Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
8F0oMWUhg7.exe

Overview

General Information

Sample name:8F0oMWUhg7.exe
renamed because original name is a hash value
Original sample name:ac6323cfb95cc48955949b4d2e7f91a5.exe
Analysis ID:1557672
MD5:ac6323cfb95cc48955949b4d2e7f91a5
SHA1:525a7271bef3988185b4f2be7d797b2dfab8bcd0
SHA256:a681393f417174f96a6f0814677b28d81884fb836b501de132eb0003e4782eac
Tags:exeMeduzaStealeruser-abuse_ch
Infos:

Detection

CredGrabber, Meduza Stealer
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected CredGrabber
Yara detected Meduza Stealer
AI detected suspicious sample
Found many strings related to Crypto-Wallets (likely being stolen)
Machine Learning detection for sample
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to dynamically determine API calls
Contains functionality to launch a program with higher privileges
Contains functionality to query locales information (e.g. system language)
Contains functionality to record screenshots
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Enables debug privileges
Found evasive API chain checking for process token information
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May check the online IP address of the machine
Queries the volume information (name, serial number etc) of a device
Queries time zone information
Suricata IDS alerts with low severity for network traffic
Terminates after testing mutex exists (may check infected machine status)
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer

Classification

  • System is w10x64
  • 8F0oMWUhg7.exe (PID: 4896 cmdline: "C:\Users\user\Desktop\8F0oMWUhg7.exe" MD5: AC6323CFB95CC48955949B4D2E7F91A5)
  • cleanup
{"C2 url": "193.3.19.151", "grabber_max_size": 4194304, "anti_vm": true, "anti_dbg": true, "self_destruct": false, "extensions": ".txt", "build_name": "enew", "links": "", "port": 15666}
SourceRuleDescriptionAuthorStrings
8F0oMWUhg7.exeJoeSecurity_MeduzaStealerYara detected Meduza StealerJoe Security
    SourceRuleDescriptionAuthorStrings
    00000000.00000002.2288125378.00000170CDF3C000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_MeduzaStealerYara detected Meduza StealerJoe Security
      Process Memory Space: 8F0oMWUhg7.exe PID: 4896JoeSecurity_MeduzaStealerYara detected Meduza StealerJoe Security
        Process Memory Space: 8F0oMWUhg7.exe PID: 4896JoeSecurity_CredGrabberYara detected CredGrabberJoe Security
          Process Memory Space: 8F0oMWUhg7.exe PID: 4896JoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
            SourceRuleDescriptionAuthorStrings
            0.0.8F0oMWUhg7.exe.7ff6ebf50000.0.unpackJoeSecurity_MeduzaStealerYara detected Meduza StealerJoe Security
              0.2.8F0oMWUhg7.exe.7ff6ebf50000.0.unpackJoeSecurity_MeduzaStealerYara detected Meduza StealerJoe Security
                No Sigma rule has matched
                TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                2024-11-18T14:28:30.771762+010020494411A Network Trojan was detected192.168.2.649710193.3.19.15115666TCP
                TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                2024-11-18T14:28:30.771762+010020508061A Network Trojan was detected192.168.2.649710193.3.19.15115666TCP
                2024-11-18T14:28:30.776994+010020508061A Network Trojan was detected192.168.2.649710193.3.19.15115666TCP
                TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                2024-11-18T14:28:30.771762+010020508071A Network Trojan was detected192.168.2.649710193.3.19.15115666TCP
                2024-11-18T14:28:30.776994+010020508071A Network Trojan was detected192.168.2.649710193.3.19.15115666TCP

                Click to jump to signature section

                Show All Signature Results

                AV Detection

                barindex
                Source: 8F0oMWUhg7.exeMalware Configuration Extractor: Meduza Stealer {"C2 url": "193.3.19.151", "grabber_max_size": 4194304, "anti_vm": true, "anti_dbg": true, "self_destruct": false, "extensions": ".txt", "build_name": "enew", "links": "", "port": 15666}
                Source: 8F0oMWUhg7.exeReversingLabs: Detection: 23%
                Source: Submited SampleIntegrated Neural Analysis Model: Matched 99.9% probability
                Source: 8F0oMWUhg7.exeJoe Sandbox ML: detected
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFC7BA0 CryptUnprotectData,LocalFree,0_2_00007FF6EBFC7BA0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFC7EC0 CryptProtectData,LocalFree,0_2_00007FF6EBFC7EC0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFC8020 BCryptDecrypt,BCryptDecrypt,_invalid_parameter_noinfo_noreturn,0_2_00007FF6EBFC8020
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF83A30 BCryptDestroyKey,0_2_00007FF6EBF83A30
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF87C20 CryptUnprotectData,LocalFree,_invalid_parameter_noinfo_noreturn,0_2_00007FF6EBF87C20
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFC83C0 BCryptCloseAlgorithmProvider,_invalid_parameter_noinfo_noreturn,0_2_00007FF6EBFC83C0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFC8440 BCryptOpenAlgorithmProvider,BCryptSetProperty,BCryptGenerateSymmetricKey,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,Concurrency::cancel_current_task,0_2_00007FF6EBFC8440
                Source: unknownHTTPS traffic detected: 104.26.12.205:443 -> 192.168.2.6:49711 version: TLS 1.2
                Source: 8F0oMWUhg7.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EC00B5B0 GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,__std_fs_open_handle,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,CloseHandle,CloseHandle,0_2_00007FF6EC00B5B0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EC00B500 FindClose,FindFirstFileExW,GetLastError,0_2_00007FF6EC00B500
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFD73F0 GetLogicalDriveStringsW,_invalid_parameter_noinfo_noreturn,0_2_00007FF6EBFD73F0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: D:\sources\migration\Jump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: D:\sources\replacementmanifests\Jump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: D:\sources\migration\wtr\Jump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: D:\sources\replacementmanifests\microsoft-activedirectory-webservices\Jump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: D:\sources\replacementmanifests\microsoft-client-license-platform-service-migration\Jump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: D:\sources\replacementmanifests\hwvid-migration-2\Jump to behavior

                Networking

                barindex
                Source: Network trafficSuricata IDS: 2049441 - Severity 1 - ET MALWARE Win32/Unknown Grabber Base64 Data Exfiltration Attempt : 192.168.2.6:49710 -> 193.3.19.151:15666
                Source: Network trafficSuricata IDS: 2050806 - Severity 1 - ET MALWARE [ANY.RUN] Meduza Stealer Exfiltration M2 : 192.168.2.6:49710 -> 193.3.19.151:15666
                Source: global trafficTCP traffic: 192.168.2.6:49710 -> 193.3.19.151:15666
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Accept: text/html; text/plain; */*Host: api.ipify.orgCache-Control: no-cache
                Source: Joe Sandbox ViewIP Address: 104.26.12.205 104.26.12.205
                Source: Joe Sandbox ViewIP Address: 104.26.12.205 104.26.12.205
                Source: Joe Sandbox ViewASN Name: ARNES-NETAcademicandResearchNetworkofSloveniaSI ARNES-NETAcademicandResearchNetworkofSloveniaSI
                Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
                Source: unknownDNS query: name: api.ipify.org
                Source: unknownDNS query: name: api.ipify.org
                Source: Network trafficSuricata IDS: 2050807 - Severity 1 - ET MALWARE [ANY.RUN] Possible Meduza Stealer Exfiltration (TCP) : 192.168.2.6:49710 -> 193.3.19.151:15666
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.151
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFD4A30 recv,recv,closesocket,WSACleanup,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF6EBFD4A30
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Accept: text/html; text/plain; */*Host: api.ipify.orgCache-Control: no-cache
                Source: global trafficDNS traffic detected: DNS query: api.ipify.org
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2189504933.00000170D0781000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2287442237.00000170D0790000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2287413441.00000170D0790000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2287552722.00000170D0794000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ns.microsoft.t/Regi
                Source: 8F0oMWUhg7.exe, 00000000.00000002.2288125378.00000170CDFA1000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2190136548.00000170CDFB7000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000002.2288125378.00000170CDF3C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.ipify.org/
                Source: 8F0oMWUhg7.exe, 00000000.00000002.2288125378.00000170CDF3C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.ipify.orgN
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2209282971.00000170D0968000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bridge.sfo1.admarketplace.net/ctp?version=16.0.0&key=1696484494400800000.2&ci=1696484494189.
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2208740371.00000170D0A48000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2210217485.00000170CDFDE000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2209282971.00000170D0968000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bridge.sfo1.ap01.net/ctp?version=16.0.0&key=1696484494400800000.1&ci=1696484494189.12791&cta
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2209282971.00000170D0968000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://contile-images.services.mozilla.com/T23eBL4EHswiSaF6kya2gYsRHvdfADK-NYjs1mVRNGE.3351.jpg
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2208740371.00000170D0A48000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2210217485.00000170CDFDE000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2209282971.00000170D0968000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://contile-images.services.mozilla.com/obgoOYObjIFea_bXuT6L4LbBJ8j425AD87S1HMD3BWg.9991.jpg
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2220956682.00000170CE008000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://go.microsoft.co
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2220956682.00000170CE008000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://go.microsoft.coan
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2209282971.00000170D0968000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://imp.mt48.net/static?id=7RHzfOIXjFEYsBdvIpkX4Qqm4pLk4pqk4pbW1pbWfpbW7ReNxR3UIG8zInwYIFIVs9eYi
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2201970579.00000170CFDE0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2201970579.00000170CFE44000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2201970579.00000170CFE44000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/products/firefoxgro.allizom.troppus.ZAnPVwXvBbYt
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2208740371.00000170D0A48000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2210217485.00000170CDFDE000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2209282971.00000170D0968000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.amazon.com/?tag=admarketus-20&ref=pd_sl_86277c656a4bd7d619968160e91c45fd066919bb3bd119b3
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2206721017.00000170D1503000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2201970579.00000170CFDE8000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2208386177.00000170D0B01000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2201970579.00000170CFEBB000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2201970579.00000170CFE3C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2201970579.00000170CFDE0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org#
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2201970579.00000170CFE44000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/about/gro.allizom.www.bwSC1pmG_zle
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2201970579.00000170CFE44000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/contribute/gro.allizom.www.hjKdHaZH-dbQ
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2201970579.00000170CFE44000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/firefox/?utm_medium=firefox-desktop&utm_source=bookmarks-toolbar&utm_campaig
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2209282971.00000170D0968000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.t-mobile.com/cell-phones/brand/apple?cmpid=MGPO_PAM_P_EVGRNIPHN_
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
                Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
                Source: unknownHTTPS traffic detected: 104.26.12.205:443 -> 192.168.2.6:49711 version: TLS 1.2
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFD5B70 GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetDC,GetDeviceCaps,GetDeviceCaps,CreateCompatibleDC,CreateCompatibleBitmap,SelectObject,BitBlt,SHCreateMemStream,SelectObject,DeleteDC,ReleaseDC,DeleteObject,EnterCriticalSection,LeaveCriticalSection,IStream_Size,IStream_Reset,IStream_Read,SelectObject,DeleteDC,ReleaseDC,DeleteObject,0_2_00007FF6EBFD5B70
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFD9D30 GetModuleHandleA,GetProcAddress,OpenProcess,NtQuerySystemInformation,NtQuerySystemInformation,GetCurrentProcess,NtQueryObject,GetFinalPathNameByHandleA,CloseHandle,CloseHandle,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF6EBFD9D30
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFDA430 RtlAcquirePebLock,NtAllocateVirtualMemory,lstrcpyW,lstrcatW,NtAllocateVirtualMemory,lstrcpyW,RtlInitUnicodeString,RtlInitUnicodeString,LdrEnumerateLoadedModules,RtlReleasePebLock,_invalid_parameter_noinfo_noreturn,CoInitializeEx,lstrcpyW,lstrcatW,CoGetObject,lstrcpyW,lstrcatW,CoGetObject,CoUninitialize,0_2_00007FF6EBFDA430
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF7FE200_2_00007FF6EBF7FE20
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFF2E3C0_2_00007FF6EBFF2E3C
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF99F800_2_00007FF6EBF99F80
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFCF0200_2_00007FF6EBFCF020
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFDD0500_2_00007FF6EBFDD050
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFBD0800_2_00007FF6EBFBD080
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF820B00_2_00007FF6EBF820B0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFB59700_2_00007FF6EBFB5970
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF8CA100_2_00007FF6EBF8CA10
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFD5B700_2_00007FF6EBFD5B70
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF84B700_2_00007FF6EBF84B70
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF81B900_2_00007FF6EBF81B90
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF82CA00_2_00007FF6EBF82CA0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF8ECB00_2_00007FF6EBF8ECB0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF8D5700_2_00007FF6EBF8D570
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EC00B5B00_2_00007FF6EC00B5B0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFDC5CB0_2_00007FF6EBFDC5CB
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF8E6100_2_00007FF6EBF8E610
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EC0106580_2_00007FF6EC010658
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFD76A00_2_00007FF6EBFD76A0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF7F7300_2_00007FF6EBF7F730
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFD68600_2_00007FF6EBFD6860
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFE918C0_2_00007FF6EBFE918C
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFD52400_2_00007FF6EBFD5240
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF953100_2_00007FF6EBF95310
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFD83300_2_00007FF6EBFD8330
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFB63500_2_00007FF6EBFB6350
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF804500_2_00007FF6EBF80450
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFC4D400_2_00007FF6EBFC4D40
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFE8D500_2_00007FF6EBFE8D50
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF55DB00_2_00007FF6EBF55DB0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFABDD00_2_00007FF6EBFABDD0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF8ADD00_2_00007FF6EBF8ADD0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF87E700_2_00007FF6EBF87E70
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF80E800_2_00007FF6EBF80E80
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFD0E900_2_00007FF6EBFD0E90
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFC5EF00_2_00007FF6EBFC5EF0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF8BF400_2_00007FF6EBF8BF40
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EC00FFBC0_2_00007FF6EC00FFBC
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFF30B80_2_00007FF6EBFF30B8
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFEF0D80_2_00007FF6EBFEF0D8
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF570E00_2_00007FF6EBF570E0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFAC0F00_2_00007FF6EBFAC0F0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFFC1280_2_00007FF6EBFFC128
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF83A300_2_00007FF6EBF83A30
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFF6A680_2_00007FF6EBFF6A68
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF80A800_2_00007FF6EBF80A80
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFABAB00_2_00007FF6EBFABAB0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFC5AB00_2_00007FF6EBFC5AB0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFB0AC00_2_00007FF6EBFB0AC0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFA1AF00_2_00007FF6EBFA1AF0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFC8B000_2_00007FF6EBFC8B00
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFFBB900_2_00007FF6EBFFBB90
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFA7CEB0_2_00007FF6EBFA7CEB
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFE0D140_2_00007FF6EBFE0D14
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFD65400_2_00007FF6EBFD6540
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFE55980_2_00007FF6EBFE5598
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF566100_2_00007FF6EBF56610
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFF86740_2_00007FF6EBFF8674
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFE666C0_2_00007FF6EBFE666C
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFF36A80_2_00007FF6EBFF36A8
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFF46E40_2_00007FF6EBFF46E4
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFA47200_2_00007FF6EBFA4720
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFB27500_2_00007FF6EBFB2750
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFAB7800_2_00007FF6EBFAB780
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFDA7800_2_00007FF6EBFDA780
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFE579C0_2_00007FF6EBFE579C
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFEF7E60_2_00007FF6EBFEF7E6
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF898CD0_2_00007FF6EBF898CD
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFCC8E00_2_00007FF6EBFCC8E0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFEA9240_2_00007FF6EBFEA924
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFE31500_2_00007FF6EBFE3150
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFE61640_2_00007FF6EBFE6164
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF561800_2_00007FF6EBF56180
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFF71D80_2_00007FF6EBFF71D8
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFE12200_2_00007FF6EBFE1220
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFC02C00_2_00007FF6EBFC02C0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFCE2F00_2_00007FF6EBFCE2F0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFE53940_2_00007FF6EBFE5394
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFC63A60_2_00007FF6EBFC63A6
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF783D00_2_00007FF6EBF783D0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFFA3C80_2_00007FF6EBFFA3C8
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFAC4200_2_00007FF6EBFAC420
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFCB4200_2_00007FF6EBFCB420
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFDA4300_2_00007FF6EBFDA430
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFFA44F0_2_00007FF6EBFFA44F
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFAB4800_2_00007FF6EBFAB480
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFF14E40_2_00007FF6EBFF14E4
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF765100_2_00007FF6EBF76510
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF755200_2_00007FF6EBF75520
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: String function: 00007FF6EBF986B0 appears 54 times
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: String function: 00007FF6EBFE8254 appears 34 times
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: String function: 00007FF6EBF7E1D0 appears 33 times
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: String function: 00007FF6EBF86940 appears 41 times
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: String function: 00007FF6EBF7BA80 appears 32 times
                Source: classification engineClassification label: mal100.troj.spyw.winEXE@1/0@1/2
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFDB9B0 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,CloseHandle,0_2_00007FF6EBFDB9B0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF8E610 CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CloseHandle,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF6EBF8E610
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFC4D40 CoInitializeEx,CoInitializeSecurity,CoCreateInstance,CoSetProxyBlanket,SysAllocStringByteLen,SysFreeString,SysAllocStringByteLen,SysFreeString,SysStringByteLen,SysStringByteLen,SysFreeString,SysFreeString,_invalid_parameter_noinfo_noreturn,0_2_00007FF6EBFC4D40
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeMutant created: \Sessions\1\BaseNamedObjects\Mmm-A33C734061CA11EE8C18806E6F6E6963E2D9E553
                Source: 8F0oMWUhg7.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                Source: 8F0oMWUhg7.exeReversingLabs: Detection: 23%
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: wininet.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: rstrtmgr.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: ncrypt.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: ntasn1.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: iertutil.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: winnsi.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: urlmon.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: srvcli.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: netutils.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: rasadhlp.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: fwpuclnt.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: schannel.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: mskeyprotect.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: msasn1.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: dpapi.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: cryptsp.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: rsaenh.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: cryptbase.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: gpapi.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: ncryptsslp.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: uxtheme.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: windowscodecs.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: vaultcli.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeSection loaded: wintypes.dllJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32Jump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
                Source: 8F0oMWUhg7.exeStatic PE information: Image base 0x140000000 > 0x60000000
                Source: 8F0oMWUhg7.exeStatic file information: File size 1292800 > 1048576
                Source: 8F0oMWUhg7.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
                Source: 8F0oMWUhg7.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
                Source: 8F0oMWUhg7.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
                Source: 8F0oMWUhg7.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
                Source: 8F0oMWUhg7.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
                Source: 8F0oMWUhg7.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
                Source: 8F0oMWUhg7.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                Source: 8F0oMWUhg7.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
                Source: 8F0oMWUhg7.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
                Source: 8F0oMWUhg7.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
                Source: 8F0oMWUhg7.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
                Source: 8F0oMWUhg7.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
                Source: 8F0oMWUhg7.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF8D570 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF6EBF8D570
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF9CAB2 push rdi; retf 0004h0_2_00007FF6EBF9CAB5
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFCC600 ExitProcess,OpenMutexA,ExitProcess,CreateMutexExA,ExitProcess,ReleaseMutex,CloseHandle,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF6EBFCC600
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCheck user administrative privileges: GetTokenInformation,DecisionNodesgraph_0-64527
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EC00B5B0 GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,__std_fs_open_handle,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,CloseHandle,CloseHandle,0_2_00007FF6EC00B5B0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EC00B500 FindClose,FindFirstFileExW,GetLastError,0_2_00007FF6EC00B500
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFD73F0 GetLogicalDriveStringsW,_invalid_parameter_noinfo_noreturn,0_2_00007FF6EBFD73F0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFE9038 VirtualQuery,GetSystemInfo,VirtualAlloc,VirtualProtect,0_2_00007FF6EBFE9038
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: D:\sources\migration\Jump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: D:\sources\replacementmanifests\Jump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: D:\sources\migration\wtr\Jump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: D:\sources\replacementmanifests\microsoft-activedirectory-webservices\Jump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: D:\sources\replacementmanifests\microsoft-client-license-platform-service-migration\Jump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: D:\sources\replacementmanifests\hwvid-migration-2\Jump to behavior
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - EU East & CentralVMware20,11696487552
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2285333586.00000170D09F4000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000002.2288727259.00000170D09F4000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2286913636.00000170D09F4000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: sQESKgDDWxvI+5plRl0mqyGVpPublicSrpUR0YjkNNeEv5G7awCnfaJaJwFQPjJtiAJ5SpmbKttIMZpYu80BSdSqT7Rsuq+o8GtZ9WpgqUKjFMBRL1uXGutdkzajoHcuBUZyBXTwqKixgDQxyV54KHBvuiWWsly+og4Ep/POJh2vbgHq2cPEnsU5NpTT0E7eb7hgDW4yBv9DhxgOKJnbxBmnBgRS1lGtbWAgU/kzxaGoyOahRPGoy5RS4kFALDm+SUrolLecKY4quXOi6Zcu6pL3Jy6Vumhe6ptiWJaUsY/k8iJZEIJuy5CmBjUiiXuiqqUPlzySOMjdXXw0ZJOQE0tubykzHhgxVtWxFchxjpSH0oB0Ly5Qc/22OWXDQhwVrS/OFt7Rs1cIzQpwp5c7vqRsFazcP4oit3SB0N3m8CMIQFI7hKBIWmEYBmHo0TEVic19bKhaNwjAR3fJkEMaks+aAVJrLylug2cYF9Y8OAmWpLk1ZJwU0w5GcxYItHRoTsgYWBNMsF2tKJXrbBj/G763c/PcNSwOWvRqvwTqBZTLo9/oZ5KvXlPlByrz8dZOGGcQgucCWvqvNNT5O3VEcyTdt31cd6tZQHZiOzQcZC8E22ETZKkgudAP+oUn2G+KcQQbBErMtKVCZBX1tsjmSu2SuFLZCAqXhI9FKzFE906Z2Be2GpMiub+uyTB2beHZ83XMdHeNHIAN/4LMoDxZbf05vsAqlTzcMWZ5kn2EQvW8S382ZMJYjBW++Y1oatCZgYUqKp9u6TaNSIF2TEDvtQNfQGaUsS7L0JVKfbZGyWA+S5rE3OIx9oWGlORaMqS90h6xgIArp0pvuywtTd7hyCA1zsj5AzYXmAOlYkuN5JpKphnYFwV7y48/ITdP4M/PSOAzJ/HkaLJcsjdjnhQbDyaoUAa+FMRwoWhJBvMnzeLkMaVCYG1NaWHN/aSrkxVjgiuRb9tsS8Q4WhQcbkim7iMoyOZgJl5OYrQOnOTSVgGNwOB/E3uIC6RH4THKNpfamWGBHPLBt6Lhm3xM34g7ygXlCorNUKYPh8ZZ5braau967FwbeO5o1pHIsdubrKoaNNYEeMvcDymdblm2CC0Q5VXMkOQgYohlMadka/PhNe/MD3YKpEXhNQ4LhdYiADEA6OJjsMUXFJKIDUh4dyJpiEbehY8xIhAvThNKKRcv0Q3mFBaMYnhF4fO1h6ZMFsw1XStckRVu+LYDkoBAWriOp3mrhmjo9a+gZHWRMVWxqhmGkwPDYyjKMCw0Og3WVeEka+xsvn29TtmTfWbTJ0IYJkyXVZTogEvk0Ug/cTvdVBjxCPm0bNBY/sA3VxFhkhdzQsFcLBz6uGXB1DV0nbobJw9jhNYa0gG/En+48ZFhmCFIXmuZoqiopbM5c3YRODtzXlizVX/mAitADqNeW5oaJtWpjpinGWLCK8urG3jKNN0mmupGvcU5HlXybvdFUXWgqEhdpkMfvjkkaEbCSfMYSxkL4HWyoXAB1G5hDlqeMuUnwoUAFmVChtHrzZUujZ1qMtmQuVsgyJgRjoLosLTOWYnCQQNUD+mHRChOMZhQemhTYAQZgYPXrgAlY7arGVNjsQrU1hANJXXgrvFAvKP9iwWKe4wjrnFHs+Z6nrkdzDfsQ7pfwBivJDdeBjyC8ZBrYMHeatMrX4SJ1l2vEDg/GZZwN3qvaQEOk1nsYI0nQhADMY/hZsIxYmq3ilFF3yHgGzY6tEzFmBea/UBzFhAmYb1oqHrA2HYnHoIDc0qDg5jN/iSm+UGwHYbQqqkRJVpdhCsWfEsDQs2YatlmgMvGsygRH9PIZM241n1Wg2QJriGdD15v8AEBGUz5wmlUAhSdeuRka5XGneIZTmGpDHsAMQJpeyqP8xYFGCRUAjTnqs8pnAw7ZfJaRM+v+EFLwrtaPnqkMBbgxavDBYWANPixOUg4B+VzjJUjJYCBsUJclzNAchyM4pexDM02OhsoxyzrVD0C6Arsg91oEjxRVPKLcNQkNKVbxTCUW6soC2egIZoCPA7t4NFXTGOgK4Ztqmq9iAIBoyJ0taxTdWMw6zUbRFVnX0UrMS8+qbjpa49lGwqehC3MjgPLqrkBUFpyDPwpFUfupRlk6QW9NIcWAwPgjCgxdK6okaC1DF0K1ohFZDl5jASmKR3itQzUXpUraHaACX6vQ/9XAsTV4DSBo7dk3QZrlT5uo4dswPOpnsJUzg7nmNYtWoEgESZWcUTH2xOwuFIKgJgfVnHTK+JLmAb/RowJPMKhAsCv3xIKp3A3J0bIrT6Kneikg7dvk+GJmkHFttaJEguSLSv129ueZxPU8u/jjbOh58SbK79gHC6fbyHtiXugGa2piEQXxG+bmG0Cus4t/nq2zXfIR5aooh8B19rBJQYmQ20FEfz4uFqfTRmf/+lM6Ex746uEtS7v0ouFUMm83c8HpZ5PQzRdxuv47EQAZ9PEP/ZL6ecyVbL+8hOSJm6+yF+1A6ySN83i+WdwHy5TP6AGa54yNOQDMt0K/OHXfg+kqThLIfk6QFsLDCjZdpZTGOzjUsCOwZe5C6Gi8Q8TVSedBLpSfsvQj8BDp18kmZ3ex54YP0+Gs0yuOc0oHyahpuklKSN9DNVuBZhWH/uMHS1PAuQ5a2Lju9F/SWeKm7prBc0jVP84iPJxdnHVJ/HDDDbXL54Z89qdU0Vcin6gqmwXrJjGgP4IA8IR19qewIwTnUCQdrTZp1GW0u9j1R6sUgPUrm2c5cvXl9oot3E2Yi+lA6TVxs+wzTv0RyoJlnAb/LVyrQ+JXXkt08JQiqZojt7zmAq6A6TMAI3d99XjZOb1H2Ej05cPkbrRi3jsQ/1cA/+FiEaSdYURoSjyCbui7SR58sFKCEAn3HKH4uwm3eDW6eeqSVnn3vRu5S+ZPUrZgKYs8lgl1/fYieGCfbdnVWn1in27qZ19Yfhv4WKpf3SAPgywfR4sYK3wdc8VGoHmK3TWFL5jmOUHB49Ogy2jYoedRvh3
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: secure.bankofamerica.comVMware20,11696487552|UE
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: account.microsoft.com/profileVMware20,11696487552u
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: discord.comVMware20,11696487552f
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: bankofamerica.comVMware20,11696487552x
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2200160738.00000170D09F4000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: TvruvX0RyBJtK5EljSQn7R3Mf99TpJ62JbtngcXFAoOeSKwqFovFqlMk5T/ORnG0CJbjq+zs4uyPb2fXo+m3s4tvZ5PB00CRbdWw5IEyUBRpMrga6Kpm2wN1YH47k0DqL1lB+3dQqLKsaGhUZKl4YRi2BmateFY02zHxbIhn2dY1E60Ds3h2FFs3IcAoGGTLcNAdRBQUIJEVg/ovCXRTUepndOmYat2jrNqqBuWNgaGWfVqqYuH/A7XSSjYMFTLKZ4wZnSoDq3yWLctBu1VqqSoq0Tvls2kackMH2VC0hk6yY6kauAdK1YEOJdCBUz5rjqnXCsiOI9ty3S7bjmWQ0fkccAYVJE2NYXm7oaGpGZZBZqsZFINmRi/NhkE1JoKGaDoNszmOabSeDdNsdoAhqa2JxMTaA32gVAQwqd4QAI0UvWkTXdZhkfoZE6U0TaBamt16Vgy7Kc+2bWdgVDaVbdMg11EGdjlGh/5rjBlWtPTGGGxHNbizVc+K4jRUVDSTT3vVbplmc1ptQzHMhkq26tgGqaRUL+CemIWyQ90yoB9UqAgwD2rDipajW1qjB902uTNXg7QsQ2sxWAq3YukomCXHGWjQSrFLQ1myYjesoGsa962KwFIMp+UakCJDy6odhtAaM2XJMqa+HpVhGlpTBxNKtWbKVFWnXk2yIcO0TXrFkVXy1YpAk83mIA1b0dWmADin2Ry0amE1qdpAr8eo0kxiMuSSRsf0NpQyVNXQyV9LAsQESKgDDWxvI+5plRl0mqyGVphMRWs8q6am0mSrpUR0YjkNNeEv5G7awCnfaJaJwFQPjJtiAJ5SpmbKttIMZpYu80BSdSqT7Rsuq+o8GtZ9WpgqUKjFMBRL1uXGutdkzajoHcuBUZyBXTwqKixgDQxyV54KHBvuiWWsly+og4Ep/POJh2vbgHq2cPEnsU5NpTT0E7eb7hgDW4yBv9DhxgOKJnbxBmnBgRS1lGtbWAgU/kzxaGoyOahRPGoy5RS4kFALDm+SUrolLecKY4quXOi6Zcu6pL3Jy6Vumhe6ptiWJaUsY/k8iJZEIJuy5CmBjUiiXuiqqUPlzySOMjdXXw0ZJOQE0tubykzHhgxVtWxFchxjpSH0oB0Ly5Qc/22OWXDQhwVrS/OFt7Rs1cIzQpwp5c7vqRsFazcP4oit3SB0N3m8CMIQFI7hKBIWmEYBmHo0TEVic19bKhaNwjAR3fJkEMaks+aAVJrLylug2cYF9Y8OAmWpLk1ZJwU0w5GcxYItHRoTsgYWBNMsF2tKJXrbBj/G763c/PcNSwOWvRqvwTqBZTLo9/oZ5KvXlPlByrz8dZOGGcQgucCWvqvNNT5O3VEcyTdt31cd6tZQHZiOzQcZC8E22ETZKkgudAP+oUn2G+KcQQbBErMtKVCZBX1tsjmSu2SuFLZCAqXhI9FKzFE906Z2Be2GpMiub+uyTB2beHZ83XMdHeNHIAN/4LMoDxZbf05vsAqlTzcMWZ5kn2EQvW8S382ZMJYjBW++Y1oatCZgYUqKp9u6TaNSIF2TEDvtQNfQGaUsS7L0JVKfbZGyWA+S5rE3OIx9oWGlORaMqS90h6xgIArp0pvuywtTd7hyCA1zsj5AzYXmAOlYkuN5JpKphnYFwV7y48/ITdP4M/PSOAzJ/HkaLJcsjdjnhQbDyaoUAa+FMRwoWhJBvMnzeLkMaVCYG1NaWHN/aSrkxVjgiuRb9tsS8Q4WhQcbkim7iMoyOZgJl5OYrQOnOTSVgGNwOB/E3uIC6RH4THKNpfamWGBHPLBt6Lhm3xM34g7ygXlCorNUKYPh8ZZ5braau967FwbeO5o1pHIsdubrKoaNNYEeMvcDymdblm2CC0Q5VXMkOQgYohlMadka/PhNe/MD3YKpEXhNQ4LhdYiADEA6OJjsMUXFJKIDUh4dyJpiEbehY8xIhAvThNKKRcv0Q3mFBaMYnhF4fO1h6ZMFsw1XStckRVu+LYDkoBAWriOp3mrhmjo9a+gZHWRMVWxqhmGkwPDYyjKMCw0Og3WVeEka+xsvn29TtmTfWbTJ0IYJkyXVZTogEvk0Ug/cTvdVBjxCPm0bNBY/sA3VxFhkhdzQsFcLBz6uGXB1DV0nbobJw9jhNYa0gG/En+48ZFhmCFIXmuZoqiopbM5c3YRODtzXlizVX/mAitADqNeW5oaJtWpjpinGWLCK8urG3jKNN0mmupGvcU5HlXybvdFUXWgqEhdpkMfvjkkaEbCSfMYSxkL4HWyoXAB1G5hDlqeMuUnwoUAFmVChtHrzZUujZ1qMtmQuVsgyJgRjoLosLTOWYnCQQNUD+mHRChOMZhQemhTYAQZgYPXrgAlY7arGVNjsQrU1hANJXXgrvFAvKP9iwWKe4wjrnFHs+Z6nrkdzDfsQ7pfwBivJDdeBjyC8ZBrYMHeatMrX4SJ1l2vEDg/GZZwN3qvaQEOk1nsYI0nQhADMY/hZsIxYmq3ilFF3yHgGzY6tEzFmBea/UBzFhAmYb1oqHrA2HYnHoIDc0qDg5jN/iSm+UGwHYbQqqkRJVpdhCsWfEsDQs2YatlmgMvGsygRH9PIZM241n1Wg2QJriGdD15v8AEBGUz5wmlUAhSdeuRka5XGneIZTmGpDHsAMQJpeyqP8xYFGCRUAjTnqs8pnAw7ZfJaRM+v+EFLwrtaPnqkMBbgxavDBYWANPixOUg4B+VzjJUjJYCBsUJclzNAchyM4pexDM02OhsoxyzrVD0C6Arsg91oEjxRVPKLcNQkNKVbxTCUW6soC2egIZoCPA7t4NFXTGOgK4Ztqmq9iAIBoyJ0taxTdWMw6zUbRFVnX0UrMS8+qbjpa49lGwqehC3MjgPLqrkBUFpyDPwpFUfupRlk6QW9NIcWAwPgjCgxdK6okaC1DF0K1ohFZDl5jASmKR3itQzUXpUraHaACX6vQ/9XAsTV4DSBo7dk3QZrlT5uo4dswPOpnsJUzg7nmNYtWoEgESZWcUTH2xOwuFIKg
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: www.interactivebrokers.comVMware20,11696487552}
                Source: 8F0oMWUhg7.exe, 00000000.00000002.2288125378.00000170CDFCD000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2190136548.00000170CDFCD000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: ms.portal.azure.comVMware20,11696487552
                Source: 8F0oMWUhg7.exe, 00000000.00000002.2288125378.00000170CDFCD000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2190136548.00000170CDFCD000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW'
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Canara Change Transaction PasswordVMware20,11696487552
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - COM.HKVMware20,11696487552
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: global block list test formVMware20,11696487552
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: tasks.office.comVMware20,11696487552o
                Source: 8F0oMWUhg7.exe, 00000000.00000002.2288125378.00000170CDF68000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW`
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: AMC password management pageVMware20,11696487552
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: interactivebrokers.co.inVMware20,11696487552d
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: interactivebrokers.comVMware20,11696487552
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: dev.azure.comVMware20,11696487552j
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - HKVMware20,11696487552]
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: microsoft.visualstudio.comVMware20,11696487552x
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2285333586.00000170D09F4000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000002.2288727259.00000170D09F4000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2286913636.00000170D09F4000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SrpUR0YjkNNeEv5G7awCnfaJaJwFQPjJtiAJ5SpmbKttIMZpYu80BSdSqT7Rsuq+o8GtZ9WpgqUKjFMBRL1uXGutdkzajoHcuBUZyBXTwqKixgDQxyV54KHBvuiWWsly+og4Ep/POJh2vbgHq2cPEnsU5NpTT0E7eb7hgDW4yBv9DhxgOKJnbxBmnBgRS1lGtbWAgU/kzxaGoyOahRPGoy5RS4kFALDm+SUrolLecKY4quXOi6Zcu6pL3Jy6Vumhe6ptiWJaUsY/k8iJZEIJuy5CmBjUiiXuiqqUPlzySOMjdXXw0ZJOQE0tubykzHhgxVtWxFchxjpSH0oB0Ly5Qc/22OWXDQhwVrS/OFt7Rs1cIzQpwp5c7vqRsFazcP4oit3SB0N3m8CMIQFI7hKBIWmEYBmHo0TEVic19bKhaNwjAR3fJkEMaks+aAVJrLylug2cYF9Y8OAmWpLk1ZJwU0w5GcxYItHRoTsgYWBNMsF2tKJXrbBj/G763c/PcNSwOWvRqvwTqBZTLo9/oZ5KvXlPlByrz8dZOGGcQgucCWvqvNNT5O3VEcyTdt31cd6tZQHZiOzQcZC8E22ETZKkgudAP+oUn2G+KcQQbBErMtKVCZBX1tsjmSu2SuFLZCAqXhI9FKzFE906Z2Be2GpMiub+uyTB2beHZ83XMdHeNHIAN/4LMoDxZbf05vsAqlTzcMWZ5kn2EQvW8S382ZMJYjBW++Y1oatCZgYUqKp9u6TaNSIF2TEDvtQNfQGaUsS7L0JVKfbZGyWA+S5rE3OIx9oWGlORaMqS90h6xgIArp0pvuywtTd7hyCA1zsj5AzYXmAOlYkuN5JpKphnYFwV7y48/ITdP4M/PSOAzJ/HkaLJcsjdjnhQbDyaoUAa+FMRwoWhJBvMnzeLkMaVCYG1NaWHN/aSrkxVjgiuRb9tsS8Q4WhQcbkim7iMoyOZgJl5OYrQOnOTSVgGNwOB/E3uIC6RH4THKNpfamWGBHPLBt6Lhm3xM34g7ygXlCorNUKYPh8ZZ5braau967FwbeO5o1pHIsdubrKoaNNYEeMvcDymdblm2CC0Q5VXMkOQgYohlMadka/PhNe/MD3YKpEXhNQ4LhdYiADEA6OJjsMUXFJKIDUh4dyJpiEbehY8xIhAvThNKKRcv0Q3mFBaMYnhF4fO1h6ZMFsw1XStckRVu+LYDkoBAWriOp3mrhmjo9a+gZHWRMVWxqhmGkwPDYyjKMCw0Og3WVeEka+xsvn29TtmTfWbTJ0IYJkyXVZTogEvk0Ug/cTvdVBjxCPm0bNBY/sA3VxFhkhdzQsFcLBz6uGXB1DV0nbobJw9jhNYa0gG/En+48ZFhmCFIXmuZoqiopbM5c3YRODtzXlizVX/mAitADqNeW5oaJtWpjpinGWLCK8urG3jKNN0mmupGvcU5HlXybvdFUXWgqEhdpkMfvjkkaEbCSfMYSxkL4HWyoXAB1G5hDlqeMuUnwoUAFmVChtHrzZUujZ1qMtmQuVsgyJgRjoLosLTOWYnCQQNUD+mHRChOMZhQemhTYAQZgYPXrgAlY7arGVNjsQrU1hANJXXgrvFAvKP9iwWKe4wjrnFHs+Z6nrkdzDfsQ7pfwBivJDdeBjyC8ZBrYMHeatMrX4SJ1l2vEDg/GZZwN3qvaQEOk1nsYI0nQhADMY/hZsIxYmq3ilFF3yHgGzY6tEzFmBea/UBzFhAmYb1oqHrA2HYnHoIDc0qDg5jN/iSm+UGwHYbQqqkRJVpdhCsWfEsDQs2YatlmgMvGsygRH9PIZM241n1Wg2QJriGdD15v8AEBGUz5wmlUAhSdeuRka5XGneIZTmGpDHsAMQJpeyqP8xYFGCRUAjTnqs8pnAw7ZfJaRM+v+EFLwrtaPnqkMBbgxavDBYWANPixOUg4B+VzjJUjJYCBsUJclzNAchyM4pexDM02OhsoxyzrVD0C6Arsg91oEjxRVPKLcNQkNKVbxTCUW6soC2egIZoCPA7t4NFXTGOgK4Ztqmq9iAIBoyJ0taxTdWMw6zUbRFVnX0UrMS8+qbjpa49lGwqehC3MjgPLqrkBUFpyDPwpFUfupRlk6QW9NIcWAwPgjCgxdK6okaC1DF0K1ohFZDl5jASmKR3itQzUXpUraHaACX6vQ/9XAsTV4DSBo7dk3QZrlT5uo4dswPOpnsJUzg7nmNYtWoEgESZWcUTH2xOwuFIKgJgfVnHTK+JLmAb/RowJPMKhAsCv3xIKp3A3J0bIrT6Kneikg7dvk+GJmkHFttaJEguSLSv129ueZxPU8u/jjbOh58SbK79gHC6fbyHtiXugGa2piEQXxG+bmG0Cus4t/nq2zXfIR5aooh8B19rBJQYmQ20FEfz4uFqfTRmf/+lM6Ex746uEtS7v0ouFUMm83c8HpZ5PQzRdxuv47EQAZ9PEP/ZL6ecyVbL+8hOSJm6+yF+1A6ySN83i+WdwHy5TP6AGa54yNOQDMt0K/OHXfg+kqThLIfk6QFsLDCjZdpZTGOzjUsCOwZe5C6Gi8Q8TVSedBLpSfsvQj8BDp18kmZ3ex54YP0+Gs0yuOc0oHyahpuklKSN9DNVuBZhWH/uMHS1PAuQ5a2Lju9F/SWeKm7prBc0jVP84iPJxdnHVJ/HDDDbXL54Z89qdU0Vcin6gqmwXrJjGgP4IA8IR19qewIwTnUCQdrTZp1GW0u9j1R6sUgPUrm2c5cvXl9oot3E2Yi+lA6TVxs+wzTv0RyoJlnAb/LVyrQ+JXXkt08JQiqZojt7zmAq6A6TMAI3d99XjZOb1H2Ej05cPkbrRi3jsQ/1cA/+FiEaSdYURoSjyCbui7SR58sFKCEAn3HKH4uwm3eDW6eeqSVnn3vRu5S+ZPUrZgKYs8lgl1/fYieGCfbdnVWn1in27qZ19Yfhv4WKpf3SAPgywfR4sYK3wdc8VGoHmK3TWFL5jmOUHB49Ogy2jYoedRvh3h9D96fGhUBv0WbVKW3Fxq4ViXVL2x9N
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: netportal.hdfcbank.comVMware20,11696487552
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: trackpan.utiitsl.comVMware20,11696487552h
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - NDCDYNVMware20,11696487552z
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: www.interactivebrokers.co.inVMware20,11696487552~
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: outlook.office365.comVMware20,11696487552t
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Canara Change Transaction PasswordVMware20,11696487552^
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - GDCDYNVMware20,11696487552p
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - EU WestVMware20,11696487552n
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: outlook.office.comVMware20,11696487552s
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Test URL for global passwords blocklistVMware20,11696487552
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: turbotax.intuit.comVMware20,11696487552t
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Canara Transaction PasswordVMware20,11696487552x
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Canara Transaction PasswordVMware20,11696487552}
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2194132118.00000170D0ABA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696487552
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeAPI call chain: ExitProcess graph end nodegraph_0-64469
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeProcess information queried: ProcessInformationJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFDA430 RtlAcquirePebLock,NtAllocateVirtualMemory,lstrcpyW,lstrcatW,NtAllocateVirtualMemory,lstrcpyW,RtlInitUnicodeString,RtlInitUnicodeString,LdrEnumerateLoadedModules,RtlReleasePebLock,_invalid_parameter_noinfo_noreturn,CoInitializeEx,lstrcpyW,lstrcatW,CoGetObject,lstrcpyW,lstrcatW,CoGetObject,CoUninitialize,0_2_00007FF6EBFDA430
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFE7F68 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF6EBFE7F68
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EC00D804 GetLastError,IsDebuggerPresent,OutputDebugStringW,0_2_00007FF6EC00D804
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBF8D570 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF6EBF8D570
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFF9EEC GetProcessHeap,0_2_00007FF6EBFF9EEC
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeProcess token adjusted: DebugJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFE7F68 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF6EBFE7F68
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFFEC08 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF6EBFFEC08
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFCB420 ShellExecuteW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF6EBFCB420
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: EnumSystemLocalesW,0_2_00007FF6EBFF8F60
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: GetLocaleInfoW,0_2_00007FF6EBFEE020
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: EnumSystemLocalesW,0_2_00007FF6EBFF9030
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,0_2_00007FF6EBFF90C8
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: EnumSystemLocalesW,0_2_00007FF6EBFEDAE0
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: TranslateName,TranslateName,GetACP,IsValidCodePage,GetLocaleInfoW,0_2_00007FF6EBFF8C04
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,0_2_00007FF6EBFF964C
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: GetLocaleInfoEx,FormatMessageA,0_2_00007FF6EC00B170
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: GetLocaleInfoW,0_2_00007FF6EBFF9310
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,0_2_00007FF6EBFF9468
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: GetLocaleInfoW,0_2_00007FF6EBFF9518
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeQueries volume information: C:\ VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeQueries volume information: C:\ VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeKey value queried: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation TimeZoneKeyNameJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFFF908 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_00007FF6EBFFF908
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFD6150 GetUserNameW,0_2_00007FF6EBFD6150
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeCode function: 0_2_00007FF6EBFF2E3C _get_daylight,_get_daylight,_get_daylight,_get_daylight,_get_daylight,GetTimeZoneInformation,0_2_00007FF6EBFF2E3C

                Stealing of Sensitive Information

                barindex
                Source: Yara matchFile source: Process Memory Space: 8F0oMWUhg7.exe PID: 4896, type: MEMORYSTR
                Source: Yara matchFile source: 8F0oMWUhg7.exe, type: SAMPLE
                Source: Yara matchFile source: 0.0.8F0oMWUhg7.exe.7ff6ebf50000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 0.2.8F0oMWUhg7.exe.7ff6ebf50000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000000.00000002.2288125378.00000170CDF3C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: Process Memory Space: 8F0oMWUhg7.exe PID: 4896, type: MEMORYSTR
                Source: 8F0oMWUhg7.exe, 00000000.00000002.2288125378.00000170CDF3C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Electrum-LTC\wallets
                Source: 8F0oMWUhg7.exe, 00000000.00000002.2288125378.00000170CDF3C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: ElectronCash\config
                Source: 8F0oMWUhg7.exe, 00000000.00000003.2234868057.00000170D318F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: "software": "Ny1aaXAgMjMuMDEgKHg2NCkgWzIzLjAxXQpNb3ppbGxhIEZpcmVmb3ggKHg2NCBlbi1VUykgWzExOC4wLjFdCk1vemlsbGEgTWFpbnRlbmFuY2UgU2VydmljZSBbMTE4LjAuMV0KTWljcm9zb2Z0IE9mZmljZSBQcm9mZXNzaW9uYWwgUGx1cyAyMDE5IC0gZW4tdXMgWzE2LjAuMTY4MjcuMjAxMzBdCk1pY3Jvc29mdCBWaXN1YWwgQysrIDIwMjIgWDY0IEFkZGl0aW9uYWwgUnVudGltZSAtIDE0LjM2LjMyNTMyIFsxNC4zNi4zMjUzMl0KT2ZmaWNlIDE2IENsaWNrLXRvLVJ1biBMaWNlbnNpbmcgQ29tcG9uZW50IFsxNi4wLjE2ODI3LjIwMTMwXQpPZmZpY2UgMTYgQ2xpY2stdG8tUnVuIEV4dGVuc2liaWxpdHkgQ29tcG9uZW50IDY0LWJpdCBSZWdpc3RyYXRpb24gWzE2LjAuMTY4MjcuMjAwNTZdCkFkb2JlIEFjcm9iYXQgKDY0LWJpdCkgWzIzLjAwNi4yMDMyMF0KTWljcm9zb2Z0IFZpc3VhbCBDKysgMjAyMiBYNjQgTWluaW11bSBSdW50aW1lIC0gMTQuMzYuMzI1MzIgWzE0LjM2LjMyNTMyXQpHb29nbGUgQ2hyb21lIFsxMTcuMC41OTM4LjEzNF0KTWljcm9zb2Z0IEVkZ2UgWzExNy4wLjIwNDUuNTVdCk1pY3Jvc29mdCBFZGdlIFVwZGF0ZSBbMS4zLjE3Ny4xMV0KTWljcm9zb2Z0IEVkZ2UgV2ViVmlldzIgUnVudGltZSBbMTE3LjAuMjA0NS40N10KSmF2YSBBdXRvIFVwZGF0ZXIgWzIuOC4zODEuOV0KSmF2YSA4IFVwZGF0ZSAzODEgWzguMC4zODEwLjldCk1pY3Jvc29mdCBWaXN1YWwgQysrIDIwMTUtMjAyMiBSZWRpc3RyaWJ1dGFibGUgKHg2NCkgLSAxNC4zNi4zMjUzMiBbMTQuMzYuMzI1MzIuMF0KT2ZmaWNlIDE2IENsaWNrLXRvLVJ1biBFeHRlbnNpYmlsaXR5IENvbXBvbmVudCBbMTYuMC4xNjgyNy4yMDEzMF0K",
                Source: 8F0oMWUhg7.exe, 00000000.00000002.2288125378.00000170CDF3C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Exodus\exodus.wallet
                Source: 8F0oMWUhg7.exe, 00000000.00000002.2288125378.00000170CDF3C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Ethereum\keystore
                Source: 8F0oMWUhg7.exe, 00000000.00000002.2288125378.00000170CDF3C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Ethereum\keystore
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\monero-project\monero-coreJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\CookiesJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\prefs.jsJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data For AccountJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension CookiesJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web DataJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\MANIFEST-000001Jump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\places.sqliteJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\cookies.sqliteJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\key4.dbJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOGJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\CURRENTJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOCKJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.logJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.oldJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\CookiesJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\HistoryJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\HistoryJump to behavior
                Source: C:\Users\user\Desktop\8F0oMWUhg7.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
                Source: Yara matchFile source: Process Memory Space: 8F0oMWUhg7.exe PID: 4896, type: MEMORYSTR

                Remote Access Functionality

                barindex
                Source: Yara matchFile source: Process Memory Space: 8F0oMWUhg7.exe PID: 4896, type: MEMORYSTR
                Source: Yara matchFile source: 8F0oMWUhg7.exe, type: SAMPLE
                Source: Yara matchFile source: 0.0.8F0oMWUhg7.exe.7ff6ebf50000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 0.2.8F0oMWUhg7.exe.7ff6ebf50000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000000.00000002.2288125378.00000170CDF3C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: Process Memory Space: 8F0oMWUhg7.exe PID: 4896, type: MEMORYSTR
                ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
                Native API
                1
                DLL Side-Loading
                1
                Exploitation for Privilege Escalation
                1
                Access Token Manipulation
                1
                OS Credential Dumping
                12
                System Time Discovery
                Remote Services1
                Screen Capture
                21
                Encrypted Channel
                Exfiltration Over Other Network MediumAbuse Accessibility Features
                CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
                Access Token Manipulation
                1
                Deobfuscate/Decode Files or Information
                LSASS Memory31
                Security Software Discovery
                Remote Desktop Protocol1
                Email Collection
                1
                Non-Standard Port
                Exfiltration Over BluetoothNetwork Denial of Service
                Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
                DLL Side-Loading
                2
                Obfuscated Files or Information
                Security Account Manager2
                Process Discovery
                SMB/Windows Admin Shares1
                Archive Collected Data
                2
                Ingress Tool Transfer
                Automated ExfiltrationData Encrypted for Impact
                Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
                DLL Side-Loading
                NTDS1
                Account Discovery
                Distributed Component Object Model2
                Data from Local System
                2
                Non-Application Layer Protocol
                Traffic DuplicationData Destruction
                Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA Secrets1
                System Owner/User Discovery
                SSHKeylogging3
                Application Layer Protocol
                Scheduled TransferData Encrypted for Impact
                Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC ScriptsSteganographyCached Domain Credentials1
                System Network Configuration Discovery
                VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup ItemsCompile After DeliveryDCSync3
                File and Directory Discovery
                Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/JobIndicator Removal from ToolsProc Filesystem24
                System Information Discovery
                Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement

                This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                windows-stand
                SourceDetectionScannerLabelLink
                8F0oMWUhg7.exe24%ReversingLabs
                8F0oMWUhg7.exe100%Joe Sandbox ML
                No Antivirus matches
                No Antivirus matches
                No Antivirus matches
                SourceDetectionScannerLabelLink
                https://api.ipify.orgN0%Avira URL Cloudsafe
                https://go.microsoft.coan0%Avira URL Cloudsafe
                NameIPActiveMaliciousAntivirus DetectionReputation
                api.ipify.org
                104.26.12.205
                truefalse
                  high
                  NameMaliciousAntivirus DetectionReputation
                  https://api.ipify.org/false
                    high
                    NameSourceMaliciousAntivirus DetectionReputation
                    https://api.ipify.orgN8F0oMWUhg7.exe, 00000000.00000002.2288125378.00000170CDF3C000.00000004.00000020.00020000.00000000.sdmpfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://go.microsoft.co8F0oMWUhg7.exe, 00000000.00000003.2220956682.00000170CE008000.00000004.00000020.00020000.00000000.sdmpfalse
                      high
                      https://support.mozilla.org/products/firefoxgro.allizom.troppus.ZAnPVwXvBbYt8F0oMWUhg7.exe, 00000000.00000003.2201970579.00000170CFE44000.00000004.00000020.00020000.00000000.sdmpfalse
                        high
                        https://contile-images.services.mozilla.com/obgoOYObjIFea_bXuT6L4LbBJ8j425AD87S1HMD3BWg.9991.jpg8F0oMWUhg7.exe, 00000000.00000003.2208740371.00000170D0A48000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2210217485.00000170CDFDE000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2209282971.00000170D0968000.00000004.00000020.00020000.00000000.sdmpfalse
                          high
                          https://bridge.sfo1.admarketplace.net/ctp?version=16.0.0&key=1696484494400800000.2&ci=1696484494189.8F0oMWUhg7.exe, 00000000.00000003.2209282971.00000170D0968000.00000004.00000020.00020000.00000000.sdmpfalse
                            high
                            https://go.microsoft.coan8F0oMWUhg7.exe, 00000000.00000003.2220956682.00000170CE008000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://imp.mt48.net/static?id=7RHzfOIXjFEYsBdvIpkX4Qqm4pLk4pqk4pbW1pbWfpbW7ReNxR3UIG8zInwYIFIVs9eYi8F0oMWUhg7.exe, 00000000.00000003.2209282971.00000170D0968000.00000004.00000020.00020000.00000000.sdmpfalse
                              high
                              https://www.amazon.com/?tag=admarketus-20&ref=pd_sl_86277c656a4bd7d619968160e91c45fd066919bb3bd119b38F0oMWUhg7.exe, 00000000.00000003.2208740371.00000170D0A48000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2210217485.00000170CDFDE000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2209282971.00000170D0968000.00000004.00000020.00020000.00000000.sdmpfalse
                                high
                                https://support.mozilla.org8F0oMWUhg7.exe, 00000000.00000003.2201970579.00000170CFDE0000.00000004.00000020.00020000.00000000.sdmpfalse
                                  high
                                  http://ns.microsoft.t/Regi8F0oMWUhg7.exe, 00000000.00000003.2189504933.00000170D0781000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2287442237.00000170D0790000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2287413441.00000170D0790000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2287552722.00000170D0794000.00000004.00000020.00020000.00000000.sdmpfalse
                                    high
                                    https://contile-images.services.mozilla.com/T23eBL4EHswiSaF6kya2gYsRHvdfADK-NYjs1mVRNGE.3351.jpg8F0oMWUhg7.exe, 00000000.00000003.2209282971.00000170D0968000.00000004.00000020.00020000.00000000.sdmpfalse
                                      high
                                      https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br8F0oMWUhg7.exe, 00000000.00000003.2201970579.00000170CFE44000.00000004.00000020.00020000.00000000.sdmpfalse
                                        high
                                        https://www.t-mobile.com/cell-phones/brand/apple?cmpid=MGPO_PAM_P_EVGRNIPHN_8F0oMWUhg7.exe, 00000000.00000003.2209282971.00000170D0968000.00000004.00000020.00020000.00000000.sdmpfalse
                                          high
                                          https://bridge.sfo1.ap01.net/ctp?version=16.0.0&key=1696484494400800000.1&ci=1696484494189.12791&cta8F0oMWUhg7.exe, 00000000.00000003.2208740371.00000170D0A48000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2210217485.00000170CDFDE000.00000004.00000020.00020000.00000000.sdmp, 8F0oMWUhg7.exe, 00000000.00000003.2209282971.00000170D0968000.00000004.00000020.00020000.00000000.sdmpfalse
                                            high
                                            • No. of IPs < 25%
                                            • 25% < No. of IPs < 50%
                                            • 50% < No. of IPs < 75%
                                            • 75% < No. of IPs
                                            IPDomainCountryFlagASNASN NameMalicious
                                            104.26.12.205
                                            api.ipify.orgUnited States
                                            13335CLOUDFLARENETUSfalse
                                            193.3.19.151
                                            unknownDenmark
                                            2107ARNES-NETAcademicandResearchNetworkofSloveniaSItrue
                                            Joe Sandbox version:41.0.0 Charoite
                                            Analysis ID:1557672
                                            Start date and time:2024-11-18 14:27:27 +01:00
                                            Joe Sandbox product:CloudBasic
                                            Overall analysis duration:0h 5m 19s
                                            Hypervisor based Inspection enabled:false
                                            Report type:full
                                            Cookbook file name:default.jbs
                                            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                            Number of analysed new started processes analysed:5
                                            Number of new started drivers analysed:0
                                            Number of existing processes analysed:0
                                            Number of existing drivers analysed:0
                                            Number of injected processes analysed:0
                                            Technologies:
                                            • HCA enabled
                                            • EGA enabled
                                            • AMSI enabled
                                            Analysis Mode:default
                                            Analysis stop reason:Timeout
                                            Sample name:8F0oMWUhg7.exe
                                            renamed because original name is a hash value
                                            Original Sample Name:ac6323cfb95cc48955949b4d2e7f91a5.exe
                                            Detection:MAL
                                            Classification:mal100.troj.spyw.winEXE@1/0@1/2
                                            EGA Information:
                                            • Successful, ratio: 100%
                                            HCA Information:
                                            • Successful, ratio: 97%
                                            • Number of executed functions: 93
                                            • Number of non-executed functions: 90
                                            Cookbook Comments:
                                            • Found application associated with file extension: .exe
                                            • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
                                            • Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                            • Report size exceeded maximum capacity and may have missing disassembly code.
                                            • Report size exceeded maximum capacity and may have missing network information.
                                            • Report size getting too big, too many NtOpenKeyEx calls found.
                                            • Report size getting too big, too many NtQueryValueKey calls found.
                                            • VT rate limit hit for: 8F0oMWUhg7.exe
                                            No simulations
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            104.26.12.205Ransomware Mallox.exeGet hashmaliciousTargeted RansomwareBrowse
                                            • api.ipify.org/
                                            Yc9hcFC1ux.exeGet hashmaliciousUnknownBrowse
                                            • api.ipify.org/
                                            6706e721f2c06.exeGet hashmaliciousRemcosBrowse
                                            • api.ipify.org/
                                            perfcc.elfGet hashmaliciousXmrigBrowse
                                            • api.ipify.org/
                                            SecuriteInfo.com.Win32.MalwareX-gen.16395.23732.exeGet hashmaliciousRDPWrap ToolBrowse
                                            • api.ipify.org/
                                            SecuriteInfo.com.Win32.MalwareX-gen.16395.23732.exeGet hashmaliciousRDPWrap ToolBrowse
                                            • api.ipify.org/
                                            hloRQZmlfg.exeGet hashmaliciousRDPWrap ToolBrowse
                                            • api.ipify.org/
                                            file.exeGet hashmaliciousRDPWrap ToolBrowse
                                            • api.ipify.org/
                                            file.exeGet hashmaliciousUnknownBrowse
                                            • api.ipify.org/
                                            file.exeGet hashmaliciousUnknownBrowse
                                            • api.ipify.org/
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            api.ipify.org[Inquiry] mv Palmela - CE replacement at your port, oa Nov. 22nd.scr.exeGet hashmaliciousAgentTeslaBrowse
                                            • 172.67.74.152
                                            Ziraat_Bankasi_Swift_Mesaji_BXB04958T.cmdGet hashmaliciousAgentTesla, DBatLoader, PureLog StealerBrowse
                                            • 104.26.13.205
                                            Ziraat_Bankasi_Swift_Mesaji_DXB04958T.cmdGet hashmaliciousAgentTesla, DBatLoader, PureLog StealerBrowse
                                            • 104.26.13.205
                                            SOA.exeGet hashmaliciousAgentTeslaBrowse
                                            • 104.26.13.205
                                            PEACE SHIP PARTICULARS.pdf.exeGet hashmaliciousAgentTesla, PureLog StealerBrowse
                                            • 172.67.74.152
                                            ZHENGHE 3_Q88 20241118.pdf.exeGet hashmaliciousAgentTesla, PureLog StealerBrowse
                                            • 172.67.74.152
                                            F8TXbAdG3G.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                            • 104.26.13.205
                                            EternalPredictor.exeGet hashmaliciousBlank Grabber, Skuld Stealer, XWormBrowse
                                            • 172.67.74.152
                                            skuld.exeGet hashmaliciousSkuld StealerBrowse
                                            • 104.26.13.205
                                            chelentano.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                            • 172.67.74.152
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            ARNES-NETAcademicandResearchNetworkofSloveniaSIbotx.mpsl.elfGet hashmaliciousMiraiBrowse
                                            • 95.87.151.60
                                            yakuza.mips.elfGet hashmaliciousUnknownBrowse
                                            • 194.249.92.194
                                            HRU6b08mmd.exeGet hashmaliciousAmadey, Healer AV Disabler, PureLog Stealer, RedLineBrowse
                                            • 193.3.19.154
                                            Josho.x86.elfGet hashmaliciousUnknownBrowse
                                            • 95.87.138.87
                                            h0r0zx00x.x86.elfGet hashmaliciousMiraiBrowse
                                            • 141.255.194.230
                                            belks.ppc.elfGet hashmaliciousMiraiBrowse
                                            • 95.87.151.62
                                            botnet.spc.elfGet hashmaliciousMirai, MoobotBrowse
                                            • 193.2.192.118
                                            la.bot.mipsel.elfGet hashmaliciousUnknownBrowse
                                            • 88.200.51.87
                                            https://zupimages.net/up/24/42/ol13.jpg?d6mSMvU0ZvpGwffnuqPHYMR7NvlxIzVjDfTD4YJjdRSCOccGet hashmaliciousUnknownBrowse
                                            • 193.3.178.3
                                            l6G93s9XLN.elfGet hashmaliciousMiraiBrowse
                                            • 95.87.151.49
                                            CLOUDFLARENETUSbPRQRIfbbq.exeGet hashmaliciousUnknownBrowse
                                            • 104.16.123.96
                                            New Order Data sheet Page.exeGet hashmaliciousMassLogger RAT, PureLog StealerBrowse
                                            • 188.114.97.3
                                            https://tipicopisco.com/go/bebek.txtGet hashmaliciousUnknownBrowse
                                            • 1.1.1.1
                                            bPRQRIfbbq.exeGet hashmaliciousUnknownBrowse
                                            • 172.67.69.226
                                            AD6dpKQm7n.exeGet hashmaliciousUnknownBrowse
                                            • 104.16.124.96
                                            phish_alert_sp1_1.0.0.0.emlGet hashmaliciousUnknownBrowse
                                            • 1.1.1.1
                                            file.exeGet hashmaliciousLummaCBrowse
                                            • 188.114.97.3
                                            AD6dpKQm7n.exeGet hashmaliciousUnknownBrowse
                                            • 104.16.124.96
                                            emes.batGet hashmaliciousUnknownBrowse
                                            • 104.16.231.132
                                            PO 20495088.exeGet hashmaliciousFormBookBrowse
                                            • 104.21.74.79
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            37f463bf4616ecd445d4a1937da06e19P6uSqL3TTL.exeGet hashmaliciousGhostRat, Mimikatz, NitolBrowse
                                            • 104.26.12.205
                                            Factura Honorarios 2024-11-17.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                            • 104.26.12.205
                                            JOSHHHHHH.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                            • 104.26.12.205
                                            Richiesta Proposta (MACHINES ITALIA) 18-11-2024#U00b7pdf.vbsGet hashmaliciousRemcos, GuLoaderBrowse
                                            • 104.26.12.205
                                            Unlock_Tool_v2.6.5.exeGet hashmaliciousStealc, VidarBrowse
                                            • 104.26.12.205
                                            DHL_Shipping_Invoices_Awb_BL_000000000111820242247820020031808174Global180030011182024.vbsGet hashmaliciousGuLoader, RemcosBrowse
                                            • 104.26.12.205
                                            rBankRemittance_pdf.scr.exeGet hashmaliciousRemcos, GuLoaderBrowse
                                            • 104.26.12.205
                                            rCEMG242598.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                            • 104.26.12.205
                                            file.exeGet hashmaliciousClipboard HijackerBrowse
                                            • 104.26.12.205
                                            file.exeGet hashmaliciousPureCrypter, LummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc, VidarBrowse
                                            • 104.26.12.205
                                            No context
                                            No created / dropped files found
                                            File type:PE32+ executable (GUI) x86-64, for MS Windows
                                            Entropy (8bit):6.519483490367315
                                            TrID:
                                            • Win64 Executable GUI (202006/5) 92.65%
                                            • Win64 Executable (generic) (12005/4) 5.51%
                                            • Generic Win/DOS Executable (2004/3) 0.92%
                                            • DOS Executable Generic (2002/1) 0.92%
                                            • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                            File name:8F0oMWUhg7.exe
                                            File size:1'292'800 bytes
                                            MD5:ac6323cfb95cc48955949b4d2e7f91a5
                                            SHA1:525a7271bef3988185b4f2be7d797b2dfab8bcd0
                                            SHA256:a681393f417174f96a6f0814677b28d81884fb836b501de132eb0003e4782eac
                                            SHA512:34bc32f1e5c578a4b0e438311828d390ba6b657aafc018294a22db16697e5313693cce40996cfb31d55eb5f25e0713f835b1933620b1f23b0ea5732e7518e9df
                                            SSDEEP:24576:W2hVX3mzctl0cJQEcUKs9MjemJ5gx1wj7h0lhSMXl54Tud:9TX3yctl0E1Ks+egCx+jKp4T6
                                            TLSH:B8555B65195C03E9D8BE9138DEAB8A12F575380903B1E7EB1AD147921FE37E09E3E350
                                            File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........N.7./.d./.d./.d.W.e./.d.W.e./.d...e./.d...e./.d...e./.d...e./.d.W.e8/.d.W.e./.d.W.e./.d./.d...d.W.e./.d...e./.d..>d./.d...e./.
                                            Icon Hash:00928e8e8686b000
                                            Entrypoint:0x1400af220
                                            Entrypoint Section:.text
                                            Digitally signed:false
                                            Imagebase:0x140000000
                                            Subsystem:windows gui
                                            Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
                                            DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                                            Time Stamp:0x673B35F5 [Mon Nov 18 12:41:25 2024 UTC]
                                            TLS Callbacks:
                                            CLR (.Net) Version:
                                            OS Version Major:6
                                            OS Version Minor:0
                                            File Version Major:6
                                            File Version Minor:0
                                            Subsystem Version Major:6
                                            Subsystem Version Minor:0
                                            Import Hash:0095cfee1cdfcef936c4c086b6b4fe85
                                            Instruction
                                            dec eax
                                            sub esp, 28h
                                            call 00007FBF94B49964h
                                            dec eax
                                            add esp, 28h
                                            jmp 00007FBF94B490FFh
                                            int3
                                            int3
                                            dec eax
                                            sub esp, 28h
                                            dec ebp
                                            mov eax, dword ptr [ecx+38h]
                                            dec eax
                                            mov ecx, edx
                                            dec ecx
                                            mov edx, ecx
                                            call 00007FBF94B49292h
                                            mov eax, 00000001h
                                            dec eax
                                            add esp, 28h
                                            ret
                                            int3
                                            int3
                                            int3
                                            inc eax
                                            push ebx
                                            inc ebp
                                            mov ebx, dword ptr [eax]
                                            dec eax
                                            mov ebx, edx
                                            inc ecx
                                            and ebx, FFFFFFF8h
                                            dec esp
                                            mov ecx, ecx
                                            inc ecx
                                            test byte ptr [eax], 00000004h
                                            dec esp
                                            mov edx, ecx
                                            je 00007FBF94B49295h
                                            inc ecx
                                            mov eax, dword ptr [eax+08h]
                                            dec ebp
                                            arpl word ptr [eax+04h], dx
                                            neg eax
                                            dec esp
                                            add edx, ecx
                                            dec eax
                                            arpl ax, cx
                                            dec esp
                                            and edx, ecx
                                            dec ecx
                                            arpl bx, ax
                                            dec edx
                                            mov edx, dword ptr [eax+edx]
                                            dec eax
                                            mov eax, dword ptr [ebx+10h]
                                            mov ecx, dword ptr [eax+08h]
                                            dec eax
                                            mov eax, dword ptr [ebx+08h]
                                            test byte ptr [ecx+eax+03h], 0000000Fh
                                            je 00007FBF94B4928Dh
                                            movzx eax, byte ptr [ecx+eax+03h]
                                            and eax, FFFFFFF0h
                                            dec esp
                                            add ecx, eax
                                            dec esp
                                            xor ecx, edx
                                            dec ecx
                                            mov ecx, ecx
                                            pop ebx
                                            jmp 00007FBF94B48836h
                                            int3
                                            and dword ptr [00087639h], 00000000h
                                            ret
                                            dec eax
                                            mov dword ptr [esp+08h], ebx
                                            push ebp
                                            dec eax
                                            lea ebp, dword ptr [esp-000004C0h]
                                            dec eax
                                            sub esp, 000005C0h
                                            mov ebx, ecx
                                            mov ecx, 00000017h
                                            call dword ptr [0002600Eh]
                                            test eax, eax
                                            je 00007FBF94B49286h
                                            mov ecx, ebx
                                            int 29h
                                            mov ecx, 00000003h
                                            NameVirtual AddressVirtual Size Is in Section
                                            IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_IMPORT0x12df680x140.rdata
                                            IMAGE_DIRECTORY_ENTRY_RESOURCE0x13f0000x1e0.rsrc
                                            IMAGE_DIRECTORY_ENTRY_EXCEPTION0x1380000x6c18.pdata
                                            IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                            IMAGE_DIRECTORY_ENTRY_BASERELOC0x1400000xd3c.reloc
                                            IMAGE_DIRECTORY_ENTRY_DEBUG0x1183c00x38.rdata
                                            IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                            IMAGE_DIRECTORY_ENTRY_TLS0x1185800x28.rdata
                                            IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x1182800x140.rdata
                                            IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_IAT0xd50000x778.rdata
                                            IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                            IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                            NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                            .text0x10000xd32900xd34001e7cc584bbe8c210fc8e52d1759b2f82False0.4169517381656805zlib compressed data6.321993088475943IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                            .rdata0xd50000x5a8780x5aa00bacdbd3defa9877219334eb9a9ea5683False0.4009186422413793data6.306972634139164IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                            .data0x1300000x7ce40x5a006bc2f26b443764d2872d13f9d896878bFalse0.08211805555555556data4.536476287471787IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                            .pdata0x1380000x6c180x6e00c6eecc837e87b0c200a192a62ab8b009False0.4799715909090909data5.967062390694732IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                            .rsrc0x13f0000x1e00x2003bdf73d69c827b52e4eecca5ab7e253dFalse0.533203125data4.7176788329467545IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                            .reloc0x1400000xd3c0xe00d6a7436fce611f2c2c78378799be5f90False0.48604910714285715data5.34163148644649IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                            NameRVASizeTypeLanguageCountryZLIB Complexity
                                            RT_MANIFEST0x13f0600x17dXML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.5931758530183727
                                            DLLImport
                                            WS2_32.dllclosesocket, inet_pton, WSAStartup, send, socket, connect, recv, WSACleanup, htons
                                            CRYPT32.dllCryptUnprotectData, CryptProtectData
                                            WININET.dllInternetOpenW, InternetCloseHandle, InternetReadFile, InternetQueryDataAvailable, HttpQueryInfoW, InternetOpenUrlA, InternetOpenA
                                            ntdll.dllNtQuerySystemInformation, RtlInitUnicodeString, LdrEnumerateLoadedModules, RtlAcquirePebLock, RtlReleasePebLock, NtQueryObject, NtAllocateVirtualMemory
                                            RstrtMgr.DLLRmGetList, RmStartSession, RmEndSession, RmRegisterResources
                                            bcrypt.dllBCryptCloseAlgorithmProvider, BCryptOpenAlgorithmProvider, BCryptDecrypt, BCryptDestroyKey, BCryptGenerateSymmetricKey, BCryptSetProperty
                                            KERNEL32.dllGetFileInformationByHandleEx, AreFileApisANSI, FindFirstFileW, FindNextFileW, FindClose, OpenProcess, CreateToolhelp32Snapshot, Process32NextW, LoadLibraryA, Process32FirstW, CloseHandle, GetSystemInfo, GetProcAddress, LocalFree, FreeLibrary, GetLastError, ExitProcess, MultiByteToWideChar, WideCharToMultiByte, VirtualAlloc, ReadFile, WriteFile, CreateFileW, GetFileSize, GetCurrentProcess, VirtualQuery, GetStdHandle, TerminateProcess, CreateMutexA, ReleaseMutex, OpenMutexA, GetModuleFileNameA, GetVolumeInformationW, GetGeoInfoA, HeapFree, EnterCriticalSection, GetModuleFileNameW, GetProcessId, LeaveCriticalSection, SetFilePointer, InitializeCriticalSectionEx, FreeEnvironmentStringsW, GetModuleHandleA, HeapSize, GetLogicalDriveStringsW, GetFinalPathNameByHandleA, GetTimeZoneInformation, lstrcatW, HeapReAlloc, HeapAlloc, GetComputerNameW, GetProcessHeap, GlobalMemoryStatusEx, GetModuleHandleW, lstrcpyW, GetEnvironmentStringsW, SetLastError, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, IsDebuggerPresent, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsProcessorFeaturePresent, GetCurrentProcessId, GetSystemTimeAsFileTime, VirtualProtect, GetFileSizeEx, SetFilePointerEx, GetCurrentThreadId, GetFileType, GetStartupInfoW, FlushFileBuffers, GetConsoleOutputCP, GetConsoleMode, GetTempPathW, FlsAlloc, FlsGetValue, FlsSetValue, FlsFree, InitializeCriticalSectionAndSpinCount, LoadLibraryExW, GetDateFormatW, GetTimeFormatW, CompareStringW, LCMapStringW, GetLocaleInfoW, IsValidLocale, SetEndOfFile, EnumSystemLocalesW, ReadConsoleW, RaiseException, GetModuleHandleExW, SetStdHandle, IsValidCodePage, GetACP, GetOEMCP, GetCPInfo, GetStringTypeW, WriteConsoleW, OutputDebugStringW, SetEnvironmentVariableW, ReleaseSRWLockExclusive, AcquireSRWLockExclusive, WakeAllConditionVariable, SleepConditionVariableSRW, QueryPerformanceCounter, InitializeSListHead, RtlUnwindEx, RtlUnwind, RtlPcToFileHeader, EncodePointer, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, GetFileAttributesExW, GetFileAttributesW, FindFirstFileExW, GetCurrentDirectoryW, GetNativeSystemInfo, LCMapStringEx, CompareStringEx, DecodePointer, DeleteCriticalSection, GetCommandLineA, GetCommandLineW, GetUserGeoID, GetUserDefaultLCID, GetLocaleInfoEx, FormatMessageA
                                            USER32.dllGetWindowRect, ReleaseDC, GetDesktopWindow, EnumDisplayDevicesW, GetSystemMetrics, GetDC
                                            GDI32.dllBitBlt, CreateCompatibleBitmap, SelectObject, CreateCompatibleDC, GetDeviceCaps, DeleteDC, GetObjectW, DeleteObject
                                            ADVAPI32.dllLookupPrivilegeValueW, AdjustTokenPrivileges, GetCurrentHwProfileW, RegCloseKey, RegGetValueA, RegQueryValueExA, RegOpenKeyExA, GetUserNameW, RegEnumKeyExA, RevertToSelf, ConvertSidToStringSidA, ImpersonateLoggedOnUser, OpenProcessToken, DuplicateTokenEx, GetTokenInformation, CredEnumerateA, CredFree
                                            SHELL32.dllSHGetKnownFolderPath, ShellExecuteW
                                            ole32.dllCoTaskMemFree, CoGetObject, CoCreateInstance, CoUninitialize, CoSetProxyBlanket, CoInitializeSecurity, CoInitializeEx
                                            OLEAUT32.dllSysStringByteLen, SysAllocStringByteLen, SysFreeString
                                            SHLWAPI.dll
                                            gdiplus.dllGdipGetImageEncodersSize, GdipFree, GdipDisposeImage, GdiplusShutdown, GdiplusStartup, GdipCloneImage, GdipAlloc, GdipCreateBitmapFromScan0, GdipCreateBitmapFromHBITMAP, GdipSaveImageToStream, GdipGetImageEncoders
                                            Language of compilation systemCountry where language is spokenMap
                                            EnglishUnited States
                                            TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                            2024-11-18T14:28:30.771762+01002049441ET MALWARE Win32/Unknown Grabber Base64 Data Exfiltration Attempt1192.168.2.649710193.3.19.15115666TCP
                                            2024-11-18T14:28:30.771762+01002050806ET MALWARE [ANY.RUN] Meduza Stealer Exfiltration M21192.168.2.649710193.3.19.15115666TCP
                                            2024-11-18T14:28:30.771762+01002050807ET MALWARE [ANY.RUN] Possible Meduza Stealer Exfiltration (TCP)1192.168.2.649710193.3.19.15115666TCP
                                            2024-11-18T14:28:30.776994+01002050806ET MALWARE [ANY.RUN] Meduza Stealer Exfiltration M21192.168.2.649710193.3.19.15115666TCP
                                            2024-11-18T14:28:30.776994+01002050807ET MALWARE [ANY.RUN] Possible Meduza Stealer Exfiltration (TCP)1192.168.2.649710193.3.19.15115666TCP
                                            TimestampSource PortDest PortSource IPDest IP
                                            Nov 18, 2024 14:28:23.504689932 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:23.509773970 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:23.509849072 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:24.267546892 CET49711443192.168.2.6104.26.12.205
                                            Nov 18, 2024 14:28:24.267592907 CET44349711104.26.12.205192.168.2.6
                                            Nov 18, 2024 14:28:24.267687082 CET49711443192.168.2.6104.26.12.205
                                            Nov 18, 2024 14:28:24.300579071 CET49711443192.168.2.6104.26.12.205
                                            Nov 18, 2024 14:28:24.300621033 CET44349711104.26.12.205192.168.2.6
                                            Nov 18, 2024 14:28:24.918097973 CET44349711104.26.12.205192.168.2.6
                                            Nov 18, 2024 14:28:24.918395996 CET49711443192.168.2.6104.26.12.205
                                            Nov 18, 2024 14:28:25.269002914 CET49711443192.168.2.6104.26.12.205
                                            Nov 18, 2024 14:28:25.269031048 CET44349711104.26.12.205192.168.2.6
                                            Nov 18, 2024 14:28:25.269510984 CET44349711104.26.12.205192.168.2.6
                                            Nov 18, 2024 14:28:25.269649029 CET49711443192.168.2.6104.26.12.205
                                            Nov 18, 2024 14:28:25.271302938 CET49711443192.168.2.6104.26.12.205
                                            Nov 18, 2024 14:28:25.315336943 CET44349711104.26.12.205192.168.2.6
                                            Nov 18, 2024 14:28:25.446847916 CET44349711104.26.12.205192.168.2.6
                                            Nov 18, 2024 14:28:25.446948051 CET44349711104.26.12.205192.168.2.6
                                            Nov 18, 2024 14:28:25.447026014 CET49711443192.168.2.6104.26.12.205
                                            Nov 18, 2024 14:28:25.447058916 CET49711443192.168.2.6104.26.12.205
                                            Nov 18, 2024 14:28:25.447921991 CET49711443192.168.2.6104.26.12.205
                                            Nov 18, 2024 14:28:25.447952032 CET44349711104.26.12.205192.168.2.6
                                            Nov 18, 2024 14:28:30.771761894 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.776866913 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.776892900 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.776911020 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.776920080 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.776993990 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.777012110 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.777029037 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.777070045 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.777077913 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.777110100 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.777133942 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.777158022 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.777168036 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.777221918 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.781980991 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.781994104 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.782090902 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.782108068 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.782216072 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.782265902 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.782279015 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.782289028 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.782335997 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.782339096 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.782385111 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.782407999 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.782409906 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.782428980 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.782439947 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.782440901 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.782473087 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.782490969 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.782515049 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.782520056 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.782556057 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.787167072 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.787230015 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.787239075 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.787260056 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.787298918 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.787308931 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.787334919 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.787348032 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.787379026 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.787399054 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.787422895 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.787441969 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.787488937 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.787497997 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.787502050 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.787506104 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.787517071 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.787564039 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.787586927 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.787595987 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.787604094 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.787633896 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.787636042 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.787642956 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.787651062 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.787676096 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.787678957 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.787687063 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.787704945 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.787715912 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.787753105 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.787761927 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.787777901 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.787811041 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.787823915 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.792222023 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792232990 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792244911 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792253017 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792269945 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792279005 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792292118 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.792294979 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792304993 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792308092 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.792321920 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792324066 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.792331934 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792362928 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.792378902 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.792382956 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792397976 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792412043 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792421103 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792435884 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792439938 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.792444944 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792454958 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.792475939 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792484999 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792500973 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.792516947 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.792516947 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792526007 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792531967 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.792567968 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792570114 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.792582989 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792598009 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792607069 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792619944 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.792654037 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.792674065 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792691946 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792700052 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792715073 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792723894 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792732954 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.792746067 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792747021 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.792757988 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.792768002 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.792781115 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792789936 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792795897 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.792800903 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792820930 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.792824984 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792850018 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.792871952 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.792891979 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792902946 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792949915 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792956114 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.792958975 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792963982 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792984962 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.792996883 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793016911 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.793025970 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793035030 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793050051 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.793078899 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.793096066 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793104887 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793112993 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793121099 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793132067 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793153048 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.793157101 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793168068 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793178082 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793181896 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.793203115 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793210030 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.793211937 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793237925 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.793256998 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793266058 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793320894 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.793350935 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793359995 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793386936 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793395996 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793425083 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.793436050 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793445110 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793452978 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793456078 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.793468952 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793473005 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793483019 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.793520927 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.793524981 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793534994 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.793586969 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.797190905 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797207117 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797214985 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797229052 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797238111 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797240973 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797271967 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797282934 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797305107 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.797317028 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797326088 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797353983 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.797362089 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797370911 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797383070 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.797388077 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797395945 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.797395945 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797422886 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.797466040 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797473907 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797477007 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.797483921 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797487974 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797509909 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797519922 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797519922 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.797540903 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.797553062 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797561884 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797565937 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.797576904 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797585964 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797586918 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.797627926 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.797627926 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797642946 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797666073 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.797691107 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797693014 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.797708988 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797760010 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.797772884 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797785044 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797797918 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797826052 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797842979 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.797858953 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.797868013 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797877073 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797888994 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.797909975 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797920942 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797924042 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.797941923 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797951937 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.797955990 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.797969103 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.797993898 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798003912 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798006058 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798053026 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798055887 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798064947 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798085928 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798095942 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798118114 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798141956 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798151970 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798155069 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798166990 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798198938 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798213959 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798217058 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798266888 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798290014 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798300982 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798316956 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798325062 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798332930 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798358917 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798366070 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798376083 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798383951 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798384905 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798407078 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798410892 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798415899 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798427105 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798440933 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798449993 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798454046 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798470974 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798480034 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798495054 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798504114 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798507929 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798512936 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798541069 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798552990 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798562050 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798571110 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798584938 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798594952 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798597097 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798640966 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798648119 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798650980 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798667908 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798676968 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798705101 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798706055 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798713923 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798719883 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798744917 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798749924 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798754930 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798768997 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798783064 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798808098 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798830986 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798835993 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798866987 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798878908 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798887968 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798899889 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798907995 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798919916 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798937082 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798938990 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798949003 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798949957 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.798964024 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.798973083 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799006939 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799007893 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.799016953 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799034119 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799052954 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799052954 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.799062014 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799086094 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.799113035 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.799114943 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799124956 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799134016 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799149990 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799158096 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799166918 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799171925 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.799175024 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799187899 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.799221992 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.799232960 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799242973 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799257994 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799266100 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799284935 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.799308062 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.799309015 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799324989 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799357891 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799366951 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799376965 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.799407959 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.799442053 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799463034 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799490929 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.799514055 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.799557924 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799566984 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799575090 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799582958 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799587011 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799591064 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799606085 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799613953 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799617052 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.799633980 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.799654007 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.799669027 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799678087 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799685955 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799694061 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799710989 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799719095 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799730062 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799740076 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.799760103 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799765110 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.799781084 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.799801111 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799806118 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.799809933 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799834013 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799843073 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799858093 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.799879074 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799880028 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.799887896 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.799925089 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.804404974 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.804414988 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.804471016 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.804553986 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.804904938 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.804914951 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.804966927 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.805042028 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.805088997 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.805360079 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.805428028 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.805520058 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.805675030 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.805726051 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.806139946 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.806149960 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.806195021 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.806461096 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.806471109 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.806519032 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.806603909 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.806777000 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.806828976 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.806968927 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.807116032 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.807166100 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.807435989 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.807571888 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.807579994 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.807627916 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.807913065 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.807921886 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.807977915 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.819562912 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.819572926 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.819581032 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.819590092 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.819597006 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.819605112 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.819665909 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.819899082 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.819910049 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.819917917 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.819927931 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.819936991 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.819946051 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.819953918 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.819957972 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.819967985 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.819968939 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.819977999 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.819987059 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.819994926 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820003986 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820012093 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820014000 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.820019960 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820028067 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820036888 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820041895 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.820044994 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820049047 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820053101 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820055962 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820060015 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820067883 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820075989 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820081949 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.820086002 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820095062 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820103884 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820111990 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820120096 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820127964 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820137024 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820141077 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.820143938 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820154905 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820167065 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820174932 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820184946 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820199966 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.820242882 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.820857048 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820867062 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820875883 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820883989 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820892096 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820900917 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820909977 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820914984 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.820918083 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820925951 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820926905 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.820935965 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820939064 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.820945024 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820950985 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.820954084 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820962906 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820971012 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820980072 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820981979 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.820987940 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.820997953 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821006060 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821014881 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821018934 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.821023941 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821031094 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821042061 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821048021 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.821053028 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821060896 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821069002 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821072102 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.821077108 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821080923 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821084976 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821088076 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821096897 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821100950 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.821105003 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821114063 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821122885 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821130991 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821136951 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.821139097 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821149111 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821157932 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821166992 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821170092 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821177959 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821180105 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.821187019 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821194887 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821203947 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821212053 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821218967 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.821221113 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821230888 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821233988 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.821243048 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821250916 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821259022 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821263075 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.821268082 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821275949 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821284056 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821293116 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821295977 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.821300983 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821310043 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821317911 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821326971 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821333885 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.821335077 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821342945 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821351051 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.821356058 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.821371078 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.821398020 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.845834970 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.847296000 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.847398043 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.847451925 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.847515106 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.847579002 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.847656965 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.847719908 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.847805023 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.847872019 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.847948074 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.848005056 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.848088980 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.848120928 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.893822908 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.894603014 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.894855022 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.894939899 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.895000935 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.895059109 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.895114899 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.895179033 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.899894953 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.902256012 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.908582926 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.909677982 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.909756899 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.909807920 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.909859896 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.909907103 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.909964085 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.910006046 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.910063982 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.910118103 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.910190105 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.910243988 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.910314083 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.910348892 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:30.957847118 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:30.958005905 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.009814024 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.009881973 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.047966003 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.048755884 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.048831940 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.048880100 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.048958063 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.053808928 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.054306030 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.102195978 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.102264881 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.143343925 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.143506050 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.143584967 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.143630981 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.143733025 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.143889904 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.143944979 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.143990040 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.144042015 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.144067049 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.189824104 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.189891100 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.228177071 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.228302956 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.228358984 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.228449106 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.228693008 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.228748083 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.228792906 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.228844881 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.228898048 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.228960037 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.233498096 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.233695030 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.233781099 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.233822107 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.273866892 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.275053978 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.309051037 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.309254885 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.309340000 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.309379101 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.309441090 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.309461117 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.310698986 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.310766935 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.310831070 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.310894012 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.310918093 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.314260960 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.314677954 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.314795971 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.314866066 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.314937115 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.315004110 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.315068007 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.361635923 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.361819029 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.361901999 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.361947060 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.393538952 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.393789053 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.393887043 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.393944025 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.394001007 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.394054890 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.394104004 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.394159079 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.394222021 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.394273996 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.394335985 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.394383907 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.394449949 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.394494057 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.394561052 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.394598961 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.401559114 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.401571035 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.401644945 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.401866913 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.401906967 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.401993990 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402004004 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402014017 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402024031 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402031898 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402035952 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.402050972 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402053118 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.402060986 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402062893 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.402070045 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402071953 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.402080059 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402090073 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402098894 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402103901 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.402107954 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402117014 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402132034 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.402160883 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.402170897 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402182102 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402189970 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402198076 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402205944 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402215004 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402215958 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.402226925 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402239084 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402245998 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.402270079 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.402285099 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.402759075 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402767897 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402776003 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402785063 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402792931 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402815104 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402820110 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.402825117 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402832985 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402841091 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402844906 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.402851105 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402859926 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402859926 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.402868986 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402877092 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402879953 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.402885914 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402887106 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.402889967 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402894974 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402898073 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402901888 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402906895 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402909994 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402916908 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.402918100 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402923107 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402968884 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.402997017 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.403023005 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.403506041 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.403516054 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.403523922 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.403532982 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.403542042 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.403551102 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.403556108 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.403559923 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.403570890 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.403574944 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.403579950 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.403589010 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.403598070 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.403605938 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.403609991 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.403626919 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.403633118 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.403637886 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.403645992 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.403655052 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.403656960 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.403662920 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.403673887 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.403678894 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.403682947 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.403691053 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.403717041 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.403731108 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.404033899 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404043913 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404052019 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404061079 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404068947 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404077053 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404082060 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.404093981 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404103041 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404109001 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.404110909 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404119015 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404124022 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.404128075 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404136896 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404145002 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404154062 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404162884 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.404162884 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404187918 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404192924 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.404196978 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404206038 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404222965 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.404247999 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.404362917 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404403925 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.404656887 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404700041 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.404736042 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404747963 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404756069 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404764891 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404774904 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.404798985 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.404809952 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404819012 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404827118 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404834986 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404844046 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404851913 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404856920 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.404861927 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404870033 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.404870987 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404880047 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.404887915 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.404923916 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.405309916 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.405318975 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.405327082 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.405334949 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.405344009 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.405352116 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.405359983 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.405359983 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.405401945 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.405435085 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.405443907 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.405452013 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.405469894 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.405482054 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.406276941 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.406318903 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.406604052 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.406613111 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.406620979 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.406630039 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.406657934 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.406672955 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.406673908 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.406682968 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.406691074 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.406699896 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.406708956 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.406713009 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.406717062 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.406721115 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.406725883 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.406733990 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.406738043 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.406740904 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.406745911 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.406749964 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.406758070 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.406766891 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.406802893 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.406959057 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.406969070 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.406976938 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.407013893 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.407061100 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.407069921 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.407104969 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.407233000 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.407247066 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.407254934 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.407283068 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.407358885 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.407370090 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.407377958 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.407387018 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.407399893 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.407423019 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.407547951 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.407557011 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.407565117 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.407572985 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.407581091 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.407589912 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.407598972 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.407603025 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.407604933 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.407623053 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.407655001 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.407677889 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.407687902 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.407696009 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.407705069 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.407721996 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.407744884 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.454142094 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.454305887 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.454781055 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.454862118 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.454916000 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.454971075 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.455023050 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.455091953 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.455146074 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.455204964 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.455257893 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.455327988 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.455380917 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.455454111 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.455517054 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.455588102 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.455641031 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.455703020 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.455727100 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.459990978 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.460145950 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.460236073 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.460320950 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.460330963 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.460366964 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.460386038 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.460645914 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.460655928 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.460664988 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.460685015 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.460704088 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.460867882 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.460877895 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.460886955 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.460896015 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.460905075 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.460916996 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.460926056 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.460936069 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.460946083 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.460947990 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.460954905 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.460954905 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.460967064 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.460980892 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.460980892 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.460988998 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461008072 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461009026 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.461018085 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461028099 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461030006 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.461035967 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461045027 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.461045027 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461054087 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.461054087 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461062908 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461064100 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.461101055 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.461116076 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.461152077 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461191893 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.461289883 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461299896 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461308002 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461323977 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461333036 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461337090 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.461340904 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461349964 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461359024 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.461359024 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461369038 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461383104 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.461385965 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461395025 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461404085 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461411953 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461419106 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.461421013 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461430073 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461437941 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461447001 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461455107 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461457014 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.461462975 CET1566649710193.3.19.151192.168.2.6
                                            Nov 18, 2024 14:28:31.461478949 CET4971015666192.168.2.6193.3.19.151
                                            Nov 18, 2024 14:28:31.461492062 CET4971015666192.168.2.6193.3.19.151
                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                            Nov 18, 2024 14:28:24.254170895 CET192.168.2.61.1.1.10x8908Standard query (0)api.ipify.orgA (IP address)IN (0x0001)false
                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                            Nov 18, 2024 14:28:24.261068106 CET1.1.1.1192.168.2.60x8908No error (0)api.ipify.org104.26.12.205A (IP address)IN (0x0001)false
                                            Nov 18, 2024 14:28:24.261068106 CET1.1.1.1192.168.2.60x8908No error (0)api.ipify.org172.67.74.152A (IP address)IN (0x0001)false
                                            Nov 18, 2024 14:28:24.261068106 CET1.1.1.1192.168.2.60x8908No error (0)api.ipify.org104.26.13.205A (IP address)IN (0x0001)false
                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            0192.168.2.649711104.26.12.2054434896C:\Users\user\Desktop\8F0oMWUhg7.exe
                                            TimestampBytes transferredDirectionData
                                            2024-11-18 13:28:25 UTC100OUTGET / HTTP/1.1
                                            Accept: text/html; text/plain; */*
                                            Host: api.ipify.org
                                            Cache-Control: no-cache
                                            2024-11-18 13:28:25 UTC399INHTTP/1.1 200 OK
                                            Date: Mon, 18 Nov 2024 13:28:25 GMT
                                            Content-Type: text/plain
                                            Content-Length: 14
                                            Connection: close
                                            Vary: Origin
                                            cf-cache-status: DYNAMIC
                                            Server: cloudflare
                                            CF-RAY: 8e484db65a924770-DFW
                                            server-timing: cfL4;desc="?proto=TCP&rtt=1943&sent=5&recv=6&lost=0&retrans=0&sent_bytes=2820&recv_bytes=738&delivery_rate=1501296&cwnd=251&unsent_bytes=0&cid=f8aa546fb6ac57aa&ts=540&x=0"
                                            2024-11-18 13:28:25 UTC14INData Raw: 31 35 35 2e 39 34 2e 32 34 31 2e 31 38 37
                                            Data Ascii: 155.94.241.187


                                            Click to jump to process

                                            Click to jump to process

                                            Click to dive into process behavior distribution

                                            Target ID:0
                                            Start time:08:28:22
                                            Start date:18/11/2024
                                            Path:C:\Users\user\Desktop\8F0oMWUhg7.exe
                                            Wow64 process (32bit):false
                                            Commandline:"C:\Users\user\Desktop\8F0oMWUhg7.exe"
                                            Imagebase:0x7ff6ebf50000
                                            File size:1'292'800 bytes
                                            MD5 hash:AC6323CFB95CC48955949B4D2E7F91A5
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Yara matches:
                                            • Rule: JoeSecurity_MeduzaStealer, Description: Yara detected Meduza Stealer, Source: 00000000.00000002.2288125378.00000170CDF3C000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                            Reputation:low
                                            Has exited:true

                                            Reset < >

                                              Execution Graph

                                              Execution Coverage:7.4%
                                              Dynamic/Decrypted Code Coverage:0%
                                              Signature Coverage:15.6%
                                              Total number of Nodes:1274
                                              Total number of Limit Nodes:50
                                              execution_graph 63465 7ff6ebfbd080 63566 7ff6ebf7eaf0 63465->63566 63468 7ff6ebf7eaf0 97 API calls 63469 7ff6ebfbd954 63468->63469 63482 7ff6ebfbdd76 _Receive_impl 63469->63482 63572 7ff6ebf7d4e0 63469->63572 63481 7ff6ebfbdd3d 63481->63482 63483 7ff6ebfbddbd 63481->63483 63616 7ff6ebffe860 63482->63616 63611 7ff6ebfe8254 63483->63611 63567 7ff6ebf7eb21 63566->63567 63625 7ff6ec00b5b0 63567->63625 63570 7ff6ebffe860 _Strcoll 8 API calls 63571 7ff6ebf7ebc2 63570->63571 63571->63468 63573 7ff6ebf7d509 63572->63573 63673 7ff6ebf86940 63573->63673 63575 7ff6ebf7d59a 63576 7ff6ebf7d370 63575->63576 63577 7ff6ebf7d3a0 63576->63577 63710 7ff6ec00b260 63577->63710 63580 7ff6ebf7d43a 63593 7ff6ebfbfdd0 63580->63593 63583 7ff6ebf7d48f 63725 7ff6ebf7c530 82 API calls Concurrency::cancel_current_task 63583->63725 63584 7ff6ebf7d3f3 63584->63583 63716 7ff6ebf927e0 63584->63716 63588 7ff6ebf7d410 63722 7ff6ec00b2d0 WideCharToMultiByte WideCharToMultiByte GetLastError WideCharToMultiByte GetLastError 63588->63722 63590 7ff6ebf7d42f 63590->63580 63723 7ff6ebf7c530 82 API calls Concurrency::cancel_current_task 63590->63723 63592 7ff6ebf7d489 63724 7ff6ebf7c160 82 API calls 2 library calls 63592->63724 63594 7ff6ebfbfdf6 63593->63594 63786 7ff6ebfc0920 63594->63786 63596 7ff6ebfbd9ab 63597 7ff6ebfcf8f0 63596->63597 63792 7ff6ebfcf020 63597->63792 63600 7ff6ebfcf94a 63602 7ff6ebf7f380 78 API calls 63600->63602 63603 7ff6ebfcf9bd 63602->63603 63604 7ff6ebffe860 _Strcoll 8 API calls 63603->63604 63605 7ff6ebfbda5d 63604->63605 63606 7ff6ebf7f380 63605->63606 63607 7ff6ebf7f3c2 _Receive_impl 63606->63607 63608 7ff6ebf7f394 63606->63608 63607->63481 63608->63607 63609 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 63608->63609 63610 7ff6ebf7f3e8 63609->63610 63610->63481 64409 7ff6ebfe80cc 78 API calls _invalid_parameter_noinfo 63611->64409 63613 7ff6ebfe826d 64410 7ff6ebfe8284 IsProcessorFeaturePresent 63613->64410 63617 7ff6ebffe869 63616->63617 63618 7ff6ebfbdda1 63617->63618 63619 7ff6ebffec3c IsProcessorFeaturePresent 63617->63619 63620 7ff6ebffec54 63619->63620 64415 7ff6ebffee34 RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind 63620->64415 63622 7ff6ebffec67 64416 7ff6ebffec08 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 63622->64416 63628 7ff6ec00b5f2 63625->63628 63626 7ff6ec00b5fb 63627 7ff6ebffe860 _Strcoll 8 API calls 63626->63627 63630 7ff6ebf7eb3d 63627->63630 63628->63626 63629 7ff6ec00b70d 63628->63629 63632 7ff6ec00b653 GetFileAttributesExW 63628->63632 63668 7ff6ec00b984 CreateFileW GetLastError 63629->63668 63630->63570 63634 7ff6ec00b667 GetLastError 63632->63634 63635 7ff6ec00b6b8 63632->63635 63633 7ff6ec00b730 63636 7ff6ec00b756 63633->63636 63637 7ff6ec00b736 63633->63637 63634->63626 63638 7ff6ec00b676 FindFirstFileW 63634->63638 63635->63626 63635->63629 63640 7ff6ec00b765 GetFileInformationByHandleEx 63636->63640 63655 7ff6ec00b803 63636->63655 63639 7ff6ec00b741 CloseHandle 63637->63639 63650 7ff6ec00b74f 63637->63650 63641 7ff6ec00b68a GetLastError 63638->63641 63642 7ff6ec00b695 FindClose 63638->63642 63643 7ff6ec00b8c5 63639->63643 63639->63650 63646 7ff6ec00b77f GetLastError 63640->63646 63653 7ff6ec00b7a5 63640->63653 63641->63626 63642->63635 63669 7ff6ebfe98b4 78 API calls 2 library calls 63643->63669 63644 7ff6ec00b858 63651 7ff6ec00b8ab 63644->63651 63652 7ff6ec00b86f 63644->63652 63645 7ff6ec00b81e GetFileInformationByHandleEx 63645->63644 63648 7ff6ec00b834 GetLastError 63645->63648 63649 7ff6ec00b78d CloseHandle 63646->63649 63646->63650 63648->63650 63658 7ff6ec00b846 CloseHandle 63648->63658 63649->63650 63659 7ff6ec00b8d6 63649->63659 63650->63626 63651->63650 63656 7ff6ec00b8b1 CloseHandle 63651->63656 63652->63626 63660 7ff6ec00b875 CloseHandle 63652->63660 63654 7ff6ec00b7c6 GetFileInformationByHandleEx 63653->63654 63653->63655 63654->63655 63661 7ff6ec00b7e2 GetLastError 63654->63661 63655->63644 63655->63645 63656->63643 63656->63650 63657 7ff6ec00b8ca 63670 7ff6ebfe98b4 78 API calls 2 library calls 63657->63670 63658->63650 63663 7ff6ec00b8d0 63658->63663 63672 7ff6ebfe98b4 78 API calls 2 library calls 63659->63672 63660->63626 63660->63643 63661->63650 63664 7ff6ec00b7f0 CloseHandle 63661->63664 63671 7ff6ebfe98b4 78 API calls 2 library calls 63663->63671 63664->63650 63664->63657 63668->63633 63674 7ff6ebf86a64 63673->63674 63676 7ff6ebf86966 63673->63676 63698 7ff6ebf7b8e0 82 API calls 63674->63698 63677 7ff6ebf86a5f 63676->63677 63679 7ff6ebf869ca 63676->63679 63680 7ff6ebf86a22 63676->63680 63687 7ff6ebf86971 ctype 63676->63687 63697 7ff6ebf7b820 82 API calls 2 library calls 63677->63697 63679->63677 63682 7ff6ebf869d7 63679->63682 63684 7ff6ebffe888 std::_Facet_Register 82 API calls 63680->63684 63681 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 63683 7ff6ebf86a70 63681->63683 63688 7ff6ebffe888 63682->63688 63684->63687 63687->63575 63689 7ff6ebffe893 63688->63689 63690 7ff6ebf869df 63689->63690 63693 7ff6ebffe8b2 63689->63693 63699 7ff6ebff9f1c 63689->63699 63690->63681 63690->63687 63692 7ff6ebffe8bd 63703 7ff6ebf7b820 82 API calls 2 library calls 63692->63703 63693->63692 63702 7ff6ebfff8dc RtlPcToFileHeader RaiseException Concurrency::cancel_current_task std::bad_alloc::bad_alloc 63693->63702 63696 7ff6ebffe8c3 63697->63674 63704 7ff6ebff9f5c 63699->63704 63702->63692 63703->63696 63709 7ff6ebfec3bc EnterCriticalSection 63704->63709 63726 7ff6ebff69a4 63710->63726 63713 7ff6ebf7d3ac 63713->63580 63713->63592 63715 7ff6ec00b2d0 WideCharToMultiByte WideCharToMultiByte GetLastError WideCharToMultiByte GetLastError 63713->63715 63714 7ff6ec00b272 AreFileApisANSI 63714->63713 63715->63584 63717 7ff6ebf927ed 63716->63717 63718 7ff6ebf92804 63716->63718 63717->63588 63721 7ff6ebf9281e memcpy_s 63718->63721 63769 7ff6ebf98e80 63718->63769 63720 7ff6ebf9286c 63720->63588 63721->63588 63722->63590 63724->63583 63731 7ff6ebfe9eec GetLastError 63726->63731 63732 7ff6ebfe9f10 FlsGetValue 63731->63732 63733 7ff6ebfe9f2d FlsSetValue 63731->63733 63735 7ff6ebfe9f1d 63732->63735 63736 7ff6ebfe9f27 63732->63736 63734 7ff6ebfe9f3f 63733->63734 63733->63735 63758 7ff6ebfeda30 11 API calls 3 library calls 63734->63758 63737 7ff6ebfe9f99 SetLastError 63735->63737 63736->63733 63739 7ff6ebfe9fb9 63737->63739 63740 7ff6ebfe9fa6 63737->63740 63766 7ff6ebfe98b4 78 API calls 2 library calls 63739->63766 63754 7ff6ebfec178 63740->63754 63741 7ff6ebfe9f4e 63743 7ff6ebfe9f6c FlsSetValue 63741->63743 63744 7ff6ebfe9f5c FlsSetValue 63741->63744 63747 7ff6ebfe9f8a 63743->63747 63748 7ff6ebfe9f78 FlsSetValue 63743->63748 63746 7ff6ebfe9f65 63744->63746 63759 7ff6ebfed3c8 63746->63759 63765 7ff6ebfe9c9c 11 API calls _Strcoll 63747->63765 63748->63746 63752 7ff6ebfe9f92 63753 7ff6ebfed3c8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 63752->63753 63753->63737 63755 7ff6ebfec1a0 63754->63755 63756 7ff6ebfec18d 63754->63756 63755->63713 63755->63714 63756->63755 63768 7ff6ebff5c14 78 API calls 3 library calls 63756->63768 63758->63741 63760 7ff6ebfe9f6a 63759->63760 63761 7ff6ebfed3cd RtlFreeHeap 63759->63761 63760->63735 63761->63760 63762 7ff6ebfed3e8 GetLastError 63761->63762 63763 7ff6ebfed3f5 Concurrency::details::SchedulerProxy::DeleteThis 63762->63763 63767 7ff6ebfe4e68 11 API calls _get_daylight 63763->63767 63765->63752 63767->63760 63768->63755 63770 7ff6ebf9900f 63769->63770 63774 7ff6ebf98eaf 63769->63774 63784 7ff6ebf7b8e0 82 API calls 63770->63784 63772 7ff6ebf98f19 63775 7ff6ebffe888 std::_Facet_Register 82 API calls 63772->63775 63773 7ff6ebf99014 63785 7ff6ebf7b820 82 API calls 2 library calls 63773->63785 63774->63772 63777 7ff6ebf98f48 63774->63777 63778 7ff6ebf98f0c 63774->63778 63781 7ff6ebf98eff memcpy_s ctype 63774->63781 63775->63781 63779 7ff6ebffe888 std::_Facet_Register 82 API calls 63777->63779 63778->63772 63778->63773 63779->63781 63780 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 63782 7ff6ebf99020 63780->63782 63781->63780 63783 7ff6ebf98fbe memcpy_s ctype _Receive_impl 63781->63783 63783->63720 63785->63781 63787 7ff6ebfc0950 ctype 63786->63787 63788 7ff6ebfc09e5 63786->63788 63787->63596 63791 7ff6ebfc45c0 83 API calls 5 library calls 63788->63791 63790 7ff6ebfc09fa 63790->63596 63791->63790 63793 7ff6ebf7eaf0 97 API calls 63792->63793 63794 7ff6ebfcf06f memcpy_s 63793->63794 63795 7ff6ebfcf0a7 63794->63795 63796 7ff6ebfcf0af 63794->63796 63855 7ff6ebf9a910 63794->63855 63795->63796 63849 7ff6ebfcf7bf 63795->63849 63799 7ff6ebffe860 _Strcoll 8 API calls 63796->63799 63798 7ff6ebfcf7d6 63802 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 63798->63802 63800 7ff6ebfcf751 63799->63800 63800->63600 63850 7ff6ebf95310 63800->63850 63810 7ff6ebfcf7dc 63802->63810 63803 7ff6ebfcf0ee 63804 7ff6ebfcf545 63803->63804 63805 7ff6ebfcf151 63803->63805 63872 7ff6ebfafdb0 63804->63872 63931 7ff6ebfd9b70 30 API calls 2 library calls 63805->63931 63950 7ff6ebf7cdc0 82 API calls 63810->63950 63812 7ff6ebfcf163 63932 7ff6ebfd9d30 98 API calls 6 library calls 63812->63932 63816 7ff6ebfcf800 63819 7ff6ec000e88 Concurrency::cancel_current_task 2 API calls 63816->63819 63817 7ff6ebfcf597 63821 7ff6ebfafdb0 84 API calls 63817->63821 63818 7ff6ebfcf174 63822 7ff6ebfcf25c GetFileSize 63818->63822 63823 7ff6ebfcf187 63818->63823 63824 7ff6ebfcf811 63819->63824 63826 7ff6ebfcf5aa 63821->63826 63825 7ff6ebfcf29d 63822->63825 63830 7ff6ebfcf278 memcpy_s 63822->63830 63823->63798 63827 7ff6ebfcf1ce _Receive_impl 63823->63827 63825->63830 63833 7ff6ebf98e80 82 API calls 63825->63833 63917 7ff6ebfdd640 63826->63917 63933 7ff6ebf912f0 82 API calls 63827->63933 63829 7ff6ebfcf302 SetFilePointer ReadFile 63839 7ff6ebfcf351 63829->63839 63842 7ff6ebfcf462 63829->63842 63830->63829 63832 7ff6ebfcf21f 63832->63796 63833->63829 63836 7ff6ebfcf4b7 _Receive_impl 63935 7ff6ebf912f0 82 API calls 63836->63935 63837 7ff6ebfcf3d4 _Receive_impl 63934 7ff6ebf912f0 82 API calls 63837->63934 63839->63798 63839->63837 63840 7ff6ebfcf66d 63942 7ff6ebf912f0 82 API calls 63840->63942 63842->63798 63842->63836 63845 7ff6ebfcf76c 63943 7ff6ebf7cdc0 82 API calls 63845->63943 63847 7ff6ebfcf7ae 63944 7ff6ec000e88 63847->63944 63949 7ff6ebf7e240 87 API calls Concurrency::cancel_current_task 63849->63949 63851 7ff6ebf927e0 82 API calls 63850->63851 63852 7ff6ebf9537a 63851->63852 63853 7ff6ebf927e0 82 API calls 63852->63853 63854 7ff6ebf9548d 63853->63854 63854->63600 63951 7ff6ebf94ab0 63855->63951 63860 7ff6ebf9aaa8 63871 7ff6ebf9aa58 63860->63871 63979 7ff6ebf7cdc0 82 API calls 63860->63979 63863 7ff6ebf9aa1f 63977 7ff6ebf93520 78 API calls _Strcoll 63863->63977 63865 7ff6ebf9aa31 63978 7ff6ebf978a0 115 API calls 4 library calls 63865->63978 63867 7ff6ebf9ab12 63868 7ff6ec000e88 Concurrency::cancel_current_task 2 API calls 63867->63868 63870 7ff6ebf9ab23 63868->63870 63871->63803 63873 7ff6ebfafe0d 63872->63873 63876 7ff6ebfafef3 63872->63876 64182 7ff6ebfb0bd0 63873->64182 63875 7ff6ebfafe32 63881 7ff6ebfafe69 63875->63881 64196 7ff6ebf908a0 63875->64196 64206 7ff6ebf7cdc0 82 API calls 63876->64206 63877 7ff6ebfafec0 63887 7ff6ebfafcd0 63877->63887 63879 7ff6ebfaff35 63880 7ff6ec000e88 Concurrency::cancel_current_task 2 API calls 63879->63880 63880->63881 63881->63877 64207 7ff6ebf7cdc0 82 API calls 63881->64207 63883 7ff6ebfaff8e 63884 7ff6ec000e88 Concurrency::cancel_current_task 2 API calls 63883->63884 63885 7ff6ebfaffa2 63884->63885 63888 7ff6ebfafd00 63887->63888 63889 7ff6ebfb0bd0 82 API calls 63888->63889 63890 7ff6ebfafd0f 63889->63890 63890->63817 63891 7ff6ebf98560 63890->63891 63892 7ff6ebf9869a 63891->63892 63897 7ff6ebf98589 63891->63897 64306 7ff6ebf7b8e0 82 API calls 63892->64306 63894 7ff6ebf985ee 63896 7ff6ebffe888 std::_Facet_Register 82 API calls 63894->63896 63895 7ff6ebf9869f 64307 7ff6ebf7b820 82 API calls 2 library calls 63895->64307 63903 7ff6ebf985d4 ctype 63896->63903 63897->63894 63899 7ff6ebf985e1 63897->63899 63900 7ff6ebf9861d 63897->63900 63897->63903 63899->63894 63899->63895 63901 7ff6ebffe888 std::_Facet_Register 82 API calls 63900->63901 63901->63903 63902 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 63905 7ff6ebf986ab 63902->63905 63903->63902 63904 7ff6ebf98667 ctype _Receive_impl 63903->63904 63904->63817 63906 7ff6ebf9870c 63905->63906 63908 7ff6ebf986dc ctype 63905->63908 63909 7ff6ebf98765 63905->63909 63910 7ff6ebf9875a 63905->63910 63907 7ff6ebffe888 std::_Facet_Register 82 API calls 63906->63907 63911 7ff6ebf98722 63907->63911 63908->63817 63913 7ff6ebffe888 std::_Facet_Register 82 API calls 63909->63913 63910->63906 63912 7ff6ebf9879f 63910->63912 63911->63908 63915 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 63911->63915 64308 7ff6ebf7b820 82 API calls 2 library calls 63912->64308 63913->63908 63916 7ff6ebf987aa 63915->63916 63916->63817 63918 7ff6ebfdd69d 63917->63918 63919 7ff6ebfdd6b7 63917->63919 63918->63919 64309 7ff6ebf90ca0 63918->64309 63920 7ff6ebfdd75a 63919->63920 64330 7ff6ebfdf150 63919->64330 63925 7ff6ebfdd765 63920->63925 64343 7ff6ebf94600 63920->64343 63923 7ff6ebfdd7ea _Receive_impl 63924 7ff6ebffe860 _Strcoll 8 API calls 63923->63924 63926 7ff6ebfcf60d 63924->63926 63925->63923 63927 7ff6ebfdd829 63925->63927 63926->63810 63936 7ff6ebf93620 63926->63936 63928 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 63927->63928 63929 7ff6ebfdd82e 63928->63929 63931->63812 63932->63818 63933->63832 63934->63832 63935->63832 63937 7ff6ebf9363a 63936->63937 63941 7ff6ebf9368a 63936->63941 63938 7ff6ebf93430 79 API calls 63937->63938 63939 7ff6ebf93674 63938->63939 64408 7ff6ebfe3818 81 API calls _invalid_parameter_noinfo 63939->64408 63941->63840 63941->63845 63942->63796 63943->63847 63945 7ff6ec000ea7 63944->63945 63946 7ff6ec000ef2 RaiseException 63945->63946 63947 7ff6ec000ed0 RtlPcToFileHeader 63945->63947 63946->63849 63948 7ff6ec000ee8 63947->63948 63948->63946 63950->63816 63952 7ff6ebffe888 std::_Facet_Register 82 API calls 63951->63952 63953 7ff6ebf94b11 63952->63953 63980 7ff6ec00c5ec 63953->63980 63955 7ff6ebf94b21 63989 7ff6ebf94e10 63955->63989 63957 7ff6ebf94bae 63959 7ff6ebf94bbb 63957->63959 64004 7ff6ec00c8b8 6 API calls std::_Lockit::_Lockit 63957->64004 63966 7ff6ebf9c3b0 63959->63966 63961 7ff6ebf94bd6 64005 7ff6ebf7cdc0 82 API calls 63961->64005 63963 7ff6ebf94c16 63964 7ff6ec000e88 Concurrency::cancel_current_task 2 API calls 63963->63964 63965 7ff6ebf94c27 63964->63965 64017 7ff6ebf94500 63966->64017 63969 7ff6ec00cb28 63972 7ff6ec00cb6e 63969->63972 63973 7ff6ebf9aa16 63972->63973 64022 7ff6ec00e200 63972->64022 63973->63860 63973->63863 63975 7ff6ec00cbbc 63975->63973 64042 7ff6ebfe3818 81 API calls _invalid_parameter_noinfo 63975->64042 63977->63865 63978->63871 63979->63867 64006 7ff6ec00bf8c 63980->64006 63982 7ff6ec00c60e 63988 7ff6ec00c652 ctype 63982->63988 64010 7ff6ec00c7e4 82 API calls std::_Facet_Register 63982->64010 63984 7ff6ec00c626 64011 7ff6ec00c814 79 API calls std::locale::_Setgloballocale 63984->64011 63986 7ff6ec00c631 63986->63988 64012 7ff6ebfe7620 13 API calls 2 library calls 63986->64012 63988->63955 63990 7ff6ec00bf8c std::_Lockit::_Lockit 6 API calls 63989->63990 63991 7ff6ebf94e40 63990->63991 63992 7ff6ec00bf8c std::_Lockit::_Lockit 6 API calls 63991->63992 63994 7ff6ebf94e65 63991->63994 63992->63994 63993 7ff6ebf94edd 63995 7ff6ebffe860 _Strcoll 8 API calls 63993->63995 63994->63993 64014 7ff6ebf7ca60 121 API calls 6 library calls 63994->64014 63996 7ff6ebf94b52 63995->63996 63996->63957 63996->63961 63998 7ff6ebf94eef 63999 7ff6ebf94ef5 63998->63999 64000 7ff6ebf94f56 63998->64000 64015 7ff6ec00c5ac 82 API calls std::_Facet_Register 63999->64015 64016 7ff6ebf7c5a0 82 API calls 2 library calls 64000->64016 64003 7ff6ebf94f5b 64004->63959 64005->63963 64007 7ff6ec00bf9b 64006->64007 64008 7ff6ec00bfa0 64006->64008 64013 7ff6ebfec42c 6 API calls std::_Locinfo::_Locinfo_ctor 64007->64013 64008->63982 64010->63984 64011->63986 64012->63988 64014->63998 64015->63993 64016->64003 64018 7ff6ebffe888 std::_Facet_Register 82 API calls 64017->64018 64019 7ff6ebf94577 64018->64019 64020 7ff6ec00c5ec 89 API calls 64019->64020 64021 7ff6ebf94587 64020->64021 64021->63860 64021->63969 64023 7ff6ec00e12c 64022->64023 64024 7ff6ec00e152 64023->64024 64027 7ff6ec00e185 64023->64027 64055 7ff6ebfe4e68 11 API calls _get_daylight 64024->64055 64026 7ff6ec00e157 64056 7ff6ebfe8234 78 API calls _invalid_parameter_noinfo 64026->64056 64029 7ff6ec00e198 64027->64029 64030 7ff6ec00e18b 64027->64030 64043 7ff6ebfed6a8 64029->64043 64057 7ff6ebfe4e68 11 API calls _get_daylight 64030->64057 64031 7ff6ec00cba1 64031->63973 64041 7ff6ebfe7e14 78 API calls _invalid_parameter_noinfo 64031->64041 64041->63975 64042->63973 64060 7ff6ebfec3bc EnterCriticalSection 64043->64060 64055->64026 64056->64031 64057->64031 64183 7ff6ebfb0c10 64182->64183 64187 7ff6ebfb0bed 64182->64187 64185 7ff6ebfb0c1e 64183->64185 64208 7ff6ebf9af10 64183->64208 64184 7ff6ebfb0c0a 64184->63875 64185->63875 64187->64184 64232 7ff6ebf7cdc0 82 API calls 64187->64232 64189 7ff6ebfb0c73 64190 7ff6ec000e88 Concurrency::cancel_current_task 2 API calls 64189->64190 64195 7ff6ebfb0c84 _Receive_impl 64190->64195 64191 7ff6ebfb0de5 64191->63875 64192 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 64193 7ff6ebfb0f37 64192->64193 64233 7ff6ebfaf640 82 API calls ctype 64193->64233 64195->64191 64195->64192 64195->64195 64197 7ff6ebf908d3 64196->64197 64205 7ff6ebf9092b 64197->64205 64239 7ff6ebf93430 64197->64239 64199 7ff6ebffe860 _Strcoll 8 API calls 64201 7ff6ebf90999 64199->64201 64200 7ff6ebf908f6 64202 7ff6ebf90916 64200->64202 64200->64205 64249 7ff6ebfe7d7c 64200->64249 64201->63881 64202->64205 64257 7ff6ebfe7374 64202->64257 64205->64199 64206->63879 64207->63883 64209 7ff6ebf9af4e 64208->64209 64210 7ff6ebf9afd0 64208->64210 64234 7ff6ebf99f00 82 API calls 64209->64234 64212 7ff6ebffe860 _Strcoll 8 API calls 64210->64212 64214 7ff6ebf9affd 64212->64214 64213 7ff6ebf9af5b 64215 7ff6ebf9afbd 64213->64215 64217 7ff6ebf9b012 64213->64217 64214->64185 64215->64210 64235 7ff6ebf9c530 82 API calls 2 library calls 64215->64235 64236 7ff6ebf7cdc0 82 API calls 64217->64236 64219 7ff6ebf9b054 64220 7ff6ec000e88 Concurrency::cancel_current_task 2 API calls 64219->64220 64221 7ff6ebf9b065 64220->64221 64222 7ff6ebf9af10 82 API calls 64221->64222 64223 7ff6ebf9b0bb 64221->64223 64222->64223 64224 7ff6ebf9b18a 64223->64224 64225 7ff6ebf9b1c8 64223->64225 64228 7ff6ebf9b19b 64224->64228 64237 7ff6ebf9c530 82 API calls 2 library calls 64224->64237 64238 7ff6ebf7cdc0 82 API calls 64225->64238 64228->64185 64229 7ff6ebf9b20a 64230 7ff6ec000e88 Concurrency::cancel_current_task 2 API calls 64229->64230 64231 7ff6ebf9b21b 64230->64231 64232->64189 64234->64213 64235->64210 64236->64219 64237->64228 64238->64229 64240 7ff6ebf93502 64239->64240 64241 7ff6ebf93453 64239->64241 64242 7ff6ebffe860 _Strcoll 8 API calls 64240->64242 64241->64240 64247 7ff6ebf9345d 64241->64247 64243 7ff6ebf93511 64242->64243 64243->64200 64244 7ff6ebf934a1 64245 7ff6ebffe860 _Strcoll 8 API calls 64244->64245 64246 7ff6ebf934be 64245->64246 64246->64200 64247->64244 64266 7ff6ebfe4cf0 79 API calls _invalid_parameter_noinfo 64247->64266 64250 7ff6ebfe7dac 64249->64250 64267 7ff6ebfe7b0c 64250->64267 64253 7ff6ebfe7dea 64256 7ff6ebfe7dff 64253->64256 64279 7ff6ebfdf864 78 API calls 2 library calls 64253->64279 64256->64202 64258 7ff6ebfe739d 64257->64258 64259 7ff6ebfe7388 64257->64259 64258->64259 64261 7ff6ebfe73a2 64258->64261 64290 7ff6ebfe4e68 11 API calls _get_daylight 64259->64290 64282 7ff6ebff0274 64261->64282 64262 7ff6ebfe738d 64291 7ff6ebfe8234 78 API calls _invalid_parameter_noinfo 64262->64291 64265 7ff6ebfe7398 64265->64205 64266->64244 64268 7ff6ebfe7b76 64267->64268 64269 7ff6ebfe7b36 64267->64269 64268->64269 64271 7ff6ebfe7b82 64268->64271 64281 7ff6ebfe8168 78 API calls 2 library calls 64269->64281 64280 7ff6ebfe4934 EnterCriticalSection 64271->64280 64277 7ff6ebfe7b5d 64277->64253 64278 7ff6ebfdf864 78 API calls 2 library calls 64277->64278 64278->64253 64279->64256 64281->64277 64283 7ff6ebff02a4 64282->64283 64292 7ff6ebfefd80 64283->64292 64286 7ff6ebff02e3 64288 7ff6ebff02f8 64286->64288 64303 7ff6ebfdf864 78 API calls 2 library calls 64286->64303 64288->64265 64290->64262 64291->64265 64293 7ff6ebfefdca 64292->64293 64294 7ff6ebfefd9b 64292->64294 64304 7ff6ebfe4934 EnterCriticalSection 64293->64304 64305 7ff6ebfe8168 78 API calls 2 library calls 64294->64305 64297 7ff6ebfefdbb 64297->64286 64302 7ff6ebfdf864 78 API calls 2 library calls 64297->64302 64302->64286 64303->64288 64305->64297 64307->63903 64308->63911 64310 7ff6ebf90cdd 64309->64310 64311 7ff6ebf90ced _Receive_impl 64310->64311 64313 7ff6ebf90d51 64310->64313 64314 7ff6ebf90d73 64310->64314 64312 7ff6ebffe860 _Strcoll 8 API calls 64311->64312 64315 7ff6ebf90f1f 64312->64315 64358 7ff6ebfe4648 64313->64358 64317 7ff6ebfe4648 78 API calls 64314->64317 64315->63919 64324 7ff6ebf90da1 ctype 64317->64324 64318 7ff6ebf90ec1 64318->64311 64320 7ff6ebf90fa7 64318->64320 64321 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 64320->64321 64322 7ff6ebf90fac 64321->64322 64323 7ff6ebf90fd4 64322->64323 64329 7ff6ebf90ca0 82 API calls 64322->64329 64323->63919 64324->64318 64326 7ff6ebfe4648 78 API calls 64324->64326 64328 7ff6ebf90f57 64324->64328 64379 7ff6ebf98d10 64324->64379 64325 7ff6ebf90feb 64325->63919 64326->64324 64328->64318 64394 7ff6ebfe7754 78 API calls 3 library calls 64328->64394 64329->64325 64400 7ff6ebfdf080 64330->64400 64332 7ff6ebfdf362 64332->63920 64333 7ff6ebfdf399 64404 7ff6ebf7b8e0 82 API calls 64333->64404 64335 7ff6ebfdf39f 64405 7ff6ebf7b820 82 API calls 2 library calls 64335->64405 64337 7ff6ebfdf080 82 API calls 64338 7ff6ebfdf18c ctype _Receive_impl 64337->64338 64338->64332 64338->64333 64338->64335 64338->64337 64340 7ff6ebfdf394 64338->64340 64341 7ff6ebffe888 82 API calls std::_Facet_Register 64338->64341 64339 7ff6ebfdf3a5 64342 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 64340->64342 64341->64338 64342->64333 64347 7ff6ebf9461d ctype 64343->64347 64348 7ff6ebf94647 64343->64348 64344 7ff6ebf9474a 64406 7ff6ebf7b8e0 82 API calls 64344->64406 64346 7ff6ebf94750 64407 7ff6ebf7b820 82 API calls 2 library calls 64346->64407 64347->63925 64348->64344 64351 7ff6ebf946a1 64348->64351 64352 7ff6ebf946d9 64348->64352 64357 7ff6ebf94693 ctype 64348->64357 64349 7ff6ebffe888 std::_Facet_Register 82 API calls 64349->64357 64351->64346 64351->64349 64353 7ff6ebffe888 std::_Facet_Register 82 API calls 64352->64353 64353->64357 64354 7ff6ebf94756 64355 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 64355->64344 64356 7ff6ebf94727 _Receive_impl 64356->63925 64357->64355 64357->64356 64359 7ff6ebfe4682 64358->64359 64360 7ff6ebfe4664 64358->64360 64395 7ff6ebfe4934 EnterCriticalSection 64359->64395 64396 7ff6ebfe4e68 11 API calls _get_daylight 64360->64396 64363 7ff6ebfe4669 64397 7ff6ebfe8234 78 API calls _invalid_parameter_noinfo 64363->64397 64366 7ff6ebfe4674 64366->64311 64380 7ff6ebf98e65 64379->64380 64384 7ff6ebf98d3f 64379->64384 64398 7ff6ebf7b8e0 82 API calls 64380->64398 64382 7ff6ebf98da4 64385 7ff6ebffe888 std::_Facet_Register 82 API calls 64382->64385 64383 7ff6ebf98e6a 64399 7ff6ebf7b820 82 API calls 2 library calls 64383->64399 64384->64382 64387 7ff6ebf98dd3 64384->64387 64388 7ff6ebf98d97 64384->64388 64391 7ff6ebf98d8a ctype 64384->64391 64385->64391 64389 7ff6ebffe888 std::_Facet_Register 82 API calls 64387->64389 64388->64382 64388->64383 64389->64391 64390 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 64392 7ff6ebf98e76 64390->64392 64391->64390 64393 7ff6ebf98e26 ctype _Receive_impl 64391->64393 64393->64324 64394->64328 64396->64363 64397->64366 64399->64391 64401 7ff6ebfdf096 64400->64401 64402 7ff6ebfdf0b3 64400->64402 64401->64402 64403 7ff6ebf90ca0 82 API calls 64401->64403 64402->64338 64403->64402 64405->64339 64407->64354 64408->63941 64409->63613 64411 7ff6ebfe8297 64410->64411 64414 7ff6ebfe7f68 14 API calls 3 library calls 64411->64414 64413 7ff6ebfe82b2 GetCurrentProcess TerminateProcess 64414->64413 64415->63622 64417 7ff6ebf9c8de 64422 7ff6ebf9d4b0 64417->64422 64420 7ff6ebffe860 _Strcoll 8 API calls 64421 7ff6ebf9c91b 64420->64421 64423 7ff6ebf9d4d6 64422->64423 64424 7ff6ebf9d502 64423->64424 64448 7ff6ebfa9fb0 82 API calls 5 library calls 64423->64448 64431 7ff6ebf9e200 64424->64431 64427 7ff6ebf9c8e6 64427->64420 64428 7ff6ebf9d567 64428->64427 64429 7ff6ebf98d10 82 API calls 64428->64429 64430 7ff6ebf9e200 82 API calls 64428->64430 64429->64428 64430->64428 64432 7ff6ebf9e223 64431->64432 64435 7ff6ebf9e21d 64431->64435 64433 7ff6ebf9e23a 64432->64433 64447 7ff6ebf90ca0 82 API calls 64432->64447 64433->64435 64437 7ff6ebf9e2d4 64433->64437 64434 7ff6ebf9e2a7 64434->64428 64435->64434 64449 7ff6ebfa9fb0 82 API calls 5 library calls 64435->64449 64450 7ff6ebf7cdc0 82 API calls 64437->64450 64439 7ff6ebf9e316 64440 7ff6ec000e88 Concurrency::cancel_current_task 2 API calls 64439->64440 64441 7ff6ebf9e327 64440->64441 64442 7ff6ebf98d10 82 API calls 64441->64442 64445 7ff6ebf9e355 64441->64445 64442->64445 64443 7ff6ebf9e400 64443->64428 64444 7ff6ebf9e200 82 API calls 64444->64445 64445->64443 64445->64444 64446 7ff6ebf98d10 82 API calls 64445->64446 64446->64445 64447->64433 64448->64424 64449->64434 64450->64439 64451 7ff6ebfcc600 64525 7ff6ebfcf820 GetCurrentProcess OpenProcessToken 64451->64525 64454 7ff6ebfcc624 65398 7ff6ebfcfb60 83 API calls 2 library calls 64454->65398 64455 7ff6ebfcc64e 64532 7ff6ebfdb9b0 GetCurrentProcess OpenProcessToken 64455->64532 64459 7ff6ebfcc62e 65399 7ff6ebfda780 110 API calls _Strcoll 64459->65399 64460 7ff6ebfdb9b0 13 API calls 64463 7ff6ebfcc666 64460->64463 64462 7ff6ebfcc637 65400 7ff6ebf92660 78 API calls 2 library calls 64462->65400 64540 7ff6ebfcd030 64463->64540 64465 7ff6ebfcc642 ExitProcess 64468 7ff6ebfcc734 OpenMutexA 64469 7ff6ebfcc76d ExitProcess 64468->64469 64470 7ff6ebfcc779 CreateMutexExA 64468->64470 64472 7ff6ebfcc7a9 64470->64472 64471 7ff6ebfcc72f _Receive_impl 64471->64468 64544 7ff6ebfcfca0 64472->64544 64473 7ff6ebfcc8c6 64474 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 64473->64474 64476 7ff6ebfcc8cb 64474->64476 64478 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 64476->64478 64481 7ff6ebfcc8d1 64478->64481 64479 7ff6ebfcc7b2 ExitProcess 64480 7ff6ebfcc7be 64584 7ff6ebfd8330 64480->64584 64526 7ff6ebfcf8b4 64525->64526 64527 7ff6ebfcf878 GetTokenInformation 64525->64527 64528 7ff6ebfcf8c1 CloseHandle 64526->64528 64529 7ff6ebfcf8cd 64526->64529 64527->64526 64528->64529 64530 7ff6ebffe860 _Strcoll 8 API calls 64529->64530 64531 7ff6ebfcc620 64530->64531 64531->64454 64531->64455 64533 7ff6ebfdba1b LookupPrivilegeValueW 64532->64533 64534 7ff6ebfdba86 64532->64534 64533->64534 64535 7ff6ebfdba3c AdjustTokenPrivileges 64533->64535 64536 7ff6ebfdba8e CloseHandle 64534->64536 64537 7ff6ebfdba9a 64534->64537 64535->64534 64536->64537 64538 7ff6ebffe860 _Strcoll 8 API calls 64537->64538 64539 7ff6ebfcc65a 64538->64539 64539->64460 64541 7ff6ebfcd052 64540->64541 64541->64541 64542 7ff6ebfc0920 83 API calls 64541->64542 64543 7ff6ebfcc6f6 64542->64543 64543->64468 64543->64471 64543->64473 65403 7ff6ebfd58d0 GetUserGeoID GetGeoInfoA 64544->65403 64548 7ff6ebfcfd04 65418 7ff6ebf91900 64548->65418 64550 7ff6ebfcfd4b 64551 7ff6ebf91900 82 API calls 64550->64551 64552 7ff6ebfcfd88 64551->64552 65436 7ff6ebf93ff0 64552->65436 64555 7ff6ebfcfdcc socket 64556 7ff6ebfcfdf2 htons 64555->64556 64557 7ff6ebfcfe81 WSACleanup 64555->64557 64567 7ff6ebfcfe24 64556->64567 64578 7ff6ebfcff28 64556->64578 64560 7ff6ebfcfe87 _Receive_impl 64557->64560 64558 7ff6ebfcfebf _Receive_impl 64561 7ff6ebffe860 _Strcoll 8 API calls 64558->64561 64560->64558 64583 7ff6ebfd002a 64560->64583 64564 7ff6ebfcc7ae 64561->64564 64564->64479 64564->64480 64566 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 64570 7ff6ebfd0030 64566->64570 64568 7ff6ebfcfe39 inet_pton connect 64567->64568 64572 7ff6ebfcfe74 closesocket 64567->64572 65468 7ff6ebfdd830 64567->65468 64568->64567 64571 7ff6ebfcff06 64568->64571 64569 7ff6ebfcff4c _Receive_impl 64569->64570 64573 7ff6ebfceed0 84 API calls 64569->64573 64574 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 64570->64574 64577 7ff6ebf94600 82 API calls 64571->64577 64571->64578 64572->64557 64575 7ff6ebfcffb4 64573->64575 64576 7ff6ebfd0036 64574->64576 64579 7ff6ebf926d0 78 API calls 64575->64579 64577->64578 65474 7ff6ebfceed0 SHGetKnownFolderPath 64578->65474 64580 7ff6ebfcffca 64579->64580 64580->64560 64581 7ff6ebfd0025 64580->64581 64582 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 64581->64582 64582->64583 64583->64566 65641 7ff6ebfd6540 64584->65641 65398->64459 65399->64462 65400->64465 65404 7ff6ebf927e0 82 API calls 65403->65404 65405 7ff6ebfd5945 GetGeoInfoA 65404->65405 65407 7ff6ebf927e0 82 API calls 65405->65407 65408 7ff6ebfcfce1 65407->65408 65409 7ff6ebfad590 65408->65409 65410 7ff6ebf93ff0 82 API calls 65409->65410 65411 7ff6ebfad5c3 65410->65411 65412 7ff6ebffe888 std::_Facet_Register 82 API calls 65411->65412 65413 7ff6ebfad5d8 65412->65413 65492 7ff6ebf929b0 65413->65492 65415 7ff6ebfad5f5 65416 7ff6ebffe860 _Strcoll 8 API calls 65415->65416 65417 7ff6ebfad60e 65416->65417 65417->64548 65419 7ff6ebf9193f 65418->65419 65420 7ff6ebf91937 65418->65420 65422 7ff6ebf919d9 65419->65422 65508 7ff6ebf97d40 65419->65508 65518 7ff6ebf97e80 82 API calls 2 library calls 65420->65518 65519 7ff6ebf97f10 82 API calls 65422->65519 65424 7ff6ebf9195d 65426 7ff6ebf91990 _Receive_impl 65424->65426 65431 7ff6ebf919d4 65424->65431 65427 7ff6ebffe860 _Strcoll 8 API calls 65426->65427 65429 7ff6ebf919bf 65427->65429 65428 7ff6ebf919f6 65520 7ff6ebf97ac0 65428->65520 65429->64550 65432 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 65431->65432 65432->65422 65434 7ff6ec000e88 Concurrency::cancel_current_task 2 API calls 65435 7ff6ebf91a1a 65434->65435 65437 7ff6ebf9402d 65436->65437 65439 7ff6ebf94066 65437->65439 65440 7ff6ebf94107 65437->65440 65456 7ff6ebf94350 65437->65456 65461 7ff6ebf943c2 _Receive_impl 65437->65461 65438 7ff6ebffe860 _Strcoll 8 API calls 65441 7ff6ebf9445f WSAStartup 65438->65441 65444 7ff6ebf94482 65439->65444 65455 7ff6ebf940a6 65439->65455 65621 7ff6ebf992c0 82 API calls 3 library calls 65439->65621 65440->65444 65453 7ff6ebf94134 65440->65453 65623 7ff6ebf992c0 82 API calls 3 library calls 65440->65623 65441->64555 65441->64560 65442 7ff6ebf94373 65446 7ff6ebf9442b 65442->65446 65459 7ff6ebf9437c 65442->65459 65443 7ff6ebf9443a 65629 7ff6ebf900f0 82 API calls _Receive_impl 65443->65629 65630 7ff6ebf90640 82 API calls 65444->65630 65445 7ff6ebf94347 65627 7ff6ebf94ca0 82 API calls 2 library calls 65445->65627 65628 7ff6ebf94ca0 82 API calls 2 library calls 65446->65628 65466 7ff6ebf94102 _Receive_impl 65453->65466 65624 7ff6ebfa0610 82 API calls 3 library calls 65453->65624 65455->65466 65622 7ff6ebfa0610 82 API calls 3 library calls 65455->65622 65456->65442 65456->65443 65456->65461 65460 7ff6ebf9447d 65459->65460 65459->65461 65462 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 65460->65462 65461->65438 65462->65444 65463 7ff6ebfa0610 82 API calls 65463->65466 65464 7ff6ebf91a20 82 API calls 65464->65466 65466->65445 65466->65463 65466->65464 65625 7ff6ebf99380 82 API calls _Receive_impl 65466->65625 65626 7ff6ebfa9810 82 API calls 2 library calls 65466->65626 65470 7ff6ebfdd84c 65468->65470 65472 7ff6ebfdd87b ctype 65470->65472 65631 7ff6ebfe89b0 65470->65631 65471 7ff6ebfe89b0 80 API calls 65471->65472 65472->65471 65473 7ff6ebfdd8fa ctype 65472->65473 65473->64567 65475 7ff6ebfcefe5 CoTaskMemFree 65474->65475 65476 7ff6ebfcef37 65474->65476 65477 7ff6ebffe860 _Strcoll 8 API calls 65475->65477 65479 7ff6ebf86940 82 API calls 65476->65479 65478 7ff6ebfcf000 65477->65478 65487 7ff6ebf926d0 65478->65487 65480 7ff6ebfcef69 65479->65480 65481 7ff6ebf926d0 78 API calls 65480->65481 65482 7ff6ebfcef8d 65481->65482 65483 7ff6ebfcf012 65482->65483 65484 7ff6ebfcefcd _Receive_impl 65482->65484 65485 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 65483->65485 65484->65475 65486 7ff6ebfcf017 65485->65486 65488 7ff6ebf92718 _Receive_impl 65487->65488 65489 7ff6ebf926e5 65487->65489 65488->64569 65489->65488 65490 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 65489->65490 65491 7ff6ebf92761 65490->65491 65495 7ff6ebf929de 65492->65495 65493 7ff6ebf92abd 65507 7ff6ebf7b8e0 82 API calls 65493->65507 65495->65493 65496 7ff6ebf92a2a 65495->65496 65498 7ff6ebf929fa ctype 65495->65498 65500 7ff6ebf92a82 65495->65500 65499 7ff6ebffe888 std::_Facet_Register 82 API calls 65496->65499 65503 7ff6ebf92ab7 65496->65503 65498->65415 65502 7ff6ebf92a40 65499->65502 65501 7ff6ebffe888 std::_Facet_Register 82 API calls 65500->65501 65501->65498 65502->65498 65505 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 65502->65505 65506 7ff6ebf7b820 82 API calls 2 library calls 65503->65506 65505->65503 65506->65493 65511 7ff6ebf97d66 65508->65511 65509 7ff6ebf97e73 65550 7ff6ebf7b9e0 82 API calls 65509->65550 65510 7ff6ebf97dac 65512 7ff6ebffe888 std::_Facet_Register 82 API calls 65510->65512 65511->65509 65511->65510 65514 7ff6ebf97e1f 65511->65514 65515 7ff6ebf97dca 65512->65515 65514->65424 65540 7ff6ebf937f0 65515->65540 65518->65419 65519->65428 65521 7ff6ebf97b17 65520->65521 65552 7ff6ebf7ebf0 65521->65552 65523 7ff6ebf97b55 65576 7ff6ebfa0400 65523->65576 65525 7ff6ebf97b69 _Receive_impl 65528 7ff6ebf97d35 65525->65528 65529 7ff6ebf97d2f 65525->65529 65539 7ff6ebf97d29 65525->65539 65586 7ff6ec000740 65525->65586 65526 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 65526->65529 65532 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 65528->65532 65530 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 65529->65530 65530->65528 65534 7ff6ebf97d3b 65532->65534 65533 7ff6ebf97cf1 _Receive_impl 65535 7ff6ebffe860 _Strcoll 8 API calls 65533->65535 65537 7ff6ebf91a09 65535->65537 65536 7ff6ebf97d24 65538 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 65536->65538 65537->65434 65538->65539 65539->65526 65541 7ff6ebf93823 65540->65541 65542 7ff6ebf93946 65540->65542 65544 7ff6ebffe860 _Strcoll 8 API calls 65541->65544 65542->65541 65543 7ff6ebf93953 65542->65543 65551 7ff6ebf988c0 82 API calls 4 library calls 65543->65551 65545 7ff6ebf93852 65544->65545 65545->65514 65547 7ff6ebf93974 65548 7ff6ec000e88 Concurrency::cancel_current_task 2 API calls 65547->65548 65549 7ff6ebf93985 65548->65549 65551->65547 65553 7ff6ebf7ec2b 65552->65553 65554 7ff6ebf7ed21 65553->65554 65555 7ff6ebf98560 82 API calls 65553->65555 65592 7ff6ebf93d70 65554->65592 65555->65554 65557 7ff6ebf7ed3a 65558 7ff6ebf93d70 82 API calls 65557->65558 65559 7ff6ebf7ed53 65558->65559 65560 7ff6ebf98d10 82 API calls 65559->65560 65561 7ff6ebf7ed60 65559->65561 65560->65561 65562 7ff6ebf93d70 82 API calls 65561->65562 65563 7ff6ebf7edaa 65562->65563 65564 7ff6ebf93d70 82 API calls 65563->65564 65565 7ff6ebf7edbf 65564->65565 65566 7ff6ebf7ee03 _Receive_impl 65565->65566 65568 7ff6ebf7ee3c 65565->65568 65567 7ff6ebffe860 _Strcoll 8 API calls 65566->65567 65569 7ff6ebf7ee28 65567->65569 65570 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 65568->65570 65569->65523 65571 7ff6ebf7ee41 65570->65571 65597 7ff6ec0007d0 65571->65597 65574 7ff6ec0007d0 __std_exception_destroy 13 API calls 65575 7ff6ebf7ee92 _Receive_impl 65574->65575 65575->65523 65577 7ff6ebfa0464 65576->65577 65578 7ff6ebfa0458 65576->65578 65580 7ff6ebf93d70 82 API calls 65577->65580 65579 7ff6ebf98560 82 API calls 65578->65579 65579->65577 65581 7ff6ebfa0481 65580->65581 65582 7ff6ebf93d70 82 API calls 65581->65582 65583 7ff6ebfa049a 65582->65583 65584 7ff6ebf93d70 82 API calls 65583->65584 65585 7ff6ebfa04b3 65584->65585 65585->65525 65587 7ff6ec000761 65586->65587 65591 7ff6ebf97ca4 65586->65591 65588 7ff6ec000796 65587->65588 65587->65591 65619 7ff6ebfe8cb0 78 API calls 2 library calls 65587->65619 65620 7ff6ebfe7620 13 API calls 2 library calls 65588->65620 65591->65533 65591->65536 65593 7ff6ebf93dd2 65592->65593 65596 7ff6ebf93d93 ctype 65592->65596 65601 7ff6ebf99030 65593->65601 65595 7ff6ebf93deb 65595->65557 65596->65557 65598 7ff6ec0007df 65597->65598 65599 7ff6ebf7ee85 65597->65599 65618 7ff6ebfe7620 13 API calls 2 library calls 65598->65618 65599->65574 65602 7ff6ebf991a6 65601->65602 65607 7ff6ebf99068 65601->65607 65616 7ff6ebf7b8e0 82 API calls 65602->65616 65604 7ff6ebf990cd 65606 7ff6ebffe888 std::_Facet_Register 82 API calls 65604->65606 65605 7ff6ebf991ab 65617 7ff6ebf7b820 82 API calls 2 library calls 65605->65617 65614 7ff6ebf990b3 ctype 65606->65614 65607->65604 65608 7ff6ebf990c0 65607->65608 65609 7ff6ebf990fc 65607->65609 65607->65614 65608->65604 65608->65605 65611 7ff6ebffe888 std::_Facet_Register 82 API calls 65609->65611 65611->65614 65612 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 65613 7ff6ebf991b7 65612->65613 65614->65612 65615 7ff6ebf9915c ctype _Receive_impl 65614->65615 65615->65595 65617->65614 65618->65599 65619->65588 65620->65591 65622->65455 65624->65453 65625->65466 65626->65466 65627->65456 65628->65461 65632 7ff6ebfe89ea 65631->65632 65636 7ff6ebfe89c9 65631->65636 65633 7ff6ebfe9eec _Strcoll 78 API calls 65632->65633 65634 7ff6ebfe89ef 65633->65634 65635 7ff6ebfec178 _Strcoll 78 API calls 65634->65635 65637 7ff6ebfe8a08 65635->65637 65636->65470 65637->65636 65640 7ff6ebfed2ac 80 API calls 3 library calls 65637->65640 65639 7ff6ebfe8a3e 65639->65470 65640->65639 65642 7ff6ebfd6599 memcpy_s 65641->65642 65643 7ff6ebffe888 std::_Facet_Register 82 API calls 65642->65643 65644 7ff6ebfd6603 65643->65644 65821 7ff6ebf9cad0 65644->65821 65646 7ff6ebfd6648 EnumDisplayDevicesW 65653 7ff6ebfd6709 65646->65653 65654 7ff6ebfd6665 _Receive_impl 65646->65654 65656 7ff6ebf93d70 82 API calls 65653->65656 65658 7ff6ebfd6711 65653->65658 65655 7ff6ebfd66d1 EnumDisplayDevicesW 65654->65655 65657 7ff6ebfd684f 65654->65657 65845 7ff6ebfc78f0 65654->65845 65857 7ff6ebfddbf0 82 API calls 2 library calls 65654->65857 65655->65653 65655->65654 65656->65653 65659 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 65657->65659 65839 7ff6ebfa2ec0 65658->65839 65660 7ff6ebfd6854 65659->65660 65822 7ff6ebf9cafc 65821->65822 65832 7ff6ebf9cb9b _Receive_impl 65821->65832 65823 7ff6ebf9cc02 65822->65823 65825 7ff6ebf9cb21 65822->65825 65826 7ff6ebf9cb2e 65822->65826 65827 7ff6ebf9cb57 65822->65827 65858 7ff6ebf7b820 82 API calls 2 library calls 65823->65858 65831 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 65825->65831 65825->65832 65826->65823 65829 7ff6ebf9cb3b 65826->65829 65828 7ff6ebffe888 std::_Facet_Register 82 API calls 65827->65828 65828->65825 65830 7ff6ebffe888 std::_Facet_Register 82 API calls 65829->65830 65830->65825 65834 7ff6ebf9cc0d 65831->65834 65832->65646 65833 7ff6ebf9cc4a _Receive_impl 65833->65646 65834->65833 65835 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 65834->65835 65836 7ff6ebf9cc6a 65835->65836 65837 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 65836->65837 65838 7ff6ebf9ccb1 65837->65838 65840 7ff6ebfa2ed7 _Receive_impl 65839->65840 65842 7ff6ebfa2f27 65840->65842 65859 7ff6ebfaca60 78 API calls 2 library calls 65840->65859 65843 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 65842->65843 65844 7ff6ebfa2f3f 65843->65844 65846 7ff6ebfc793e 65845->65846 65853 7ff6ebfc791f _Receive_impl 65845->65853 65848 7ff6ebf86940 82 API calls 65846->65848 65847 7ff6ebffe860 _Strcoll 8 API calls 65849 7ff6ebfc79de 65847->65849 65850 7ff6ebfc7967 65848->65850 65849->65654 65860 7ff6ebfc7a00 10 API calls _Strcoll 65850->65860 65852 7ff6ebfc7975 65852->65853 65854 7ff6ebfc79ec 65852->65854 65853->65847 65855 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 65854->65855 65856 7ff6ebfc79f1 65855->65856 65857->65654 65858->65825 65859->65842 65860->65852 67580 7ff6ebfa23c4 67581 7ff6ebf9c600 82 API calls 67580->67581 67582 7ff6ebfa23d4 67581->67582 67583 7ff6ebfd6e1b RegOpenKeyExA 67584 7ff6ebfd6e45 RegQueryValueExA 67583->67584 67592 7ff6ebfd6ebd _Receive_impl 67583->67592 67589 7ff6ebfd6e84 67584->67589 67584->67592 67586 7ff6ebfd6f14 RegCloseKey 67587 7ff6ebfd6f1a 67586->67587 67588 7ff6ebffe860 _Strcoll 8 API calls 67587->67588 67590 7ff6ebfd6f2d 67588->67590 67593 7ff6ebf928e0 78 API calls 2 library calls 67589->67593 67592->67586 67592->67587 67593->67592 67594 7ff6ebfdcb57 67595 7ff6ebfdcb61 67594->67595 67600 7ff6ebfdd050 67595->67600 67598 7ff6ebffe860 _Strcoll 8 API calls 67599 7ff6ebfdceb3 67598->67599 67604 7ff6ebfdd08f 67600->67604 67607 7ff6ebfdcb70 67600->67607 67601 7ff6ebfdd308 67621 7ff6ebf7b900 8 API calls _Strcoll 67601->67621 67604->67601 67611 7ff6ebfdd28d 67604->67611 67619 7ff6ebf93d70 82 API calls 67604->67619 67620 7ff6ebf7b5b0 80 API calls 67604->67620 67605 7ff6ebfdd329 67622 7ff6ebfde760 82 API calls 67605->67622 67607->67598 67608 7ff6ebfdd33f 67609 7ff6ebf97ac0 82 API calls 67608->67609 67610 7ff6ebfdd352 67609->67610 67612 7ff6ec000e88 Concurrency::cancel_current_task 2 API calls 67610->67612 67611->67607 67623 7ff6ebfde840 82 API calls 67611->67623 67612->67611 67614 7ff6ebfdd38a 67615 7ff6ebf97ac0 82 API calls 67614->67615 67616 7ff6ebfdd39d 67615->67616 67617 7ff6ec000e88 Concurrency::cancel_current_task 2 API calls 67616->67617 67618 7ff6ebfdd3ae 67617->67618 67619->67604 67620->67604 67621->67605 67622->67608 67623->67614 67624 7ff6ebfba41b 67625 7ff6ebfba433 67624->67625 67626 7ff6ebfba468 _Receive_impl 67624->67626 67625->67626 67629 7ff6ebfba8d0 67625->67629 67627 7ff6ebfba4c1 _Receive_impl 67626->67627 67630 7ff6ebfba8d5 67626->67630 67628 7ff6ebfba515 _Receive_impl 67627->67628 67634 7ff6ebfba8db 67627->67634 67632 7ff6ebffe860 _Strcoll 8 API calls 67628->67632 67631 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 67629->67631 67633 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 67630->67633 67631->67630 67635 7ff6ebfba543 67632->67635 67633->67634 67636 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 67634->67636 67637 7ff6ebfba8e1 67636->67637 67694 7ff6ebfd0040 67637->67694 67639 7ff6ebfba93f memcpy_s 67640 7ff6ebfba97e GetModuleFileNameW 67639->67640 67641 7ff6ebfba9c0 67640->67641 67641->67641 67642 7ff6ebf86940 82 API calls 67641->67642 67643 7ff6ebfba9dd 67642->67643 67644 7ff6ebf86940 82 API calls 67643->67644 67645 7ff6ebfbabfe 67644->67645 67646 7ff6ebf86bd0 82 API calls 67645->67646 67647 7ff6ebfbac0c 67646->67647 67770 7ff6ebf95fd0 85 API calls 67647->67770 67649 7ff6ebfbac26 67650 7ff6ebf86940 82 API calls 67649->67650 67651 7ff6ebfbae9d 67650->67651 67652 7ff6ebf86bd0 82 API calls 67651->67652 67653 7ff6ebfbaeab 67652->67653 67771 7ff6ebf95fd0 85 API calls 67653->67771 67655 7ff6ebfbaec6 67656 7ff6ebf86940 82 API calls 67655->67656 67657 7ff6ebfbb13e 67656->67657 67772 7ff6ebf7d4a0 82 API calls 67657->67772 67659 7ff6ebfbb15a 67773 7ff6ebf95fd0 85 API calls 67659->67773 67661 7ff6ebfbb16f 67662 7ff6ebf86940 82 API calls 67661->67662 67663 7ff6ebfbb61d 67662->67663 67664 7ff6ebf86bd0 82 API calls 67663->67664 67665 7ff6ebfbb62e 67664->67665 67774 7ff6ebf95fd0 85 API calls 67665->67774 67667 7ff6ebfbb64c 67668 7ff6ebf86940 82 API calls 67667->67668 67669 7ff6ebfbb8dd 67668->67669 67670 7ff6ebf86bd0 82 API calls 67669->67670 67671 7ff6ebfbb8ee 67670->67671 67775 7ff6ebf95fd0 85 API calls 67671->67775 67673 7ff6ebfbb90c 67674 7ff6ebf86940 82 API calls 67673->67674 67675 7ff6ebfbbb90 67674->67675 67676 7ff6ebf86bd0 82 API calls 67675->67676 67677 7ff6ebfbbba1 67676->67677 67776 7ff6ebf95fd0 85 API calls 67677->67776 67679 7ff6ebfbbbbf 67680 7ff6ebf86940 82 API calls 67679->67680 67681 7ff6ebfbbdaa 67680->67681 67682 7ff6ebf86bd0 82 API calls 67681->67682 67683 7ff6ebfbbdbb 67682->67683 67777 7ff6ebf95fd0 85 API calls 67683->67777 67685 7ff6ebfbbdd9 67686 7ff6ebf86940 82 API calls 67685->67686 67687 7ff6ebfbc0ef 67686->67687 67688 7ff6ebf86bd0 82 API calls 67687->67688 67689 7ff6ebfbc100 67688->67689 67778 7ff6ebf95fd0 85 API calls 67689->67778 67691 7ff6ebfbc11e 67692 7ff6ebf7cf70 2 API calls 67691->67692 67693 7ff6ebfbc2dc 67692->67693 67695 7ff6ebfd00d3 67694->67695 67696 7ff6ebf7d810 82 API calls 67695->67696 67697 7ff6ebfd00f8 _Receive_impl 67696->67697 67698 7ff6ebf7eaf0 97 API calls 67697->67698 67699 7ff6ebfd064c 67697->67699 67703 7ff6ebfd0164 memcpy_s 67698->67703 67700 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 67699->67700 67702 7ff6ebfd0652 67700->67702 67701 7ff6ebfd01a6 67701->67702 67705 7ff6ebfd0207 _Receive_impl 67701->67705 67706 7ff6ebfd0647 67701->67706 67783 7ff6ebf7e240 87 API calls Concurrency::cancel_current_task 67702->67783 67703->67701 67708 7ff6ebf9a910 148 API calls 67703->67708 67707 7ff6ebffe860 _Strcoll 8 API calls 67705->67707 67709 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 67706->67709 67710 7ff6ebfd0239 67707->67710 67711 7ff6ebfd0289 67708->67711 67709->67699 67710->67639 67713 7ff6ebfd02cd 67711->67713 67714 7ff6ebfd0539 67711->67714 67712 7ff6ebfd066f 67784 7ff6ebf7cdc0 82 API calls 67712->67784 67717 7ff6ebf956a0 84 API calls 67713->67717 67782 7ff6ebf912f0 82 API calls 67714->67782 67718 7ff6ebfd0302 67717->67718 67722 7ff6ebfd03a2 67718->67722 67723 7ff6ebfd031f 67718->67723 67719 7ff6ebfd0696 67720 7ff6ec000e88 Concurrency::cancel_current_task 2 API calls 67719->67720 67721 7ff6ebfd06a7 67720->67721 67785 7ff6ebf7cdc0 82 API calls 67721->67785 67725 7ff6ebfdc0b0 82 API calls 67722->67725 67723->67712 67724 7ff6ebfd0351 67723->67724 67726 7ff6ebf913a0 86 API calls 67724->67726 67728 7ff6ebfd03b6 67725->67728 67729 7ff6ebfd035e 67726->67729 67733 7ff6ebfd0450 67728->67733 67734 7ff6ebfd03cd 67728->67734 67731 7ff6ebf93ff0 82 API calls 67729->67731 67730 7ff6ebfd06d0 67732 7ff6ec000e88 Concurrency::cancel_current_task 2 API calls 67730->67732 67735 7ff6ebfd037e 67731->67735 67745 7ff6ebfd06e4 67732->67745 67738 7ff6ebfdc0b0 82 API calls 67733->67738 67734->67721 67736 7ff6ebfd03ff 67734->67736 67779 7ff6ebf84ac0 82 API calls 67735->67779 67739 7ff6ebf913a0 86 API calls 67736->67739 67741 7ff6ebfd0464 67738->67741 67742 7ff6ebfd040c 67739->67742 67740 7ff6ebfd038c 67743 7ff6ebf7da40 78 API calls 67740->67743 67744 7ff6ebfdc0b0 82 API calls 67741->67744 67748 7ff6ebf93ff0 82 API calls 67742->67748 67743->67705 67746 7ff6ebfd0473 67744->67746 67786 7ff6ebf7cdc0 82 API calls 67745->67786 67749 7ff6ebf957c0 82 API calls 67746->67749 67751 7ff6ebfd042c 67748->67751 67752 7ff6ebfd0483 67749->67752 67750 7ff6ebfd070e 67753 7ff6ec000e88 Concurrency::cancel_current_task 2 API calls 67750->67753 67780 7ff6ebf84ac0 82 API calls 67751->67780 67752->67745 67755 7ff6ebfd04b6 67752->67755 67756 7ff6ebfd0722 67753->67756 67758 7ff6ebf913a0 86 API calls 67755->67758 67757 7ff6ebfd043a 67759 7ff6ebf7da40 78 API calls 67757->67759 67760 7ff6ebfd04c3 67758->67760 67759->67705 67761 7ff6ebf929b0 82 API calls 67760->67761 67762 7ff6ebfd04d3 67761->67762 67763 7ff6ebf92880 78 API calls 67762->67763 67764 7ff6ebfd04ec 67763->67764 67765 7ff6ebf93ff0 82 API calls 67764->67765 67766 7ff6ebfd0502 67765->67766 67781 7ff6ebf84ac0 82 API calls 67766->67781 67768 7ff6ebfd0510 67769 7ff6ebf7da40 78 API calls 67768->67769 67769->67705 67770->67649 67771->67655 67772->67659 67773->67661 67774->67667 67775->67673 67776->67679 67777->67685 67778->67691 67779->67740 67780->67757 67781->67768 67782->67701 67784->67719 67785->67730 67786->67750 67787 7ff6ebf90af0 67788 7ff6ebf90b14 ctype 67787->67788 67789 7ff6ebf90b08 67787->67789 67790 7ff6ebf90b25 ctype 67788->67790 67791 7ff6ebf90c5e 67788->67791 67794 7ff6ebfe7a44 67788->67794 67791->67790 67793 7ff6ebfe7a44 _fread_nolock 87 API calls 67791->67793 67793->67790 67797 7ff6ebfe7a64 67794->67797 67798 7ff6ebfe7a8e 67797->67798 67799 7ff6ebfe7a5c 67797->67799 67798->67799 67800 7ff6ebfe7ada 67798->67800 67801 7ff6ebfe7a9d memcpy_s 67798->67801 67799->67788 67810 7ff6ebfe4934 EnterCriticalSection 67800->67810 67811 7ff6ebfe4e68 11 API calls _get_daylight 67801->67811 67805 7ff6ebfe7ab2 67812 7ff6ebfe8234 78 API calls _invalid_parameter_noinfo 67805->67812 67811->67805 67812->67799 67813 7ff6ebff4e91 67825 7ff6ebffbf24 67813->67825 67826 7ff6ebfe9eec _Strcoll 78 API calls 67825->67826 67827 7ff6ebffbf2d 67826->67827 67830 7ff6ebfe98b4 78 API calls 2 library calls 67827->67830 67831 7ff6ebfcfc10 67832 7ff6ebfcfc40 67831->67832 67833 7ff6ec00b5b0 97 API calls 67832->67833 67834 7ff6ebfcfc59 67833->67834 67835 7ff6ebffe860 _Strcoll 8 API calls 67834->67835 67836 7ff6ebfcfc96 67835->67836 67837 7ff6ebfd6c70 GetCurrentHwProfileW 67838 7ff6ebfd6cba 67837->67838 67840 7ff6ebfd6d19 67837->67840 67839 7ff6ebfc78f0 84 API calls 67838->67839 67844 7ff6ebfd6cc9 67839->67844 67841 7ff6ebffe860 _Strcoll 8 API calls 67840->67841 67843 7ff6ebfd6d91 67841->67843 67844->67840 67845 7ff6ebfdfb34 85 API calls 67844->67845 67845->67844 67846 7ff6ebfd6290 67865 7ff6ebfcf9e0 67846->67865 67850 7ff6ebfd6333 67852 7ff6ebfd6457 67850->67852 67854 7ff6ebfd6365 memcpy_s _Receive_impl 67850->67854 67851 7ff6ebfd6381 67855 7ff6ebffe860 _Strcoll 8 API calls 67851->67855 67853 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 67852->67853 67856 7ff6ebfd645c 67853->67856 67854->67851 67878 7ff6ebfc86d0 122 API calls 67854->67878 67858 7ff6ebfd643e 67855->67858 67859 7ff6ebfd63bd 67879 7ff6ebfc8830 121 API calls 2 library calls 67859->67879 67861 7ff6ebfd63e4 67862 7ff6ebf8fe50 82 API calls 67861->67862 67863 7ff6ebfd63f1 67862->67863 67864 7ff6ebf8ebc0 78 API calls 67863->67864 67864->67851 67880 7ff6ebfcdec0 67865->67880 67869 7ff6ebfcfa2d 67870 7ff6ebf86940 82 API calls 67869->67870 67877 7ff6ebfcfb47 67869->67877 67871 7ff6ebfcfa9e 67870->67871 67873 7ff6ebfcfb42 67871->67873 67874 7ff6ebfcfb07 _Receive_impl 67871->67874 67872 7ff6ebffe860 _Strcoll 8 API calls 67875 7ff6ebfcfb2c GetVolumeInformationW 67872->67875 67876 7ff6ebfe8254 _invalid_parameter_noinfo_noreturn 78 API calls 67873->67876 67874->67872 67875->67850 67875->67854 67876->67877 67887 7ff6ebfcdcd0 82 API calls Concurrency::cancel_current_task 67877->67887 67878->67859 67879->67861 67881 7ff6ebfcdf3f 67880->67881 67884 7ff6ebfcdf20 67880->67884 67881->67884 67892 7ff6ebf98b50 82 API calls 5 library calls 67881->67892 67886 7ff6ebfce055 67884->67886 67888 7ff6ec00b574 GetCurrentDirectoryW 67884->67888 67893 7ff6ebf98b50 82 API calls 5 library calls 67884->67893 67886->67869 67889 7ff6ec00b586 67888->67889 67890 7ff6ec00b595 GetLastError 67888->67890 67889->67890 67891 7ff6ec00b58a 67889->67891 67890->67891 67891->67884 67892->67884 67893->67884 67894 7ff6ebfe918c 67895 7ff6ebfe91a2 67894->67895 67896 7ff6ebfe91bd 67894->67896 67928 7ff6ebfe4e68 11 API calls _get_daylight 67895->67928 67896->67895 67898 7ff6ebfe91d6 67896->67898 67900 7ff6ebfe91dc 67898->67900 67903 7ff6ebfe91f9 67898->67903 67899 7ff6ebfe91a7 67929 7ff6ebfe8234 78 API calls _invalid_parameter_noinfo 67899->67929 67930 7ff6ebfe4e68 11 API calls _get_daylight 67900->67930 67921 7ff6ebff33d0 67903->67921 67908 7ff6ebfe9473 67910 7ff6ebfe8284 _invalid_parameter_noinfo_noreturn 17 API calls 67908->67910 67912 7ff6ebfe9488 67910->67912 67915 7ff6ebfe923d 67916 7ff6ebfe92b6 67915->67916 67917 7ff6ebfe9256 67915->67917 67920 7ff6ebfe91b3 67916->67920 67950 7ff6ebff3414 78 API calls _isindst 67916->67950 67917->67920 67949 7ff6ebff3414 78 API calls _isindst 67917->67949 67922 7ff6ebff33df 67921->67922 67923 7ff6ebfe91fe 67921->67923 67951 7ff6ebfec3bc EnterCriticalSection 67922->67951 67931 7ff6ebff24e8 67923->67931 67928->67899 67929->67920 67930->67920 67932 7ff6ebff24f1 67931->67932 67934 7ff6ebfe9213 67931->67934 67952 7ff6ebfe4e68 11 API calls _get_daylight 67932->67952 67934->67908 67937 7ff6ebff2518 67934->67937 67935 7ff6ebff24f6 67953 7ff6ebfe8234 78 API calls _invalid_parameter_noinfo 67935->67953 67938 7ff6ebff2521 67937->67938 67939 7ff6ebfe9224 67937->67939 67954 7ff6ebfe4e68 11 API calls _get_daylight 67938->67954 67939->67908 67943 7ff6ebff2548 67939->67943 67941 7ff6ebff2526 67955 7ff6ebfe8234 78 API calls _invalid_parameter_noinfo 67941->67955 67944 7ff6ebff2551 67943->67944 67945 7ff6ebfe9235 67943->67945 67956 7ff6ebfe4e68 11 API calls _get_daylight 67944->67956 67945->67908 67945->67915 67947 7ff6ebff2556 67957 7ff6ebfe8234 78 API calls _invalid_parameter_noinfo 67947->67957 67949->67920 67950->67920 67952->67935 67953->67934 67954->67941 67955->67939 67956->67947 67957->67945 67958 7ff6ebfdc5cb 67959 7ff6ebfdc5f1 67958->67959 67973 7ff6ebfdc5dc 67958->67973 67960 7ff6ebfdc5fa 67959->67960 67975 7ff6ebfdc7bf 67959->67975 67962 7ff6ebf927e0 82 API calls 67960->67962 67978 7ff6ebfdc652 67960->67978 67961 7ff6ebfdc86f 67966 7ff6ebfdd050 84 API calls 67961->67966 67962->67978 67963 7ff6ebffe860 _Strcoll 8 API calls 67964 7ff6ebfdceb3 67963->67964 67965 7ff6ebfdd050 84 API calls 67965->67975 67967 7ff6ebfdc888 67966->67967 67969 7ff6ebfdc570 8 API calls 67967->67969 67968 7ff6ebfdc722 67972 7ff6ebfdd050 84 API calls 67968->67972 67969->67973 67970 7ff6ebfdc570 8 API calls 67970->67975 67971 7ff6ebfdd050 84 API calls 67971->67978 67974 7ff6ebfdc75b 67972->67974 67973->67963 67976 7ff6ebfdc570 8 API calls 67974->67976 67975->67961 67975->67965 67975->67970 67976->67973 67977 7ff6ebfdc570 8 API calls 67977->67978 67978->67968 67978->67971 67978->67977 67979 7ff6ebffd32c 67980 7ff6ebffd345 67979->67980 67981 7ff6ebffd341 67979->67981 67994 7ff6ebff64e4 67980->67994 67986 7ff6ebffd363 68020 7ff6ebffd410 78 API calls 5 library calls 67986->68020 67987 7ff6ebffd357 67988 7ff6ebfed3c8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 67987->67988 67988->67981 67990 7ff6ebffd36b 67991 7ff6ebfed3c8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 67990->67991 67992 7ff6ebffd38a 67991->67992 67993 7ff6ebfed3c8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 67992->67993 67993->67981 67995 7ff6ebff64f1 67994->67995 67996 7ff6ebff6536 67994->67996 68021 7ff6ebfe9fc0 83 API calls 3 library calls 67995->68021 68000 7ff6ebffe244 GetEnvironmentStringsW 67996->68000 67998 7ff6ebff6520 68022 7ff6ebff61bc 91 API calls 3 library calls 67998->68022 68001 7ff6ebffe274 68000->68001 68002 7ff6ebffd34f 68000->68002 68023 7ff6ebff34d4 WideCharToMultiByte 68001->68023 68002->67986 68002->67987 68020->67990 68021->67998 68022->67996 68024 7ff6ebf87633 68025 7ff6ebf7da40 78 API calls 68024->68025 68026 7ff6ebf87666 FindNextFileW 68025->68026 68027 7ff6ebf87684 68026->68027 68028 7ff6ebffe860 _Strcoll 8 API calls 68027->68028 68029 7ff6ebf876ab 68028->68029 68030 7ff6ebfe9aa8 68041 7ff6ebfe990c 68030->68041 68033 7ff6ebfe9b08 68034 7ff6ebfe9b49 68033->68034 68035 7ff6ebfe9acf 68033->68035 68059 7ff6ebfee768 78 API calls 2 library calls 68033->68059 68047 7ff6ebfe9934 68034->68047 68039 7ff6ebfe9b3d 68039->68034 68060 7ff6ebff0318 11 API calls 2 library calls 68039->68060 68042 7ff6ebfe9915 68041->68042 68043 7ff6ebfe9925 68041->68043 68061 7ff6ebfe4e68 11 API calls _get_daylight 68042->68061 68043->68033 68043->68035 68058 7ff6ebfe9a2c 78 API calls _invalid_parameter_noinfo 68043->68058 68045 7ff6ebfe991a 68062 7ff6ebfe8234 78 API calls _invalid_parameter_noinfo 68045->68062 68048 7ff6ebfe990c _fread_nolock 78 API calls 68047->68048 68049 7ff6ebfe9959 68048->68049 68050 7ff6ebfe99fa 68049->68050 68051 7ff6ebfe9969 68049->68051 68072 7ff6ebfece18 78 API calls 2 library calls 68050->68072 68053 7ff6ebfe9987 68051->68053 68056 7ff6ebfe99a5 68051->68056 68071 7ff6ebfece18 78 API calls 2 library calls 68053->68071 68055 7ff6ebfe9995 68055->68035 68056->68055 68063 7ff6ebff0f48 68056->68063 68058->68033 68059->68039 68060->68034 68061->68045 68062->68043 68064 7ff6ebff0f78 68063->68064 68073 7ff6ebff0d7c 68064->68073 68067 7ff6ebff0fb7 68070 7ff6ebff0fcc 68067->68070 68085 7ff6ebfdf864 78 API calls 2 library calls 68067->68085 68070->68055 68071->68055 68072->68055 68074 7ff6ebff0da5 68073->68074 68075 7ff6ebff0dd3 68073->68075 68074->68067 68084 7ff6ebfdf864 78 API calls 2 library calls 68074->68084 68076 7ff6ebff0dec 68075->68076 68078 7ff6ebff0e43 68075->68078 68087 7ff6ebfe8168 78 API calls 2 library calls 68076->68087 68086 7ff6ebff555c EnterCriticalSection 68078->68086 68084->68067 68085->68070 68087->68074 68088 7ff6ebfdc8c9 68089 7ff6ebfdc8f4 68088->68089 68098 7ff6ebfdc8df 68088->68098 68091 7ff6ebfdcac0 68089->68091 68095 7ff6ebfdc8fd 68089->68095 68090 7ff6ebfdcb29 68094 7ff6ebfdc570 8 API calls 68090->68094 68091->68090 68096 7ff6ebfdc570 8 API calls 68091->68096 68092 7ff6ebffe860 _Strcoll 8 API calls 68097 7ff6ebfdceb3 68092->68097 68093 7ff6ebfdca4a 68101 7ff6ebfdc570 8 API calls 68093->68101 68094->68098 68099 7ff6ebf98e80 82 API calls 68095->68099 68100 7ff6ebfdc95a memcpy_s 68095->68100 68096->68091 68098->68092 68099->68100 68100->68093 68102 7ff6ebfdc570 8 API calls 68100->68102 68101->68098 68102->68100

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 0 7ff6ebfd8330-7ff6ebfd87cc call 7ff6ebfd6540 call 7ff6ebfd6460 call 7ff6ebfd6860 call 7ff6ebfd6150 call 7ff6ebfd61f0 call 7ff6ebfd8030 call 7ff6ebfd5fc0 call 7ff6ebfad590 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf93ff0 call 7ff6ebfad590 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf93ff0 call 7ff6ebfad590 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf93ff0 call 7ff6ebfad590 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf93ff0 GlobalMemoryStatusEx 63 7ff6ebfd87d5-7ff6ebfd87e6 0->63 64 7ff6ebfd87ce-7ff6ebfd87d3 0->64 65 7ff6ebfd87ea-7ff6ebfd8af1 call 7ff6ebf93ff0 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf93ff0 call 7ff6ebfad590 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf93ff0 call 7ff6ebfad590 call 7ff6ebf986b0 call 7ff6ebf91900 63->65 64->65 96 7ff6ebfd8af4-7ff6ebfd8afc 65->96 96->96 97 7ff6ebfd8afe-7ff6ebfd8b6c call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf93ff0 call 7ff6ebfd5b70 96->97 106 7ff6ebfd8b6e 97->106 107 7ff6ebfd8b71-7ff6ebfd8c6d call 7ff6ebf95310 call 7ff6ebf955e0 call 7ff6ebf986b0 call 7ff6ebf91900 97->107 106->107 116 7ff6ebfd8c70-7ff6ebfd8c78 107->116 116->116 117 7ff6ebfd8c7a-7ff6ebfd8cd7 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf93ff0 116->117 124 7ff6ebfd8d0b-7ff6ebfd8d26 117->124 125 7ff6ebfd8cd9-7ff6ebfd8ceb 117->125 126 7ff6ebfd8d59-7ff6ebfd8edc call 7ff6ebfd59a0 call 7ff6ebf955e0 call 7ff6ebf986b0 call 7ff6ebf91900 124->126 127 7ff6ebfd8d28-7ff6ebfd8d39 124->127 128 7ff6ebfd8ced-7ff6ebfd8d00 125->128 129 7ff6ebfd8d06 call 7ff6ebffe880 125->129 153 7ff6ebfd8ee0-7ff6ebfd8ee8 126->153 131 7ff6ebfd8d54 call 7ff6ebffe880 127->131 132 7ff6ebfd8d3b-7ff6ebfd8d4e 127->132 128->129 134 7ff6ebfd9b0f-7ff6ebfd9b14 call 7ff6ebfe8254 128->134 129->124 131->126 132->131 135 7ff6ebfd9b15-7ff6ebfd9b1a call 7ff6ebfe8254 132->135 134->135 145 7ff6ebfd9b1b-7ff6ebfd9b20 call 7ff6ebfe8254 135->145 150 7ff6ebfd9b21-7ff6ebfd9b26 call 7ff6ebfe8254 145->150 157 7ff6ebfd9b27-7ff6ebfd9b2c call 7ff6ebfe8254 150->157 153->153 154 7ff6ebfd8eea-7ff6ebfd8f3d call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf93ff0 153->154 168 7ff6ebfd8f3f-7ff6ebfd8f50 154->168 169 7ff6ebfd8f70-7ff6ebfd8fcd call 7ff6ebfe840c call 7ff6ebfe948c call 7ff6ebfe9898 154->169 163 7ff6ebfd9b2d-7ff6ebfd9b32 call 7ff6ebfe8254 157->163 170 7ff6ebfd9b33-7ff6ebfd9b38 call 7ff6ebfe8254 163->170 171 7ff6ebfd8f52-7ff6ebfd8f65 168->171 172 7ff6ebfd8f6b call 7ff6ebffe880 168->172 186 7ff6ebfd8fd0-7ff6ebfd8fd8 169->186 179 7ff6ebfd9b39-7ff6ebfd9b3e call 7ff6ebfe8254 170->179 171->145 171->172 172->169 185 7ff6ebfd9b3f-7ff6ebfd9b44 call 7ff6ebfe8254 179->185 191 7ff6ebfd9b45-7ff6ebfd9b4a call 7ff6ebfe8254 185->191 186->186 188 7ff6ebfd8fda-7ff6ebfd90dc call 7ff6ebf986b0 call 7ff6ebf955e0 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf93ff0 186->188 218 7ff6ebfd910f-7ff6ebfd9167 call 7ff6ec011650 GetModuleFileNameA 188->218 219 7ff6ebfd90de-7ff6ebfd90ef 188->219 197 7ff6ebfd9b4b-7ff6ebfd9b50 call 7ff6ebfe8254 191->197 203 7ff6ebfd9b51-7ff6ebfd9b56 call 7ff6ebfe8254 197->203 209 7ff6ebfd9b57-7ff6ebfd9b5c call 7ff6ebfe8254 203->209 215 7ff6ebfd9b5d-7ff6ebfd9b62 call 7ff6ebfe8254 209->215 223 7ff6ebfd9b63-7ff6ebfd9b68 call 7ff6ebfe8254 215->223 229 7ff6ebfd9170-7ff6ebfd9178 218->229 221 7ff6ebfd90f1-7ff6ebfd9104 219->221 222 7ff6ebfd910a call 7ff6ebffe880 219->222 221->150 221->222 222->218 229->229 230 7ff6ebfd917a-7ff6ebfd92a2 call 7ff6ebf986b0 call 7ff6ebf95310 call 7ff6ebf955e0 call 7ff6ebf986b0 call 7ff6ebf91900 229->230 241 7ff6ebfd92a5-7ff6ebfd92ad 230->241 241->241 242 7ff6ebfd92af-7ff6ebfd930d call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf93ff0 241->242 249 7ff6ebfd930f-7ff6ebfd9320 242->249 250 7ff6ebfd9340-7ff6ebfd935b 242->250 253 7ff6ebfd9322-7ff6ebfd9335 249->253 254 7ff6ebfd933b call 7ff6ebffe880 249->254 251 7ff6ebfd938f-7ff6ebfd93b9 call 7ff6ebfd76a0 250->251 252 7ff6ebfd935d-7ff6ebfd936f 250->252 261 7ff6ebfd93be-7ff6ebfd94ae call 7ff6ebf95310 call 7ff6ebf955e0 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf93ff0 251->261 262 7ff6ebfd93bb 251->262 256 7ff6ebfd9371-7ff6ebfd9384 252->256 257 7ff6ebfd938a call 7ff6ebffe880 252->257 253->157 253->254 254->250 256->163 256->257 257->251 277 7ff6ebfd94e4-7ff6ebfd94fb 261->277 278 7ff6ebfd94b0-7ff6ebfd94c4 261->278 262->261 281 7ff6ebfd952e-7ff6ebfd964c call 7ff6ebf95310 call 7ff6ebf955e0 call 7ff6ebf986b0 call 7ff6ebf91900 277->281 282 7ff6ebfd94fd-7ff6ebfd950e 277->282 279 7ff6ebfd94df call 7ff6ebffe880 278->279 280 7ff6ebfd94c6-7ff6ebfd94d9 278->280 279->277 280->170 280->279 295 7ff6ebfd9651-7ff6ebfd9658 281->295 285 7ff6ebfd9510-7ff6ebfd9523 282->285 286 7ff6ebfd9529 call 7ff6ebffe880 282->286 285->179 285->286 286->281 295->295 296 7ff6ebfd965a-7ff6ebfd96b4 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf93ff0 295->296 303 7ff6ebfd96ea-7ff6ebfd970a 296->303 304 7ff6ebfd96b6-7ff6ebfd96ca 296->304 307 7ff6ebfd97e2-7ff6ebfd989e call 7ff6ebf937f0 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf986b0 call 7ff6ebf91900 303->307 308 7ff6ebfd9710-7ff6ebfd97dd call 7ff6ebfad590 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf986b0 call 7ff6ebf91900 303->308 305 7ff6ebfd96e5 call 7ff6ebffe880 304->305 306 7ff6ebfd96cc-7ff6ebfd96df 304->306 305->303 306->185 306->305 330 7ff6ebfd98a3-7ff6ebfd98bb call 7ff6ebf93ff0 307->330 308->330 333 7ff6ebfd98ee-7ff6ebfd9909 330->333 334 7ff6ebfd98bd-7ff6ebfd98ce 330->334 337 7ff6ebfd990b-7ff6ebfd991c 333->337 338 7ff6ebfd993c-7ff6ebfd9953 333->338 335 7ff6ebfd98d0-7ff6ebfd98e3 334->335 336 7ff6ebfd98e9 call 7ff6ebffe880 334->336 335->191 335->336 336->333 340 7ff6ebfd991e-7ff6ebfd9931 337->340 341 7ff6ebfd9937 call 7ff6ebffe880 337->341 342 7ff6ebfd9955-7ff6ebfd9969 338->342 343 7ff6ebfd9989-7ff6ebfd99a3 338->343 340->197 340->341 341->338 347 7ff6ebfd9984 call 7ff6ebffe880 342->347 348 7ff6ebfd996b-7ff6ebfd997e 342->348 344 7ff6ebfd99a5-7ff6ebfd99b9 343->344 345 7ff6ebfd99d9-7ff6ebfd99f3 343->345 349 7ff6ebfd99d4 call 7ff6ebffe880 344->349 350 7ff6ebfd99bb-7ff6ebfd99ce 344->350 351 7ff6ebfd99f5-7ff6ebfd9a09 345->351 352 7ff6ebfd9a29-7ff6ebfd9a43 345->352 347->343 348->203 348->347 349->345 350->209 350->349 355 7ff6ebfd9a24 call 7ff6ebffe880 351->355 356 7ff6ebfd9a0b-7ff6ebfd9a1e 351->356 357 7ff6ebfd9a45-7ff6ebfd9a59 352->357 358 7ff6ebfd9a79-7ff6ebfd9a93 352->358 355->352 356->215 356->355 360 7ff6ebfd9a74 call 7ff6ebffe880 357->360 361 7ff6ebfd9a5b-7ff6ebfd9a6e 357->361 362 7ff6ebfd9ac5-7ff6ebfd9b08 call 7ff6ebffe860 358->362 363 7ff6ebfd9a95-7ff6ebfd9aa9 358->363 360->358 361->223 361->360 364 7ff6ebfd9ac0 call 7ff6ebffe880 363->364 365 7ff6ebfd9aab-7ff6ebfd9abe 363->365 364->362 365->364 368 7ff6ebfd9b09-7ff6ebfd9b0e call 7ff6ebfe8254 365->368 368->134
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$Name$DevicesDisplayEnum$ComputerFileGlobalMemoryModuleStatusUserValuewcsftime
                                              • String ID: %d-%m-%Y, %H:%M:%S$computer_name$cpu$gpu$ram$system$time$timezone$user_name
                                              • API String ID: 4122120932-1182675529
                                              • Opcode ID: 144dd6f8b04f88af25308643b4b5e8a4b2b864948436e5f9f7b139f435a0641b
                                              • Instruction ID: 059098e3d428038ffd7e35c47a0d664bd7e772bb1d16dcd1b1066a2d9227f7d1
                                              • Opcode Fuzzy Hash: 144dd6f8b04f88af25308643b4b5e8a4b2b864948436e5f9f7b139f435a0641b
                                              • Instruction Fuzzy Hash: EFE29333A18BC195DB21CF65E8403ED77A1FB89798F009225EA8D47BA9DF39D284C705
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$CloseOpenQueryValue
                                              • String ID: content$directory_iterator::directory_iterator$exists$filename$status
                                              • API String ID: 1254564140-3429737954
                                              • Opcode ID: 55c2bb045bb96185970b24680b3c0d0404c05ffe49abc176e468b77682173e3f
                                              • Instruction ID: 7097a1ccaa93d1fded14a95a941da76685b5b0d78db4b6555aad8f60734b87ce
                                              • Opcode Fuzzy Hash: 55c2bb045bb96185970b24680b3c0d0404c05ffe49abc176e468b77682173e3f
                                              • Instruction Fuzzy Hash: A5E28F73A14BC18AEB218F75D8803ED3365FB89758F504235EA5C8BAA9DF79D284C305

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 800 7ff6ebfb6350-7ff6ebfb69ee call 7ff6ebf7d4e0 call 7ff6ebf7d370 808 7ff6ebfb69f0-7ff6ebfb69f7 800->808 808->808 809 7ff6ebfb69f9-7ff6ebfba9b7 call 7ff6ebfa5c20 call 7ff6ebf7d810 call 7ff6ebf7eaf0 call 7ff6ebf7e240 call 7ff6ebfe8254 * 3 call 7ff6ebf7e1d0 call 7ff6ebfe8254 call 7ff6ebf939b0 call 7ff6ebf979f0 call 7ff6ebf97ac0 call 7ff6ec000e88 call 7ff6ebfe8254 * 2 call 7ff6ebf7cf70 call 7ff6ebf7e0c0 call 7ff6ebf7e1d0 call 7ff6ebf7e240 call 7ff6ebfe8254 call 7ff6ebf7e1d0 * 2 call 7ff6ebfe8254 call 7ff6ebf939b0 call 7ff6ebf979f0 call 7ff6ebf97ac0 call 7ff6ec000e88 call 7ff6ebfe8254 call 7ff6ebf7e0c0 call 7ff6ebf7cf70 call 7ff6ebfe8254 call 7ff6ebf7e240 call 7ff6ebfe8254 * 3 call 7ff6ebf7e1d0 call 7ff6ebfe8254 call 7ff6ebf939b0 call 7ff6ebf979f0 call 7ff6ebf97ac0 call 7ff6ec000e88 call 7ff6ebfe8254 * 2 call 7ff6ebf7cf70 call 7ff6ebf7e0c0 call 7ff6ebf7e1d0 call 7ff6ebf7e240 call 7ff6ebf7e1d0 * 4 call 7ff6ebf7cf70 call 7ff6ebf7e1d0 * 3 call 7ff6ebf7cf70 call 7ff6ebfe8254 * 3 call 7ff6ebfd0040 call 7ff6ec011650 GetModuleFileNameW 808->809 939 7ff6ebfba9c0-7ff6ebfba9c9 809->939 939->939 940 7ff6ebfba9cb-7ff6ebfbabde call 7ff6ebf86940 939->940 943 7ff6ebfbabe1-7ff6ebfbabea 940->943 943->943 944 7ff6ebfbabec-7ff6ebfbae7d call 7ff6ebf86940 call 7ff6ebf86bd0 call 7ff6ebf95fd0 943->944 954 7ff6ebfbae80-7ff6ebfbae89 944->954 954->954 955 7ff6ebfbae8b-7ff6ebfbb11e call 7ff6ebf86940 call 7ff6ebf86bd0 call 7ff6ebf95fd0 954->955 965 7ff6ebfbb121-7ff6ebfbb12a 955->965 965->965 966 7ff6ebfbb12c-7ff6ebfbb600 call 7ff6ebf86940 call 7ff6ebf7d4a0 call 7ff6ebf95fd0 965->966 979 7ff6ebfbb603-7ff6ebfbb60c 966->979 979->979 980 7ff6ebfbb60e-7ff6ebfbb8bd call 7ff6ebf86940 call 7ff6ebf86bd0 call 7ff6ebf95fd0 979->980 990 7ff6ebfbb8c0-7ff6ebfbb8c9 980->990 990->990 991 7ff6ebfbb8cb-7ff6ebfbbb70 call 7ff6ebf86940 call 7ff6ebf86bd0 call 7ff6ebf95fd0 990->991 1001 7ff6ebfbbb73-7ff6ebfbbb7c 991->1001 1001->1001 1002 7ff6ebfbbb7e-7ff6ebfbbd8b call 7ff6ebf86940 call 7ff6ebf86bd0 call 7ff6ebf95fd0 1001->1002 1012 7ff6ebfbbd90-7ff6ebfbbd99 1002->1012 1012->1012 1013 7ff6ebfbbd9b-7ff6ebfbc0c7 call 7ff6ebf86940 call 7ff6ebf86bd0 call 7ff6ebf95fd0 1012->1013 1023 7ff6ebfbc0d0-7ff6ebfbc0d8 1013->1023 1023->1023 1024 7ff6ebfbc0da-7ff6ebfbc326 call 7ff6ebf86940 call 7ff6ebf86bd0 call 7ff6ebf95fd0 call 7ff6ebf7cf70 call 7ff6ebfb5d70 1023->1024
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: __std_fs_convert_wide_to_narrow$__std_fs_code_page
                                              • String ID: cannot use push_back() with $directory_iterator::directory_iterator$exists$recursive_directory_iterator::operator++$recursive_directory_iterator::recursive_directory_iterator$status
                                              • API String ID: 3645842244-1862120484
                                              • Opcode ID: b85098497e29e174e5e0d125e38a865b4444aacdb133920c5e87522b3c1c6480
                                              • Instruction ID: 63c7990759061a6ac2e2b104242239598be81c0e5c3a8222dff5f3ca560cd018
                                              • Opcode Fuzzy Hash: b85098497e29e174e5e0d125e38a865b4444aacdb133920c5e87522b3c1c6480
                                              • Instruction Fuzzy Hash: E9D21473919BC985D6708B19F4813AAB3A0FB9C784F405225EACC93B69EF7DD254CB04

                                              Control-flow Graph

                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Object$DeleteMetricsSystem$CreateSelectStream_$CapsCompatibleCriticalDeviceReleaseSection$BitmapEnterLeaveReadResetSizeStream
                                              • String ID:
                                              • API String ID: 3214587331-3916222277
                                              • Opcode ID: b4a9d957edc9c5224d8b964fe23b4a119de3175bf205accea35f2dd7d15a2983
                                              • Instruction ID: a21de02c23ba1453c4d8af16ce631e0f3d02d6f68a48fed9d71e0dfe2b77be11
                                              • Opcode Fuzzy Hash: b4a9d957edc9c5224d8b964fe23b4a119de3175bf205accea35f2dd7d15a2983
                                              • Instruction Fuzzy Hash: 0BB16633608BC185E764DB21F8643AAB3A5FB89B90F404535DA8E83B65DF3DD084CB49

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 1078 7ff6ebf8d570-7ff6ebf8d66f LoadLibraryA 1079 7ff6ebf8e530-7ff6ebf8e53a 1078->1079 1080 7ff6ebf8d675-7ff6ebf8da30 GetProcAddress * 6 1078->1080 1082 7ff6ebf8e549-7ff6ebf8e54c 1079->1082 1083 7ff6ebf8e53c-7ff6ebf8e53e 1079->1083 1080->1079 1081 7ff6ebf8da36-7ff6ebf8da39 1080->1081 1081->1079 1086 7ff6ebf8da3f-7ff6ebf8da42 1081->1086 1084 7ff6ebf8e54e-7ff6ebf8e551 FreeLibrary 1082->1084 1085 7ff6ebf8e557-7ff6ebf8e586 call 7ff6ebffe860 1082->1085 1083->1082 1084->1085 1086->1079 1089 7ff6ebf8da48-7ff6ebf8da4b 1086->1089 1089->1079 1091 7ff6ebf8da51-7ff6ebf8da54 1089->1091 1091->1079 1092 7ff6ebf8da5a-7ff6ebf8da5d 1091->1092 1092->1079 1093 7ff6ebf8da63-7ff6ebf8da71 1092->1093 1094 7ff6ebf8da75-7ff6ebf8da77 1093->1094 1094->1079 1095 7ff6ebf8da7d-7ff6ebf8da89 1094->1095 1095->1079 1096 7ff6ebf8da8f-7ff6ebf8da98 1095->1096 1097 7ff6ebf8daa0-7ff6ebf8dabb 1096->1097 1099 7ff6ebf8dac1-7ff6ebf8dadf 1097->1099 1100 7ff6ebf8e517-7ff6ebf8e523 1097->1100 1099->1100 1103 7ff6ebf8dae5-7ff6ebf8daf7 1099->1103 1100->1097 1101 7ff6ebf8e529 1100->1101 1101->1079 1104 7ff6ebf8e503-7ff6ebf8e512 1103->1104 1105 7ff6ebf8dafd 1103->1105 1104->1100 1106 7ff6ebf8db02-7ff6ebf8db53 call 7ff6ebffe888 1105->1106 1111 7ff6ebf8ddd2 1106->1111 1112 7ff6ebf8db59-7ff6ebf8db60 1106->1112 1114 7ff6ebf8ddd4-7ff6ebf8dddb 1111->1114 1112->1111 1113 7ff6ebf8db66-7ff6ebf8dc5f call 7ff6ebfc78f0 call 7ff6ebf95310 call 7ff6ebf955e0 1112->1113 1139 7ff6ebf8dc60-7ff6ebf8dc68 1113->1139 1116 7ff6ebf8e051-7ff6ebf8e08d 1114->1116 1117 7ff6ebf8dde1-7ff6ebf8dde8 1114->1117 1125 7ff6ebf8e093-7ff6ebf8e0a1 1116->1125 1126 7ff6ebf8e327-7ff6ebf8e329 1116->1126 1117->1116 1118 7ff6ebf8ddee-7ff6ebf8dedb call 7ff6ebfc78f0 call 7ff6ebf95310 call 7ff6ebf955e0 1117->1118 1151 7ff6ebf8dee2-7ff6ebf8deea 1118->1151 1129 7ff6ebf8e320-7ff6ebf8e323 1125->1129 1130 7ff6ebf8e0a7-7ff6ebf8e0ae 1125->1130 1131 7ff6ebf8e32f-7ff6ebf8e458 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf93ff0 call 7ff6ebffe888 call 7ff6ebfb51b0 1126->1131 1132 7ff6ebf8e4d5-7ff6ebf8e4eb call 7ff6ebf900f0 1126->1132 1129->1126 1135 7ff6ebf8e325 1129->1135 1130->1129 1137 7ff6ebf8e0b4-7ff6ebf8e1a8 call 7ff6ebfc78f0 call 7ff6ebf95310 call 7ff6ebf955e0 1130->1137 1222 7ff6ebf8e464-7ff6ebf8e477 call 7ff6ebf937f0 1131->1222 1223 7ff6ebf8e45a-7ff6ebf8e45c 1131->1223 1146 7ff6ebf8db00 1132->1146 1147 7ff6ebf8e4f1-7ff6ebf8e4fc 1132->1147 1135->1126 1168 7ff6ebf8e1b0-7ff6ebf8e1b7 1137->1168 1139->1139 1144 7ff6ebf8dc6a-7ff6ebf8dcc4 call 7ff6ebf986b0 call 7ff6ebf96bc0 call 7ff6ebf93ff0 1139->1144 1175 7ff6ebf8dcc6-7ff6ebf8dcd7 1144->1175 1176 7ff6ebf8dcf7-7ff6ebf8dd21 1144->1176 1146->1106 1147->1104 1151->1151 1155 7ff6ebf8deec-7ff6ebf8df45 call 7ff6ebf986b0 call 7ff6ebf96bc0 call 7ff6ebf93ff0 1151->1155 1194 7ff6ebf8df47-7ff6ebf8df58 1155->1194 1195 7ff6ebf8df78-7ff6ebf8dfa2 1155->1195 1168->1168 1173 7ff6ebf8e1b9-7ff6ebf8e212 call 7ff6ebf986b0 call 7ff6ebf96bc0 call 7ff6ebf93ff0 1168->1173 1233 7ff6ebf8e214-7ff6ebf8e225 1173->1233 1234 7ff6ebf8e245-7ff6ebf8e26e 1173->1234 1182 7ff6ebf8dcf2 call 7ff6ebffe880 1175->1182 1183 7ff6ebf8dcd9-7ff6ebf8dcec 1175->1183 1179 7ff6ebf8dd23-7ff6ebf8dd37 1176->1179 1180 7ff6ebf8dd59-7ff6ebf8dd7f 1176->1180 1187 7ff6ebf8dd52-7ff6ebf8dd57 call 7ff6ebffe880 1179->1187 1188 7ff6ebf8dd39-7ff6ebf8dd4c 1179->1188 1190 7ff6ebf8dd81-7ff6ebf8dd95 1180->1190 1191 7ff6ebf8ddb7-7ff6ebf8ddd0 1180->1191 1182->1176 1183->1182 1192 7ff6ebf8e5e1-7ff6ebf8e5e6 call 7ff6ebfe8254 1183->1192 1187->1180 1188->1187 1199 7ff6ebf8e5e7-7ff6ebf8e5ec call 7ff6ebfe8254 1188->1199 1205 7ff6ebf8ddb0-7ff6ebf8ddb5 call 7ff6ebffe880 1190->1205 1206 7ff6ebf8dd97-7ff6ebf8ddaa 1190->1206 1191->1114 1192->1199 1196 7ff6ebf8df73 call 7ff6ebffe880 1194->1196 1197 7ff6ebf8df5a-7ff6ebf8df6d 1194->1197 1202 7ff6ebf8dfa4-7ff6ebf8dfb8 1195->1202 1203 7ff6ebf8dfda-7ff6ebf8e000 1195->1203 1196->1195 1197->1196 1207 7ff6ebf8e5f3-7ff6ebf8e5f8 call 7ff6ebfe8254 1197->1207 1215 7ff6ebf8e5ed-7ff6ebf8e5f2 call 7ff6ebfe8254 1199->1215 1212 7ff6ebf8dfd3-7ff6ebf8dfd8 call 7ff6ebffe880 1202->1212 1213 7ff6ebf8dfba-7ff6ebf8dfcd 1202->1213 1217 7ff6ebf8e002-7ff6ebf8e016 1203->1217 1218 7ff6ebf8e038-7ff6ebf8e04a 1203->1218 1205->1191 1206->1205 1206->1215 1224 7ff6ebf8e5f9-7ff6ebf8e5fe call 7ff6ebfe8254 1207->1224 1212->1203 1213->1212 1213->1224 1215->1207 1226 7ff6ebf8e031-7ff6ebf8e036 call 7ff6ebffe880 1217->1226 1227 7ff6ebf8e018-7ff6ebf8e02b 1217->1227 1218->1116 1246 7ff6ebf8e47b-7ff6ebf8e487 1222->1246 1235 7ff6ebf8e462 1223->1235 1236 7ff6ebf8e58d-7ff6ebf8e5da call 7ff6ebf939b0 call 7ff6ebf979f0 call 7ff6ebf97ac0 call 7ff6ec000e88 1223->1236 1239 7ff6ebf8e5ff-7ff6ebf8e604 call 7ff6ebfe8254 1224->1239 1226->1218 1227->1226 1227->1239 1243 7ff6ebf8e240 call 7ff6ebffe880 1233->1243 1244 7ff6ebf8e227-7ff6ebf8e23a 1233->1244 1247 7ff6ebf8e270-7ff6ebf8e284 1234->1247 1248 7ff6ebf8e2a4-7ff6ebf8e2ca 1234->1248 1235->1246 1270 7ff6ebf8e5db-7ff6ebf8e5e0 call 7ff6ebfe8254 1236->1270 1252 7ff6ebf8e605-7ff6ebf8e60a call 7ff6ebfe8254 1239->1252 1243->1234 1244->1243 1244->1252 1257 7ff6ebf8e4ae-7ff6ebf8e4b8 call 7ff6ebfa0610 1246->1257 1258 7ff6ebf8e489-7ff6ebf8e4ac 1246->1258 1255 7ff6ebf8e29f call 7ff6ebffe880 1247->1255 1256 7ff6ebf8e286-7ff6ebf8e299 1247->1256 1260 7ff6ebf8e300-7ff6ebf8e319 1248->1260 1261 7ff6ebf8e2cc-7ff6ebf8e2e0 1248->1261 1255->1248 1256->1255 1263 7ff6ebf8e587-7ff6ebf8e58c call 7ff6ebfe8254 1256->1263 1265 7ff6ebf8e4bd-7ff6ebf8e4ce call 7ff6ebf93ff0 1257->1265 1258->1265 1260->1129 1268 7ff6ebf8e2e2-7ff6ebf8e2f5 1261->1268 1269 7ff6ebf8e2fb call 7ff6ebffe880 1261->1269 1263->1236 1265->1132 1268->1269 1268->1270 1269->1260 1270->1192
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$AddressProc$Library$FreeLoad
                                              • String ID: cannot use push_back() with $system$vault
                                              • API String ID: 2463004387-1741236777
                                              • Opcode ID: 02ed4c03ae5195d23b1ec4d987f7dc12a0391b494a2e0b00b14e86e221b1b524
                                              • Instruction ID: 1bf4401dcb705a94f5db71f40f700a1524a2412962c910e8be8fbf509853b8b6
                                              • Opcode Fuzzy Hash: 02ed4c03ae5195d23b1ec4d987f7dc12a0391b494a2e0b00b14e86e221b1b524
                                              • Instruction Fuzzy Hash: 89925D33605BC589DB608F69E8943ED73A0FB49798F104225DB9C9BBA9EF39D644C304

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 1285 7ff6ebf82ca0-7ff6ebf82d72 1286 7ff6ebf82d75-7ff6ebf82d7c 1285->1286 1286->1286 1287 7ff6ebf82d7e-7ff6ebf82efe call 7ff6ebf986b0 1286->1287 1290 7ff6ebf82f01-7ff6ebf82f09 1287->1290 1290->1290 1291 7ff6ebf82f0b-7ff6ebf82f93 call 7ff6ebf986b0 1290->1291 1294 7ff6ebf82f96-7ff6ebf82f9e 1291->1294 1294->1294 1295 7ff6ebf82fa0-7ff6ebf8302a call 7ff6ebf986b0 RegOpenKeyExA 1294->1295 1298 7ff6ebf83030-7ff6ebf83072 RegQueryValueExA 1295->1298 1299 7ff6ebf830ee-7ff6ebf830f5 1295->1299 1298->1299 1302 7ff6ebf83074-7ff6ebf830b2 call 7ff6ebf986b0 call 7ff6ebf928e0 1298->1302 1300 7ff6ebf830fd-7ff6ebf83168 call 7ff6ebfa5c20 1299->1300 1301 7ff6ebf830f7 RegCloseKey 1299->1301 1307 7ff6ebf8319c-7ff6ebf831af 1300->1307 1308 7ff6ebf8316a-7ff6ebf8317c 1300->1308 1301->1300 1320 7ff6ebf830e5-7ff6ebf830ea 1302->1320 1321 7ff6ebf830b4-7ff6ebf830c5 1302->1321 1312 7ff6ebf8382b-7ff6ebf83836 1307->1312 1313 7ff6ebf831b5-7ff6ebf831f5 call 7ff6ebf7eaf0 1307->1313 1310 7ff6ebf83197 call 7ff6ebffe880 1308->1310 1311 7ff6ebf8317e-7ff6ebf83191 1308->1311 1310->1307 1311->1310 1317 7ff6ebf839d1-7ff6ebf839d6 call 7ff6ebfe8254 1311->1317 1315 7ff6ebf83838-7ff6ebf8384e 1312->1315 1316 7ff6ebf8386e-7ff6ebf83890 1312->1316 1337 7ff6ebf831fb-7ff6ebf831fe 1313->1337 1338 7ff6ebf839a7-7ff6ebf839a9 1313->1338 1322 7ff6ebf83869 call 7ff6ebffe880 1315->1322 1323 7ff6ebf83850-7ff6ebf83863 1315->1323 1325 7ff6ebf838c6-7ff6ebf838e0 1316->1325 1326 7ff6ebf83892-7ff6ebf838a6 1316->1326 1344 7ff6ebf839d7-7ff6ebf839e9 call 7ff6ebf7e1d0 1317->1344 1320->1299 1328 7ff6ebf830c7-7ff6ebf830da 1321->1328 1329 7ff6ebf830e0 call 7ff6ebffe880 1321->1329 1322->1316 1323->1322 1330 7ff6ebf839f0-7ff6ebf839f5 call 7ff6ebfe8254 1323->1330 1335 7ff6ebf83916-7ff6ebf83930 1325->1335 1336 7ff6ebf838e2-7ff6ebf838f6 1325->1336 1333 7ff6ebf838a8-7ff6ebf838bb 1326->1333 1334 7ff6ebf838c1 call 7ff6ebffe880 1326->1334 1328->1329 1339 7ff6ebf839cb-7ff6ebf839d0 call 7ff6ebfe8254 1328->1339 1329->1320 1371 7ff6ebf839f6-7ff6ebf83a05 call 7ff6ebf7e1d0 1330->1371 1333->1334 1345 7ff6ebf83a1e-7ff6ebf83a23 call 7ff6ebfe8254 1333->1345 1334->1325 1341 7ff6ebf83962-7ff6ebf839a6 call 7ff6ebffe860 1335->1341 1342 7ff6ebf83932-7ff6ebf83946 1335->1342 1350 7ff6ebf838f8-7ff6ebf8390b 1336->1350 1351 7ff6ebf83911 call 7ff6ebffe880 1336->1351 1337->1312 1352 7ff6ebf83204-7ff6ebf8322b call 7ff6ebf7d020 1337->1352 1346 7ff6ebf839ab 1338->1346 1347 7ff6ebf839b6-7ff6ebf839ca call 7ff6ebf7e240 1338->1347 1339->1317 1353 7ff6ebf8395d call 7ff6ebffe880 1342->1353 1354 7ff6ebf83948-7ff6ebf8395b 1342->1354 1376 7ff6ebf839ea-7ff6ebf839ef call 7ff6ebfe8254 1344->1376 1360 7ff6ebf83a24-7ff6ebf83a29 call 7ff6ebfe8254 1345->1360 1346->1312 1347->1339 1350->1351 1350->1360 1351->1335 1373 7ff6ebf8322d 1352->1373 1374 7ff6ebf8329c-7ff6ebf83305 call 7ff6ebf86940 call 7ff6ebf95140 1352->1374 1353->1341 1354->1353 1366 7ff6ebf839b0-7ff6ebf839b5 call 7ff6ebfe8254 1354->1366 1366->1347 1384 7ff6ebf83a06-7ff6ebf83a0b call 7ff6ebfe8254 1371->1384 1381 7ff6ebf83230-7ff6ebf83237 1373->1381 1374->1344 1396 7ff6ebf8330b-7ff6ebf8331a 1374->1396 1376->1330 1386 7ff6ebf83239-7ff6ebf8323d 1381->1386 1387 7ff6ebf8323f-7ff6ebf83246 1381->1387 1395 7ff6ebf83a0c-7ff6ebf83a11 call 7ff6ebfe8254 1384->1395 1386->1387 1391 7ff6ebf83248-7ff6ebf8324b 1386->1391 1387->1381 1387->1391 1391->1374 1394 7ff6ebf8324d 1391->1394 1397 7ff6ebf83250-7ff6ebf8325c 1394->1397 1410 7ff6ebf83a12-7ff6ebf83a17 call 7ff6ebfe8254 1395->1410 1399 7ff6ebf8331c-7ff6ebf83332 1396->1399 1400 7ff6ebf83352-7ff6ebf83382 1396->1400 1401 7ff6ebf8326e-7ff6ebf83271 1397->1401 1402 7ff6ebf8325e-7ff6ebf83262 1397->1402 1404 7ff6ebf8334d call 7ff6ebffe880 1399->1404 1405 7ff6ebf83334-7ff6ebf83347 1399->1405 1407 7ff6ebf8338c-7ff6ebf833cb call 7ff6ebf7e8c0 1400->1407 1408 7ff6ebf83384-7ff6ebf83388 1400->1408 1401->1374 1409 7ff6ebf83273-7ff6ebf83277 1401->1409 1402->1401 1406 7ff6ebf83264-7ff6ebf8326a 1402->1406 1404->1400 1405->1376 1405->1404 1406->1397 1412 7ff6ebf8326c 1406->1412 1420 7ff6ebf833cd-7ff6ebf833d6 1407->1420 1421 7ff6ebf833da-7ff6ebf83404 call 7ff6ebf7e9a0 1407->1421 1408->1407 1414 7ff6ebf83280-7ff6ebf8328c 1409->1414 1423 7ff6ebf83a18-7ff6ebf83a1d call 7ff6ebf7cf70 1410->1423 1412->1374 1417 7ff6ebf83294-7ff6ebf8329a 1414->1417 1418 7ff6ebf8328e-7ff6ebf83292 1414->1418 1417->1374 1417->1414 1418->1374 1418->1417 1420->1421 1426 7ff6ebf8340a 1421->1426 1427 7ff6ebf83789-7ff6ebf83793 1421->1427 1423->1345 1429 7ff6ebf83410-7ff6ebf83431 call 7ff6ebf7eaf0 1426->1429 1430 7ff6ebf83795-7ff6ebf8379f 1427->1430 1431 7ff6ebf837bf-7ff6ebf837c9 1427->1431 1439 7ff6ebf83433-7ff6ebf8343b 1429->1439 1440 7ff6ebf83441-7ff6ebf83444 1429->1440 1430->1431 1435 7ff6ebf837a1-7ff6ebf837b3 1430->1435 1432 7ff6ebf837cb-7ff6ebf837d5 1431->1432 1433 7ff6ebf837f5-7ff6ebf837fc 1431->1433 1432->1433 1436 7ff6ebf837d7-7ff6ebf837e9 1432->1436 1433->1312 1438 7ff6ebf837fe-7ff6ebf83808 1433->1438 1435->1431 1446 7ff6ebf837b5-7ff6ebf837be 1435->1446 1436->1433 1447 7ff6ebf837eb-7ff6ebf837f4 1436->1447 1438->1312 1441 7ff6ebf8380a-7ff6ebf8381e 1438->1441 1439->1371 1439->1440 1444 7ff6ebf8344a-7ff6ebf83461 call 7ff6ebfcf8f0 1440->1444 1445 7ff6ebf83769-7ff6ebf83783 call 7ff6ebf7e7b0 1440->1445 1441->1312 1453 7ff6ebf83820-7ff6ebf8382a 1441->1453 1456 7ff6ebf8375d-7ff6ebf83764 call 7ff6ebf7f380 1444->1456 1457 7ff6ebf83467-7ff6ebf834b0 call 7ff6ebf93a40 call 7ff6ebf7d4e0 call 7ff6ebf7d370 1444->1457 1445->1427 1445->1429 1446->1431 1447->1433 1453->1312 1456->1445 1466 7ff6ebf834b5-7ff6ebf83554 call 7ff6ebf95310 call 7ff6ebf955e0 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf93ff0 1457->1466 1467 7ff6ebf834b2 1457->1467 1478 7ff6ebf83587-7ff6ebf8359f 1466->1478 1479 7ff6ebf83556-7ff6ebf83567 1466->1479 1467->1466 1482 7ff6ebf835d2-7ff6ebf835ea 1478->1482 1483 7ff6ebf835a1-7ff6ebf835b2 1478->1483 1480 7ff6ebf83569-7ff6ebf8357c 1479->1480 1481 7ff6ebf83582 call 7ff6ebffe880 1479->1481 1480->1384 1480->1481 1481->1478 1487 7ff6ebf835ec-7ff6ebf83602 1482->1487 1488 7ff6ebf83622-7ff6ebf83643 1482->1488 1485 7ff6ebf835cd call 7ff6ebffe880 1483->1485 1486 7ff6ebf835b4-7ff6ebf835c7 1483->1486 1485->1482 1486->1395 1486->1485 1490 7ff6ebf8361d call 7ff6ebffe880 1487->1490 1491 7ff6ebf83604-7ff6ebf83617 1487->1491 1488->1423 1492 7ff6ebf83649-7ff6ebf8375c call 7ff6ebfad590 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf93ff0 call 7ff6ebf929b0 call 7ff6ebf91900 call 7ff6ebf929b0 call 7ff6ebf91900 call 7ff6ebf917a0 call 7ff6ebf93ff0 1488->1492 1490->1488 1491->1410 1491->1490 1492->1456
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$CloseOpenQueryValue
                                              • String ID: content$directory_iterator::directory_iterator$exists$filename$status
                                              • API String ID: 1254564140-3429737954
                                              • Opcode ID: cca0d0ff4b654a582c9538a666395e913b528b61201c86974eb431a7376eaa37
                                              • Instruction ID: 904517c3eb2c136bd475b89a57673064efea97e7480bbf6b64f3ff619ee37366
                                              • Opcode Fuzzy Hash: cca0d0ff4b654a582c9538a666395e913b528b61201c86974eb431a7376eaa37
                                              • Instruction Fuzzy Hash: B3829D73A15BC589EB208F35D8803ED73A1FB89798F105221EA9D87BA9DF39D580C345

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 1514 7ff6ebf820b0-7ff6ebf82182 1515 7ff6ebf82185-7ff6ebf8218c 1514->1515 1515->1515 1516 7ff6ebf8218e-7ff6ebf822ea call 7ff6ebf986b0 1515->1516 1519 7ff6ebf822f0-7ff6ebf822f8 1516->1519 1519->1519 1520 7ff6ebf822fa-7ff6ebf82378 call 7ff6ebf986b0 1519->1520 1523 7ff6ebf82380-7ff6ebf82388 1520->1523 1523->1523 1524 7ff6ebf8238a-7ff6ebf82411 call 7ff6ebf986b0 RegOpenKeyExA 1523->1524 1527 7ff6ebf82417-7ff6ebf82456 RegQueryValueExA 1524->1527 1528 7ff6ebf824ee-7ff6ebf824f5 1524->1528 1527->1528 1531 7ff6ebf8245c-7ff6ebf824a9 call 7ff6ebf986b0 call 7ff6ebf928e0 1527->1531 1529 7ff6ebf824fd-7ff6ebf8256e call 7ff6ebfa5c20 1528->1529 1530 7ff6ebf824f7 RegCloseKey 1528->1530 1537 7ff6ebf825a2-7ff6ebf825b5 1529->1537 1538 7ff6ebf82570-7ff6ebf82582 1529->1538 1530->1529 1545 7ff6ebf824ab-7ff6ebf824bf 1531->1545 1546 7ff6ebf824df-7ff6ebf824e7 1531->1546 1540 7ff6ebf825bb-7ff6ebf82601 call 7ff6ebf7eaf0 1537->1540 1541 7ff6ebf82aa3-7ff6ebf82aae 1537->1541 1542 7ff6ebf8259d call 7ff6ebffe880 1538->1542 1543 7ff6ebf82584-7ff6ebf82597 1538->1543 1564 7ff6ebf82607-7ff6ebf8260a 1540->1564 1565 7ff6ebf82c25-7ff6ebf82c27 1540->1565 1548 7ff6ebf82ae9-7ff6ebf82b0e 1541->1548 1549 7ff6ebf82ab0-7ff6ebf82ac9 1541->1549 1542->1537 1543->1542 1550 7ff6ebf82c55-7ff6ebf82c5a call 7ff6ebfe8254 1543->1550 1553 7ff6ebf824da call 7ff6ebffe880 1545->1553 1554 7ff6ebf824c1-7ff6ebf824d4 1545->1554 1546->1528 1551 7ff6ebf82b44-7ff6ebf82b5e 1548->1551 1552 7ff6ebf82b10-7ff6ebf82b24 1548->1552 1556 7ff6ebf82acb-7ff6ebf82ade 1549->1556 1557 7ff6ebf82ae4 call 7ff6ebffe880 1549->1557 1581 7ff6ebf82c5b-7ff6ebf82c70 call 7ff6ebf7e1d0 1550->1581 1561 7ff6ebf82b94-7ff6ebf82bae 1551->1561 1562 7ff6ebf82b60-7ff6ebf82b74 1551->1562 1559 7ff6ebf82b26-7ff6ebf82b39 1552->1559 1560 7ff6ebf82b3f call 7ff6ebffe880 1552->1560 1553->1546 1554->1553 1563 7ff6ebf82c4f-7ff6ebf82c54 call 7ff6ebfe8254 1554->1563 1556->1557 1567 7ff6ebf82c71-7ff6ebf82c76 call 7ff6ebfe8254 1556->1567 1557->1548 1559->1560 1570 7ff6ebf82c8f-7ff6ebf82c94 call 7ff6ebfe8254 1559->1570 1560->1551 1578 7ff6ebf82be0-7ff6ebf82c24 call 7ff6ebffe860 1561->1578 1579 7ff6ebf82bb0-7ff6ebf82bc4 1561->1579 1575 7ff6ebf82b76-7ff6ebf82b89 1562->1575 1576 7ff6ebf82b8f call 7ff6ebffe880 1562->1576 1563->1550 1564->1541 1577 7ff6ebf82610-7ff6ebf8262d call 7ff6ebf95140 1564->1577 1571 7ff6ebf82c29 1565->1571 1572 7ff6ebf82c34-7ff6ebf82c4e call 7ff6ebf7e240 1565->1572 1596 7ff6ebf82c77-7ff6ebf82c7c call 7ff6ebfe8254 1567->1596 1586 7ff6ebf82c95-7ff6ebf82c9a call 7ff6ebfe8254 1570->1586 1571->1541 1572->1563 1575->1576 1575->1586 1576->1561 1577->1581 1605 7ff6ebf82633-7ff6ebf8264e 1577->1605 1589 7ff6ebf82bdb call 7ff6ebffe880 1579->1589 1590 7ff6ebf82bc6-7ff6ebf82bd9 1579->1590 1581->1567 1589->1578 1590->1589 1600 7ff6ebf82c2e-7ff6ebf82c33 call 7ff6ebfe8254 1590->1600 1610 7ff6ebf82c7d-7ff6ebf82c82 call 7ff6ebfe8254 1596->1610 1600->1572 1608 7ff6ebf82658-7ff6ebf8268e call 7ff6ebf7e8c0 1605->1608 1609 7ff6ebf82650-7ff6ebf82654 1605->1609 1615 7ff6ebf8269d-7ff6ebf826be call 7ff6ebf7e9a0 1608->1615 1616 7ff6ebf82690-7ff6ebf82699 1608->1616 1609->1608 1618 7ff6ebf82c83-7ff6ebf82c88 call 7ff6ebfe8254 1610->1618 1621 7ff6ebf826c4-7ff6ebf826c8 1615->1621 1622 7ff6ebf82a01-7ff6ebf82a0b 1615->1622 1616->1615 1627 7ff6ebf82c89-7ff6ebf82c8e call 7ff6ebf7cf70 1618->1627 1624 7ff6ebf826d0-7ff6ebf826e5 call 7ff6ebfcf8f0 1621->1624 1625 7ff6ebf82a0d-7ff6ebf82a17 1622->1625 1626 7ff6ebf82a37-7ff6ebf82a41 1622->1626 1638 7ff6ebf826eb-7ff6ebf82737 call 7ff6ebf93a40 call 7ff6ebf7d4e0 call 7ff6ebf7d370 1624->1638 1639 7ff6ebf829de-7ff6ebf829fb call 7ff6ebf7f380 call 7ff6ebf7e7b0 1624->1639 1625->1626 1629 7ff6ebf82a19-7ff6ebf82a2b 1625->1629 1630 7ff6ebf82a6d-7ff6ebf82a74 1626->1630 1631 7ff6ebf82a43-7ff6ebf82a4d 1626->1631 1627->1570 1629->1626 1642 7ff6ebf82a2d-7ff6ebf82a36 1629->1642 1630->1541 1634 7ff6ebf82a76-7ff6ebf82a80 1630->1634 1631->1630 1636 7ff6ebf82a4f-7ff6ebf82a61 1631->1636 1634->1541 1637 7ff6ebf82a82-7ff6ebf82a96 1634->1637 1636->1630 1648 7ff6ebf82a63-7ff6ebf82a6c 1636->1648 1637->1541 1650 7ff6ebf82a98-7ff6ebf82aa2 1637->1650 1659 7ff6ebf8273c-7ff6ebf827db call 7ff6ebf95310 call 7ff6ebf955e0 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf93ff0 1638->1659 1660 7ff6ebf82739 1638->1660 1639->1622 1639->1624 1642->1626 1648->1630 1650->1541 1671 7ff6ebf827dd-7ff6ebf827ee 1659->1671 1672 7ff6ebf8280e-7ff6ebf82826 1659->1672 1660->1659 1673 7ff6ebf82809 call 7ff6ebffe880 1671->1673 1674 7ff6ebf827f0-7ff6ebf82803 1671->1674 1675 7ff6ebf82859-7ff6ebf82871 1672->1675 1676 7ff6ebf82828-7ff6ebf82839 1672->1676 1673->1672 1674->1596 1674->1673 1677 7ff6ebf828a9-7ff6ebf828c7 1675->1677 1678 7ff6ebf82873-7ff6ebf82889 1675->1678 1680 7ff6ebf8283b-7ff6ebf8284e 1676->1680 1681 7ff6ebf82854 call 7ff6ebffe880 1676->1681 1677->1627 1685 7ff6ebf828cd-7ff6ebf829dd call 7ff6ebfad590 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf93ff0 call 7ff6ebf929b0 call 7ff6ebf91900 call 7ff6ebf929b0 call 7ff6ebf91900 call 7ff6ebf917a0 call 7ff6ebf93ff0 1677->1685 1683 7ff6ebf8288b-7ff6ebf8289e 1678->1683 1684 7ff6ebf828a4 call 7ff6ebffe880 1678->1684 1680->1610 1680->1681 1681->1675 1683->1618 1683->1684 1684->1677 1685->1639
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$CloseOpenQueryValue
                                              • String ID: content$directory_iterator::directory_iterator$exists$filename
                                              • API String ID: 1254564140-1400943384
                                              • Opcode ID: 72bc06b4c23dae53119d17e32e2d83f94c8cf5b542223a1ca38e21ddfdc9481e
                                              • Instruction ID: 1cbdd76de5dacdbdeea046ce2e5a7e2de84b8a09c46b1e9d2cb3abd804ed2943
                                              • Opcode Fuzzy Hash: 72bc06b4c23dae53119d17e32e2d83f94c8cf5b542223a1ca38e21ddfdc9481e
                                              • Instruction Fuzzy Hash: FC729273A14BC589DB208F35D8803ED77A0FB89798F109225EA9C57BA9DF39D680C345

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 1707 7ff6ebfbd080-7ff6ebfbd978 call 7ff6ebf7eaf0 * 2 1715 7ff6ebfbd97e-7ff6ebfbdd49 call 7ff6ebf7d4e0 call 7ff6ebf7d370 call 7ff6ebfbfdd0 call 7ff6ebfcf8f0 call 7ff6ebf7f380 1707->1715 1716 7ff6ebfbdd92-7ff6ebfbddbc call 7ff6ebffe860 1707->1716 1732 7ff6ebfbdd7b-7ff6ebfbdd8b 1715->1732 1733 7ff6ebfbdd4b-7ff6ebfbdd5f 1715->1733 1732->1716 1734 7ff6ebfbdd61-7ff6ebfbdd74 1733->1734 1735 7ff6ebfbdd76 call 7ff6ebffe880 1733->1735 1734->1735 1736 7ff6ebfbddbd-7ff6ebfbe39d call 7ff6ebfe8254 call 7ff6ebf939b0 call 7ff6ebf979f0 call 7ff6ebf97ac0 call 7ff6ec000e88 call 7ff6ebf7e1d0 * 3 call 7ff6ebfe8254 * 4 call 7ff6ebf7e1d0 call 7ff6ebfe8254 * 2 call 7ff6ebf7cf70 call 7ff6ebfe8254 call 7ff6ebf7e1d0 call 7ff6ebfe8254 * 2 call 7ff6ebf7cf70 call 7ff6ebf7d4e0 call 7ff6ebf7d370 1734->1736 1735->1732 1786 7ff6ebfbe3a0-7ff6ebfbe3a7 1736->1786 1786->1786 1787 7ff6ebfbe3a9-7ff6ebfbe5a8 call 7ff6ebfa5c20 call 7ff6ebf7d810 call 7ff6ebf7da40 1786->1787 1794 7ff6ebfbe5b0-7ff6ebfbe5b8 1787->1794 1794->1794 1795 7ff6ebfbe5ba-7ff6ebfbe659 call 7ff6ebf986b0 call 7ff6ebfa5c20 call 7ff6ebf7d810 call 7ff6ebfcf020 1794->1795 1803 7ff6ebfbe65e-7ff6ebfbe98a call 7ff6ebf7da40 * 2 call 7ff6ebf92c80 1795->1803 1810 7ff6ebfbe990-7ff6ebfbe997 1803->1810 1810->1810 1811 7ff6ebfbe999-7ff6ebfbe9c7 call 7ff6ebf97600 1810->1811 1814 7ff6ebfbf363-7ff6ebfbf36e 1811->1814 1815 7ff6ebfbe9cd-7ff6ebfbe9dc call 7ff6ebf7ea50 1811->1815 1816 7ff6ebfbf370-7ff6ebfbf37a 1814->1816 1817 7ff6ebfbf3a2-7ff6ebfbf3c2 1814->1817 1815->1814 1825 7ff6ebfbe9e2-7ff6ebfbea8e 1815->1825 1816->1817 1819 7ff6ebfbf37c 1816->1819 1820 7ff6ebfbf3e1-7ff6ebfbf464 call 7ff6ebf7f380 call 7ff6ebf92880 call 7ff6ebf7da40 call 7ff6ebf92880 call 7ff6ebffe860 1817->1820 1821 7ff6ebfbf3c4-7ff6ebfbf3cd 1817->1821 1823 7ff6ebfbf384-7ff6ebfbf387 1819->1823 1821->1820 1831 7ff6ebfbf3cf-7ff6ebfbf3e0 1821->1831 1823->1817 1826 7ff6ebfbf389-7ff6ebfbf3a0 1823->1826 1825->1814 1829 7ff6ebfbf477-7ff6ebfbf4f6 call 7ff6ebf7cf70 call 7ff6ebf7e240 call 7ff6ebf7e1d0 call 7ff6ebfe8254 call 7ff6ebfbce40 1825->1829 1826->1823 1831->1820
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: cannot use push_back() with $directory_iterator::directory_iterator$exists$prefs.js$status
                                              • API String ID: 0-2713369562
                                              • Opcode ID: aa60501c34197aa9be3dc6d7d78cee9937bc4b4afc7b8e28a6d077cabfff3da7
                                              • Instruction ID: 5a80bec37c048b0581733c5358ecbef02e544f341982dad401f2e2f264d8c033
                                              • Opcode Fuzzy Hash: aa60501c34197aa9be3dc6d7d78cee9937bc4b4afc7b8e28a6d077cabfff3da7
                                              • Instruction Fuzzy Hash: 95525733919FC184E6B19B14E8813EEB3A4FB89754F504226DACC93B69EF79C194CB05

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 1852 7ff6ec00b5b0-7ff6ec00b5f0 1853 7ff6ec00b5f2-7ff6ec00b5f9 1852->1853 1854 7ff6ec00b605-7ff6ec00b60e 1852->1854 1853->1854 1857 7ff6ec00b5fb-7ff6ec00b600 1853->1857 1855 7ff6ec00b62a-7ff6ec00b62c 1854->1855 1856 7ff6ec00b610-7ff6ec00b613 1854->1856 1860 7ff6ec00b882 1855->1860 1861 7ff6ec00b632-7ff6ec00b636 1855->1861 1856->1855 1859 7ff6ec00b615-7ff6ec00b61d 1856->1859 1858 7ff6ec00b884-7ff6ec00b8aa call 7ff6ebffe860 1857->1858 1863 7ff6ec00b61f-7ff6ec00b621 1859->1863 1864 7ff6ec00b623-7ff6ec00b626 1859->1864 1860->1858 1865 7ff6ec00b63c-7ff6ec00b63f 1861->1865 1866 7ff6ec00b70d-7ff6ec00b734 call 7ff6ec00b984 1861->1866 1863->1855 1863->1864 1864->1855 1869 7ff6ec00b641-7ff6ec00b649 1865->1869 1870 7ff6ec00b653-7ff6ec00b665 GetFileAttributesExW 1865->1870 1876 7ff6ec00b756-7ff6ec00b75f 1866->1876 1877 7ff6ec00b736-7ff6ec00b73f 1866->1877 1869->1870 1872 7ff6ec00b64b-7ff6ec00b64d 1869->1872 1873 7ff6ec00b667-7ff6ec00b670 GetLastError 1870->1873 1874 7ff6ec00b6b8-7ff6ec00b6c7 1870->1874 1872->1866 1872->1870 1873->1858 1878 7ff6ec00b676-7ff6ec00b688 FindFirstFileW 1873->1878 1875 7ff6ec00b6cb-7ff6ec00b6cd 1874->1875 1879 7ff6ec00b6d9-7ff6ec00b707 1875->1879 1880 7ff6ec00b6cf-7ff6ec00b6d7 1875->1880 1883 7ff6ec00b813-7ff6ec00b81c 1876->1883 1884 7ff6ec00b765-7ff6ec00b77d GetFileInformationByHandleEx 1876->1884 1881 7ff6ec00b74f-7ff6ec00b751 1877->1881 1882 7ff6ec00b741-7ff6ec00b749 CloseHandle 1877->1882 1885 7ff6ec00b68a-7ff6ec00b690 GetLastError 1878->1885 1886 7ff6ec00b695-7ff6ec00b6b6 FindClose 1878->1886 1879->1860 1879->1866 1880->1866 1880->1879 1881->1858 1882->1881 1887 7ff6ec00b8c5-7ff6ec00b8ca call 7ff6ebfe98b4 1882->1887 1888 7ff6ec00b86b-7ff6ec00b86d 1883->1888 1889 7ff6ec00b81e-7ff6ec00b832 GetFileInformationByHandleEx 1883->1889 1890 7ff6ec00b77f-7ff6ec00b78b GetLastError 1884->1890 1891 7ff6ec00b7a5-7ff6ec00b7be 1884->1891 1885->1858 1886->1875 1912 7ff6ec00b8cb-7ff6ec00b8d0 call 7ff6ebfe98b4 1887->1912 1897 7ff6ec00b8ab-7ff6ec00b8af 1888->1897 1898 7ff6ec00b86f-7ff6ec00b873 1888->1898 1893 7ff6ec00b858-7ff6ec00b868 1889->1893 1894 7ff6ec00b834-7ff6ec00b840 GetLastError 1889->1894 1895 7ff6ec00b78d-7ff6ec00b798 CloseHandle 1890->1895 1896 7ff6ec00b79e-7ff6ec00b7a0 1890->1896 1891->1883 1899 7ff6ec00b7c0-7ff6ec00b7c4 1891->1899 1893->1888 1894->1896 1905 7ff6ec00b846-7ff6ec00b851 CloseHandle 1894->1905 1895->1896 1906 7ff6ec00b8d7-7ff6ec00b8df call 7ff6ebfe98b4 1895->1906 1896->1858 1902 7ff6ec00b8be-7ff6ec00b8c3 1897->1902 1903 7ff6ec00b8b1-7ff6ec00b8bc CloseHandle 1897->1903 1898->1860 1907 7ff6ec00b875-7ff6ec00b880 CloseHandle 1898->1907 1900 7ff6ec00b7c6-7ff6ec00b7e0 GetFileInformationByHandleEx 1899->1900 1901 7ff6ec00b80c 1899->1901 1908 7ff6ec00b7e2-7ff6ec00b7ee GetLastError 1900->1908 1909 7ff6ec00b803-7ff6ec00b80a 1900->1909 1911 7ff6ec00b810 1901->1911 1902->1858 1903->1887 1903->1902 1913 7ff6ec00b8d1-7ff6ec00b8d6 call 7ff6ebfe98b4 1905->1913 1914 7ff6ec00b853 1905->1914 1907->1860 1907->1887 1908->1896 1915 7ff6ec00b7f0-7ff6ec00b7fb CloseHandle 1908->1915 1909->1911 1911->1883 1912->1913 1913->1906 1914->1896 1915->1912 1919 7ff6ec00b801 1915->1919 1919->1896
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Close$ErrorFileFindHandleLast$AttributesFirst__std_fs_open_handle
                                              • String ID:
                                              • API String ID: 2398595512-0
                                              • Opcode ID: ae06ef96b620ec177ea6819a3a1ac38214177ad565b87e13f1ccf53398ca1eb7
                                              • Instruction ID: 96395411a5eb9b04f828a4fc712c2179f5287a141aa046fb86e1d55e5ceea5d4
                                              • Opcode Fuzzy Hash: ae06ef96b620ec177ea6819a3a1ac38214177ad565b87e13f1ccf53398ca1eb7
                                              • Instruction Fuzzy Hash: 94918333A08A0246E6748F25A8267792290AF447B4F594B30D97EC77E4EF3FE505C70A

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 1976 7ff6ebf8ca10-7ff6ebf8ca7a CredEnumerateA 1977 7ff6ebf8ca80-7ff6ebf8ca89 1976->1977 1978 7ff6ebf8d49c-7ff6ebf8d4cb call 7ff6ebffe860 1976->1978 1980 7ff6ebf8d48f-7ff6ebf8d496 CredFree 1977->1980 1981 7ff6ebf8ca8f-7ff6ebf8caa7 1977->1981 1980->1978 1983 7ff6ebf8cab0-7ff6ebf8cb02 call 7ff6ebffe888 1981->1983 1986 7ff6ebf8cb08-7ff6ebf8cb2e 1983->1986 1987 7ff6ebf8cd4d-7ff6ebf8cd54 1983->1987 1988 7ff6ebf8cb30-7ff6ebf8cb38 1986->1988 1989 7ff6ebf8cfa9-7ff6ebf8cfb0 1987->1989 1990 7ff6ebf8cd5a-7ff6ebf8cd7e 1987->1990 1988->1988 1991 7ff6ebf8cb3a-7ff6ebf8cbf7 call 7ff6ebf986b0 call 7ff6ebf95310 call 7ff6ebf955e0 1988->1991 1992 7ff6ebf8cfb6-7ff6ebf8d09f call 7ff6ebf986b0 call 7ff6ebf95310 call 7ff6ebf955e0 1989->1992 1993 7ff6ebf8d1f7-7ff6ebf8d1fa 1989->1993 1994 7ff6ebf8cd80-7ff6ebf8cd88 1990->1994 2023 7ff6ebf8cc00-7ff6ebf8cc08 1991->2023 2024 7ff6ebf8d0a0-7ff6ebf8d0a8 1992->2024 1995 7ff6ebf8d200-7ff6ebf8d28a 1993->1995 1996 7ff6ebf8d473-7ff6ebf8d489 call 7ff6ebf900f0 1993->1996 1994->1994 1999 7ff6ebf8cd8a-7ff6ebf8ce49 call 7ff6ebf986b0 call 7ff6ebf95310 call 7ff6ebf955e0 1994->1999 2000 7ff6ebf8d290-7ff6ebf8d298 1995->2000 1996->1980 1996->1983 2029 7ff6ebf8ce50-7ff6ebf8ce58 1999->2029 2000->2000 2005 7ff6ebf8d29a-7ff6ebf8d34b call 7ff6ebf986b0 call 7ff6ebf91900 2000->2005 2026 7ff6ebf8d350-7ff6ebf8d358 2005->2026 2023->2023 2027 7ff6ebf8cc0a-7ff6ebf8cc63 call 7ff6ebf986b0 call 7ff6ebf96bc0 call 7ff6ebf93ff0 2023->2027 2024->2024 2028 7ff6ebf8d0aa-7ff6ebf8d103 call 7ff6ebf986b0 call 7ff6ebf96bc0 call 7ff6ebf93ff0 2024->2028 2026->2026 2030 7ff6ebf8d35a-7ff6ebf8d3f8 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf93ff0 call 7ff6ebffe888 call 7ff6ebfb51b0 2026->2030 2054 7ff6ebf8cc65-7ff6ebf8cc76 2027->2054 2055 7ff6ebf8cc96-7ff6ebf8ccb9 2027->2055 2056 7ff6ebf8d105-7ff6ebf8d116 2028->2056 2057 7ff6ebf8d136-7ff6ebf8d156 2028->2057 2029->2029 2033 7ff6ebf8ce5a-7ff6ebf8ceb3 call 7ff6ebf986b0 call 7ff6ebf96bc0 call 7ff6ebf93ff0 2029->2033 2119 7ff6ebf8d404-7ff6ebf8d419 call 7ff6ebf937f0 2030->2119 2120 7ff6ebf8d3fa-7ff6ebf8d3fc 2030->2120 2065 7ff6ebf8ceb5-7ff6ebf8cec6 2033->2065 2066 7ff6ebf8cee6-7ff6ebf8cf0c 2033->2066 2061 7ff6ebf8cc91 call 7ff6ebffe880 2054->2061 2062 7ff6ebf8cc78-7ff6ebf8cc8b 2054->2062 2067 7ff6ebf8ccbb-7ff6ebf8cccc 2055->2067 2068 7ff6ebf8ccec-7ff6ebf8cd04 2055->2068 2063 7ff6ebf8d131 call 7ff6ebffe880 2056->2063 2064 7ff6ebf8d118-7ff6ebf8d12b 2056->2064 2069 7ff6ebf8d158-7ff6ebf8d16c 2057->2069 2070 7ff6ebf8d18c-7ff6ebf8d1ae 2057->2070 2061->2055 2062->2061 2072 7ff6ebf8d526-7ff6ebf8d52b call 7ff6ebfe8254 2062->2072 2063->2057 2064->2063 2073 7ff6ebf8d54a-7ff6ebf96d9d call 7ff6ebfe8254 2064->2073 2074 7ff6ebf8cee1 call 7ff6ebffe880 2065->2074 2075 7ff6ebf8cec8-7ff6ebf8cedb 2065->2075 2078 7ff6ebf8cf0e-7ff6ebf8cf22 2066->2078 2079 7ff6ebf8cf42-7ff6ebf8cf63 2066->2079 2080 7ff6ebf8ccce-7ff6ebf8cce1 2067->2080 2081 7ff6ebf8cce7 call 7ff6ebffe880 2067->2081 2084 7ff6ebf8cd06-7ff6ebf8cd18 2068->2084 2085 7ff6ebf8cd38-7ff6ebf8cd4a 2068->2085 2082 7ff6ebf8d16e-7ff6ebf8d181 2069->2082 2083 7ff6ebf8d187 call 7ff6ebffe880 2069->2083 2086 7ff6ebf8d1b0-7ff6ebf8d1c2 2070->2086 2087 7ff6ebf8d1e2-7ff6ebf8d1f5 2070->2087 2094 7ff6ebf8d52c-7ff6ebf8d531 call 7ff6ebfe8254 2072->2094 2137 7ff6ebf96d9f 2073->2137 2138 7ff6ebf96dd1-7ff6ebf96de4 2073->2138 2074->2066 2075->2074 2089 7ff6ebf8d538-7ff6ebf8d53d call 7ff6ebfe8254 2075->2089 2092 7ff6ebf8cf24-7ff6ebf8cf37 2078->2092 2093 7ff6ebf8cf3d call 7ff6ebffe880 2078->2093 2098 7ff6ebf8cf65-7ff6ebf8cf76 2079->2098 2099 7ff6ebf8cf96-7ff6ebf8cfa6 2079->2099 2080->2081 2080->2094 2081->2068 2082->2083 2095 7ff6ebf8d4cc-7ff6ebf8d4d1 call 7ff6ebfe8254 2082->2095 2083->2070 2100 7ff6ebf8cd33 call 7ff6ebffe880 2084->2100 2101 7ff6ebf8cd1a-7ff6ebf8cd2d 2084->2101 2085->1987 2102 7ff6ebf8d1c4-7ff6ebf8d1d7 2086->2102 2103 7ff6ebf8d1dd call 7ff6ebffe880 2086->2103 2087->1995 2107 7ff6ebf8d53e-7ff6ebf8d543 call 7ff6ebfe8254 2089->2107 2092->2093 2092->2107 2093->2079 2112 7ff6ebf8d532-7ff6ebf8d537 call 7ff6ebfe8254 2094->2112 2130 7ff6ebf8d4d2-7ff6ebf8d51f call 7ff6ebf939b0 call 7ff6ebf979f0 call 7ff6ebf97ac0 call 7ff6ec000e88 2095->2130 2110 7ff6ebf8cf91 call 7ff6ebffe880 2098->2110 2111 7ff6ebf8cf78-7ff6ebf8cf8b 2098->2111 2099->1989 2100->2085 2101->2100 2101->2112 2102->2103 2113 7ff6ebf8d520-7ff6ebf8d525 call 7ff6ebfe8254 2102->2113 2103->2087 2123 7ff6ebf8d544-7ff6ebf8d549 call 7ff6ebfe8254 2107->2123 2110->2099 2111->2110 2111->2123 2112->2089 2113->2072 2139 7ff6ebf8d41d-7ff6ebf8d429 2119->2139 2120->2130 2131 7ff6ebf8d402 2120->2131 2123->2073 2130->2113 2131->2139 2143 7ff6ebf96da0-7ff6ebf96dcf call 7ff6ebf99380 call 7ff6ebfa9810 call 7ff6ebffe880 2137->2143 2144 7ff6ebf8d42b-7ff6ebf8d44a 2139->2144 2145 7ff6ebf8d44c-7ff6ebf8d456 call 7ff6ebfa0610 2139->2145 2143->2138 2149 7ff6ebf8d45b-7ff6ebf8d469 call 7ff6ebf93ff0 2144->2149 2145->2149 2149->1996
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$Cred$EnumerateFree
                                              • String ID: cannot use push_back() with
                                              • API String ID: 1347986415-4122110429
                                              • Opcode ID: 397a3b11ec9aefb8a90e43e1be536f4e1bfcecda5c7bfe9a44244f3446273e2b
                                              • Instruction ID: 6a613110d039665eae4ed4b2ec83355fd6879ff8b2f3d77b5782b71b982f3a64
                                              • Opcode Fuzzy Hash: 397a3b11ec9aefb8a90e43e1be536f4e1bfcecda5c7bfe9a44244f3446273e2b
                                              • Instruction Fuzzy Hash: 6E628273A04BC589EB208F65E8803ED7761FB89798F104325EA9C57BA9DF39D284C305

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 2164 7ff6ebf99f80-7ff6ebf99fc5 2165 7ff6ebf9a291-7ff6ebf9a2cb call 7ff6ebfa1e10 call 7ff6ebf9c600 2164->2165 2166 7ff6ebf99fcb-7ff6ebf99ff5 call 7ff6ec011650 2164->2166 2175 7ff6ebf9a2d0-7ff6ebf9a2d6 2165->2175 2171 7ff6ebf9a004-7ff6ebf9a03d call 7ff6ebf9b5b0 call 7ff6ebfa0c20 call 7ff6ebf9c600 2166->2171 2172 7ff6ebf99ff7-7ff6ebf9a000 2166->2172 2206 7ff6ebf9a043-7ff6ebf9a0c8 call 7ff6ebf986b0 call 7ff6ebf9b780 call 7ff6ebfa1af0 call 7ff6ebf9bd00 2171->2206 2207 7ff6ebf9a1d4-7ff6ebf9a1db 2171->2207 2172->2171 2178 7ff6ebf9a467-7ff6ebf9a46b 2175->2178 2179 7ff6ebf9a2dc-7ff6ebf9a35b call 7ff6ebf986b0 call 7ff6ebf9b780 call 7ff6ebfa1af0 call 7ff6ebf9bd00 2175->2179 2181 7ff6ebf9a471-7ff6ebf9a4ce call 7ff6ebf937f0 call 7ff6ebf93ff0 2178->2181 2182 7ff6ebf9a539-7ff6ebf9a540 2178->2182 2230 7ff6ebf9a361-7ff6ebf9a369 2179->2230 2231 7ff6ebf9a5ab-7ff6ebf9a5c7 call 7ff6ebf93e90 call 7ff6ec000e88 2179->2231 2186 7ff6ebf9a50d-7ff6ebf9a538 call 7ff6ebffe860 2181->2186 2208 7ff6ebf9a4d0-7ff6ebf9a4e5 2181->2208 2185 7ff6ebf9a542-7ff6ebf9a557 2182->2185 2182->2186 2191 7ff6ebf9a559-7ff6ebf9a56c 2185->2191 2192 7ff6ebf9a4fc-7ff6ebf9a508 call 7ff6ebffe880 2185->2192 2198 7ff6ebf9a56e 2191->2198 2199 7ff6ebf9a576-7ff6ebf9a57b call 7ff6ebfe8254 2191->2199 2192->2186 2198->2192 2218 7ff6ebf9a57c-7ff6ebf9a598 call 7ff6ebf93e90 call 7ff6ec000e88 2199->2218 2206->2218 2259 7ff6ebf9a0ce-7ff6ebf9a0d6 2206->2259 2211 7ff6ebf9a225-7ff6ebf9a228 2207->2211 2212 7ff6ebf9a1dd-7ff6ebf9a223 call 7ff6ebf937f0 2207->2212 2208->2192 2217 7ff6ebf9a4e7-7ff6ebf9a4fa 2208->2217 2214 7ff6ebf9a280-7ff6ebf9a28c call 7ff6ebf9b3d0 2211->2214 2215 7ff6ebf9a22a-7ff6ebf9a26b call 7ff6ebf937f0 2211->2215 2233 7ff6ebf9a270-7ff6ebf9a27f call 7ff6ebf93ff0 2212->2233 2214->2186 2215->2233 2217->2192 2217->2199 2249 7ff6ebf9a599-7ff6ebf9a59e call 7ff6ebfe8254 2218->2249 2238 7ff6ebf9a36b-7ff6ebf9a37c 2230->2238 2239 7ff6ebf9a39c-7ff6ebf9a3e1 call 7ff6ec0007d0 * 2 2230->2239 2250 7ff6ebf9a5c8-7ff6ebf9a5cd call 7ff6ebfe8254 2231->2250 2233->2214 2244 7ff6ebf9a37e-7ff6ebf9a391 2238->2244 2245 7ff6ebf9a397 call 7ff6ebffe880 2238->2245 2262 7ff6ebf9a3e3-7ff6ebf9a3f5 2239->2262 2263 7ff6ebf9a415-7ff6ebf9a428 2239->2263 2244->2245 2244->2250 2245->2239 2267 7ff6ebf9a59f-7ff6ebf9a5a4 call 7ff6ebfe8254 2249->2267 2266 7ff6ebf9a5ce-7ff6ebf9a5e6 call 7ff6ebfe8254 2250->2266 2264 7ff6ebf9a0d8-7ff6ebf9a0ea 2259->2264 2265 7ff6ebf9a10a-7ff6ebf9a150 call 7ff6ec0007d0 * 2 2259->2265 2268 7ff6ebf9a410 call 7ff6ebffe880 2262->2268 2269 7ff6ebf9a3f7-7ff6ebf9a40a 2262->2269 2270 7ff6ebf9a42a-7ff6ebf9a43c 2263->2270 2271 7ff6ebf9a45c-7ff6ebf9a462 2263->2271 2272 7ff6ebf9a105 call 7ff6ebffe880 2264->2272 2273 7ff6ebf9a0ec-7ff6ebf9a0ff 2264->2273 2294 7ff6ebf9a183-7ff6ebf9a195 2265->2294 2295 7ff6ebf9a152-7ff6ebf9a163 2265->2295 2286 7ff6ebf9a5f3 2266->2286 2287 7ff6ebf9a5e8-7ff6ebf9a5eb 2266->2287 2288 7ff6ebf9a5a5-7ff6ebf9a5aa call 7ff6ebfe8254 2267->2288 2268->2263 2269->2266 2269->2268 2278 7ff6ebf9a43e-7ff6ebf9a451 2270->2278 2279 7ff6ebf9a457 call 7ff6ebffe880 2270->2279 2271->2178 2272->2265 2273->2249 2273->2272 2278->2279 2284 7ff6ebf9a570-7ff6ebf9a575 call 7ff6ebfe8254 2278->2284 2279->2271 2284->2199 2287->2286 2288->2231 2299 7ff6ebf9a197-7ff6ebf9a1a9 2294->2299 2300 7ff6ebf9a1c9-7ff6ebf9a1cf 2294->2300 2297 7ff6ebf9a17e call 7ff6ebffe880 2295->2297 2298 7ff6ebf9a165-7ff6ebf9a178 2295->2298 2297->2294 2298->2267 2298->2297 2302 7ff6ebf9a1c4 call 7ff6ebffe880 2299->2302 2303 7ff6ebf9a1ab-7ff6ebf9a1be 2299->2303 2300->2207 2302->2300 2303->2288 2303->2302
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$__std_exception_destroy
                                              • String ID: value
                                              • API String ID: 1346393832-494360628
                                              • Opcode ID: 6393ec53b8289c00639532b8d15cf4b8dcd6fc4cbd1acde857b26dc4558d973b
                                              • Instruction ID: 55131f31d19022f60150a623e0a424a72f07ad65b0aba212ea1be3dfcf526ffb
                                              • Opcode Fuzzy Hash: 6393ec53b8289c00639532b8d15cf4b8dcd6fc4cbd1acde857b26dc4558d973b
                                              • Instruction Fuzzy Hash: 4B028F63A18BC185EB00DFB8D4803ED6761EF897A4F105231EA9D83AEADF2DD185C745

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 2374 7ff6ebfd4a30-7ff6ebfd4a92 call 7ff6ebfff520 call 7ff6ebfdc190 2379 7ff6ebfd4a94 2374->2379 2380 7ff6ebfd4a97-7ff6ebfd4ae1 call 7ff6ebf95310 call 7ff6ebf94fe0 2374->2380 2379->2380 2385 7ff6ebfd4ae3-7ff6ebfd4af5 2380->2385 2386 7ff6ebfd4b15-7ff6ebfd4b34 2380->2386 2387 7ff6ebfd4b10 call 7ff6ebffe880 2385->2387 2388 7ff6ebfd4af7-7ff6ebfd4b0a 2385->2388 2389 7ff6ebfd4b6b-7ff6ebfd4bef call 7ff6ebfd0e00 call 7ff6ec011650 2386->2389 2390 7ff6ebfd4b36-7ff6ebfd4b4b 2386->2390 2387->2386 2388->2387 2391 7ff6ebfd51fc-7ff6ebfd5201 call 7ff6ebfe8254 2388->2391 2406 7ff6ebfd4bf4-7ff6ebfd4c14 recv 2389->2406 2393 7ff6ebfd4b4d-7ff6ebfd4b60 2390->2393 2394 7ff6ebfd4b66 call 7ff6ebffe880 2390->2394 2397 7ff6ebfd5202-7ff6ebfd5207 call 7ff6ebfe8254 2391->2397 2393->2394 2393->2397 2394->2389 2405 7ff6ebfd5208-7ff6ebfd520d call 7ff6ebfe8254 2397->2405 2420 7ff6ebfd520e-7ff6ebfd5213 call 7ff6ebfe8254 2405->2420 2408 7ff6ebfd4c1a-7ff6ebfd4c36 2406->2408 2409 7ff6ebfd4cd7-7ff6ebfd4d19 2406->2409 2413 7ff6ebfd4c76-7ff6ebfd4c92 call 7ff6ebf99030 2408->2413 2414 7ff6ebfd4c38-7ff6ebfd4c74 call 7ff6ec010fb0 2408->2414 2410 7ff6ebfd4d1f 2409->2410 2411 7ff6ebfd5011-7ff6ebfd5029 2409->2411 2419 7ff6ebfd4d20-7ff6ebfd4d2c call 7ff6ebfe89b0 2410->2419 2416 7ff6ebfd502f-7ff6ebfd5095 call 7ff6ebf9b220 call 7ff6ebfd0e00 2411->2416 2417 7ff6ebfd5220-7ff6ebfd5225 call 7ff6ebf7b8e0 2411->2417 2423 7ff6ebfd4c97-7ff6ebfd4ca0 2413->2423 2414->2423 2442 7ff6ebfd5097-7ff6ebfd50a9 2416->2442 2443 7ff6ebfd50c9-7ff6ebfd50cf 2416->2443 2434 7ff6ebfd5226-7ff6ebfd522b call 7ff6ebfe8254 2417->2434 2435 7ff6ebfd4d32-7ff6ebfd4d35 2419->2435 2436 7ff6ebfd5005-7ff6ebfd500b 2419->2436 2432 7ff6ebfd5214-7ff6ebfd5219 call 7ff6ebfe8254 2420->2432 2423->2406 2429 7ff6ebfd4ca6-7ff6ebfd4cd3 2423->2429 2429->2409 2446 7ff6ebfd521a-7ff6ebfd521f call 7ff6ebfe8254 2432->2446 2450 7ff6ebfd522c-7ff6ebfd5231 call 7ff6ebfe8254 2434->2450 2435->2436 2440 7ff6ebfd4d3b-7ff6ebfd4dec call 7ff6ebf96700 call 7ff6ebfc0040 call 7ff6ebf937f0 call 7ff6ebfd0e90 call 7ff6ebfdc190 2435->2440 2436->2411 2436->2419 2483 7ff6ebfd4dee 2440->2483 2484 7ff6ebfd4df1-7ff6ebfd4e7d call 7ff6ebf95310 call 7ff6ebf93d70 call 7ff6ebfd0e00 2440->2484 2447 7ff6ebfd50c4 call 7ff6ebffe880 2442->2447 2448 7ff6ebfd50ab-7ff6ebfd50be 2442->2448 2449 7ff6ebfd50d4-7ff6ebfd50fc recv 2443->2449 2446->2417 2447->2443 2448->2434 2448->2447 2454 7ff6ebfd5104-7ff6ebfd5117 WSACleanup 2449->2454 2455 7ff6ebfd50fe closesocket 2449->2455 2463 7ff6ebfd5232-7ff6ebfd5237 call 7ff6ebfe8254 2450->2463 2460 7ff6ebfd514e-7ff6ebfd5176 2454->2460 2461 7ff6ebfd5119-7ff6ebfd512e 2454->2461 2455->2454 2465 7ff6ebfd51ad-7ff6ebfd51fb call 7ff6ebffe860 2460->2465 2466 7ff6ebfd5178-7ff6ebfd518d 2460->2466 2467 7ff6ebfd5130-7ff6ebfd5143 2461->2467 2468 7ff6ebfd5149 call 7ff6ebffe880 2461->2468 2472 7ff6ebfd518f-7ff6ebfd51a2 2466->2472 2473 7ff6ebfd51a8 call 7ff6ebffe880 2466->2473 2467->2450 2467->2468 2468->2460 2472->2463 2472->2473 2473->2465 2483->2484 2490 7ff6ebfd4e82-7ff6ebfd4e92 2484->2490 2491 7ff6ebfd4e94-7ff6ebfd4ea6 2490->2491 2492 7ff6ebfd4ec6-7ff6ebfd4ee4 2490->2492 2493 7ff6ebfd4ec1 call 7ff6ebffe880 2491->2493 2494 7ff6ebfd4ea8-7ff6ebfd4ebb 2491->2494 2495 7ff6ebfd4f1b-7ff6ebfd4f38 2492->2495 2496 7ff6ebfd4ee6-7ff6ebfd4efb 2492->2496 2493->2492 2494->2405 2494->2493 2500 7ff6ebfd4f6f-7ff6ebfd4fb8 call 7ff6ebf93ff0 * 2 2495->2500 2501 7ff6ebfd4f3a-7ff6ebfd4f4f 2495->2501 2498 7ff6ebfd4efd-7ff6ebfd4f10 2496->2498 2499 7ff6ebfd4f16 call 7ff6ebffe880 2496->2499 2498->2420 2498->2499 2499->2495 2510 7ff6ebfd4fef-7ff6ebfd5000 2500->2510 2511 7ff6ebfd4fba-7ff6ebfd4fcf 2500->2511 2504 7ff6ebfd4f51-7ff6ebfd4f64 2501->2504 2505 7ff6ebfd4f6a call 7ff6ebffe880 2501->2505 2504->2432 2504->2505 2505->2500 2510->2449 2512 7ff6ebfd4fd1-7ff6ebfd4fe4 2511->2512 2513 7ff6ebfd4fea call 7ff6ebffe880 2511->2513 2512->2446 2512->2513 2513->2510
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$recv$Cleanupclosesocket
                                              • String ID:
                                              • API String ID: 3402187201-0
                                              • Opcode ID: 7da1f52dcf02eec2e376e397382e74fdcf212ce6f330cc234e01b66058b24776
                                              • Instruction ID: 32414643eb5cab97b3b23e9227a7263d6f1de4765fda8cde6c8ecfc1ba6484cf
                                              • Opcode Fuzzy Hash: 7da1f52dcf02eec2e376e397382e74fdcf212ce6f330cc234e01b66058b24776
                                              • Instruction Fuzzy Hash: B4129573A1CBC181EA209B14F4543EE6761FB89790F104631DAAC87AEADF7ED484CB05

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 2515 7ff6ebfcc600-7ff6ebfcc622 call 7ff6ebfcf820 2518 7ff6ebfcc624-7ff6ebfcc647 call 7ff6ebfcfb60 call 7ff6ebfda780 call 7ff6ebf92660 ExitProcess 2515->2518 2519 7ff6ebfcc64e-7ff6ebfcc700 call 7ff6ebfdb9b0 * 2 call 7ff6ebfd8030 call 7ff6ebfcd030 2515->2519 2534 7ff6ebfcc702-7ff6ebfcc714 2519->2534 2535 7ff6ebfcc734-7ff6ebfcc76b OpenMutexA 2519->2535 2538 7ff6ebfcc72f call 7ff6ebffe880 2534->2538 2539 7ff6ebfcc716-7ff6ebfcc729 2534->2539 2536 7ff6ebfcc76d-7ff6ebfcc772 ExitProcess 2535->2536 2537 7ff6ebfcc779-7ff6ebfcc7b0 CreateMutexExA call 7ff6ebfc66f0 call 7ff6ebfcfca0 2535->2537 2550 7ff6ebfcc7b2-7ff6ebfcc7b7 ExitProcess 2537->2550 2551 7ff6ebfcc7be-7ff6ebfcc821 call 7ff6ebfd8330 call 7ff6ebf8d570 call 7ff6ebf8e610 call 7ff6ebf8ecb0 call 7ff6ebf8f9e0 call 7ff6ebf8ca10 call 7ff6ebfbcab0 call 7ff6ebfbf7a0 call 7ff6ebf81b90 call 7ff6ebf8add0 call 7ff6ebf89680 call 7ff6ebfcd260 call 7ff6ebf8bf40 call 7ff6ebf877d0 call 7ff6ebf84b70 call 7ff6ebf87aa0 call 7ff6ebfd4a30 2537->2551 2538->2535 2539->2538 2541 7ff6ebfcc8c6-7ff6ebfcc8cb call 7ff6ebfe8254 2539->2541 2547 7ff6ebfcc8cc-7ff6ebfcc8d1 call 7ff6ebfe8254 2541->2547 2588 7ff6ebfcc826-7ff6ebfcc836 call 7ff6ebfcbcc0 2551->2588 2592 7ff6ebfcc84a-7ff6ebfcc851 2588->2592 2593 7ff6ebfcc838-7ff6ebfcc844 ReleaseMutex CloseHandle 2588->2593 2594 7ff6ebfcc853-7ff6ebfcc858 call 7ff6ebfcc8e0 2592->2594 2595 7ff6ebfcc859-7ff6ebfcc865 2592->2595 2593->2592 2594->2595 2597 7ff6ebfcc895-7ff6ebfcc8c5 call 7ff6ebffe860 2595->2597 2598 7ff6ebfcc867-7ff6ebfcc879 2595->2598 2600 7ff6ebfcc890 call 7ff6ebffe880 2598->2600 2601 7ff6ebfcc87b-7ff6ebfcc88e 2598->2601 2600->2597 2601->2547 2601->2600
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Process$ExitOpenToken$CloseCurrentFileHandleInformationInitializeModuleMutexName
                                              • String ID: SeDebugPrivilege$SeImpersonatePrivilege
                                              • API String ID: 3348294976-3768118664
                                              • Opcode ID: ba67cdc4a9eadfff59423ebbf1ec18657226234c36bf65d0b363ddb74215bdc7
                                              • Instruction ID: 7ff5f06d4f67977007f2226b058ac71e6fbbaa15f541c1a61a4f3045400ec44d
                                              • Opcode Fuzzy Hash: ba67cdc4a9eadfff59423ebbf1ec18657226234c36bf65d0b363ddb74215bdc7
                                              • Instruction Fuzzy Hash: C8617F23D1CA8641EA10AB65A4553FAA250FF8D740F504135E68DC76F7EF2EE081CB4E

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 2605 7ff6ebfb5970-7ff6ebfb59b0 2606 7ff6ebfb5aaf-7ff6ebfb5ab8 2605->2606 2607 7ff6ebfb59b6-7ff6ebfb59c0 2605->2607 2608 7ff6ebfb5b02-7ff6ebfb5b14 call 7ff6ec00b4c0 2606->2608 2609 7ff6ebfb5aba-7ff6ebfb5ac6 2606->2609 2610 7ff6ebfb5aa6-7ff6ebfb5aac 2607->2610 2611 7ff6ebfb59c6-7ff6ebfb59ce 2607->2611 2624 7ff6ebfb5b56-7ff6ebfb5b5a 2608->2624 2625 7ff6ebfb5b16-7ff6ebfb5b1a 2608->2625 2613 7ff6ebfb5ac8-7ff6ebfb5ad8 2609->2613 2614 7ff6ebfb5ada-7ff6ebfb5ae1 call 7ff6ebfc2660 2609->2614 2610->2606 2615 7ff6ebfb59d0-7ff6ebfb59d5 2611->2615 2616 7ff6ebfb59db-7ff6ebfb59df 2611->2616 2620 7ff6ebfb5ae6-7ff6ebfb5b00 call 7ff6ebf7e2a0 2613->2620 2614->2620 2615->2610 2615->2616 2617 7ff6ebfb59e1-7ff6ebfb59ea 2616->2617 2618 7ff6ebfb5a38-7ff6ebfb5a3a 2616->2618 2622 7ff6ebfb59ef-7ff6ebfb5a06 call 7ff6ec00b5b0 2617->2622 2623 7ff6ebfb59ec 2617->2623 2618->2606 2627 7ff6ebfb5a3c-7ff6ebfb5a6c 2618->2627 2632 7ff6ebfb5b5e-7ff6ebfb5b64 2620->2632 2642 7ff6ebfb5a14-7ff6ebfb5a17 2622->2642 2643 7ff6ebfb5a08-7ff6ebfb5a12 2622->2643 2623->2622 2624->2632 2631 7ff6ebfb5b20-7ff6ebfb5b26 2625->2631 2628 7ff6ebfb5a6e-7ff6ebfb5a80 2627->2628 2629 7ff6ebfb5a9f-7ff6ebfb5aa1 2627->2629 2628->2629 2634 7ff6ebfb5a82-7ff6ebfb5a94 2628->2634 2638 7ff6ebfb5cc2-7ff6ebfb5cf2 call 7ff6ebffe860 2629->2638 2636 7ff6ebfb5b54 2631->2636 2637 7ff6ebfb5b28-7ff6ebfb5b30 2631->2637 2639 7ff6ebfb5cb3-7ff6ebfb5cc0 call 7ff6ebf7e4f0 2632->2639 2640 7ff6ebfb5b6a-7ff6ebfb5b6c 2632->2640 2634->2629 2661 7ff6ebfb5a96-7ff6ebfb5a99 2634->2661 2636->2624 2644 7ff6ebfb5b3f-7ff6ebfb5b50 call 7ff6ec00b4c0 2637->2644 2645 7ff6ebfb5b32-7ff6ebfb5b36 2637->2645 2639->2638 2641 7ff6ebfb5b70-7ff6ebfb5b73 2640->2641 2648 7ff6ebfb5cf5-7ff6ebfb5d29 2641->2648 2649 7ff6ebfb5b79-7ff6ebfb5b81 2641->2649 2652 7ff6ebfb5a19-7ff6ebfb5a1c 2642->2652 2653 7ff6ebfb5a36 2642->2653 2643->2618 2644->2631 2667 7ff6ebfb5b52 2644->2667 2645->2636 2651 7ff6ebfb5b38-7ff6ebfb5b3d 2645->2651 2657 7ff6ebfb5d55-7ff6ebfb5d57 2648->2657 2658 7ff6ebfb5d2b-7ff6ebfb5d36 2648->2658 2659 7ff6ebfb5cf3 2649->2659 2660 7ff6ebfb5b87-7ff6ebfb5bba call 7ff6ec00b4e0 * 2 2649->2660 2651->2636 2651->2644 2652->2653 2662 7ff6ebfb5a1e-7ff6ebfb5a21 2652->2662 2653->2618 2657->2638 2658->2657 2664 7ff6ebfb5d38-7ff6ebfb5d4a 2658->2664 2659->2648 2675 7ff6ebfb5bbf-7ff6ebfb5bd2 call 7ff6ebf7d020 2660->2675 2676 7ff6ebfb5bbc 2660->2676 2661->2629 2662->2653 2666 7ff6ebfb5a23-7ff6ebfb5a26 2662->2666 2664->2657 2673 7ff6ebfb5d4c-7ff6ebfb5d4f 2664->2673 2666->2653 2669 7ff6ebfb5a28-7ff6ebfb5a2b 2666->2669 2667->2624 2669->2618 2672 7ff6ebfb5a2d-7ff6ebfb5a34 2669->2672 2672->2618 2672->2653 2673->2657 2679 7ff6ebfb5bd4-7ff6ebfb5bdb 2675->2679 2680 7ff6ebfb5c2d-7ff6ebfb5c37 2675->2680 2676->2675 2683 7ff6ebfb5be3 2679->2683 2684 7ff6ebfb5bdd-7ff6ebfb5be1 2679->2684 2681 7ff6ebfb5d5c-7ff6ebfb5d61 call 7ff6ebf945e0 2680->2681 2682 7ff6ebfb5c3d-7ff6ebfb5c49 2680->2682 2686 7ff6ebfb5c4e-7ff6ebfb5c64 call 7ff6ec00b4c0 2682->2686 2687 7ff6ebfb5c4b 2682->2687 2688 7ff6ebfb5be7-7ff6ebfb5bea 2683->2688 2684->2683 2684->2688 2686->2641 2696 7ff6ebfb5c6a-7ff6ebfb5c6e 2686->2696 2687->2686 2688->2680 2691 7ff6ebfb5bec 2688->2691 2692 7ff6ebfb5bf0-7ff6ebfb5bfc 2691->2692 2694 7ff6ebfb5bfe-7ff6ebfb5c02 2692->2694 2695 7ff6ebfb5c0c-7ff6ebfb5c0f 2692->2695 2694->2695 2697 7ff6ebfb5c04-7ff6ebfb5c0a 2694->2697 2695->2680 2698 7ff6ebfb5c11-7ff6ebfb5c1d 2695->2698 2699 7ff6ebfb5c70-7ff6ebfb5c76 2696->2699 2697->2692 2697->2695 2700 7ff6ebfb5c1f-7ff6ebfb5c23 2698->2700 2701 7ff6ebfb5c25-7ff6ebfb5c2b 2698->2701 2702 7ff6ebfb5c78-7ff6ebfb5c80 2699->2702 2703 7ff6ebfb5ca7-7ff6ebfb5ca9 2699->2703 2700->2680 2700->2701 2701->2680 2701->2698 2704 7ff6ebfb5c90-7ff6ebfb5ca1 call 7ff6ec00b4c0 2702->2704 2705 7ff6ebfb5c82-7ff6ebfb5c86 2702->2705 2706 7ff6ebfb5cab-7ff6ebfb5cad 2703->2706 2704->2699 2710 7ff6ebfb5ca3-7ff6ebfb5ca5 2704->2710 2705->2703 2707 7ff6ebfb5c88-7ff6ebfb5c8e 2705->2707 2706->2639 2706->2641 2707->2703 2707->2704 2710->2706
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: .$@$@$cannot use push_back() with $chrome_key$content$directory_iterator::directory_iterator$exists$filename$key$prefs.js$recursive_directory_iterator::operator++$recursive_directory_iterator::recursive_directory_iterator$status
                                              • API String ID: 0-4287193513
                                              • Opcode ID: 8adc91dd6644a2bfb7387dc78b72df08f999bd5353c1b7ff9b33895fcf5abe12
                                              • Instruction ID: 9cd13c2637172fdaed848d64398b71b5a0f5da84ba5905421fe00dc20002748d
                                              • Opcode Fuzzy Hash: 8adc91dd6644a2bfb7387dc78b72df08f999bd5353c1b7ff9b33895fcf5abe12
                                              • Instruction Fuzzy Hash: AAC1D373A08B8286EB609F25D4A43B963A1FB4C795F544232DA5D837A8DF3EE841C705
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Internet$Query$AvailableDataHttpInfoOpen_invalid_parameter_noinfo_noreturn$CloseConcurrency::cancel_current_taskFileHandleRead
                                              • String ID:
                                              • API String ID: 1352168858-0
                                              • Opcode ID: f0f06bfc5229ad43a134cc2e5cf5d57c8af5ef26157f18d200528da81e841abb
                                              • Instruction ID: 56e68fb3c93065cbbd47ec5938d6128cd262f5bba1a54cba2145493e86dd4687
                                              • Opcode Fuzzy Hash: f0f06bfc5229ad43a134cc2e5cf5d57c8af5ef26157f18d200528da81e841abb
                                              • Instruction Fuzzy Hash: F7028233A18B9585EB10CB69F8403AE77B5FB99794F104225EE9C57BA8DF79D080CB04
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$Process32$CloseCreateFirstHandleNextSnapshotToolhelp32
                                              • String ID: [PID:
                                              • API String ID: 1946380282-2210602247
                                              • Opcode ID: 775278d011838b3c82a30bd51d8c922216805a17ad3d78b1e9f84401a34e296d
                                              • Instruction ID: e0f6bb6124462294699d490304d9fc74cea1f010c487f93baf4ba08dcf842eba
                                              • Opcode Fuzzy Hash: 775278d011838b3c82a30bd51d8c922216805a17ad3d78b1e9f84401a34e296d
                                              • Instruction Fuzzy Hash: 18E1C633A18BC185EB20DF25E8903ED77A1F7897A4F504225EA9D47BA9DF39D240C705
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 3668304517-0
                                              • Opcode ID: a81d8968a17a13dc277e57e3dc7582a2f7565247fbcd59ce3d43ce117267cb21
                                              • Instruction ID: 95a7757adf3beed97151d13303a63ed8bff803190ac6e60ccbc58841b66d1c20
                                              • Opcode Fuzzy Hash: a81d8968a17a13dc277e57e3dc7582a2f7565247fbcd59ce3d43ce117267cb21
                                              • Instruction Fuzzy Hash: E0725B73A18B8589EB208F69E8403ED63A1F78D798F504325EADC57BA9DF39D240C705
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: File$PointerReadSize_invalid_parameter_noinfo_noreturn
                                              • String ID: exists$ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
                                              • API String ID: 2478245620-15404121
                                              • Opcode ID: 66a69ea613784884e0830e2cf4cd3502bd24be5abfc7ae4b6da5a38c28b90bd3
                                              • Instruction ID: c1074a549446ae3d64cea58d974c3f56452218beed0dca80c6a1631dc5c36e2a
                                              • Opcode Fuzzy Hash: 66a69ea613784884e0830e2cf4cd3502bd24be5abfc7ae4b6da5a38c28b90bd3
                                              • Instruction Fuzzy Hash: 1B322933A14BC589EB20CF24D8803ED77A1FB44748F508226DA8D9BBA9DF7AD645C705
                                              APIs
                                              • _get_daylight.LIBCMT ref: 00007FF6EBFF2E81
                                                • Part of subcall function 00007FF6EBFF24E8: _invalid_parameter_noinfo.LIBCMT ref: 00007FF6EBFF24FC
                                                • Part of subcall function 00007FF6EBFED3C8: RtlFreeHeap.NTDLL ref: 00007FF6EBFED3DE
                                                • Part of subcall function 00007FF6EBFED3C8: GetLastError.KERNEL32 ref: 00007FF6EBFED3E8
                                                • Part of subcall function 00007FF6EBFE8284: IsProcessorFeaturePresent.KERNEL32(?,?,?,?,00007FF6EBFE8233,?,?,?,?,-2723E8D8DEBC5093,00007FF6EBFE811E), ref: 00007FF6EBFE828D
                                                • Part of subcall function 00007FF6EBFE8284: GetCurrentProcess.KERNEL32(?,?,?,?,00007FF6EBFE8233,?,?,?,?,-2723E8D8DEBC5093,00007FF6EBFE811E), ref: 00007FF6EBFE82B2
                                                • Part of subcall function 00007FF6EBFFBA84: _invalid_parameter_noinfo.LIBCMT ref: 00007FF6EBFFB9CF
                                              • _get_daylight.LIBCMT ref: 00007FF6EBFF2E70
                                                • Part of subcall function 00007FF6EBFF2548: _invalid_parameter_noinfo.LIBCMT ref: 00007FF6EBFF255C
                                              • _get_daylight.LIBCMT ref: 00007FF6EBFF30E6
                                              • _get_daylight.LIBCMT ref: 00007FF6EBFF30F7
                                              • _get_daylight.LIBCMT ref: 00007FF6EBFF3108
                                              • GetTimeZoneInformation.KERNEL32(00007FF6EBFF33F8), ref: 00007FF6EBFF312F
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _get_daylight$_invalid_parameter_noinfo$CurrentErrorFeatureFreeHeapInformationLastPresentProcessProcessorTimeZone
                                              • String ID: Eastern Standard Time$Eastern Summer Time
                                              • API String ID: 4070488512-239921721
                                              • Opcode ID: 6ff4704e37b1592320c13e659d1f856dd22dc212be1b833c6838491f576543a9
                                              • Instruction ID: a0e514d3ef693e3db5cd3ed27aba9c2484dcce8ae8809dad09ab5d384cda702b
                                              • Opcode Fuzzy Hash: 6ff4704e37b1592320c13e659d1f856dd22dc212be1b833c6838491f576543a9
                                              • Instruction Fuzzy Hash: 16D1D123E0860286EB209F25D9507FD6761FF48B94F548036EA1DC7AA6DF3EE441C34A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: File$CreateErrorLast_invalid_parameter_noinfo$CloseHandle$Type
                                              • String ID:
                                              • API String ID: 1617910340-0
                                              • Opcode ID: 9219a76bbf5b0a68fd8075754a2c2160bfaa822f6e476498c8a23ea95eed312f
                                              • Instruction ID: 28b96ce90c458595f8eff05c31ec59ef1e7c09a739561339bf16f2f58829311f
                                              • Opcode Fuzzy Hash: 9219a76bbf5b0a68fd8075754a2c2160bfaa822f6e476498c8a23ea95eed312f
                                              • Instruction Fuzzy Hash: CBC1CF33B28A4285EB10CFA9C4902BC3761FB49BACF011225DE6E9B3A5DF3AD115C345
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _get_daylight_invalid_parameter_noinfo$ErrorFreeHeapInformationLastTimeZone
                                              • String ID: Eastern Standard Time$Eastern Summer Time
                                              • API String ID: 3458911817-239921721
                                              • Opcode ID: 12951480f3fe79566017d45e51369301be5158125170c6a9e6aaf334c955a331
                                              • Instruction ID: cd1c1a2b069b02abfe3287ae3d54a8efd81ad88f09d9c0303b67fa5711c0a10f
                                              • Opcode Fuzzy Hash: 12951480f3fe79566017d45e51369301be5158125170c6a9e6aaf334c955a331
                                              • Instruction Fuzzy Hash: 57518F33A0864286E720DF25E9906FD6760FB4CB84F559135EA1DC7AA6DF3EE400C749
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _get_daylight$_isindst$_invalid_parameter_noinfo
                                              • String ID:
                                              • API String ID: 1405656091-0
                                              • Opcode ID: cd6fea744430340711cd49b3e9bdbfdb1b852b0eb5a7692198664b91c055b650
                                              • Instruction ID: 8d8f5deb7f484c72c86eb23b1b069ad76fbc0d5ecc9671c4149e457f269bd2d1
                                              • Opcode Fuzzy Hash: cd6fea744430340711cd49b3e9bdbfdb1b852b0eb5a7692198664b91c055b650
                                              • Instruction Fuzzy Hash: 2281A3B3B042468BEB588F25C9413FC22A5EB58B98F04D039EA0D8B799EF3DE540C755
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID: cores
                                              • API String ID: 3668304517-2370456839
                                              • Opcode ID: a87a5c1c4029a56fc1ae84d797c8968129aed14d0dad27f13aedc116e44e4e04
                                              • Instruction ID: 925818fcc87b5c113f62752446fcaf4b22f61c2548bff3b233d4f4f215ff9345
                                              • Opcode Fuzzy Hash: a87a5c1c4029a56fc1ae84d797c8968129aed14d0dad27f13aedc116e44e4e04
                                              • Instruction Fuzzy Hash: 77C10663E18B818AF710CFB8D4403EC7761E7997A8F105325EA9C57AA6DF39D181C748
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: ProcessToken$AdjustCloseCurrentHandleLookupOpenPrivilegePrivilegesValue
                                              • String ID:
                                              • API String ID: 3038321057-0
                                              • Opcode ID: d2de06470b4ed8e39d37734a47601b9eff7cf65b32299141bc4bcc42cf026e17
                                              • Instruction ID: fceeffa0599be5956c7197ec5dbb0cb3edb5293b20dc67f6a99eec677b9db5ff
                                              • Opcode Fuzzy Hash: d2de06470b4ed8e39d37734a47601b9eff7cf65b32299141bc4bcc42cf026e17
                                              • Instruction Fuzzy Hash: 94219132618B8186E720CF21F45436AB3A0FB88B80F958135EA8D83B58DF7ED544CB44
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 435728f26feb55d38dd2406e9396d00c3032b6853f4929e1a1c60f4ff5484234
                                              • Instruction ID: 1ce35b23f897dc84b8f64fe4e62a29829ebe865267247ca648fe48ef0c5acffa
                                              • Opcode Fuzzy Hash: 435728f26feb55d38dd2406e9396d00c3032b6853f4929e1a1c60f4ff5484234
                                              • Instruction Fuzzy Hash: AEF15C73A19BC58AEB208B69E4413AD77A0F78C798F100325EEDC57B99EF79C1808744
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: a0256dd7fc52a6c4b2d738b897fca39afb68c8f6f903d96dd625e41008a66197
                                              • Instruction ID: 607e6b69d1d0ea5e8026702a4ad42811c33292b3af610f30d97ddd49fcd1c123
                                              • Opcode Fuzzy Hash: a0256dd7fc52a6c4b2d738b897fca39afb68c8f6f903d96dd625e41008a66197
                                              • Instruction Fuzzy Hash: 60F14D33A09B858AEB208B69E44039D77A4F78C798F104325EEDC57B99EF78D190C744
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: a763192257ec61e9adf52f6911b76a4d9ec981118bcce0b41448b20aa0983423
                                              • Instruction ID: a4da3c99be5486740fbc866e6424f38a3c05e8e8bf0e82d5089f7abd381811cd
                                              • Opcode Fuzzy Hash: a763192257ec61e9adf52f6911b76a4d9ec981118bcce0b41448b20aa0983423
                                              • Instruction Fuzzy Hash: E9F14D73A19B858AEB208B69E44039D77A4F78C7A8F100325EADC57B99EF38D190C744
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: InformationTimeZone
                                              • String ID: [UTC
                                              • API String ID: 565725191-1715286942
                                              • Opcode ID: 6fe6f81e5b62afaa7baa2b9ab6ff81250fb1b9bc5dec80abcd354a2763d4484f
                                              • Instruction ID: f62c9395461f74d239a337a9ea56d48f7be07c519ccdfc2005e38f5b4c17c4d8
                                              • Opcode Fuzzy Hash: 6fe6f81e5b62afaa7baa2b9ab6ff81250fb1b9bc5dec80abcd354a2763d4484f
                                              • Instruction Fuzzy Hash: 54B13C32918BC889D7718F29E84129AB7A4F78D788F105325EACC57B59DF78D250CB44
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: DriveLogicalStrings
                                              • String ID:
                                              • API String ID: 2022863570-0
                                              • Opcode ID: fb7d747b0e00fdc5bcf2296ff1af6a0a651aca07fcdd1d1013c1aaaac54d4c2a
                                              • Instruction ID: 479334b2a165b649aecd01be3a81f5aeeb8b39f8355f8ce83bca0e074bd8ec87
                                              • Opcode Fuzzy Hash: fb7d747b0e00fdc5bcf2296ff1af6a0a651aca07fcdd1d1013c1aaaac54d4c2a
                                              • Instruction Fuzzy Hash: 75519033E08B8082E7108F24E4803AE7765FB88798F105225EB9C57AA9DF7DE591DB44
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: CryptDataFreeLocalUnprotect
                                              • String ID:
                                              • API String ID: 1561624719-0
                                              • Opcode ID: 3f0d2640eba4d0f7871c2ec703edcb503dbe0d7ea7d03094cd3af9045bbe76bf
                                              • Instruction ID: 9f418e52aa4afbbf22a06f70928abd16db5753c7c53e166b287f32d6c6f66147
                                              • Opcode Fuzzy Hash: 3f0d2640eba4d0f7871c2ec703edcb503dbe0d7ea7d03094cd3af9045bbe76bf
                                              • Instruction Fuzzy Hash: 5A412633A18A818AE3208F74D4503ED37A4FB5878CF444229EB8C46A4ADF7AD5A4C748
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 3668304517-0
                                              • Opcode ID: a1a3130b3957abc88560b0093295f96a78c31b3c67a94cf5472d23aee1a1b46d
                                              • Instruction ID: 446d1e38eb6f81dea5cb211988981f4f8c7c7e5d3ac06ea76dcbd8673083fc54
                                              • Opcode Fuzzy Hash: a1a3130b3957abc88560b0093295f96a78c31b3c67a94cf5472d23aee1a1b46d
                                              • Instruction Fuzzy Hash: 3BD16B63F18B8189F711CB75D4403EC27B2EB5978CF005235EA4C67AAADF79A191C389
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: NameUser
                                              • String ID:
                                              • API String ID: 2645101109-0
                                              • Opcode ID: 543acbdf146a9e7b635a600a3cba3d05f3b2ef6cd278b1f660c9ea2185c3ff0f
                                              • Instruction ID: 3cdc4b75336fd83ac48e21439f6744206c0d8a0d205d4182434acf91771b007d
                                              • Opcode Fuzzy Hash: 543acbdf146a9e7b635a600a3cba3d05f3b2ef6cd278b1f660c9ea2185c3ff0f
                                              • Instruction Fuzzy Hash: 2101613391878182E721CF21F8403AAB3A0FB9C788F540131E68D83659DFBDD194CB49
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: \u%04x
                                              • API String ID: 0-2916071157
                                              • Opcode ID: b2b871009dddb1a89fd49cebdd6041a976c6c630323626df0c68259fe89b00fc
                                              • Instruction ID: f07a1daa87ebd1f8db33ffba73f63c4c317f5caa9fc749dd28f8f675a7e23ab1
                                              • Opcode Fuzzy Hash: b2b871009dddb1a89fd49cebdd6041a976c6c630323626df0c68259fe89b00fc
                                              • Instruction Fuzzy Hash: EE815627B0868691EA54DB25E0507FE6760FB89B80F448132DF0E93BA5DF3EE605C709
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: ":
                                              • API String ID: 0-3662656813
                                              • Opcode ID: 319ab71c5f42aa37bb32eb00852f8e3ea5b886a469a470e3f8ed3cf71016280d
                                              • Instruction ID: a97fd1e734e3668d8c696008682a6a6476a80e8bcb17b2a5282639901b202b5e
                                              • Opcode Fuzzy Hash: 319ab71c5f42aa37bb32eb00852f8e3ea5b886a469a470e3f8ed3cf71016280d
                                              • Instruction Fuzzy Hash: 22912677708A8681DB209F2AE1947AD7761FB88FC8F409022CB5E47B65CF3AD558CB05
                                              Strings
                                              • ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/, xrefs: 00007FF6EBF95399
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
                                              • API String ID: 0-1713319389
                                              • Opcode ID: a7242879f608aa47813c865fc74e262a7c273f84777ad565790803f492419e94
                                              • Instruction ID: f0b6aae499f3d5b48946f7ac5d35b5cf801428a1bbf866c1ce549c502db3ab67
                                              • Opcode Fuzzy Hash: a7242879f608aa47813c865fc74e262a7c273f84777ad565790803f492419e94
                                              • Instruction Fuzzy Hash: 2541156361D7E04AD702CB39841137D7FB2D36AB89B1CC162D7D887756CA2ED206CB11

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 1922 7ff6ebfcebf0-7ff6ebfcec2b call 7ff6ebfce970 1925 7ff6ebfcec6c 1922->1925 1926 7ff6ebfcec2d-7ff6ebfcec3c EnterCriticalSection 1922->1926 1929 7ff6ebfcec71-7ff6ebfcec8f call 7ff6ebffe860 1925->1929 1927 7ff6ebfcec3e-7ff6ebfcec60 GdiplusStartup 1926->1927 1928 7ff6ebfcec90-7ff6ebfcecaa LeaveCriticalSection GdipGetImageEncodersSize 1926->1928 1927->1928 1930 7ff6ebfcec62-7ff6ebfcec66 LeaveCriticalSection 1927->1930 1928->1925 1932 7ff6ebfcecac-7ff6ebfcecbf 1928->1932 1930->1925 1933 7ff6ebfcecc1-7ff6ebfcecca call 7ff6ebfce700 1932->1933 1934 7ff6ebfcecfb-7ff6ebfced09 call 7ff6ebfe83d8 1932->1934 1940 7ff6ebfceccc-7ff6ebfcecd6 1933->1940 1941 7ff6ebfcecf8 1933->1941 1942 7ff6ebfced10-7ff6ebfced1a 1934->1942 1943 7ff6ebfced0b-7ff6ebfced0e 1934->1943 1944 7ff6ebfcece2-7ff6ebfcecf6 call 7ff6ebfff520 1940->1944 1945 7ff6ebfcecd8 1940->1945 1941->1934 1946 7ff6ebfced1e 1942->1946 1943->1946 1948 7ff6ebfced21-7ff6ebfced24 1944->1948 1945->1944 1946->1948 1949 7ff6ebfced30-7ff6ebfced3e GdipGetImageEncoders 1948->1949 1950 7ff6ebfced26-7ff6ebfced2b 1948->1950 1953 7ff6ebfced44-7ff6ebfced4d 1949->1953 1954 7ff6ebfcee89-7ff6ebfcee8e 1949->1954 1952 7ff6ebfcee9e-7ff6ebfceea1 1950->1952 1957 7ff6ebfceea3-7ff6ebfceea7 1952->1957 1958 7ff6ebfceec4-7ff6ebfceec6 1952->1958 1955 7ff6ebfced7f 1953->1955 1956 7ff6ebfced4f-7ff6ebfced5d 1953->1956 1954->1952 1961 7ff6ebfced86-7ff6ebfced96 1955->1961 1959 7ff6ebfced60-7ff6ebfced6b 1956->1959 1960 7ff6ebfceeb0-7ff6ebfceec2 call 7ff6ebfe7620 1957->1960 1958->1929 1962 7ff6ebfced6d-7ff6ebfced72 1959->1962 1963 7ff6ebfced78-7ff6ebfced7d 1959->1963 1960->1958 1965 7ff6ebfcedaf-7ff6ebfcedcb 1961->1965 1966 7ff6ebfced98-7ff6ebfceda9 1961->1966 1962->1963 1967 7ff6ebfcee2d-7ff6ebfcee31 1962->1967 1963->1955 1963->1959 1969 7ff6ebfcedcd-7ff6ebfcee26 GdipCreateBitmapFromScan0 GdipSaveImageToStream 1965->1969 1970 7ff6ebfcee38-7ff6ebfcee77 GdipCreateBitmapFromHBITMAP GdipSaveImageToStream 1965->1970 1966->1954 1966->1965 1967->1961 1973 7ff6ebfcee36 1969->1973 1974 7ff6ebfcee28-7ff6ebfcee2b 1969->1974 1971 7ff6ebfcee90-7ff6ebfcee9d GdipDisposeImage 1970->1971 1972 7ff6ebfcee79 1970->1972 1971->1952 1975 7ff6ebfcee7c-7ff6ebfcee83 GdipDisposeImage 1972->1975 1973->1971 1974->1975 1975->1954
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Gdip$Image$CriticalSection$DisposeEncodersLeave$BitmapCreateEnterErrorFromGdiplusInitializeLastSaveScan0SizeStartupStream
                                              • String ID: &
                                              • API String ID: 1703174404-3042966939
                                              • Opcode ID: bf0236f101f8e21e317088f3cb88ff4920e04948ae26449d129670ccf4dc63a8
                                              • Instruction ID: 065b12599f3587357f3673c47a7ad6a9c8d1720ada37d353de338c61f9d9be0c
                                              • Opcode Fuzzy Hash: bf0236f101f8e21e317088f3cb88ff4920e04948ae26449d129670ccf4dc63a8
                                              • Instruction Fuzzy Hash: 59918133B04B4289E720CF20E8107E937A4FB58B98F554635DA0D8BBA4DF3AE595C749

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 2305 7ff6ebfcfca0-7ff6ebfcfdc6 call 7ff6ebfd58d0 call 7ff6ebfad590 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf986b0 call 7ff6ebf91900 call 7ff6ebf93ff0 WSAStartup 2320 7ff6ebfcfdcc-7ff6ebfcfdec socket 2305->2320 2321 7ff6ebfcfe87 2305->2321 2323 7ff6ebfcfdf2-7ff6ebfcfe1e htons 2320->2323 2324 7ff6ebfcfe81 WSACleanup 2320->2324 2322 7ff6ebfcfe89-7ff6ebfcfe91 2321->2322 2325 7ff6ebfcfe93-7ff6ebfcfea4 2322->2325 2326 7ff6ebfcfec4-7ff6ebfcff05 call 7ff6ebffe860 2322->2326 2327 7ff6ebfcfe24-7ff6ebfcfe34 call 7ff6ebfdd830 2323->2327 2328 7ff6ebfcff29-7ff6ebfcff5a call 7ff6ebfceed0 call 7ff6ebf926d0 2323->2328 2324->2321 2330 7ff6ebfcfebf call 7ff6ebffe880 2325->2330 2331 7ff6ebfcfea6-7ff6ebfcfeb9 2325->2331 2341 7ff6ebfcfe36 2327->2341 2342 7ff6ebfcfe39-7ff6ebfcfe65 inet_pton connect 2327->2342 2348 7ff6ebfcff92-7ff6ebfcffaf call 7ff6ebfceed0 2328->2348 2349 7ff6ebfcff5c-7ff6ebfcff72 2328->2349 2330->2326 2331->2330 2335 7ff6ebfd002b-7ff6ebfd0030 call 7ff6ebfe8254 2331->2335 2350 7ff6ebfd0031-7ff6ebfd0036 call 7ff6ebfe8254 2335->2350 2341->2342 2345 7ff6ebfcfe6b-7ff6ebfcfe72 2342->2345 2346 7ff6ebfcff06-7ff6ebfcff10 2342->2346 2345->2327 2347 7ff6ebfcfe74-7ff6ebfcfe7b closesocket 2345->2347 2346->2328 2351 7ff6ebfcff12-7ff6ebfcff1b 2346->2351 2347->2324 2359 7ff6ebfcffb4-7ff6ebfcffd8 call 7ff6ebf926d0 2348->2359 2352 7ff6ebfcff74-7ff6ebfcff87 2349->2352 2353 7ff6ebfcff8d call 7ff6ebffe880 2349->2353 2356 7ff6ebfcff20-7ff6ebfcff28 call 7ff6ebf94600 2351->2356 2357 7ff6ebfcff1d 2351->2357 2352->2350 2352->2353 2353->2348 2356->2328 2357->2356 2365 7ff6ebfd0014-7ff6ebfd0020 2359->2365 2366 7ff6ebfcffda-7ff6ebfcfff0 2359->2366 2365->2322 2367 7ff6ebfcfff2-7ff6ebfd0005 2366->2367 2368 7ff6ebfd0007-7ff6ebfd000c call 7ff6ebffe880 2366->2368 2367->2368 2369 7ff6ebfd0025-7ff6ebfd002a call 7ff6ebfe8254 2367->2369 2368->2365 2369->2335
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$Info$CleanupStartupUserclosesocketconnecthtonsinet_ptonsocket
                                              • String ID: geo$system
                                              • API String ID: 2440148987-2364779556
                                              • Opcode ID: 79ad5b3e3efdae5a5b2a0125b093c5025208262c15e6277f1057e95b232bf15d
                                              • Instruction ID: 44fe7282650a799c5f91a0d74ee495fabf358f5383f95305f01c9f5a6b053bb5
                                              • Opcode Fuzzy Hash: 79ad5b3e3efdae5a5b2a0125b093c5025208262c15e6277f1057e95b232bf15d
                                              • Instruction Fuzzy Hash: 1CB19163F18A4285EB009F74D4503FC2362AF58798F415236DA6C97BA9DF3AD549C309
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 3668304517-0
                                              • Opcode ID: 3ec2c6582c01c6f5f21d75f637b81b2b286b1884956eaace790e428f66b07f29
                                              • Instruction ID: 75c4e4c058fd8057d828e8be632d5406ba413cccb8f8eae716519a37445fa74a
                                              • Opcode Fuzzy Hash: 3ec2c6582c01c6f5f21d75f637b81b2b286b1884956eaace790e428f66b07f29
                                              • Instruction Fuzzy Hash: A7E1F0A3E18BC145EB119B38D4443FD2721EB9D7A8F105721EA6C4BAEADF7991C0C349
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo
                                              • String ID:
                                              • API String ID: 3215553584-0
                                              • Opcode ID: 8d4d1184268d38eb40f1b2f8de77a3be335aedca5c603a4bb4196d88dea7cd4c
                                              • Instruction ID: c8abe67108ef98e9c24013029bc52cd24e3535316b564e05c81544b9f622d0df
                                              • Opcode Fuzzy Hash: 8d4d1184268d38eb40f1b2f8de77a3be335aedca5c603a4bb4196d88dea7cd4c
                                              • Instruction Fuzzy Hash: 4DC1DF23A0C68791EA608F2494403FD7B91FB89B90F654135DA4DC77B2DE7EE845C30A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$CloseEnumOpen
                                              • String ID:
                                              • API String ID: 2177193445-0
                                              • Opcode ID: 335175d7de52c3cde64611ab16eb3cfcda64a9e8965c77d2a6e7e56c34a0b7bd
                                              • Instruction ID: c8ad44bf34b6cc35b2f07113c5e9df2c3bad2a368f61c512c7e1fa1bc6612ef5
                                              • Opcode Fuzzy Hash: 335175d7de52c3cde64611ab16eb3cfcda64a9e8965c77d2a6e7e56c34a0b7bd
                                              • Instruction Fuzzy Hash: EE719173E08B8685EB108B65E4403AD6760FB893A8F100225EFAD57AE5DF7DE091C705
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: CriticalSection$EnterLeave$DeleteGdiplusObjectShutdown
                                              • String ID:
                                              • API String ID: 4268643673-0
                                              • Opcode ID: 46c865431367d1bada0cd35fb3685f35713bfb53898f18d72c1e296ca1b3c958
                                              • Instruction ID: b44a9b9cd2e9f095401facb3907a37cb17f85537ffd5d4cf7eb26673e3271ca2
                                              • Opcode Fuzzy Hash: 46c865431367d1bada0cd35fb3685f35713bfb53898f18d72c1e296ca1b3c958
                                              • Instruction Fuzzy Hash: A9116D33605B41C1EB148F24F8601687374FB48FA4B684235DA5E876F4DF3AD896C749
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID: exists
                                              • API String ID: 3668304517-2996790960
                                              • Opcode ID: dd39506e3b16e7330b4abe6451600a7c0fd848cc8279869255eb7a7b046cd30c
                                              • Instruction ID: 1d79c42506d438ba73329fbc141cf212625658f6f1ad47d3f574f9cc9d3a2467
                                              • Opcode Fuzzy Hash: dd39506e3b16e7330b4abe6451600a7c0fd848cc8279869255eb7a7b046cd30c
                                              • Instruction Fuzzy Hash: B0A19473A14B8285EB10DF28E8803EE6361FB48798F105635EA6D97AACDF79D581C305
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID: exists
                                              • API String ID: 3668304517-2996790960
                                              • Opcode ID: a44ba3adb8b489534081c7e7143e4e360c22edcd45d63f06aad23b00fe7e26f9
                                              • Instruction ID: c62ee714d6bb5d88e6801cfd443db6785e355c92841dddf8e26353e4f5858714
                                              • Opcode Fuzzy Hash: a44ba3adb8b489534081c7e7143e4e360c22edcd45d63f06aad23b00fe7e26f9
                                              • Instruction Fuzzy Hash: FCA1A473A14B8295EB10DF28E8903ED6361FB48798F105632EA9C87AECDF39D581C305
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: EnumOpen
                                              • String ID:
                                              • API String ID: 3231578192-0
                                              • Opcode ID: d80f14cf87453080268adb68deae75d6ba4fc3d7dfc0e44dc0fd8621660a0c44
                                              • Instruction ID: 83448ceaffdbfade3a80ecefdd03842782604bad292369afd84c5938f394463f
                                              • Opcode Fuzzy Hash: d80f14cf87453080268adb68deae75d6ba4fc3d7dfc0e44dc0fd8621660a0c44
                                              • Instruction Fuzzy Hash: 95319F33A14B8685E7208FA1E850BAE7364FB48798F200225EF9D57B64DF3DD592C708
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID: exists$ios_base::badbit set
                                              • API String ID: 3668304517-2074760687
                                              • Opcode ID: be5baf6a45f3388e1d191bb0d74bb8fda1e0b9d9c77acac1c5cb0ee964cc72c1
                                              • Instruction ID: 5c3fff6b809dfac781da71f66c7a35cb7fcba2e6d726cac70f3a38949d153d7d
                                              • Opcode Fuzzy Hash: be5baf6a45f3388e1d191bb0d74bb8fda1e0b9d9c77acac1c5cb0ee964cc72c1
                                              • Instruction Fuzzy Hash: 26F16273A1DBC291EA61DB14E4943EEA361FBC8744F804132DA8D83AA9DF7ED505CB05
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: exists$ios_base::badbit set
                                              • API String ID: 0-2074760687
                                              • Opcode ID: c0ba86726db1fc3d4dca897409d179d31dc2fc9af7ec50ae3b3b445d14058caa
                                              • Instruction ID: e66c202a8e140ccba35dd2c5d068c39d289b4029a66b572bf99fae3ead3da66a
                                              • Opcode Fuzzy Hash: c0ba86726db1fc3d4dca897409d179d31dc2fc9af7ec50ae3b3b445d14058caa
                                              • Instruction Fuzzy Hash: 08F17173A1DBC291EA20DB14E4943EEA360FBC8784F404132DA8D83AA9DF7ED545CB45
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$DriveFileFindFirstLogicalStrings
                                              • String ID: content$filename
                                              • API String ID: 3820383557-474635906
                                              • Opcode ID: 20add7056d8b2eb03ca0bd7d4cb820fe4141accc525585ac0007d3c03aa2e00b
                                              • Instruction ID: 6088a125ef8e50af184ac159dd5ae6f7b0b49ef470e87fd4ae590cf30dd1eb8f
                                              • Opcode Fuzzy Hash: 20add7056d8b2eb03ca0bd7d4cb820fe4141accc525585ac0007d3c03aa2e00b
                                              • Instruction Fuzzy Hash: BF417663E1868141EA209B15F4413AEA752EB897F4F180331EBAD47BF9DE7DD181C709
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 73155330-0
                                              • Opcode ID: f3d20f7ff9aef2d20e099abdc6c0f644fad1f528a559c700ea0f51425dce6b11
                                              • Instruction ID: 134a31ecf59c19484dc2e7ca241d398c34bc13387d7ea21085c3612b957ba185
                                              • Opcode Fuzzy Hash: f3d20f7ff9aef2d20e099abdc6c0f644fad1f528a559c700ea0f51425dce6b11
                                              • Instruction Fuzzy Hash: 6F51EA63B0974245EE259F51E5003F96261AB0CBE4F580631DF6D8B7E6DE3EE582C30A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: ProcessToken$CloseCurrentHandleInformationOpen
                                              • String ID:
                                              • API String ID: 215268677-0
                                              • Opcode ID: 1c225c442ed3ae12c114120d81f2afce391d37106ff629cfd40a7a8c2f449ed4
                                              • Instruction ID: 4576b5938152ba352cd11a0f10032030514175fe49b4b55b9d7c3062c1d506cd
                                              • Opcode Fuzzy Hash: 1c225c442ed3ae12c114120d81f2afce391d37106ff629cfd40a7a8c2f449ed4
                                              • Instruction Fuzzy Hash: 16112133618B4182E7509F11F85036AB3A0FB88B80F545135EB9D87B68DF3DD445CB49
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 73155330-3916222277
                                              • Opcode ID: e9ee0ea9cb05badcaafc3030dd89d403cff2b1080adc24c0eb6429b903a99815
                                              • Instruction ID: 460ee60fd52b958e3f565eb249d84e055f18ff96019ee7608026779cdc54427b
                                              • Opcode Fuzzy Hash: e9ee0ea9cb05badcaafc3030dd89d403cff2b1080adc24c0eb6429b903a99815
                                              • Instruction Fuzzy Hash: FB517833A08B4596EB158F6AD5503AC73A0FB88B94F544632CB5D83BB4CF7AE4A1C305
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Value
                                              • String ID: ProductName$SOFTWARE\Microsoft\Windows NT\CurrentVersion
                                              • API String ID: 3702945584-1787575317
                                              • Opcode ID: e129a29887b9f0183be8920cc3d2091bc8a651926bc5c4bdd94bfbca20363a4e
                                              • Instruction ID: 5f38c1402c81aa75e1308e99704924f173dcd1808065e2b1f1753e5eae750851
                                              • Opcode Fuzzy Hash: e129a29887b9f0183be8920cc3d2091bc8a651926bc5c4bdd94bfbca20363a4e
                                              • Instruction Fuzzy Hash: 1A11B13361CB8182E7208F21F4403AAB3A4FB88788F504235EA8C83B59CF7DD154CB44
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$Cleanupclosesocketrecv
                                              • String ID:
                                              • API String ID: 1729841683-0
                                              • Opcode ID: 423ce7c02498701cdf810b56ca2b3f2970b796b57fc3722cb109c0b0bb42e6c9
                                              • Instruction ID: 72d0311316521fd65af92e8ae6cce705599421b91dd6142b92c5a71d3620c892
                                              • Opcode Fuzzy Hash: 423ce7c02498701cdf810b56ca2b3f2970b796b57fc3722cb109c0b0bb42e6c9
                                              • Instruction Fuzzy Hash: F7918573E18BC141EA209B14E4543EE6761EB897A0F104331DAAC87AF9DF7ED481C745
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: __std_fs_directory_iterator_open
                                              • String ID:
                                              • API String ID: 4007087469-0
                                              • Opcode ID: bade2491281f1fef4aa2a3921fc5c81b18db9172341867c9daf41203c220b864
                                              • Instruction ID: 58f1cfcd5fe823be3edfbe69f4cb9542cb8d271fbd21cb7c68a431edb2651bd1
                                              • Opcode Fuzzy Hash: bade2491281f1fef4aa2a3921fc5c81b18db9172341867c9daf41203c220b864
                                              • Instruction Fuzzy Hash: 1961D373F24A5285FB10DF65E4A03FC22A5AB487A8F104632DE1D97AE5DE7ED481C309
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: FolderFreeKnownPathTask_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 2444108017-0
                                              • Opcode ID: 99fb8c2fe80d49c3e055109db2acc5069031cd252a507a967ec4545ab22d43bc
                                              • Instruction ID: b49e3c95dce5d0e856cc4e24dfdedc4531bde4d0f6d656e222802f93886d0572
                                              • Opcode Fuzzy Hash: 99fb8c2fe80d49c3e055109db2acc5069031cd252a507a967ec4545ab22d43bc
                                              • Instruction Fuzzy Hash: 74316473A18B8181E620CF25E45036AA761FB987B4F205325FAAC47AA5DF7DD181CB44
                                              APIs
                                              • GetEnvironmentStringsW.KERNEL32(?,?,?,?,?,?,?,00007FF6EBFFD34F), ref: 00007FF6EBFFE25D
                                              • FreeEnvironmentStringsW.KERNEL32(?,?,?,?,?,?,?,00007FF6EBFFD34F), ref: 00007FF6EBFFE2CF
                                                • Part of subcall function 00007FF6EBFEE8BC: HeapAlloc.KERNEL32 ref: 00007FF6EBFEE8FA
                                              • FreeEnvironmentStringsW.KERNEL32(?,?,?,?,?,?,?,00007FF6EBFFD34F), ref: 00007FF6EBFFE32E
                                                • Part of subcall function 00007FF6EBFED3C8: RtlFreeHeap.NTDLL ref: 00007FF6EBFED3DE
                                                • Part of subcall function 00007FF6EBFED3C8: GetLastError.KERNEL32 ref: 00007FF6EBFED3E8
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: EnvironmentFreeStrings$Heap$AllocErrorLast
                                              • String ID:
                                              • API String ID: 3331406755-0
                                              • Opcode ID: 1d0bf75b071093d12094f7dee8fd8af945b062a2b8fd277503c0f7ab36c504b9
                                              • Instruction ID: 7455758f5d35e95a54bd008d3b29d878ce6338e56c9e2216bedb79f809a033cc
                                              • Opcode Fuzzy Hash: 1d0bf75b071093d12094f7dee8fd8af945b062a2b8fd277503c0f7ab36c504b9
                                              • Instruction Fuzzy Hash: DC31A132A0874285EA249F2574102BE7694BB4CBE0F585235EA4E97FE5EF3DE051C30A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: CloseOpenQueryValue
                                              • String ID:
                                              • API String ID: 3677997916-0
                                              • Opcode ID: 17dee76c03d428f35d4c65fa7b9c3d7c2ee4daaffae04ff52252677660165fa7
                                              • Instruction ID: 04ce7ce5b6ae7f69180a4dffa6c5f56e9ce8b709fbd4140f0d8dd5c762417e03
                                              • Opcode Fuzzy Hash: 17dee76c03d428f35d4c65fa7b9c3d7c2ee4daaffae04ff52252677660165fa7
                                              • Instruction Fuzzy Hash: 9D21D873E18B8241EA10DB65F4503AEA350FBC97D4F105235EA8D83AA5EF3DD084CB09
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Info$User
                                              • String ID:
                                              • API String ID: 2017065092-0
                                              • Opcode ID: 877c1b4e073b3a87c3d7ac6068cbd316133fc0437c9f32c249d117db553f0db1
                                              • Instruction ID: 26bb40c429b49d09352fac18fc674dd52b2d0b634e44a9f06a34ffd22403ed3f
                                              • Opcode Fuzzy Hash: 877c1b4e073b3a87c3d7ac6068cbd316133fc0437c9f32c249d117db553f0db1
                                              • Instruction Fuzzy Hash: 31118B33A1878282D7108F61E42076EB3A2FB84F88F045135EB8943B59DF7DE490CB4A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Process$CurrentExitTerminate
                                              • String ID:
                                              • API String ID: 1703294689-0
                                              • Opcode ID: 38c7b4f83e553420579c8e330882a64258dcf8d372290847a19fb81a50e45df1
                                              • Instruction ID: dadcab730ee444afef2478dcc0ec62bff95de6f1a5ab725074b48c5e75e66840
                                              • Opcode Fuzzy Hash: 38c7b4f83e553420579c8e330882a64258dcf8d372290847a19fb81a50e45df1
                                              • Instruction Fuzzy Hash: F4D09E12B1870252EF282B705CA52BC12556F9DB01F501438D80FC73F3DE2FA449C20E
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: CurrentProfile
                                              • String ID: Unknown
                                              • API String ID: 2104809126-1654365787
                                              • Opcode ID: 4f76827918f10dd37431429cd59c3a5dad29082fcd72efb0a37b876298fa9b22
                                              • Instruction ID: 8c2c2b98620b93723ff6633c9422cc01c0d7d31b9c70adbd4bc9d256fccae525
                                              • Opcode Fuzzy Hash: 4f76827918f10dd37431429cd59c3a5dad29082fcd72efb0a37b876298fa9b22
                                              • Instruction Fuzzy Hash: 9331CD23A2CBC186E7108F20F4403AAA360FB99B44F545225EBCD47A5ADF7DD695CB04
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 84cc3fcf227e02e52b61538abd4e65d466ccc1b3300c52dbbcf8ccaa401fe197
                                              • Instruction ID: 152d99064f66b1a23c05c29ffee6cd327b1d110a7ea58ff96a1c7310c7376ce8
                                              • Opcode Fuzzy Hash: 84cc3fcf227e02e52b61538abd4e65d466ccc1b3300c52dbbcf8ccaa401fe197
                                              • Instruction Fuzzy Hash: 3EA1B673A08B8186EB10DF25E8443AD77A0FB89B98F189135DA4D87765DF3ED481CB44
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 73155330-0
                                              • Opcode ID: ac9bef72bc1becd6db7cc4271beee6234b712f072e2808e18e88f5b5e70667f7
                                              • Instruction ID: 6f7201cb724231b88a0ebfa772dde016c7bd800568f460d0cd06a5c8a829af2f
                                              • Opcode Fuzzy Hash: ac9bef72bc1becd6db7cc4271beee6234b712f072e2808e18e88f5b5e70667f7
                                              • Instruction Fuzzy Hash: 6161CE27B08A8184EA149F15E1547BC23A1AB08FDCF548531CEAD877E5DF3ED856C709
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$CloseOpen
                                              • String ID:
                                              • API String ID: 3087652857-0
                                              • Opcode ID: 1c753be8555c0af407bbc24c1b8d0eba1ba72afc8dd8ae089e3295aa949478a4
                                              • Instruction ID: bde0e47aaeffa26a24f791f8453554cb2bcef1410b2d5c6dc8c8feb313d3a879
                                              • Opcode Fuzzy Hash: 1c753be8555c0af407bbc24c1b8d0eba1ba72afc8dd8ae089e3295aa949478a4
                                              • Instruction Fuzzy Hash: 2D71AF73A18B8185EB20CF64E4403ED77A1FB88798F104221EA9C97BA9DF7DD584CB05
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 73155330-0
                                              • Opcode ID: 5b7d7fd70192a4e4944a2bb577c6d29a3e24d2c7cdd49feae3e27b0a8b6ea48b
                                              • Instruction ID: 3d1586c0be91e4554c558207aecb5804528f5a7f607a6b010d2c26c7bcf5077a
                                              • Opcode Fuzzy Hash: 5b7d7fd70192a4e4944a2bb577c6d29a3e24d2c7cdd49feae3e27b0a8b6ea48b
                                              • Instruction Fuzzy Hash: E241C163708A4185EA109F15E5043ADA262BB4DBD8F544631EE6D4B7A6CF3ED041C309
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 73155330-0
                                              • Opcode ID: f229da4666ea8dff03910a5f1e3a89d98b16a4a07dd6be01f1c3f08d8ecc4d5b
                                              • Instruction ID: 6990f68e54af6eb6545921b90f96048659631f02731deec8a5669124cb3382e7
                                              • Opcode Fuzzy Hash: f229da4666ea8dff03910a5f1e3a89d98b16a4a07dd6be01f1c3f08d8ecc4d5b
                                              • Instruction Fuzzy Hash: 9641A173B0874285EE10AF56A9043E9A251BB0CBD4F548631DE6D4B7E6DE3ED185C30A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 73155330-0
                                              • Opcode ID: cff85fe953d420dccce08e1046e48035e46e767a6b7b4afb2ae039212143e7e5
                                              • Instruction ID: 305794cac83be8d4fff1c3d2084e3a7a54fa39c02fb221c7ff56b9a8734bf54a
                                              • Opcode Fuzzy Hash: cff85fe953d420dccce08e1046e48035e46e767a6b7b4afb2ae039212143e7e5
                                              • Instruction Fuzzy Hash: 93313763B0968644FE25AF91E5003F852819B19FE8F540231DE2D87BF6DE3EE481C34A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 73155330-0
                                              • Opcode ID: acb9e5508733fae1dd540759d6bda89f7ddf5a62efa39cfbafa2fb88ad30eaba
                                              • Instruction ID: 4bab2ca751c56ab643d915cc994728a69bbab6dbc4116fcd724e6d2f998363da
                                              • Opcode Fuzzy Hash: acb9e5508733fae1dd540759d6bda89f7ddf5a62efa39cfbafa2fb88ad30eaba
                                              • Instruction Fuzzy Hash: A9312733B0878284EE15AF51E5443EDA261EB08BD4F580631DE6D4BBE6DE3DE041C309
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: InformationVolume_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 4269842375-0
                                              • Opcode ID: 24033c2ac7bed2f4e8f15d55fcafd191dcb30c1665651ddb7ad32a86d71ab98b
                                              • Instruction ID: e3e566a292173c1c4d966531dfe042edc0ee500813025dbd75f7390034b909be
                                              • Opcode Fuzzy Hash: 24033c2ac7bed2f4e8f15d55fcafd191dcb30c1665651ddb7ad32a86d71ab98b
                                              • Instruction Fuzzy Hash: 81519033A18B8185E710CF64E4403ED7364FB89788F504221EB8C97AA9DF79D684CB45
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task__std_exception_copy_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 2371198981-0
                                              • Opcode ID: 2d69a428c11ea821f27ff1f3d7374fd16da8ba22ab34fa477410b1d2b1653004
                                              • Instruction ID: 48e069e4f23dae8b6ea47153b6d170cf0f34cb69711277c5e763a1f84b3d79ee
                                              • Opcode Fuzzy Hash: 2d69a428c11ea821f27ff1f3d7374fd16da8ba22ab34fa477410b1d2b1653004
                                              • Instruction Fuzzy Hash: 3121F623E05B4241EA2DAF55E5403FC6290AB48BA4F244631DA7C43BE2EE7ED5D3C345
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo
                                              • String ID:
                                              • API String ID: 3215553584-0
                                              • Opcode ID: 77ff38050bbf038ec147631c291faae903e00292372ea36fba1d268a897535c6
                                              • Instruction ID: 638c3dc327316168f0df3467d2c9e29debcf70edb271e6a5dbee44dd1b2f2c8f
                                              • Opcode Fuzzy Hash: 77ff38050bbf038ec147631c291faae903e00292372ea36fba1d268a897535c6
                                              • Instruction Fuzzy Hash: F431DF33A19A4282EE50EB10D4516FD6361AF99BA4F550139E61EC73F2EF3EE101C70A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: CloseOpen
                                              • String ID:
                                              • API String ID: 47109696-0
                                              • Opcode ID: f1dca321947a1367f0d55f51290a78f41f5e328790fa86022a41bb21031095aa
                                              • Instruction ID: 367c6470f2066decc868d23dc882f1129748c09bb3da6af06491dace98581eb4
                                              • Opcode Fuzzy Hash: f1dca321947a1367f0d55f51290a78f41f5e328790fa86022a41bb21031095aa
                                              • Instruction Fuzzy Hash: 4D21D823B18A4145EA509B25E8403FAA350EF98BD8F545231FA4D97BA9DF2ED481CB09
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 3668304517-0
                                              • Opcode ID: 3d34ab0db7fb0990d57ac02bed3557035daf76a6fef70437342f33dff0a88ccb
                                              • Instruction ID: 521bbb28714e50fe9d0ed8b582a23875ad65e228a55854cb7f5e23f3da88f228
                                              • Opcode Fuzzy Hash: 3d34ab0db7fb0990d57ac02bed3557035daf76a6fef70437342f33dff0a88ccb
                                              • Instruction Fuzzy Hash: 4F1190A3B16A8544EF48AFB5E4543BC6391EF08F98F244930DA6C87795EF2DC4908345
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: CloseCreateCredEnumerateFirstHandleMutexProcess32ReleaseSnapshotToolhelp32recv
                                              • String ID:
                                              • API String ID: 420082584-0
                                              • Opcode ID: f11b699a3200bdf963b6fe7cb1f436a7dd20cd12770bb3a4eed5e0f4a283c88b
                                              • Instruction ID: 0dc6204b4b31fb27427cfd49e34bcd9a4d965d983fd25fbff80c3ab58fe97012
                                              • Opcode Fuzzy Hash: f11b699a3200bdf963b6fe7cb1f436a7dd20cd12770bb3a4eed5e0f4a283c88b
                                              • Instruction Fuzzy Hash: 38216D13E0C68351F910B776A0663FE5240AF8D750F185A30E59ECB5F79E1FA0818A5F
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: CloseHandleMutexReleaserecv
                                              • String ID:
                                              • API String ID: 2659716615-0
                                              • Opcode ID: 9d42044f10cd135358d729f1a28af767efc6d875bb591a1efa5037cd7f4a2a2c
                                              • Instruction ID: 7b89cca635fcaf9c1c7c0f0742dcdb6e2ef04a893b175129aeb9fedcdef1c638
                                              • Opcode Fuzzy Hash: 9d42044f10cd135358d729f1a28af767efc6d875bb591a1efa5037cd7f4a2a2c
                                              • Instruction Fuzzy Hash: 88118C13E0C68241FA10B775A0163FE5240AF8D750F185630EA9DCB6F79F2EA081CA5F
                                              APIs
                                              • SetFilePointerEx.KERNEL32(?,?,?,?,?,00007FF6EBFF0E88,?,?,?,?,00000000,00007FF6EBFF0F91), ref: 00007FF6EBFF0EE8
                                              • GetLastError.KERNEL32(?,?,?,?,?,00007FF6EBFF0E88,?,?,?,?,00000000,00007FF6EBFF0F91), ref: 00007FF6EBFF0EF2
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: ErrorFileLastPointer
                                              • String ID:
                                              • API String ID: 2976181284-0
                                              • Opcode ID: 85342b8448b5f83962e520861b5040a532baca975cc467821ece28218af4e603
                                              • Instruction ID: 9b3b194f5e26f5b1dff1989f461b4ffd0688c84fd685f583c221115bac2729f1
                                              • Opcode Fuzzy Hash: 85342b8448b5f83962e520861b5040a532baca975cc467821ece28218af4e603
                                              • Instruction Fuzzy Hash: 9E11E763718B8281DE10CB25A4042A9A361EB48BF4F644331EE7D877E9DF7DD451C709
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task$std::bad_alloc::bad_alloc
                                              • String ID:
                                              • API String ID: 1173176844-0
                                              • Opcode ID: ad7fb39d7d0572768195cdb96d88edf57c93c5d00d8eaa663e4c704e5b7bea2c
                                              • Instruction ID: 82e21f0a1ad93b047de2d39f2cc34c440465fd48223aba2fe08c7c62b6e8945f
                                              • Opcode Fuzzy Hash: ad7fb39d7d0572768195cdb96d88edf57c93c5d00d8eaa663e4c704e5b7bea2c
                                              • Instruction Fuzzy Hash: 55E0EC12E1A10B15FD2835A265253F910400F8D770E3C1B70D97DCB3F3AE1EA496C15A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: ErrorFreeHeapLast
                                              • String ID:
                                              • API String ID: 485612231-0
                                              • Opcode ID: b7253a55b1276d1b57d670979138b52c86c30a15e8b70f9b8b054cc625f4c6ce
                                              • Instruction ID: f5a5c1e3fc5d6a930ea4efeeddeb8fa61a31818b531f006dfb9a2fa28a037fe1
                                              • Opcode Fuzzy Hash: b7253a55b1276d1b57d670979138b52c86c30a15e8b70f9b8b054cc625f4c6ce
                                              • Instruction Fuzzy Hash: FAE0C243F0A60282FE1867F2A8143BC02915F9C720F044034C90DD32B2FE2F6484C20E
                                              APIs
                                                • Part of subcall function 00007FF6EBFA0610: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF6EBFA0778
                                                • Part of subcall function 00007FF6EBFA0610: _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF6EBFA0784
                                              • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF6EBF9447D
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task
                                              • String ID:
                                              • API String ID: 3936042273-0
                                              • Opcode ID: 99a23dee99c3a2274b7ddeba9ef6eb76800722cce447ebe3384dcadd42dfb027
                                              • Instruction ID: 7214713a42a3aeb2efcc7cd97101d31bd253cf5159d5333fd080d26d7ce93ecd
                                              • Opcode Fuzzy Hash: 99a23dee99c3a2274b7ddeba9ef6eb76800722cce447ebe3384dcadd42dfb027
                                              • Instruction Fuzzy Hash: 35E15933A18A8184FB20CFA5E4503ED2761BB68B98F554136CF5D97BA9CF3AD490C349
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 3668304517-0
                                              • Opcode ID: d4dc96effbc9d42830f1952c9ee5ab7cd6b903e2a1abf0213b57e309d5a974ca
                                              • Instruction ID: 47a5b2939ccfdd1b36ddb252b5096dd309f02ea8a347bc35f4824d1c0aa4bb77
                                              • Opcode Fuzzy Hash: d4dc96effbc9d42830f1952c9ee5ab7cd6b903e2a1abf0213b57e309d5a974ca
                                              • Instruction Fuzzy Hash: 74B16973605A82CAEB208F75D0903EC73A1FB48B58F545632EA5D87BA8DF3AD555C304
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 3668304517-0
                                              • Opcode ID: 753ac6b25466ae8614fdc00e4c28624e9b5f05847843f991b0835b1cdb834e5b
                                              • Instruction ID: f582658e9b04942e3c2d108ed3e30242d90bcd0c0a0abfe0834c1872223e9030
                                              • Opcode Fuzzy Hash: 753ac6b25466ae8614fdc00e4c28624e9b5f05847843f991b0835b1cdb834e5b
                                              • Instruction Fuzzy Hash: E751BE27F08A818AFB118F78A4003FC6371AF58748F049721DE9D77AA5DF3AA5958349
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo
                                              • String ID:
                                              • API String ID: 3215553584-0
                                              • Opcode ID: 506399ceb7efd258d9ee9312528a7fb0108d3bcc24f039aa6e7519c78468f3b6
                                              • Instruction ID: c2b2485e0e378ce93a3c38789185e788a49f0078e5a229cd5c2770aad581553d
                                              • Opcode Fuzzy Hash: 506399ceb7efd258d9ee9312528a7fb0108d3bcc24f039aa6e7519c78468f3b6
                                              • Instruction Fuzzy Hash: 9D41C53390864587EB648F18D5413BD73A0FB5ABA0F105231DA9ED3AA1CF3EE502C75A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 3668304517-0
                                              • Opcode ID: 1191e2e04b0b3c0e310dd91d7e63048de9958ccc4be8b9de566a62fb0c638077
                                              • Instruction ID: 0134d67eefbd26f36b63bca00992ea197913471944c85970807870f9ff9da400
                                              • Opcode Fuzzy Hash: 1191e2e04b0b3c0e310dd91d7e63048de9958ccc4be8b9de566a62fb0c638077
                                              • Instruction Fuzzy Hash: C9414973B15B488EE7008FB9E4403AC33B1E74C798F004625EE9C67B99EE3591648398
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo
                                              • String ID:
                                              • API String ID: 3215553584-0
                                              • Opcode ID: a24f7c79d48368e33d7deb9d4eeecb52ce7ec7a6106812cc151fd4020b53ad0d
                                              • Instruction ID: b5f63fdbc8cadf3726d061ec0cf3175d9258bcd9128029cb4f35b36c140ac5d8
                                              • Opcode Fuzzy Hash: a24f7c79d48368e33d7deb9d4eeecb52ce7ec7a6106812cc151fd4020b53ad0d
                                              • Instruction Fuzzy Hash: 2031AF23E1864385FB516F6588413FC2690AB48BA0F620239E95D833F2DF7EE541C75A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 3668304517-0
                                              • Opcode ID: f7c75751447ac11c5e35aee20a9c5d0e2d30382cc5caf270d6c91394aa1194c9
                                              • Instruction ID: 183fd25618d6dadd9763608e44e146fd49e4e517cca3e18a51b9d893afc69d6c
                                              • Opcode Fuzzy Hash: f7c75751447ac11c5e35aee20a9c5d0e2d30382cc5caf270d6c91394aa1194c9
                                              • Instruction Fuzzy Hash: 6B310277B09B4982EF098FA9E4902AC3365EB88F89B548432CF4D47768DF3AD495C345
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: HandleModule$AddressFreeLibraryProc
                                              • String ID:
                                              • API String ID: 3947729631-0
                                              • Opcode ID: 9e03c0276b42d0bae273c9ceb8b8abd1e24865752fa8da44abca3c0ffcb1668a
                                              • Instruction ID: 203d2847bb6bab047e730766ae8d1ed3b288373f6f34aecdd0751533586fd491
                                              • Opcode Fuzzy Hash: 9e03c0276b42d0bae273c9ceb8b8abd1e24865752fa8da44abca3c0ffcb1668a
                                              • Instruction Fuzzy Hash: 11214C32A046468AEB648F68C4443EC37A0EB4871CF640635E72D87BE5DF79D584CB45
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo
                                              • String ID:
                                              • API String ID: 3215553584-0
                                              • Opcode ID: 4bdd7c7df9abbb715da046ae302baf4d590079e7e30464498c50f0bf6b7ea38d
                                              • Instruction ID: 80e689f72d00035024adf00029e98b39192eb820bf486b1e0aaff37c7f40e256
                                              • Opcode Fuzzy Hash: 4bdd7c7df9abbb715da046ae302baf4d590079e7e30464498c50f0bf6b7ea38d
                                              • Instruction Fuzzy Hash: 48218073A18A4287DB618F18D44137A77A0EF85B94F554234E65D876D9EF3ED400CB05
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo
                                              • String ID:
                                              • API String ID: 3215553584-0
                                              • Opcode ID: 277766cc613ac521deff1262cc5973a4c6dda0ce244441028124d0478fb53980
                                              • Instruction ID: efd0cba991475629bb9ca069d2bb533cf6ac47a221cae4e746953613a4f4b58b
                                              • Opcode Fuzzy Hash: 277766cc613ac521deff1262cc5973a4c6dda0ce244441028124d0478fb53980
                                              • Instruction Fuzzy Hash: B7115133A1D64181EA609F1194013FEA260BF89F90F454835EADCA7AA7EF3FD500C74A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 3668304517-0
                                              • Opcode ID: 554b7db7ea9ca0f42748f15c58d51ccebd3c07419b982c2e64439f92371340d5
                                              • Instruction ID: ab29549aeda1cd1275b1b3b0d569933ae79717a86d93afe938ce93a80bd15acb
                                              • Opcode Fuzzy Hash: 554b7db7ea9ca0f42748f15c58d51ccebd3c07419b982c2e64439f92371340d5
                                              • Instruction Fuzzy Hash: 82F0AFA3A25AC541EB459B24E0043BC2351AB48F88F600471CA9C4B6E6DFBEC495C349
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: send
                                              • String ID:
                                              • API String ID: 2809346765-0
                                              • Opcode ID: 10723b900c3d3fb221c2729e0f2ab508e71a113b43aaaf7fd55bda6ca2804ccb
                                              • Instruction ID: b103b272d2bdb8854b20a32ce6537ed97fb42703d3edd7ed60ee7bd132d5cb7f
                                              • Opcode Fuzzy Hash: 10723b900c3d3fb221c2729e0f2ab508e71a113b43aaaf7fd55bda6ca2804ccb
                                              • Instruction Fuzzy Hash: 6A01F222B18A8181DB108F26F950669A7A0FB8CFD4F485234EE5D83B58DF39C8418B04
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: FileFindNext
                                              • String ID:
                                              • API String ID: 2029273394-0
                                              • Opcode ID: 752fe5805e453647425062ce64daa4e53c54a82ad0d646f83825288564bb7983
                                              • Instruction ID: 75cf034b5c5251da4a6f0a033f3f1f1a85629eedd077bd93fee4c99a30ee87ad
                                              • Opcode Fuzzy Hash: 752fe5805e453647425062ce64daa4e53c54a82ad0d646f83825288564bb7983
                                              • Instruction Fuzzy Hash: C001442761C98190EA70CB56F4543AA6364F788B94F440032DE8D93B69DF3ED886CB04
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo
                                              • String ID:
                                              • API String ID: 3215553584-0
                                              • Opcode ID: 68ea0e6e30933e9dd76abf56f21314c638998a57c534cc3687c594a1fb5b02e7
                                              • Instruction ID: da3d01b67f426954d89b630fe96282046ea4798338273bb65c97dc11f07e17f7
                                              • Opcode Fuzzy Hash: 68ea0e6e30933e9dd76abf56f21314c638998a57c534cc3687c594a1fb5b02e7
                                              • Instruction Fuzzy Hash: 82E06D33E19A4285EBA56BA992412BC61506F487B0F544331EB3C836E6DE3A9460871A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: FileFindNext
                                              • String ID:
                                              • API String ID: 2029273394-0
                                              • Opcode ID: 4104833be8186ecfced91f05a1dc286f8d4e1ac7fad94ea37a2bf5d234dce428
                                              • Instruction ID: 358172623b2513cb882f0d3c298832f85b6fa1bc66bfd9cc4d5bc71a532bc8be
                                              • Opcode Fuzzy Hash: 4104833be8186ecfced91f05a1dc286f8d4e1ac7fad94ea37a2bf5d234dce428
                                              • Instruction Fuzzy Hash: EBC04C16F1D542D1E6581B625C9226211D45B54B21F440430C508C1151EF1F91D6CA1A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: InfoNativeSystem
                                              • String ID:
                                              • API String ID: 1721193555-0
                                              • Opcode ID: ebb3c2d15c06801dfe805b6087078b0f501a5fe9f8c446694f4975735c5f9cad
                                              • Instruction ID: 976cf1bb6cc96f4ab8bc3e538abd6f49fb13df750a8eda4246582542b874af3e
                                              • Opcode Fuzzy Hash: ebb3c2d15c06801dfe805b6087078b0f501a5fe9f8c446694f4975735c5f9cad
                                              • Instruction Fuzzy Hash: 58B09B36E148C0C3C511EB04D8510157331F79470DFD00010D24D42615DF1DD515CE04
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: AllocHeap
                                              • String ID:
                                              • API String ID: 4292702814-0
                                              • Opcode ID: eba47d0c810211a009f984e3ce810decee2d7cb9fb39a7e87e15bbee8ef19542
                                              • Instruction ID: 2529c9a31ea8f646ec4b7b3e446893d5e6b7e6d3e94eed55a49ba5abc10a4a14
                                              • Opcode Fuzzy Hash: eba47d0c810211a009f984e3ce810decee2d7cb9fb39a7e87e15bbee8ef19542
                                              • Instruction Fuzzy Hash: 45F05E23B0920644FE9466A178207FD22815F8C770F484230D92EC72E2DE2EE480C21A
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                              • String ID: cannot compare iterators of different containers$cannot use push_back() with $type must be string, but is $value
                                              • API String ID: 73155330-2711811579
                                              • Opcode ID: d0719c5418f008686ca9cf5146cdc412f2d75a86e3b203137f9a55923ab0c254
                                              • Instruction ID: a0f6b3fe0a6564f4785db6f1eb897b98cf004550227fb6d2adf9cc005dfad99b
                                              • Opcode Fuzzy Hash: d0719c5418f008686ca9cf5146cdc412f2d75a86e3b203137f9a55923ab0c254
                                              • Instruction Fuzzy Hash: 24538F73A04BC689DB709F24D8803ED23A0FB49758F409635DA5D9BBA9EF39D284C705
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task$ExceptionFileHeaderRaise__std_exception_copy
                                              • String ID: "$#base$#include$*$/$No closed word$Unexpected eof$key declared, but no value$key opened, but never closed$object is not closed with '}'$quote was opened but not closed.$unexpected '}'$unexpected key without object$word wasnt properly ended
                                              • API String ID: 1861853482-3561477107
                                              • Opcode ID: 799aef1f6f9097462206881b47845b806dc41db112fb01f7a86afa31b7bee32f
                                              • Instruction ID: b2d5d21502d9a55efa77f2da736000d653b25057c6e8d61ad41c9ebd67389c99
                                              • Opcode Fuzzy Hash: 799aef1f6f9097462206881b47845b806dc41db112fb01f7a86afa31b7bee32f
                                              • Instruction Fuzzy Hash: 65D2C473A09BC685EB759F24C8503FC23A1FB48788F448131CA5D8BAA9DF79D685C706
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: Software$exists
                                              • API String ID: 0-2364128853
                                              • Opcode ID: 3b7153b56b37cf3a74ea77418dd2f4322d64642f8a990d637fac1f4450f4d51d
                                              • Instruction ID: 1804148c5ad7abb8413aa67a68cdef2f2d7eec0b8e6b79281b6d2b5a970ac6bb
                                              • Opcode Fuzzy Hash: 3b7153b56b37cf3a74ea77418dd2f4322d64642f8a990d637fac1f4450f4d51d
                                              • Instruction Fuzzy Hash: 81D29073A14BC58AEB21CF25D8403ED73A0FB89798F105221EA9D97BA9DF79D580C305
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID: content$directory_iterator::directory_iterator$exists$filename$files$key
                                              • API String ID: 3668304517-2980817763
                                              • Opcode ID: 9649f2ffd3fee09ab759c6b265c90b8e1995531e4d45c1de8a47d26890731f80
                                              • Instruction ID: 0d16db9190ac610bd422c617fb4131ec272696c0cb808d306e9ecdfdc0cd9e68
                                              • Opcode Fuzzy Hash: 9649f2ffd3fee09ab759c6b265c90b8e1995531e4d45c1de8a47d26890731f80
                                              • Instruction Fuzzy Hash: A1A29F73A14BC589DB218F35D8843ED33A1FB89758F404625EA9C4BBAADF79D280C345
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Handle$Query$CloseInformationProcessSystem_invalid_parameter_noinfo_noreturn$AddressCurrentFinalModuleNameObjectOpenPathProc
                                              • String ID: File$NtDuplicateObject$ntdll.dll
                                              • API String ID: 1269246921-3955674919
                                              • Opcode ID: 7f25dccb0f32d932e33b43ccaed584e183ce49f1311762ec94acd30fa40f03ec
                                              • Instruction ID: 14678251f1e65acaf61395a8300803ec1185a1474b8f30e6bb2ddd56b7c23589
                                              • Opcode Fuzzy Hash: 7f25dccb0f32d932e33b43ccaed584e183ce49f1311762ec94acd30fa40f03ec
                                              • Instruction Fuzzy Hash: 69E1CF63B18A8589FB00CBA5E4143FC23A1AB49B98F008131DF5D97BA9DF3ED549C749
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                              • String ID: #recycle$$recycle.bin$$windows.~bt$$windows.~ws$$winreagent$All users$AppData$Application Data$Boot$PerfLogs$Program Files$Program Files (x86)$ProgramData$System Volume Information$Windows$Windows.old$Windows.~bt$bootmgr$config.msi$ntldr
                                              • API String ID: 73155330-2722463023
                                              • Opcode ID: 7d392a795bfbfd6594683dd8fb9872c8abf8b0b593989480866b32def73f354a
                                              • Instruction ID: f0aff3c9386e26ee966810e8caa3d37a3cd9e3e95cab68d4444350a6d2a45b65
                                              • Opcode Fuzzy Hash: 7d392a795bfbfd6594683dd8fb9872c8abf8b0b593989480866b32def73f354a
                                              • Instruction Fuzzy Hash: 3FA1A263D64FCA94E710CB35D8823F55361FBEA344F506326E98CA2866EF69E2C0C345
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Initialize_invalid_parameter_noinfo_noreturn
                                              • String ID: @
                                              • API String ID: 3490963316-2766056989
                                              • Opcode ID: 6301cce65992a297ac26bc8e5f4cb950baf5d96f16c96050c5b4453803ed6c23
                                              • Instruction ID: e241a8b6fe969ec2a9580680dc82f46a481f20bf37504200360d1b49c0314fe8
                                              • Opcode Fuzzy Hash: 6301cce65992a297ac26bc8e5f4cb950baf5d96f16c96050c5b4453803ed6c23
                                              • Instruction Fuzzy Hash: 0BA18E33B18A418AE710CF64E4113AD77B1FB88758F004235DE5E97AA5EF3AD194C749
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$__std_fs_convert_wide_to_narrow$__std_fs_code_page
                                              • String ID: content$directory_iterator::directory_iterator$exists$filename$status
                                              • API String ID: 2212124024-3429737954
                                              • Opcode ID: 91316b43dceaabf7e04d41864d2dd13ee4932e04657a8589823a74b24cde9157
                                              • Instruction ID: aec3ac0eb712618bb56fc98343ca3b9d674ab75c153705eca900b67e9cc3e4f6
                                              • Opcode Fuzzy Hash: 91316b43dceaabf7e04d41864d2dd13ee4932e04657a8589823a74b24cde9157
                                              • Instruction Fuzzy Hash: 61729033A15BC285EB219F25D8803ED6360FB8D798F444232DA9D87BA9DF79D684C305
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID: content$directory_iterator::directory_iterator$exists$filename
                                              • API String ID: 3668304517-1400943384
                                              • Opcode ID: f854aea802de4000c67eb3354c4d53a8e90241fa0fafa1c2e9f1c207d3dd868d
                                              • Instruction ID: f2432cf4ab33b2dcaede8741bd3f6c076bde00ac396d0e60cb12978955cec8be
                                              • Opcode Fuzzy Hash: f854aea802de4000c67eb3354c4d53a8e90241fa0fafa1c2e9f1c207d3dd868d
                                              • Instruction Fuzzy Hash: 8052A173A18BC189EB608F25E8803ED73A1FB89798F005231EA9D57BA9DF79D540C345
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: lstrcatlstrcpy$Object$AcquireAllocateInitializeLockMemoryUninitializeVirtual
                                              • String ID: 0
                                              • API String ID: 3636535045-4108050209
                                              • Opcode ID: 0902a0343fdc6246b23ac9e8b2963860140ecb12f80d28b06803a63a8b2f31ad
                                              • Instruction ID: 4569b13846addacd6eef49ecbf69989a2d05ed625102050f611ab22e4cbc3aea
                                              • Opcode Fuzzy Hash: 0902a0343fdc6246b23ac9e8b2963860140ecb12f80d28b06803a63a8b2f31ad
                                              • Instruction Fuzzy Hash: B4B2893662AF988AD7808F69F88165EB3B5F788B84B106215FECD57B18EF38C154C744
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$__std_exception_copy
                                              • String ID: parse_error
                                              • API String ID: 1944019136-3903021949
                                              • Opcode ID: 6a65c25fb3c11bf1777165cb4e3ab94cb82028f61fa7738f7c2cb4c2b260b402
                                              • Instruction ID: 9eafc4fcf410c2cae63ebe0499bc1bbe64cbff4c56861802f388bee5d3808341
                                              • Opcode Fuzzy Hash: 6a65c25fb3c11bf1777165cb4e3ab94cb82028f61fa7738f7c2cb4c2b260b402
                                              • Instruction Fuzzy Hash: 72A18063F14B8189EB10DF65E4403ED6361EB49798F105731EA5C57AEAEF3AD280C349
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: ErrorLastNameTranslate$CodeInfoLocalePageValidValue
                                              • String ID: utf8
                                              • API String ID: 3069159798-905460609
                                              • Opcode ID: 41343eb44851c0e8f8055f3926715ba520ae6846787d1c3cb08d70e80e5c003e
                                              • Instruction ID: 3978e831d22657132478252404c708bae0a38af9f89b8245e7b495681fe45b44
                                              • Opcode Fuzzy Hash: 41343eb44851c0e8f8055f3926715ba520ae6846787d1c3cb08d70e80e5c003e
                                              • Instruction Fuzzy Hash: 0891AB33A08742C5EB66AF21D4513F923A5EF48B80F648131DA5C877A6EF3EE541C30A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Value$Locale$CodeErrorInfoLastPageValid$DefaultEnumLocalesProcessSystemUser
                                              • String ID:
                                              • API String ID: 2591520935-0
                                              • Opcode ID: 35311c5f5cbb088db9cafc063da405a92d1dac0a49a1e36eea51d3b328654a2c
                                              • Instruction ID: 32a4494f1588e198a2280bae9af4392c15d208187bcd7dfcb5ea86406e07a9c3
                                              • Opcode Fuzzy Hash: 35311c5f5cbb088db9cafc063da405a92d1dac0a49a1e36eea51d3b328654a2c
                                              • Instruction Fuzzy Hash: B6714733F0870289EF549F60D8507F823A5AF48B48FA48535CA1D936A5EF3EE845C35A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
                                              • String ID:
                                              • API String ID: 1239891234-0
                                              • Opcode ID: 518a55c6435702555d938cb12e0853557d9473da796008457dbc6bc20602c87e
                                              • Instruction ID: e84c7f38b3b3868bffdef0f8da0c1be31ff0e7b2a992c1a9c486f4a9a79e2477
                                              • Opcode Fuzzy Hash: 518a55c6435702555d938cb12e0853557d9473da796008457dbc6bc20602c87e
                                              • Instruction Fuzzy Hash: 31317F33608B8185DB64CF25E8503AE73A4FB89798F500136EB8D83BA5EF3AD545CB05
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 0| $\|
                                              • API String ID: 0-2050777373
                                              • Opcode ID: ad8b8a06ee8e7dbd9eb0ed87f328e0d9eefed4ef2557dac10ab3baeca558fbf1
                                              • Instruction ID: 7b399740a6a304b916e75aff972e4728dfea9e484d1e864382b445168961d446
                                              • Opcode Fuzzy Hash: ad8b8a06ee8e7dbd9eb0ed87f328e0d9eefed4ef2557dac10ab3baeca558fbf1
                                              • Instruction Fuzzy Hash: 2104E032915BC489D7359F39EC853E977A4F79978CF006225EB8C5AB29EF3493A08305
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 73155330-0
                                              • Opcode ID: 18f67507a347af2e506a4d9ce346a33afe5810cc4d1d15b5aba21bf871a9060d
                                              • Instruction ID: 50cbe0f8c1fbc8c8ee492430741847a8dca2591251c5100f49c12bace5fc5c42
                                              • Opcode Fuzzy Hash: 18f67507a347af2e506a4d9ce346a33afe5810cc4d1d15b5aba21bf871a9060d
                                              • Instruction Fuzzy Hash: 0102CD63B15B8285EB20CF65D4803EE7361EB4CB98F048232DE9C977A9DE39E591C345
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Crypt$AlgorithmProvider$CloseGenerateOpenPropertySymmetric_invalid_parameter_noinfo_noreturn
                                              • String ID: content$filename$ios_base::badbit set
                                              • API String ID: 3077847781-879919306
                                              • Opcode ID: 6e94e060122cfcc206018a54e50cb69dc838f32e9354242d1e19bd33f96211b6
                                              • Instruction ID: bb2c86fc9c53f07f4451b2e70a11b9e4e6c6d3ccaed9a44bc9c7122470badda7
                                              • Opcode Fuzzy Hash: 6e94e060122cfcc206018a54e50cb69dc838f32e9354242d1e19bd33f96211b6
                                              • Instruction Fuzzy Hash: 3E82F13251DBC595EAB18B14E8803EAB3A4F7C8340F505226DACD83BA9EF79C594CB04
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID: %$+
                                              • API String ID: 3668304517-2626897407
                                              • Opcode ID: 2a9587413e2d48aa4d17cad7d7e1d710b4a5cce885f46ec7b2e442a08a5377da
                                              • Instruction ID: 9b3eae2d85245859912c00f689ce34ea1a7e6b451275fbf4c38f59cfb21cd927
                                              • Opcode Fuzzy Hash: 2a9587413e2d48aa4d17cad7d7e1d710b4a5cce885f46ec7b2e442a08a5377da
                                              • Instruction Fuzzy Hash: 8D221423B18A818AFB22CB65D4403FD6761AB58788F044231DE4D9BBE9DF3DD485C74A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Virtual$AllocInfoProtectQuerySystem
                                              • String ID:
                                              • API String ID: 3562403962-0
                                              • Opcode ID: 6131e7ac5c004b666fb02de1823fa69e50ababb2f1d6eff18536aed83fe204ab
                                              • Instruction ID: a47bb95a8bd3531b3e4d4c5094dd10e7083c87fb06c7cefdf43f4fd92b2d60e3
                                              • Opcode Fuzzy Hash: 6131e7ac5c004b666fb02de1823fa69e50ababb2f1d6eff18536aed83fe204ab
                                              • Instruction Fuzzy Hash: BC316833714A819EEB20CF31D8547E823A5FB48B98F948025EA4D87B59DF3AE645C705
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _get_daylight$_invalid_parameter_noinfo
                                              • String ID:
                                              • API String ID: 1286766494-0
                                              • Opcode ID: 91154ea289c3556cf103cf6e37fc2ba0624cd5322ab1aec8ddf48183395d8b30
                                              • Instruction ID: 601c1c84671ae73e17a93e783c9320756db177eb86274432b4ef9ca44314a3ca
                                              • Opcode Fuzzy Hash: 91154ea289c3556cf103cf6e37fc2ba0624cd5322ab1aec8ddf48183395d8b30
                                              • Instruction Fuzzy Hash: F392D133A0868686EB648F2596502BD77A5FF49784F244135DB8D87BB4DF3ED510C30A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: CryptDecrypt
                                              • String ID:
                                              • API String ID: 2620231605-0
                                              • Opcode ID: 53ff8f15f52a4dad002d02071431e1ae472ef2918a40c303ed80889b4daa44ad
                                              • Instruction ID: 68df2f4ce992d2b214dd1171a2dc081775614261493978bea9490416edb6e08c
                                              • Opcode Fuzzy Hash: 53ff8f15f52a4dad002d02071431e1ae472ef2918a40c303ed80889b4daa44ad
                                              • Instruction Fuzzy Hash: F4B18A73E08B819AE711CB64E4143BD37A1E74878CF018226DE4C4BAA9DF7AD199C709
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: DevicesDisplayEnum$_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 2655931952-0
                                              • Opcode ID: c108eed3e8d4d35de98e63ec076e666f2f7a86b78baa1b258911472a2c54d96a
                                              • Instruction ID: 9fedefb9b5b182a94ec6cf47563513cd7d17f711608afc8e90b255e0ad8e85c9
                                              • Opcode Fuzzy Hash: c108eed3e8d4d35de98e63ec076e666f2f7a86b78baa1b258911472a2c54d96a
                                              • Instruction Fuzzy Hash: 8881DD33A18B8586E720CF25E8403AE77A5F788788F505225EE9C57BA8DF3DD181CB04
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: InfoLocale$ErrorLastValue_invalid_parameter_noinfo
                                              • String ID:
                                              • API String ID: 1791019856-0
                                              • Opcode ID: 8cdfe7f1b5fd9999da327c4f4609675d5690c7bae2d768c40d9912784c01383a
                                              • Instruction ID: 15029595dbce43ab05f0d041b6e970067d33a3cdf0e1a9142c99bff0c6316ce7
                                              • Opcode Fuzzy Hash: 8cdfe7f1b5fd9999da327c4f4609675d5690c7bae2d768c40d9912784c01383a
                                              • Instruction Fuzzy Hash: 45618D33A085428AEB249F11E5503F973A2FB98744F548135CB9ED3AA1DF3EE551C70A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: CryptDataFreeLocalUnprotect_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 2610421622-0
                                              • Opcode ID: e5360f3d140a921f7379d2b2b326bf004e0d324b5271c99d0bbab57465024cd6
                                              • Instruction ID: c3262c417120355dc704713b2b2d8ec139537c250734e40f33f1fb67276ae4c1
                                              • Opcode Fuzzy Hash: e5360f3d140a921f7379d2b2b326bf004e0d324b5271c99d0bbab57465024cd6
                                              • Instruction Fuzzy Hash: 42617733F18A808AE710DF75E4413EC73A1EB5978CF008225EA8C57A9ADF7AD594C348
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: -$e+000$gfff
                                              • API String ID: 0-2620144452
                                              • Opcode ID: c7e19593615f5b016f33edca04d76eabfb088503034d3aa1c419b3a715446e94
                                              • Instruction ID: c45b93bdf922c9ebc230979f85c1d4028c50081962d76b55918a5ab98dbe65a9
                                              • Opcode Fuzzy Hash: c7e19593615f5b016f33edca04d76eabfb088503034d3aa1c419b3a715446e94
                                              • Instruction Fuzzy Hash: E0516867B286C546F7258E35D8007BDB791E748BA4F488231DBA8C7AE5CF3ED4008706
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: InfoLocale
                                              • String ID: GetLocaleInfoEx
                                              • API String ID: 2299586839-2904428671
                                              • Opcode ID: 099550578a3a416ea78b7fa52ed638fc0f733537aeae7f3447c0ea0cdfd8c17a
                                              • Instruction ID: f59f1cbd85e2e0252bc29c267ea3e0053525356a973aadcb62485829ff8604f8
                                              • Opcode Fuzzy Hash: 099550578a3a416ea78b7fa52ed638fc0f733537aeae7f3447c0ea0cdfd8c17a
                                              • Instruction Fuzzy Hash: 0801A726B0C68185EB848B5AF4102BAA761FF8CBD0F544035DE4D93BAACF3ED501C349
                                              APIs
                                              • GetLastError.KERNEL32 ref: 00007FF6EBFFC1CD
                                              • _invalid_parameter_noinfo.LIBCMT ref: 00007FF6EBFFC38F
                                                • Part of subcall function 00007FF6EBFEDA30: HeapAlloc.KERNEL32(?,?,00000000,00007FF6EBFEA0C6,?,?,-2723E8D8DEBC5093,00007FF6EBFE4E71,?,?,?,?,00007FF6EBFED3FC), ref: 00007FF6EBFEDA85
                                                • Part of subcall function 00007FF6EBFED3C8: RtlFreeHeap.NTDLL ref: 00007FF6EBFED3DE
                                                • Part of subcall function 00007FF6EBFED3C8: GetLastError.KERNEL32 ref: 00007FF6EBFED3E8
                                                • Part of subcall function 00007FF6EBFFD894: _invalid_parameter_noinfo.LIBCMT ref: 00007FF6EBFFD8C7
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: ErrorHeapLast_invalid_parameter_noinfo$AllocFree
                                              • String ID:
                                              • API String ID: 749460637-0
                                              • Opcode ID: 27640a1b4452658f619c330b6942f42c57ed7cbddb1e0b5935f25c2a2fe2ad05
                                              • Instruction ID: 74cf48da633deaaba1109c99192da6bd1613a04f4d2ae9e246c4a008c380fa51
                                              • Opcode Fuzzy Hash: 27640a1b4452658f619c330b6942f42c57ed7cbddb1e0b5935f25c2a2fe2ad05
                                              • Instruction Fuzzy Hash: A9611823B0865242E7209F66A4107FD7290BF8CBC0F144131EE4D87BA6EE3EE401C709
                                              APIs
                                              • CryptProtectData.CRYPT32(?,?,?,?,?,?,?,?,1E5E0F68EF71A387,00007FF6EBFC7E98), ref: 00007FF6EBFC7F18
                                              • LocalFree.KERNEL32(?,?,?,?,?,?,?,?,1E5E0F68EF71A387,00007FF6EBFC7E98), ref: 00007FF6EBFC7FAA
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: CryptDataFreeLocalProtect
                                              • String ID:
                                              • API String ID: 2714945720-0
                                              • Opcode ID: a2378fc87af65e51448867ee86bab5adaeca8e4500ced070fe446fae58ae31d0
                                              • Instruction ID: 0577d35691e542b3ce27c516178c1e38d6247ee0953c09f9783728d697d83b14
                                              • Opcode Fuzzy Hash: a2378fc87af65e51448867ee86bab5adaeca8e4500ced070fe446fae58ae31d0
                                              • Instruction Fuzzy Hash: 8E412633A18A818AE3208F74D4503ED77A4FB5878CF044229EA8C46A4ADF7AD5A4C748
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: a/p$am/pm
                                              • API String ID: 0-3206640213
                                              • Opcode ID: 3aa2d18b96f53096dafde024e84d8e74b450cb229927da4525f6c74ea8e41481
                                              • Instruction ID: f944e2b184ae913b7b47efb043c4af56d2aea06d12be2553e4231b49ed02f46a
                                              • Opcode Fuzzy Hash: 3aa2d18b96f53096dafde024e84d8e74b450cb229927da4525f6c74ea8e41481
                                              • Instruction Fuzzy Hash: 28E1A923A0868281EF748F2591547F922A4FF58794F654132EB5D87BB5EF3EE940C30A
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: dumps$emoji
                                              • API String ID: 0-2873254224
                                              • Opcode ID: 9c1d1d90ca4f88bc8268b0322e863aaa792dfa8aa99b6ae742cb4d4f1446b717
                                              • Instruction ID: 4bd903d0b63107745ee2c61dc3ece84ba05432ffea97f31a81d23158bc45a277
                                              • Opcode Fuzzy Hash: 9c1d1d90ca4f88bc8268b0322e863aaa792dfa8aa99b6ae742cb4d4f1446b717
                                              • Instruction Fuzzy Hash: F3B11A23928BC586E661CB25E8802AAB7B4F79D788F505325FACD53B59DF3CD250CB04
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Info
                                              • String ID:
                                              • API String ID: 1807457897-0
                                              • Opcode ID: 90946a6b15058c528e056b8d8cd1a92ef4f6d2102c32f556ef9c06fc4cf9f037
                                              • Instruction ID: 386b781b675a06504762380b7b44c1c431aa73d85aa19485af057d4f5d05e1e0
                                              • Opcode Fuzzy Hash: 90946a6b15058c528e056b8d8cd1a92ef4f6d2102c32f556ef9c06fc4cf9f037
                                              • Instruction Fuzzy Hash: 6A12AB23A08BC186E751CF2894053FD73A4FB59748F159235EB9C876A2EF3AE294C705
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task
                                              • String ID:
                                              • API String ID: 118556049-0
                                              • Opcode ID: 77270c227ffeb004b750eba44a016f14a5b20c8e9565abcba5683151d7bf73c1
                                              • Instruction ID: 3ed671b064092663c391501c9dc4f9d62aa38171a1039aea27fdf68e9507da59
                                              • Opcode Fuzzy Hash: 77270c227ffeb004b750eba44a016f14a5b20c8e9565abcba5683151d7bf73c1
                                              • Instruction Fuzzy Hash: B5A18823A09B9989EB04CBA9D8803EC27B0F719B48F548426CF8D93B65DF39D091C315
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task
                                              • String ID:
                                              • API String ID: 118556049-0
                                              • Opcode ID: 19769e847731a8f3ae8f2781323fac765a50851832732306f59deb7ca3333fae
                                              • Instruction ID: e50902977192af358fd95eaf86fbdcdcbf4d3aad3346e0f16af69a62fbfeb7a3
                                              • Opcode Fuzzy Hash: 19769e847731a8f3ae8f2781323fac765a50851832732306f59deb7ca3333fae
                                              • Instruction Fuzzy Hash: 92A19C23A19B9989EB04CBA9D4803EC37B0F758B88F548426DF8D93766DF39D091C751
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task
                                              • String ID:
                                              • API String ID: 118556049-0
                                              • Opcode ID: ee8b0f9f2e73586f7a4fc3912ce6b8e3a620c06cd61257d921c36885d417bf64
                                              • Instruction ID: 5004350d7def9ef8dec98d2fe7b0fd66ea10f1c91bb8fbf0601586cdb2ae0bf3
                                              • Opcode Fuzzy Hash: ee8b0f9f2e73586f7a4fc3912ce6b8e3a620c06cd61257d921c36885d417bf64
                                              • Instruction Fuzzy Hash: 58A18B23A19B9A89EB04CBA9D4803EC3770F759788F544426DF8D93BAADF39D091C311
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task
                                              • String ID:
                                              • API String ID: 118556049-0
                                              • Opcode ID: a0e78a6ef54e2a893f1caef4e4e4ab9343fbc453b4b6cae2b4af0f6514b75cbd
                                              • Instruction ID: 36e1f56279bf7ebab8cf0caa9e7641af9a821080c3212728750706d074fbd786
                                              • Opcode Fuzzy Hash: a0e78a6ef54e2a893f1caef4e4e4ab9343fbc453b4b6cae2b4af0f6514b75cbd
                                              • Instruction Fuzzy Hash: ACA19A23A18B9989EB04CBA9D4803EC67B0FB48788F544126DF8D97B66DF39E091C304
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: ErrorLast$EnumLocalesSystemValue
                                              • String ID:
                                              • API String ID: 3029459697-0
                                              • Opcode ID: b863ec2cec9009a3af30c9a1a615a32510d45c83cc126c9469ae93d30e306958
                                              • Instruction ID: b6eebf12ebd1ad23efab762c0af32795390ad7184b3db9cbaef3f620a42f926e
                                              • Opcode Fuzzy Hash: b863ec2cec9009a3af30c9a1a615a32510d45c83cc126c9469ae93d30e306958
                                              • Instruction Fuzzy Hash: 8E110263A08645CAEB158F2AD4407EC7BA2FB94BA0F548131D629833E4CE79D6D1C745
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: ErrorLast$EnumLocalesSystemValue
                                              • String ID:
                                              • API String ID: 3029459697-0
                                              • Opcode ID: 0c241287891358d20c5c1590d81d3974ae3e0a48a457f3cbc01ffa927b921278
                                              • Instruction ID: 8a37e7878a09153c7320dcb3c146fb4bddc63a92b0497d6a1d3bc905ba3dfb80
                                              • Opcode Fuzzy Hash: 0c241287891358d20c5c1590d81d3974ae3e0a48a457f3cbc01ffa927b921278
                                              • Instruction Fuzzy Hash: EF01B573E0824546EB144F2AE8407F97692EB44BA4F55C231D669873E4DF7AD481C70A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: EnumLocalesSystem
                                              • String ID:
                                              • API String ID: 2099609381-0
                                              • Opcode ID: 17140df511fe09419b9fc83be2d2c34c2fb9fdba42dd4bc62a26aeb66c77a399
                                              • Instruction ID: ca10826eea7792ee47b646c6391be62be0835b3354014e132a7278d08a911618
                                              • Opcode Fuzzy Hash: 17140df511fe09419b9fc83be2d2c34c2fb9fdba42dd4bc62a26aeb66c77a399
                                              • Instruction Fuzzy Hash: CCF08C73B08B4182E704DB25F8906B96361EB88B90F149035EA5DC7366CF3ED5A1C309
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: HeapProcess
                                              • String ID:
                                              • API String ID: 54951025-0
                                              • Opcode ID: 9736d98ff4c00b43741f239e002f48ba729bdd9c0db5a1f9682fb9dc510a38ab
                                              • Instruction ID: 45ebf314685048d76cbf22dd93213eff3967f9efda14ef407488a22143cb3b31
                                              • Opcode Fuzzy Hash: 9736d98ff4c00b43741f239e002f48ba729bdd9c0db5a1f9682fb9dc510a38ab
                                              • Instruction Fuzzy Hash: 41B09222E07A06C6EA482B516C86B1823A47F88720F994178C20C81320EF2E20A9971A
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: ff8ff783da37649173626c7f7158936b22345755ff077d27462f74136c1878ba
                                              • Instruction ID: b51522c8191b9d47f0b3e8f108ed8025879a33973fff8ea65a5c19a0ba8e3ffa
                                              • Opcode Fuzzy Hash: ff8ff783da37649173626c7f7158936b22345755ff077d27462f74136c1878ba
                                              • Instruction Fuzzy Hash: 73C12573B2869587EB16CF12D9846A9BB62F7D8BD0B55C134DE4A47B98CE3CD802C704
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 4ec180874deb86fd7714d37a9704177cb1ddf6bae5bd7525a532394d6be90ec0
                                              • Instruction ID: fa64da84deb5e9d002de8df61b7b77e48a18f475a959888d303a9b1891e4dd40
                                              • Opcode Fuzzy Hash: 4ec180874deb86fd7714d37a9704177cb1ddf6bae5bd7525a532394d6be90ec0
                                              • Instruction Fuzzy Hash: 4812D433919BC98AD7618F29E84139AB7A4F78D788F505325EACC57B19EF38D250CB04
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 34fb1097c6f2363caac24c1e5b45ae24c1a6ca50cb597d280e611698873f3a91
                                              • Instruction ID: 605526383a6b88ae65967e97439eee0468e569ecba62453400a53e69ed1a4d99
                                              • Opcode Fuzzy Hash: 34fb1097c6f2363caac24c1e5b45ae24c1a6ca50cb597d280e611698873f3a91
                                              • Instruction Fuzzy Hash: B1C1D3B3A146948BE355CF2DD40195D7BA0F398B84F40A629EB56C3B01E778E9A5CF80
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 9192222adae4e2f0070c299c0844eec1f899de7045819fce69bb7a8004539528
                                              • Instruction ID: 4f8c0764004646b65f7417029c2872cfe75bc475bac1a95f24f1b0d51169346a
                                              • Opcode Fuzzy Hash: 9192222adae4e2f0070c299c0844eec1f899de7045819fce69bb7a8004539528
                                              • Instruction Fuzzy Hash: 67915923B1828746EA344E3AA0127FD1690AF487A4F040639DE5ECB7E5DD3EF5059B0A
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: f0c2dc1868310f7be340402d514fcc5ddbcaaf30b09b4b1a75e66e521b583746
                                              • Instruction ID: 03d870374ec5ebe0bcccccfadc526436bdad545f679ced8ab3c14868497a5106
                                              • Opcode Fuzzy Hash: f0c2dc1868310f7be340402d514fcc5ddbcaaf30b09b4b1a75e66e521b583746
                                              • Instruction Fuzzy Hash: 79C1F033A0864A96EB28CF65C4403BD37A0EB49B68F144235CE1D977E5DF3AE845C34A
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: ErrorLast$Value_invalid_parameter_noinfo
                                              • String ID:
                                              • API String ID: 1500699246-0
                                              • Opcode ID: 468b93f19c7ca54f8d79ce9aecab092ca155e8bca1880fa3cbddf3014db9fedd
                                              • Instruction ID: e2e8cf9b057547aa7886dc01ab78fe97f7c54a8c13275060d7cb75be92f65d88
                                              • Opcode Fuzzy Hash: 468b93f19c7ca54f8d79ce9aecab092ca155e8bca1880fa3cbddf3014db9fedd
                                              • Instruction Fuzzy Hash: B6B1F633A18646C2EB659F21D4117F933A0FB88B88F244231DA49C36E9DF7EE541C74A
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo
                                              • String ID:
                                              • API String ID: 3215553584-0
                                              • Opcode ID: 6b2222bd4161aa0df81311004b32476a3e68bf497272c3efca11fb2e46f97a06
                                              • Instruction ID: cfb08e23b1a2f46626ce8d028227d4460cc110db1dd654c6b8a61bbc27f75223
                                              • Opcode Fuzzy Hash: 6b2222bd4161aa0df81311004b32476a3e68bf497272c3efca11fb2e46f97a06
                                              • Instruction Fuzzy Hash: E881D133A04A5186EB61DE25D4813BD2360FB88BA8F144636EF1ED7BA4CF3AD151C349
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 8096616a82d0af589e55529d9e21aaaddb0a4067eb04550f42ec58ec897b5e0e
                                              • Instruction ID: 908555259f6f59ec163113d9edc8f8f4937ac7afc07db916b0c00c3939a76e7d
                                              • Opcode Fuzzy Hash: 8096616a82d0af589e55529d9e21aaaddb0a4067eb04550f42ec58ec897b5e0e
                                              • Instruction Fuzzy Hash: AC61F623B18BC982DE14CB19E0402E9A361E75D7D4F549231DB9D87BA8EF7DE190C744
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo
                                              • String ID:
                                              • API String ID: 3215553584-0
                                              • Opcode ID: 6b3816cb3a988972d41337c60df476b316031ac7a58811eca424fd60ba025d64
                                              • Instruction ID: 6ac220829cee5e3dc46e15ac437632801659c818a1de37d558bf6884364eecfc
                                              • Opcode Fuzzy Hash: 6b3816cb3a988972d41337c60df476b316031ac7a58811eca424fd60ba025d64
                                              • Instruction Fuzzy Hash: 2B61E423E1824246F7658A2C845077DA680BF4077CF144239EABEC76D5DF2FEA48C70A
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 35b24077aedd3f9e8a449d09c4eafcb8d5ede4dcad30c6275166c395dfd1882a
                                              • Instruction ID: 3e2ee553ccc26651c5d6aa930ab6f4bfd09c411c85c637b61ff4c93870bff125
                                              • Opcode Fuzzy Hash: 35b24077aedd3f9e8a449d09c4eafcb8d5ede4dcad30c6275166c395dfd1882a
                                              • Instruction Fuzzy Hash: 0361E12321E2C48FD30DDF7C589106D7F61D3A7908388469DEAC5EB74BC504C91ACBA6
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 45278502b4de115ed76afef2690a2838d0b28876f14c66dd069eb4612fa83dd3
                                              • Instruction ID: 4e1fce9abf10485501c62346c190b28ffc6a6be26e18f3b3ed707e483a8cde7d
                                              • Opcode Fuzzy Hash: 45278502b4de115ed76afef2690a2838d0b28876f14c66dd069eb4612fa83dd3
                                              • Instruction Fuzzy Hash: 3451A277A2865586EB248B28C1403BC37A1EB4CB69F244131CE4E977B5CF3BE852C785
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: ErrorFreeHeapLast
                                              • String ID:
                                              • API String ID: 485612231-0
                                              • Opcode ID: d05f01d9c7e6d1227e296b3139dc3c4d5665c446069bb1063acdd8e7d0dd9ca1
                                              • Instruction ID: 3ef392957dc665b3a360a43174b9e5acdd410ae58c0f0190b091b8f35a37dfdf
                                              • Opcode Fuzzy Hash: d05f01d9c7e6d1227e296b3139dc3c4d5665c446069bb1063acdd8e7d0dd9ca1
                                              • Instruction Fuzzy Hash: 9141EF63714A5582EF04CF2AE9546A963A1BB48FD4F19A032EE0D97B68DE3ED142C305
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: No closed word$key declared, but no value$key opened, but never closed$object is not closed with '}'$quote was opened but not closed.$unexpected '}'$unexpected key without object$word wasnt properly ended
                                              • API String ID: 0-2700065129
                                              • Opcode ID: 2f769f3a61af26de02fdc7094952ae9039798cd0f5a8ea2391996b067ad7b2a7
                                              • Instruction ID: 2d63fb5403f8420f186bc80c8352c28dd4db35675307d56358985d68ec276ceb
                                              • Opcode Fuzzy Hash: 2f769f3a61af26de02fdc7094952ae9039798cd0f5a8ea2391996b067ad7b2a7
                                              • Instruction Fuzzy Hash: 61B11F73919BC694EB60EF20DC517E83364FB54348F805532D64C8B9AAEF6AD399C309
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: CloseHandle$Process32Token$InformationNextOpenProcess$ConvertCreateErrorFirstLastSnapshotStringToolhelp32
                                              • String ID:
                                              • API String ID: 3925315391-0
                                              • Opcode ID: b7cdb7a7c6588e50aaab37c0fa57b8db1cd1071ffc72c1321cf755afb8342ce3
                                              • Instruction ID: 4be7bf851d1f5b60bf14864702492317e0fa8aab29fedb6c0123b59338d6ad2a
                                              • Opcode Fuzzy Hash: b7cdb7a7c6588e50aaab37c0fa57b8db1cd1071ffc72c1321cf755afb8342ce3
                                              • Instruction Fuzzy Hash: DD817133A18B4182EB54DB16E8507BAA3A4FB88B94F404035DE4D87B79EF7ED445CB09
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID: ; expected $; last read: '$syntax error $unexpected $while parsing
                                              • API String ID: 3668304517-4239264347
                                              • Opcode ID: e61819bdb5c2b5145de86d6a00541d87f1f8e50f84490c57d63a8f3144ea801d
                                              • Instruction ID: d5a02360a2f20b2d9e92d67bed2cc4c214c3fc1a51cf2df78c790130fea18409
                                              • Opcode Fuzzy Hash: e61819bdb5c2b5145de86d6a00541d87f1f8e50f84490c57d63a8f3144ea801d
                                              • Instruction Fuzzy Hash: 9AF1A363F14A8189FB00DFE4D5403EC2B72AB087A8F504235DE1D9BAEADF799485D345
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$__std_exception_destroy$ApisFile__std_fs_code_page
                                              • String ID: ", "$: "
                                              • API String ID: 1991941009-747220369
                                              • Opcode ID: c4991a261102bd4fcc0315cd5d52d9dfb8c9e4714ac4c9995ffdcacead30aef8
                                              • Instruction ID: acb39da4205eaf9ec83b77512f675128a0986af526545e3a17a4d6f126c3d6d0
                                              • Opcode Fuzzy Hash: c4991a261102bd4fcc0315cd5d52d9dfb8c9e4714ac4c9995ffdcacead30aef8
                                              • Instruction Fuzzy Hash: 8CB1E0B3B14A4185EB00EF64E0503FC2362EB48B88F504531DE5D97BAADF7AD595C389
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task$std::_$Locinfo::_Locinfo_ctorLockitLockit::_
                                              • String ID: bad locale name$false$true
                                              • API String ID: 164343898-1062449267
                                              • Opcode ID: 752f03881db0d34c5be6f162abf39008bebade7dbabb6014c0db619d265bd8c1
                                              • Instruction ID: 408b174eb00c006b6c039e2160bb5faa5d4f600b973688413a896182ed8bc601
                                              • Opcode Fuzzy Hash: 752f03881db0d34c5be6f162abf39008bebade7dbabb6014c0db619d265bd8c1
                                              • Instruction Fuzzy Hash: 4B715A23B0AB418AEB41DF64E4503FC33A5EF88718F144135DA4DA7AAADF3A9451C34A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Session$ListProcess$CurrentRegisterResourcesStart
                                              • String ID:
                                              • API String ID: 3299295986-0
                                              • Opcode ID: 4ddc3a5b4f8c6342cd3dcf0c0e78daa6693b2bbe667ef408570da53bc05ca548
                                              • Instruction ID: 265cf4de7ae2af98c8d2296e2fc67beb14cc5ec4657c0f448f8ba67823bbd3e2
                                              • Opcode Fuzzy Hash: 4ddc3a5b4f8c6342cd3dcf0c0e78daa6693b2bbe667ef408570da53bc05ca548
                                              • Instruction Fuzzy Hash: 86510C33B18A528AF714CFA5E4507ED33A1BB48758F504139DA0EA7B94DF3A9805CB49
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturnstd::_$GetcollLocinfo::_Locinfo_ctorLockitLockit::_
                                              • String ID: bad locale name
                                              • API String ID: 2486341784-1405518554
                                              • Opcode ID: bff3b163910ba8b525fbd19bc746e20794f2b3bdbc9240d59d620adf475c1be6
                                              • Instruction ID: fb3678cdcfa3d85524933863de2504e7f460437a25b325ef5958162dfe8afaf0
                                              • Opcode Fuzzy Hash: bff3b163910ba8b525fbd19bc746e20794f2b3bdbc9240d59d620adf475c1be6
                                              • Instruction Fuzzy Hash: BB91AD33B09A818AEB149FA5E4503EC3361EF48788F048535DA4D97AA9DF3ED451C34A
                                              APIs
                                              • FreeLibrary.KERNEL32(?,00000000,00007FF6EBFEE206,?,?,00000030,00007FF6EBFF5408,?,?,?,?,?,?,?,?), ref: 00007FF6EBFEDCD8
                                              • GetProcAddress.KERNEL32(?,00000000,00007FF6EBFEE206,?,?,00000030,00007FF6EBFF5408,?,?,?,?,?,?,?,?), ref: 00007FF6EBFEDCE4
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: AddressFreeLibraryProc
                                              • String ID: api-ms-$ext-ms-
                                              • API String ID: 3013587201-537541572
                                              • Opcode ID: ca7c09baf792878f96d911292d21648074434898d998409f668d6f16be7d0add
                                              • Instruction ID: ae3be86564a5cc71947d6979b6788a6f3758784d52349f8ef852e64c02a8f56f
                                              • Opcode Fuzzy Hash: ca7c09baf792878f96d911292d21648074434898d998409f668d6f16be7d0add
                                              • Instruction Fuzzy Hash: 7441F527B19A1281EA198B1A98107BA2395BF48BE0F445635DD0DD7BA4EF3EE405C30A
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$__std_exception_copy
                                              • String ID: out_of_range
                                              • API String ID: 1944019136-3053435996
                                              • Opcode ID: 7282e88c707efd82a2a4641735d606e4b68e22d667b574cd1ede7d770373114b
                                              • Instruction ID: ac566be3fa062e3c03d07464428f1622882b9f9d36bd3f511dc94b953a30c799
                                              • Opcode Fuzzy Hash: 7282e88c707efd82a2a4641735d606e4b68e22d667b574cd1ede7d770373114b
                                              • Instruction Fuzzy Hash: 60718173F18B8288FB00DF74E4513EC2361AB597A8F105331EA5C57AE9DE3A9185C349
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$__std_exception_copy
                                              • String ID: out_of_range
                                              • API String ID: 1944019136-3053435996
                                              • Opcode ID: 52929eb672d255f4dc8f3a29923393050b952fc81a1d2ccb85de26b65a84be6a
                                              • Instruction ID: c82311104f2cace1fffa90bba26c6d91a1757a70b1883c730b0a0acf356123d9
                                              • Opcode Fuzzy Hash: 52929eb672d255f4dc8f3a29923393050b952fc81a1d2ccb85de26b65a84be6a
                                              • Instruction Fuzzy Hash: CA719073F18B8288FB00DF64D4503EC2361AB597A8F009331EA5C57AE9DE3A9185C349
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$__std_exception_copy
                                              • String ID: type_error
                                              • API String ID: 1944019136-1406221190
                                              • Opcode ID: 27d4ea6155a7175561f26f74a55a22754afd6e3558035c21fb0bce210540d754
                                              • Instruction ID: c0372ea28fb9a94870c10523a6a67899fb11c3e0562f9b4102802ec87d1647e9
                                              • Opcode Fuzzy Hash: 27d4ea6155a7175561f26f74a55a22754afd6e3558035c21fb0bce210540d754
                                              • Instruction Fuzzy Hash: 6271A263F19B8288FB00DFB5D4513EC2361AB49798F105231DE6C57AE9EF39A185C349
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$__std_exception_copy
                                              • String ID: invalid_iterator
                                              • API String ID: 1944019136-2508626007
                                              • Opcode ID: 399a224074fd632ffd11ec39e9541ffd9d18d7573fa0b2a288f4ab9197235c05
                                              • Instruction ID: 4eb4981c8ed153fbc402e2f9bf75850a950ca3209c3c72cd0442b9344c5e23e2
                                              • Opcode Fuzzy Hash: 399a224074fd632ffd11ec39e9541ffd9d18d7573fa0b2a288f4ab9197235c05
                                              • Instruction Fuzzy Hash: F5718363F19B8288FB00DF75D4503EC2361AB49798F105731DE6C57AE9EE3AA185C349
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: __std_exception_destroy_invalid_parameter_noinfo_noreturn
                                              • String ID: at line $, column
                                              • API String ID: 729085983-191570568
                                              • Opcode ID: 5eb50482a23a13387e4ba2c98b03166af1b9dba654dc704b1591e29ab17620d3
                                              • Instruction ID: c3a15f27178c07116427f0a814e803c335adc5ecc6afa29e7fe8b18789584447
                                              • Opcode Fuzzy Hash: 5eb50482a23a13387e4ba2c98b03166af1b9dba654dc704b1591e29ab17620d3
                                              • Instruction Fuzzy Hash: 1951D473A18B8141EA109F19E5403AE6761FB89BD0F104231EBAC47BE6DF7EE581C349
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Value$ErrorLast
                                              • String ID:
                                              • API String ID: 2506987500-0
                                              • Opcode ID: 393d71075e39267f9418b9d8d6d74273635a9a8691926b1b96f338eff6d5f6ad
                                              • Instruction ID: 1ad23d8de4308668194774058973c488ff2f2628b362fea2e111b27ee7d5b2eb
                                              • Opcode Fuzzy Hash: 393d71075e39267f9418b9d8d6d74273635a9a8691926b1b96f338eff6d5f6ad
                                              • Instruction Fuzzy Hash: 9A217F37A0D28242FA58A76165513BD52824F4CBB0F049734E93E9FAE6DE3FF441821A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: ByteCharMultiStringWide
                                              • String ID:
                                              • API String ID: 2829165498-0
                                              • Opcode ID: 7d9f455a94f84a05f587d57d339c879795f99f0f1217d4298ff39db3fa6ba98e
                                              • Instruction ID: addabf8c622173316a884108925a3a235dac9e98adf83dfc81bea69015fd64eb
                                              • Opcode Fuzzy Hash: 7d9f455a94f84a05f587d57d339c879795f99f0f1217d4298ff39db3fa6ba98e
                                              • Instruction Fuzzy Hash: 4E81A173A0878186EB208F25A8413B972A5FF84BA8F154635EA5D87BD9EF3ED400C715
                                              APIs
                                              • GetLastError.KERNEL32(?,?,-2723E8D8DEBC5093,00007FF6EBFE4E71,?,?,?,?,00007FF6EBFED3FC), ref: 00007FF6EBFEA073
                                              • FlsSetValue.KERNEL32(?,?,-2723E8D8DEBC5093,00007FF6EBFE4E71,?,?,?,?,00007FF6EBFED3FC), ref: 00007FF6EBFEA0A9
                                              • FlsSetValue.KERNEL32(?,?,-2723E8D8DEBC5093,00007FF6EBFE4E71,?,?,?,?,00007FF6EBFED3FC), ref: 00007FF6EBFEA0D6
                                              • FlsSetValue.KERNEL32(?,?,-2723E8D8DEBC5093,00007FF6EBFE4E71,?,?,?,?,00007FF6EBFED3FC), ref: 00007FF6EBFEA0E7
                                              • FlsSetValue.KERNEL32(?,?,-2723E8D8DEBC5093,00007FF6EBFE4E71,?,?,?,?,00007FF6EBFED3FC), ref: 00007FF6EBFEA0F8
                                              • SetLastError.KERNEL32(?,?,-2723E8D8DEBC5093,00007FF6EBFE4E71,?,?,?,?,00007FF6EBFED3FC), ref: 00007FF6EBFEA113
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Value$ErrorLast
                                              • String ID:
                                              • API String ID: 2506987500-0
                                              • Opcode ID: 9171995ea5c336ae991c260a04bbd1332f14451c84c9f4660891b61a794840d0
                                              • Instruction ID: 3e2faa07945249d4def6a0332378c7098c89cef8031562ebd7eff1176023feff
                                              • Opcode Fuzzy Hash: 9171995ea5c336ae991c260a04bbd1332f14451c84c9f4660891b61a794840d0
                                              • Instruction Fuzzy Hash: 84119027B0D28642FA14A7255A513BD62825F4C7B0F045334E93EDBBE6DE2FF840864B
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Open
                                              • String ID: ?
                                              • API String ID: 71445658-1684325040
                                              • Opcode ID: 208e14def8f7a52b27832f13a9a4675c2dd0128cefc550b82194dbe05051c383
                                              • Instruction ID: da64a70fd88036dd427540b59cd0695132b3310e89eff57617fe22d4578c58b9
                                              • Opcode Fuzzy Hash: 208e14def8f7a52b27832f13a9a4675c2dd0128cefc550b82194dbe05051c383
                                              • Instruction Fuzzy Hash: 6841B433A18B8181EA508B25F48436EA360FB89794F104235FB9D87BA9DF3DD084CB49
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: AddressFreeHandleLibraryModuleProc
                                              • String ID: CorExitProcess$mscoree.dll
                                              • API String ID: 4061214504-1276376045
                                              • Opcode ID: 780b3f1f3aecbe1eb4b75bb10cd40d76e1f940e32b271abccdf7c11bca0f4dbd
                                              • Instruction ID: 8419150b92a5329f5bc47a486672a97b9dd3bf4be7579ae40956478dc77be4e5
                                              • Opcode Fuzzy Hash: 780b3f1f3aecbe1eb4b75bb10cd40d76e1f940e32b271abccdf7c11bca0f4dbd
                                              • Instruction Fuzzy Hash: 4EF06223A1970681EB188B64E46437A5320BF88BA5F940235D96DC72F5EF3FD045C74A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$Window$DesktopRect
                                              • String ID:
                                              • API String ID: 1991322523-0
                                              • Opcode ID: 0c09b0636b7a4a74a671a8d5e0a4a232b23c6647649f34c84a78b3815982ffaa
                                              • Instruction ID: 7e47e0ea006d19438a44e37ce186c3c4e53944b852f2e55a84e9cd9bc03e5a83
                                              • Opcode Fuzzy Hash: 0c09b0636b7a4a74a671a8d5e0a4a232b23c6647649f34c84a78b3815982ffaa
                                              • Instruction Fuzzy Hash: 5D419963E1878545EA109B14F4513BEA351EBC97A4F104331E6AC87BEADF2ED080CB49
                                              APIs
                                              • FlsGetValue.KERNEL32(?,?,?,00007FF6EBFE7EF7,?,?,00000000,00007FF6EBFE8192,?,?,?,?,-2723E8D8DEBC5093,00007FF6EBFE811E), ref: 00007FF6EBFEA14B
                                              • FlsSetValue.KERNEL32(?,?,?,00007FF6EBFE7EF7,?,?,00000000,00007FF6EBFE8192,?,?,?,?,-2723E8D8DEBC5093,00007FF6EBFE811E), ref: 00007FF6EBFEA16A
                                              • FlsSetValue.KERNEL32(?,?,?,00007FF6EBFE7EF7,?,?,00000000,00007FF6EBFE8192,?,?,?,?,-2723E8D8DEBC5093,00007FF6EBFE811E), ref: 00007FF6EBFEA192
                                              • FlsSetValue.KERNEL32(?,?,?,00007FF6EBFE7EF7,?,?,00000000,00007FF6EBFE8192,?,?,?,?,-2723E8D8DEBC5093,00007FF6EBFE811E), ref: 00007FF6EBFEA1A3
                                              • FlsSetValue.KERNEL32(?,?,?,00007FF6EBFE7EF7,?,?,00000000,00007FF6EBFE8192,?,?,?,?,-2723E8D8DEBC5093,00007FF6EBFE811E), ref: 00007FF6EBFEA1B4
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Value
                                              • String ID:
                                              • API String ID: 3702945584-0
                                              • Opcode ID: 899af4340b37942fc89d2eda1bd92b937099c6712e87118af2802e5ac3ca3c8d
                                              • Instruction ID: 6f1255d788b1d70bca81365cc8f0e7d3d5380f06152d198ec9dc7d860c375d36
                                              • Opcode Fuzzy Hash: 899af4340b37942fc89d2eda1bd92b937099c6712e87118af2802e5ac3ca3c8d
                                              • Instruction Fuzzy Hash: 97117F27F0D28A41FA58932169517BD11414F487B0F045334E93EDBAF6DE2EF901864B
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: Value
                                              • String ID:
                                              • API String ID: 3702945584-0
                                              • Opcode ID: 27a8d680a01718b2f16bf98748d9030277dcffc577ce5399e3a087c28c18192a
                                              • Instruction ID: cf0ad2a421bffc96322263e2995ab255984e23f940f8fbcdce0febc6585468c4
                                              • Opcode Fuzzy Hash: 27a8d680a01718b2f16bf98748d9030277dcffc577ce5399e3a087c28c18192a
                                              • Instruction Fuzzy Hash: E2115727A0D24742F968A22518517FD11824F48770F08A734EA3EDF6F2DE2FB900825B
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
                                              • API String ID: 0-1866435925
                                              • Opcode ID: 58c131a224e6ab11856af939a775decd2d344bb436384685c14c7c404b401b05
                                              • Instruction ID: c5d24c30f283ea5840ea498929f2f00a8ed0c7c57d0728e0fb418f1a1be2d45c
                                              • Opcode Fuzzy Hash: 58c131a224e6ab11856af939a775decd2d344bb436384685c14c7c404b401b05
                                              • Instruction Fuzzy Hash: 4891AE73A08B8682EB64CB11E4503ADB7A5FB48BD4F554032EA5D87BA8DF3ED481C345
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo
                                              • String ID: UTF-16LEUNICODE$UTF-8$ccs
                                              • API String ID: 3215553584-1196891531
                                              • Opcode ID: a61b9dafeebeef71c778538e02d1dd93d241f4be75a88b4b5df5efb2b9ec5def
                                              • Instruction ID: b59bc83e19a2357f2cf480402ac309777a5d35ffe6ff53ed5044708bc0df99d1
                                              • Opcode Fuzzy Hash: a61b9dafeebeef71c778538e02d1dd93d241f4be75a88b4b5df5efb2b9ec5def
                                              • Instruction Fuzzy Hash: 9581C377D0C60286F7A58E25C11237A36A0AB11B58F578835CB09D7295EF3FE842E30B
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: [json.exception.
                                              • API String ID: 0-791563284
                                              • Opcode ID: 6a4279c4ab6d3c4d22781d422e23e4c9bae50b78e4f0ddac313b26c6f69d5c85
                                              • Instruction ID: b2e8032a43dbe91bde7899245f934703b7014617842b63c776455ff365ba0852
                                              • Opcode Fuzzy Hash: 6a4279c4ab6d3c4d22781d422e23e4c9bae50b78e4f0ddac313b26c6f69d5c85
                                              • Instruction Fuzzy Hash: BB71ED73F24A9185F700CF69E8503EC27A1EB99B98F104236DE5D57AAACF7AD081C345
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: std::_$GetctypeLocinfo::_Locinfo_ctorLockitLockit::_
                                              • String ID: bad locale name
                                              • API String ID: 1612978173-1405518554
                                              • Opcode ID: cb25b9fab8f2b540b2e1f80e552673d1662e08701ae7d8b7d6e9bc1a0f0fedaa
                                              • Instruction ID: a7f1c320a9a82659b88d57b1cec89074ed84aa9026829ead43ce996782314075
                                              • Opcode Fuzzy Hash: cb25b9fab8f2b540b2e1f80e552673d1662e08701ae7d8b7d6e9bc1a0f0fedaa
                                              • Instruction Fuzzy Hash: 56514833B09A418AEB10DFA4E4503ED3364AF48748F044435DA4DA7AA5DF3A9565C34A
                                              APIs
                                              • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF6EBFD0D1F
                                              • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF6EBFD0D25
                                                • Part of subcall function 00007FF6EC000E88: RtlPcToFileHeader.KERNEL32(?,?,?,?,?,?,?,?,-2723E8D8DEBC5094,00007FF6EC00C3D2), ref: 00007FF6EC000ED8
                                                • Part of subcall function 00007FF6EC000E88: RaiseException.KERNEL32(?,?,?,?,?,?,?,?,-2723E8D8DEBC5094,00007FF6EC00C3D2), ref: 00007FF6EC000F19
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$ExceptionFileHeaderRaise
                                              • String ID: exists$ios_base::badbit set
                                              • API String ID: 240014264-2074760687
                                              • Opcode ID: a5a59e918b60e0c8ffbbc047f386daa408d0b82dfff3e722bcb7dc2d295da79a
                                              • Instruction ID: 22418524d89a484953b6fb87859e9628149f75d1e901e64607741d5fd35702c8
                                              • Opcode Fuzzy Hash: a5a59e918b60e0c8ffbbc047f386daa408d0b82dfff3e722bcb7dc2d295da79a
                                              • Instruction Fuzzy Hash: 7C417173A19BC694EA20DF14E4943EE7361FB88754F804132CA8C83AA9EF7ED145CB45
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$FreeString
                                              • String ID:
                                              • API String ID: 1965679434-0
                                              • Opcode ID: ac0ba30e2cecf2f5c947f9ac700c2fa436c4031c6f388644c168f7db9c4a35da
                                              • Instruction ID: fd6b50ec48a3069705064fcc58320a88e0de7d05e2d9684956288881ff0b1a70
                                              • Opcode Fuzzy Hash: ac0ba30e2cecf2f5c947f9ac700c2fa436c4031c6f388644c168f7db9c4a35da
                                              • Instruction Fuzzy Hash: 10E1AF63F18A818AFB00DFA5D4503EC2372AB49798F404635DE1DABBAADF39D144C349
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: FileWrite$ConsoleErrorLastOutput
                                              • String ID:
                                              • API String ID: 2718003287-0
                                              • Opcode ID: 51ca5d62aa19301a18794717acfbf1a46562df65ce568f5fb7798e040ec77a5b
                                              • Instruction ID: 995f07392248fd56ceee5b3354f6bcfb796a184304805c330a41a519e43e2e9b
                                              • Opcode Fuzzy Hash: 51ca5d62aa19301a18794717acfbf1a46562df65ce568f5fb7798e040ec77a5b
                                              • Instruction Fuzzy Hash: 56D1EE33B18A8189E711CF65D4406FC3BB1FB58BA8B004236DE9D97BA9DE39E406C345
                                              APIs
                                              • GetConsoleMode.KERNEL32(?,?,?,?,?,?,00000000,?,00000000,?,00000000,00000000,00000000,?,00007FF6EBFECF23), ref: 00007FF6EBFED054
                                              • GetLastError.KERNEL32(?,?,?,?,?,?,00000000,?,00000000,?,00000000,00000000,00000000,?,00007FF6EBFECF23), ref: 00007FF6EBFED0DF
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: ConsoleErrorLastMode
                                              • String ID:
                                              • API String ID: 953036326-0
                                              • Opcode ID: 3f62383259c36c84ae499e9679ffdb2c1832cde853ef017496f7ee74174e2e70
                                              • Instruction ID: 94fad34a8aad4b8ea1a749484bd9510d33d331494b0c80102045f3e9d2b8608e
                                              • Opcode Fuzzy Hash: 3f62383259c36c84ae499e9679ffdb2c1832cde853ef017496f7ee74174e2e70
                                              • Instruction Fuzzy Hash: 9F91FA37F1865185F7509F6594403FD2BA0BB49BA8F145239EE0EA7AA4CF3EE442C306
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task
                                              • String ID:
                                              • API String ID: 3936042273-0
                                              • Opcode ID: 37b5a384d894ce52b23881f2ba836fa197112d377954dcc88dc1db7d4ed38b02
                                              • Instruction ID: 6343bf9c18249cda4acb5e5c741d6c055c05289c25df660cdaaa327031232346
                                              • Opcode Fuzzy Hash: 37b5a384d894ce52b23881f2ba836fa197112d377954dcc88dc1db7d4ed38b02
                                              • Instruction Fuzzy Hash: 9441E363B0668581FD189FA5D1043BC6291DF4CBF0F544631CE7D877E5DE6EA4928309
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: std::_$LockitLockit::_$Concurrency::cancel_current_taskFacet_RegisterSetgloballocalestd::locale::_
                                              • String ID:
                                              • API String ID: 3698853521-0
                                              • Opcode ID: 4fc220db6eaac0443d91f4384fb0f2b142d491479135c28509da1aa1f4e14997
                                              • Instruction ID: a2af49add391f418d11bf4257a356a0c485a4aa95efdf1272d63692e87b95f6c
                                              • Opcode Fuzzy Hash: 4fc220db6eaac0443d91f4384fb0f2b142d491479135c28509da1aa1f4e14997
                                              • Instruction Fuzzy Hash: BC41CF33A18B4181EA54DF55E4417B933A0FB88B84F154532EA9D837A9DF3FE446C70A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo
                                              • String ID:
                                              • API String ID: 3215553584-0
                                              • Opcode ID: f1f9df1a05da3301ed415653e8360f7cb12179a044a2575d07df28b1a0800ec9
                                              • Instruction ID: 236fc849b4a1250aef88aff402d141c718ff72bf64e4576c5c2cdbf1f0da7b8a
                                              • Opcode Fuzzy Hash: f1f9df1a05da3301ed415653e8360f7cb12179a044a2575d07df28b1a0800ec9
                                              • Instruction Fuzzy Hash: 94416023909A8685EB529F34C4213FD3BA0EB49F94F49C071CA8C973A5DE3E9445C75A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: std::_$LockitLockit::_$Concurrency::cancel_current_taskFacet_Register
                                              • String ID:
                                              • API String ID: 1168246061-0
                                              • Opcode ID: acbc9ea0ed55ab8395d29e3490695ccec0bb7a6dea11a1816461c93234175631
                                              • Instruction ID: 4ee454ba60e73f45092a96d405b515cada7d97436c93f827a5ea31a2adc78ff4
                                              • Opcode Fuzzy Hash: acbc9ea0ed55ab8395d29e3490695ccec0bb7a6dea11a1816461c93234175631
                                              • Instruction Fuzzy Hash: 0A41BF23A18A4280EE25DF15E4403BD6760FB98B98F590531EA8D877B5DF3FE581C70A
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: std::_$LockitLockit::_$Concurrency::cancel_current_taskFacet_Register
                                              • String ID:
                                              • API String ID: 1168246061-0
                                              • Opcode ID: 73d040060e39de7473f733929aeeb815445ca65359d0c265211a911782271014
                                              • Instruction ID: a9b46842e3a062b91426131db5d5820e10fc6b25db45cd828bdb44487ef6b3d3
                                              • Opcode Fuzzy Hash: 73d040060e39de7473f733929aeeb815445ca65359d0c265211a911782271014
                                              • Instruction Fuzzy Hash: 8141C623A18A4181EB15DF15E4413B96760FF48B94F194531EA4D8B7B9DF3FE481CB0A
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: std::_$Locinfo::_Locinfo_ctorLockitLockit::_
                                              • String ID: bad locale name
                                              • API String ID: 3988782225-1405518554
                                              • Opcode ID: cd45b69d38e937e2b2c105ad083e3fa59ee127999d26fb8e2da05732c8aec6bf
                                              • Instruction ID: a59f175837aef3b29f2a2e2b9c7193b2d4245f8c2c4f272e4ed9dc3c6d7e58e6
                                              • Opcode Fuzzy Hash: cd45b69d38e937e2b2c105ad083e3fa59ee127999d26fb8e2da05732c8aec6bf
                                              • Instruction Fuzzy Hash: 77517A33B09A4189EB55DF70E4903FC2364EF88748F040435EA4DABAA6DF3AD452C34A
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: std::_$Locinfo::_Locinfo_ctorLockitLockit::_
                                              • String ID: bad locale name
                                              • API String ID: 3988782225-1405518554
                                              • Opcode ID: fc0e6e2b9b421333c13244ee569d98d54f4ff8361596dcdfacd00c0aeb48e991
                                              • Instruction ID: cc56fee29d448455648aa74de3670de840a6f011d5306c69933c8fe9cb7c3fc6
                                              • Opcode Fuzzy Hash: fc0e6e2b9b421333c13244ee569d98d54f4ff8361596dcdfacd00c0aeb48e991
                                              • Instruction Fuzzy Hash: A1514933A0AA4189EB54DFA0E4913FC33A4EF48748F044435EE4DA7AA5DF3AD515C38A
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: _get_daylight$_invalid_parameter_noinfo
                                              • String ID: ?
                                              • API String ID: 1286766494-1684325040
                                              • Opcode ID: 9cb3a800b4e5433171cdfee83524aba1d0ffe5a917aa16eb1e5a6d3dafcd7e64
                                              • Instruction ID: 70451986c44d33e5e69b0e0f686c4c05e8be218fad19d9264120141add040145
                                              • Opcode Fuzzy Hash: 9cb3a800b4e5433171cdfee83524aba1d0ffe5a917aa16eb1e5a6d3dafcd7e64
                                              • Instruction Fuzzy Hash: D441E823A0878245FB649B25E8113BE6651EB88BA4F344235FE6C87AF5DF3ED441C706
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: ErrorFileLastWrite
                                              • String ID: U
                                              • API String ID: 442123175-4171548499
                                              • Opcode ID: 136ebf252562798dd94b0934f5b608a87eddbdd1c89cb1577b5bf7720501d192
                                              • Instruction ID: 746bcd6665c92fe5db3f26b029e36f7d8a6cdc3182dd92a3e51a6c7ceac41cd7
                                              • Opcode Fuzzy Hash: 136ebf252562798dd94b0934f5b608a87eddbdd1c89cb1577b5bf7720501d192
                                              • Instruction Fuzzy Hash: B0419123A19A8182DB208F25E4443FE67A1FB88794F544031EE4DC7794EF7EE441C745
                                              APIs
                                              • RtlPcToFileHeader.KERNEL32(?,?,?,?,?,?,?,?,-2723E8D8DEBC5094,00007FF6EC00C3D2), ref: 00007FF6EC000ED8
                                              • RaiseException.KERNEL32(?,?,?,?,?,?,?,?,-2723E8D8DEBC5094,00007FF6EC00C3D2), ref: 00007FF6EC000F19
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2288962032.00007FF6EBF51000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6EBF50000, based on PE: true
                                              • Associated: 00000000.00000002.2288936587.00007FF6EBF50000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289049035.00007FF6EC025000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289106509.00007FF6EC080000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289138075.00007FF6EC082000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289169667.00007FF6EC085000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2289201118.00007FF6EC088000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff6ebf50000_8F0oMWUhg7.jbxd
                                              Similarity
                                              • API ID: ExceptionFileHeaderRaise
                                              • String ID: csm
                                              • API String ID: 2573137834-1018135373
                                              • Opcode ID: b70c8f01ca01e1ec4819aea0aadbf8579bb2f3e39c9b562f706c3da26c2f4cc1
                                              • Instruction ID: 716416e88447e29c2c5fbe4a2a2845b12a851fef67ff705237b005ee9f0d1a24
                                              • Opcode Fuzzy Hash: b70c8f01ca01e1ec4819aea0aadbf8579bb2f3e39c9b562f706c3da26c2f4cc1
                                              • Instruction Fuzzy Hash: D4115B32608B8182EB608F15F400369B7E5FB88B88F594634DB8D47B95EF3ED651CB04