Windows
Analysis Report
wsmprovhost.exe
Overview
General Information
Detection
Score: | 21 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
- wsmprovhost.exe (PID: 4784 cmdline:
"C:\Users\ user\Deskt op\wsmprov host.exe" MD5: F71DA90302D91734921FDEFEB312DC47)
- cleanup
System Summary |
---|
Source: | Author: Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Bencherchali: |
Click to jump to signature section
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Classification label: |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 DLL Side-Loading | OS Credential Dumping | 1 System Information Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1544359 |
Start date and time: | 2024-10-29 10:17:31 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 33s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 4 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | wsmprovhost.exe |
Detection: | SUS |
Classification: | sus21.winEXE@1/0@0/0 |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- VT rate limit hit for: wsmprovhost.exe
File type: | |
Entropy (8bit): | 5.586915396369068 |
TrID: |
|
File name: | wsmprovhost.exe |
File size: | 37'376 bytes |
MD5: | f71da90302d91734921fdefeb312dc47 |
SHA1: | dd7e12465bbe667554f977503ea44bfffc59cbd7 |
SHA256: | 2330ad427ec48dfe1abe51747d900a334bac7b8599388387ad7c64234964ab58 |
SHA512: | 6cb6c929be2ccaabde796e7cc4b6d83e4ccfb2e4044bb15ff1ce471242645aa61dbd408c822f9eecfef7a55f6ee93312c0bc4c2ee6eebbee976c91d4724c9ee5 |
SSDEEP: | 384:BKYYAGDVPibLECF9QAfokJr8msW5DTaChev6+31CoNHjJrk9wmW7EfW:BA+jlwq8m1MChc6+FCotjJCw4 |
TLSH: | E4F2C8559F9D8CCBCC69E73C84514269A671F4388B02D6DB401C9A1F7FEB9E6023EE60 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........................................................................................o.............Rich............PE..d....q.f... |
Icon Hash: | 00928e8e8686b000 |
Entrypoint: | 0x140002f60 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x140000000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x66AC71F9 [Fri Aug 2 05:43:21 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 10 |
OS Version Minor: | 0 |
File Version Major: | 10 |
File Version Minor: | 0 |
Subsystem Version Major: | 10 |
Subsystem Version Minor: | 0 |
Import Hash: | f01729c7436aceea744ac48f9c4dc3a6 |
Instruction |
---|
dec eax |
sub esp, 28h |
call 00007FEFACE2A010h |
dec eax |
add esp, 28h |
jmp 00007FEFACE299BBh |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
dec eax |
mov dword ptr [esp+08h], ebx |
dec eax |
mov dword ptr [esp+10h], edi |
inc ecx |
push esi |
dec eax |
sub esp, 000000B0h |
and dword ptr [esp+20h], 00000000h |
dec eax |
lea ecx, dword ptr [esp+40h] |
call dword ptr [00002305h] |
nop |
dec eax |
mov eax, dword ptr [00000030h] |
dec eax |
mov ebx, dword ptr [eax+08h] |
xor edi, edi |
xor eax, eax |
dec eax |
cmpxchg dword ptr [00007732h], ebx |
je 00007FEFACE299CBh |
dec eax |
cmp eax, ebx |
jne 00007FEFACE299B9h |
mov edi, 00000001h |
jmp 00007FEFACE299BFh |
mov ecx, 000003E8h |
call dword ptr [00002321h] |
jmp 00007FEFACE2998Ch |
mov eax, dword ptr [00007719h] |
cmp eax, 01h |
jne 00007FEFACE299BCh |
lea ecx, dword ptr [eax+1Eh] |
call 00007FEFACE29E95h |
jmp 00007FEFACE29A1Fh |
mov eax, dword ptr [00007704h] |
test eax, eax |
jne 00007FEFACE29A0Bh |
mov dword ptr [000076F6h], 00000001h |
dec esp |
lea esi, dword ptr [0000244Fh] |
dec eax |
lea ebx, dword ptr [00002430h] |
dec eax |
mov dword ptr [esp+30h], ebx |
mov dword ptr [esp+24h], eax |
dec ecx |
cmp ebx, esi |
jnc 00007FEFACE299D7h |
test eax, eax |
jne 00007FEFACE299D7h |
dec eax |
cmp dword ptr [ebx], 00000000h |
je 00007FEFACE299C2h |
dec eax |
mov eax, dword ptr [ebx] |
dec eax |
mov ecx, dword ptr [000023EEh] |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x69b0 | 0x22ec | .rdata |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x8c9c | 0x140 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xd000 | 0x7f8 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0xb000 | 0x420 | .pdata |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0xe000 | 0x80 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x5b00 | 0x38 | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x50d0 | 0xd0 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x51a0 | 0x270 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x6624 | 0x100 | .rdata |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x3110 | 0x3200 | 4329a36d8239c7be8907b6cb600bbada | False | 0.43765625 | data | 5.804970943230553 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x5000 | 0x474c | 0x4800 | 57da435683fe14f5f65851604c361ad3 | False | 0.25537109375 | data | 5.132239546739868 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0xa000 | 0x700 | 0x200 | 99fba338ca6022c889ff588253de7aa1 | False | 0.138671875 | data | 0.9039837914257391 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.pdata | 0xb000 | 0x420 | 0x600 | 5e5a593b136176912c6b0c5456640799 | False | 0.3802083333333333 | data | 3.1361090895774124 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.didat | 0xc000 | 0xb8 | 0x200 | b6a71d732aa46b3739654ecdd9303245 | False | 0.13671875 | data | 0.9634928742433803 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0xd000 | 0x7f8 | 0x800 | 2a848d5f061dd04601461e61dd739d71 | False | 0.451171875 | data | 4.579924322317571 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0xe000 | 0x80 | 0x200 | 0317123eb900eaa8204b8ea37027add2 | False | 0.21875 | data | 1.4920348671341515 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_VERSION | 0xd430 | 0x3c4 | data | English | United States | 0.45643153526970953 |
RT_MANIFEST | 0xd0a0 | 0x38a | XML 1.0 document, ASCII text, with CRLF line terminators | English | United States | 0.47902869757174393 |
DLL | Import |
---|---|
msvcrt.dll | _exit, __setusermatherr, _acmdln, __C_specific_handler, _ismbblead, _cexit, exit, _initterm, ?terminate@@YAXXZ, __set_app_type, ??1type_info@@UEAA@XZ, _commode, __getmainargs, _amsg_exit, _XcptFilter, __CxxFrameHandler3, _CxxThrowException, _fmode, memset |
api-ms-win-eventing-classicprovider-l1-1-0.dll | TraceMessage, GetTraceLoggerHandle, GetTraceEnableLevel, UnregisterTraceGuids, RegisterTraceGuidsW, GetTraceEnableFlags |
api-ms-win-core-synch-l1-2-0.dll | WaitForSingleObjectEx, SetEvent, Sleep, InitializeCriticalSection, CreateEventW, DeleteCriticalSection |
api-ms-win-core-errorhandling-l1-1-1.dll | GetLastError, UnhandledExceptionFilter, SetUnhandledExceptionFilter |
api-ms-win-core-com-l1-1-0.dll | CoUninitialize, CoRegisterClassObject, CoInitializeEx, CoInitializeSecurity, CoCreateInstance, CoRevokeClassObject |
api-ms-win-core-sysinfo-l1-2-0.dll | GetVersionExW, GetSystemTimeAsFileTime, GetTickCount |
api-ms-win-core-heap-l1-2-0.dll | HeapSetInformation |
api-ms-win-core-processthreads-l1-1-1.dll | GetCurrentProcess, GetCurrentThreadId, GetCurrentProcessId, TerminateProcess, GetStartupInfoW |
api-ms-win-core-rtlsupport-l1-2-0.dll | RtlLookupFunctionEntry, RtlCaptureContext, RtlVirtualUnwind |
api-ms-win-core-debug-l1-1-1.dll | OutputDebugStringA |
api-ms-win-core-libraryloader-l1-1-1.dll | GetModuleHandleW |
api-ms-win-core-profile-l1-1-0.dll | QueryPerformanceCounter |
WsmSvc.DLL | ?Alloc@WSManMemory@@SAPEAX_KHW4_NitsFaultMode@@@Z, ??1CWSManCriticalSection@@QEAA@XZ, WSManError, CreateProvHost, ?Free@WSManMemory@@SAXPEAXH@Z |
api-ms-win-core-apiquery-l1-1-0.dll | ApiSetQueryApiSetPresence |
api-ms-win-core-delayload-l1-1-1.dll | DelayLoadFailureHook, ResolveDelayLoadedAPI |
Name | Ordinal | Address |
---|---|---|
??0?$SafeMap@VKey@Locale@@KV?$SafeMap_Iterator@VKey@Locale@@K@@@@QEAA@XZ | 1 | 0x140001820 |
??0?$SafeMap_Iterator@VKey@Locale@@K@@QEAA@AEAV?$SafeMap@VKey@Locale@@KV?$SafeMap_Iterator@VKey@Locale@@K@@@@_N@Z | 2 | 0x140001b70 |
??0?$SafeMap_Lock@VKey@Locale@@KV?$SafeMap_Iterator@VKey@Locale@@K@@@@QEAA@AEBV?$SafeMap@VKey@Locale@@KV?$SafeMap_Iterator@VKey@Locale@@K@@@@_N@Z | 3 | 0x140001c70 |
??1?$SafeMap@PEAVCListenerOperation@@UEmpty@@V?$SafeSet_Iterator@PEAVCListenerOperation@@@@@@QEAA@XZ | 4 | 0x1400010c0 |
??1?$SafeMap@PEAVIOperation@@UEmpty@@V?$SafeSet_Iterator@PEAVIOperation@@@@@@QEAA@XZ | 5 | 0x140001060 |
??1?$SafeMap@UPluginKey@@KV?$SafeMap_Iterator@UPluginKey@@K@@@@QEAA@XZ | 6 | 0x140001600 |
??1?$SafeMap@VKey@Locale@@KV?$SafeMap_Iterator@VKey@Locale@@K@@@@QEAA@XZ | 7 | 0x1400017c0 |
??1?$SafeMap_Iterator@PEAVCListenerOperation@@UEmpty@@@@QEAA@XZ | 8 | 0x1400012b0 |
??1?$SafeMap_Iterator@PEAVIOperation@@UEmpty@@@@QEAA@XZ | 9 | 0x1400012b0 |
??1?$SafeMap_Iterator@UPluginKey@@K@@QEAA@XZ | 10 | 0x1400012b0 |
??1?$SafeMap_Iterator@VKey@Locale@@K@@QEAA@XZ | 11 | 0x1400012b0 |
??1?$SafeMap_Lock@PEAVCListenerOperation@@UEmpty@@V?$SafeMap_Iterator@PEAVCListenerOperation@@UEmpty@@@@@@QEAA@XZ | 12 | 0x140001a00 |
??1?$SafeMap_Lock@PEAVIOperation@@UEmpty@@V?$SafeMap_Iterator@PEAVIOperation@@UEmpty@@@@@@QEAA@XZ | 13 | 0x140001a00 |
??1?$SafeMap_Lock@UPluginKey@@KV?$SafeMap_Iterator@UPluginKey@@K@@@@QEAA@XZ | 14 | 0x140001a00 |
??1?$SafeMap_Lock@VKey@Locale@@KV?$SafeMap_Iterator@VKey@Locale@@K@@@@QEAA@XZ | 15 | 0x140001a00 |
??1?$SafeSet@PEAVCListenerOperation@@@@QEAA@XZ | 16 | 0x1400010c0 |
??1?$SafeSet@PEAVIOperation@@@@QEAA@XZ | 17 | 0x140001060 |
??1?$SafeSet_Iterator@PEAVCListenerOperation@@@@QEAA@XZ | 18 | 0x140001050 |
??1?$SafeSet_Iterator@PEAVIOperation@@@@QEAA@XZ | 19 | 0x140001050 |
??1CWSManCriticalSectionWithConditionVar@@QEAA@XZ | 20 | 0x140001040 |
??_7?$SafeMap@PEAVCListenerOperation@@UEmpty@@V?$SafeSet_Iterator@PEAVCListenerOperation@@@@@@6B@ | 21 | 0x140005088 |
??_7?$SafeMap@PEAVIOperation@@UEmpty@@V?$SafeSet_Iterator@PEAVIOperation@@@@@@6B@ | 22 | 0x140005048 |
??_7?$SafeMap@UPluginKey@@KV?$SafeMap_Iterator@UPluginKey@@K@@@@6B@ | 23 | 0x140005028 |
??_7?$SafeMap@VKey@Locale@@KV?$SafeMap_Iterator@VKey@Locale@@K@@@@6B@ | 24 | 0x140005068 |
?Acquire@?$SafeMap@PEAVCListenerOperation@@UEmpty@@V?$SafeMap_Iterator@PEAVCListenerOperation@@UEmpty@@@@@@UEBAXXZ | 25 | 0x140001140 |
?Acquire@?$SafeMap@PEAVCListenerOperation@@UEmpty@@V?$SafeSet_Iterator@PEAVCListenerOperation@@@@@@UEBAXXZ | 26 | 0x140001140 |
?Acquire@?$SafeMap@PEAVIOperation@@UEmpty@@V?$SafeMap_Iterator@PEAVIOperation@@UEmpty@@@@@@UEBAXXZ | 27 | 0x140001140 |
?Acquire@?$SafeMap@PEAVIOperation@@UEmpty@@V?$SafeSet_Iterator@PEAVIOperation@@@@@@UEBAXXZ | 28 | 0x140001140 |
?Acquire@?$SafeMap@UPluginKey@@KV?$SafeMap_Iterator@UPluginKey@@K@@@@UEBAXXZ | 29 | 0x140001140 |
?Acquire@?$SafeMap@UUserKey@@PEAVBlockedRecord@@V?$SafeMap_Iterator@UUserKey@@PEAVBlockedRecord@@@@@@UEBAXXZ | 30 | 0x140001140 |
?Acquire@?$SafeMap@VKey@Locale@@KV?$SafeMap_Iterator@VKey@Locale@@K@@@@UEBAXXZ | 31 | 0x140001140 |
?Acquire@?$SafeMap@VStringKeyStore@@PEAVServerFullDuplexChannel@@V?$SafeMap_Iterator@VStringKeyStore@@PEAVServerFullDuplexChannel@@@@@@UEBAXXZ | 32 | 0x140001140 |
?Acquire@?$SafeMap_Lock@VKey@Locale@@KV?$SafeMap_Iterator@VKey@Locale@@K@@@@QEAAXXZ | 33 | 0x140001d20 |
?Acquired@?$SafeMap_Lock@PEAVCListenerOperation@@UEmpty@@V?$SafeMap_Iterator@PEAVCListenerOperation@@UEmpty@@@@@@QEAA_NXZ | 34 | 0x1400019f0 |
?Acquired@?$SafeMap_Lock@PEAVIOperation@@UEmpty@@V?$SafeMap_Iterator@PEAVIOperation@@UEmpty@@@@@@QEAA_NXZ | 35 | 0x1400019f0 |
?Acquired@?$SafeMap_Lock@UPluginKey@@KV?$SafeMap_Iterator@UPluginKey@@K@@@@QEAA_NXZ | 36 | 0x1400019f0 |
?Acquired@?$SafeMap_Lock@VKey@Locale@@KV?$SafeMap_Iterator@VKey@Locale@@K@@@@QEAA_NXZ | 37 | 0x1400019f0 |
?AsReference@?$SafeMap@VKey@Locale@@KV?$SafeMap_Iterator@VKey@Locale@@K@@@@QEAAAEAV1@XZ | 38 | 0x140001b60 |
?Data@?$SafeMap_Iterator@VKey@Locale@@K@@IEBAAEAV?$STLMap@VKey@Locale@@K@@XZ | 39 | 0x140001e40 |
?DeInitialize@?$SafeMap@PEAVCListenerOperation@@UEmpty@@V?$SafeMap_Iterator@PEAVCListenerOperation@@UEmpty@@@@@@UEAA_NAEAVIRequestContext@@@Z | 40 | 0x140001340 |
?DeInitialize@?$SafeMap@PEAVCListenerOperation@@UEmpty@@V?$SafeSet_Iterator@PEAVCListenerOperation@@@@@@UEAA_NAEAVIRequestContext@@@Z | 41 | 0x140001340 |
?DeInitialize@?$SafeMap@PEAVIOperation@@UEmpty@@V?$SafeMap_Iterator@PEAVIOperation@@UEmpty@@@@@@UEAA_NAEAVIRequestContext@@@Z | 42 | 0x140001340 |
?DeInitialize@?$SafeMap@PEAVIOperation@@UEmpty@@V?$SafeSet_Iterator@PEAVIOperation@@@@@@UEAA_NAEAVIRequestContext@@@Z | 43 | 0x140001340 |
?DeInitialize@?$SafeMap@UPluginKey@@KV?$SafeMap_Iterator@UPluginKey@@K@@@@UEAA_NAEAVIRequestContext@@@Z | 44 | 0x140001340 |
?DeInitialize@?$SafeMap@UUserKey@@PEAVBlockedRecord@@V?$SafeMap_Iterator@UUserKey@@PEAVBlockedRecord@@@@@@UEAA_NAEAVIRequestContext@@@Z | 45 | 0x1400014a0 |
?DeInitialize@?$SafeMap@VKey@Locale@@KV?$SafeMap_Iterator@VKey@Locale@@K@@@@UEAA_NAEAVIRequestContext@@@Z | 46 | 0x140001660 |
?DeInitialize@?$SafeMap@VStringKeyStore@@PEAVServerFullDuplexChannel@@V?$SafeMap_Iterator@VStringKeyStore@@PEAVServerFullDuplexChannel@@@@@@UEAA_NAEAVIRequestContext@@@Z | 47 | 0x140001150 |
?GetInitError@CWSManCriticalSection@@QEBAKXZ | 48 | 0x140001030 |
?GetMap@?$SafeMap_Iterator@PEAVCListenerOperation@@UEmpty@@@@QEBAAEAV?$SafeMap@PEAVCListenerOperation@@UEmpty@@V?$SafeMap_Iterator@PEAVCListenerOperation@@UEmpty@@@@@@XZ | 49 | 0x140001a30 |
?GetMap@?$SafeMap_Iterator@PEAVIOperation@@UEmpty@@@@QEBAAEAV?$SafeMap@PEAVIOperation@@UEmpty@@V?$SafeMap_Iterator@PEAVIOperation@@UEmpty@@@@@@XZ | 50 | 0x140001a30 |
?GetMap@?$SafeMap_Iterator@UPluginKey@@K@@QEBAAEAV?$SafeMap@UPluginKey@@KV?$SafeMap_Iterator@UPluginKey@@K@@@@XZ | 51 | 0x140001a30 |
?GetMap@?$SafeMap_Iterator@VKey@Locale@@K@@QEBAAEAV?$SafeMap@VKey@Locale@@KV?$SafeMap_Iterator@VKey@Locale@@K@@@@XZ | 52 | 0x140001a30 |
?GetMap@?$SafeMap_Lock@PEAVCListenerOperation@@UEmpty@@V?$SafeMap_Iterator@PEAVCListenerOperation@@UEmpty@@@@@@QEBAAEBV?$SafeMap@PEAVCListenerOperation@@UEmpty@@V?$SafeMap_Iterator@PEAVCListenerOperation@@UEmpty@@@@@@XZ | 53 | 0x140001a30 |
?GetMap@?$SafeMap_Lock@PEAVIOperation@@UEmpty@@V?$SafeMap_Iterator@PEAVIOperation@@UEmpty@@@@@@QEBAAEBV?$SafeMap@PEAVIOperation@@UEmpty@@V?$SafeMap_Iterator@PEAVIOperation@@UEmpty@@@@@@XZ | 54 | 0x140001a30 |
?GetMap@?$SafeMap_Lock@UPluginKey@@KV?$SafeMap_Iterator@UPluginKey@@K@@@@QEBAAEBV?$SafeMap@UPluginKey@@KV?$SafeMap_Iterator@UPluginKey@@K@@@@XZ | 55 | 0x140001a30 |
?GetMap@?$SafeMap_Lock@VKey@Locale@@KV?$SafeMap_Iterator@VKey@Locale@@K@@@@QEBAAEBV?$SafeMap@VKey@Locale@@KV?$SafeMap_Iterator@VKey@Locale@@K@@@@XZ | 56 | 0x140001a30 |
?Initialize@?$SafeMap@PEAVCListenerOperation@@UEmpty@@V?$SafeMap_Iterator@PEAVCListenerOperation@@UEmpty@@@@@@UEAA_NAEAVIRequestContext@@@Z | 57 | 0x1400013b0 |
?Initialize@?$SafeMap@PEAVCListenerOperation@@UEmpty@@V?$SafeSet_Iterator@PEAVCListenerOperation@@@@@@UEAA_NAEAVIRequestContext@@@Z | 58 | 0x1400013b0 |
?Initialize@?$SafeMap@PEAVIOperation@@UEmpty@@V?$SafeMap_Iterator@PEAVIOperation@@UEmpty@@@@@@UEAA_NAEAVIRequestContext@@@Z | 59 | 0x1400013b0 |
?Initialize@?$SafeMap@PEAVIOperation@@UEmpty@@V?$SafeSet_Iterator@PEAVIOperation@@@@@@UEAA_NAEAVIRequestContext@@@Z | 60 | 0x1400013b0 |
?Initialize@?$SafeMap@UPluginKey@@KV?$SafeMap_Iterator@UPluginKey@@K@@@@UEAA_NAEAVIRequestContext@@@Z | 61 | 0x1400013b0 |
?Initialize@?$SafeMap@UUserKey@@PEAVBlockedRecord@@V?$SafeMap_Iterator@UUserKey@@PEAVBlockedRecord@@@@@@UEAA_NAEAVIRequestContext@@@Z | 62 | 0x140001510 |
?Initialize@?$SafeMap@VKey@Locale@@KV?$SafeMap_Iterator@VKey@Locale@@K@@@@UEAA_NAEAVIRequestContext@@@Z | 63 | 0x1400016d0 |
?Initialize@?$SafeMap@VStringKeyStore@@PEAVServerFullDuplexChannel@@V?$SafeMap_Iterator@VStringKeyStore@@PEAVServerFullDuplexChannel@@@@@@UEAA_NAEAVIRequestContext@@@Z | 64 | 0x1400011c0 |
?IsValid@?$SafeMap@VStringKeyStore@@PEAVServerFullDuplexChannel@@V?$SafeMap_Iterator@VStringKeyStore@@PEAVServerFullDuplexChannel@@@@@@QEBA_NXZ | 65 | 0x140001120 |
?IsValid@?$SafeMap_Iterator@PEAVCListenerOperation@@UEmpty@@@@QEBA_NXZ | 66 | 0x140001950 |
?IsValid@?$SafeMap_Iterator@PEAVIOperation@@UEmpty@@@@QEBA_NXZ | 67 | 0x140001950 |
?IsValid@?$SafeMap_Iterator@UPluginKey@@K@@QEBA_NXZ | 68 | 0x140001950 |
?IsValid@?$SafeMap_Iterator@UUserKey@@PEAVBlockedRecord@@@@QEBA_NXZ | 69 | 0x140001950 |
?IsValid@?$SafeMap_Iterator@VKey@Locale@@K@@QEBA_NXZ | 70 | 0x140001950 |
?IsValid@?$SafeMap_Iterator@VStringKeyStore@@PEAVServerFullDuplexChannel@@@@QEBA_NXZ | 71 | 0x140001950 |
?Release@?$SafeMap@PEAVCListenerOperation@@UEmpty@@V?$SafeMap_Iterator@PEAVCListenerOperation@@UEmpty@@@@@@UEBAXXZ | 72 | 0x140001140 |
?Release@?$SafeMap@PEAVCListenerOperation@@UEmpty@@V?$SafeSet_Iterator@PEAVCListenerOperation@@@@@@UEBAXXZ | 73 | 0x140001140 |
?Release@?$SafeMap@PEAVIOperation@@UEmpty@@V?$SafeMap_Iterator@PEAVIOperation@@UEmpty@@@@@@UEBAXXZ | 74 | 0x140001140 |
?Release@?$SafeMap@PEAVIOperation@@UEmpty@@V?$SafeSet_Iterator@PEAVIOperation@@@@@@UEBAXXZ | 75 | 0x140001140 |
?Release@?$SafeMap@UPluginKey@@KV?$SafeMap_Iterator@UPluginKey@@K@@@@UEBAXXZ | 76 | 0x140001140 |
?Release@?$SafeMap@UUserKey@@PEAVBlockedRecord@@V?$SafeMap_Iterator@UUserKey@@PEAVBlockedRecord@@@@@@UEBAXXZ | 77 | 0x140001140 |
?Release@?$SafeMap@VKey@Locale@@KV?$SafeMap_Iterator@VKey@Locale@@K@@@@UEBAXXZ | 78 | 0x140001140 |
?Release@?$SafeMap@VStringKeyStore@@PEAVServerFullDuplexChannel@@V?$SafeMap_Iterator@VStringKeyStore@@PEAVServerFullDuplexChannel@@@@@@UEBAXXZ | 79 | 0x140001140 |
?Reset@?$SafeMap_Iterator@VKey@Locale@@K@@QEAAXXZ | 80 | 0x140001cb0 |
?SkipOrphans@?$SafeMap_Iterator@VKey@Locale@@K@@IEAAXXZ | 81 | 0x140001d80 |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Target ID: | 0 |
Start time: | 05:18:22 |
Start date: | 29/10/2024 |
Path: | C:\Users\user\Desktop\wsmprovhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7ecb10000 |
File size: | 37'376 bytes |
MD5 hash: | F71DA90302D91734921FDEFEB312DC47 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |