard, CreateIconIndirect, CreateWindowExW, DefWindowProcW, DestroyIcon, DestroyWindow, DispatchMessageW, EmptyClipboard, EnumDisplayDevicesW, EnumDisplayMonitors, EnumDisplaySettingsExW, EnumDisplaySettingsW, FlashWindow, GetActiveWindow, GetClassLongPtrW, GetClientRect, GetClipboardData, GetCursorPos, GetDC, GetKeyState, GetLayeredWindowAttributes, GetMessageTime, GetMonitorInfoW, GetPropW, GetRawInputData, GetRawInputDeviceInfoA, GetRawInputDeviceList, GetSystemMetrics, GetWindowLongW, GetWindowPlacement, GetWindowRect, IsIconic, IsWindowVisible, IsZoomed, LoadCursorW, LoadImageW, MapVirtualKeyW, MonitorFromWindow, MoveWindow, MsgWaitForMultipleObjects, OffsetRect, OpenClipboard, PeekMessageW, PostMessageW, PtInRect, RegisterClassExW, RegisterDeviceNotificationW, RegisterRawInputDevices, ReleaseCapture, ReleaseDC, RemovePropW, ScreenToClient, SendMessageW, SetCapture, SetClipboardData, SetCursor, SetCursorPos, SetFocus, SetForegroundWindow, SetLayeredWindowAttributes, SetPropW, SetRect, SetWindowLongW, SetWindowPlacement, SetWindowPos, SetWindowTextW, ShowWindow, SystemParametersInfoW, ToUnicode, TrackMouseEvent, TranslateMessage, UnregisterClassW, UnregisterDeviceNotification, WaitMessage, WindowFromPoint
        NameOrdinalAddress
        _cgo_dummy_export10x14179a660
        glowDebugCallback_gl2120x140542830
        goCharCB30x14052d040
        goCharModsCB40x14052d090
        goCursorEnterCB50x14052cf10
        goCursorPosCB60x14052cea0
        goDropCB70x14052d0f0
        goErrorCB80x14052cda0
        goFramebufferSizeCB90x14052d260
        goJoystickCB100x14052cdf0
        goKeyCB110x14052cfd0
        goMonitorCB120x14052d150
        goMouseButtonCB130x14052ce40
        goScrollCB140x14052cf60
        goWindowCloseCB150x14052d2c0
        goWindowContentScaleCB160x14052d430
        goWindowFocusCB170x14052d390
        goWindowIconifyCB180x14052d3e0
        goWindowMaximizeCB190x14052d300
        goWindowPosCB200x14052d1a0
        goWindowRefreshCB210x14052d350
        goWindowSizeCB220x14052d200
        Language of compilation systemCountry where language is spokenMap
        EnglishUnited States
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Oct 10, 2024 06:30:20.540833950 CEST1.1.1.1192.168.2.50xae28No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Oct 10, 2024 06:30:20.540833950 CEST1.1.1.1192.168.2.50xae28No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false

        Click to jump to process

        Click to jump to process

        • File
        • Registry

        Click to dive into process behavior distribution

        Target ID:0
        Start time:00:30:22
        Start date:10/10/2024
        Path:C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exe
        Wow64 process (32bit):false
        Commandline:"C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Dropper.WinGo.Agent.10058.14118.exe"
        Imagebase:0x7ff610150000
        File size:24'577'536 bytes
        MD5 hash:0CF6E58863853AE6163CF20CFE99379C
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:Go lang
        Reputation:low
        Has exited:true
        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

        Execution Graph

        Execution Coverage

        Dynamic/Packed Code Coverage

        Signature Coverage

        Execution Coverage:1.3%
        Dynamic/Decrypted Code Coverage:0%
        Signature Coverage:19.8%
        Total number of Nodes:1390
        Total number of Limit Nodes:118
        Show Legend
        Hide Nodes/Edges
        execution_graph 45814 7ff6101b60c0 45815 7ff6101b6102 45814->45815 45818 7ff6101bcfa0 45815->45818 45817 7ff6101b6209 45821 7ff610193480 45818->45821 45822 7ff610193486 45821->45822 45822->45821 45825 7ff6101b6340 45822->45825 45824 7ff6101934cb 45824->45817 45826 7ff6101b6361 45825->45826 45828 7ff6101b63bf 45825->45828 45826->45828 45839 7ff6101af760 45826->45839 45843 7ff61015e4a0 45826->45843 45847 7ff6101788e0 45826->45847 45853 7ff61016a440 45826->45853 45858 7ff61016c700 45826->45858 45877 7ff61016ec20 45826->45877 45881 7ff610193500 45826->45881 45889 7ff6101afa00 45826->45889 45893 7ff6101aef40 45826->45893 45897 7ff6101af980 45826->45897 45827 7ff6101b6389 45827->45824 45828->45824 45840 7ff6101af766 45839->45840 45840->45839 45905 7ff61018d6c0 45840->45905 45844 7ff61015e4a6 45843->45844 45844->45843 46273 7ff61015e4e0 45844->46273 45846 7ff61015e4c8 45846->45827 45849 7ff6101788e6 45847->45849 45848 7ff610178926 46338 7ff610178d00 45848->46338 45849->45847 45849->45848 46376 7ff610178200 GetProcAddressForCaller 45849->46376 45852 7ff61017893c 45852->45827 45857 7ff61016a446 45853->45857 45855 7ff61016a473 45855->45827 45857->45853 45857->45855 46547 7ff61017a300 45857->46547 46569 7ff6101882a0 GetProcAddressForCaller 45857->46569 45863 7ff61016c70a 45858->45863 45860 7ff61016c78a 46578 7ff61016fc40 45860->46578 45862 7ff61016c774 45865 7ff61016fc40 GetProcAddressForCaller 45862->45865 45863->45858 45863->45860 45863->45862 45864 7ff61016c75f 45863->45864 46597 7ff61018cbe0 GetProcAddressForCaller 45863->46597 46601 7ff6101882a0 GetProcAddressForCaller 45863->46601 45868 7ff61016fc40 GetProcAddressForCaller 45864->45868 45869 7ff61016c76f 45865->45869 45866 7ff61016c845 45870 7ff61016fc40 GetProcAddressForCaller 45866->45870 45868->45869 46600 7ff61018cbe0 GetProcAddressForCaller 45869->46600 45870->45869 45872 7ff61016c868 45872->45827 45873 7ff61016c7a5 45873->45866 46598 7ff61015c020 GetProcAddressForCaller 45873->46598 45875 7ff61016c7e5 46599 7ff61015c240 GetProcAddressForCaller 45875->46599 45879 7ff61016ec26 45877->45879 45879->45877 46714 7ff61016ec60 45879->46714 45880 7ff61016ec3b 45880->45827 45882 7ff610193506 45881->45882 45882->45881 46758 7ff610193560 GetProcAddressForCaller 45882->46758 45884 7ff61019351f 46759 7ff610197280 GetProcAddressForCaller 45884->46759 45886 7ff61019353a 45887 7ff610193548 45886->45887 45888 7ff61018f5c0 GetProcAddressForCaller 45886->45888 45887->45827 45888->45887 45890 7ff6101afa06 45889->45890 45890->45889 46760 7ff61018d420 45890->46760 45894 7ff6101aef46 45893->45894 45894->45893 45895 7ff61018ea20 GetProcAddressForCaller 45894->45895 45896 7ff6101aef65 45895->45896 45896->45827 45898 7ff6101af986 45897->45898 45898->45897 46877 7ff61018cbe0 GetProcAddressForCaller 45898->46877 45900 7ff6101af9b5 46862 7ff61018dcc0 45900->46862 45904 7ff6101af9d9 45904->45827 45914 7ff61018d6ca 45905->45914 45910 7ff61015c320 GetProcAddressForCaller 45910->45914 45912 7ff61018d7e7 45962 7ff6101ba000 GetProcAddressForCaller 45912->45962 45914->45905 45914->45910 45914->45912 45922 7ff610194940 45914->45922 45945 7ff6101827c0 GetProcAddressForCaller 45914->45945 45946 7ff6101912a0 GetProcAddressForCaller 45914->45946 45947 7ff61015c020 GetProcAddressForCaller 45914->45947 45948 7ff61015c240 GetProcAddressForCaller 45914->45948 45949 7ff61018ea20 45914->45949 45978 7ff6101882a0 GetProcAddressForCaller 45914->45978 45917 7ff61018d7ed 45918 7ff61018d83e 45917->45918 45963 7ff6101a7320 GetProcAddressForCaller 45917->45963 45964 7ff61018f5c0 45918->45964 45921 7ff61018d848 45921->45827 45941 7ff61019494f 45922->45941 45924 7ff6101a7320 GetProcAddressForCaller 45924->45941 45935 7ff61019c740 GetProcAddressForCaller 45935->45941 45937 7ff61015c020 GetProcAddressForCaller 45937->45941 45938 7ff6101950b2 45939 7ff6101950d5 45938->45939 46014 7ff61016d840 GetProcAddressForCaller 45938->46014 45939->45914 45940 7ff61015c240 GetProcAddressForCaller 45940->45941 45941->45922 45941->45924 45941->45935 45941->45937 45941->45940 45944 7ff610194fec 45941->45944 45979 7ff610166e40 45941->45979 45993 7ff6101ba000 GetProcAddressForCaller 45941->45993 45994 7ff61019c8a0 GetProcAddressForCaller 45941->45994 45995 7ff6101646e0 GetProcAddressForCaller 45941->45995 45996 7ff61015e120 45941->45996 46000 7ff610194300 GetProcAddressForCaller 45941->46000 46001 7ff610154de0 GetProcAddressForCaller 45941->46001 46002 7ff6101a8480 GetProcAddressForCaller 45941->46002 46003 7ff6101951c0 45941->46003 46011 7ff6101a8840 GetProcAddressForCaller 45941->46011 46012 7ff6101944a0 GetProcAddressForCaller 45941->46012 46015 7ff6101882a0 GetProcAddressForCaller 45941->46015 45944->45938 46013 7ff61019c980 GetProcAddressForCaller 45944->46013 45945->45914 45946->45914 45947->45914 45948->45914 45956 7ff61018ea2a 45949->45956 45951 7ff61018eb27 46176 7ff61018eba0 45951->46176 45953 7ff61018eb2c 45953->45914 45955 7ff61018eab2 45958 7ff61018eae9 45955->45958 46194 7ff61015c320 GetProcAddressForCaller 45955->46194 45956->45949 45956->45951 45956->45955 46154 7ff61018e0a0 45956->46154 46193 7ff61015c020 GetProcAddressForCaller 45956->46193 46196 7ff6101882a0 GetProcAddressForCaller 45956->46196 46195 7ff61015c240 GetProcAddressForCaller 45958->46195 45961 7ff61018eaf7 45961->45914 45962->45917 45963->45918 45969 7ff61018f5ca 45964->45969 45965 7ff61018f5f5 45965->45921 45968 7ff61018f688 46263 7ff61015c240 GetProcAddressForCaller 45968->46263 45969->45964 45969->45965 45969->45968 45971 7ff61018f648 45969->45971 46260 7ff61015c020 GetProcAddressForCaller 45969->46260 46261 7ff610197220 GetProcAddressForCaller 45969->46261 46264 7ff6101882a0 GetProcAddressForCaller 45969->46264 46262 7ff61015c240 GetProcAddressForCaller 45971->46262 45972 7ff61018f69b 46239 7ff61018efc0 45972->46239 45976 7ff61018f656 45976->45921 45977 7ff61018f6ac 45977->45921 45978->45914 45991 7ff610166e4a 45979->45991 45980 7ff610166e96 45980->45941 45981 7ff610166e6b 46016 7ff610166c40 45981->46016 45986 7ff61018a560 GetProcAddressForCaller 45986->45991 45987 7ff610166e7f 45987->45941 45988 7ff61018a2a0 GetProcAddressForCaller 45988->45991 45991->45979 45991->45980 45991->45981 45991->45986 45991->45988 46029 7ff610189ce0 GetProcAddressForCaller 45991->46029 46030 7ff610189f20 GetProcAddressForCaller 45991->46030 46031 7ff610189d40 GetProcAddressForCaller 45991->46031 46032 7ff6101882a0 GetProcAddressForCaller 45991->46032 45993->45941 45994->45941 45995->45941 45999 7ff61015e126 45996->45999 45998 7ff61015e145 45998->45941 45999->45996 46116 7ff61015d7c0 45999->46116 46000->45941 46001->45941 46002->45941 46004 7ff6101951c6 46003->46004 46004->46003 46152 7ff610195240 GetProcAddressForCaller 46004->46152 46006 7ff6101951d8 46007 7ff610166e40 GetProcAddressForCaller 46006->46007 46008 7ff6101951e6 46007->46008 46009 7ff610195227 46008->46009 46153 7ff6101a7320 GetProcAddressForCaller 46008->46153 46009->45941 46011->45941 46012->45941 46013->45944 46014->45939 46015->45941 46017 7ff610166c4a 46016->46017 46017->46016 46018 7ff610166db2 46017->46018 46033 7ff610167280 46017->46033 46045 7ff6101815c0 GetProcAddressForCaller 46017->46045 46046 7ff6101816a0 GetProcAddressForCaller 46017->46046 46047 7ff6101815c0 GetProcAddressForCaller 46018->46047 46021 7ff610166dc5 46048 7ff6101816a0 GetProcAddressForCaller 46021->46048 46023 7ff610166de8 46049 7ff610172160 GetProcAddressForCaller 46023->46049 46026 7ff610166dfe 46028 7ff61019d6e0 GetProcAddressForCaller 46026->46028 46028->45987 46029->45991 46030->45991 46031->45991 46032->45991 46034 7ff61016728a 46033->46034 46034->46033 46035 7ff61016729d 46034->46035 46115 7ff6101882a0 GetProcAddressForCaller 46034->46115 46037 7ff610167307 46035->46037 46038 7ff6101672c2 46035->46038 46050 7ff610175b20 46037->46050 46039 7ff6101672ec 46038->46039 46040 7ff6101672d2 46038->46040 46043 7ff610180f80 GetProcAddressForCaller 46039->46043 46102 7ff610180f80 46040->46102 46044 7ff6101672ea 46043->46044 46044->46017 46045->46017 46046->46017 46047->46021 46048->46023 46049->46026 46055 7ff610175b2f 46050->46055 46051 7ff610189ce0 GetProcAddressForCaller 46051->46055 46052 7ff6101a8620 GetProcAddressForCaller 46052->46055 46053 7ff61018a2a0 GetProcAddressForCaller 46053->46055 46054 7ff610186820 GetProcAddressForCaller 46054->46055 46055->46050 46055->46051 46055->46052 46055->46053 46055->46054 46056 7ff61018a560 GetProcAddressForCaller 46055->46056 46057 7ff61017a6a0 GetProcAddressForCaller 46055->46057 46064 7ff610189f20 GetProcAddressForCaller 46055->46064 46066 7ff610189d40 GetProcAddressForCaller 46055->46066 46068 7ff6101882a0 GetProcAddressForCaller 46055->46068 46101 7ff610175daa 46055->46101 46056->46055 46057->46055 46058 7ff610176611 46061 7ff610180320 GetProcAddressForCaller 46058->46061 46062 7ff61017667f 46058->46062 46059 7ff610176ac0 GetProcAddressForCaller 46059->46101 46060 7ff610189ce0 GetProcAddressForCaller 46060->46101 46061->46062 46062->46044 46063 7ff61017a840 GetProcAddressForCaller 46063->46101 46064->46055 46065 7ff610188ec0 GetProcAddressForCaller 46065->46101 46066->46055 46067 7ff61018a560 GetProcAddressForCaller 46067->46101 46068->46055 46069 7ff6101761fb 46069->46044 46070 7ff61017608a 46073 7ff6101b6340 GetProcAddressForCaller 46070->46073 46071 7ff6101762cb 46075 7ff6101762d4 46071->46075 46076 7ff610176302 46071->46076 46072 7ff610176056 46077 7ff610180f80 GetProcAddressForCaller 46072->46077 46078 7ff6101760d8 46073->46078 46074 7ff6101815c0 GetProcAddressForCaller 46074->46101 46080 7ff6101678c0 GetProcAddressForCaller 46075->46080 46082 7ff6101b6340 GetProcAddressForCaller 46076->46082 46081 7ff61017607f 46077->46081 46078->46044 46079 7ff6101763bd 46083 7ff610180f80 GetProcAddressForCaller 46079->46083 46087 7ff6101762ff 46080->46087 46081->46044 46082->46087 46083->46069 46084 7ff61017623f 46085 7ff6101b6340 GetProcAddressForCaller 46084->46085 46091 7ff61017628c 46085->46091 46086 7ff61018a2a0 GetProcAddressForCaller 46086->46101 46094 7ff6101815c0 GetProcAddressForCaller 46087->46094 46088 7ff6101816a0 GetProcAddressForCaller 46088->46101 46089 7ff6101761d2 46092 7ff610180f80 GetProcAddressForCaller 46089->46092 46090 7ff610176211 46093 7ff610180f80 GetProcAddressForCaller 46090->46093 46091->46044 46092->46069 46093->46069 46095 7ff61017636d 46094->46095 46097 7ff6101816a0 GetProcAddressForCaller 46095->46097 46096 7ff610189d40 GetProcAddressForCaller 46096->46101 46098 7ff610176395 46097->46098 46098->46044 46099 7ff610189f20 GetProcAddressForCaller 46099->46101 46100 7ff6101882a0 GetProcAddressForCaller 46100->46101 46101->46058 46101->46059 46101->46060 46101->46063 46101->46065 46101->46067 46101->46069 46101->46070 46101->46071 46101->46072 46101->46074 46101->46079 46101->46084 46101->46086 46101->46088 46101->46089 46101->46090 46101->46096 46101->46099 46101->46100 46103 7ff610180f8a 46102->46103 46103->46102 46104 7ff610181440 GetProcAddressForCaller 46103->46104 46106 7ff610180faa 46104->46106 46105 7ff61015c020 GetProcAddressForCaller 46105->46106 46106->46105 46107 7ff61015c240 GetProcAddressForCaller 46106->46107 46108 7ff61018100b 46106->46108 46114 7ff6101810c9 46106->46114 46107->46106 46110 7ff61015e3e0 GetProcAddressForCaller 46108->46110 46112 7ff61018104d 46108->46112 46109 7ff6101813a0 GetProcAddressForCaller 46111 7ff61018109b 46109->46111 46110->46112 46113 7ff61015c240 GetProcAddressForCaller 46111->46113 46112->46109 46113->46114 46114->46044 46115->46034 46119 7ff61015d7ca 46116->46119 46117 7ff61015df3a 46117->45998 46119->46116 46119->46117 46120 7ff61015d808 46119->46120 46122 7ff6101882a0 GetProcAddressForCaller 46119->46122 46125 7ff61015d987 46119->46125 46127 7ff61015d5c0 GetProcAddressForCaller 46119->46127 46129 7ff61015de9e 46119->46129 46131 7ff61015de91 46119->46131 46143 7ff61015e000 GetProcAddressForCaller 46119->46143 46144 7ff610166a80 GetProcAddressForCaller 46119->46144 46145 7ff610165be0 GetProcAddressForCaller 46119->46145 46146 7ff6101710a0 GetProcAddressForCaller 46119->46146 46147 7ff61015e200 GetProcAddressForCaller 46119->46147 46139 7ff61015e3e0 46120->46139 46122->46119 46125->45998 46127->46119 46132 7ff61015dec7 46129->46132 46149 7ff610180080 GetProcAddressForCaller 46129->46149 46148 7ff61015e080 GetProcAddressForCaller 46131->46148 46134 7ff61015df2f 46132->46134 46150 7ff61016aa20 GetProcAddressForCaller 46132->46150 46134->45998 46137 7ff61015df1d 46137->46134 46151 7ff61016ab20 GetProcAddressForCaller 46137->46151 46141 7ff61015e3e6 46139->46141 46140 7ff6101b6340 GetProcAddressForCaller 46142 7ff61015d859 46140->46142 46141->46139 46141->46140 46142->45998 46143->46119 46144->46119 46145->46119 46146->46119 46147->46119 46148->46129 46149->46132 46150->46137 46151->46134 46152->46006 46153->46009 46155 7ff61018e0aa 46154->46155 46155->46154 46197 7ff610198fa0 GetProcAddressForCaller 46155->46197 46157 7ff61018e0cd 46158 7ff61018e0fa 46157->46158 46159 7ff6101951c0 GetProcAddressForCaller 46157->46159 46160 7ff61018e125 46158->46160 46198 7ff61015c020 GetProcAddressForCaller 46158->46198 46159->46158 46161 7ff61015e120 GetProcAddressForCaller 46160->46161 46164 7ff61018e131 46161->46164 46163 7ff61018e2d6 46215 7ff61015c240 GetProcAddressForCaller 46163->46215 46199 7ff61018bde0 GetProcAddressForCaller 46164->46199 46166 7ff61018e112 46166->46163 46169 7ff6101b6340 GetProcAddressForCaller 46166->46169 46167 7ff61018e165 46200 7ff610193360 GetProcAddressForCaller 46167->46200 46169->46166 46171 7ff61018e16f 46172 7ff61018e1d5 46171->46172 46201 7ff610195360 46171->46201 46214 7ff6101990c0 GetProcAddressForCaller 46172->46214 46175 7ff61018e216 46175->45956 46177 7ff61018ebaa 46176->46177 46177->46176 46178 7ff61018ec43 46177->46178 46179 7ff61018ebdc 46177->46179 46235 7ff6101882a0 GetProcAddressForCaller 46177->46235 46232 7ff610198fa0 GetProcAddressForCaller 46178->46232 46230 7ff610198fa0 GetProcAddressForCaller 46179->46230 46182 7ff61018ec54 46233 7ff610184c00 GetProcAddressForCaller 46182->46233 46184 7ff61018ec05 46222 7ff6101b7f40 46184->46222 46187 7ff61018ec5e 46234 7ff6101990c0 GetProcAddressForCaller 46187->46234 46188 7ff61018ec1f 46231 7ff6101990c0 GetProcAddressForCaller 46188->46231 46191 7ff61018ec6a 46191->45953 46192 7ff61018ec3d 46192->45953 46193->45956 46194->45958 46195->45961 46196->45956 46197->46157 46198->46166 46199->46167 46200->46171 46207 7ff61019536a 46201->46207 46203 7ff6101953ab 46204 7ff6101953be 46203->46204 46216 7ff6101a8480 GetProcAddressForCaller 46203->46216 46204->46172 46206 7ff61018a4e0 GetProcAddressForCaller 46206->46207 46207->46201 46207->46203 46207->46206 46209 7ff61018a560 GetProcAddressForCaller 46207->46209 46213 7ff6101882a0 GetProcAddressForCaller 46207->46213 46217 7ff610189ce0 GetProcAddressForCaller 46207->46217 46218 7ff61018a3e0 GetProcAddressForCaller 46207->46218 46219 7ff61018a2a0 GetProcAddressForCaller 46207->46219 46220 7ff610189f20 GetProcAddressForCaller 46207->46220 46221 7ff610189d40 GetProcAddressForCaller 46207->46221 46209->46207 46213->46207 46214->46175 46215->46160 46216->46204 46217->46207 46218->46207 46219->46207 46220->46207 46221->46207 46223 7ff6101b7f65 46222->46223 46224 7ff6101b7fcc 46222->46224 46223->46224 46226 7ff6101b7f7a 46223->46226 46228 7ff6101b9b20 GetProcAddressForCaller 46224->46228 46225 7ff6101b7fea 46225->46188 46236 7ff6101b9b20 46226->46236 46227 7ff6101b7fa7 46227->46188 46228->46225 46230->46184 46231->46192 46232->46182 46233->46187 46234->46191 46235->46177 46237 7ff6101b9b70 GetProcAddressForCaller 46236->46237 46238 7ff6101b9b5f 46236->46238 46237->46227 46238->46237 46256 7ff61018efca 46239->46256 46242 7ff6101882a0 GetProcAddressForCaller 46242->46256 46243 7ff61018f0cc 46268 7ff61018bd80 GetProcAddressForCaller 46243->46268 46245 7ff61018f0d1 46269 7ff61015c240 GetProcAddressForCaller 46245->46269 46246 7ff61018f164 46248 7ff61018f17b 46246->46248 46271 7ff61015c240 GetProcAddressForCaller 46246->46271 46248->45977 46250 7ff61018f0c5 46272 7ff61015c320 GetProcAddressForCaller 46250->46272 46252 7ff61018f0f1 46253 7ff61018ea20 GetProcAddressForCaller 46252->46253 46255 7ff61018f118 46253->46255 46258 7ff61018f132 46255->46258 46270 7ff61015c020 GetProcAddressForCaller 46255->46270 46256->46239 46256->46242 46256->46243 46256->46246 46256->46250 46265 7ff61015c020 GetProcAddressForCaller 46256->46265 46266 7ff610197080 GetProcAddressForCaller 46256->46266 46267 7ff61015c240 GetProcAddressForCaller 46256->46267 46257 7ff61018f1c9 46257->45977 46258->45977 46260->45969 46261->45969 46262->45976 46263->45972 46264->45969 46265->46256 46266->46256 46267->46256 46268->46245 46269->46252 46270->46258 46271->46248 46272->46257 46274 7ff61015e4ea 46273->46274 46274->46273 46275 7ff61015e525 46274->46275 46276 7ff6101882a0 GetProcAddressForCaller 46274->46276 46277 7ff61015e5fc 46275->46277 46278 7ff61015e536 46275->46278 46276->46274 46279 7ff6101677c0 GetProcAddressForCaller 46277->46279 46280 7ff61015e56a 46278->46280 46300 7ff61015c020 GetProcAddressForCaller 46278->46300 46282 7ff61015e605 46279->46282 46286 7ff61015e5f7 46280->46286 46295 7ff6101677c0 46280->46295 46282->45846 46285 7ff61015e669 46289 7ff61015e6a5 46285->46289 46302 7ff610181500 46285->46302 46286->46285 46301 7ff61015c240 GetProcAddressForCaller 46286->46301 46287 7ff61015e710 46321 7ff6101882a0 GetProcAddressForCaller 46287->46321 46322 7ff61015c240 GetProcAddressForCaller 46287->46322 46289->45846 46294 7ff610181500 GetProcAddressForCaller 46294->46289 46296 7ff610181500 GetProcAddressForCaller 46295->46296 46297 7ff6101677db 46296->46297 46323 7ff610185560 46297->46323 46300->46280 46301->46285 46304 7ff610181525 46302->46304 46303 7ff61015e690 46303->46294 46304->46303 46330 7ff610189ce0 GetProcAddressForCaller 46304->46330 46306 7ff610181545 46331 7ff61018a560 GetProcAddressForCaller 46306->46331 46308 7ff610181556 46332 7ff61018a2a0 GetProcAddressForCaller 46308->46332 46310 7ff610181565 46333 7ff61018a560 GetProcAddressForCaller 46310->46333 46312 7ff610181576 46334 7ff61018a380 GetProcAddressForCaller 46312->46334 46314 7ff610181585 46335 7ff610189f20 GetProcAddressForCaller 46314->46335 46316 7ff61018158a 46336 7ff610189d40 GetProcAddressForCaller 46316->46336 46318 7ff61018158f 46337 7ff6101882a0 GetProcAddressForCaller 46318->46337 46320 7ff6101815a5 46321->46287 46322->46287 46326 7ff6101852e0 46323->46326 46327 7ff6101852fc 46326->46327 46328 7ff6101b7f40 GetProcAddressForCaller 46327->46328 46329 7ff61015e5e5 46328->46329 46329->46286 46329->46287 46330->46306 46331->46308 46332->46310 46333->46312 46334->46314 46335->46316 46336->46318 46337->46320 46352 7ff610178d0f 46338->46352 46339 7ff61015c020 GetProcAddressForCaller 46339->46352 46340 7ff610178e5d 46343 7ff610178f1e 46340->46343 46413 7ff610178c00 46340->46413 46342 7ff61017c9c0 GetProcAddressForCaller 46342->46352 46440 7ff61015c240 GetProcAddressForCaller 46343->46440 46348 7ff610178eb4 46439 7ff61015c240 GetProcAddressForCaller 46348->46439 46349 7ff610178e10 46371 7ff6101790f5 46349->46371 46441 7ff6101ba000 GetProcAddressForCaller 46349->46441 46351 7ff610178ec5 46351->45852 46352->46338 46352->46339 46352->46340 46352->46342 46352->46348 46352->46349 46377 7ff610179560 46352->46377 46437 7ff61017e0a0 GetProcAddressForCaller 46352->46437 46438 7ff61015c240 GetProcAddressForCaller 46352->46438 46447 7ff6101882a0 GetProcAddressForCaller 46352->46447 46356 7ff610179145 46358 7ff610179198 46356->46358 46427 7ff610167a80 46356->46427 46357 7ff610179025 46442 7ff610173460 GetProcAddressForCaller 46357->46442 46360 7ff610181500 GetProcAddressForCaller 46358->46360 46363 7ff6101791b4 46360->46363 46366 7ff6101791d5 46363->46366 46368 7ff610181500 GetProcAddressForCaller 46363->46368 46364 7ff610181500 GetProcAddressForCaller 46364->46358 46365 7ff6101790a6 46443 7ff6101ba000 GetProcAddressForCaller 46365->46443 46445 7ff6101815c0 GetProcAddressForCaller 46366->46445 46368->46366 46370 7ff6101790b9 46370->46371 46444 7ff61016d9c0 GetProcAddressForCaller 46370->46444 46421 7ff6101792c0 46371->46421 46373 7ff6101791e5 46446 7ff6101816a0 GetProcAddressForCaller 46373->46446 46375 7ff610179254 46375->45852 46376->45848 46378 7ff61017956a 46377->46378 46378->46377 46386 7ff6101795f6 46378->46386 46448 7ff61015cc20 46378->46448 46381 7ff610181500 GetProcAddressForCaller 46385 7ff6101797a9 46381->46385 46382 7ff6101796dc 46475 7ff610189ce0 GetProcAddressForCaller 46382->46475 46383 7ff6101795df 46383->46386 46391 7ff610181500 GetProcAddressForCaller 46383->46391 46482 7ff6101815c0 GetProcAddressForCaller 46385->46482 46386->46381 46387 7ff610179705 46476 7ff61018a560 GetProcAddressForCaller 46387->46476 46390 7ff6101797b5 46483 7ff6101816a0 GetProcAddressForCaller 46390->46483 46394 7ff610179646 46391->46394 46392 7ff610179716 46477 7ff61018a2a0 GetProcAddressForCaller 46392->46477 46473 7ff6101815c0 GetProcAddressForCaller 46394->46473 46396 7ff6101797cc 46464 7ff61017ae80 46396->46464 46398 7ff610179725 46478 7ff61018a560 GetProcAddressForCaller 46398->46478 46400 7ff610179652 46474 7ff6101816a0 GetProcAddressForCaller 46400->46474 46402 7ff6101797e5 46402->46352 46404 7ff610179736 46479 7ff61018a2a0 GetProcAddressForCaller 46404->46479 46405 7ff610179669 46407 7ff61017ae80 GetProcAddressForCaller 46405->46407 46407->46386 46408 7ff610179748 46480 7ff61018a560 GetProcAddressForCaller 46408->46480 46410 7ff610179759 46481 7ff610189d40 GetProcAddressForCaller 46410->46481 46412 7ff61017975e 46412->46352 46414 7ff610178c0a 46413->46414 46414->46413 46415 7ff610178c3d 46414->46415 46419 7ff610178c25 46414->46419 46521 7ff61016a600 46415->46521 46417 7ff610178c48 46417->46343 46418 7ff610178c69 46418->46343 46419->46418 46420 7ff61016a600 GetProcAddressForCaller 46419->46420 46420->46419 46424 7ff6101792ca 46421->46424 46424->46421 46425 7ff61017948b 46424->46425 46426 7ff61017a840 GetProcAddressForCaller 46424->46426 46545 7ff610178aa0 GetProcAddressForCaller 46424->46545 46546 7ff610186820 GetProcAddressForCaller 46424->46546 46425->46356 46426->46424 46435 7ff610167a8a 46427->46435 46428 7ff610167af3 46428->46364 46429 7ff610185560 GetProcAddressForCaller 46429->46435 46430 7ff610189ce0 GetProcAddressForCaller 46430->46435 46431 7ff61018a560 GetProcAddressForCaller 46431->46435 46432 7ff61018a2a0 GetProcAddressForCaller 46432->46435 46433 7ff610189f20 GetProcAddressForCaller 46433->46435 46434 7ff610189d40 GetProcAddressForCaller 46434->46435 46435->46427 46435->46428 46435->46429 46435->46430 46435->46431 46435->46432 46435->46433 46435->46434 46436 7ff6101882a0 GetProcAddressForCaller 46435->46436 46436->46435 46437->46352 46438->46352 46439->46351 46440->46349 46441->46357 46442->46365 46443->46370 46444->46371 46445->46373 46446->46375 46447->46352 46449 7ff61015cc2f 46448->46449 46449->46448 46453 7ff61016a600 GetProcAddressForCaller 46449->46453 46455 7ff610185560 GetProcAddressForCaller 46449->46455 46456 7ff61015e7a0 GetProcAddressForCaller 46449->46456 46457 7ff61018a3e0 GetProcAddressForCaller 46449->46457 46458 7ff61015e3e0 GetProcAddressForCaller 46449->46458 46459 7ff61018a560 GetProcAddressForCaller 46449->46459 46460 7ff61015cf79 46449->46460 46463 7ff6101882a0 GetProcAddressForCaller 46449->46463 46484 7ff610167dc0 46449->46484 46491 7ff610167ce0 GetProcAddressForCaller 46449->46491 46492 7ff61015d3e0 GetProcAddressForCaller 46449->46492 46493 7ff610189ce0 GetProcAddressForCaller 46449->46493 46494 7ff610189f20 GetProcAddressForCaller 46449->46494 46495 7ff610189d40 GetProcAddressForCaller 46449->46495 46453->46449 46455->46449 46456->46449 46457->46449 46458->46449 46459->46449 46460->46382 46460->46383 46463->46449 46465 7ff61017ae8a 46464->46465 46465->46464 46470 7ff61017b0ac 46465->46470 46471 7ff6101677c0 GetProcAddressForCaller 46465->46471 46496 7ff61017d2e0 46465->46496 46511 7ff6101741c0 GetProcAddressForCaller 46465->46511 46512 7ff610180560 GetProcAddressForCaller 46465->46512 46513 7ff610180960 GetProcAddressForCaller 46465->46513 46514 7ff6101882a0 GetProcAddressForCaller 46465->46514 46470->46402 46471->46465 46473->46400 46474->46405 46475->46387 46476->46392 46477->46398 46478->46404 46479->46408 46480->46410 46481->46412 46482->46390 46483->46396 46486 7ff610167dca 46484->46486 46485 7ff610185560 GetProcAddressForCaller 46487 7ff610167e05 46485->46487 46486->46484 46486->46485 46488 7ff610167e25 46487->46488 46489 7ff610185560 GetProcAddressForCaller 46487->46489 46488->46449 46490 7ff610167e65 46489->46490 46490->46449 46491->46449 46492->46449 46493->46449 46494->46449 46495->46449 46498 7ff61017d2ef 46496->46498 46498->46496 46499 7ff61017d667 46498->46499 46500 7ff61018a3e0 GetProcAddressForCaller 46498->46500 46504 7ff61018a560 GetProcAddressForCaller 46498->46504 46508 7ff6101805e0 GetProcAddressForCaller 46498->46508 46509 7ff610181500 GetProcAddressForCaller 46498->46509 46510 7ff610167a80 GetProcAddressForCaller 46498->46510 46515 7ff610180560 GetProcAddressForCaller 46498->46515 46517 7ff610189ce0 GetProcAddressForCaller 46498->46517 46518 7ff610189f20 GetProcAddressForCaller 46498->46518 46519 7ff610189d40 GetProcAddressForCaller 46498->46519 46520 7ff6101882a0 GetProcAddressForCaller 46498->46520 46516 7ff61017d880 GetProcAddressForCaller 46499->46516 46500->46498 46503 7ff61017d695 46503->46465 46504->46498 46508->46498 46509->46498 46510->46498 46511->46465 46512->46465 46513->46465 46514->46465 46515->46498 46516->46503 46517->46498 46518->46498 46519->46498 46520->46498 46522 7ff61016a60a 46521->46522 46522->46521 46523 7ff61016a61e 46522->46523 46539 7ff610189ce0 GetProcAddressForCaller 46522->46539 46540 7ff61018a560 GetProcAddressForCaller 46522->46540 46541 7ff610189d40 GetProcAddressForCaller 46522->46541 46542 7ff6101882a0 GetProcAddressForCaller 46522->46542 46526 7ff61016a627 46523->46526 46527 7ff61015e3e0 GetProcAddressForCaller 46523->46527 46528 7ff61016a677 46523->46528 46526->46417 46527->46528 46529 7ff61016a6a7 46528->46529 46533 7ff610177d60 46528->46533 46529->46417 46536 7ff610177d6a 46533->46536 46534 7ff6101677c0 GetProcAddressForCaller 46534->46536 46535 7ff610177ebc 46535->46529 46536->46533 46536->46534 46536->46535 46543 7ff610167860 GetProcAddressForCaller 46536->46543 46544 7ff6101882a0 GetProcAddressForCaller 46536->46544 46539->46522 46540->46522 46541->46522 46542->46522 46543->46536 46544->46536 46545->46424 46548 7ff61017a30a 46547->46548 46548->46547 46570 7ff61015c020 GetProcAddressForCaller 46548->46570 46550 7ff61017a339 46551 7ff61016a600 GetProcAddressForCaller 46550->46551 46552 7ff61017a345 46551->46552 46571 7ff61015c240 GetProcAddressForCaller 46552->46571 46554 7ff61017a358 46572 7ff610179f20 GetProcAddressForCaller 46554->46572 46556 7ff61017a3e5 46557 7ff61017a3ed 46556->46557 46558 7ff61017a4a4 46556->46558 46559 7ff61017a469 46557->46559 46573 7ff610164be0 GetProcAddressForCaller 46557->46573 46576 7ff61015c020 GetProcAddressForCaller 46558->46576 46559->45857 46561 7ff61017a4b2 46577 7ff61015c240 GetProcAddressForCaller 46561->46577 46564 7ff61017a409 46566 7ff61017a445 46564->46566 46574 7ff6101703e0 GetProcAddressForCaller 46564->46574 46565 7ff61017a4ec 46565->45857 46575 7ff610170260 GetProcAddressForCaller 46566->46575 46569->45857 46570->46550 46571->46554 46572->46556 46573->46564 46574->46566 46575->46559 46576->46561 46577->46565 46579 7ff61016fc4a 46578->46579 46579->46578 46581 7ff61016fc5f 46579->46581 46656 7ff6101882a0 GetProcAddressForCaller 46579->46656 46583 7ff61016fd9b 46581->46583 46596 7ff61016fe28 46581->46596 46602 7ff61016df40 46581->46602 46645 7ff610177500 GetProcAddressForCaller 46581->46645 46586 7ff61016fdc5 46583->46586 46646 7ff610177340 46583->46646 46584 7ff61016fea6 46584->45873 46586->46596 46653 7ff6101703e0 GetProcAddressForCaller 46586->46653 46591 7ff61016fdfa 46591->46596 46654 7ff61016f160 GetProcAddressForCaller 46591->46654 46593 7ff61016fdb8 46595 7ff610177340 GetProcAddressForCaller 46593->46595 46595->46586 46596->46584 46655 7ff61016f160 GetProcAddressForCaller 46596->46655 46597->45863 46598->45875 46599->45866 46600->45872 46601->45863 46603 7ff61016df4f 46602->46603 46603->46602 46604 7ff61016dfc0 46603->46604 46611 7ff61016df90 46603->46611 46605 7ff61016dffb 46604->46605 46612 7ff61016dfd0 46604->46612 46606 7ff61016dfff 46605->46606 46607 7ff61016e014 46605->46607 46608 7ff61016e103 46605->46608 46621 7ff61016e02f 46606->46621 46670 7ff610170260 GetProcAddressForCaller 46606->46670 46610 7ff61016e036 46607->46610 46614 7ff61016e028 46607->46614 46609 7ff6101b6340 GetProcAddressForCaller 46608->46609 46609->46621 46615 7ff61016e161 46610->46615 46623 7ff61016e069 46610->46623 46611->46621 46672 7ff61016e4e0 GetProcAddressForCaller 46611->46672 46612->46621 46671 7ff61016e4e0 GetProcAddressForCaller 46612->46671 46657 7ff61016e680 GetProcAddressForCaller 46614->46657 46659 7ff610189ce0 GetProcAddressForCaller 46615->46659 46619 7ff61016e152 46619->46581 46620 7ff61016e170 46660 7ff610189ce0 GetProcAddressForCaller 46620->46660 46621->46619 46658 7ff61016f160 GetProcAddressForCaller 46621->46658 46627 7ff6101b6340 GetProcAddressForCaller 46623->46627 46625 7ff61016e199 46661 7ff61018a560 GetProcAddressForCaller 46625->46661 46627->46621 46629 7ff61016e1aa 46662 7ff61018a2a0 GetProcAddressForCaller 46629->46662 46631 7ff61016e1b4 46663 7ff61018a560 GetProcAddressForCaller 46631->46663 46633 7ff61016e1c5 46664 7ff61018a2a0 GetProcAddressForCaller 46633->46664 46635 7ff61016e1cf 46665 7ff61018a560 GetProcAddressForCaller 46635->46665 46637 7ff61016e1e5 46666 7ff61018a2a0 GetProcAddressForCaller 46637->46666 46639 7ff61016e1ef 46667 7ff61018a560 GetProcAddressForCaller 46639->46667 46641 7ff61016e205 46668 7ff610189d40 GetProcAddressForCaller 46641->46668 46643 7ff61016e20a 46669 7ff6101882a0 GetProcAddressForCaller 46643->46669 46645->46581 46649 7ff61017734a 46646->46649 46649->46646 46650 7ff61016fdae 46649->46650 46673 7ff610176fc0 46649->46673 46681 7ff610177960 GetProcAddressForCaller 46649->46681 46682 7ff6101778a0 GetProcAddressForCaller 46649->46682 46650->46586 46652 7ff610181820 GetProcAddressForCaller 46650->46652 46652->46593 46653->46591 46654->46596 46655->46584 46656->46579 46657->46621 46658->46619 46659->46620 46660->46625 46661->46629 46662->46631 46663->46633 46664->46635 46665->46637 46666->46639 46667->46641 46668->46643 46669->46606 46670->46606 46671->46612 46672->46611 46674 7ff610176fc6 46673->46674 46674->46673 46683 7ff610177640 46674->46683 46678 7ff610176fe5 46679 7ff610176fef 46678->46679 46680 7ff610177640 GetProcAddressForCaller 46678->46680 46679->46649 46680->46679 46681->46649 46682->46649 46694 7ff61017764a 46683->46694 46684 7ff610176fd4 46702 7ff610177960 GetProcAddressForCaller 46684->46702 46687 7ff6101b6340 GetProcAddressForCaller 46687->46694 46688 7ff61017772a 46707 7ff61015c020 GetProcAddressForCaller 46688->46707 46694->46683 46694->46684 46694->46687 46694->46688 46701 7ff610177757 46694->46701 46703 7ff61015c020 GetProcAddressForCaller 46694->46703 46704 7ff610179ca0 GetProcAddressForCaller 46694->46704 46705 7ff610179e20 GetProcAddressForCaller 46694->46705 46706 7ff61015c240 GetProcAddressForCaller 46694->46706 46712 7ff6101882a0 GetProcAddressForCaller 46694->46712 46713 7ff610177600 GetProcAddressForCaller 46694->46713 46695 7ff610177738 46708 7ff610179e20 GetProcAddressForCaller 46695->46708 46699 7ff610177749 46709 7ff61015c240 GetProcAddressForCaller 46699->46709 46701->46684 46710 7ff61015bf00 GetProcAddressForCaller 46701->46710 46711 7ff6101778a0 GetProcAddressForCaller 46701->46711 46702->46678 46703->46694 46704->46694 46705->46694 46706->46694 46707->46695 46708->46699 46709->46701 46710->46701 46711->46701 46712->46694 46713->46694 46715 7ff61016ec6a 46714->46715 46715->46714 46716 7ff61016eca4 46715->46716 46719 7ff61018cbe0 GetProcAddressForCaller 46715->46719 46720 7ff610189ce0 GetProcAddressForCaller 46715->46720 46722 7ff61018a560 GetProcAddressForCaller 46715->46722 46725 7ff61016ede9 46715->46725 46729 7ff61018a2a0 GetProcAddressForCaller 46715->46729 46730 7ff610189f20 GetProcAddressForCaller 46715->46730 46731 7ff610189d40 GetProcAddressForCaller 46715->46731 46732 7ff6101882a0 GetProcAddressForCaller 46715->46732 46733 7ff610170040 46715->46733 46750 7ff6101ba000 GetProcAddressForCaller 46715->46750 46716->45880 46719->46715 46720->46715 46722->46715 46723 7ff61016ee45 46724 7ff61016eea9 46723->46724 46752 7ff61016d9c0 GetProcAddressForCaller 46723->46752 46727 7ff61016eee5 46724->46727 46753 7ff61016d4a0 GetProcAddressForCaller 46724->46753 46751 7ff6101ba000 GetProcAddressForCaller 46725->46751 46727->45880 46729->46715 46730->46715 46731->46715 46732->46715 46735 7ff61017004a 46733->46735 46735->46733 46736 7ff61017011a 46735->46736 46744 7ff6101701ba 46735->46744 46754 7ff610177500 GetProcAddressForCaller 46735->46754 46757 7ff6101882a0 GetProcAddressForCaller 46735->46757 46738 7ff610170145 46736->46738 46739 7ff610177340 GetProcAddressForCaller 46736->46739 46740 7ff610170165 46738->46740 46741 7ff6101701af 46738->46741 46743 7ff61017012e 46739->46743 46740->46744 46745 7ff61016df40 GetProcAddressForCaller 46740->46745 46756 7ff6101703e0 GetProcAddressForCaller 46741->46756 46743->46738 46755 7ff610181820 GetProcAddressForCaller 46743->46755 46744->46715 46747 7ff61017019d 46745->46747 46747->46715 46748 7ff610170138 46749 7ff610177340 GetProcAddressForCaller 46748->46749 46749->46738 46750->46715 46751->46723 46752->46724 46753->46727 46754->46735 46755->46748 46756->46744 46757->46735 46758->45884 46759->45886 46761 7ff61018d42a 46760->46761 46761->46760 46762 7ff61018d456 46761->46762 46788 7ff6101a8540 GetProcAddressForCaller 46761->46788 46797 7ff6101882a0 GetProcAddressForCaller 46761->46797 46789 7ff61015c020 GetProcAddressForCaller 46762->46789 46766 7ff61018d469 46784 7ff610196120 46766->46784 46768 7ff61018d556 46792 7ff6101ba000 GetProcAddressForCaller 46768->46792 46770 7ff61018d48a 46770->46768 46790 7ff6101a8ba0 GetProcAddressForCaller 46770->46790 46791 7ff6101a8480 GetProcAddressForCaller 46770->46791 46772 7ff61018d55c 46774 7ff61018d595 46772->46774 46793 7ff610197080 GetProcAddressForCaller 46772->46793 46794 7ff61015c240 GetProcAddressForCaller 46774->46794 46778 7ff61018d5ad 46781 7ff61018d5d1 46778->46781 46782 7ff610196120 GetProcAddressForCaller 46778->46782 46795 7ff61015c760 GetProcAddressForCaller 46778->46795 46779 7ff61015c020 GetProcAddressForCaller 46779->46781 46780 7ff61018d64a 46780->45827 46781->46779 46781->46780 46796 7ff6101882a0 GetProcAddressForCaller 46781->46796 46782->46778 46785 7ff610196126 46784->46785 46785->46784 46786 7ff610196187 46785->46786 46798 7ff6101961a0 46785->46798 46786->46770 46788->46761 46789->46766 46790->46770 46791->46770 46792->46772 46793->46772 46794->46778 46795->46778 46796->46781 46797->46761 46799 7ff6101961a6 46798->46799 46799->46798 46800 7ff6101961f5 46799->46800 46802 7ff610185920 46799->46802 46800->46785 46827 7ff610185932 46802->46827 46803 7ff6101882a0 GetProcAddressForCaller 46803->46827 46804 7ff610185d22 46804->46800 46806 7ff610185997 46851 7ff61015c240 GetProcAddressForCaller 46806->46851 46809 7ff6101859a6 46809->46800 46810 7ff610185a3b 46852 7ff61015c240 GetProcAddressForCaller 46810->46852 46812 7ff610185a4a 46853 7ff61015c020 GetProcAddressForCaller 46812->46853 46815 7ff610185a85 46844 7ff6101853e0 46815->46844 46819 7ff610185cc1 46856 7ff61015c240 GetProcAddressForCaller 46819->46856 46820 7ff610185abf 46823 7ff610185460 GetProcAddressForCaller 46820->46823 46825 7ff610185ae6 46823->46825 46824 7ff610185ccf 46828 7ff6101853e0 GetProcAddressForCaller 46824->46828 46854 7ff61015c240 GetProcAddressForCaller 46825->46854 46827->46802 46827->46803 46827->46804 46827->46806 46827->46810 46841 7ff6101856e0 46827->46841 46850 7ff61015c020 GetProcAddressForCaller 46827->46850 46857 7ff610189ce0 GetProcAddressForCaller 46827->46857 46858 7ff61018a560 GetProcAddressForCaller 46827->46858 46859 7ff61018a2a0 GetProcAddressForCaller 46827->46859 46860 7ff610189f20 GetProcAddressForCaller 46827->46860 46861 7ff610189d40 GetProcAddressForCaller 46827->46861 46831 7ff610185ce9 46828->46831 46831->46800 46832 7ff610185b06 46833 7ff610185c2c 46832->46833 46855 7ff610189800 GetProcAddressForCaller 46832->46855 46835 7ff6101853e0 GetProcAddressForCaller 46833->46835 46837 7ff610185c76 46835->46837 46836 7ff610185bd8 46836->46833 46847 7ff610185460 46836->46847 46838 7ff6101853e0 GetProcAddressForCaller 46837->46838 46840 7ff610185ca5 46838->46840 46840->46800 46842 7ff6101852e0 GetProcAddressForCaller 46841->46842 46843 7ff610185736 46842->46843 46843->46827 46845 7ff6101852e0 GetProcAddressForCaller 46844->46845 46846 7ff610185436 46845->46846 46846->46819 46846->46820 46848 7ff6101852e0 GetProcAddressForCaller 46847->46848 46849 7ff6101854b6 46848->46849 46849->46833 46850->46827 46851->46809 46852->46812 46853->46815 46854->46832 46855->46836 46856->46824 46857->46827 46858->46827 46859->46827 46860->46827 46861->46827 46872 7ff61018dcca 46862->46872 46864 7ff610196120 GetProcAddressForCaller 46864->46872 46867 7ff6101882a0 GetProcAddressForCaller 46867->46872 46868 7ff61018df3e 46930 7ff61015c020 GetProcAddressForCaller 46868->46930 46872->46862 46872->46864 46872->46867 46872->46868 46879 7ff61015c020 GetProcAddressForCaller 46872->46879 46880 7ff61015c240 GetProcAddressForCaller 46872->46880 46881 7ff6101a8ba0 GetProcAddressForCaller 46872->46881 46882 7ff6101a8480 GetProcAddressForCaller 46872->46882 46883 7ff61018f2a0 46872->46883 46929 7ff61015c760 GetProcAddressForCaller 46872->46929 46873 7ff61018df4c 46931 7ff61015c240 GetProcAddressForCaller 46873->46931 46876 7ff61018df85 46878 7ff61018cbe0 GetProcAddressForCaller 46876->46878 46877->45900 46878->45904 46879->46872 46880->46872 46881->46872 46882->46872 46884 7ff61018f2aa 46883->46884 46884->46883 46885 7ff61018f58d 46884->46885 46889 7ff61018f2f6 46884->46889 46886 7ff61018efc0 GetProcAddressForCaller 46885->46886 46887 7ff61018f596 46886->46887 46887->46872 46888 7ff61018f3ab 46891 7ff61018f405 46888->46891 46892 7ff61018f3e4 46888->46892 46890 7ff61018f32d 46889->46890 46893 7ff61018f33c 46889->46893 46895 7ff61018efc0 GetProcAddressForCaller 46890->46895 46932 7ff61015c020 GetProcAddressForCaller 46891->46932 46896 7ff61018efc0 GetProcAddressForCaller 46892->46896 46893->46888 46901 7ff61018f39c 46893->46901 46898 7ff61018f336 46895->46898 46899 7ff61018f3ff 46896->46899 46897 7ff61018f413 46900 7ff61018f41d 46897->46900 46908 7ff61018f45d 46897->46908 46898->46872 46899->46872 46902 7ff61018f449 46900->46902 46933 7ff61015c320 GetProcAddressForCaller 46900->46933 46903 7ff61018efc0 GetProcAddressForCaller 46901->46903 46934 7ff61015c240 GetProcAddressForCaller 46902->46934 46906 7ff61018f3a5 46903->46906 46906->46872 46907 7ff61018f4bc 46910 7ff61018f4ce 46907->46910 46911 7ff61018f56b 46907->46911 46908->46907 46935 7ff61015c320 GetProcAddressForCaller 46908->46935 46909 7ff61018f457 46909->46872 46912 7ff61018f512 46910->46912 46914 7ff61018f4f0 46910->46914 46940 7ff61015c240 GetProcAddressForCaller 46911->46940 46937 7ff610196ee0 GetProcAddressForCaller 46912->46937 46936 7ff61015c240 GetProcAddressForCaller 46914->46936 46915 7ff61018f579 46919 7ff61018efc0 GetProcAddressForCaller 46915->46919 46922 7ff61018f587 46919->46922 46920 7ff61018f545 46938 7ff61015c240 GetProcAddressForCaller 46920->46938 46921 7ff61018f4fe 46924 7ff61018efc0 GetProcAddressForCaller 46921->46924 46922->46872 46926 7ff61018f50c 46924->46926 46925 7ff61018f553 46927 7ff61018f565 46925->46927 46939 7ff6101911c0 GetProcAddressForCaller 46925->46939 46926->46872 46927->46872 46929->46872 46930->46873 46931->46876 46932->46897 46933->46902 46934->46909 46935->46907 46936->46921 46937->46920 46938->46925 46939->46927 46940->46915 46941 7ff6101b62c0 46942 7ff6101b62ef 46941->46942 46943 7ff6101b62f4 46941->46943 46964 7ff61018b680 GetProcAddressForCaller 46942->46964 46950 7ff610191a20 46943->46950 46951 7ff610191a2a 46950->46951 46951->46950 46952 7ff610191a65 46951->46952 46992 7ff6101a7320 GetProcAddressForCaller 46951->46992 46993 7ff61018cbe0 GetProcAddressForCaller 46952->46993 46955 7ff610191b3a 46978 7ff610191580 46955->46978 46958 7ff610191a79 46958->46955 46959 7ff610191b17 46958->46959 46994 7ff6101a89a0 GetProcAddressForCaller 46958->46994 46995 7ff61018cbe0 GetProcAddressForCaller 46959->46995 46962 7ff610191b2b 46966 7ff61018fb40 46962->46966 46965 7ff61018b6c0 GetProcAddressForCaller 46967 7ff61018fb4a 46966->46967 46967->46966 46969 7ff61018fb79 46967->46969 46996 7ff61017f9e0 GetProcAddressForCaller 46967->46996 46997 7ff61018cbe0 GetProcAddressForCaller 46969->46997 46971 7ff61018fbdb 46972 7ff61018fc33 46971->46972 46998 7ff610185840 GetProcAddressForCaller 46971->46998 46974 7ff61018fc53 46972->46974 46975 7ff61018fc4e 46972->46975 46999 7ff6101a8ac0 GetProcAddressForCaller 46972->46999 46974->46955 47000 7ff6101a8840 GetProcAddressForCaller 46975->47000 46990 7ff61019158a 46978->46990 46980 7ff6101882a0 GetProcAddressForCaller 46980->46990 46982 7ff61018fb40 GetProcAddressForCaller 46982->46990 46984 7ff61015c020 GetProcAddressForCaller 46984->46990 46985 7ff61018f5c0 GetProcAddressForCaller 46985->46990 46986 7ff6101917b7 46987 7ff61018fb40 GetProcAddressForCaller 46986->46987 46989 7ff6101917bc 46987->46989 46989->46965 46990->46978 46990->46980 46990->46982 46990->46984 46990->46985 46990->46986 46991 7ff61015c240 GetProcAddressForCaller 46990->46991 47001 7ff61018f700 46990->47001 47017 7ff61018fca0 46990->47017 47081 7ff610191220 46990->47081 47087 7ff61018f980 GetProcAddressForCaller 46990->47087 46991->46990 46992->46952 46993->46958 46994->46959 46995->46962 46996->46969 46997->46971 46998->46972 46999->46975 47000->46974 47016 7ff61018f70a 47001->47016 47002 7ff6101882a0 GetProcAddressForCaller 47002->47016 47003 7ff610195360 GetProcAddressForCaller 47003->47016 47005 7ff61018f2a0 GetProcAddressForCaller 47005->47016 47007 7ff61018f7a8 47008 7ff6101951c0 GetProcAddressForCaller 47007->47008 47009 7ff61018f7b8 47008->47009 47009->46990 47010 7ff610189d40 GetProcAddressForCaller 47010->47016 47011 7ff610189ce0 GetProcAddressForCaller 47011->47016 47012 7ff61018a560 GetProcAddressForCaller 47012->47016 47013 7ff61018a2a0 GetProcAddressForCaller 47013->47016 47014 7ff610189f20 GetProcAddressForCaller 47014->47016 47015 7ff61018a4e0 GetProcAddressForCaller 47015->47016 47016->47001 47016->47002 47016->47003 47016->47005 47016->47007 47016->47010 47016->47011 47016->47012 47016->47013 47016->47014 47016->47015 47088 7ff6101954c0 GetProcAddressForCaller 47016->47088 47089 7ff61015c3a0 GetProcAddressForCaller 47016->47089 47056 7ff61018fcb2 47017->47056 47023 7ff6101905e4 47102 7ff61018cbe0 GetProcAddressForCaller 47023->47102 47025 7ff61015c020 GetProcAddressForCaller 47025->47056 47026 7ff6101905fb 47103 7ff6101a89a0 GetProcAddressForCaller 47026->47103 47028 7ff610196cc0 GetProcAddressForCaller 47028->47056 47029 7ff6101b7f40 GetProcAddressForCaller 47029->47056 47030 7ff61019060a 47030->46990 47032 7ff61015c240 GetProcAddressForCaller 47032->47056 47033 7ff610190667 47104 7ff6101912a0 GetProcAddressForCaller 47033->47104 47034 7ff6101905c7 47034->46990 47037 7ff61019068c 47105 7ff61018cbe0 GetProcAddressForCaller 47037->47105 47039 7ff6101906a5 47041 7ff6101906bd 47039->47041 47106 7ff6101a89a0 GetProcAddressForCaller 47039->47106 47041->46990 47043 7ff610190916 47117 7ff61018cbe0 GetProcAddressForCaller 47043->47117 47044 7ff610190849 47114 7ff610196cc0 GetProcAddressForCaller 47044->47114 47047 7ff610190939 47049 7ff610190951 47047->47049 47118 7ff6101a89a0 GetProcAddressForCaller 47047->47118 47049->46990 47050 7ff610190850 47115 7ff61015c240 GetProcAddressForCaller 47050->47115 47053 7ff610190866 47053->46990 47054 7ff610195360 GetProcAddressForCaller 47054->47056 47056->47017 47056->47023 47056->47025 47056->47028 47056->47029 47056->47032 47056->47033 47056->47034 47056->47043 47056->47044 47056->47054 47058 7ff6101882a0 GetProcAddressForCaller 47056->47058 47059 7ff6101951c0 GetProcAddressForCaller 47056->47059 47061 7ff6101906ec 47056->47061 47065 7ff6101827c0 GetProcAddressForCaller 47056->47065 47067 7ff6101ba000 GetProcAddressForCaller 47056->47067 47071 7ff61018ee80 GetProcAddressForCaller 47056->47071 47074 7ff610190789 47056->47074 47090 7ff61018fa40 GetProcAddressForCaller 47056->47090 47091 7ff61018e000 GetProcAddressForCaller 47056->47091 47092 7ff610191820 GetProcAddressForCaller 47056->47092 47093 7ff6101a7180 GetProcAddressForCaller 47056->47093 47094 7ff610171d60 GetProcAddressForCaller 47056->47094 47095 7ff61018bfe0 GetProcAddressForCaller 47056->47095 47096 7ff610190a60 GetProcAddressForCaller 47056->47096 47097 7ff610172740 GetProcAddressForCaller 47056->47097 47098 7ff610196ee0 GetProcAddressForCaller 47056->47098 47099 7ff610190e20 GetProcAddressForCaller 47056->47099 47100 7ff610191000 GetProcAddressForCaller 47056->47100 47101 7ff610197080 GetProcAddressForCaller 47056->47101 47112 7ff6101912a0 GetProcAddressForCaller 47056->47112 47113 7ff6101826c0 GetProcAddressForCaller 47056->47113 47116 7ff610172820 GetProcAddressForCaller 47056->47116 47058->47056 47059->47056 47062 7ff6101951c0 GetProcAddressForCaller 47061->47062 47064 7ff610190705 47062->47064 47107 7ff61018cbe0 GetProcAddressForCaller 47064->47107 47065->47056 47067->47056 47068 7ff61019075c 47069 7ff610190774 47068->47069 47108 7ff6101a89a0 GetProcAddressForCaller 47068->47108 47069->46990 47071->47056 47109 7ff6101912a0 GetProcAddressForCaller 47074->47109 47076 7ff6101907ae 47110 7ff61018cbe0 GetProcAddressForCaller 47076->47110 47078 7ff6101907c5 47079 7ff6101907dd 47078->47079 47111 7ff6101a89a0 GetProcAddressForCaller 47078->47111 47079->46990 47082 7ff610191226 47081->47082 47082->47081 47083 7ff610191259 47082->47083 47085 7ff6101882a0 GetProcAddressForCaller 47082->47085 47084 7ff61018f5c0 GetProcAddressForCaller 47083->47084 47086 7ff61019125e 47084->47086 47085->47082 47086->46990 47087->46990 47088->47016 47089->47016 47090->47056 47091->47056 47092->47056 47093->47056 47094->47056 47095->47056 47096->47056 47097->47056 47098->47056 47099->47056 47100->47056 47101->47056 47102->47026 47103->47030 47104->47037 47105->47039 47106->47041 47107->47068 47108->47069 47109->47076 47110->47078 47111->47079 47112->47056 47113->47056 47114->47050 47115->47053 47116->47056 47117->47047 47118->47049 47119 7ff61018ba60 47137 7ff61018ba6a 47119->47137 47136 7ff610194940 GetProcAddressForCaller 47136->47137 47137->47119 47137->47136 47138 7ff61018bc29 47137->47138 47142 7ff61015c8e0 47137->47142 47157 7ff610151080 47137->47157 47163 7ff610184000 47137->47163 47178 7ff610198700 47137->47178 47194 7ff6101a2660 GetProcAddressForCaller 47137->47194 47195 7ff610154a60 GetProcAddressForCaller 47137->47195 47196 7ff610183f60 47137->47196 47203 7ff61018bde0 GetProcAddressForCaller 47137->47203 47204 7ff6101a2440 GetProcAddressForCaller 47137->47204 47205 7ff6101ad4a0 GetProcAddressForCaller 47137->47205 47206 7ff61015b420 GetProcAddressForCaller 47137->47206 47207 7ff6101a03c0 GetProcAddressForCaller 47137->47207 47208 7ff61016a740 GetProcAddressForCaller 47137->47208 47209 7ff61015c020 GetProcAddressForCaller 47137->47209 47210 7ff6101ba000 GetProcAddressForCaller 47137->47210 47211 7ff610158740 GetProcAddressForCaller 47137->47211 47213 7ff6101882a0 GetProcAddressForCaller 47137->47213 47212 7ff61015c240 GetProcAddressForCaller 47138->47212 47141 7ff61018bc37 47154 7ff61015c8ea 47142->47154 47143 7ff610189ce0 GetProcAddressForCaller 47143->47154 47144 7ff61018a560 GetProcAddressForCaller 47144->47154 47146 7ff61018a2a0 GetProcAddressForCaller 47146->47154 47147 7ff61015c95d 47214 7ff610178060 47147->47214 47150 7ff61018a380 GetProcAddressForCaller 47150->47154 47151 7ff610189d40 GetProcAddressForCaller 47151->47154 47152 7ff61015ca1f 47152->47137 47153 7ff6101882a0 GetProcAddressForCaller 47153->47154 47154->47142 47154->47143 47154->47144 47154->47146 47154->47147 47154->47150 47154->47151 47154->47153 47155 7ff61015c997 47155->47152 47156 7ff61016a600 GetProcAddressForCaller 47155->47156 47156->47155 47158 7ff610151086 47157->47158 47158->47157 47274 7ff610151620 47158->47274 47160 7ff61015109d 47282 7ff6101510e0 GetProcAddressForCaller 47160->47282 47162 7ff6101510ac 47162->47137 47174 7ff61018400a 47163->47174 47166 7ff610184151 47167 7ff6101853e0 GetProcAddressForCaller 47166->47167 47169 7ff610184166 47167->47169 47302 7ff6101b43e0 GetProcAddressForCaller 47169->47302 47171 7ff6101841a5 47172 7ff610185460 GetProcAddressForCaller 47171->47172 47173 7ff6101841c5 47172->47173 47285 7ff6101833a0 47173->47285 47174->47163 47174->47166 47176 7ff610184202 47174->47176 47297 7ff6101853a0 47174->47297 47300 7ff61019c8a0 GetProcAddressForCaller 47174->47300 47301 7ff6101a1860 GetProcAddressForCaller 47174->47301 47176->47137 47177 7ff6101841dc 47177->47137 47179 7ff61019870a 47178->47179 47179->47178 47314 7ff610158740 GetProcAddressForCaller 47179->47314 47181 7ff610198745 47182 7ff61015e120 GetProcAddressForCaller 47181->47182 47183 7ff61019875b 47182->47183 47315 7ff6101b0f80 GetProcAddressForCaller 47183->47315 47185 7ff610198795 47316 7ff6101989e0 GetProcAddressForCaller 47185->47316 47187 7ff6101987ec 47317 7ff6101989e0 GetProcAddressForCaller 47187->47317 47189 7ff6101987fd 47318 7ff610158740 GetProcAddressForCaller 47189->47318 47191 7ff610198829 47319 7ff6101b30e0 GetProcAddressForCaller 47191->47319 47193 7ff61019882e 47193->47137 47194->47137 47195->47137 47197 7ff610183fd8 47196->47197 47198 7ff610183f72 47196->47198 47199 7ff610185460 GetProcAddressForCaller 47198->47199 47200 7ff610183f9b 47199->47200 47320 7ff610198e40 GetProcAddressForCaller 47200->47320 47202 7ff610183fd2 47202->47137 47203->47137 47204->47137 47205->47137 47206->47137 47207->47137 47208->47137 47209->47137 47210->47137 47211->47137 47212->47141 47213->47137 47216 7ff61017806a 47214->47216 47216->47214 47248 7ff61016a4e0 GetProcAddressForCaller 47216->47248 47217 7ff6101780e6 47249 7ff61016a4e0 GetProcAddressForCaller 47217->47249 47219 7ff610178105 47250 7ff61016a4e0 GetProcAddressForCaller 47219->47250 47221 7ff61017811f 47251 7ff61016a4e0 GetProcAddressForCaller 47221->47251 47223 7ff610178139 47252 7ff61016a4e0 GetProcAddressForCaller 47223->47252 47225 7ff610178153 47253 7ff61016a4e0 GetProcAddressForCaller 47225->47253 47227 7ff61017816d 47254 7ff61016a4e0 GetProcAddressForCaller 47227->47254 47229 7ff610178187 47233 7ff61017acc0 47229->47233 47232 7ff6101666e0 GetProcAddressForCaller 47232->47155 47241 7ff61017acca 47233->47241 47234 7ff61017acea 47255 7ff6101806c0 47234->47255 47236 7ff61018a560 GetProcAddressForCaller 47236->47241 47237 7ff61017ad36 47259 7ff61017d1a0 47237->47259 47239 7ff61017ad45 47264 7ff6101740e0 47239->47264 47240 7ff61018a380 GetProcAddressForCaller 47240->47241 47241->47233 47241->47234 47241->47236 47241->47240 47243 7ff610189d40 GetProcAddressForCaller 47241->47243 47245 7ff610189ce0 GetProcAddressForCaller 47241->47245 47246 7ff610189f20 GetProcAddressForCaller 47241->47246 47268 7ff6101882a0 GetProcAddressForCaller 47241->47268 47243->47241 47245->47241 47246->47241 47248->47217 47249->47219 47250->47221 47251->47223 47252->47225 47253->47227 47254->47229 47256 7ff6101806c6 47255->47256 47256->47255 47257 7ff61015e3e0 GetProcAddressForCaller 47256->47257 47258 7ff6101806fa 47257->47258 47258->47237 47262 7ff61017d1aa 47259->47262 47260 7ff61017d2a5 47260->47239 47261 7ff610167dc0 GetProcAddressForCaller 47261->47262 47262->47259 47262->47260 47262->47261 47269 7ff6101882a0 GetProcAddressForCaller 47262->47269 47265 7ff6101740ea 47264->47265 47265->47264 47270 7ff61017dbc0 47265->47270 47267 7ff61015c992 47267->47232 47268->47241 47269->47262 47271 7ff61017dbc6 47270->47271 47271->47270 47272 7ff610167dc0 GetProcAddressForCaller 47271->47272 47273 7ff61017dbe5 47272->47273 47273->47267 47275 7ff61015162a 47274->47275 47275->47274 47276 7ff61015e120 GetProcAddressForCaller 47275->47276 47277 7ff61015163e 47276->47277 47278 7ff61015179f 47277->47278 47283 7ff61019c980 GetProcAddressForCaller 47277->47283 47281 7ff6101519aa 47278->47281 47284 7ff61019c980 GetProcAddressForCaller 47278->47284 47281->47160 47282->47162 47283->47278 47284->47281 47287 7ff6101833af 47285->47287 47287->47285 47303 7ff6101854e0 47287->47303 47289 7ff610183505 47289->47177 47292 7ff6101834ff 47292->47177 47294 7ff6101834a5 47295 7ff6101854e0 GetProcAddressForCaller 47294->47295 47296 7ff6101834e7 47295->47296 47296->47177 47298 7ff6101852e0 GetProcAddressForCaller 47297->47298 47299 7ff6101853d2 47298->47299 47299->47174 47300->47174 47301->47174 47302->47171 47304 7ff6101852e0 GetProcAddressForCaller 47303->47304 47305 7ff6101833e6 47304->47305 47305->47289 47306 7ff610182c20 47305->47306 47307 7ff610182c26 47306->47307 47307->47306 47308 7ff610182c45 47307->47308 47313 7ff6101882a0 GetProcAddressForCaller 47307->47313 47309 7ff610185460 GetProcAddressForCaller 47308->47309 47311 7ff610182c5f 47309->47311 47311->47292 47312 7ff6101b43e0 GetProcAddressForCaller 47311->47312 47312->47294 47313->47307 47314->47181 47315->47185 47316->47187 47317->47189 47318->47191 47319->47193 47320->47202 47321 7ff61018d8a0 47322 7ff61018d8b3 47321->47322 47327 7ff61018d920 47322->47327 47326 7ff61018d914 47329 7ff61018d92a 47327->47329 47328 7ff61018d949 47343 7ff610184da0 47328->47343 47329->47327 47329->47328 47390 7ff6101882a0 GetProcAddressForCaller 47329->47390 47332 7ff61018d985 47335 7ff61018d99c 47332->47335 47389 7ff61018da20 GetProcAddressForCaller 47332->47389 47334 7ff61018d9bd 47336 7ff61018d9de 47334->47336 47337 7ff6101951c0 GetProcAddressForCaller 47334->47337 47335->47334 47359 7ff610195960 47335->47359 47377 7ff61018ed80 47335->47377 47338 7ff610191580 GetProcAddressForCaller 47336->47338 47337->47336 47339 7ff61018d90a 47338->47339 47342 7ff61018da60 GetProcAddressForCaller 47339->47342 47342->47326 47351 7ff610184daf 47343->47351 47344 7ff6101856e0 GetProcAddressForCaller 47344->47351 47346 7ff6101853a0 GetProcAddressForCaller 47346->47351 47348 7ff610185560 GetProcAddressForCaller 47348->47351 47349 7ff6101854e0 GetProcAddressForCaller 47349->47351 47350 7ff610189f20 GetProcAddressForCaller 47350->47351 47351->47343 47351->47344 47351->47346 47351->47348 47351->47349 47351->47350 47352 7ff610189ce0 GetProcAddressForCaller 47351->47352 47353 7ff610184f89 47351->47353 47354 7ff61018a3e0 GetProcAddressForCaller 47351->47354 47355 7ff61018a2a0 GetProcAddressForCaller 47351->47355 47356 7ff610189d40 GetProcAddressForCaller 47351->47356 47357 7ff61018a560 GetProcAddressForCaller 47351->47357 47358 7ff6101882a0 GetProcAddressForCaller 47351->47358 47391 7ff61015c020 GetProcAddressForCaller 47351->47391 47392 7ff61015c240 GetProcAddressForCaller 47351->47392 47352->47351 47353->47332 47354->47351 47355->47351 47356->47351 47357->47351 47358->47351 47373 7ff61019596a 47359->47373 47361 7ff6101b6340 GetProcAddressForCaller 47361->47373 47362 7ff6101ba000 GetProcAddressForCaller 47362->47373 47363 7ff61015c020 GetProcAddressForCaller 47363->47373 47365 7ff61015c240 GetProcAddressForCaller 47365->47373 47366 7ff6101b7f40 GetProcAddressForCaller 47366->47373 47372 7ff610183620 GetProcAddressForCaller 47372->47373 47373->47359 47373->47361 47373->47362 47373->47363 47373->47365 47373->47366 47373->47372 47374 7ff6101954c0 GetProcAddressForCaller 47373->47374 47376 7ff6101912a0 GetProcAddressForCaller 47373->47376 47393 7ff610195ee0 47373->47393 47407 7ff610195520 GetProcAddressForCaller 47373->47407 47408 7ff6101a6c60 GetProcAddressForCaller 47373->47408 47409 7ff61015c760 GetProcAddressForCaller 47373->47409 47410 7ff6101827c0 GetProcAddressForCaller 47373->47410 47411 7ff610172ea0 GetProcAddressForCaller 47373->47411 47412 7ff61016aa20 GetProcAddressForCaller 47373->47412 47413 7ff610196240 GetProcAddressForCaller 47373->47413 47374->47373 47376->47373 47378 7ff61018ed8a 47377->47378 47378->47377 47420 7ff61015c020 GetProcAddressForCaller 47378->47420 47380 7ff61018eda5 47421 7ff610195520 GetProcAddressForCaller 47380->47421 47382 7ff61018edb0 47422 7ff61015c240 GetProcAddressForCaller 47382->47422 47384 7ff61015c240 GetProcAddressForCaller 47385 7ff61018edbe 47384->47385 47385->47384 47387 7ff61018eba0 GetProcAddressForCaller 47385->47387 47388 7ff61015c020 GetProcAddressForCaller 47385->47388 47423 7ff61015c3a0 GetProcAddressForCaller 47385->47423 47387->47385 47388->47385 47389->47335 47390->47329 47391->47351 47392->47351 47394 7ff610195eea 47393->47394 47394->47393 47414 7ff61015c020 GetProcAddressForCaller 47394->47414 47396 7ff610195fe7 47415 7ff61015c240 GetProcAddressForCaller 47396->47415 47398 7ff610195ff5 47398->47373 47399 7ff6101961a0 GetProcAddressForCaller 47404 7ff610195f05 47399->47404 47401 7ff6101954c0 GetProcAddressForCaller 47401->47404 47403 7ff61018f2a0 GetProcAddressForCaller 47403->47404 47404->47396 47404->47399 47404->47401 47404->47403 47416 7ff61015c240 GetProcAddressForCaller 47404->47416 47417 7ff6101a8ba0 GetProcAddressForCaller 47404->47417 47418 7ff6101a8480 GetProcAddressForCaller 47404->47418 47419 7ff61015c020 GetProcAddressForCaller 47404->47419 47407->47373 47408->47373 47409->47373 47410->47373 47411->47373 47412->47373 47413->47373 47414->47404 47415->47398 47416->47404 47417->47404 47418->47404 47419->47404 47420->47380 47421->47382 47422->47385 47423->47385 47424 7ff610195e00 47426 7ff610195e0a 47424->47426 47425 7ff610195e9d 47426->47424 47426->47425 47430 7ff610185660 47426->47430 47429 7ff6101854e0 GetProcAddressForCaller 47429->47425 47431 7ff6101852e0 GetProcAddressForCaller 47430->47431 47432 7ff6101856b6 47431->47432 47432->47429 47433 7ff610177840 47434 7ff610177846 47433->47434 47434->47433 47437 7ff610178960 47434->47437 47438 7ff610178966 47437->47438 47438->47437 47439 7ff610178972 47438->47439 47443 7ff6101882a0 GetProcAddressForCaller 47438->47443 47440 7ff610178d00 GetProcAddressForCaller 47439->47440 47442 7ff61017786d 47440->47442 47443->47438 47444 7ff61016e3a0 47447 7ff61016e3aa 47444->47447 47447->47444 47448 7ff61016e4a1 47447->47448 47449 7ff61016e43b 47447->47449 47457 7ff610188fc0 47447->47457 47542 7ff61018cbe0 GetProcAddressForCaller 47447->47542 47545 7ff6101882a0 GetProcAddressForCaller 47447->47545 47489 7ff61016f2e0 47449->47489 47452 7ff61016e455 47543 7ff610189520 GetProcAddressForCaller 47452->47543 47454 7ff61016e47d 47455 7ff61016e49a 47454->47455 47544 7ff61018cbe0 GetProcAddressForCaller 47454->47544 47458 7ff610188fca 47457->47458 47458->47457 47459 7ff6101882a0 GetProcAddressForCaller 47458->47459 47460 7ff610189206 47458->47460 47461 7ff6101893bd 47458->47461 47463 7ff61018915c 47458->47463 47465 7ff610189236 47458->47465 47470 7ff610189074 47458->47470 47473 7ff610189ce0 GetProcAddressForCaller 47458->47473 47481 7ff61018a560 GetProcAddressForCaller 47458->47481 47485 7ff610189f20 GetProcAddressForCaller 47458->47485 47486 7ff610189d40 GetProcAddressForCaller 47458->47486 47487 7ff61018a4e0 GetProcAddressForCaller 47458->47487 47488 7ff61018a2a0 GetProcAddressForCaller 47458->47488 47459->47458 47460->47463 47550 7ff61018cb00 GetProcAddressForCaller 47460->47550 47461->47447 47464 7ff6101892d7 47463->47464 47466 7ff61018936d 47463->47466 47551 7ff6101ba000 GetProcAddressForCaller 47463->47551 47552 7ff6101ba000 GetProcAddressForCaller 47464->47552 47549 7ff61018d0a0 GetProcAddressForCaller 47465->47549 47466->47447 47470->47463 47546 7ff61018cb00 GetProcAddressForCaller 47470->47546 47471 7ff6101892fe 47474 7ff61018931b 47471->47474 47475 7ff6101b6340 GetProcAddressForCaller 47471->47475 47473->47458 47474->47447 47476 7ff610189356 47475->47476 47553 7ff6101ba000 GetProcAddressForCaller 47476->47553 47478 7ff6101890d8 47478->47463 47547 7ff61018c740 GetProcAddressForCaller 47478->47547 47480 7ff61018914a 47480->47463 47548 7ff6101ba000 GetProcAddressForCaller 47480->47548 47481->47458 47483 7ff610189169 47483->47463 47484 7ff610185920 GetProcAddressForCaller 47483->47484 47484->47463 47485->47458 47486->47458 47487->47458 47488->47458 47524 7ff61016f2f2 47489->47524 47490 7ff610189ce0 GetProcAddressForCaller 47490->47524 47491 7ff61016f480 47492 7ff61016f485 47491->47492 47563 7ff610189ce0 GetProcAddressForCaller 47491->47563 47492->47452 47494 7ff61016f4af 47564 7ff61018a560 GetProcAddressForCaller 47494->47564 47495 7ff61018a4e0 GetProcAddressForCaller 47495->47524 47497 7ff61016f349 47503 7ff61016f3ad 47497->47503 47554 7ff61019f600 47497->47554 47498 7ff61016f4c5 47565 7ff61018a4e0 GetProcAddressForCaller 47498->47565 47499 7ff61018a560 GetProcAddressForCaller 47499->47524 47502 7ff61016f4d2 47566 7ff61018a560 GetProcAddressForCaller 47502->47566 47505 7ff61016f431 47503->47505 47561 7ff610170260 GetProcAddressForCaller 47503->47561 47562 7ff6101a8e20 GetProcAddressForCaller 47505->47562 47506 7ff61016f4e5 47567 7ff61018a2a0 GetProcAddressForCaller 47506->47567 47510 7ff61016f4ef 47568 7ff61018a560 GetProcAddressForCaller 47510->47568 47513 7ff610189f20 GetProcAddressForCaller 47513->47524 47514 7ff61016f505 47569 7ff61018a2a0 GetProcAddressForCaller 47514->47569 47516 7ff61016f50f 47570 7ff610189f20 GetProcAddressForCaller 47516->47570 47517 7ff61018a2a0 GetProcAddressForCaller 47517->47524 47520 7ff61016f478 47526 7ff61016f55d 47520->47526 47573 7ff61016fa00 GetProcAddressForCaller 47520->47573 47574 7ff6101a9440 GetProcAddressForCaller 47520->47574 47521 7ff61016f64c 47538 7ff61016f665 47521->47538 47575 7ff610174bc0 GetProcAddressForCaller 47521->47575 47522 7ff61016f514 47571 7ff610189d40 GetProcAddressForCaller 47522->47571 47524->47489 47524->47490 47524->47491 47524->47495 47524->47497 47524->47499 47524->47513 47524->47517 47528 7ff610189d40 GetProcAddressForCaller 47524->47528 47532 7ff6101882a0 GetProcAddressForCaller 47524->47532 47583 7ff61018a3e0 GetProcAddressForCaller 47524->47583 47526->47521 47531 7ff610170260 GetProcAddressForCaller 47526->47531 47527 7ff61016f519 47572 7ff6101882a0 GetProcAddressForCaller 47527->47572 47528->47524 47531->47526 47532->47524 47536 7ff61016f71b 47536->47452 47538->47536 47576 7ff610174ce0 GetProcAddressForCaller 47538->47576 47577 7ff6101778a0 GetProcAddressForCaller 47538->47577 47578 7ff6101882a0 GetProcAddressForCaller 47538->47578 47579 7ff610166660 GetProcAddressForCaller 47538->47579 47580 7ff6101706c0 GetProcAddressForCaller 47538->47580 47581 7ff610170260 GetProcAddressForCaller 47538->47581 47582 7ff610179820 GetProcAddressForCaller 47538->47582 47542->47447 47543->47454 47544->47455 47545->47447 47546->47478 47547->47480 47548->47483 47549->47460 47550->47463 47551->47464 47552->47471 47553->47466 47556 7ff61019f60a 47554->47556 47555 7ff6101882a0 GetProcAddressForCaller 47555->47556 47556->47554 47556->47555 47557 7ff61019f69d 47556->47557 47558 7ff61019f6c5 47557->47558 47584 7ff61019e560 47557->47584 47558->47503 47561->47505 47562->47520 47563->47494 47564->47498 47565->47502 47566->47506 47567->47510 47568->47514 47569->47516 47570->47522 47571->47527 47572->47520 47573->47520 47574->47520 47575->47538 47576->47538 47577->47538 47578->47538 47579->47538 47580->47538 47581->47538 47582->47538 47583->47524 47585 7ff61019e572 47584->47585 47585->47584 47586 7ff61019e594 47585->47586 47587 7ff6101882a0 GetProcAddressForCaller 47585->47587 47601 7ff61019d7e0 47586->47601 47587->47585 47589 7ff61019e63d 47590 7ff61019e6a7 47589->47590 47593 7ff61019e6d5 47589->47593 47616 7ff6101882a0 GetProcAddressForCaller 47589->47616 47617 7ff61019e3e0 GetProcAddressForCaller 47590->47617 47612 7ff6101a8e20 GetProcAddressForCaller 47593->47612 47596 7ff61019e810 47600 7ff61019e83d 47596->47600 47613 7ff61019dfa0 GetProcAddressForCaller 47596->47613 47614 7ff6101a9440 GetProcAddressForCaller 47596->47614 47599 7ff61019e866 47599->47503 47615 7ff61019daa0 GetProcAddressForCaller 47600->47615 47610 7ff61019d7ea 47601->47610 47602 7ff6101677c0 GetProcAddressForCaller 47602->47610 47603 7ff61015c020 GetProcAddressForCaller 47603->47610 47607 7ff61015c240 GetProcAddressForCaller 47607->47610 47608 7ff61019d871 47608->47589 47609 7ff610178960 GetProcAddressForCaller 47609->47610 47610->47601 47610->47602 47610->47603 47610->47607 47610->47608 47610->47609 47611 7ff6101882a0 GetProcAddressForCaller 47610->47611 47618 7ff61019d4a0 47610->47618 47626 7ff610179ca0 GetProcAddressForCaller 47610->47626 47627 7ff61019d160 47610->47627 47611->47610 47612->47596 47613->47596 47614->47596 47615->47599 47616->47590 47617->47593 47619 7ff61019d4aa 47618->47619 47619->47618 47637 7ff61015c020 GetProcAddressForCaller 47619->47637 47621 7ff61019d52c 47638 7ff61015c240 GetProcAddressForCaller 47621->47638 47622 7ff61019d160 GetProcAddressForCaller 47624 7ff61019d4e6 47622->47624 47624->47621 47624->47622 47625 7ff61019d546 47625->47610 47626->47610 47634 7ff61019d16a 47627->47634 47628 7ff61019d20a 47630 7ff61019d235 47628->47630 47639 7ff610179ca0 GetProcAddressForCaller 47628->47639 47629 7ff610178960 GetProcAddressForCaller 47629->47634 47630->47610 47633 7ff61019d1e9 47633->47628 47640 7ff6101882a0 GetProcAddressForCaller 47633->47640 47641 7ff610179e20 GetProcAddressForCaller 47633->47641 47634->47627 47634->47629 47634->47633 47635 7ff6101882a0 GetProcAddressForCaller 47634->47635 47635->47634 47637->47624 47638->47625 47639->47630 47640->47633 47641->47633 47642 7ff610183a20 47644 7ff610183a2a 47642->47644 47644->47642 47664 7ff610182d80 47644->47664 47653 7ff610183a76 47701 7ff610182ce0 47653->47701 47657 7ff610183a8a 47722 7ff610183520 47657->47722 47659 7ff610183a8f 47660 7ff6101853e0 GetProcAddressForCaller 47659->47660 47661 7ff610183ac5 47660->47661 47662 7ff610185460 GetProcAddressForCaller 47661->47662 47663 7ff610183b05 47662->47663 47668 7ff610182d8f 47664->47668 47665 7ff6101854e0 GetProcAddressForCaller 47665->47668 47666 7ff610182c20 GetProcAddressForCaller 47666->47668 47667 7ff6101882a0 GetProcAddressForCaller 47667->47668 47668->47664 47668->47665 47668->47666 47668->47667 47669 7ff6101832a5 47668->47669 47670 7ff610182c20 GetProcAddressForCaller 47669->47670 47671 7ff6101832e9 47670->47671 47672 7ff6101832f8 47671->47672 47730 7ff610183ca0 GetProcAddressForCaller 47671->47730 47674 7ff61019b880 47672->47674 47675 7ff61019b88a 47674->47675 47675->47674 47676 7ff6101853a0 GetProcAddressForCaller 47675->47676 47677 7ff61019b89e 47676->47677 47678 7ff6101853e0 GetProcAddressForCaller 47677->47678 47679 7ff61019b8b9 47678->47679 47680 7ff610185460 GetProcAddressForCaller 47679->47680 47681 7ff61019b8f7 47680->47681 47682 7ff6101853e0 GetProcAddressForCaller 47681->47682 47683 7ff610183a65 47682->47683 47684 7ff61019b9c0 47683->47684 47685 7ff61019b9ca 47684->47685 47685->47684 47686 7ff610185460 GetProcAddressForCaller 47685->47686 47687 7ff61019b9f7 47686->47687 47688 7ff61019ba7e 47687->47688 47689 7ff61019ba15 47687->47689 47690 7ff6101853e0 GetProcAddressForCaller 47688->47690 47691 7ff610185460 GetProcAddressForCaller 47689->47691 47692 7ff610183a6a 47690->47692 47693 7ff61019ba33 47691->47693 47695 7ff6101836e0 47692->47695 47694 7ff610185460 GetProcAddressForCaller 47693->47694 47694->47692 47696 7ff6101836ea 47695->47696 47696->47695 47697 7ff610185560 GetProcAddressForCaller 47696->47697 47698 7ff61018371b 47697->47698 47699 7ff610183753 47698->47699 47700 7ff6101853e0 GetProcAddressForCaller 47698->47700 47729 7ff610183620 GetProcAddressForCaller 47699->47729 47700->47699 47703 7ff610182cea 47701->47703 47702 7ff610185460 GetProcAddressForCaller 47702->47703 47703->47701 47703->47702 47704 7ff610182d3b 47703->47704 47731 7ff6101882a0 GetProcAddressForCaller 47703->47731 47706 7ff610183780 47704->47706 47713 7ff61018378a 47706->47713 47707 7ff6101854e0 GetProcAddressForCaller 47707->47713 47708 7ff61018387b 47708->47657 47709 7ff6101853a0 GetProcAddressForCaller 47709->47713 47710 7ff610183f60 GetProcAddressForCaller 47710->47713 47711 7ff610183925 47712 7ff6101856e0 GetProcAddressForCaller 47711->47712 47715 7ff61018395f 47712->47715 47713->47706 47713->47707 47713->47708 47713->47709 47713->47710 47713->47711 47714 7ff6101839bb 47714->47657 47715->47714 47732 7ff610189ce0 GetProcAddressForCaller 47715->47732 47717 7ff61018399f 47733 7ff61018a560 GetProcAddressForCaller 47717->47733 47719 7ff6101839b0 47734 7ff610189d40 GetProcAddressForCaller 47719->47734 47721 7ff6101839b5 47721->47657 47723 7ff61018352a 47722->47723 47723->47722 47724 7ff6101854e0 GetProcAddressForCaller 47723->47724 47726 7ff610183571 47724->47726 47725 7ff6101853e0 GetProcAddressForCaller 47727 7ff6101835bd 47725->47727 47726->47725 47728 7ff61018360b 47726->47728 47727->47659 47728->47659 47729->47653 47730->47672 47731->47703 47732->47717 47733->47719 47734->47721

        Executed Functions

        Control-flow Graph

        • Executed
        • Not Executed
        control_flow_graph 0 7ff610182d80-7ff610182d89 1 7ff61018337b-7ff610183385 call 7ff6101b6480 0->1 2 7ff610182d8f-7ff610182de3 call 7ff6101854e0 0->2 1->0 7 7ff610183369-7ff61018337a call 7ff6101882a0 2->7 8 7ff610182de9-7ff610182e52 call 7ff610182c20 2->8 7->1 13 7ff610182e67-7ff610182eb7 call 7ff6101854e0 8->13 14 7ff610182e54-7ff610182e63 call 7ff6101b83c0 8->14 19 7ff610182ebd-7ff610182f03 call 7ff610182c20 13->19 20 7ff610183358-7ff610183364 call 7ff6101882a0 13->20 14->13 23 7ff610182f08-7ff610182f0f 19->23 20->7 24 7ff610182f24-7ff610182f74 call 7ff6101854e0 23->24 25 7ff610182f11-7ff610182f20 call 7ff6101b83c0 23->25 30 7ff610182f7a-7ff610182fd1 call 7ff610182c20 24->30 31 7ff610183347-7ff610183353 call 7ff6101882a0 24->31 25->24 35 7ff610182fe6-7ff610183038 call 7ff610182c20 30->35 36 7ff610182fd3-7ff610182fe2 call 7ff6101b83c0 30->36 31->20 41 7ff61018304d-7ff6101830ac call 7ff610182c20 35->41 42 7ff61018303a-7ff610183049 call 7ff6101b83c0 35->42 36->35 47 7ff6101830c1-7ff6101830f2 call 7ff6101854e0 41->47 48 7ff6101830ae-7ff6101830bd call 7ff6101b83c0 41->48 42->41 52 7ff6101830f7-7ff610183111 47->52 48->47 53 7ff610183117-7ff610183153 call 7ff610182c20 52->53 54 7ff610183336-7ff610183342 call 7ff6101882a0 52->54 58 7ff610183168-7ff6101831ac call 7ff610182c20 53->58 59 7ff610183155-7ff610183164 call 7ff6101b83c0 53->59 54->31 64 7ff6101831c1-7ff6101831d0 58->64 65 7ff6101831ae-7ff6101831bd call 7ff6101b83c0 58->65 59->58 67 7ff6101831d6-7ff6101831d9 64->67 68 7ff610183325-7ff610183331 call 7ff6101882a0 64->68 65->64 67->68 70 7ff6101831df-7ff610183209 call 7ff6101854e0 67->70 68->54 73 7ff61018320e-7ff610183228 70->73 74 7ff610183312-7ff610183320 call 7ff6101882a0 73->74 75 7ff61018322e-7ff610183280 call 7ff610182c20 73->75 74->68 79 7ff610183295-7ff6101832a3 75->79 80 7ff610183282-7ff610183291 call 7ff6101b83c0 75->80 81 7ff6101832a5-7ff6101832ec call 7ff610182c20 79->81 82 7ff610183301-7ff61018330d call 7ff6101882a0 79->82 80->79 88 7ff6101832f8-7ff610183300 81->88 89 7ff6101832ee-7ff6101832f3 call 7ff610183ca0 81->89 82->74 89->88
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: AddVecto$Continue$ForSingl$Handler$NtWaitFo$Numbers$RtlGetCu$RtlGetNt$SystemFu$WSAGetOv$WSAGetOverlappedResult not found_cgo_pthread_key_created missingruntime: sudog with non-nil elemruntime: sudog with non-nil nextruntime: sudog with non-nil prevruntime: mcall function returnedruntime: newstack called from g=runtime: stack split at bad timepani$advapi32.dll$advapi32.dll not foundduplicated defer entryruntime.main not on m0set_crosscall2 missingbad g->status in readywirep: invalid p stateassembly checks failedstack not a power of 2minpc or maxpc invalidcompileCallback: type trace: alloc too largenon-Go function at$dPeriod$dResult$eObject$ine_get_$kernel32.dll$kernel32.dll not foundadvapi32.dll not foundduplicated defer entryruntime.main not on m0set_crosscall2 missingbad g->status in readywirep: invalid p stateassembly checks failedstack not a power of 2minpc or maxpc invalidcompileCallback: type trace: alloc too l$nPeriod$ntdll.dll$redConti$rentPeb$stemFunc$tVersion$timeBegi$timeBegin/EndPeriod not foundruntime: sudog with non-nil cgfput: bad status (not Gdead)LockOSThread nesting overflowsemacquire not on the G stackruntime: split stack overflowstring concatenation too longinvalid function symbol tableinvalid length of trace even$timeEndP$tion036$tlGetCur$verlappe$version$wine_get$winmm.dll$ws2_32.dll$ws2_32.dll not foundpreempt off reason: forcegc: phase errorgopark: bad g statusgo of nil func valuewirep: already in goselectgo: bad wakeupsemaRoot rotateRightreflect.makeFuncStubdodeltimer0: wrong Ptrace: out of memoryinvalid DNS responsegetadaptersaddresses
        • API String ID: 0-3745677394
        • Opcode ID: 25c362c981f24d6373064dd0b0538ff56f392f2b7730cde17db3a481f0dbb32d
        • Instruction ID: 24ebd1b7a1b514a91b0efdc3d26824f1c792b840a22bab5082a7f7c93cb0549c
        • Opcode Fuzzy Hash: 25c362c981f24d6373064dd0b0538ff56f392f2b7730cde17db3a481f0dbb32d
        • Instruction Fuzzy Hash: 56E1F571A0DF8295EB50CB41F8453AA73A9FB49BA0F04813ADA8C877A9EF7CD151D700
        Strings
        • sweep increased allocation countremovespecial on invalid pointerruntime: root level max pages = WSAGetOverlappedResult not found_cgo_pthread_key_created missingruntime: sudog with non-nil elemruntime: sudog with non-nil nextruntime: sudog with non-nil prevrunt, xrefs: 00007FF610176579
        • mspan.sweep: m is not lockedfound pointer to free objectmheap.freeSpanLocked - span runtime.semasleep unexpectedfatal: morestack on gsignalruntime: casgstatus: oldval=gcstopm: negative nmspinningfindrunnable: netpoll with psave on system g not allowednewproc1, xrefs: 00007FF61017689B
        • swept cached spanmarkBits overflowruntime: summary[runtime: level = , p.searchAddr = runtime.newosprocruntime/internal/thread exhaustionlocked m0 woke upentersyscallblock spinningthreads=gp.waiting != nilunknown caller pcstack: frame={sp:runtime: nameOff runti, xrefs: 00007FF610176437
        • mspan.sweep: bad span stateinvalid profile bucket typeruntime: corrupted polldescruntime: netpollinit failedcould not find QPC syscallsruntime: asyncPreemptStack=runtime: thread ID overflowstopTheWorld: holding locksgcstopm: not waiting for gcinternal lockOSTh, xrefs: 00007FF61017688A
        • nalloc= nfreed=[signal newval= mcount= bytes, stack=[ minLC= maxpc= stack=[ minutes etypes [::1]:53continue_gatewayshutdowninvalid address readfromwsaioctlunixgram2.5.4.102.5.4.112.5.4.17no anodeCancelIoReadFileAcceptExWSAIoctlArmenianBalineseBopomofoBugi, xrefs: 00007FF610176512
        • previous allocCount=, levelBits[level] = runtime: searchIdx = defer on system stackpanic on system stackasync stack too largestartm: m is spinningstartlockedm: m has pfindrunnable: wrong ppreempt at unknown pcreleasep: invalid argcheckdead: runnable gruntime:, xrefs: 00007FF61017652F
        • `r/, xrefs: 00007FF61017618A, 00007FF61017639B
        • mheap.sweepgen=runtime: nelems=workbuf is emptymSpanList.removemSpanList.insertbad special kindbad summary dataruntime: addr = runtime: base = runtime: head = already; errno=runtime stack:invalid g statuscastogscanstatusbad g transitionschedule: in cgorefl, xrefs: 00007FF610176493, 00007FF610176865
        • sweep: tried to preserve a user arena spanruntime: blocked write on closing polldescacquireSudog: found s.elem != nil in cachefatal error: cgo callback before cgo callon a locked thread with no template threadunexpected signal during runtime executionsync/ato, xrefs: 00007FF610176426
        • sweepgen= sweepgen , bound = , limit = tracefree(tracegc()exitThreadBad varintGC forced runqueue= stopwait= runqsize= gfreecnt= throwing= spinning=atomicand8float64nanfloat32nanException ptrSize= targetpc= until pc=unknown pcruntime: ggoroutine /etc/hosts, xrefs: 00007FF610176478, 00007FF610176845
        • mspan.sweep: bad span state after sweepruntime: blocked write on free polldescsuspendG from non-preemptible goroutineruntime: casfrom_Gscanstatus failed gp=stack growth not allowed in system calltraceback: unexpected SPWRITE function cipher: incorrect tag size, xrefs: 00007FF6101764B8
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: mheap.sweepgen=runtime: nelems=workbuf is emptymSpanList.removemSpanList.insertbad special kindbad summary dataruntime: addr = runtime: base = runtime: head = already; errno=runtime stack:invalid g statuscastogscanstatusbad g transitionschedule: in cgorefl$ nalloc= nfreed=[signal newval= mcount= bytes, stack=[ minLC= maxpc= stack=[ minutes etypes [::1]:53continue_gatewayshutdowninvalid address readfromwsaioctlunixgram2.5.4.102.5.4.112.5.4.17no anodeCancelIoReadFileAcceptExWSAIoctlArmenianBalineseBopomofoBugi$ previous allocCount=, levelBits[level] = runtime: searchIdx = defer on system stackpanic on system stackasync stack too largestartm: m is spinningstartlockedm: m has pfindrunnable: wrong ppreempt at unknown pcreleasep: invalid argcheckdead: runnable gruntime:$ sweepgen= sweepgen , bound = , limit = tracefree(tracegc()exitThreadBad varintGC forced runqueue= stopwait= runqsize= gfreecnt= throwing= spinning=atomicand8float64nanfloat32nanException ptrSize= targetpc= until pc=unknown pcruntime: ggoroutine /etc/hosts$`r/$mspan.sweep: bad span state after sweepruntime: blocked write on free polldescsuspendG from non-preemptible goroutineruntime: casfrom_Gscanstatus failed gp=stack growth not allowed in system calltraceback: unexpected SPWRITE function cipher: incorrect tag size$mspan.sweep: bad span stateinvalid profile bucket typeruntime: corrupted polldescruntime: netpollinit failedcould not find QPC syscallsruntime: asyncPreemptStack=runtime: thread ID overflowstopTheWorld: holding locksgcstopm: not waiting for gcinternal lockOSTh$mspan.sweep: m is not lockedfound pointer to free objectmheap.freeSpanLocked - span runtime.semasleep unexpectedfatal: morestack on gsignalruntime: casgstatus: oldval=gcstopm: negative nmspinningfindrunnable: netpoll with psave on system g not allowednewproc1$sweep increased allocation countremovespecial on invalid pointerruntime: root level max pages = WSAGetOverlappedResult not found_cgo_pthread_key_created missingruntime: sudog with non-nil elemruntime: sudog with non-nil nextruntime: sudog with non-nil prevrunt$sweep: tried to preserve a user arena spanruntime: blocked write on closing polldescacquireSudog: found s.elem != nil in cachefatal error: cgo callback before cgo callon a locked thread with no template threadunexpected signal during runtime executionsync/ato$swept cached spanmarkBits overflowruntime: summary[runtime: level = , p.searchAddr = runtime.newosprocruntime/internal/thread exhaustionlocked m0 woke upentersyscallblock spinningthreads=gp.waiting != nilunknown caller pcstack: frame={sp:runtime: nameOff runti
        • API String ID: 0-1627491132
        • Opcode ID: 30ba0aaa65ac61afef1677808690317791d309c8e270f8130642784ff5ae1281
        • Instruction ID: 6bdfcc96d02753beb0a7524a1da6ce04872d60c4f45cb1bc53ec2530304f910c
        • Opcode Fuzzy Hash: 30ba0aaa65ac61afef1677808690317791d309c8e270f8130642784ff5ae1281
        • Instruction Fuzzy Hash: 00829032A0CE8696EB608B51E4413BA77A5FB89FA4F448536EA8D83795CF3CE554C700

        Control-flow Graph

        • Executed
        • Not Executed
        control_flow_graph 334 7ff61015cc20-7ff61015cc29 335 7ff61015cc2f-7ff61015cc72 334->335 336 7ff61015d390-7ff61015d3c0 call 7ff6101b6480 334->336 337 7ff61015cc7b-7ff61015cc99 call 7ff61015e7a0 335->337 338 7ff61015cc74-7ff61015cc76 335->338 336->334 348 7ff61015cc9b-7ff61015ccc0 337->348 349 7ff61015ccc5 337->349 340 7ff61015d047-7ff61015d04d 338->340 343 7ff61015d16c-7ff61015d17e 340->343 344 7ff61015d053-7ff61015d074 340->344 350 7ff61015d180-7ff61015d183 343->350 346 7ff61015d076-7ff61015d083 344->346 347 7ff61015d085-7ff61015d0a7 344->347 353 7ff61015d0fe-7ff61015d104 346->353 354 7ff61015d0a9-7ff61015d0ac 347->354 355 7ff61015d0ae-7ff61015d0c0 call 7ff610167dc0 347->355 348->340 356 7ff61015ccca-7ff61015cd2e 349->356 351 7ff61015d247-7ff61015d251 350->351 352 7ff61015d189-7ff61015d1a3 call 7ff61015d3e0 350->352 359 7ff61015d26c-7ff61015d287 351->359 360 7ff61015d253-7ff61015d26a 351->360 375 7ff61015d1a9-7ff61015d23d call 7ff61016a600 * 2 352->375 376 7ff61015d2e5-7ff61015d2f1 352->376 361 7ff61015d106-7ff61015d109 353->361 362 7ff61015d158-7ff61015d16a 353->362 354->353 365 7ff61015d0c5-7ff61015d0f6 355->365 371 7ff61015cfa5-7ff61015cfb0 356->371 372 7ff61015cd34-7ff61015cd44 356->372 369 7ff61015d289-7ff61015d296 359->369 370 7ff61015d298-7ff61015d2c4 359->370 366 7ff61015d2c8-7ff61015d2cb 360->366 367 7ff61015d016-7ff61015d044 361->367 368 7ff61015d10f-7ff61015d153 call 7ff610167ce0 361->368 362->350 365->353 378 7ff61015d2cd-7ff61015d2d4 366->378 379 7ff61015d305-7ff61015d38f call 7ff610189ce0 call 7ff61018a560 call 7ff61018a3e0 call 7ff61018a560 call 7ff61018a3e0 call 7ff61018a560 * 2 call 7ff610189f20 call 7ff610189d40 call 7ff6101882a0 366->379 367->340 368->367 369->366 370->366 373 7ff61015cd4a-7ff61015cd65 372->373 374 7ff61015d009-7ff61015d011 call 7ff6101b8780 372->374 380 7ff61015ce0b-7ff61015ce23 373->380 381 7ff61015cd6b-7ff61015cda3 call 7ff610185560 373->381 374->367 375->351 386 7ff61015d2d6-7ff61015d2e0 378->386 387 7ff61015d2f2-7ff61015d300 call 7ff6101882a0 378->387 379->336 392 7ff61015cfe7-7ff61015cff3 call 7ff6101882a0 380->392 393 7ff61015ce29-7ff61015ce51 call 7ff61015e7a0 380->393 394 7ff61015cda8-7ff61015cdc3 381->394 386->356 387->379 400 7ff61015cff8-7ff61015d004 call 7ff6101882a0 392->400 408 7ff61015ce53-7ff61015ce64 call 7ff61015e3e0 393->408 409 7ff61015ce72-7ff61015ce83 393->409 399 7ff61015cdc9-7ff61015cdd8 394->399 394->400 404 7ff61015cdda-7ff61015cddb 399->404 405 7ff61015cddd 399->405 400->374 412 7ff61015cdde-7ff61015ce01 404->412 405->412 418 7ff61015ce69-7ff61015ce6c 408->418 410 7ff61015ce89-7ff61015cea7 409->410 411 7ff61015cf8e-7ff61015cf9b 409->411 415 7ff61015cead-7ff61015ceb9 410->415 416 7ff61015cf56-7ff61015cf6b 410->416 411->371 412->380 419 7ff61015cebb 415->419 420 7ff61015cec2-7ff61015cee3 call 7ff61015e3e0 415->420 422 7ff61015cf6d-7ff61015cf77 416->422 423 7ff61015cfbc-7ff61015cfc0 call 7ff6101b87e0 416->423 418->409 424 7ff61015cfd6-7ff61015cfe2 call 7ff6101882a0 418->424 419->420 433 7ff61015cfc5-7ff61015cfd1 call 7ff6101882a0 420->433 435 7ff61015cee9-7ff61015cf2e 420->435 429 7ff61015cf79-7ff61015cf89 422->429 430 7ff61015cfb1-7ff61015cfb7 call 7ff6101b8760 422->430 423->433 424->392 430->423 433->424 438 7ff61015cf41-7ff61015cf4e 435->438 439 7ff61015cf30-7ff61015cf39 call 7ff6101b9160 435->439 438->416 439->438
        Strings
        • out of memory allocating heap arena metadata/cpu/classes/scavenge/background:cpu-secondsruntime: unexpected metric registration for gcmarknewobject called while doing checkmarkactive sweepers found at start of mark phaseno P available, write barriers are forbi, xrefs: 00007FF61015CFD6
        • , xrefs: 00007FF61015D2AD
        • arena already initialized to unused region of span bytes failed with errno=runtime: VirtualAlloc of /sched/gomaxprocs:threadsremaining pointer buffersslice bounds out of range_cgo_thread_start missingallgadd: bad status Gidleruntime: program exceeds startm: p , xrefs: 00007FF61015CFE7
        • out of memory allocating allArenas/memory/classes/heap/objects:bytesruntime.SetFinalizer: cannot pass too many pages allocated in chunk?mspan.ensureSwept: m is not lockedVirtualQuery for stack base failedforEachP: sched.safePointWait != 0schedule: spinning wit, xrefs: 00007FF61015CFC5
        • out of memory allocating heap arena map/cpu/classes/gc/mark/assist:cpu-seconds/cpu/classes/scavenge/total:cpu-seconds/memory/classes/profiling/buckets:bytesmspan.sweep: bad span state after sweepruntime: blocked write on free polldescsuspendG from non-preempti, xrefs: 00007FF61015CFF8
        • end outside usable address spaceruntime: failed to release pagesruntime: fixalloc size too largeinvalid limiter event type foundscanstack: goroutine not stoppedscavenger state is already wiredsweep increased allocation countremovespecial on invalid pointerrunt, xrefs: 00007FF61015D2BD
        • region exceeds uintptr rangeneed padding in bucket (key)/gc/heap/frees-by-size:bytes/gc/heap/tiny/allocs:objects/sched/goroutines:goroutinesgcBgMarkWorker: mode not setmspan.sweep: m is not lockedfound pointer to free objectmheap.freeSpanLocked - span runtime., xrefs: 00007FF61015D263
        • ) not in usable address space: runtime: cannot allocate memorycheckmark found unmarked objectruntime: failed to commit pages/memory/classes/heap/free:bytes/memory/classes/os-stacks:bytespacer: sweep done at heap size non in-use span in unswept listcasgstatus: , xrefs: 00007FF61015D354
        • memory reservation exceeds address space limittried to park scavenger from another goroutinereleased less than one physical page of memory (bad use of unsafe.Pointer? try -d=checkptr)sysGrow bounds not aligned to pallocChunkBytesruntime: failed to create new , xrefs: 00007FF61015D37E
        • base outside usable address spaceruntime: memory allocated by OS [misrounded allocation in sysAllocconcurrent map read and map writeruntime: failed to decommit pages/cpu/classes/gc/pause:cpu-seconds/cpu/classes/gc/total:cpu-seconds/gc/limiter/last-enabled:gc-c, xrefs: 00007FF61015D28F
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: $) not in usable address space: runtime: cannot allocate memorycheckmark found unmarked objectruntime: failed to commit pages/memory/classes/heap/free:bytes/memory/classes/os-stacks:bytespacer: sweep done at heap size non in-use span in unswept listcasgstatus: $arena already initialized to unused region of span bytes failed with errno=runtime: VirtualAlloc of /sched/gomaxprocs:threadsremaining pointer buffersslice bounds out of range_cgo_thread_start missingallgadd: bad status Gidleruntime: program exceeds startm: p $base outside usable address spaceruntime: memory allocated by OS [misrounded allocation in sysAllocconcurrent map read and map writeruntime: failed to decommit pages/cpu/classes/gc/pause:cpu-seconds/cpu/classes/gc/total:cpu-seconds/gc/limiter/last-enabled:gc-c$end outside usable address spaceruntime: failed to release pagesruntime: fixalloc size too largeinvalid limiter event type foundscanstack: goroutine not stoppedscavenger state is already wiredsweep increased allocation countremovespecial on invalid pointerrunt$memory reservation exceeds address space limittried to park scavenger from another goroutinereleased less than one physical page of memory (bad use of unsafe.Pointer? try -d=checkptr)sysGrow bounds not aligned to pallocChunkBytesruntime: failed to create new $out of memory allocating allArenas/memory/classes/heap/objects:bytesruntime.SetFinalizer: cannot pass too many pages allocated in chunk?mspan.ensureSwept: m is not lockedVirtualQuery for stack base failedforEachP: sched.safePointWait != 0schedule: spinning wit$out of memory allocating heap arena map/cpu/classes/gc/mark/assist:cpu-seconds/cpu/classes/scavenge/total:cpu-seconds/memory/classes/profiling/buckets:bytesmspan.sweep: bad span state after sweepruntime: blocked write on free polldescsuspendG from non-preempti$out of memory allocating heap arena metadata/cpu/classes/scavenge/background:cpu-secondsruntime: unexpected metric registration for gcmarknewobject called while doing checkmarkactive sweepers found at start of mark phaseno P available, write barriers are forbi$region exceeds uintptr rangeneed padding in bucket (key)/gc/heap/frees-by-size:bytes/gc/heap/tiny/allocs:objects/sched/goroutines:goroutinesgcBgMarkWorker: mode not setmspan.sweep: m is not lockedfound pointer to free objectmheap.freeSpanLocked - span runtime.
        • API String ID: 0-1376041300
        • Opcode ID: ec11399766b57ebe5fb6afea625e3d63a2098c03ff5d49b9463fe5fc196a9834
        • Instruction ID: b5eb26ef8904309d56a8b1335dbfbc12a3612b6a178dcbc6ccc666b17b0b02cf
        • Opcode Fuzzy Hash: ec11399766b57ebe5fb6afea625e3d63a2098c03ff5d49b9463fe5fc196a9834
        • Instruction Fuzzy Hash: 73029F36A0CF8596EE609F91E4413AAA765FB86FA0F448232EE9D87795CF3CD141C740
        Strings
        • mallocgc called without a P or outside bootstrappingruntime.SetFinalizer: pointer not in allocated blockruntime: use of FixAlloc_Alloc before FixAlloc_Initspan set block with unpopped elements found in resetruntime: GetQueuedCompletionStatusEx failed (errno= , xrefs: 00007FF61015DF8C
        • !"#$%%&&''((()))*++,,,,,------....//////0001123333333333444444444455666677777888888888889999999999::::::;;;;;;;;;;;;;;;;<<<<<<<<<<<<<<<<=====>>>>>>>>>>>??????????@@@@@@@@@@@@@@@@@@@@@@AAAAAAAAAAAAAAAAAAAAABBBBBBBBBBBCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC, xrefs: 00007FF61015DB0D
        • malloc deadlockruntime error: elem size wrong with GC progscan missed a gmisaligned maskruntime: min = runtime: inUse=runtime: max = recovery failedstopm holding pstartm: m has ppreempt SPWRITEmissing mcache?ms: gomaxprocs=]morebuf={pc:: no frame (sp=runti, xrefs: 00007FF61015DFAE
        • malloc during signalclose of nil channelinconsistent lockedmnotetsleep not on g0bad system page size to unallocated span/gc/scan/stack:bytes/gc/scan/total:bytes/gc/heap/frees:bytes/gc/gomemlimit:bytesp mcache not flushed markroot jobs donepacer: assist ratio=, xrefs: 00007FF61015DF9D
        • delayed zeroing on data that may contain pointersruntime.reflect_makemap: unsupported map key typesweeper left outstanding across sweep generationsfully empty unfreed span set block found in resetcasgstatus: waiting for Gwaiting but is Grunnablechacha20poly130, xrefs: 00007FF61015DF47
        • mallocgc called with gcphase == _GCmarkterminationrecursive call during initialization - linker skewattempt to execute system stack code on user stackcompileCallback: function argument frame too largecrypto/cipher: incorrect nonce length given to GCMchacha20: , xrefs: 00007FF61015DFBF
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: !"#$%%&&''((()))*++,,,,,------....//////0001123333333333444444444455666677777888888888889999999999::::::;;;;;;;;;;;;;;;;<<<<<<<<<<<<<<<<=====>>>>>>>>>>>??????????@@@@@@@@@@@@@@@@@@@@@@AAAAAAAAAAAAAAAAAAAAABBBBBBBBBBBCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC$delayed zeroing on data that may contain pointersruntime.reflect_makemap: unsupported map key typesweeper left outstanding across sweep generationsfully empty unfreed span set block found in resetcasgstatus: waiting for Gwaiting but is Grunnablechacha20poly130$malloc deadlockruntime error: elem size wrong with GC progscan missed a gmisaligned maskruntime: min = runtime: inUse=runtime: max = recovery failedstopm holding pstartm: m has ppreempt SPWRITEmissing mcache?ms: gomaxprocs=]morebuf={pc:: no frame (sp=runti$malloc during signalclose of nil channelinconsistent lockedmnotetsleep not on g0bad system page size to unallocated span/gc/scan/stack:bytes/gc/scan/total:bytes/gc/heap/frees:bytes/gc/gomemlimit:bytesp mcache not flushed markroot jobs donepacer: assist ratio=$mallocgc called with gcphase == _GCmarkterminationrecursive call during initialization - linker skewattempt to execute system stack code on user stackcompileCallback: function argument frame too largecrypto/cipher: incorrect nonce length given to GCMchacha20: $mallocgc called without a P or outside bootstrappingruntime.SetFinalizer: pointer not in allocated blockruntime: use of FixAlloc_Alloc before FixAlloc_Initspan set block with unpopped elements found in resetruntime: GetQueuedCompletionStatusEx failed (errno=
        • API String ID: 0-422566602
        • Opcode ID: e449710473363f20e587bf4b9915df02a7e8baeab371d7711497224fe303168c
        • Instruction ID: 6ed38bd7c37a2acb3618ee0574fcca35a6e3831c3be362398ac7c78dc15441e0
        • Opcode Fuzzy Hash: e449710473363f20e587bf4b9915df02a7e8baeab371d7711497224fe303168c
        • Instruction Fuzzy Hash: 7632B066A0CE8291FF609B95E4417BA6765FB46FA4F844132EE8D8B795CF3CD482C700

        Control-flow Graph

        • Executed
        • Not Executed
        control_flow_graph 1118 7ff610188fc0-7ff610188fc4 1119 7ff610188fca-7ff610188fe3 1118->1119 1120 7ff6101894fc-7ff61018950b call 7ff6101bd060 1118->1120 1121 7ff610188ff5-7ff610189050 1119->1121 1122 7ff610188fe5-7ff610188fef 1119->1122 1120->1118 1127 7ff610189056-7ff610189064 1121->1127 1128 7ff610189208-7ff61018920c 1121->1128 1122->1121 1125 7ff6101894ea-7ff6101894fb call 7ff6101882a0 1122->1125 1125->1120 1130 7ff61018906a-7ff61018906e 1127->1130 1131 7ff61018927d-7ff610189293 call 7ff61018cb00 1127->1131 1132 7ff610189212-7ff610189216 1128->1132 1133 7ff6101893bd-7ff6101893cb 1128->1133 1136 7ff610189200-7ff610189204 1130->1136 1137 7ff610189074-7ff61018907b 1130->1137 1148 7ff61018938f-7ff6101893bc 1131->1148 1149 7ff610189299-7ff6101892b6 1131->1149 1138 7ff6101892bb-7ff6101892d0 1132->1138 1139 7ff61018921c-7ff610189224 1132->1139 1141 7ff610189226-7ff61018922b 1136->1141 1142 7ff610189206 1136->1142 1145 7ff6101890b5-7ff6101890b8 1137->1145 1146 7ff61018907d-7ff610189084 1137->1146 1143 7ff6101892d2-7ff6101892ed call 7ff6101ba000 1138->1143 1144 7ff6101892f4-7ff610189319 call 7ff6101ba000 1138->1144 1139->1141 1147 7ff610189236-7ff610189247 call 7ff61018d0a0 1139->1147 1141->1138 1154 7ff610189231-7ff6101894e5 call 7ff610189ce0 call 7ff61018a560 call 7ff61018a4e0 call 7ff61018a560 call 7ff61018a2a0 call 7ff61018a560 call 7ff61018a2a0 call 7ff610189f20 call 7ff610189d40 call 7ff610189ce0 call 7ff61018a560 call 7ff61018a4e0 call 7ff61018a560 call 7ff61018a2a0 call 7ff61018a560 call 7ff61018a2a0 call 7ff610189f20 call 7ff610189d40 call 7ff6101882a0 1141->1154 1142->1131 1143->1144 1168 7ff610189345-7ff610189383 call 7ff6101b6340 call 7ff6101ba000 1144->1168 1169 7ff61018931b-7ff610189340 call 7ff6101b7f00 1144->1169 1156 7ff6101890c0-7ff6101890c3 1145->1156 1151 7ff6101890b0-7ff6101890b3 1146->1151 1152 7ff610189086-7ff61018908e 1146->1152 1170 7ff610189249-7ff61018926b 1147->1170 1171 7ff61018926d-7ff610189278 1147->1171 1149->1138 1151->1156 1158 7ff610189090-7ff610189094 1152->1158 1159 7ff6101890ab-7ff6101890ae 1152->1159 1154->1125 1156->1138 1163 7ff6101890c9-7ff6101890e2 call 7ff61018cb00 1156->1163 1166 7ff6101890a6-7ff6101890a9 1158->1166 1167 7ff610189096-7ff6101890a4 1158->1167 1159->1156 1176 7ff6101891d3-7ff6101891f5 1163->1176 1177 7ff6101890e8-7ff610189123 1163->1177 1166->1156 1167->1156 1168->1148 1170->1138 1171->1131 1176->1138 1182 7ff610189125-7ff61018912a 1177->1182 1183 7ff61018912c-7ff610189132 1177->1183 1186 7ff610189136-7ff610189151 call 7ff61018c740 1182->1186 1183->1186 1192 7ff610189153-7ff61018915a 1186->1192 1193 7ff6101891a9 1186->1193 1196 7ff610189163-7ff610189187 call 7ff6101ba000 1192->1196 1197 7ff61018915c-7ff610189161 1192->1197 1195 7ff6101891ae-7ff6101891ce 1193->1195 1195->1138 1196->1195 1204 7ff610189189-7ff610189193 call 7ff610185920 1196->1204 1197->1195 1208 7ff610189198-7ff6101891a7 1204->1208 1208->1195
        Strings
        • , goid= s=nil (scan MB in pacer: % CPU ( zombie, j0 = head = panic: nmsys= locks= dying= allocs m->g0= pad1= pad2= text= minpc= value= (scan)types : type nil keywsarecvwsasendconnectlookup 2.5.4.62.5.4.32.5.4.52.5.4.72.5.4.82.5.4.9abortedCopySidWSARecvW, xrefs: 00007FF61018940F, 00007FF610189497
        • runtime: gp: gp=runtime: getg: g=forEachP: not done in async preemptbad manualFreeListruntime: textAddr cleantimers: bad p frames elided..., locked to threadruntime.semacreateruntime.semawakeupcontext.Backgroundserver misbehavinginvalid IP address/etc/nss, xrefs: 00007FF6101893F1
        • invalid g statuscastogscanstatusbad g transitionschedule: in cgoreflect mismatch untyped locals missing stackmapbad symbol tablenon-Go function not in ranges:GODEBUG: value "context canceled.WithValue(type hostLookupOrder=/etc/resolv.confnon-IPv4 addressnon-, xrefs: 00007FF6101894D9
        • suspendG from non-preemptible goroutineruntime: casfrom_Gscanstatus failed gp=stack growth not allowed in system calltraceback: unexpected SPWRITE function cipher: incorrect tag size given to GCMgo package net: using cgo DNS resolvertags don't match (%d vs %+, xrefs: 00007FF6101894EA
        • , gp->atomicstatus=marking free object KiB work (eager), [controller reset]mspan.sweep: state=sysMemStat overflowbad sequence numberntdll.dll not foundwinmm.dll not foundruntime: g0 stack [missing deferreturnpanic during mallocpanic holding lockspanic during , xrefs: 00007FF61018942F
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: , goid= s=nil (scan MB in pacer: % CPU ( zombie, j0 = head = panic: nmsys= locks= dying= allocs m->g0= pad1= pad2= text= minpc= value= (scan)types : type nil keywsarecvwsasendconnectlookup 2.5.4.62.5.4.32.5.4.52.5.4.72.5.4.82.5.4.9abortedCopySidWSARecvW$, gp->atomicstatus=marking free object KiB work (eager), [controller reset]mspan.sweep: state=sysMemStat overflowbad sequence numberntdll.dll not foundwinmm.dll not foundruntime: g0 stack [missing deferreturnpanic during mallocpanic holding lockspanic during $invalid g statuscastogscanstatusbad g transitionschedule: in cgoreflect mismatch untyped locals missing stackmapbad symbol tablenon-Go function not in ranges:GODEBUG: value "context canceled.WithValue(type hostLookupOrder=/etc/resolv.confnon-IPv4 addressnon-$runtime: gp: gp=runtime: getg: g=forEachP: not done in async preemptbad manualFreeListruntime: textAddr cleantimers: bad p frames elided..., locked to threadruntime.semacreateruntime.semawakeupcontext.Backgroundserver misbehavinginvalid IP address/etc/nss$suspendG from non-preemptible goroutineruntime: casfrom_Gscanstatus failed gp=stack growth not allowed in system calltraceback: unexpected SPWRITE function cipher: incorrect tag size given to GCMgo package net: using cgo DNS resolvertags don't match (%d vs %+
        • API String ID: 0-1517158637
        • Opcode ID: 1d2a5417bad405a48e8d7e9bbc17bbd897f9759ad74d9b57a47e61b6ea87bf1c
        • Instruction ID: 4574cc0086905b7c0f34cfeb67499b1602d1b7bb824e35d6d9926624abe6bb5c
        • Opcode Fuzzy Hash: 1d2a5417bad405a48e8d7e9bbc17bbd897f9759ad74d9b57a47e61b6ea87bf1c
        • Instruction Fuzzy Hash: 76E15332A0CF4192FB50DB95E04276A7B66FB85FA0F584132EA9D83B96CF3CD5419700
        Strings
        • findrunnable: netpoll with psave on system g not allowednewproc1: newg missing stacknewproc1: new g is not GdeadFixedStack is not power-of-2missing stack in shrinkstack args stack map entries for invalid runtime symbol tableruntime: no module data for [origina, xrefs: 00007FF61019088C
        • findrunnable: wrong ppreempt at unknown pcreleasep: invalid argcheckdead: runnable gruntime: newstack at runtime: newstack sp=runtime: confused by pcHeader.textStart= timer data corruptionkey is not comparablelocalhost.localdomainsequence tag mismatchtrace/br, xrefs: 00007FF6101908AE
        • findrunnable: netpoll with spinningpidleput: P has non-empty run queuetraceback did not unwind completelyruntime: createevent failed; errno=crypto/md5: invalid hash state sizesuperfluous leading zeros in length'_' must separate successive digitsencoding/hex: o, xrefs: 00007FF61019087B
        • findrunnable: negative nmspinningfreeing stack not in a stack spanstackalloc not on scheduler stackruntime: goroutine stack exceeds runtime: text offset out of rangetimer period must be non-negativeruntime: name offset out of rangeruntime: type offset out of r, xrefs: 00007FF61019089D
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: findrunnable: negative nmspinningfreeing stack not in a stack spanstackalloc not on scheduler stackruntime: goroutine stack exceeds runtime: text offset out of rangetimer period must be non-negativeruntime: name offset out of rangeruntime: type offset out of r$findrunnable: netpoll with psave on system g not allowednewproc1: newg missing stacknewproc1: new g is not GdeadFixedStack is not power-of-2missing stack in shrinkstack args stack map entries for invalid runtime symbol tableruntime: no module data for [origina$findrunnable: netpoll with spinningpidleput: P has non-empty run queuetraceback did not unwind completelyruntime: createevent failed; errno=crypto/md5: invalid hash state sizesuperfluous leading zeros in length'_' must separate successive digitsencoding/hex: o$findrunnable: wrong ppreempt at unknown pcreleasep: invalid argcheckdead: runnable gruntime: newstack at runtime: newstack sp=runtime: confused by pcHeader.textStart= timer data corruptionkey is not comparablelocalhost.localdomainsequence tag mismatchtrace/br
        • API String ID: 0-3153311741
        • Opcode ID: d65171931f59779970705a251106b487ba6979bb8942aa3fea61fd1d449a41e0
        • Instruction ID: 83a6534d166454f7fb4ff45b08c03e7c928cbcbf1c37f4d4e48c93112ddc868a
        • Opcode Fuzzy Hash: d65171931f59779970705a251106b487ba6979bb8942aa3fea61fd1d449a41e0
        • Instruction Fuzzy Hash: 9C729432A0DF8695FFA19B95E4413BA63A4EB85FA0F448036DA4C87B95CF3CE485D740
        Strings
        • self-preempt [recovered]bad recoverybad g statusentersyscallwirep: p->m=) p->status=releasep: m= sysmonwait= preemptoff=cas64 failed m->gsignal=-byte limitruntime: sp=abi mismatchcontext.TODOmultipathtcp127.0.0.1:53no such hostCIDR addressunknown portinvalid , xrefs: 00007FF610185D96
        • runtime.preemptM: duplicatehandle failed; errno=runtime: waitforsingleobject wait_failed; errno=out points to big.Int, but defaultValue does notsyscall: string with NUL passed to StringToUTF16bufio: writer returned negative count from Writeparsing/packing of t, xrefs: 00007FF610185D5D
        • runtime.preemptM: duplicatehandle faileddeferproc: d.panic != nil after newdefermust be able to track idle limiter eventruntime: SyscallN has too many argumentscrypto/cipher: message too large for GCMcrypto/cipher: output smaller than inputchacha20poly1305: in, xrefs: 00007FF610185D85
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: runtime.preemptM: duplicatehandle failed; errno=runtime: waitforsingleobject wait_failed; errno=out points to big.Int, but defaultValue does notsyscall: string with NUL passed to StringToUTF16bufio: writer returned negative count from Writeparsing/packing of t$runtime.preemptM: duplicatehandle faileddeferproc: d.panic != nil after newdefermust be able to track idle limiter eventruntime: SyscallN has too many argumentscrypto/cipher: message too large for GCMcrypto/cipher: output smaller than inputchacha20poly1305: in$self-preempt [recovered]bad recoverybad g statusentersyscallwirep: p->m=) p->status=releasep: m= sysmonwait= preemptoff=cas64 failed m->gsignal=-byte limitruntime: sp=abi mismatchcontext.TODOmultipathtcp127.0.0.1:53no such hostCIDR addressunknown portinvalid
        • API String ID: 0-1001307366
        • Opcode ID: 66dea0b84f719a52b8d7b34791ec59492439e043c99db2ad5537a50729c9f6b5
        • Instruction ID: 24215fa9a5d153ed577332485c37c7cc63767ce6a64f6dc66b79d922c5cfb5ef
        • Opcode Fuzzy Hash: 66dea0b84f719a52b8d7b34791ec59492439e043c99db2ad5537a50729c9f6b5
        • Instruction Fuzzy Hash: BFD15D36A09F8192EB51CB55E4823AA7765FB46FA0F148236DA9C837D9DF3CD582C700
        Strings
        • grew heap, but no adequate free space foundroot level max pages doesn't fit in summaryunfinished open-coded defers in deferreturnruntime: releaseSudog with non-nil gp.paramunknown runnable goroutine during bootstrapruntime: casfrom_Gscanstatus bad oldval gp=ru, xrefs: 00007FF610179262
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: grew heap, but no adequate free space foundroot level max pages doesn't fit in summaryunfinished open-coded defers in deferreturnruntime: releaseSudog with non-nil gp.paramunknown runnable goroutine during bootstrapruntime: casfrom_Gscanstatus bad oldval gp=ru
        • API String ID: 0-3045916205
        • Opcode ID: f96ba30dc8824358f88242c2e1e5cf6fbfd609d408364d825b0dd1a13564caf1
        • Instruction ID: 09ce3edb577733f124c740120fe283efc4175157fac1ece8f81931c07153cd97
        • Opcode Fuzzy Hash: f96ba30dc8824358f88242c2e1e5cf6fbfd609d408364d825b0dd1a13564caf1
        • Instruction Fuzzy Hash: 31E16E3260DF8695EB609B96E4413AAA761FB85FE0F588135EE8D83B95CF3CD454CB00
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 6afbbc9ab1a404aea0e40ac8dee0ed1a90b0ad9758cb92e43e48102795c54532
        • Instruction ID: 2242bae57468b2223a1782d3069602fb27e872940dc4336b96f4688c40396fbc
        • Opcode Fuzzy Hash: 6afbbc9ab1a404aea0e40ac8dee0ed1a90b0ad9758cb92e43e48102795c54532
        • Instruction Fuzzy Hash: 2DD17C32A0CE4296FB408F95E4922BAB7A4FB86F60F548135E68DC77A5DF6CE441C700
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 1c34ef30a5c8c028492a7aec91fd8cc93f3bd9139ed12097f4394b216d7ffd09
        • Instruction ID: bbaa692af10a6feafb8fed9647aeffa92202484386f40619e1ce73e839290298
        • Opcode Fuzzy Hash: 1c34ef30a5c8c028492a7aec91fd8cc93f3bd9139ed12097f4394b216d7ffd09
        • Instruction Fuzzy Hash: 3491A231E08E02A6FF549F94E48137963A5AF45F74F54913ACA0CC7795CE2CB985E740
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 00d6594e87fb8031d2f50870ca9dbc537816535ed285a207e4c3f8c8e40483fd
        • Instruction ID: 5c6676a5db4a9b560c1c8ce7cd0e8287b4bb05e86b151e7d0bcb00c5bbcc42be
        • Opcode Fuzzy Hash: 00d6594e87fb8031d2f50870ca9dbc537816535ed285a207e4c3f8c8e40483fd
        • Instruction Fuzzy Hash: D9417F36608F85A1EB448B15E8411EA67A4FB84FA4F958036EF4D93769CE7CD646C700
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 6a5007af97247e32ca3394a6c7ae49790ba6805b55db95342021c6b1231998a4
        • Instruction ID: 714571373fea60243dca9c9b38c72bc6a57e573b103aa2bc957f42e32d29cf82
        • Opcode Fuzzy Hash: 6a5007af97247e32ca3394a6c7ae49790ba6805b55db95342021c6b1231998a4
        • Instruction Fuzzy Hash: 09211B36A09F4591EB40CB21E44213A7764FB5AFA0F158632EE9C83796DF3DD292C700
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID: AddressCallerProc
        • String ID:
        • API String ID: 2663294120-0
        • Opcode ID: ae9484ab8339121adab38818ee12098b0ed07cd46f7304dadeff90e65abf235e
        • Instruction ID: cc7f9e5b8a37cfb72e6d0cfd046c9c1969932853139d6a78c6e94d88e218e5cf
        • Opcode Fuzzy Hash: ae9484ab8339121adab38818ee12098b0ed07cd46f7304dadeff90e65abf235e
        • Instruction Fuzzy Hash: 58015B36A04F80C1EB118B5AE9413297374E749BE4F248226DEAD57BA4CB29E1A3C740

        Non-executed Functions

        Strings
        • runtime: summary[runtime: level = , p.searchAddr = runtime.newosprocruntime/internal/thread exhaustionlocked m0 woke upentersyscallblock spinningthreads=gp.waiting != nilunknown caller pcstack: frame={sp:runtime: nameOff runtime: typeOff runtime: textOff 06010, xrefs: 00007FF61017BFBF, 00007FF61017C3F6
        • , npages = tracealloc( p->status= in status idleprocs= gcwaiting= schedtick= timerslen= mallocing=bad timedivfloat64nan1float64nan2float64nan3float32nan2GOTRACEBACK) at entry+ (targetpc= , plugin: runtime: g : frame.sp=created by .WithCanceli/o timeoutbroken , xrefs: 00007FF61017C4BC
        • , i = code= addr= m->p= p->m=SCHED curg= ctxt: min= max= (...) base rdtscppopcnt, val netdns.localreturnlisten.onionip+netsocketdomaingophertelnetSTREEThangupkilleduint16uint32uint64structchan<-<-chan ValueCommonArabicBrahmiCarianChakmaCopticGothicHangulHa, xrefs: 00007FF61017C545
        • runtime: p.searchAddr = range partially overlapsbad defer entry in panicbypassed recovery failedstack trace unavailablebindm in unexpected GOOSrunqsteal: runq overflowdouble traceGCSweepStartfloating point exceptionconnection reset by peerlevel 2 not synchron, xrefs: 00007FF61017C525
        • bad summary dataruntime: addr = runtime: base = runtime: head = already; errno=runtime stack:invalid g statuscastogscanstatusbad g transitionschedule: in cgoreflect mismatch untyped locals missing stackmapbad symbol tablenon-Go function not in ranges:GODE, xrefs: 00007FF61017C09C, 00007FF61017C7EC
        • , levelBits[level] = runtime: searchIdx = defer on system stackpanic on system stackasync stack too largestartm: m is spinningstartlockedm: m has pfindrunnable: wrong ppreempt at unknown pcreleasep: invalid argcheckdead: runnable gruntime: newstack at runtime:, xrefs: 00007FF61017C5C5
        • ] = pc=none: p=cas1cas2cas3cas4cas5cas6 at m= sp= sp: lr: fp=) m=ermssse3avx2bmi1bmi2dialbind on unixicmpigmpftpspop3smtpasn1quitint8uintchanfuncpartcallkind != AhomChamKawiLisuMiaoModiNewaThaiTotonameFrom.css.gif.htm.jpg.mjs.svg.xmlxn--graymenuhelpbold, xrefs: 00007FF61017C436
        • ] = (usageinit ms, fault and tab= top=[...], fp:sse41sse42ssse3hostsfilesimap2imap3imapspop3sntohsint16int32int64uint8sliceGreekAdlamBamumBatakBuhidDograKhmerLatinLimbuNushuOghamOriyaOsageRunicTakriTamilUTF-8utf-8%s*%dtext/.avif.html.jpeg.json.wasm.webpbad n, xrefs: 00007FF61017BFF8
        • , j0 = head = panic: nmsys= locks= dying= allocs m->g0= pad1= pad2= text= minpc= value= (scan)types : type nil keywsarecvwsasendconnectlookup 2.5.4.62.5.4.32.5.4.52.5.4.72.5.4.82.5.4.9abortedCopySidWSARecvWSASendsignal invaliduintptrSwapperChanDir Value>C, xrefs: 00007FF61017C4DA
        • runtime: npages = runtime: range = {index out of rangeruntime: gp: gp=runtime: getg: g=forEachP: not done in async preemptbad manualFreeListruntime: textAddr cleantimers: bad p frames elided..., locked to threadruntime.semacreateruntime.semawakeupcontext., xrefs: 00007FF61017C06F
        • runtime: levelShift[level] = doRecordGoroutineProfile gp1=timeBegin/EndPeriod not foundruntime: sudog with non-nil cgfput: bad status (not Gdead)LockOSThread nesting overflowsemacquire not on the G stackruntime: split stack overflowstring concatenation too lon, xrefs: 00007FF61017C5A5
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: , i = code= addr= m->p= p->m=SCHED curg= ctxt: min= max= (...) base rdtscppopcnt, val netdns.localreturnlisten.onionip+netsocketdomaingophertelnetSTREEThangupkilleduint16uint32uint64structchan<-<-chan ValueCommonArabicBrahmiCarianChakmaCopticGothicHangulHa$, j0 = head = panic: nmsys= locks= dying= allocs m->g0= pad1= pad2= text= minpc= value= (scan)types : type nil keywsarecvwsasendconnectlookup 2.5.4.62.5.4.32.5.4.52.5.4.72.5.4.82.5.4.9abortedCopySidWSARecvWSASendsignal invaliduintptrSwapperChanDir Value>C$, levelBits[level] = runtime: searchIdx = defer on system stackpanic on system stackasync stack too largestartm: m is spinningstartlockedm: m has pfindrunnable: wrong ppreempt at unknown pcreleasep: invalid argcheckdead: runnable gruntime: newstack at runtime:$, npages = tracealloc( p->status= in status idleprocs= gcwaiting= schedtick= timerslen= mallocing=bad timedivfloat64nan1float64nan2float64nan3float32nan2GOTRACEBACK) at entry+ (targetpc= , plugin: runtime: g : frame.sp=created by .WithCanceli/o timeoutbroken $] = pc=none: p=cas1cas2cas3cas4cas5cas6 at m= sp= sp: lr: fp=) m=ermssse3avx2bmi1bmi2dialbind on unixicmpigmpftpspop3smtpasn1quitint8uintchanfuncpartcallkind != AhomChamKawiLisuMiaoModiNewaThaiTotonameFrom.css.gif.htm.jpg.mjs.svg.xmlxn--graymenuhelpbold$] = (usageinit ms, fault and tab= top=[...], fp:sse41sse42ssse3hostsfilesimap2imap3imapspop3sntohsint16int32int64uint8sliceGreekAdlamBamumBatakBuhidDograKhmerLatinLimbuNushuOghamOriyaOsageRunicTakriTamilUTF-8utf-8%s*%dtext/.avif.html.jpeg.json.wasm.webpbad n$bad summary dataruntime: addr = runtime: base = runtime: head = already; errno=runtime stack:invalid g statuscastogscanstatusbad g transitionschedule: in cgoreflect mismatch untyped locals missing stackmapbad symbol tablenon-Go function not in ranges:GODE$runtime: levelShift[level] = doRecordGoroutineProfile gp1=timeBegin/EndPeriod not foundruntime: sudog with non-nil cgfput: bad status (not Gdead)LockOSThread nesting overflowsemacquire not on the G stackruntime: split stack overflowstring concatenation too lon$runtime: npages = runtime: range = {index out of rangeruntime: gp: gp=runtime: getg: g=forEachP: not done in async preemptbad manualFreeListruntime: textAddr cleantimers: bad p frames elided..., locked to threadruntime.semacreateruntime.semawakeupcontext.$runtime: p.searchAddr = range partially overlapsbad defer entry in panicbypassed recovery failedstack trace unavailablebindm in unexpected GOOSrunqsteal: runq overflowdouble traceGCSweepStartfloating point exceptionconnection reset by peerlevel 2 not synchron$runtime: summary[runtime: level = , p.searchAddr = runtime.newosprocruntime/internal/thread exhaustionlocked m0 woke upentersyscallblock spinningthreads=gp.waiting != nilunknown caller pcstack: frame={sp:runtime: nameOff runtime: typeOff runtime: textOff 06010
        • API String ID: 0-1068691519
        • Opcode ID: 5fe916b6e128f9508ea0b91f435b5366af0e7932e17c9fe4a6e59cc7b20b0fa1
        • Instruction ID: 25ea43a36e057c6a35d4abb3300a0a6f3c8ff717c3e4460e8c775168486b1a71
        • Opcode Fuzzy Hash: 5fe916b6e128f9508ea0b91f435b5366af0e7932e17c9fe4a6e59cc7b20b0fa1
        • Instruction Fuzzy Hash: 56328F36A18E86A1FE209B91E4423EAA325FB44FA0F408136DE4D97B9ADF3CD545C740
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID: malloc$ExceptionFilterInfoSleepStartupUnhandled_amsg_exit_inittermstrlen
        • String ID:
        • API String ID: 4258315806-0
        • Opcode ID: 98c0ac51aeb6d5c780bab1ecde70b34fc64bb73ac44fd7a404b2ad799f47fdfc
        • Instruction ID: 71476e8fa1fe47bfb4048caa6127642f3fa8fbeb14fbecbde3ad4241c6dd063c
        • Opcode Fuzzy Hash: 98c0ac51aeb6d5c780bab1ecde70b34fc64bb73ac44fd7a404b2ad799f47fdfc
        • Instruction Fuzzy Hash: F4817C30A19E52E5FF50AB15E4553B963A4AF89F60F244036D94DC73B1DF3EE8819B80
        Strings
        • runtime: pcdata is bad ABI descriptiondodeltimer: wrong Padjusttimers: bad psync.Cond is copiedcriterion too short20060102150405Z0700binary.LittleEndianunknown Go type: %villegal instructionbad file descriptordisk quota exceededtoo many open filesdevice not a , xrefs: 00007FF6101A009D, 00007FF6101A0227
        • untyped locals missing stackmapbad symbol tablenon-Go function not in ranges:GODEBUG: value "context canceled.WithValue(type hostLookupOrder=/etc/resolv.confnon-IPv4 addressnon-IPv6 addressunknown network no colon on linebinary.BigEndianlength too largeinva, xrefs: 00007FF6101A031D
        • untyped args out of range no module data in goroutine .WithDeadline(<not Stringer>getprotobynameunknown mode: data truncatedfile too largelevel 2 haltedlevel 3 haltedtoo many linksno such deviceprotocol errortext file busytoo many usersCryptGenRandomCertClos, xrefs: 00007FF6101A0197
        • runtime: frame runtimer: bad ptraceback stuckmissing address/etc/mdns.allowunknown network0601021504Z0700invalid booleannon-minimal tagunknown Go typeadvertise errorkey has expirednetwork is downno medium foundno such processGetAdaptersInfoCreateHardLinkWDevic, xrefs: 00007FF6101A0174, 00007FF6101A02FA
        • locals stack map entries for abi mismatch detected between runtime: impossible type kind unsafe.Slice: len out of rangesync: inconsistent mutex statesync: unlock of unlocked mutexGODEBUG: unknown cpu feature "subtle.XORBytes: dst too shortasn1: cannot marshal, xrefs: 00007FF6101A0265
        • and tab= top=[...], fp:sse41sse42ssse3hostsfilesimap2imap3imapspop3sntohsint16int32int64uint8sliceGreekAdlamBamumBatakBuhidDograKhmerLatinLimbuNushuOghamOriyaOsageRunicTakriTamilUTF-8utf-8%s*%dtext/.avif.html.jpeg.json.wasm.webpbad nfocushoverloginShiftSuper, xrefs: 00007FF6101A00BB, 00007FF6101A0245
        • bad symbol tablenon-Go function not in ranges:GODEBUG: value "context canceled.WithValue(type hostLookupOrder=/etc/resolv.confnon-IPv4 addressnon-IPv6 addressunknown network no colon on linebinary.BigEndianlength too largeinvalid rune %#Udivision by zeroinva, xrefs: 00007FF6101A012A, 00007FF6101A02BB
        • missing stackmapbad symbol tablenon-Go function not in ranges:GODEBUG: value "context canceled.WithValue(type hostLookupOrder=/etc/resolv.confnon-IPv4 addressnon-IPv6 addressunknown network no colon on linebinary.BigEndianlength too largeinvalid rune %#Udivi, xrefs: 00007FF6101A01D9, 00007FF6101A036F
        • args stack map entries for invalid runtime symbol tableruntime: no module data for [originating from goroutine cannot unmarshal DNS messagepending ASN.1 child too longasn1: string not valid UTF-8big: misuse of expNNWindowedfile descriptor in bad statedestinat, xrefs: 00007FF6101A00D6
        • (targetpc= , plugin: runtime: g : frame.sp=created by .WithCanceli/o timeoutbroken pipealarm clockbad messagefile existsbad addressRegCloseKeyCreateFileWDeleteFileWExitProcessFreeLibrarySetFileTimeVirtualLockWSARecvFromclosesocketgetpeernamegetsocknamecrypt32, xrefs: 00007FF6101A00F9, 00007FF6101A0288
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: (targetpc= , plugin: runtime: g : frame.sp=created by .WithCanceli/o timeoutbroken pipealarm clockbad messagefile existsbad addressRegCloseKeyCreateFileWDeleteFileWExitProcessFreeLibrarySetFileTimeVirtualLockWSARecvFromclosesocketgetpeernamegetsocknamecrypt32$ and tab= top=[...], fp:sse41sse42ssse3hostsfilesimap2imap3imapspop3sntohsint16int32int64uint8sliceGreekAdlamBamumBatakBuhidDograKhmerLatinLimbuNushuOghamOriyaOsageRunicTakriTamilUTF-8utf-8%s*%dtext/.avif.html.jpeg.json.wasm.webpbad nfocushoverloginShiftSuper$ args stack map entries for invalid runtime symbol tableruntime: no module data for [originating from goroutine cannot unmarshal DNS messagepending ASN.1 child too longasn1: string not valid UTF-8big: misuse of expNNWindowedfile descriptor in bad statedestinat$ locals stack map entries for abi mismatch detected between runtime: impossible type kind unsafe.Slice: len out of rangesync: inconsistent mutex statesync: unlock of unlocked mutexGODEBUG: unknown cpu feature "subtle.XORBytes: dst too shortasn1: cannot marshal$ untyped args out of range no module data in goroutine .WithDeadline(<not Stringer>getprotobynameunknown mode: data truncatedfile too largelevel 2 haltedlevel 3 haltedtoo many linksno such deviceprotocol errortext file busytoo many usersCryptGenRandomCertClos$ untyped locals missing stackmapbad symbol tablenon-Go function not in ranges:GODEBUG: value "context canceled.WithValue(type hostLookupOrder=/etc/resolv.confnon-IPv4 addressnon-IPv6 addressunknown network no colon on linebinary.BigEndianlength too largeinva$bad symbol tablenon-Go function not in ranges:GODEBUG: value "context canceled.WithValue(type hostLookupOrder=/etc/resolv.confnon-IPv4 addressnon-IPv6 addressunknown network no colon on linebinary.BigEndianlength too largeinvalid rune %#Udivision by zeroinva$missing stackmapbad symbol tablenon-Go function not in ranges:GODEBUG: value "context canceled.WithValue(type hostLookupOrder=/etc/resolv.confnon-IPv4 addressnon-IPv6 addressunknown network no colon on linebinary.BigEndianlength too largeinvalid rune %#Udivi$runtime: frame runtimer: bad ptraceback stuckmissing address/etc/mdns.allowunknown network0601021504Z0700invalid booleannon-minimal tagunknown Go typeadvertise errorkey has expirednetwork is downno medium foundno such processGetAdaptersInfoCreateHardLinkWDevic$runtime: pcdata is bad ABI descriptiondodeltimer: wrong Padjusttimers: bad psync.Cond is copiedcriterion too short20060102150405Z0700binary.LittleEndianunknown Go type: %villegal instructionbad file descriptordisk quota exceededtoo many open filesdevice not a
        • API String ID: 0-1479805975
        • Opcode ID: c46760339fd2f599396afd07bed73da93f650bf32e891572605b6857b3fb7b27
        • Instruction ID: 58bbf9f93d120f1bef9dd3071dfbd3d924547ad1b91e00642272b39938185e19
        • Opcode Fuzzy Hash: c46760339fd2f599396afd07bed73da93f650bf32e891572605b6857b3fb7b27
        • Instruction Fuzzy Hash: CB02533660CE86A5FF60DB95E4813AAA365FB44FA0F544136EA4D837A6DF3CE544C700
        Strings
        • ms clock, nBSSRoots=runtime: P exp.) for minTrigger=GOMEMLIMIT=bad m value, elemsize= freeindex= span.list=, npages = tracealloc( p->status= in status idleprocs= gcwaiting= schedtick= timerslen= mallocing=bad timedivfloat64nan1float64nan2float64nan3float32, xrefs: 00007FF61016BCC5
        • MB globals, work.nproc= work.nwait= nStackRoots= flushedWork double unlock s.spanclass= MB) workers=min too large-byte block (runtime: val=runtime: seq=fatal error: idlethreads= syscalltick=load64 failedxadd64 failedxchg64 failednil stackbase}sched={pc:, xrefs: 00007FF61016BF85
        • MB goal, s.state = s.base()= heapGoal=GOMEMLIMIT KiB now, pages at sweepgen= sweepgen , bound = , limit = tracefree(tracegc()exitThreadBad varintGC forced runqueue= stopwait= runqsize= gfreecnt= throwing= spinning=atomicand8float64nanfloat32nanException , xrefs: 00007FF61016BF45
        • gc done but gcphase != _GCoffruntime: p.gcMarkWorkerMode= scanobject of a noscan objectruntime: marking free object addspecial on invalid pointerruntime: summary max pages = runtime: levelShift[level] = doRecordGoroutineProfile gp1=timeBegin/EndPeriod not foun, xrefs: 00007FF61016C169
        • ms cpu, (forced) wbuf1.n= wbuf2.n= s.limit= s.state= B work ( B exp.) marked unmarked in use), size = bad prune, tail = recover: not in [ctxt != 0, oldval=, newval= threads=: status= blocked= lockedg=atomicor8 runtime= m->curg=(unknown)traceback} stack=, xrefs: 00007FF61016BECB
        • failed to set sweep barrierwork.nwait was > work.nproc not in stack roots range [allocated pages below zero?address not a stack addressmspan.sweep: bad span stateinvalid profile bucket typeruntime: corrupted polldescruntime: netpollinit failedcould not find QP, xrefs: 00007FF61016C158
        • MB stacks, worker mode nDataRoots= nSpanRoots= wbuf1=<nil> wbuf2=<nil> gcscandone runtime: gp= found at *( s.elemsize= B (goal , cons/mark maxTrigger= pages/byte s.sweepgen= allocCount end tracegcbad g0 stackself-preempt [recovered]bad recoverybad g , xrefs: 00007FF61016BF65
        • ., xrefs: 00007FF61016BAB4
        • gcing MB, got= ... max=scav ptr ] = (usageinit ms, fault and tab= top=[...], fp:sse41sse42ssse3hostsfilesimap2imap3imapspop3sntohsint16int32int64uint8sliceGreekAdlamBamumBatakBuhidDograKhmerLatinLimbuNushuOghamOriyaOsageRunicTakriTamilUTF-8utf-8%s*%dtext/, xrefs: 00007FF61016B59A
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: MB globals, work.nproc= work.nwait= nStackRoots= flushedWork double unlock s.spanclass= MB) workers=min too large-byte block (runtime: val=runtime: seq=fatal error: idlethreads= syscalltick=load64 failedxadd64 failedxchg64 failednil stackbase}sched={pc:$ MB goal, s.state = s.base()= heapGoal=GOMEMLIMIT KiB now, pages at sweepgen= sweepgen , bound = , limit = tracefree(tracegc()exitThreadBad varintGC forced runqueue= stopwait= runqsize= gfreecnt= throwing= spinning=atomicand8float64nanfloat32nanException $ MB stacks, worker mode nDataRoots= nSpanRoots= wbuf1=<nil> wbuf2=<nil> gcscandone runtime: gp= found at *( s.elemsize= B (goal , cons/mark maxTrigger= pages/byte s.sweepgen= allocCount end tracegcbad g0 stackself-preempt [recovered]bad recoverybad g $ ms clock, nBSSRoots=runtime: P exp.) for minTrigger=GOMEMLIMIT=bad m value, elemsize= freeindex= span.list=, npages = tracealloc( p->status= in status idleprocs= gcwaiting= schedtick= timerslen= mallocing=bad timedivfloat64nan1float64nan2float64nan3float32$ ms cpu, (forced) wbuf1.n= wbuf2.n= s.limit= s.state= B work ( B exp.) marked unmarked in use), size = bad prune, tail = recover: not in [ctxt != 0, oldval=, newval= threads=: status= blocked= lockedg=atomicor8 runtime= m->curg=(unknown)traceback} stack=$.$failed to set sweep barrierwork.nwait was > work.nproc not in stack roots range [allocated pages below zero?address not a stack addressmspan.sweep: bad span stateinvalid profile bucket typeruntime: corrupted polldescruntime: netpollinit failedcould not find QP$gc done but gcphase != _GCoffruntime: p.gcMarkWorkerMode= scanobject of a noscan objectruntime: marking free object addspecial on invalid pointerruntime: summary max pages = runtime: levelShift[level] = doRecordGoroutineProfile gp1=timeBegin/EndPeriod not foun$gcing MB, got= ... max=scav ptr ] = (usageinit ms, fault and tab= top=[...], fp:sse41sse42ssse3hostsfilesimap2imap3imapspop3sntohsint16int32int64uint8sliceGreekAdlamBamumBatakBuhidDograKhmerLatinLimbuNushuOghamOriyaOsageRunicTakriTamilUTF-8utf-8%s*%dtext/
        • API String ID: 0-2179417172
        • Opcode ID: 7c55ca730704873aed7c9746711b5483d7c4bf4b57c327105f5186bd00b8c946
        • Instruction ID: d064a5a0519d02a1ed80e3090fe9db1e5dad66a0aed26181d1897e90212b3882
        • Opcode Fuzzy Hash: 7c55ca730704873aed7c9746711b5483d7c4bf4b57c327105f5186bd00b8c946
        • Instruction Fuzzy Hash: 53623C36A0DE8696FB50DB55E8823BA6369FB45FA0F448132DA4D837A6DF3CE145C700
        Strings
        • greyobject: obj not pointer-alignedmismatched begin/end of activeSweepmheap.freeSpanLocked - invalid freeattempt to clear non-empty span setruntime: close polldesc w/o unblockruntime: inconsistent read deadlinefindrunnable: netpoll with spinningpidleput: P has, xrefs: 00007FF610170BEF
        • runtime: marking free object addspecial on invalid pointerruntime: summary max pages = runtime: levelShift[level] = doRecordGoroutineProfile gp1=timeBegin/EndPeriod not foundruntime: sudog with non-nil cgfput: bad status (not Gdead)LockOSThread nesting overflo, xrefs: 00007FF610170B27
        • marking free object KiB work (eager), [controller reset]mspan.sweep: state=sysMemStat overflowbad sequence numberntdll.dll not foundwinmm.dll not foundruntime: g0 stack [missing deferreturnpanic during mallocpanic holding lockspanic during panic, g->atomics, xrefs: 00007FF610170BDE
        • base of ) = <==GOGC] = pc=none: p=cas1cas2cas3cas4cas5cas6 at m= sp= sp: lr: fp=) m=ermssse3avx2bmi1bmi2dialbind on unixicmpigmpftpspop3smtpasn1quitint8uintchanfuncpartcallkind != AhomChamKawiLisuMiaoModiNewaThaiTotonameFrom.css.gif.htm.jpg.mjs.svg.xml, xrefs: 00007FF610170B9B
        • found at *( s.elemsize= B (goal , cons/mark maxTrigger= pages/byte s.sweepgen= allocCount end tracegcbad g0 stackself-preempt [recovered]bad recoverybad g statusentersyscallwirep: p->m=) p->status=releasep: m= sysmonwait= preemptoff=cas64 failed m->gs, xrefs: 00007FF610170B45
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: found at *( s.elemsize= B (goal , cons/mark maxTrigger= pages/byte s.sweepgen= allocCount end tracegcbad g0 stackself-preempt [recovered]bad recoverybad g statusentersyscallwirep: p->m=) p->status=releasep: m= sysmonwait= preemptoff=cas64 failed m->gs$base of ) = <==GOGC] = pc=none: p=cas1cas2cas3cas4cas5cas6 at m= sp= sp: lr: fp=) m=ermssse3avx2bmi1bmi2dialbind on unixicmpigmpftpspop3smtpasn1quitint8uintchanfuncpartcallkind != AhomChamKawiLisuMiaoModiNewaThaiTotonameFrom.css.gif.htm.jpg.mjs.svg.xml$greyobject: obj not pointer-alignedmismatched begin/end of activeSweepmheap.freeSpanLocked - invalid freeattempt to clear non-empty span setruntime: close polldesc w/o unblockruntime: inconsistent read deadlinefindrunnable: netpoll with spinningpidleput: P has$marking free object KiB work (eager), [controller reset]mspan.sweep: state=sysMemStat overflowbad sequence numberntdll.dll not foundwinmm.dll not foundruntime: g0 stack [missing deferreturnpanic during mallocpanic holding lockspanic during panic, g->atomics$runtime: marking free object addspecial on invalid pointerruntime: summary max pages = runtime: levelShift[level] = doRecordGoroutineProfile gp1=timeBegin/EndPeriod not foundruntime: sudog with non-nil cgfput: bad status (not Gdead)LockOSThread nesting overflo
        • API String ID: 0-1311871524
        • Opcode ID: c327a77b9e576fa19080a6dc40b0ed77d00f9745771a7b26d2bc3e184cd3c822
        • Instruction ID: 011008399197f4a8ccbbe86750f6357577073a9a84d46e8401c934982d687ed4
        • Opcode Fuzzy Hash: c327a77b9e576fa19080a6dc40b0ed77d00f9745771a7b26d2bc3e184cd3c822
        • Instruction Fuzzy Hash: 5D71DE66A08F82A6FF019B51E4423B9A764FB45FA0F444136EF9D83B96CF2CE654C700
        Strings
        • -> node= ms cpu, (forced) wbuf1.n= wbuf2.n= s.limit= s.state= B work ( B exp.) marked unmarked in use), size = bad prune, tail = recover: not in [ctxt != 0, oldval=, newval= threads=: status= blocked= lockedg=atomicor8 runtime= m->curg=(unknown)tracebac, xrefs: 00007FF61015BE85
        • runtime: lfstack.push invalid packing: node=out of memory allocating heap arena metadata/cpu/classes/scavenge/background:cpu-secondsruntime: unexpected metric registration for gcmarknewobject called while doing checkmarkactive sweepers found at start of mark p, xrefs: 00007FF61015BE25
        • lfstack.push span.limit= span.state=bad flushGen MB stacks, worker mode nDataRoots= nSpanRoots= wbuf1=<nil> wbuf2=<nil> gcscandone runtime: gp= found at *( s.elemsize= B (goal , cons/mark maxTrigger= pages/byte s.sweepgen= allocCount end tracegcbad g0, xrefs: 00007FF61015BEAF
        • cnt=gcing MB, got= ... max=scav ptr ] = (usageinit ms, fault and tab= top=[...], fp:sse41sse42ssse3hostsfilesimap2imap3imapspop3sntohsint16int32int64uint8sliceGreekAdlamBamumBatakBuhidDograKhmerLatinLimbuNushuOghamOriyaOsageRunicTakriTamilUTF-8utf-8%s*%d, xrefs: 00007FF61015BE45
        • packed=BAD RANK status unknown(trigger= npages= nalloc= nfreed=[signal newval= mcount= bytes, stack=[ minLC= maxpc= stack=[ minutes etypes [::1]:53continue_gatewayshutdowninvalid address readfromwsaioctlunixgram2.5.4.102.5.4.112.5.4.17no anodeCancelIoRead, xrefs: 00007FF61015BE65
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: -> node= ms cpu, (forced) wbuf1.n= wbuf2.n= s.limit= s.state= B work ( B exp.) marked unmarked in use), size = bad prune, tail = recover: not in [ctxt != 0, oldval=, newval= threads=: status= blocked= lockedg=atomicor8 runtime= m->curg=(unknown)tracebac$ cnt=gcing MB, got= ... max=scav ptr ] = (usageinit ms, fault and tab= top=[...], fp:sse41sse42ssse3hostsfilesimap2imap3imapspop3sntohsint16int32int64uint8sliceGreekAdlamBamumBatakBuhidDograKhmerLatinLimbuNushuOghamOriyaOsageRunicTakriTamilUTF-8utf-8%s*%d$ packed=BAD RANK status unknown(trigger= npages= nalloc= nfreed=[signal newval= mcount= bytes, stack=[ minLC= maxpc= stack=[ minutes etypes [::1]:53continue_gatewayshutdowninvalid address readfromwsaioctlunixgram2.5.4.102.5.4.112.5.4.17no anodeCancelIoRead$lfstack.push span.limit= span.state=bad flushGen MB stacks, worker mode nDataRoots= nSpanRoots= wbuf1=<nil> wbuf2=<nil> gcscandone runtime: gp= found at *( s.elemsize= B (goal , cons/mark maxTrigger= pages/byte s.sweepgen= allocCount end tracegcbad g0$runtime: lfstack.push invalid packing: node=out of memory allocating heap arena metadata/cpu/classes/scavenge/background:cpu-secondsruntime: unexpected metric registration for gcmarknewobject called while doing checkmarkactive sweepers found at start of mark p
        • API String ID: 0-2803183959
        • Opcode ID: 56043d0f2cfa56b9763b09324244c05be8344afcb26b7588ab5eda2fe720084e
        • Instruction ID: 3de4619e0ee7226fe1be3249e999f82bb5cc0292724fca4f33a612d0823dce04
        • Opcode Fuzzy Hash: 56043d0f2cfa56b9763b09324244c05be8344afcb26b7588ab5eda2fe720084e
        • Instruction Fuzzy Hash: D0317436A1CF46A6FE109B90E8821B9A768FB49F90F488531DE5D87756CF3CD5109740
        Strings
        • runtime: p ms clock, nBSSRoots=runtime: P exp.) for minTrigger=GOMEMLIMIT=bad m value, elemsize= freeindex= span.list=, npages = tracealloc( p->status= in status idleprocs= gcwaiting= schedtick= timerslen= mallocing=bad timedivfloat64nan1float64nan2float64, xrefs: 00007FF61016AFDA
        • p mcache not flushed markroot jobs donepacer: assist ratio=workbuf is not emptybad use of bucket.mpbad use of bucket.bpruntime: double waitws2_32.dll not foundpreempt off reason: forcegc: phase errorgopark: bad g statusgo of nil func valuewirep: already in go, xrefs: 00007FF61016B038
        • != sweepgen MB globals, work.nproc= work.nwait= nStackRoots= flushedWork double unlock s.spanclass= MB) workers=min too large-byte block (runtime: val=runtime: seq=fatal error: idlethreads= syscalltick=load64 failedxadd64 failedxchg64 failednil stackbase, xrefs: 00007FF61016B010
        • flushGen MB goal, s.state = s.base()= heapGoal=GOMEMLIMIT KiB now, pages at sweepgen= sweepgen , bound = , limit = tracefree(tracegc()exitThreadBad varintGC forced runqueue= stopwait= runqsize= gfreecnt= throwing= spinning=atomicand8float64nanfloat32nan, xrefs: 00007FF61016AFF5
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: != sweepgen MB globals, work.nproc= work.nwait= nStackRoots= flushedWork double unlock s.spanclass= MB) workers=min too large-byte block (runtime: val=runtime: seq=fatal error: idlethreads= syscalltick=load64 failedxadd64 failedxchg64 failednil stackbase$ flushGen MB goal, s.state = s.base()= heapGoal=GOMEMLIMIT KiB now, pages at sweepgen= sweepgen , bound = , limit = tracefree(tracegc()exitThreadBad varintGC forced runqueue= stopwait= runqsize= gfreecnt= throwing= spinning=atomicand8float64nanfloat32nan$p mcache not flushed markroot jobs donepacer: assist ratio=workbuf is not emptybad use of bucket.mpbad use of bucket.bpruntime: double waitws2_32.dll not foundpreempt off reason: forcegc: phase errorgopark: bad g statusgo of nil func valuewirep: already in go$runtime: p ms clock, nBSSRoots=runtime: P exp.) for minTrigger=GOMEMLIMIT=bad m value, elemsize= freeindex= span.list=, npages = tracealloc( p->status= in status idleprocs= gcwaiting= schedtick= timerslen= mallocing=bad timedivfloat64nan1float64nan2float64
        • API String ID: 0-3993034679
        • Opcode ID: 56d4ca2dfd565013226413e68c2678a8f4e2d89a683b36b22dfa4e2ba73036b0
        • Instruction ID: 1edd0dcc7eaec44ebc07e0c4aad24e737beb62aeedff01418738824923b04ad0
        • Opcode Fuzzy Hash: 56d4ca2dfd565013226413e68c2678a8f4e2d89a683b36b22dfa4e2ba73036b0
        • Instruction Fuzzy Hash: F0E17C32A09F8296FB50CBA5E4822AA7365FB45F70F448136DA5D837A5DF7CE445CB00
        Strings
        • runtime: casgstatus: oldval=gcstopm: negative nmspinningfindrunnable: netpoll with psave on system g not allowednewproc1: newg missing stacknewproc1: new g is not GdeadFixedStack is not power-of-2missing stack in shrinkstack args stack map entries for invalid , xrefs: 00007FF61018CFA7
        • newval= mcount= bytes, stack=[ minLC= maxpc= stack=[ minutes etypes [::1]:53continue_gatewayshutdowninvalid address readfromwsaioctlunixgram2.5.4.102.5.4.112.5.4.17no anodeCancelIoReadFileAcceptExWSAIoctlArmenianBalineseBopomofoBugineseCherokeeCyrillicDupl, xrefs: 00007FF61018CFC5
        • casgstatus: waiting for Gwaiting but is Grunnablechacha20poly1305: bad nonce length passed to Sealchacha20poly1305: bad nonce length passed to Openinvalid or incomplete multibyte or wide characterreflect.Value.Slice: slice of unaddressable arraySOS length inco, xrefs: 00007FF61018CF5B
        • casgstatus: bad incoming valuesresetspinning: not a spinning mentersyscallblock inconsistent signal_recv: inconsistent stateruntime: split stack overflow: ...additional frames elided...unsafe.String: len out of rangecrypto/ecdh: invalid public keyencoding/hex, xrefs: 00007FF61018CFEF
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: newval= mcount= bytes, stack=[ minLC= maxpc= stack=[ minutes etypes [::1]:53continue_gatewayshutdowninvalid address readfromwsaioctlunixgram2.5.4.102.5.4.112.5.4.17no anodeCancelIoReadFileAcceptExWSAIoctlArmenianBalineseBopomofoBugineseCherokeeCyrillicDupl$casgstatus: bad incoming valuesresetspinning: not a spinning mentersyscallblock inconsistent signal_recv: inconsistent stateruntime: split stack overflow: ...additional frames elided...unsafe.String: len out of rangecrypto/ecdh: invalid public keyencoding/hex$casgstatus: waiting for Gwaiting but is Grunnablechacha20poly1305: bad nonce length passed to Sealchacha20poly1305: bad nonce length passed to Openinvalid or incomplete multibyte or wide characterreflect.Value.Slice: slice of unaddressable arraySOS length inco$runtime: casgstatus: oldval=gcstopm: negative nmspinningfindrunnable: netpoll with psave on system g not allowednewproc1: newg missing stacknewproc1: new g is not GdeadFixedStack is not power-of-2missing stack in shrinkstack args stack map entries for invalid
        • API String ID: 0-46102773
        • Opcode ID: 5ee303449469180826746fa8b3b1ce009e7a4ca6762484b9112589c647276da8
        • Instruction ID: 7c2b410b57ab2f720eb0c4f1b1c6e89869fdcb6ac3631774cd54bb3513b84d95
        • Opcode Fuzzy Hash: 5ee303449469180826746fa8b3b1ce009e7a4ca6762484b9112589c647276da8
        • Instruction Fuzzy Hash: 18C19336A09E4596FB50CB65E08636A7B61FB4AFA0F548133EA8C83795CF3DE542D700
        Strings
        • bad restart PC-thread limitstopm spinning nmidlelocked= needspinning=store64 failedsemaRoot queuebad allocCountbad span statestack overflow untyped args out of range no module data in goroutine .WithDeadline(<not Stringer>getprotobynameunknown mode: data tru, xrefs: 00007FF610189AE5
        • runtime/internal/thread exhaustionlocked m0 woke upentersyscallblock spinningthreads=gp.waiting != nilunknown caller pcstack: frame={sp:runtime: nameOff runtime: typeOff runtime: textOff 060102150405Z0700integer too large%%!%c(big.Int=%s)permission deniedwrong, xrefs: 00007FF6101899F4
        • reflect., xrefs: 00007FF610189A1B
        • runtime., xrefs: 00007FF6101899BB
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: bad restart PC-thread limitstopm spinning nmidlelocked= needspinning=store64 failedsemaRoot queuebad allocCountbad span statestack overflow untyped args out of range no module data in goroutine .WithDeadline(<not Stringer>getprotobynameunknown mode: data tru$reflect.$runtime.$runtime/internal/thread exhaustionlocked m0 woke upentersyscallblock spinningthreads=gp.waiting != nilunknown caller pcstack: frame={sp:runtime: nameOff runtime: typeOff runtime: textOff 060102150405Z0700integer too large%%!%c(big.Int=%s)permission deniedwrong
        • API String ID: 0-3342706229
        • Opcode ID: 44cebdfb341399189e94adc77e095006bfeb2946ec34af142254a9e35e2230c5
        • Instruction ID: c06d8057df547e104ee53042f60bb2fcf89c7e9b05e067e5dfaa258b80d926d2
        • Opcode Fuzzy Hash: 44cebdfb341399189e94adc77e095006bfeb2946ec34af142254a9e35e2230c5
        • Instruction Fuzzy Hash: F281B472B08E4196FF548B90A4423BD63A2FB85FA4F5C8136DA9D87794CF3CE9919700
        Strings
        • sp= sp: lr: fp=) m=ermssse3avx2bmi1bmi2dialbind on unixicmpigmpftpspop3smtpasn1quitint8uintchanfuncpartcallkind != AhomChamKawiLisuMiaoModiNewaThaiTotonameFrom.css.gif.htm.jpg.mjs.svg.xmlxn--graymenuhelpboldBoldQuitMenujpeg, xrefs: 00007FF6101AB312
        • pc=none: p=cas1cas2cas3cas4cas5cas6 at m= sp= sp: lr: fp=) m=ermssse3avx2bmi1bmi2dialbind on unixicmpigmpftpspop3smtpasn1quitint8uintchanfuncpartcallkind != AhomChamKawiLisuMiaoModiNewaThaiTotonameFrom.css.gif.htm.jpg.mjs.svg.xmlxn--graymenuhelpboldBold, xrefs: 00007FF6101AB332
        • non-Go function at pc=.localhost.localdomainmissing ']' in addressinvalid address familyoperation was canceledzero length BIT STRINGInt.Scan: invalid verbinvalid number base %dinternal inconsistencyargument list too longaddress already in usenetwork is unreach, xrefs: 00007FF6101AB445
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: pc=none: p=cas1cas2cas3cas4cas5cas6 at m= sp= sp: lr: fp=) m=ermssse3avx2bmi1bmi2dialbind on unixicmpigmpftpspop3smtpasn1quitint8uintchanfuncpartcallkind != AhomChamKawiLisuMiaoModiNewaThaiTotonameFrom.css.gif.htm.jpg.mjs.svg.xmlxn--graymenuhelpboldBold$ sp= sp: lr: fp=) m=ermssse3avx2bmi1bmi2dialbind on unixicmpigmpftpspop3smtpasn1quitint8uintchanfuncpartcallkind != AhomChamKawiLisuMiaoModiNewaThaiTotonameFrom.css.gif.htm.jpg.mjs.svg.xmlxn--graymenuhelpboldBoldQuitMenujpeg$non-Go function at pc=.localhost.localdomainmissing ']' in addressinvalid address familyoperation was canceledzero length BIT STRINGInt.Scan: invalid verbinvalid number base %dinternal inconsistencyargument list too longaddress already in usenetwork is unreach
        • API String ID: 0-2530365593
        • Opcode ID: 252ae0ff3c2ae623be827e6aa53b4a45c845b7eea3f55d11c43f8f7c460e9daa
        • Instruction ID: 01521ab6b811205e254813199735167333f8b9e75282d9f485fdd3066ebb5ce2
        • Opcode Fuzzy Hash: 252ae0ff3c2ae623be827e6aa53b4a45c845b7eea3f55d11c43f8f7c460e9daa
        • Instruction Fuzzy Hash: 0022303660CBC1D5FB609B51E4853AEA761FB89B90F544136EA8D87BAACF3CD544CB00
        Strings
        • MB) workers=min too large-byte block (runtime: val=runtime: seq=fatal error: idlethreads= syscalltick=load64 failedxadd64 failedxchg64 failednil stackbase}sched={pc:, gp->status= pluginpath= : unknown pc called from lame referralempty integerunsupported: , xrefs: 00007FF610171585
        • pacer: assist ratio=workbuf is not emptybad use of bucket.mpbad use of bucket.bpruntime: double waitws2_32.dll not foundpreempt off reason: forcegc: phase errorgopark: bad g statusgo of nil func valuewirep: already in goselectgo: bad wakeupsemaRoot rotateRight, xrefs: 00007FF610171506
        • (scan MB in pacer: % CPU ( zombie, j0 = head = panic: nmsys= locks= dying= allocs m->g0= pad1= pad2= text= minpc= value= (scan)types : type nil keywsarecvwsasendconnectlookup 2.5.4.62.5.4.32.5.4.52.5.4.72.5.4.82.5.4.9abortedCopySidWSARecvWSASendsignal i, xrefs: 00007FF610171525
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: (scan MB in pacer: % CPU ( zombie, j0 = head = panic: nmsys= locks= dying= allocs m->g0= pad1= pad2= text= minpc= value= (scan)types : type nil keywsarecvwsasendconnectlookup 2.5.4.62.5.4.32.5.4.52.5.4.72.5.4.82.5.4.9abortedCopySidWSARecvWSASendsignal i$ MB) workers=min too large-byte block (runtime: val=runtime: seq=fatal error: idlethreads= syscalltick=load64 failedxadd64 failedxchg64 failednil stackbase}sched={pc:, gp->status= pluginpath= : unknown pc called from lame referralempty integerunsupported: $pacer: assist ratio=workbuf is not emptybad use of bucket.mpbad use of bucket.bpruntime: double waitws2_32.dll not foundpreempt off reason: forcegc: phase errorgopark: bad g statusgo of nil func valuewirep: already in goselectgo: bad wakeupsemaRoot rotateRight
        • API String ID: 0-3236778523
        • Opcode ID: 35924cb4025de42fec3cfb584335521766d1d61abf2dc37a8a8b601091c62e8c
        • Instruction ID: c235040f54f4ab51819e9245eb35d657ac63a78e4eedbd22910b21e5f1654e5b
        • Opcode Fuzzy Hash: 35924cb4025de42fec3cfb584335521766d1d61abf2dc37a8a8b601091c62e8c
        • Instruction Fuzzy Hash: 4D81283291CF5595FA51DB65E0412A9B7A5FF8AFA0F448332EA4E93766CF2CE081C740
        Strings
        • gp.waiting != nilunknown caller pcstack: frame={sp:runtime: nameOff runtime: typeOff runtime: textOff 060102150405Z0700integer too large%%!%c(big.Int=%s)permission deniedwrong medium typeno data availableexec format errorLookupAccountSidWDnsRecordListFreeGetCu, xrefs: 00007FF61019A0A5
        • selectgo: bad wakeupsemaRoot rotateRightreflect.makeFuncStubdodeltimer0: wrong Ptrace: out of memoryinvalid DNS responsegetadaptersaddressesunexpected network: invalid integer typeasn1: syntax error: number has no digitsinvalid request codebad font file format, xrefs: 00007FF61019A07B
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: gp.waiting != nilunknown caller pcstack: frame={sp:runtime: nameOff runtime: typeOff runtime: textOff 060102150405Z0700integer too large%%!%c(big.Int=%s)permission deniedwrong medium typeno data availableexec format errorLookupAccountSidWDnsRecordListFreeGetCu$selectgo: bad wakeupsemaRoot rotateRightreflect.makeFuncStubdodeltimer0: wrong Ptrace: out of memoryinvalid DNS responsegetadaptersaddressesunexpected network: invalid integer typeasn1: syntax error: number has no digitsinvalid request codebad font file format
        • API String ID: 0-583483709
        • Opcode ID: 8634b7551b64b0da93f0dd62979e7d5678ef80e6e5195458227be0b86f57c4b1
        • Instruction ID: 215b3fcf1b33f7140eaff6108c212fdbd86b95c54e6fadd760b49c73266755d2
        • Opcode Fuzzy Hash: 8634b7551b64b0da93f0dd62979e7d5678ef80e6e5195458227be0b86f57c4b1
        • Instruction Fuzzy Hash: 15C28932A08F8292EB608F46E4467AA77A9FB48FA0F558136DE9D83795CF3CD454C740
        Strings
        • reflectlite.Value.IsNilindex out of range [%x]ReadMemStatsSlow (test)chan receive (nil chan)garbage collection scanmakechan: bad alignmentclose of closed channel) must be a power of 2system huge page size (runtime: s.allocCount= s.allocCount > s.nelems/gc/hea, xrefs: 00007FF6101C42ED
        • reflectlite.Value.Typeinteger divide by zeroCountPagesInUse (test)ReadMetricsSlow (test)trace reader (blocked)send on closed channelcall not at safe pointgetenv before env initinterface conversion: freeIndex is not validoldoverflow is not nils.freeindex > s.ne, xrefs: 00007FF6101C4323
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: reflectlite.Value.IsNilindex out of range [%x]ReadMemStatsSlow (test)chan receive (nil chan)garbage collection scanmakechan: bad alignmentclose of closed channel) must be a power of 2system huge page size (runtime: s.allocCount= s.allocCount > s.nelems/gc/hea$reflectlite.Value.Typeinteger divide by zeroCountPagesInUse (test)ReadMetricsSlow (test)trace reader (blocked)send on closed channelcall not at safe pointgetenv before env initinterface conversion: freeIndex is not validoldoverflow is not nils.freeindex > s.ne
        • API String ID: 0-227815786
        • Opcode ID: 2ec79d2b54654f2c6d2d8696764666edc1516fa8e5cdacc8d62f69bb32cb862b
        • Instruction ID: d905ff5e2647814cf4d07da94c044f4459c1e9479fbdd312ef6711f1b2c5a2e1
        • Opcode Fuzzy Hash: 2ec79d2b54654f2c6d2d8696764666edc1516fa8e5cdacc8d62f69bb32cb862b
        • Instruction Fuzzy Hash: A3E12B22A4CF8291FE60CB91F5413BAA7A5FB85FA0F489435EA8D87B55DF3CE4548700
        Strings
        • runtime: inconsistent write deadlineUnable to determine system directoryruntime: VirtualQuery failed; errno=runtime: sudog with non-nil waitlinkruntime: mcall called on m->g0 stackstartm: P required for spinning=true) is not Grunnable or Gscanrunnableruntime:, xrefs: 00007FF61018223D
        • runtime: inconsistent read deadlinefindrunnable: netpoll with spinningpidleput: P has non-empty run queuetraceback did not unwind completelyruntime: createevent failed; errno=crypto/md5: invalid hash state sizesuperfluous leading zeros in length'_' must separa, xrefs: 00007FF6101822A6
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: runtime: inconsistent read deadlinefindrunnable: netpoll with spinningpidleput: P has non-empty run queuetraceback did not unwind completelyruntime: createevent failed; errno=crypto/md5: invalid hash state sizesuperfluous leading zeros in length'_' must separa$runtime: inconsistent write deadlineUnable to determine system directoryruntime: VirtualQuery failed; errno=runtime: sudog with non-nil waitlinkruntime: mcall called on m->g0 stackstartm: P required for spinning=true) is not Grunnable or Gscanrunnableruntime:
        • API String ID: 0-2369679140
        • Opcode ID: 86c6cf755bfedec63f871b92cce58c9d070a42879884477fa7a4cacb85d8d30f
        • Instruction ID: 3cc41f4958b2a54c0fc1a50ab6da49698995ff09d8fe16b6d86596d276ab0ccd
        • Opcode Fuzzy Hash: 86c6cf755bfedec63f871b92cce58c9d070a42879884477fa7a4cacb85d8d30f
        • Instruction Fuzzy Hash: E5510923A0DF4695FE65CB90A0463BA67A1EB85FB0F184536EA9E837D5CF3CD5409700
        Strings
        • !"#$%%&&''((()))*++,,,,,------....//////0001123333333333444444444455666677777888888888889999999999::::::;;;;;;;;;;;;;;;;<<<<<<<<<<<<<<<<=====>>>>>>>>>>>??????????@@@@@@@@@@@@@@@@@@@@@@AAAAAAAAAAAAAAAAAAAAABBBBBBBBBBBCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC, xrefs: 00007FF61019CA5A, 00007FF61019CB3A, 00007FF61019CC50, 00007FF61019CD6C
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: !"#$%%&&''((()))*++,,,,,------....//////0001123333333333444444444455666677777888888888889999999999::::::;;;;;;;;;;;;;;;;<<<<<<<<<<<<<<<<=====>>>>>>>>>>>??????????@@@@@@@@@@@@@@@@@@@@@@AAAAAAAAAAAAAAAAAAAAABBBBBBBBBBBCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC
        • API String ID: 0-2911004680
        • Opcode ID: d63f89bb412955e5af079325a5c22b77a1b1d5fd0a5dd1b71bc0c74c9146912a
        • Instruction ID: a803f0118b5b966778501ddad38699b5562eba1156f2f92deb59ac8135064cf7
        • Opcode Fuzzy Hash: d63f89bb412955e5af079325a5c22b77a1b1d5fd0a5dd1b71bc0c74c9146912a
        • Instruction Fuzzy Hash: 69F19061A08E8A65FE109B95E5023F9A666FB44FE0F884032EA8E877D5CF7CE445C740
        Strings
        • invalid length of trace eventruntime: traceback stuck. pc=runtime: impossible type kindruntime.semasleep wait_failedcrypto/aes: invalid key size crypto/des: invalid key size crypto/rc4: invalid key size mismatched local address typeinteger not minimally-encode, xrefs: 00007FF6101A7704
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: invalid length of trace eventruntime: traceback stuck. pc=runtime: impossible type kindruntime.semasleep wait_failedcrypto/aes: invalid key size crypto/des: invalid key size crypto/rc4: invalid key size mismatched local address typeinteger not minimally-encode
        • API String ID: 0-2993922484
        • Opcode ID: 1836ae96430115e679d0462661d31ee040cefbbede3808bcc55ab55485fae765
        • Instruction ID: 8b44bbcf9e23869ff617c7684a24049b6a12fb3294e5aeb08c8397969f15f49b
        • Opcode Fuzzy Hash: 1836ae96430115e679d0462661d31ee040cefbbede3808bcc55ab55485fae765
        • Instruction Fuzzy Hash: 60D1D022A0CFCAD6FE508B95D4013AA7761FB45FA0F244136EA8E43BA5CF2CD595CB41
        Strings
        • ParseFloat%!Weekday(contentAddforegroundbackgroundSelect allvisibilitymenuExpandLiberationCreateFile/dev/stdinRIPEMD-160notifyListprofInsertstackLargemSpanInUseGOMAXPROCSstop traceinvalidptrschedtracesemacquiredebug call flushGen MB goal, s.state = s.base()=, xrefs: 00007FF6101C6C46, 00007FF6101C6D1F, 00007FF6101C6DE6
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: ParseFloat%!Weekday(contentAddforegroundbackgroundSelect allvisibilitymenuExpandLiberationCreateFile/dev/stdinRIPEMD-160notifyListprofInsertstackLargemSpanInUseGOMAXPROCSstop traceinvalidptrschedtracesemacquiredebug call flushGen MB goal, s.state = s.base()=
        • API String ID: 0-3973417152
        • Opcode ID: 00d01e0276de42b9c3f87868dc3220cd4bee0804cca2e62fd3894b4effa9f591
        • Instruction ID: b53d1e2b32a2f73a1ec27caa892a19eb63276b4ebc6548b75144b88c15904cff
        • Opcode Fuzzy Hash: 00d01e0276de42b9c3f87868dc3220cd4bee0804cca2e62fd3894b4effa9f591
        • Instruction Fuzzy Hash: 81C15C72A08F8595EB609B51F8413AAB3A4FB88FA0F449535EB8D87765DF3CE454C700
        Strings
        • bad summary dataruntime: addr = runtime: base = runtime: head = already; errno=runtime stack:invalid g statuscastogscanstatusbad g transitionschedule: in cgoreflect mismatch untyped locals missing stackmapbad symbol tablenon-Go function not in ranges:GODE, xrefs: 00007FF61017E367
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: bad summary dataruntime: addr = runtime: base = runtime: head = already; errno=runtime stack:invalid g statuscastogscanstatusbad g transitionschedule: in cgoreflect mismatch untyped locals missing stackmapbad symbol tablenon-Go function not in ranges:GODE
        • API String ID: 0-1953148292
        • Opcode ID: 2f3c693474d52ac68f634bf1c593e7638ea16859ddc89ec39470c5d3dfe79e52
        • Instruction ID: 81068feca8e20b577d584e87c74ab30c276bfab714e948f4cc886bdca1896e0c
        • Opcode Fuzzy Hash: 2f3c693474d52ac68f634bf1c593e7638ea16859ddc89ec39470c5d3dfe79e52
        • Instruction Fuzzy Hash: 5471B072A18F8592EE409B95D0413A977A5FB4AFE4F548232EE9D93796CF3CD580C340
        Strings
        • 00010203040506070809101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899<?xml version="1.0"?><!-- Generated by SVGo and Plotinum VG, xrefs: 00007FF6101CC55B
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: 00010203040506070809101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899<?xml version="1.0"?><!-- Generated by SVGo and Plotinum VG
        • API String ID: 0-4272309662
        • Opcode ID: 335d65aa143b80ba69ae09960ae173cf32ef29dbe2e789b342e87f483438da5f
        • Instruction ID: fbb52f65a63cc7c28c47262238b916c95be4bb417718493797c44af7339d55f4
        • Opcode Fuzzy Hash: 335d65aa143b80ba69ae09960ae173cf32ef29dbe2e789b342e87f483438da5f
        • Instruction Fuzzy Hash: 2051F622B4CE5E56FE2C8698922367CA651AB84FB4F959139DE0ED77C1CE2CEC41C740
        Strings
        • gcing MB, got= ... max=scav ptr ] = (usageinit ms, fault and tab= top=[...], fp:sse41sse42ssse3hostsfilesimap2imap3imapspop3sntohsint16int32int64uint8sliceGreekAdlamBamumBatakBuhidDograKhmerLatinLimbuNushuOghamOriyaOsageRunicTakriTamilUTF-8utf-8%s*%dtext/, xrefs: 00007FF61016B2C8
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: gcing MB, got= ... max=scav ptr ] = (usageinit ms, fault and tab= top=[...], fp:sse41sse42ssse3hostsfilesimap2imap3imapspop3sntohsint16int32int64uint8sliceGreekAdlamBamumBatakBuhidDograKhmerLatinLimbuNushuOghamOriyaOsageRunicTakriTamilUTF-8utf-8%s*%dtext/
        • API String ID: 0-3739349256
        • Opcode ID: 3a322f68f5dcba258d1e685d57df3124e461481a84c250d2b47c20bf408274af
        • Instruction ID: 268934a006f653ee0f054fe8263601802f42722732db309e9d13e51a93ea8ca7
        • Opcode Fuzzy Hash: 3a322f68f5dcba258d1e685d57df3124e461481a84c250d2b47c20bf408274af
        • Instruction Fuzzy Hash: 93717E32A09E46A6FB40DBA1E8823BA67A4BB45F60F41C536D94DC37A1DF7DE045C700
        Strings
        • gcmarknewobject called while doing checkmarkactive sweepers found at start of mark phaseno P available, write barriers are forbiddencompileCallback: float results not supportedcannot trace user goroutine on its own stackunsafe.Slice: ptr is nil and len is not , xrefs: 00007FF610171187
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: gcmarknewobject called while doing checkmarkactive sweepers found at start of mark phaseno P available, write barriers are forbiddencompileCallback: float results not supportedcannot trace user goroutine on its own stackunsafe.Slice: ptr is nil and len is not
        • API String ID: 0-3110597650
        • Opcode ID: 66ab3be5eb6520d4733e0726f54e12a9b5803f835c0a48eefca03a5fbcf1b4b6
        • Instruction ID: a29c38c47dd8dc5c825d353afafade3786e7e8713ed3fa0efe7b15f5ddae8320
        • Opcode Fuzzy Hash: 66ab3be5eb6520d4733e0726f54e12a9b5803f835c0a48eefca03a5fbcf1b4b6
        • Instruction Fuzzy Hash: BC21DEA3B15E8956EF018E25C4413A86B65E796FE4F8E9076CE0C47B92CE2CC180C310
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 6ad4bbeeffcb74c8a2ccb5ce296d24719f6cebb8fe9c821436144fae7ee123d1
        • Instruction ID: ec8ef162474982d47d87aca7929b6f3de48c41e575112c44cb4d54a7f9469522
        • Opcode Fuzzy Hash: 6ad4bbeeffcb74c8a2ccb5ce296d24719f6cebb8fe9c821436144fae7ee123d1
        • Instruction Fuzzy Hash: 6C320662F1CE9293FF604A95D2022BE67A1FB45FE0F484071EE4D97799DE6CE8819300
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: a1333f5d83c2dd1925072e9f66173095465b6cef118f9379983b8e2b9441fd89
        • Instruction ID: 45b16fad65c784dcabf6d54b80abebc5cb97165b5e0ea22775f62517e4727187
        • Opcode Fuzzy Hash: a1333f5d83c2dd1925072e9f66173095465b6cef118f9379983b8e2b9441fd89
        • Instruction Fuzzy Hash: 7DD14A12F0C9A195FF208692A612B7E7A52A785FA4F885071EE8D57BC6CE7CDCC0D710
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: de528f8d5946d1fc12860a0fc08bf938aa2712733b096b174a15079f20c39510
        • Instruction ID: 1ee62738166750f0375ab4262c6a84d4358b48d6b1f2cc4226fe5675afd74195
        • Opcode Fuzzy Hash: de528f8d5946d1fc12860a0fc08bf938aa2712733b096b174a15079f20c39510
        • Instruction Fuzzy Hash: 97D10623F0CE9992FE50CA56A5426BAA7A4FB85FD0F484031EE8DC7B55CE2CD945CB40
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 7eddef948b28cd2b1993eb2611c4731c5b1a71f02f37668dbe59ef0cc2ccd1f3
        • Instruction ID: 22a6e4bab305edc44caad025e159698ccc854cb30c204f0ce43005547023ed36
        • Opcode Fuzzy Hash: 7eddef948b28cd2b1993eb2611c4731c5b1a71f02f37668dbe59ef0cc2ccd1f3
        • Instruction Fuzzy Hash: 22D16272B08FC591EA609B96A8017AAB765F789FD0F448036EE8D93B99CF7CD450C700
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 48f2b2c521ae1b55f6d96cf9e5ab12a504a28c9276f4a2408df59b7e5d845ac2
        • Instruction ID: 02c5303a93dd23a7574b35a18a9cd267ee65370f2400883d449bc3a0d8841549
        • Opcode Fuzzy Hash: 48f2b2c521ae1b55f6d96cf9e5ab12a504a28c9276f4a2408df59b7e5d845ac2
        • Instruction Fuzzy Hash: 6BF16932A08F8591EAA08B55E4423BA77B5FB85FA0F55C036DA8D87B95DF3CD488C700
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: b38d7e5531262e03e38e7d63fd134cb9d18fdfa30eb4dd30112dd8ff6b0e700c
        • Instruction ID: 947293ef2ca8f061b2489ae7341e606684aae17e50c3eb806290028ccdf792eb
        • Opcode Fuzzy Hash: b38d7e5531262e03e38e7d63fd134cb9d18fdfa30eb4dd30112dd8ff6b0e700c
        • Instruction Fuzzy Hash: 0EE17332A4CF8195FE609B55E1423BAB365FB86FA0F148031EA8D97B99DF3CD4518B00
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: b739285d9161dbcf08a7083b34396fa2de3a12f312483158218e686325995c7a
        • Instruction ID: 9100b057899d733037249cb6cdcbea57e41099ad729e071f3ead9b5151024022
        • Opcode Fuzzy Hash: b739285d9161dbcf08a7083b34396fa2de3a12f312483158218e686325995c7a
        • Instruction Fuzzy Hash: CAB1D372F09E85A6FE0A878983463B86696EB44FF4F988171CE4D97786DF2CE5458300
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: bbf2c2b77e2e6a2e2985aabbb3e5f39879a37e073dac0e31404cf8ce1dc19dcc
        • Instruction ID: 48d947bbb6ddb3d664111ab31dde85d07b5745a98a1acd6fc50f300ab1ca4c6a
        • Opcode Fuzzy Hash: bbf2c2b77e2e6a2e2985aabbb3e5f39879a37e073dac0e31404cf8ce1dc19dcc
        • Instruction Fuzzy Hash: 0BB13016D1CFCB60E613577D94036762B14AEF39D4B01D73AFAC6F16A3DB162A00B922
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: f81950eb57cdedf7ee696981fb799075b2830386b822a2d81bb46f1d09e277b8
        • Instruction ID: 63053573068269b30ce0f70e6a1387a062e0c3ff981ba58ce5c3621ca4c8c5ce
        • Opcode Fuzzy Hash: f81950eb57cdedf7ee696981fb799075b2830386b822a2d81bb46f1d09e277b8
        • Instruction Fuzzy Hash: 7891FA32B1CA469AFB55CBE6A00197AA7A1FB85FD4F145035FE4D83B45CE3CE4808B40
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 6585207a936aef38389f71132a79df3df0ef6d397a2ddf555b3ca67ec38a48ef
        • Instruction ID: 724a4b2d2fe6f5affe582f2d18d229706d6bb0160ca39360b7721c7bb942a023
        • Opcode Fuzzy Hash: 6585207a936aef38389f71132a79df3df0ef6d397a2ddf555b3ca67ec38a48ef
        • Instruction Fuzzy Hash: 8DA17076618F8592EB108B55E0812AAB7A5F789BE4F545236EF9D43B9ACF3CD050CB00
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: f00cabc2ffdb691408ec2e75165ad4e240b1fe71801b78f08867384f6dc42d9b
        • Instruction ID: b62419852b37e9787b163ed3430e8210fdce37cda17770ec9acde064cbef42a5
        • Opcode Fuzzy Hash: f00cabc2ffdb691408ec2e75165ad4e240b1fe71801b78f08867384f6dc42d9b
        • Instruction Fuzzy Hash: EF916F72A18B8992EB108B55E4413AEA762F789FD0F045136EF8D97B9ACF3CD151C740
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 7ce2e951a879f108d5a0da5cc528a8fb1bc95aac0e01c85cfbb45601ae8539c0
        • Instruction ID: 02bb84347d7530eb276a0c4304df72344242db1a881e0feb564a5adcd2344572
        • Opcode Fuzzy Hash: 7ce2e951a879f108d5a0da5cc528a8fb1bc95aac0e01c85cfbb45601ae8539c0
        • Instruction Fuzzy Hash: 6571B532A0CF8196FF518B65A4523B967A1BF56FA0F049331E95E937D5CF7CD0918600
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: ad7c876f15eab11cb5793ced8ec262eb1250f0fea8228bfec39d126b129f4331
        • Instruction ID: fb3efc7e080634790b96e210bd000e52426d23ea23bd703cad85e1460bcb0b75
        • Opcode Fuzzy Hash: ad7c876f15eab11cb5793ced8ec262eb1250f0fea8228bfec39d126b129f4331
        • Instruction Fuzzy Hash: C451FA9AB45F5591BE048A938525079B371AB4FFE0799E133CE1DBB7A8DE3CE4028344
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 9949fceb29c97a5ff3d2ed4fe2d7fe3b5ef6cadb7309894e7d4fb8f05aa9de24
        • Instruction ID: 9d47b7aef51c2b383166e2e8190991bde68b62474371aa656ecd7ca0190f7aba
        • Opcode Fuzzy Hash: 9949fceb29c97a5ff3d2ed4fe2d7fe3b5ef6cadb7309894e7d4fb8f05aa9de24
        • Instruction Fuzzy Hash: F941E922F88D86DAFE109AB454433B522869B41BF4FDC4674CF2DC73D2DEACA4999510
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 6f81c73674328995e41abdd2d448dff1299f24c35ccc3e78014d1270fff2c246
        • Instruction ID: c5068b226824ef4b78d21fbc993cafc4e554d045725a76071199d0f1e5b121af
        • Opcode Fuzzy Hash: 6f81c73674328995e41abdd2d448dff1299f24c35ccc3e78014d1270fff2c246
        • Instruction Fuzzy Hash: FE4149A2F05A9551FF44896596413F492529F95FF0F889336DE2EA7BC8EF6CD8428200
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: e5fd3fa0c349f8e2a5786a3c5f6aac94008baa28ded248d482275702ce66728a
        • Instruction ID: a5e23dc55dffefb788291faaacbdcdb4fef7b5c740240fb94e4deb3583bacde1
        • Opcode Fuzzy Hash: e5fd3fa0c349f8e2a5786a3c5f6aac94008baa28ded248d482275702ce66728a
        • Instruction Fuzzy Hash: 9A4148A2F04E9651FE54896696093F892538B55FF0F5C8332ED3DA7BD8EE5CD9418200
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 344a08fdb3a7dc300b787eee98faf353a1df37f694ad734ba4c6589fd6c7b48a
        • Instruction ID: ab2754c326cf00ce99a60b7872740ed2a624aeefab0d9d90780f2382d777d2f2
        • Opcode Fuzzy Hash: 344a08fdb3a7dc300b787eee98faf353a1df37f694ad734ba4c6589fd6c7b48a
        • Instruction Fuzzy Hash: E541D4A1E0FE4655EE47DBBB94A21B4820B9F52FF4654C731D82FA72D5DF1DA1438200
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: a2a8d026b04d227592b48c56c2a5716629ca97d87f6dd987ef2c4ad1c59ff1c3
        • Instruction ID: 002fb0b6ba45b18784018efc799b1de49a4250c1c6d50add66106277284e3c44
        • Opcode Fuzzy Hash: a2a8d026b04d227592b48c56c2a5716629ca97d87f6dd987ef2c4ad1c59ff1c3
        • Instruction Fuzzy Hash: 78212CE1E29F051AEE8786769451321810A5F96FE0F28D332FC1FF6796EF28A0D34100
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 96466433a2c03ce00878ad4e07e2657575574b6c1eba3e30b20a25e781da10f8
        • Instruction ID: 800ba39d9e680cb6cbdc13bb80f6dba0c9d77cbd634a54fd81b898c5a6fd46ae
        • Opcode Fuzzy Hash: 96466433a2c03ce00878ad4e07e2657575574b6c1eba3e30b20a25e781da10f8
        • Instruction Fuzzy Hash: F321EA26A09F4991EA40CB21E44617A6764FB5AF90F158632EE9C837A6DF3DD292C700
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 22522da0feb235d61bc241b6ab79d047ddd9691d3b3c1eaf56638a5be80ed470
        • Instruction ID: a201022b2e574fc6a992b628b5c80005fe64ecd4382a10da327cb491cb594ca3
        • Opcode Fuzzy Hash: 22522da0feb235d61bc241b6ab79d047ddd9691d3b3c1eaf56638a5be80ed470
        • Instruction Fuzzy Hash: FD212F36A08F4591EB40CB25E44613A7B64FB56F90F158632EE9C83796DF3DE292C700
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 4613f57ba95712c84b12882325cc74ac45903a972ad254b4baca0ae642688a08
        • Instruction ID: 0892a5b029b4d4f1c48a554f764a2bbc752be31e6caa95930a12e68bcc4aed44
        • Opcode Fuzzy Hash: 4613f57ba95712c84b12882325cc74ac45903a972ad254b4baca0ae642688a08
        • Instruction Fuzzy Hash: ED212F36A08F4591EB40CB21E44213A7764FB56F90F159632EE9C83795DF3DD192C700
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: b104dd7ceb76ec813f41b29759a8ce65ee0d13768ae0a1bb217993d6427874db
        • Instruction ID: f70314b1d69fbcc2c32be92301d893789efd4daf491eb073cbd6cb5aa17a48b3
        • Opcode Fuzzy Hash: b104dd7ceb76ec813f41b29759a8ce65ee0d13768ae0a1bb217993d6427874db
        • Instruction Fuzzy Hash: 8B212C36A08F4591EB40CB21E44213A7764FB5AF90F158632EE9C87796DF3DD292C700
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 80dbe5b1d718c49b7bd141de5a06484d8b7aec86736f171f43b741a9e2e9315f
        • Instruction ID: b8050bc1b71a9795247d45bc694fbaa34857d6dbc0750bccde0a72b8779b89c8
        • Opcode Fuzzy Hash: 80dbe5b1d718c49b7bd141de5a06484d8b7aec86736f171f43b741a9e2e9315f
        • Instruction Fuzzy Hash: 1EE0B626614E4485D6205B29E8413967324E788BB8F580322EEBC4B7E4DE28D2628E44
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: b25eacf825189e3e93b19ac92b33b3c670eb686d7544d33950804bb1f4313672
        • Instruction ID: 47f05c3c21d2b9ef35e9ac9c2825a4ca54640e842983bad4be5be71ba6d003a1
        • Opcode Fuzzy Hash: b25eacf825189e3e93b19ac92b33b3c670eb686d7544d33950804bb1f4313672
        • Instruction Fuzzy Hash: F3C08CF0D0FE832CFFA09342B5023686AEA8F48BA4DD0C0F0C25C803649F2CA280C108
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID:
        • String ID: Address %p has no image-section$CCG $Mingw-w64 runtime failure:
        • API String ID: 0-3495338426
        • Opcode ID: 688a4f7d76c71375dbaa3942914aff0a147a051046d56fec903d79268bc5a0ae
        • Instruction ID: 31a9950472a72c4b5ec2a629fe66ad03cb5d6824d2e2619be98d06ef79962735
        • Opcode Fuzzy Hash: 688a4f7d76c71375dbaa3942914aff0a147a051046d56fec903d79268bc5a0ae
        • Instruction Fuzzy Hash: 0631CE31A48926A7FE646354A4913BD12919F89FB0F348136DA4FC73E5DF2DA881A3C0
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID: Virtual$ErrorLastProtectQuery
        • String ID: VirtualProtect failed with code 0x%x$ VirtualQuery failed for %d bytes at address %p$Address %p has no image-section
        • API String ID: 637304234-2123141913
        • Opcode ID: 2c0371cb0e6e365c05a6df6054f63aa27f2e9a8a0fcf13ecf5a9ce278bf34a63
        • Instruction ID: 7a096f42b93279a12ebcef0b8f197626adea517992851b1f16f409b4331dca78
        • Opcode Fuzzy Hash: 2c0371cb0e6e365c05a6df6054f63aa27f2e9a8a0fcf13ecf5a9ce278bf34a63
        • Instruction Fuzzy Hash: 6341AF71A19E52A1FE91DB45D8446BD27A0EF88FA0F258032CA4EC77A0DF3CE981D750
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2233217266.00007FF610151000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF610150000, based on PE: true
        • Associated: 00000000.00000002.2233199274.00007FF610150000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2233649860.00007FF6106D6000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234088231.00007FF610C41000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234122898.00007FF610C47000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234150880.00007FF610C48000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234169016.00007FF610C49000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234186046.00007FF610C4A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234202747.00007FF610C4B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234221133.00007FF610C59000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234237758.00007FF610C5A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234256183.00007FF610C61000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C62000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610C8B000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF610CEB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2234274756.00007FF6116EB000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235201855.00007FF611840000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235221399.00007FF611841000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235238990.00007FF611844000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235256152.00007FF611845000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235273413.00007FF611846000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235291896.00007FF61184A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235309286.00007FF61184B000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235328242.00007FF611855000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235346355.00007FF61185A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235364461.00007FF61185F000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235394816.00007FF611878000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235412351.00007FF61187A000.00000008.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF611883000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF61188A000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118B2000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E0000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E5000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235433863.00007FF6118E9000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235598308.00007FF6118ED000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611910000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2235636771.00007FF611930000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff610150000_SecuriteInfo.jbxd
        Similarity
        • API ID: ProtectVirtual
        • String ID: Unknown pseudo relocation bit size %d.$ Unknown pseudo relocation protocol version %d.
        • API String ID: 544645111-395989641
        • Opcode ID: 5bfe78bc8aea5759c4892b4ccba3dfaa9d3e32515f38b1b5f1b2ee47f95b297f
        • Instruction ID: f88f00cfd4f73bc9c2caab58b8516d0f41e41c1e211e57b6e394b95b8100d10e
        • Opcode Fuzzy Hash: 5bfe78bc8aea5759c4892b4ccba3dfaa9d3e32515f38b1b5f1b2ee47f95b297f
        • Instruction Fuzzy Hash: DC519876A18912E6EF50DB22D8406B923B1EF08FB4F148132D91D877A5CF3CE586DB90