Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
file.exe

Overview

General Information

Sample name:file.exe
Analysis ID:1558739
MD5:3f97ee2b5aefb68fc0d7c6383b41385d
SHA1:1169a86fb0b2ccb367f9cc886b209e77c6418983
SHA256:3fb4d76805f5d0d3f23f37fea0f19da7a8e11c6e2a6104035511aded0696fc82
Tags:exeuser-Bitsight
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

AI detected suspicious sample
Creates files with lurking names (e.g. Crack.exe)
Machine Learning detection for dropped file
Machine Learning detection for sample
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to communicate with device drivers
Contains functionality to launch a program with higher privileges
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected potential crypto function
Drops PE files
File is packed with WinRar
Found dropped PE file which has not been started or loaded
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • file.exe (PID: 5916 cmdline: "C:\Users\user\Desktop\file.exe" MD5: 3F97EE2B5AEFB68FC0D7C6383B41385D)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Submited SampleIntegrated Neural Analysis Model: Matched 87.0% probability
Source: C:\Users\user\AppData\Local\Temp\crack.exeJoe Sandbox ML: detected
Source: file.exeJoe Sandbox ML: detected
Source: file.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Source: Binary string: D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb source: crack.exe.0.dr
Source: Binary string: D:\Projects\WinRAR\sfx\build\sfxrar64\Release\sfxrar.pdb source: file.exe
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB040BC FindFirstFileW,FindFirstFileW,GetLastError,FindNextFileW,GetLastError,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF76DB040BC
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB1B190 EndDialog,SetDlgItemTextW,GetMessageW,IsDialogMessageW,TranslateMessage,DispatchMessageW,EndDialog,GetDlgItem,SendMessageW,SendMessageW,SetFocus,GetLastError,GetLastError,GetTickCount,GetLastError,GetCommandLineW,CreateFileMappingW,MapViewOfFile,ShellExecuteExW,Sleep,UnmapViewOfFile,CloseHandle,SetDlgItemTextW,SetWindowTextW,SetDlgItemTextW,SetWindowTextW,GetDlgItem,GetWindowLongPtrW,SetWindowLongPtrW,SetDlgItemTextW,SendMessageW,SendDlgItemMessageW,GetDlgItem,SendMessageW,GetDlgItem,SetDlgItemTextW,SetDlgItemTextW,DialogBoxParamW,EndDialog,EnableWindow,SendMessageW,SetDlgItemTextW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,SendDlgItemMessageW,EndDialog,GetDlgItem,SetFocus,SendDlgItemMessageW,FindFirstFileW,FindClose,SendDlgItemMessageW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF76DB1B190
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB2FCA0 FindFirstFileExA,0_2_00007FF76DB2FCA0
Source: IObit.Malware.Fighter.Pro-12.0.0.1433.exe.0.drString found in binary or memory: http://nsis.sf.net/NSIS_ErrorError

System Summary

barindex
Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\crack.exeJump to behavior
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DAFC2F0: CreateFileW,CloseHandle,wcscpy,wcscpy,wcscpy,wcscpy,CreateFileW,DeviceIoControl,CloseHandle,GetLastError,RemoveDirectoryW,DeleteFileW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF76DAFC2F0
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB1CE880_2_00007FF76DB1CE88
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DAF5E240_2_00007FF76DAF5E24
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB11F200_2_00007FF76DB11F20
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DAFF9300_2_00007FF76DAFF930
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB049280_2_00007FF76DB04928
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB207540_2_00007FF76DB20754
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB1B1900_2_00007FF76DB1B190
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB0A4AC0_2_00007FF76DB0A4AC
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB134840_2_00007FF76DB13484
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB18DF40_2_00007FF76DB18DF4
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB207540_2_00007FF76DB20754
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB12D580_2_00007FF76DB12D58
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB320800_2_00007FF76DB32080
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB0AF180_2_00007FF76DB0AF18
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB35AF80_2_00007FF76DB35AF8
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DAF1AA40_2_00007FF76DAF1AA4
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB12AB00_2_00007FF76DB12AB0
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB01A480_2_00007FF76DB01A48
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB2FA940_2_00007FF76DB2FA94
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB289A00_2_00007FF76DB289A0
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB139640_2_00007FF76DB13964
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB0C96C0_2_00007FF76DB0C96C
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB28C1C0_2_00007FF76DB28C1C
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB14B980_2_00007FF76DB14B98
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB0BB900_2_00007FF76DB0BB90
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB05B600_2_00007FF76DB05B60
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DAF76C00_2_00007FF76DAF76C0
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB0B5340_2_00007FF76DB0B534
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB325500_2_00007FF76DB32550
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DAF48400_2_00007FF76DAF4840
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB2C8380_2_00007FF76DB2C838
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DAFA3100_2_00007FF76DAFA310
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DAFC2F00_2_00007FF76DAFC2F0
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DAF72880_2_00007FF76DAF7288
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB0126C0_2_00007FF76DB0126C
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB121D00_2_00007FF76DB121D0
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB0F1800_2_00007FF76DB0F180
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB153F00_2_00007FF76DB153F0
Source: IObit.Malware.Fighter.Pro-12.0.0.1433.exe.0.drStatic PE information: Resource name: RT_VERSION type: ARM COFF executable, no relocation info, not stripped, 52 sections, symbol offset=0x5f0053, 4522070 symbols, optional header size 82, created Sat Mar 7 05:34:56 1970
Source: classification engineClassification label: mal56.evad.winEXE@1/3@0/0
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DAFB6D8 GetLastError,FormatMessageW,LocalFree,0_2_00007FF76DAFB6D8
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB18624 FindResourceExW,SizeofResource,LoadResource,LockResource,GlobalAlloc,GlobalLock,CreateStreamOnHGlobal,GdipAlloc,GdipCreateHBITMAPFromBitmap,GlobalUnlock,GlobalFree,0_2_00007FF76DB18624
Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\__tmp_rar_sfx_access_check_5823640Jump to behavior
Source: file.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\file.exeFile read: C:\Windows\win.iniJump to behavior
Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Users\user\Desktop\file.exeFile read: C:\Users\user\Desktop\file.exeJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: dxgidebug.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: riched20.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: usp10.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: msls31.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: dlnashext.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: wpdshext.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: ndfapi.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: wdi.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: duser.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: xmllite.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeSection loaded: atlthunk.dllJump to behavior
Source: C:\Users\user\Desktop\file.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}\InProcServer32Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: file.exeStatic PE information: Image base 0x140000000 > 0x60000000
Source: file.exeStatic file information: File size 80591650 > 1048576
Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: file.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb source: crack.exe.0.dr
Source: Binary string: D:\Projects\WinRAR\sfx\build\sfxrar64\Release\sfxrar.pdb source: file.exe
Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\__tmp_rar_sfx_access_check_5823640Jump to behavior
Source: file.exeStatic PE information: section name: .didat
Source: file.exeStatic PE information: section name: _RDATA
Source: crack.exe.0.drStatic PE information: section name: .didat
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB35166 push rsi; retf 0_2_00007FF76DB35167
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB35156 push rsi; retf 0_2_00007FF76DB35157
Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\crack.exeJump to dropped file
Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\IObit.Malware.Fighter.Pro-12.0.0.1433.exeJump to dropped file
Source: C:\Users\user\Desktop\file.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\crack.exeJump to dropped file
Source: C:\Users\user\Desktop\file.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\IObit.Malware.Fighter.Pro-12.0.0.1433.exeJump to dropped file
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB040BC FindFirstFileW,FindFirstFileW,GetLastError,FindNextFileW,GetLastError,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF76DB040BC
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB1B190 EndDialog,SetDlgItemTextW,GetMessageW,IsDialogMessageW,TranslateMessage,DispatchMessageW,EndDialog,GetDlgItem,SendMessageW,SendMessageW,SetFocus,GetLastError,GetLastError,GetTickCount,GetLastError,GetCommandLineW,CreateFileMappingW,MapViewOfFile,ShellExecuteExW,Sleep,UnmapViewOfFile,CloseHandle,SetDlgItemTextW,SetWindowTextW,SetDlgItemTextW,SetWindowTextW,GetDlgItem,GetWindowLongPtrW,SetWindowLongPtrW,SetDlgItemTextW,SendMessageW,SendDlgItemMessageW,GetDlgItem,SendMessageW,GetDlgItem,SetDlgItemTextW,SetDlgItemTextW,DialogBoxParamW,EndDialog,EnableWindow,SendMessageW,SetDlgItemTextW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,SendDlgItemMessageW,EndDialog,GetDlgItem,SetFocus,SendDlgItemMessageW,FindFirstFileW,FindClose,SendDlgItemMessageW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF76DB1B190
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB2FCA0 FindFirstFileExA,0_2_00007FF76DB2FCA0
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB216A4 VirtualQuery,GetSystemInfo,0_2_00007FF76DB216A4
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB276D8 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF76DB276D8
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB30D20 GetProcessHeap,0_2_00007FF76DB30D20
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB276D8 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF76DB276D8
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB23170 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF76DB23170
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB22510 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF76DB22510
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB23354 SetUnhandledExceptionFilter,0_2_00007FF76DB23354
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB1B190 EndDialog,SetDlgItemTextW,GetMessageW,IsDialogMessageW,TranslateMessage,DispatchMessageW,EndDialog,GetDlgItem,SendMessageW,SendMessageW,SetFocus,GetLastError,GetLastError,GetTickCount,GetLastError,GetCommandLineW,CreateFileMappingW,MapViewOfFile,ShellExecuteExW,Sleep,UnmapViewOfFile,CloseHandle,SetDlgItemTextW,SetWindowTextW,SetDlgItemTextW,SetWindowTextW,GetDlgItem,GetWindowLongPtrW,SetWindowLongPtrW,SetDlgItemTextW,SendMessageW,SendDlgItemMessageW,GetDlgItem,SendMessageW,GetDlgItem,SetDlgItemTextW,SetDlgItemTextW,DialogBoxParamW,EndDialog,EnableWindow,SendMessageW,SetDlgItemTextW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,SendDlgItemMessageW,EndDialog,GetDlgItem,SetFocus,SendDlgItemMessageW,FindFirstFileW,FindClose,SendDlgItemMessageW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF76DB1B190
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB0DC70 cpuid 0_2_00007FF76DB0DC70
Source: C:\Users\user\Desktop\file.exeCode function: GetLocaleInfoW,GetNumberFormatW,0_2_00007FF76DB1A2CC
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB20754 GetCommandLineW,OpenFileMappingW,MapViewOfFile,UnmapViewOfFile,MapViewOfFile,UnmapViewOfFile,CloseHandle,SetEnvironmentVariableW,GetLocalTime,swprintf,SetEnvironmentVariableW,GetModuleHandleW,LoadIconW,DialogBoxParamW,Sleep,DeleteObject,DeleteObject,CloseHandle,OleUninitialize,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF76DB20754
Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76DB04EB0 GetVersionExW,0_2_00007FF76DB04EB0
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
1
Exploitation for Privilege Escalation
1
Masquerading
OS Credential Dumping1
System Time Discovery
Remote Services1
Archive Collected Data
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Software Packing
LSASS Memory2
Security Software Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
DLL Side-Loading
Security Account Manager2
File and Directory Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Obfuscated Files or Information
NTDS24
System Information Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
file.exe100%Joe Sandbox ML
SourceDetectionScannerLabelLink
C:\Users\user\AppData\Local\Temp\crack.exe100%Joe Sandbox ML
C:\Users\user\AppData\Local\Temp\IObit.Malware.Fighter.Pro-12.0.0.1433.exe3%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://nsis.sf.net/NSIS_ErrorErrorIObit.Malware.Fighter.Pro-12.0.0.1433.exe.0.drfalse
    high
    No contacted IP infos
    Joe Sandbox version:41.0.0 Charoite
    Analysis ID:1558739
    Start date and time:2024-11-19 18:57:13 +01:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:0h 3m 49s
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:default.jbs
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Number of analysed new started processes analysed:2
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • HCA enabled
    • EGA enabled
    • AMSI enabled
    Analysis Mode:default
    Analysis stop reason:Timeout
    Sample name:file.exe
    Detection:MAL
    Classification:mal56.evad.winEXE@1/3@0/0
    EGA Information:
    • Successful, ratio: 100%
    HCA Information:
    • Successful, ratio: 100%
    • Number of executed functions: 70
    • Number of non-executed functions: 93
    Cookbook Comments:
    • Found application associated with file extension: .exe
    • Stop behavior analysis, all processes terminated
    • Exclude process from analysis (whitelisted): dllhost.exe
    • Excluded IPs from analysis (whitelisted): 4.175.87.197
    • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, sls.update.microsoft.com, glb.sls.prod.dcat.dsp.trafficmanager.net
    • Report size getting too big, too many NtOpenKeyEx calls found.
    • Report size getting too big, too many NtProtectVirtualMemory calls found.
    • Report size getting too big, too many NtQueryValueKey calls found.
    • VT rate limit hit for: file.exe
    No simulations
    No context
    No context
    No context
    No context
    No context
    Process:C:\Users\user\Desktop\file.exe
    File Type:ASCII text, with no line terminators
    Category:dropped
    Size (bytes):44
    Entropy (8bit):4.450195892351691
    Encrypted:false
    SSDEEP:3:SAN9XLrBdO:SKPB0
    MD5:E329DD38FDB925C2D653E4A3415E465B
    SHA1:D2A746E823FCD9EAE438DE8D8C10A688315F23D8
    SHA-256:37847DCF7A973752F350E3250237A8967C341ADA351005EFF9A0EE45990B5578
    SHA-512:FAAB380172D8C0B670D6150B6BC4A80DB3FE80000344716E6DA01A7A47A695C9218B5891D13B07EDB4EABC5CF4538BC325ADAF11CBAB4EE02C920FCFFA6E3C7F
    Malicious:false
    Reputation:low
    Preview:IObit.Malware.Fighter.Pro-12.0.0.1433.exe /S
    Process:C:\Users\user\Desktop\file.exe
    File Type:PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
    Category:dropped
    Size (bytes):77088228
    Entropy (8bit):7.9989824995755425
    Encrypted:true
    SSDEEP:1572864:iO9tDrNScQik6TAH9MF9gDa9WsBNOoeP6HKWonWYCkEBvbdr2zE9SPSt5NG9lEF:hUQAd6gDad+SHSj8BMSt7GDEF
    MD5:5523E18197DA0439445F3B02163F77D0
    SHA1:F28C166B81731DE72B499E3A5EAE2BA4557F80B7
    SHA-256:9F0EE3D02648F63ACB2686E374D832CB0B657E17A7424FFB42D74EF3B15019C2
    SHA-512:A60CEE37A397C6B5FBB7685B4410E7CB2BA55229B04F9047C6DF89711218E549EC97E10E4D048A58C1D135770DDF5E5685B52552E219227F23830FA18F960B7F
    Malicious:true
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 3%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........u.Q.............lW.........j....lG......lP......lU.....Rich....................PE..L....#.].................n...,......]9............@.......................................@.............................................`............................................................................................................text....m.......n.................. ..`.rdata...............r..............@..@.data...<...........................@....ndata...P...............................rsrc...`...........................@..@........................................................................................................................................................................................................................................................................................................................................................
    Process:C:\Users\user\Desktop\file.exe
    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
    Category:dropped
    Size (bytes):3541575
    Entropy (8bit):7.970506285180278
    Encrypted:false
    SSDEEP:98304:yiqOnX5D2wa4mzAPzlJZ+roUn2G5csZXa8k1Jx1Qi:oIp1sw/+dZ05Qi
    MD5:E209F482DBF07FC1C7D9A9458C8D6F5A
    SHA1:C3F91C3C04D2B45B1937708602DC7DCCF65BBC19
    SHA-256:F51A97ACAFE22E2AF11AEFE3B4098BE19092644D4111ACAE4CA1686CC95ADD61
    SHA-512:C26981BA7B53953A560E98DAA07F9815B0617F5EDE75FB73F39F261A24931FD8F70AF04C0C1B7FC37A006A31296D8F0ED57856DC4ECFDEEBC3BC4A6862036700
    Malicious:true
    Antivirus:
    • Antivirus: Joe Sandbox ML, Detection: 100%
    Reputation:low
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......x_c.<>..<>..<>......1>.......>......$>...I.>>...I../>...I..+>...I...>..5F..7>..5F..;>..<>..)?...I...>...I..=>...I.=>...I..=>..Rich<>..........PE..L..... b............................0........0....@..........................P............@.........................p...4.......P....@....................... ..<#......T............................U..@............0..x....... ....................text............................... ..`.rdata.......0....... ..............@..@.data... G..........................@....didat.......0......................@....rsrc........@......................@..@.reloc..<#... ...$..................@..B................................................................................................................................................................................................................................................
    File type:PE32+ executable (GUI) x86-64, for MS Windows
    Entropy (8bit):7.999818697187227
    TrID:
    • Win64 Executable GUI (202006/5) 92.65%
    • Win64 Executable (generic) (12005/4) 5.51%
    • Generic Win/DOS Executable (2004/3) 0.92%
    • DOS Executable Generic (2002/1) 0.92%
    • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
    File name:file.exe
    File size:80'591'650 bytes
    MD5:3f97ee2b5aefb68fc0d7c6383b41385d
    SHA1:1169a86fb0b2ccb367f9cc886b209e77c6418983
    SHA256:3fb4d76805f5d0d3f23f37fea0f19da7a8e11c6e2a6104035511aded0696fc82
    SHA512:0e6827c292643aaf6dd3a4d96e6811e61d8a1c804054f5cb67eaec28cb228565cf1bc46aa683b37c34aea4fa9f63096ce9c4ed51b85c2104824955779abbdd6e
    SSDEEP:1572864:gbQ9z3vD69+yI1/RvrpuV+YS2C4EL9XdMDTw24g21EVGOI0RlR/xojgrYnitOpUd:Zd3rRvrsVRS73bYT9x2WgMReA5r
    TLSH:3D0833D7F6761CF4F82BFEBE2509AC8A96B538412365519E678332A60F277200E35F41
    File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......$.2.`.\.`.\.`.\..y..h.\..y....\..y..m.\.....b.\...X.r.\..._.j.\...Y.Y.\.i...i.\.i...b.\.i...g.\.`.].C.\...Y.R.\...\.a.\.....a.\
    Icon Hash:1515d4d4442f2d2d
    Entrypoint:0x140032ee0
    Entrypoint Section:.text
    Digitally signed:false
    Imagebase:0x140000000
    Subsystem:windows gui
    Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
    DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
    Time Stamp:0x66409723 [Sun May 12 10:17:07 2024 UTC]
    TLS Callbacks:
    CLR (.Net) Version:
    OS Version Major:5
    OS Version Minor:2
    File Version Major:5
    File Version Minor:2
    Subsystem Version Major:5
    Subsystem Version Minor:2
    Import Hash:b1c5b1beabd90d9fdabd1df0779ea832
    Instruction
    dec eax
    sub esp, 28h
    call 00007F32C50BDC28h
    dec eax
    add esp, 28h
    jmp 00007F32C50BD5BFh
    int3
    int3
    dec eax
    mov eax, esp
    dec eax
    mov dword ptr [eax+08h], ebx
    dec eax
    mov dword ptr [eax+10h], ebp
    dec eax
    mov dword ptr [eax+18h], esi
    dec eax
    mov dword ptr [eax+20h], edi
    inc ecx
    push esi
    dec eax
    sub esp, 20h
    dec ebp
    mov edx, dword ptr [ecx+38h]
    dec eax
    mov esi, edx
    dec ebp
    mov esi, eax
    dec eax
    mov ebp, ecx
    dec ecx
    mov edx, ecx
    dec eax
    mov ecx, esi
    dec ecx
    mov edi, ecx
    inc ecx
    mov ebx, dword ptr [edx]
    dec eax
    shl ebx, 04h
    dec ecx
    add ebx, edx
    dec esp
    lea eax, dword ptr [ebx+04h]
    call 00007F32C50BCA43h
    mov eax, dword ptr [ebp+04h]
    and al, 66h
    neg al
    mov eax, 00000001h
    sbb edx, edx
    neg edx
    add edx, eax
    test dword ptr [ebx+04h], edx
    je 00007F32C50BD753h
    dec esp
    mov ecx, edi
    dec ebp
    mov eax, esi
    dec eax
    mov edx, esi
    dec eax
    mov ecx, ebp
    call 00007F32C50BF767h
    dec eax
    mov ebx, dword ptr [esp+30h]
    dec eax
    mov ebp, dword ptr [esp+38h]
    dec eax
    mov esi, dword ptr [esp+40h]
    dec eax
    mov edi, dword ptr [esp+48h]
    dec eax
    add esp, 20h
    inc ecx
    pop esi
    ret
    int3
    int3
    int3
    dec eax
    sub esp, 48h
    dec eax
    lea ecx, dword ptr [esp+20h]
    call 00007F32C50ABFD3h
    dec eax
    lea edx, dword ptr [00025747h]
    dec eax
    lea ecx, dword ptr [esp+20h]
    call 00007F32C50BE822h
    int3
    jmp 00007F32C50C4A04h
    int3
    int3
    int3
    int3
    int3
    int3
    Programming Language:
    • [ C ] VS2008 SP1 build 30729
    • [IMP] VS2008 SP1 build 30729
    NameVirtual AddressVirtual Size Is in Section
    IMAGE_DIRECTORY_ENTRY_EXPORT0x597a00x34.rdata
    IMAGE_DIRECTORY_ENTRY_IMPORT0x597d40x50.rdata
    IMAGE_DIRECTORY_ENTRY_RESOURCE0x700000xe3bc.rsrc
    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x6a0000x306c.pdata
    IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
    IMAGE_DIRECTORY_ENTRY_BASERELOC0x7f0000x970.reloc
    IMAGE_DIRECTORY_ENTRY_DEBUG0x536c00x54.rdata
    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
    IMAGE_DIRECTORY_ENTRY_TLS0x537800x28.rdata
    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x4b3f00x140.rdata
    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
    IMAGE_DIRECTORY_ENTRY_IAT0x480000x508.rdata
    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x588bc0x120.rdata
    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
    NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
    .text0x10000x4676e0x46800f06bb06e02377ae8b223122e53be35c2False0.5372340425531915data6.47079645411382IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
    .rdata0x480000x128c40x12a002de06d4a6920a6911e64ff20000ea72fFalse0.4499003775167785data5.273999097784603IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
    .data0x5b0000xe75c0x1a000dbdb901a7d477980097e42e511a94fbFalse0.28275240384615385data3.2571023907881185IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
    .pdata0x6a0000x306c0x3200b0ce0f057741ad2a4ef4717079fa34e9False0.483359375data5.501810413666288IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
    .didat0x6e0000x3600x4001fcc7b1d7a02443319f8fcc2be4ca936False0.2578125data3.0459938492946015IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
    _RDATA0x6f0000x15c0x2003f331ec50f09ba861beaf955b33712d5False0.408203125data3.3356393424384843IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
    .rsrc0x700000xe3bc0xe4001b279dad3e3d77fcdfb269a130bf474bFalse0.6334121436403509data6.778407783727912IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
    .reloc0x7f0000x9700xa0077a9ddfc47a5650d6eebbcc823e39532False0.52421875data5.336289720085303IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
    NameRVASizeTypeLanguageCountryZLIB Complexity
    PNG0x706740xb45PNG image data, 93 x 302, 8-bit/color RGB, non-interlaced1.0027729636048528
    PNG0x711bc0x15a9PNG image data, 186 x 604, 8-bit/color RGB, non-interlaced0.9363390441839495
    RT_ICON0x727680x568Device independent bitmap graphic, 16 x 32 x 8, image size 256, resolution 2834 x 2834 px/m, 256 important colors0.47832369942196534
    RT_ICON0x72cd00x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1024, resolution 2834 x 2834 px/m, 256 important colors0.5410649819494585
    RT_ICON0x735780xea8Device independent bitmap graphic, 48 x 96 x 8, image size 2304, resolution 2834 x 2834 px/m, 256 important colors0.4933368869936034
    RT_ICON0x744200x468Device independent bitmap graphic, 16 x 32 x 32, image size 1024, resolution 2834 x 2834 px/m0.5390070921985816
    RT_ICON0x748880x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4096, resolution 2834 x 2834 px/m0.41393058161350843
    RT_ICON0x759300x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9216, resolution 2834 x 2834 px/m0.3479253112033195
    RT_ICON0x77ed80x3d71PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced0.9809269502193401
    RT_DIALOG0x7bc4c0x2badata0.5286532951289399
    RT_DIALOG0x7bf080x13adata0.6560509554140127
    RT_DIALOG0x7c0440xf2data0.71900826446281
    RT_DIALOG0x7c1380x14adata0.6
    RT_DIALOG0x7c2840x314data0.47588832487309646
    RT_DIALOG0x7c5980x24adata0.6279863481228669
    RT_STRING0x7c7e40x1fcdata0.421259842519685
    RT_STRING0x7c9e00x246data0.41924398625429554
    RT_STRING0x7cc280x1a6data0.514218009478673
    RT_STRING0x7cdd00xdcdata0.65
    RT_STRING0x7ceac0x470data0.3873239436619718
    RT_STRING0x7d31c0x164data0.5056179775280899
    RT_STRING0x7d4800x110data0.5772058823529411
    RT_STRING0x7d5900x158data0.4563953488372093
    RT_STRING0x7d6e80xe8data0.5948275862068966
    RT_STRING0x7d7d00x1c6data0.5242290748898678
    RT_STRING0x7d9980x268data0.4837662337662338
    RT_GROUP_ICON0x7dc000x68data0.7019230769230769
    RT_MANIFEST0x7dc680x753XML 1.0 document, ASCII text, with CRLF line terminators0.3957333333333333
    DLLImport
    KERNEL32.dllLocalFree, GetLastError, SetLastError, FormatMessageW, GetCurrentProcess, DeviceIoControl, SetFileTime, CloseHandle, RemoveDirectoryW, CreateFileW, DeleteFileW, CreateHardLinkW, GetShortPathNameW, GetLongPathNameW, MoveFileW, GetFileType, GetStdHandle, WriteFile, ReadFile, FlushFileBuffers, SetEndOfFile, SetFilePointer, GetCurrentProcessId, CreateDirectoryW, SetFileAttributesW, GetFileAttributesW, FindClose, FindFirstFileW, FindNextFileW, GetVersionExW, GetModuleFileNameW, SetCurrentDirectoryW, GetCurrentDirectoryW, GetFullPathNameW, FoldStringW, GetModuleHandleW, FindResourceW, FreeLibrary, GetProcAddress, ExpandEnvironmentStringsW, ExitProcess, SetThreadExecutionState, Sleep, LoadLibraryW, GetSystemDirectoryW, CompareStringW, AllocConsole, FreeConsole, AttachConsole, WriteConsoleW, GetProcessAffinityMask, CreateThread, SetThreadPriority, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, SetEvent, ResetEvent, ReleaseSemaphore, WaitForSingleObject, CreateEventW, CreateSemaphoreW, GetSystemTime, SystemTimeToTzSpecificLocalTime, TzSpecificLocalTimeToSystemTime, SystemTimeToFileTime, FileTimeToLocalFileTime, LocalFileTimeToFileTime, FileTimeToSystemTime, GetCPInfo, IsDBCSLeadByte, MultiByteToWideChar, WideCharToMultiByte, GlobalAlloc, LockResource, GlobalLock, GlobalUnlock, GlobalFree, GlobalMemoryStatusEx, LoadResource, SizeofResource, GetTimeFormatW, GetDateFormatW, GetExitCodeProcess, GetLocalTime, GetTickCount, MapViewOfFile, UnmapViewOfFile, CreateFileMappingW, OpenFileMappingW, GetCommandLineW, SetEnvironmentVariableW, GetTempPathW, MoveFileExW, GetLocaleInfoW, GetNumberFormatW, SetFilePointerEx, GetConsoleMode, GetConsoleCP, HeapSize, SetStdHandle, GetProcessHeap, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineA, GetOEMCP, IsValidCodePage, FindNextFileA, RaiseException, GetSystemInfo, VirtualProtect, VirtualQuery, LoadLibraryExA, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, TerminateProcess, IsProcessorFeaturePresent, InitializeCriticalSectionAndSpinCount, WaitForSingleObjectEx, IsDebuggerPresent, GetStartupInfoW, QueryPerformanceCounter, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, RtlPcToFileHeader, RtlUnwindEx, EncodePointer, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, LoadLibraryExW, QueryPerformanceFrequency, GetModuleHandleExW, GetModuleFileNameA, GetACP, HeapFree, HeapAlloc, GetStringTypeW, HeapReAlloc, LCMapStringW, FindFirstFileExA
    OLEAUT32.dllSysAllocString, SysFreeString, VariantClear
    gdiplus.dllGdipCloneImage, GdipFree, GdipDisposeImage, GdipCreateBitmapFromStream, GdipCreateHBITMAPFromBitmap, GdiplusStartup, GdiplusShutdown, GdipAlloc
    No network behavior found

    Click to jump to process

    Click to jump to process

    Target ID:0
    Start time:12:58:20
    Start date:19/11/2024
    Path:C:\Users\user\Desktop\file.exe
    Wow64 process (32bit):false
    Commandline:"C:\Users\user\Desktop\file.exe"
    Imagebase:0x7ff76daf0000
    File size:80'591'650 bytes
    MD5 hash:3F97EE2B5AEFB68FC0D7C6383B41385D
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:true

    Reset < >

      Execution Graph

      Execution Coverage:11.7%
      Dynamic/Decrypted Code Coverage:0%
      Signature Coverage:27.2%
      Total number of Nodes:2000
      Total number of Limit Nodes:29
      execution_graph 26093 7ff76db22d6c 26118 7ff76db227fc 26093->26118 26096 7ff76db22eb8 26216 7ff76db23170 7 API calls 2 library calls 26096->26216 26097 7ff76db22d88 __scrt_acquire_startup_lock 26099 7ff76db22ec2 26097->26099 26101 7ff76db22da6 26097->26101 26217 7ff76db23170 7 API calls 2 library calls 26099->26217 26102 7ff76db22dcb 26101->26102 26109 7ff76db22de8 __scrt_release_startup_lock 26101->26109 26126 7ff76db2cd90 26101->26126 26103 7ff76db22ecd abort 26105 7ff76db22e51 26130 7ff76db232bc 26105->26130 26107 7ff76db22e56 26133 7ff76db2cd20 26107->26133 26109->26105 26213 7ff76db2c050 35 API calls __GSHandlerCheck_EH 26109->26213 26218 7ff76db22fb0 26118->26218 26121 7ff76db2282b 26220 7ff76db2cc50 26121->26220 26122 7ff76db22827 26122->26096 26122->26097 26127 7ff76db2cdeb 26126->26127 26128 7ff76db2cdcc 26126->26128 26127->26109 26128->26127 26237 7ff76daf1120 26128->26237 26300 7ff76db23cf0 26130->26300 26132 7ff76db232d3 GetStartupInfoW 26132->26107 26302 7ff76db30730 26133->26302 26135 7ff76db2cd2f 26137 7ff76db22e5e 26135->26137 26306 7ff76db30ac0 35 API calls _snwprintf 26135->26306 26138 7ff76db20754 26137->26138 26308 7ff76db0dfd0 26138->26308 26142 7ff76db2079a 26395 7ff76db1946c 26142->26395 26144 7ff76db207a4 memcpy_s 26400 7ff76db19a14 26144->26400 26146 7ff76db2096e GetCommandLineW 26148 7ff76db20980 26146->26148 26188 7ff76db20b42 26146->26188 26147 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 26149 7ff76db20de2 26147->26149 26467 7ff76daf129c 26148->26467 26462 7ff76db27904 26149->26462 26151 7ff76db20819 26151->26146 26195 7ff76db20ddc 26151->26195 26153 7ff76db20b51 26156 7ff76daf1fa0 31 API calls 26153->26156 26161 7ff76db20b68 memcpy_s 26153->26161 26155 7ff76db209a5 26477 7ff76db1cad0 102 API calls 3 library calls 26155->26477 26156->26161 26158 7ff76db20b93 SetEnvironmentVariableW GetLocalTime 26427 7ff76db03e28 26158->26427 26422 7ff76daf1fa0 26161->26422 26164 7ff76db209af 26164->26149 26166 7ff76db209f9 OpenFileMappingW 26164->26166 26167 7ff76db20adb 26164->26167 26170 7ff76db20a19 MapViewOfFile 26166->26170 26171 7ff76db20ad0 CloseHandle 26166->26171 26175 7ff76daf129c 33 API calls 26167->26175 26170->26171 26173 7ff76db20a3f UnmapViewOfFile MapViewOfFile 26170->26173 26171->26188 26173->26171 26176 7ff76db20a71 26173->26176 26174 7ff76db20c75 26455 7ff76db167b4 26174->26455 26179 7ff76db20b00 26175->26179 26478 7ff76db1a190 33 API calls 2 library calls 26176->26478 26482 7ff76db1fd0c 35 API calls 2 library calls 26179->26482 26181 7ff76db20a81 26479 7ff76db1fd0c 35 API calls 2 library calls 26181->26479 26183 7ff76db20b0a 26183->26188 26190 7ff76db20dd7 26183->26190 26185 7ff76db167b4 33 API calls 26187 7ff76db20c87 DialogBoxParamW 26185->26187 26186 7ff76db20a90 26480 7ff76db0b9b4 102 API calls 26186->26480 26196 7ff76db20cd3 26187->26196 26410 7ff76db06454 26188->26410 26193 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 26190->26193 26191 7ff76db20aa5 26481 7ff76db0bb00 102 API calls 26191->26481 26193->26195 26194 7ff76db20ab8 26200 7ff76db20ac7 UnmapViewOfFile 26194->26200 26195->26147 26197 7ff76db20cec 26196->26197 26198 7ff76db20ce6 Sleep 26196->26198 26199 7ff76db20cfa 26197->26199 26483 7ff76db19f4c 49 API calls 2 library calls 26197->26483 26198->26197 26202 7ff76db20d06 DeleteObject 26199->26202 26200->26171 26203 7ff76db20d1f DeleteObject 26202->26203 26204 7ff76db20d25 26202->26204 26203->26204 26205 7ff76db20d5b 26204->26205 26206 7ff76db20d6d 26204->26206 26484 7ff76db1fe24 PeekMessageW GetMessageW TranslateMessage DispatchMessageW WaitForSingleObject 26205->26484 26458 7ff76db194e4 26206->26458 26209 7ff76db20d60 CloseHandle 26209->26206 26213->26105 26216->26099 26217->26103 26219 7ff76db2281e __scrt_dllmain_crt_thread_attach 26218->26219 26219->26121 26219->26122 26221 7ff76db30d4c 26220->26221 26222 7ff76db22830 26221->26222 26225 7ff76db2ec00 26221->26225 26222->26122 26224 7ff76db251a0 7 API calls 2 library calls 26222->26224 26224->26122 26236 7ff76db2f398 EnterCriticalSection 26225->26236 26242 7ff76daf91c8 26237->26242 26241 7ff76db22a01 26241->26128 26250 7ff76db056a4 26242->26250 26244 7ff76daf91df 26253 7ff76db0b788 26244->26253 26248 7ff76daf1130 26249 7ff76db229bc 34 API calls 26248->26249 26249->26241 26259 7ff76db056e8 26250->26259 26268 7ff76daf13a4 26253->26268 26256 7ff76daf9a28 26257 7ff76db056e8 2 API calls 26256->26257 26258 7ff76daf9a36 26257->26258 26258->26248 26260 7ff76db056fe memcpy_s 26259->26260 26263 7ff76db0eba4 26260->26263 26266 7ff76db0eb58 GetCurrentProcess GetProcessAffinityMask 26263->26266 26267 7ff76db056de 26266->26267 26267->26244 26269 7ff76daf13ad 26268->26269 26270 7ff76daf142d 26268->26270 26271 7ff76daf143d 26269->26271 26272 7ff76daf13ce 26269->26272 26270->26256 26288 7ff76daf2018 33 API calls std::_Xinvalid_argument 26271->26288 26275 7ff76daf13db memcpy_s 26272->26275 26278 7ff76db221d0 26272->26278 26287 7ff76daf197c 31 API calls _invalid_parameter_noinfo_noreturn 26275->26287 26279 7ff76db221db 26278->26279 26280 7ff76db221f4 26279->26280 26282 7ff76db221fa 26279->26282 26289 7ff76db2bbc0 26279->26289 26280->26275 26283 7ff76db22205 26282->26283 26292 7ff76db22f7c RtlPcToFileHeader RaiseException Concurrency::cancel_current_task std::bad_alloc::bad_alloc 26282->26292 26293 7ff76daf1f80 33 API calls 3 library calls 26283->26293 26286 7ff76db2220b 26287->26270 26294 7ff76db2bc00 26289->26294 26292->26283 26293->26286 26299 7ff76db2f398 EnterCriticalSection 26294->26299 26301 7ff76db23cd0 26300->26301 26301->26132 26301->26301 26303 7ff76db3073d 26302->26303 26304 7ff76db30749 26302->26304 26307 7ff76db30570 48 API calls 4 library calls 26303->26307 26304->26135 26306->26135 26307->26304 26485 7ff76db22450 26308->26485 26311 7ff76db0e07b 26313 7ff76db0e503 26311->26313 26527 7ff76db2b788 39 API calls _snwprintf 26311->26527 26312 7ff76db0e026 GetProcAddress 26314 7ff76db0e03b 26312->26314 26315 7ff76db0e053 GetProcAddress 26312->26315 26317 7ff76db06454 34 API calls 26313->26317 26314->26315 26315->26311 26318 7ff76db0e068 26315->26318 26320 7ff76db0e50c 26317->26320 26318->26311 26319 7ff76db0e3b0 26319->26313 26321 7ff76db0e3ba 26319->26321 26487 7ff76db07df4 26320->26487 26323 7ff76db06454 34 API calls 26321->26323 26324 7ff76db0e3c3 CreateFileW 26323->26324 26326 7ff76db0e4f0 CloseHandle 26324->26326 26327 7ff76db0e403 SetFilePointer 26324->26327 26329 7ff76daf1fa0 31 API calls 26326->26329 26327->26326 26328 7ff76db0e41c ReadFile 26327->26328 26328->26326 26330 7ff76db0e444 26328->26330 26329->26313 26331 7ff76db0e458 26330->26331 26332 7ff76db0e800 26330->26332 26337 7ff76daf129c 33 API calls 26331->26337 26543 7ff76db22624 8 API calls 26332->26543 26334 7ff76db0e805 26335 7ff76db0e53e CompareStringW 26349 7ff76db0e51a 26335->26349 26336 7ff76daf129c 33 API calls 26336->26349 26342 7ff76db0e48f 26337->26342 26340 7ff76db0e63a 26343 7ff76db0e648 26340->26343 26344 7ff76db0e7c2 26340->26344 26341 7ff76daf1fa0 31 API calls 26341->26349 26346 7ff76db0e4db 26342->26346 26528 7ff76db0d0a0 33 API calls 26342->26528 26529 7ff76db07eb0 47 API calls 26343->26529 26348 7ff76daf1fa0 31 API calls 26344->26348 26350 7ff76daf1fa0 31 API calls 26346->26350 26352 7ff76db0e7cb 26348->26352 26349->26335 26349->26336 26349->26341 26369 7ff76db0e5cc 26349->26369 26495 7ff76db051a4 26349->26495 26500 7ff76db08090 26349->26500 26504 7ff76db032bc 26349->26504 26353 7ff76db0e4e5 26350->26353 26351 7ff76db0e651 26354 7ff76db051a4 9 API calls 26351->26354 26356 7ff76daf1fa0 31 API calls 26352->26356 26357 7ff76daf1fa0 31 API calls 26353->26357 26358 7ff76db0e656 26354->26358 26355 7ff76daf129c 33 API calls 26355->26369 26359 7ff76db0e7d5 26356->26359 26357->26326 26360 7ff76db0e706 26358->26360 26370 7ff76db0e661 26358->26370 26518 7ff76db22320 26359->26518 26363 7ff76db0da98 48 API calls 26360->26363 26361 7ff76db08090 47 API calls 26361->26369 26365 7ff76db0e74b AllocConsole 26363->26365 26367 7ff76db0e6fb 26365->26367 26368 7ff76db0e755 GetCurrentProcessId AttachConsole 26365->26368 26366 7ff76daf1fa0 31 API calls 26366->26369 26542 7ff76daf19e0 31 API calls _invalid_parameter_noinfo_noreturn 26367->26542 26371 7ff76db0e76c 26368->26371 26369->26340 26369->26355 26369->26361 26369->26366 26372 7ff76db032bc 51 API calls 26369->26372 26530 7ff76db0aae0 26370->26530 26378 7ff76db0e778 GetStdHandle WriteConsoleW Sleep FreeConsole 26371->26378 26372->26369 26376 7ff76db0e7b9 ExitProcess 26378->26367 26380 7ff76db0aae0 48 API calls 26381 7ff76db0e6ce 26380->26381 26540 7ff76db0dc2c 33 API calls 26381->26540 26383 7ff76db0e6da 26541 7ff76daf19e0 31 API calls _invalid_parameter_noinfo_noreturn 26383->26541 26385 7ff76db062dc GetCurrentDirectoryW 26386 7ff76db06300 26385->26386 26391 7ff76db0638d 26385->26391 26387 7ff76daf13a4 33 API calls 26386->26387 26388 7ff76db0631b GetCurrentDirectoryW 26387->26388 26389 7ff76db06341 26388->26389 26760 7ff76daf20b0 26389->26760 26391->26142 26392 7ff76db0634f 26392->26391 26393 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 26392->26393 26394 7ff76db063a9 26393->26394 26396 7ff76db0dd88 26395->26396 26397 7ff76db19481 OleInitialize 26396->26397 26398 7ff76db194a7 26397->26398 26399 7ff76db194cd SHGetMalloc 26398->26399 26399->26144 26401 7ff76db19a49 26400->26401 26408 7ff76db19a4e memcpy_s 26400->26408 26402 7ff76daf1fa0 31 API calls 26401->26402 26402->26408 26403 7ff76db19a7d memcpy_s 26405 7ff76db19aac memcpy_s 26403->26405 26406 7ff76daf1fa0 31 API calls 26403->26406 26404 7ff76daf1fa0 31 API calls 26404->26403 26407 7ff76daf1fa0 31 API calls 26405->26407 26409 7ff76db19adb memcpy_s 26405->26409 26406->26405 26407->26409 26408->26403 26408->26404 26409->26151 26411 7ff76daf13a4 33 API calls 26410->26411 26412 7ff76db06489 26411->26412 26413 7ff76db0648c GetModuleFileNameW 26412->26413 26416 7ff76db064dc 26412->26416 26414 7ff76db064de 26413->26414 26415 7ff76db064a7 26413->26415 26414->26416 26415->26412 26417 7ff76daf129c 33 API calls 26416->26417 26419 7ff76db06506 26417->26419 26418 7ff76db0653e 26418->26153 26419->26418 26420 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 26419->26420 26421 7ff76db06560 26420->26421 26423 7ff76daf1fb3 26422->26423 26424 7ff76daf1fdc 26422->26424 26423->26424 26425 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 26423->26425 26424->26158 26426 7ff76daf2000 26425->26426 26428 7ff76db03e4d _snwprintf 26427->26428 26429 7ff76db29ef0 swprintf 46 API calls 26428->26429 26430 7ff76db03e69 SetEnvironmentVariableW GetModuleHandleW LoadIconW 26429->26430 26431 7ff76db1b014 LoadBitmapW 26430->26431 26432 7ff76db1b046 26431->26432 26433 7ff76db1b03e 26431->26433 26435 7ff76db1b04e GetObjectW 26432->26435 26436 7ff76db1b063 26432->26436 26765 7ff76db18624 FindResourceExW 26433->26765 26435->26436 26780 7ff76db1849c 26436->26780 26439 7ff76db1b0ce 26450 7ff76db098ac 26439->26450 26440 7ff76db1b09e 26785 7ff76db18504 GetDC GetDeviceCaps GetDeviceCaps ReleaseDC 26440->26785 26441 7ff76db18624 11 API calls 26443 7ff76db1b08a 26441->26443 26443->26440 26445 7ff76db1b092 DeleteObject 26443->26445 26444 7ff76db1b0a7 26786 7ff76db184cc 26444->26786 26445->26440 26449 7ff76db1b0bf DeleteObject 26449->26439 26793 7ff76db098dc 26450->26793 26452 7ff76db098ba 26860 7ff76db0a43c GetModuleHandleW FindResourceW 26452->26860 26454 7ff76db098c2 26454->26174 26456 7ff76db221d0 33 API calls 26455->26456 26457 7ff76db167fa 26456->26457 26457->26185 26459 7ff76db19501 26458->26459 26460 7ff76db1950a OleUninitialize 26459->26460 26461 7ff76db5e330 26460->26461 26942 7ff76db2783c 31 API calls 3 library calls 26462->26942 26464 7ff76db2791d 26943 7ff76db27934 16 API calls abort 26464->26943 26468 7ff76daf12d0 26467->26468 26469 7ff76daf139b 26467->26469 26472 7ff76daf1396 26468->26472 26473 7ff76daf1338 26468->26473 26476 7ff76daf12de memcpy_s 26468->26476 26945 7ff76daf2004 33 API calls std::_Xinvalid_argument 26469->26945 26944 7ff76daf1f80 33 API calls 3 library calls 26472->26944 26475 7ff76db221d0 33 API calls 26473->26475 26473->26476 26475->26476 26476->26155 26477->26164 26478->26181 26479->26186 26480->26191 26481->26194 26482->26183 26483->26199 26484->26209 26486 7ff76db0dff4 GetModuleHandleW 26485->26486 26486->26311 26486->26312 26488 7ff76db07e0c 26487->26488 26489 7ff76db07e55 26488->26489 26490 7ff76db07e23 26488->26490 26544 7ff76daf704c 47 API calls memcpy_s 26489->26544 26492 7ff76daf129c 33 API calls 26490->26492 26494 7ff76db07e47 26492->26494 26493 7ff76db07e5a 26494->26349 26496 7ff76db051c8 GetVersionExW 26495->26496 26497 7ff76db051fb 26495->26497 26496->26497 26498 7ff76db22320 _handle_error 8 API calls 26497->26498 26499 7ff76db05228 26498->26499 26499->26349 26501 7ff76db080a5 26500->26501 26545 7ff76db08188 26501->26545 26503 7ff76db080ca 26503->26349 26505 7ff76db032e4 26504->26505 26506 7ff76db032e7 GetFileAttributesW 26504->26506 26505->26506 26507 7ff76db032f8 26506->26507 26514 7ff76db03375 26506->26514 26554 7ff76db06a0c 26507->26554 26509 7ff76db22320 _handle_error 8 API calls 26511 7ff76db03389 26509->26511 26511->26349 26512 7ff76db03323 GetFileAttributesW 26513 7ff76db0333c 26512->26513 26513->26514 26515 7ff76db03399 26513->26515 26514->26509 26516 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 26515->26516 26517 7ff76db0339e 26516->26517 26519 7ff76db22329 26518->26519 26520 7ff76db0e7e4 26519->26520 26521 7ff76db22550 IsProcessorFeaturePresent 26519->26521 26520->26385 26522 7ff76db22568 26521->26522 26659 7ff76db22744 RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind 26522->26659 26524 7ff76db2257b 26660 7ff76db22510 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 26524->26660 26527->26319 26528->26342 26529->26351 26531 7ff76db0aaf3 26530->26531 26661 7ff76db09774 26531->26661 26534 7ff76db0ab58 LoadStringW 26535 7ff76db0ab86 26534->26535 26536 7ff76db0ab71 LoadStringW 26534->26536 26537 7ff76db0da98 26535->26537 26536->26535 26687 7ff76db0d874 26537->26687 26540->26383 26541->26367 26542->26376 26543->26334 26544->26493 26546 7ff76db08326 26545->26546 26549 7ff76db081ba 26545->26549 26553 7ff76daf704c 47 API calls memcpy_s 26546->26553 26548 7ff76db0832b 26551 7ff76db081d4 memcpy_s 26549->26551 26552 7ff76db058a4 33 API calls 2 library calls 26549->26552 26551->26503 26552->26551 26553->26548 26555 7ff76db06a4b 26554->26555 26575 7ff76db06a44 26554->26575 26557 7ff76daf129c 33 API calls 26555->26557 26556 7ff76db22320 _handle_error 8 API calls 26558 7ff76db0331f 26556->26558 26559 7ff76db06a76 26557->26559 26558->26512 26558->26513 26560 7ff76db06a96 26559->26560 26561 7ff76db06cc7 26559->26561 26563 7ff76db06ab0 26560->26563 26585 7ff76db06b49 26560->26585 26562 7ff76db062dc 35 API calls 26561->26562 26566 7ff76db06ce6 26562->26566 26564 7ff76db070ab 26563->26564 26627 7ff76dafc098 33 API calls 2 library calls 26563->26627 26651 7ff76daf2004 33 API calls std::_Xinvalid_argument 26564->26651 26567 7ff76db06eef 26566->26567 26570 7ff76db06d1b 26566->26570 26571 7ff76db06b44 26566->26571 26609 7ff76db070cf 26567->26609 26648 7ff76dafc098 33 API calls 2 library calls 26567->26648 26568 7ff76db070b1 26577 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 26568->26577 26600 7ff76db070bd 26570->26600 26630 7ff76dafc098 33 API calls 2 library calls 26570->26630 26571->26568 26572 7ff76db070d5 26571->26572 26571->26575 26579 7ff76db070a6 26571->26579 26578 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 26572->26578 26574 7ff76db06b03 26586 7ff76daf1fa0 31 API calls 26574->26586 26597 7ff76db06b15 memcpy_s 26574->26597 26575->26556 26583 7ff76db070b7 26577->26583 26584 7ff76db070db 26578->26584 26590 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 26579->26590 26580 7ff76db06f56 26649 7ff76daf11cc 33 API calls memcpy_s 26580->26649 26593 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 26583->26593 26595 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 26584->26595 26585->26571 26591 7ff76daf129c 33 API calls 26585->26591 26586->26597 26588 7ff76db070c3 26599 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 26588->26599 26589 7ff76daf1fa0 31 API calls 26589->26571 26590->26564 26596 7ff76db06bbe 26591->26596 26592 7ff76db06f69 26650 7ff76db057ac 33 API calls memcpy_s 26592->26650 26593->26600 26594 7ff76daf1fa0 31 API calls 26611 7ff76db06df5 26594->26611 26601 7ff76db070e1 26595->26601 26628 7ff76db05820 33 API calls 26596->26628 26597->26589 26603 7ff76db070c9 26599->26603 26652 7ff76daf2004 33 API calls std::_Xinvalid_argument 26600->26652 26653 7ff76daf704c 47 API calls memcpy_s 26603->26653 26604 7ff76db06d76 memcpy_s 26604->26588 26604->26594 26605 7ff76db06bd3 26629 7ff76dafe164 33 API calls 2 library calls 26605->26629 26606 7ff76daf1fa0 31 API calls 26610 7ff76db06fec 26606->26610 26654 7ff76daf2004 33 API calls std::_Xinvalid_argument 26609->26654 26612 7ff76daf1fa0 31 API calls 26610->26612 26617 7ff76db06e21 26611->26617 26631 7ff76daf1744 26611->26631 26616 7ff76db06ff6 26612->26616 26613 7ff76db06f79 memcpy_s 26613->26584 26613->26606 26615 7ff76daf1fa0 31 API calls 26619 7ff76db06c6d 26615->26619 26620 7ff76daf1fa0 31 API calls 26616->26620 26617->26603 26621 7ff76daf129c 33 API calls 26617->26621 26618 7ff76db06be9 memcpy_s 26618->26583 26618->26615 26622 7ff76daf1fa0 31 API calls 26619->26622 26620->26571 26623 7ff76db06ec2 26621->26623 26622->26571 26644 7ff76daf2034 26623->26644 26625 7ff76db06edf 26626 7ff76daf1fa0 31 API calls 26625->26626 26626->26571 26627->26574 26628->26605 26629->26618 26630->26604 26634 7ff76daf1784 26631->26634 26643 7ff76daf18a1 26631->26643 26633 7ff76daf18a7 26656 7ff76daf1f80 33 API calls 3 library calls 26633->26656 26634->26633 26637 7ff76db221d0 33 API calls 26634->26637 26640 7ff76daf17ac memcpy_s 26634->26640 26636 7ff76daf18ad 26657 7ff76db2354c 31 API calls __std_exception_copy 26636->26657 26637->26640 26639 7ff76daf18d9 26639->26617 26641 7ff76daf1859 memcpy_s 26640->26641 26642 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 26640->26642 26641->26617 26642->26643 26655 7ff76daf2004 33 API calls std::_Xinvalid_argument 26643->26655 26645 7ff76daf2085 26644->26645 26647 7ff76daf2059 memcpy_s 26644->26647 26658 7ff76daf15b8 33 API calls 3 library calls 26645->26658 26647->26625 26648->26580 26649->26592 26650->26613 26653->26609 26656->26636 26657->26639 26658->26647 26659->26524 26668 7ff76db09638 26661->26668 26664 7ff76db097d9 26666 7ff76db22320 _handle_error 8 API calls 26664->26666 26667 7ff76db097f2 26666->26667 26667->26534 26667->26535 26669 7ff76db09692 26668->26669 26677 7ff76db09730 26668->26677 26672 7ff76db096c0 26669->26672 26682 7ff76db10f68 WideCharToMultiByte 26669->26682 26671 7ff76db22320 _handle_error 8 API calls 26673 7ff76db09764 26671->26673 26674 7ff76db096ef 26672->26674 26684 7ff76db0aa88 45 API calls _snwprintf 26672->26684 26673->26664 26678 7ff76db09800 26673->26678 26685 7ff76db2a270 31 API calls 2 library calls 26674->26685 26677->26671 26679 7ff76db09840 26678->26679 26681 7ff76db09869 26678->26681 26686 7ff76db2a270 31 API calls 2 library calls 26679->26686 26681->26664 26683 7ff76db10faa 26682->26683 26683->26672 26684->26674 26685->26677 26686->26681 26703 7ff76db0d4d0 26687->26703 26691 7ff76db0d8e5 _snwprintf 26699 7ff76db0d974 26691->26699 26717 7ff76db29ef0 26691->26717 26744 7ff76daf9d78 33 API calls 26691->26744 26694 7ff76db0da17 26695 7ff76db22320 _handle_error 8 API calls 26694->26695 26697 7ff76db0da2b 26695->26697 26696 7ff76db0da3f 26698 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 26696->26698 26697->26380 26700 7ff76db0da44 26698->26700 26701 7ff76db0d9a3 26699->26701 26745 7ff76daf9d78 33 API calls 26699->26745 26701->26694 26701->26696 26704 7ff76db0d665 26703->26704 26706 7ff76db0d502 26703->26706 26707 7ff76db0cb80 26704->26707 26705 7ff76daf1744 33 API calls 26705->26706 26706->26704 26706->26705 26708 7ff76db0cc80 26707->26708 26709 7ff76db0cbb6 26707->26709 26747 7ff76daf2004 33 API calls std::_Xinvalid_argument 26708->26747 26712 7ff76db0cc7b 26709->26712 26713 7ff76db0cc20 26709->26713 26715 7ff76db0cbc6 26709->26715 26746 7ff76daf1f80 33 API calls 3 library calls 26712->26746 26713->26715 26716 7ff76db221d0 33 API calls 26713->26716 26715->26691 26716->26715 26718 7ff76db29f4e 26717->26718 26719 7ff76db29f36 26717->26719 26718->26719 26721 7ff76db29f58 26718->26721 26748 7ff76db2d69c 15 API calls _set_errno_from_matherr 26719->26748 26750 7ff76db27ef0 35 API calls 2 library calls 26721->26750 26722 7ff76db29f3b 26749 7ff76db278e4 31 API calls _invalid_parameter_noinfo 26722->26749 26725 7ff76db22320 _handle_error 8 API calls 26727 7ff76db2a10b 26725->26727 26726 7ff76db29f69 memcpy_s 26751 7ff76db27e70 15 API calls _set_errno_from_matherr 26726->26751 26727->26691 26729 7ff76db29fd4 26752 7ff76db282f8 46 API calls 3 library calls 26729->26752 26731 7ff76db29fdd 26732 7ff76db29fe5 26731->26732 26733 7ff76db2a014 26731->26733 26753 7ff76db2d90c 26732->26753 26735 7ff76db2a06c 26733->26735 26736 7ff76db2a092 26733->26736 26737 7ff76db2a023 26733->26737 26741 7ff76db2a01a 26733->26741 26738 7ff76db2d90c Concurrency::details::SchedulerProxy::DeleteThis 15 API calls 26735->26738 26736->26735 26739 7ff76db2a09c 26736->26739 26740 7ff76db2d90c Concurrency::details::SchedulerProxy::DeleteThis 15 API calls 26737->26740 26743 7ff76db29f46 26738->26743 26742 7ff76db2d90c Concurrency::details::SchedulerProxy::DeleteThis 15 API calls 26739->26742 26740->26743 26741->26735 26741->26737 26742->26743 26743->26725 26744->26691 26745->26701 26746->26708 26748->26722 26749->26743 26750->26726 26751->26729 26752->26731 26754 7ff76db2d911 RtlFreeHeap 26753->26754 26756 7ff76db2d941 Concurrency::details::SchedulerProxy::DeleteThis 26753->26756 26755 7ff76db2d92c 26754->26755 26754->26756 26759 7ff76db2d69c 15 API calls _set_errno_from_matherr 26755->26759 26756->26743 26758 7ff76db2d931 GetLastError 26758->26756 26759->26758 26761 7ff76daf20f6 26760->26761 26763 7ff76daf20cb memcpy_s 26760->26763 26764 7ff76daf1474 33 API calls 3 library calls 26761->26764 26763->26392 26764->26763 26766 7ff76db1864f SizeofResource 26765->26766 26767 7ff76db1879b 26765->26767 26766->26767 26768 7ff76db18669 LoadResource 26766->26768 26767->26432 26768->26767 26769 7ff76db18682 LockResource 26768->26769 26769->26767 26770 7ff76db18697 GlobalAlloc 26769->26770 26770->26767 26771 7ff76db186b8 GlobalLock 26770->26771 26772 7ff76db186ca memcpy_s 26771->26772 26773 7ff76db18792 GlobalFree 26771->26773 26774 7ff76db186d8 CreateStreamOnHGlobal 26772->26774 26773->26767 26775 7ff76db18789 GlobalUnlock 26774->26775 26776 7ff76db186f6 GdipAlloc 26774->26776 26775->26773 26777 7ff76db1870b 26776->26777 26777->26775 26778 7ff76db1875a GdipCreateHBITMAPFromBitmap 26777->26778 26779 7ff76db18772 26777->26779 26778->26779 26779->26775 26781 7ff76db184cc 4 API calls 26780->26781 26782 7ff76db184aa 26781->26782 26783 7ff76db184b9 26782->26783 26791 7ff76db18504 GetDC GetDeviceCaps GetDeviceCaps ReleaseDC 26782->26791 26783->26439 26783->26440 26783->26441 26785->26444 26787 7ff76db184e3 26786->26787 26788 7ff76db184de 26786->26788 26790 7ff76db18df4 16 API calls _handle_error 26787->26790 26792 7ff76db18590 GetDC GetDeviceCaps GetDeviceCaps ReleaseDC 26788->26792 26790->26449 26791->26783 26792->26787 26796 7ff76db098fe _snwprintf 26793->26796 26794 7ff76db09973 26911 7ff76db068b0 48 API calls 26794->26911 26796->26794 26798 7ff76db09a89 26796->26798 26797 7ff76daf1fa0 31 API calls 26800 7ff76db099fd 26797->26800 26798->26800 26802 7ff76daf20b0 33 API calls 26798->26802 26799 7ff76db0997d memcpy_s 26799->26797 26801 7ff76db0a42e 26799->26801 26862 7ff76db024c0 26800->26862 26803 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 26801->26803 26802->26800 26805 7ff76db0a434 26803->26805 26808 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 26805->26808 26807 7ff76db09a22 26810 7ff76db0204c 100 API calls 26807->26810 26811 7ff76db0a43a 26808->26811 26809 7ff76db09b17 26880 7ff76db2a450 26809->26880 26812 7ff76db09a2b 26810->26812 26812->26805 26815 7ff76db09a66 26812->26815 26814 7ff76db09aad 26814->26809 26820 7ff76db08e58 33 API calls 26814->26820 26817 7ff76db22320 _handle_error 8 API calls 26815->26817 26819 7ff76db0a40e 26817->26819 26818 7ff76db2a450 31 API calls 26831 7ff76db09b57 __vcrt_FlsAlloc 26818->26831 26819->26452 26820->26814 26821 7ff76db09c89 26822 7ff76db02aa0 101 API calls 26821->26822 26834 7ff76db09d5c 26821->26834 26825 7ff76db09ca1 26822->26825 26826 7ff76db028d0 104 API calls 26825->26826 26825->26834 26832 7ff76db09cc9 26826->26832 26831->26821 26831->26834 26888 7ff76db02bb0 26831->26888 26897 7ff76db028d0 26831->26897 26902 7ff76db02aa0 26831->26902 26832->26834 26854 7ff76db09cd7 __vcrt_FlsAlloc 26832->26854 26912 7ff76db10bbc MultiByteToWideChar 26832->26912 26907 7ff76db0204c 26834->26907 26835 7ff76db0a1ec 26845 7ff76db0a2c2 26835->26845 26918 7ff76db2cf90 31 API calls 2 library calls 26835->26918 26837 7ff76db0a157 26837->26835 26915 7ff76db2cf90 31 API calls 2 library calls 26837->26915 26840 7ff76db0a14b 26840->26452 26841 7ff76db0a2ae 26841->26845 26920 7ff76db08cd0 33 API calls 2 library calls 26841->26920 26842 7ff76db0a249 26919 7ff76db2b7bc 31 API calls _invalid_parameter_noinfo_noreturn 26842->26919 26843 7ff76db0a3a2 26844 7ff76db2a450 31 API calls 26843->26844 26847 7ff76db0a3cb 26844->26847 26845->26843 26851 7ff76db08e58 33 API calls 26845->26851 26849 7ff76db2a450 31 API calls 26847->26849 26848 7ff76db0a16d 26916 7ff76db2b7bc 31 API calls _invalid_parameter_noinfo_noreturn 26848->26916 26849->26834 26851->26845 26852 7ff76db0a1d8 26852->26835 26917 7ff76db08cd0 33 API calls 2 library calls 26852->26917 26854->26834 26854->26835 26854->26837 26854->26840 26855 7ff76db0a429 26854->26855 26857 7ff76db10f68 WideCharToMultiByte 26854->26857 26913 7ff76db0aa88 45 API calls _snwprintf 26854->26913 26914 7ff76db2a270 31 API calls 2 library calls 26854->26914 26921 7ff76db22624 8 API calls 26855->26921 26857->26854 26861 7ff76db0a468 26860->26861 26861->26454 26863 7ff76db024fd CreateFileW 26862->26863 26865 7ff76db025ae GetLastError 26863->26865 26875 7ff76db0266e 26863->26875 26866 7ff76db06a0c 49 API calls 26865->26866 26867 7ff76db025dc 26866->26867 26868 7ff76db025e0 CreateFileW GetLastError 26867->26868 26874 7ff76db0262c 26867->26874 26868->26874 26869 7ff76db026b1 SetFileTime 26873 7ff76db026cf 26869->26873 26870 7ff76db02708 26871 7ff76db22320 _handle_error 8 API calls 26870->26871 26872 7ff76db0271b 26871->26872 26872->26807 26872->26814 26873->26870 26876 7ff76daf20b0 33 API calls 26873->26876 26874->26875 26877 7ff76db02736 26874->26877 26875->26869 26875->26873 26876->26870 26878 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 26877->26878 26879 7ff76db0273b 26878->26879 26881 7ff76db2a47d 26880->26881 26887 7ff76db2a492 26881->26887 26922 7ff76db2d69c 15 API calls _set_errno_from_matherr 26881->26922 26883 7ff76db2a487 26923 7ff76db278e4 31 API calls _invalid_parameter_noinfo 26883->26923 26885 7ff76db22320 _handle_error 8 API calls 26886 7ff76db09b37 26885->26886 26886->26818 26887->26885 26889 7ff76db02be9 26888->26889 26890 7ff76db02bcd 26888->26890 26891 7ff76db02bfb 26889->26891 26893 7ff76db02c01 SetFilePointer 26889->26893 26890->26891 26924 7ff76dafb9c4 99 API calls Concurrency::cancel_current_task 26890->26924 26891->26831 26893->26891 26894 7ff76db02c1e GetLastError 26893->26894 26894->26891 26895 7ff76db02c28 26894->26895 26895->26891 26925 7ff76dafb9c4 99 API calls Concurrency::cancel_current_task 26895->26925 26899 7ff76db028f6 26897->26899 26901 7ff76db028fd 26897->26901 26898 7ff76db02320 GetStdHandle ReadFile GetLastError GetLastError GetFileType 26898->26901 26899->26831 26901->26898 26901->26899 26926 7ff76dafb8a4 99 API calls Concurrency::cancel_current_task 26901->26926 26927 7ff76db02778 26902->26927 26905 7ff76db02ac7 26905->26831 26908 7ff76db02066 26907->26908 26909 7ff76db02072 26907->26909 26908->26909 26935 7ff76db020d0 26908->26935 26911->26799 26912->26854 26913->26854 26914->26854 26915->26848 26916->26852 26917->26835 26918->26842 26919->26841 26920->26845 26921->26801 26922->26883 26923->26887 26933 7ff76db02789 _snwprintf 26927->26933 26928 7ff76db22320 _handle_error 8 API calls 26931 7ff76db0281d 26928->26931 26929 7ff76db027b5 26929->26928 26930 7ff76db02890 SetFilePointer 26930->26929 26932 7ff76db028b8 GetLastError 26930->26932 26931->26905 26934 7ff76dafb9c4 99 API calls Concurrency::cancel_current_task 26931->26934 26932->26929 26933->26929 26933->26930 26936 7ff76db02102 26935->26936 26937 7ff76db020ea 26935->26937 26938 7ff76db02126 26936->26938 26941 7ff76dafb544 99 API calls 26936->26941 26937->26936 26939 7ff76db020f6 CloseHandle 26937->26939 26938->26909 26939->26936 26941->26938 26942->26464 26944->26469 26946 7ff76db2154b 26947 7ff76db214a2 26946->26947 26949 7ff76db21900 26947->26949 26975 7ff76db21558 26949->26975 26952 7ff76db2198b 26953 7ff76db21868 DloadReleaseSectionWriteAccess 6 API calls 26952->26953 26954 7ff76db21998 RaiseException 26953->26954 26955 7ff76db21bb5 26954->26955 26955->26947 26956 7ff76db21a3d LoadLibraryExA 26958 7ff76db21aa9 26956->26958 26959 7ff76db21a54 GetLastError 26956->26959 26957 7ff76db21b85 26983 7ff76db21868 26957->26983 26960 7ff76db21ab4 FreeLibrary 26958->26960 26963 7ff76db21abd 26958->26963 26964 7ff76db21a69 26959->26964 26965 7ff76db21a7e 26959->26965 26960->26963 26961 7ff76db219b4 26961->26956 26961->26957 26961->26958 26961->26963 26962 7ff76db21b1b GetProcAddress 26962->26957 26967 7ff76db21b30 GetLastError 26962->26967 26963->26957 26963->26962 26964->26958 26964->26965 26966 7ff76db21868 DloadReleaseSectionWriteAccess 6 API calls 26965->26966 26969 7ff76db21a8b RaiseException 26966->26969 26970 7ff76db21b45 26967->26970 26969->26955 26970->26957 26971 7ff76db21868 DloadReleaseSectionWriteAccess 6 API calls 26970->26971 26972 7ff76db21b67 RaiseException 26971->26972 26973 7ff76db21558 _com_raise_error 6 API calls 26972->26973 26974 7ff76db21b81 26973->26974 26974->26957 26976 7ff76db215d3 26975->26976 26977 7ff76db2156e 26975->26977 26976->26952 26976->26961 26991 7ff76db21604 26977->26991 26980 7ff76db215ce 26982 7ff76db21604 DloadReleaseSectionWriteAccess 3 API calls 26980->26982 26982->26976 26984 7ff76db21878 26983->26984 26990 7ff76db218d1 26983->26990 26985 7ff76db21604 DloadReleaseSectionWriteAccess 3 API calls 26984->26985 26986 7ff76db2187d 26985->26986 26987 7ff76db218cc 26986->26987 26988 7ff76db217d8 DloadProtectSection 3 API calls 26986->26988 26989 7ff76db21604 DloadReleaseSectionWriteAccess 3 API calls 26987->26989 26988->26987 26989->26990 26990->26955 26992 7ff76db2161f 26991->26992 26993 7ff76db21573 26991->26993 26992->26993 26994 7ff76db21624 GetModuleHandleW 26992->26994 26993->26980 26998 7ff76db217d8 26993->26998 26995 7ff76db2163e GetProcAddress 26994->26995 26997 7ff76db21639 26994->26997 26996 7ff76db21653 GetProcAddress 26995->26996 26995->26997 26996->26997 26997->26993 27001 7ff76db217fa DloadProtectSection 26998->27001 26999 7ff76db21802 26999->26980 27000 7ff76db2183a VirtualProtect 27000->26999 27001->26999 27001->27000 27003 7ff76db216a4 VirtualQuery GetSystemInfo 27001->27003 27003->27000 27004 7ff76db2bf2c 27011 7ff76db2bc34 27004->27011 27016 7ff76db2d440 35 API calls 2 library calls 27011->27016 27013 7ff76db2bc3f 27017 7ff76db2d068 35 API calls abort 27013->27017 27016->27013 27018 7ff76db2d94c 27019 7ff76db2d997 27018->27019 27024 7ff76db2d95b abort 27018->27024 27025 7ff76db2d69c 15 API calls _set_errno_from_matherr 27019->27025 27021 7ff76db2d97e HeapAlloc 27022 7ff76db2d995 27021->27022 27021->27024 27023 7ff76db2bbc0 abort 2 API calls 27023->27024 27024->27019 27024->27021 27024->27023 27025->27022 27026 7ff76db220f0 27027 7ff76db22106 _com_error::_com_error 27026->27027 27032 7ff76db24078 27027->27032 27029 7ff76db22117 27030 7ff76db21900 _com_raise_error 14 API calls 27029->27030 27031 7ff76db22163 27030->27031 27033 7ff76db240b4 RtlPcToFileHeader 27032->27033 27034 7ff76db24097 27032->27034 27035 7ff76db240cc 27033->27035 27036 7ff76db240db RaiseException 27033->27036 27034->27033 27035->27036 27036->27029 27037 7ff76db203e0 27038 7ff76db20497 27037->27038 27039 7ff76db2041f 27037->27039 27040 7ff76db0aae0 48 API calls 27038->27040 27041 7ff76db0aae0 48 API calls 27039->27041 27043 7ff76db204ab 27040->27043 27042 7ff76db20433 27041->27042 27044 7ff76db0da98 48 API calls 27042->27044 27045 7ff76db0da98 48 API calls 27043->27045 27050 7ff76db20442 memcpy_s 27044->27050 27045->27050 27046 7ff76daf1fa0 31 API calls 27047 7ff76db20541 27046->27047 27062 7ff76daf250c 27047->27062 27048 7ff76db205cc 27053 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27048->27053 27049 7ff76db205c6 27052 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27049->27052 27050->27046 27050->27048 27050->27049 27052->27048 27055 7ff76db205d2 27053->27055 27063 7ff76daf2516 SetDlgItemTextW 27062->27063 27064 7ff76daf2513 27062->27064 27064->27063 27065 7ff76db1b190 27408 7ff76daf255c 27065->27408 27067 7ff76db1b1db 27068 7ff76db1b1ef 27067->27068 27069 7ff76db1be93 27067->27069 27117 7ff76db1b20c 27067->27117 27073 7ff76db1b2db 27068->27073 27074 7ff76db1b1ff 27068->27074 27068->27117 27674 7ff76db1f390 27069->27674 27072 7ff76db22320 _handle_error 8 API calls 27078 7ff76db1c350 27072->27078 27075 7ff76db1b391 27073->27075 27081 7ff76db1b2f5 27073->27081 27079 7ff76db1b207 27074->27079 27080 7ff76db1b2a9 27074->27080 27416 7ff76daf22bc GetDlgItem 27075->27416 27076 7ff76db1beba SendMessageW 27077 7ff76db1bec9 27076->27077 27083 7ff76db1bef0 GetDlgItem SendMessageW 27077->27083 27084 7ff76db1bed5 SendDlgItemMessageW 27077->27084 27089 7ff76db0aae0 48 API calls 27079->27089 27079->27117 27085 7ff76db1b2cb EndDialog 27080->27085 27080->27117 27086 7ff76db0aae0 48 API calls 27081->27086 27088 7ff76db062dc 35 API calls 27083->27088 27084->27083 27085->27117 27091 7ff76db1b313 SetDlgItemTextW 27086->27091 27093 7ff76db1bf47 GetDlgItem 27088->27093 27090 7ff76db1b236 27089->27090 27697 7ff76daf1ec4 34 API calls _handle_error 27090->27697 27097 7ff76db1b326 27091->27097 27092 7ff76db1b3b1 EndDialog 27270 7ff76db1b3da 27092->27270 27693 7ff76daf2520 27093->27693 27096 7ff76db1b408 GetDlgItem 27100 7ff76db1b44f SetFocus 27096->27100 27101 7ff76db1b422 SendMessageW SendMessageW 27096->27101 27105 7ff76db1b340 GetMessageW 27097->27105 27097->27117 27099 7ff76db1b246 27104 7ff76db1b25c 27099->27104 27110 7ff76daf250c SetDlgItemTextW 27099->27110 27106 7ff76db1b4f2 27100->27106 27107 7ff76db1b465 27100->27107 27101->27100 27104->27117 27123 7ff76db1c363 27104->27123 27112 7ff76db1b35e IsDialogMessageW 27105->27112 27105->27117 27430 7ff76daf8d04 27106->27430 27113 7ff76db0aae0 48 API calls 27107->27113 27108 7ff76daf1fa0 31 API calls 27108->27117 27110->27104 27112->27097 27118 7ff76db1b373 TranslateMessage DispatchMessageW 27112->27118 27119 7ff76db1b46f 27113->27119 27114 7ff76db1bcc5 27120 7ff76db0aae0 48 API calls 27114->27120 27116 7ff76db1b52c 27440 7ff76db1ef80 27116->27440 27117->27072 27118->27097 27132 7ff76daf129c 33 API calls 27119->27132 27124 7ff76db1bcd6 SetDlgItemTextW 27120->27124 27128 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27123->27128 27127 7ff76db0aae0 48 API calls 27124->27127 27133 7ff76db1bd08 27127->27133 27134 7ff76db1c368 27128->27134 27131 7ff76db0aae0 48 API calls 27136 7ff76db1b555 27131->27136 27137 7ff76db1b498 27132->27137 27145 7ff76daf129c 33 API calls 27133->27145 27139 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27134->27139 27142 7ff76db0da98 48 API calls 27136->27142 27143 7ff76db1f0a4 24 API calls 27137->27143 27146 7ff76db1c36e 27139->27146 27150 7ff76db1b568 27142->27150 27151 7ff76db1b4a5 27143->27151 27178 7ff76db1bd31 27145->27178 27157 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27146->27157 27454 7ff76db1f0a4 27150->27454 27151->27134 27162 7ff76db1b4e8 27151->27162 27156 7ff76db1bdda 27163 7ff76db0aae0 48 API calls 27156->27163 27164 7ff76db1c374 27157->27164 27171 7ff76db1b5ec 27162->27171 27698 7ff76db1fa80 33 API calls 2 library calls 27162->27698 27173 7ff76db1bde4 27163->27173 27184 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27164->27184 27168 7ff76daf1fa0 31 API calls 27176 7ff76db1b586 27168->27176 27181 7ff76db1b61a 27171->27181 27699 7ff76db032a8 27171->27699 27194 7ff76daf129c 33 API calls 27173->27194 27176->27146 27176->27162 27178->27156 27189 7ff76daf129c 33 API calls 27178->27189 27468 7ff76db02f58 27181->27468 27188 7ff76db1c37a 27184->27188 27199 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27188->27199 27196 7ff76db1bd7f 27189->27196 27192 7ff76db1b64c 27480 7ff76db07fc4 27192->27480 27193 7ff76db1b634 GetLastError 27193->27192 27209 7ff76db1be0d 27194->27209 27201 7ff76db0aae0 48 API calls 27196->27201 27210 7ff76db1c380 27199->27210 27205 7ff76db1bd8a 27201->27205 27203 7ff76db1b60e 27702 7ff76db19d90 12 API calls _handle_error 27203->27702 27212 7ff76daf1150 33 API calls 27205->27212 27208 7ff76db1b65e 27214 7ff76db1b674 27208->27214 27215 7ff76db1b665 GetLastError 27208->27215 27216 7ff76daf129c 33 API calls 27209->27216 27217 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27210->27217 27218 7ff76db1bda2 27212->27218 27220 7ff76db1b71c 27214->27220 27224 7ff76db1b68b GetTickCount 27214->27224 27225 7ff76db1b72b 27214->27225 27215->27214 27221 7ff76db1be4e 27216->27221 27222 7ff76db1c386 27217->27222 27227 7ff76daf2034 33 API calls 27218->27227 27220->27225 27242 7ff76db1bb79 27220->27242 27235 7ff76daf1fa0 31 API calls 27221->27235 27226 7ff76daf255c 61 API calls 27222->27226 27483 7ff76daf4228 27224->27483 27231 7ff76db1ba50 27225->27231 27232 7ff76db06454 34 API calls 27225->27232 27230 7ff76db1c3e4 27226->27230 27228 7ff76db1bdbe 27227->27228 27233 7ff76daf1fa0 31 API calls 27228->27233 27236 7ff76db1c3e8 27230->27236 27245 7ff76db1c489 GetDlgItem SetFocus 27230->27245 27290 7ff76db1c3fd 27230->27290 27231->27092 27711 7ff76dafbd0c 33 API calls 27231->27711 27239 7ff76db1b74e 27232->27239 27240 7ff76db1bdcc 27233->27240 27243 7ff76db1be78 27235->27243 27252 7ff76db22320 _handle_error 8 API calls 27236->27252 27703 7ff76db0b914 102 API calls 27239->27703 27247 7ff76daf1fa0 31 API calls 27240->27247 27256 7ff76db0aae0 48 API calls 27242->27256 27250 7ff76daf1fa0 31 API calls 27243->27250 27244 7ff76db1ba75 27712 7ff76daf1150 27244->27712 27248 7ff76db1c4ba 27245->27248 27247->27156 27261 7ff76daf129c 33 API calls 27248->27261 27249 7ff76db1b6ba 27255 7ff76daf1fa0 31 API calls 27249->27255 27257 7ff76db1be83 27250->27257 27259 7ff76db1ca97 27252->27259 27254 7ff76db1b768 27260 7ff76db0da98 48 API calls 27254->27260 27262 7ff76db1b6c8 27255->27262 27263 7ff76db1bba7 SetDlgItemTextW 27256->27263 27264 7ff76daf1fa0 31 API calls 27257->27264 27258 7ff76db1ba8a 27265 7ff76db0aae0 48 API calls 27258->27265 27267 7ff76db1b7aa GetCommandLineW 27260->27267 27268 7ff76db1c4cc 27261->27268 27493 7ff76db02134 27262->27493 27269 7ff76daf2534 27263->27269 27264->27270 27271 7ff76db1ba97 27265->27271 27266 7ff76db1c434 SendDlgItemMessageW 27272 7ff76db1c45d EndDialog 27266->27272 27273 7ff76db1c454 27266->27273 27274 7ff76db1b869 27267->27274 27275 7ff76db1b84f 27267->27275 27716 7ff76db080d8 33 API calls 27268->27716 27277 7ff76db1bbc5 SetDlgItemTextW GetDlgItem 27269->27277 27270->27108 27278 7ff76daf1150 33 API calls 27271->27278 27272->27236 27273->27272 27704 7ff76db1ab54 33 API calls _handle_error 27274->27704 27291 7ff76daf20b0 33 API calls 27275->27291 27282 7ff76db1bbf0 GetWindowLongPtrW SetWindowLongPtrW 27277->27282 27283 7ff76db1bc13 27277->27283 27284 7ff76db1baaa 27278->27284 27279 7ff76db1c4e0 27285 7ff76daf250c SetDlgItemTextW 27279->27285 27282->27283 27509 7ff76db1ce88 27283->27509 27289 7ff76daf1fa0 31 API calls 27284->27289 27292 7ff76db1c4f4 27285->27292 27286 7ff76db1b87a 27705 7ff76db1ab54 33 API calls _handle_error 27286->27705 27297 7ff76db1bab5 27289->27297 27290->27236 27290->27266 27291->27274 27302 7ff76db1c526 SendDlgItemMessageW FindFirstFileW 27292->27302 27294 7ff76db1b704 27299 7ff76db0204c 100 API calls 27294->27299 27295 7ff76db1b6f5 GetLastError 27295->27294 27301 7ff76daf1fa0 31 API calls 27297->27301 27298 7ff76db1b88b 27706 7ff76db1ab54 33 API calls _handle_error 27298->27706 27304 7ff76db1b711 27299->27304 27300 7ff76db1ce88 160 API calls 27305 7ff76db1bc3c 27300->27305 27306 7ff76db1bac3 27301->27306 27307 7ff76db1c57b 27302->27307 27400 7ff76db1ca04 27302->27400 27309 7ff76daf1fa0 31 API calls 27304->27309 27659 7ff76db1f974 27305->27659 27316 7ff76db0aae0 48 API calls 27306->27316 27318 7ff76db0aae0 48 API calls 27307->27318 27308 7ff76db1b89c 27707 7ff76db0b9b4 102 API calls 27308->27707 27309->27220 27313 7ff76db1b8b3 27708 7ff76db1fbdc 33 API calls 27313->27708 27314 7ff76db1ca81 27314->27236 27315 7ff76db1ce88 160 API calls 27329 7ff76db1bc6a 27315->27329 27317 7ff76db1badb 27316->27317 27330 7ff76daf129c 33 API calls 27317->27330 27322 7ff76db1c59e 27318->27322 27320 7ff76db1caa9 27324 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27320->27324 27321 7ff76db1bc96 27673 7ff76daf2298 GetDlgItem EnableWindow 27321->27673 27335 7ff76daf129c 33 API calls 27322->27335 27323 7ff76db1b8d2 CreateFileMappingW 27326 7ff76db1b911 MapViewOfFile 27323->27326 27327 7ff76db1b953 ShellExecuteExW 27323->27327 27328 7ff76db1caae 27324->27328 27709 7ff76db23640 27326->27709 27350 7ff76db1b974 27327->27350 27333 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27328->27333 27329->27321 27334 7ff76db1ce88 160 API calls 27329->27334 27340 7ff76db1bb04 27330->27340 27331 7ff76db1b3f5 27331->27092 27331->27114 27336 7ff76db1cab4 27333->27336 27334->27321 27337 7ff76db1c5cd 27335->27337 27339 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27336->27339 27338 7ff76daf1150 33 API calls 27337->27338 27342 7ff76db1c5e8 27338->27342 27344 7ff76db1caba 27339->27344 27340->27188 27341 7ff76db1bb5a 27340->27341 27345 7ff76daf1fa0 31 API calls 27341->27345 27717 7ff76dafe164 33 API calls 2 library calls 27342->27717 27343 7ff76db1b9c3 27347 7ff76db1b9dc UnmapViewOfFile CloseHandle 27343->27347 27348 7ff76db1b9ef 27343->27348 27352 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27344->27352 27345->27092 27347->27348 27348->27164 27351 7ff76db1ba25 27348->27351 27349 7ff76db1c5ff 27353 7ff76daf1fa0 31 API calls 27349->27353 27350->27343 27354 7ff76db1b9b1 Sleep 27350->27354 27356 7ff76daf1fa0 31 API calls 27351->27356 27355 7ff76db1cac0 27352->27355 27357 7ff76db1c60c 27353->27357 27354->27343 27354->27350 27360 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27355->27360 27358 7ff76db1ba42 27356->27358 27357->27328 27359 7ff76daf1fa0 31 API calls 27357->27359 27361 7ff76daf1fa0 31 API calls 27358->27361 27362 7ff76db1c673 27359->27362 27363 7ff76db1cac6 27360->27363 27361->27231 27364 7ff76daf250c SetDlgItemTextW 27362->27364 27366 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27363->27366 27365 7ff76db1c687 FindClose 27364->27365 27367 7ff76db1c797 SendDlgItemMessageW 27365->27367 27368 7ff76db1c6a3 27365->27368 27369 7ff76db1cacc 27366->27369 27371 7ff76db1c7cb 27367->27371 27718 7ff76db1a2cc 10 API calls _handle_error 27368->27718 27374 7ff76db0aae0 48 API calls 27371->27374 27372 7ff76db1c6c6 27373 7ff76db0aae0 48 API calls 27372->27373 27375 7ff76db1c6cf 27373->27375 27376 7ff76db1c7d8 27374->27376 27377 7ff76db0da98 48 API calls 27375->27377 27378 7ff76daf129c 33 API calls 27376->27378 27382 7ff76db1c6ec memcpy_s 27377->27382 27379 7ff76db1c807 27378->27379 27381 7ff76daf1150 33 API calls 27379->27381 27380 7ff76daf1fa0 31 API calls 27383 7ff76db1c783 27380->27383 27384 7ff76db1c822 27381->27384 27382->27336 27382->27380 27385 7ff76daf250c SetDlgItemTextW 27383->27385 27719 7ff76dafe164 33 API calls 2 library calls 27384->27719 27385->27367 27387 7ff76db1c839 27388 7ff76daf1fa0 31 API calls 27387->27388 27389 7ff76db1c845 memcpy_s 27388->27389 27390 7ff76daf1fa0 31 API calls 27389->27390 27391 7ff76db1c87f 27390->27391 27392 7ff76daf1fa0 31 API calls 27391->27392 27393 7ff76db1c88c 27392->27393 27393->27344 27394 7ff76daf1fa0 31 API calls 27393->27394 27395 7ff76db1c8f3 27394->27395 27396 7ff76daf250c SetDlgItemTextW 27395->27396 27397 7ff76db1c907 27396->27397 27397->27400 27720 7ff76db1a2cc 10 API calls _handle_error 27397->27720 27399 7ff76db1c932 27401 7ff76db0aae0 48 API calls 27399->27401 27400->27236 27400->27314 27400->27320 27400->27363 27402 7ff76db1c93c 27401->27402 27403 7ff76db0da98 48 API calls 27402->27403 27405 7ff76db1c959 memcpy_s 27403->27405 27404 7ff76daf1fa0 31 API calls 27406 7ff76db1c9f0 27404->27406 27405->27355 27405->27404 27407 7ff76daf250c SetDlgItemTextW 27406->27407 27407->27400 27409 7ff76daf25d0 27408->27409 27410 7ff76daf256a 27408->27410 27409->27067 27410->27409 27721 7ff76db0a4ac 27410->27721 27412 7ff76daf258f 27412->27409 27413 7ff76daf25a4 GetDlgItem 27412->27413 27413->27409 27414 7ff76daf25b7 27413->27414 27414->27409 27415 7ff76daf25be SetWindowTextW 27414->27415 27415->27409 27417 7ff76daf2334 27416->27417 27418 7ff76daf22fc 27416->27418 27770 7ff76daf23f8 GetWindowTextLengthW 27417->27770 27420 7ff76daf129c 33 API calls 27418->27420 27421 7ff76daf232a memcpy_s 27420->27421 27423 7ff76daf1fa0 31 API calls 27421->27423 27425 7ff76daf2389 27421->27425 27422 7ff76daf23c8 27424 7ff76db22320 _handle_error 8 API calls 27422->27424 27423->27425 27426 7ff76daf23dd 27424->27426 27425->27422 27427 7ff76daf23f0 27425->27427 27426->27092 27426->27096 27426->27331 27428 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27427->27428 27429 7ff76daf23f5 27428->27429 27431 7ff76daf8d34 27430->27431 27437 7ff76daf8de8 27430->27437 27433 7ff76daf8d42 memcpy_s 27431->27433 27435 7ff76daf8de3 27431->27435 27438 7ff76daf8d91 27431->27438 27433->27116 27782 7ff76daf1f80 33 API calls 3 library calls 27435->27782 27783 7ff76daf2004 33 API calls std::_Xinvalid_argument 27437->27783 27438->27433 27439 7ff76db221d0 33 API calls 27438->27439 27439->27433 27444 7ff76db1efb0 27440->27444 27441 7ff76db1efd7 27442 7ff76db22320 _handle_error 8 API calls 27441->27442 27443 7ff76db1b537 27442->27443 27443->27131 27444->27441 27784 7ff76dafbd0c 33 API calls 27444->27784 27446 7ff76db1f02a 27447 7ff76daf1150 33 API calls 27446->27447 27448 7ff76db1f03f 27447->27448 27450 7ff76daf1fa0 31 API calls 27448->27450 27452 7ff76db1f04f memcpy_s 27448->27452 27449 7ff76daf1fa0 31 API calls 27451 7ff76db1f076 27449->27451 27450->27452 27453 7ff76daf1fa0 31 API calls 27451->27453 27452->27449 27453->27441 27785 7ff76db1ae1c PeekMessageW 27454->27785 27457 7ff76db1f143 SendMessageW SendMessageW 27459 7ff76db1f189 27457->27459 27460 7ff76db1f1a4 SendMessageW 27457->27460 27458 7ff76db1f0f5 27461 7ff76db1f101 ShowWindow SendMessageW SendMessageW 27458->27461 27459->27460 27462 7ff76db1f1c3 27460->27462 27463 7ff76db1f1c6 SendMessageW SendMessageW 27460->27463 27461->27457 27462->27463 27464 7ff76db1f218 SendMessageW 27463->27464 27465 7ff76db1f1f3 SendMessageW 27463->27465 27466 7ff76db22320 _handle_error 8 API calls 27464->27466 27465->27464 27467 7ff76db1b578 27466->27467 27467->27168 27469 7ff76db0309d 27468->27469 27476 7ff76db02f8e 27468->27476 27470 7ff76db22320 _handle_error 8 API calls 27469->27470 27471 7ff76db030b3 27470->27471 27471->27192 27471->27193 27472 7ff76db03077 27472->27469 27473 7ff76db03684 56 API calls 27472->27473 27473->27469 27474 7ff76daf129c 33 API calls 27474->27476 27476->27472 27476->27474 27477 7ff76db030c8 27476->27477 27790 7ff76db03684 27476->27790 27478 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27477->27478 27479 7ff76db030cd 27478->27479 27481 7ff76db07fd2 SetCurrentDirectoryW 27480->27481 27482 7ff76db07fcf 27480->27482 27481->27208 27482->27481 27484 7ff76daf4255 27483->27484 27485 7ff76daf426a 27484->27485 27486 7ff76daf129c 33 API calls 27484->27486 27487 7ff76db22320 _handle_error 8 API calls 27485->27487 27486->27485 27488 7ff76daf42a1 27487->27488 27489 7ff76daf3c84 27488->27489 27490 7ff76daf3cab 27489->27490 27824 7ff76daf710c 27490->27824 27492 7ff76daf3cbb memcpy_s 27492->27249 27496 7ff76db0216a 27493->27496 27494 7ff76db0219e 27497 7ff76db0227f 27494->27497 27499 7ff76db06a0c 49 API calls 27494->27499 27495 7ff76db021b1 CreateFileW 27495->27494 27496->27494 27496->27495 27498 7ff76db022af 27497->27498 27502 7ff76daf20b0 33 API calls 27497->27502 27500 7ff76db22320 _handle_error 8 API calls 27498->27500 27501 7ff76db02209 27499->27501 27503 7ff76db022c4 27500->27503 27504 7ff76db02246 27501->27504 27505 7ff76db0220d CreateFileW 27501->27505 27502->27498 27503->27294 27503->27295 27504->27497 27506 7ff76db022d8 27504->27506 27505->27504 27507 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27506->27507 27508 7ff76db022dd 27507->27508 27836 7ff76db1aa08 27509->27836 27511 7ff76db1d1ee 27512 7ff76daf1fa0 31 API calls 27511->27512 27513 7ff76db1d1f7 27512->27513 27515 7ff76db22320 _handle_error 8 API calls 27513->27515 27514 7ff76db0d22c 33 API calls 27596 7ff76db1cf03 memcpy_s 27514->27596 27516 7ff76db1bc2b 27515->27516 27516->27300 27517 7ff76db1eefa 27960 7ff76daf704c 47 API calls memcpy_s 27517->27960 27520 7ff76db1ef00 27961 7ff76daf704c 47 API calls memcpy_s 27520->27961 27522 7ff76db1ef06 27526 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27522->27526 27524 7ff76db1eeee 27525 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27524->27525 27527 7ff76db1eef4 27525->27527 27528 7ff76db1ef0c 27526->27528 27959 7ff76daf704c 47 API calls memcpy_s 27527->27959 27531 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27528->27531 27533 7ff76db1ef12 27531->27533 27532 7ff76db1ee4a 27534 7ff76db1eed2 27532->27534 27535 7ff76daf20b0 33 API calls 27532->27535 27538 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27533->27538 27957 7ff76daf1f80 33 API calls 3 library calls 27534->27957 27540 7ff76db1ee77 27535->27540 27536 7ff76db1eee8 27958 7ff76daf2004 33 API calls std::_Xinvalid_argument 27536->27958 27537 7ff76daf13a4 33 API calls 27541 7ff76db1dc3a GetTempPathW 27537->27541 27542 7ff76db1ef18 27538->27542 27956 7ff76db1abe8 33 API calls 3 library calls 27540->27956 27541->27596 27550 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27542->27550 27543 7ff76db062dc 35 API calls 27543->27596 27546 7ff76db2bb8c 43 API calls 27546->27596 27548 7ff76db1ee8d 27558 7ff76daf1fa0 31 API calls 27548->27558 27562 7ff76db1eea4 memcpy_s 27548->27562 27549 7ff76daf2520 SetWindowTextW 27549->27596 27552 7ff76db1ef1e 27550->27552 27560 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27552->27560 27554 7ff76daf129c 33 API calls 27554->27596 27555 7ff76daf2034 33 API calls 27555->27596 27556 7ff76db1e7f3 27556->27534 27556->27536 27561 7ff76db221d0 33 API calls 27556->27561 27568 7ff76db1e83b memcpy_s 27556->27568 27557 7ff76daf8d04 33 API calls 27557->27596 27558->27562 27559 7ff76daf1fa0 31 API calls 27559->27534 27563 7ff76db1ef24 27560->27563 27561->27568 27562->27559 27567 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27563->27567 27565 7ff76db1aa08 33 API calls 27565->27596 27566 7ff76db1ef6c 27964 7ff76daf2004 33 API calls std::_Xinvalid_argument 27566->27964 27572 7ff76db1ef2a 27567->27572 27577 7ff76daf20b0 33 API calls 27568->27577 27622 7ff76db1eb8f 27568->27622 27570 7ff76daf1fa0 31 API calls 27570->27532 27571 7ff76db1ef78 27966 7ff76daf2004 33 API calls std::_Xinvalid_argument 27571->27966 27583 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27572->27583 27573 7ff76db1ef72 27965 7ff76daf1f80 33 API calls 3 library calls 27573->27965 27575 7ff76db05820 33 API calls 27575->27596 27576 7ff76db1ef66 27963 7ff76daf1f80 33 API calls 3 library calls 27576->27963 27584 7ff76db1e963 27577->27584 27580 7ff76db1ed40 27580->27571 27580->27573 27587 7ff76db1ed3b memcpy_s 27580->27587 27601 7ff76db221d0 33 API calls 27580->27601 27582 7ff76db1ec2a 27582->27566 27582->27576 27582->27587 27590 7ff76db1ec72 memcpy_s 27582->27590 27598 7ff76db221d0 33 API calls 27582->27598 27588 7ff76db1ef30 27583->27588 27597 7ff76daf129c 33 API calls 27584->27597 27629 7ff76db1ef60 27584->27629 27587->27570 27602 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27588->27602 27589 7ff76db03d34 51 API calls 27589->27596 27879 7ff76db1f4e0 27590->27879 27592 7ff76db1d5e9 GetDlgItem 27599 7ff76daf2520 SetWindowTextW 27592->27599 27594 7ff76db199c8 31 API calls 27594->27596 27596->27511 27596->27514 27596->27517 27596->27520 27596->27522 27596->27524 27596->27527 27596->27528 27596->27532 27596->27533 27596->27537 27596->27542 27596->27543 27596->27546 27596->27549 27596->27552 27596->27554 27596->27555 27596->27556 27596->27557 27596->27563 27596->27565 27596->27572 27596->27575 27596->27588 27596->27589 27596->27594 27605 7ff76db0dc2c 33 API calls 27596->27605 27606 7ff76daf2674 31 API calls 27596->27606 27609 7ff76db05b60 53 API calls 27596->27609 27610 7ff76db1ef36 27596->27610 27612 7ff76db05aa8 33 API calls 27596->27612 27613 7ff76db1d63c SendMessageW 27596->27613 27615 7ff76db03f30 54 API calls 27596->27615 27616 7ff76db1ef3c 27596->27616 27623 7ff76db1ef42 27596->27623 27627 7ff76daf4228 33 API calls 27596->27627 27628 7ff76daf1744 33 API calls 27596->27628 27631 7ff76db032a8 51 API calls 27596->27631 27633 7ff76dafe164 33 API calls 27596->27633 27635 7ff76daf250c SetDlgItemTextW 27596->27635 27639 7ff76db07df4 47 API calls 27596->27639 27640 7ff76daf1150 33 API calls 27596->27640 27646 7ff76db1df99 EndDialog 27596->27646 27648 7ff76db032bc 51 API calls 27596->27648 27651 7ff76daf1fa0 31 API calls 27596->27651 27652 7ff76db1db21 MoveFileW 27596->27652 27656 7ff76db02f58 56 API calls 27596->27656 27657 7ff76daf20b0 33 API calls 27596->27657 27840 7ff76db113c4 CompareStringW 27596->27840 27841 7ff76db1a440 27596->27841 27917 7ff76db0cfa4 35 API calls _invalid_parameter_noinfo_noreturn 27596->27917 27918 7ff76db195b4 33 API calls Concurrency::cancel_current_task 27596->27918 27919 7ff76db20684 31 API calls _invalid_parameter_noinfo_noreturn 27596->27919 27920 7ff76dafdf4c 47 API calls memcpy_s 27596->27920 27921 7ff76db1a834 33 API calls _invalid_parameter_noinfo_noreturn 27596->27921 27922 7ff76db19518 33 API calls 27596->27922 27923 7ff76db1abe8 33 API calls 3 library calls 27596->27923 27924 7ff76db07368 33 API calls 2 library calls 27596->27924 27925 7ff76db04088 33 API calls 27596->27925 27926 7ff76db065b0 33 API calls 3 library calls 27596->27926 27927 7ff76db072cc 27596->27927 27931 7ff76db031bc 27596->27931 27945 7ff76db03ea0 FindClose 27596->27945 27946 7ff76db113f4 CompareStringW 27596->27946 27947 7ff76db19cd0 47 API calls 27596->27947 27948 7ff76db187d8 51 API calls 3 library calls 27596->27948 27949 7ff76db1ab54 33 API calls _handle_error 27596->27949 27950 7ff76db05b08 CompareStringW 27596->27950 27951 7ff76db07eb0 47 API calls 27596->27951 27603 7ff76db1e9a6 27597->27603 27598->27590 27604 7ff76db1d608 SendMessageW 27599->27604 27601->27587 27602->27610 27952 7ff76db0d22c 27603->27952 27604->27596 27605->27596 27606->27596 27609->27596 27611 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27610->27611 27611->27616 27612->27596 27613->27596 27615->27596 27619 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27616->27619 27619->27623 27621 7ff76db1ef54 27625 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27621->27625 27622->27580 27622->27582 27622->27621 27624 7ff76db1ef5a 27622->27624 27630 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27623->27630 27626 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27624->27626 27625->27624 27626->27629 27627->27596 27628->27596 27962 7ff76daf704c 47 API calls memcpy_s 27629->27962 27632 7ff76db1ef48 27630->27632 27631->27596 27634 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27632->27634 27633->27596 27636 7ff76db1ef4e 27634->27636 27635->27596 27641 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27636->27641 27637 7ff76daf129c 33 API calls 27649 7ff76db1e9d1 27637->27649 27639->27596 27640->27596 27641->27621 27642 7ff76db113c4 CompareStringW 27642->27649 27644 7ff76daf1fa0 31 API calls 27644->27649 27646->27596 27648->27596 27649->27622 27649->27632 27649->27636 27649->27637 27649->27642 27649->27644 27650 7ff76db0d22c 33 API calls 27649->27650 27650->27649 27651->27596 27653 7ff76db1db70 27652->27653 27654 7ff76db1db55 MoveFileExW 27652->27654 27653->27596 27655 7ff76daf1fa0 31 API calls 27653->27655 27654->27653 27655->27653 27656->27596 27657->27596 27660 7ff76db1f9a3 27659->27660 27661 7ff76daf20b0 33 API calls 27660->27661 27662 7ff76db1f9b9 27661->27662 27663 7ff76db1f9ee 27662->27663 27664 7ff76daf20b0 33 API calls 27662->27664 27978 7ff76dafe34c 27663->27978 27664->27663 27666 7ff76db1fa4b 27998 7ff76dafe7a8 27666->27998 27670 7ff76db1fa61 27671 7ff76db22320 _handle_error 8 API calls 27670->27671 27672 7ff76db1bc52 27671->27672 27672->27315 27675 7ff76db1849c 4 API calls 27674->27675 27676 7ff76db1f3bf 27675->27676 27677 7ff76db1f4b7 27676->27677 27678 7ff76db1f3c7 GetWindow 27676->27678 27679 7ff76db22320 _handle_error 8 API calls 27677->27679 27683 7ff76db1f3e2 27678->27683 27680 7ff76db1be9b 27679->27680 27680->27076 27680->27077 27681 7ff76db1f3ee GetClassNameW 29018 7ff76db113c4 CompareStringW 27681->29018 27683->27677 27683->27681 27684 7ff76db1f417 GetWindowLongPtrW 27683->27684 27685 7ff76db1f496 GetWindow 27683->27685 27684->27685 27686 7ff76db1f429 SendMessageW 27684->27686 27685->27677 27685->27683 27686->27685 27687 7ff76db1f445 GetObjectW 27686->27687 29019 7ff76db18504 GetDC GetDeviceCaps GetDeviceCaps ReleaseDC 27687->29019 27689 7ff76db1f461 27690 7ff76db184cc 4 API calls 27689->27690 29020 7ff76db18df4 16 API calls _handle_error 27689->29020 27690->27689 27692 7ff76db1f479 SendMessageW DeleteObject 27692->27685 27694 7ff76daf252a SetWindowTextW 27693->27694 27695 7ff76daf2527 27693->27695 27696 7ff76db5e2e0 27694->27696 27695->27694 27697->27099 27698->27171 27700 7ff76db032bc 51 API calls 27699->27700 27701 7ff76db032b1 27700->27701 27701->27181 27701->27203 27702->27181 27703->27254 27704->27286 27705->27298 27706->27308 27707->27313 27708->27323 27710 7ff76db23620 27709->27710 27710->27327 27711->27244 27713 7ff76daf1177 27712->27713 27714 7ff76daf2034 33 API calls 27713->27714 27715 7ff76daf1185 memcpy_s 27714->27715 27715->27258 27716->27279 27717->27349 27718->27372 27719->27387 27720->27399 27722 7ff76db03e28 swprintf 46 API calls 27721->27722 27723 7ff76db0a509 27722->27723 27724 7ff76db10f68 WideCharToMultiByte 27723->27724 27726 7ff76db0a519 27724->27726 27725 7ff76db0a589 27746 7ff76db09408 27725->27746 27726->27725 27738 7ff76db09800 31 API calls 27726->27738 27743 7ff76db0a56a SetDlgItemTextW 27726->27743 27729 7ff76db0a6f2 GetSystemMetrics GetWindow 27731 7ff76db0a821 27729->27731 27744 7ff76db0a71d 27729->27744 27730 7ff76db0a603 27732 7ff76db0a60c GetWindowLongPtrW 27730->27732 27733 7ff76db0a6c2 27730->27733 27735 7ff76db22320 _handle_error 8 API calls 27731->27735 27736 7ff76db5e2c0 27732->27736 27761 7ff76db095a8 27733->27761 27739 7ff76db0a830 27735->27739 27740 7ff76db0a6aa GetWindowRect 27736->27740 27738->27726 27739->27412 27740->27733 27741 7ff76db0a6e5 SetWindowTextW 27741->27729 27742 7ff76db0a73e GetWindowRect 27742->27744 27743->27726 27744->27731 27744->27742 27745 7ff76db0a800 GetWindow 27744->27745 27745->27731 27745->27744 27747 7ff76db095a8 47 API calls 27746->27747 27750 7ff76db0944f 27747->27750 27748 7ff76db22320 _handle_error 8 API calls 27749 7ff76db0958e GetWindowRect GetClientRect 27748->27749 27749->27729 27749->27730 27751 7ff76daf129c 33 API calls 27750->27751 27758 7ff76db0955a 27750->27758 27752 7ff76db0949c 27751->27752 27753 7ff76db095a1 27752->27753 27755 7ff76daf129c 33 API calls 27752->27755 27754 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27753->27754 27756 7ff76db095a7 27754->27756 27757 7ff76db09514 27755->27757 27757->27758 27759 7ff76db0959c 27757->27759 27758->27748 27760 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27759->27760 27760->27753 27762 7ff76db03e28 swprintf 46 API calls 27761->27762 27763 7ff76db095eb 27762->27763 27764 7ff76db10f68 WideCharToMultiByte 27763->27764 27765 7ff76db09603 27764->27765 27766 7ff76db09800 31 API calls 27765->27766 27767 7ff76db0961b 27766->27767 27768 7ff76db22320 _handle_error 8 API calls 27767->27768 27769 7ff76db0962b 27768->27769 27769->27729 27769->27741 27771 7ff76daf13a4 33 API calls 27770->27771 27772 7ff76daf2462 GetWindowTextW 27771->27772 27773 7ff76daf2494 27772->27773 27774 7ff76daf129c 33 API calls 27773->27774 27775 7ff76daf24a2 27774->27775 27777 7ff76daf2505 27775->27777 27779 7ff76daf24dd 27775->27779 27776 7ff76db22320 _handle_error 8 API calls 27778 7ff76daf24f3 27776->27778 27780 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27777->27780 27778->27421 27779->27776 27781 7ff76daf250a 27780->27781 27782->27437 27784->27446 27786 7ff76db1ae3c GetMessageW 27785->27786 27787 7ff76db1ae80 GetDlgItem 27785->27787 27788 7ff76db1ae6a TranslateMessage DispatchMessageW 27786->27788 27789 7ff76db1ae5b IsDialogMessageW 27786->27789 27787->27457 27787->27458 27788->27787 27789->27787 27789->27788 27792 7ff76db036b3 27790->27792 27791 7ff76db036e0 27793 7ff76db032bc 51 API calls 27791->27793 27792->27791 27794 7ff76db036cc CreateDirectoryW 27792->27794 27796 7ff76db036ee 27793->27796 27794->27791 27797 7ff76db0377d 27794->27797 27795 7ff76db03791 GetLastError 27798 7ff76db0378d 27795->27798 27796->27795 27799 7ff76db06a0c 49 API calls 27796->27799 27797->27798 27810 7ff76db03d34 27797->27810 27801 7ff76db22320 _handle_error 8 API calls 27798->27801 27802 7ff76db0371c 27799->27802 27803 7ff76db037b9 27801->27803 27804 7ff76db03720 CreateDirectoryW 27802->27804 27805 7ff76db0373b 27802->27805 27803->27476 27804->27805 27806 7ff76db03774 27805->27806 27807 7ff76db037ce 27805->27807 27806->27795 27806->27797 27808 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27807->27808 27809 7ff76db037d3 27808->27809 27811 7ff76db03d5e SetFileAttributesW 27810->27811 27812 7ff76db03d5b 27810->27812 27813 7ff76db03d74 27811->27813 27820 7ff76db03df5 27811->27820 27812->27811 27814 7ff76db06a0c 49 API calls 27813->27814 27816 7ff76db03d99 27814->27816 27815 7ff76db22320 _handle_error 8 API calls 27817 7ff76db03e0a 27815->27817 27818 7ff76db03d9d SetFileAttributesW 27816->27818 27819 7ff76db03dbc 27816->27819 27817->27798 27818->27819 27819->27820 27821 7ff76db03e1a 27819->27821 27820->27815 27822 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27821->27822 27823 7ff76db03e1f 27822->27823 27825 7ff76daf7206 27824->27825 27826 7ff76daf713b 27824->27826 27834 7ff76daf704c 47 API calls memcpy_s 27825->27834 27828 7ff76daf714b memcpy_s 27826->27828 27833 7ff76daf3f48 33 API calls 2 library calls 27826->27833 27828->27492 27830 7ff76daf7273 27830->27492 27831 7ff76daf720b 27831->27830 27835 7ff76daf889c 8 API calls memcpy_s 27831->27835 27833->27828 27834->27831 27835->27831 27837 7ff76db1aa2f 27836->27837 27838 7ff76db1aa36 27836->27838 27837->27596 27838->27837 27839 7ff76daf1744 33 API calls 27838->27839 27839->27838 27840->27596 27842 7ff76db1a706 27841->27842 27843 7ff76db1a47f 27841->27843 27845 7ff76db22320 _handle_error 8 API calls 27842->27845 27967 7ff76db1cdf8 33 API calls 27843->27967 27847 7ff76db1a717 27845->27847 27846 7ff76db1a49e 27848 7ff76daf129c 33 API calls 27846->27848 27847->27592 27849 7ff76db1a4de 27848->27849 27850 7ff76daf129c 33 API calls 27849->27850 27851 7ff76db1a517 27850->27851 27852 7ff76daf129c 33 API calls 27851->27852 27853 7ff76db1a54a 27852->27853 27968 7ff76db1a834 33 API calls _invalid_parameter_noinfo_noreturn 27853->27968 27855 7ff76db1a734 27856 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27855->27856 27857 7ff76db1a73a 27856->27857 27859 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27857->27859 27858 7ff76db1a573 27858->27855 27858->27857 27860 7ff76db1a740 27858->27860 27861 7ff76daf20b0 33 API calls 27858->27861 27864 7ff76db1a685 27858->27864 27859->27860 27862 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27860->27862 27861->27864 27863 7ff76db1a746 27862->27863 27866 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27863->27866 27864->27842 27864->27863 27865 7ff76db1a72f 27864->27865 27867 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27865->27867 27868 7ff76db1a74c 27866->27868 27867->27855 27869 7ff76daf255c 61 API calls 27868->27869 27870 7ff76db1a795 27869->27870 27871 7ff76db1a7b1 27870->27871 27872 7ff76db1a801 SetDlgItemTextW 27870->27872 27876 7ff76db1a7a1 27870->27876 27873 7ff76db22320 _handle_error 8 API calls 27871->27873 27872->27871 27874 7ff76db1a827 27873->27874 27874->27592 27875 7ff76db1a7ad 27875->27871 27877 7ff76db1a7b7 EndDialog 27875->27877 27876->27871 27876->27875 27969 7ff76db0bb00 102 API calls 27876->27969 27877->27871 27880 7ff76db1f529 memcpy_s 27879->27880 27895 7ff76db1f87d 27879->27895 27885 7ff76db1f684 27880->27885 27970 7ff76db113c4 CompareStringW 27880->27970 27881 7ff76daf1fa0 31 API calls 27882 7ff76db1f89c 27881->27882 27883 7ff76db22320 _handle_error 8 API calls 27882->27883 27884 7ff76db1f8a8 27883->27884 27884->27587 27887 7ff76daf129c 33 API calls 27885->27887 27888 7ff76db1f6c0 27887->27888 27889 7ff76db032a8 51 API calls 27888->27889 27890 7ff76db1f6ca 27889->27890 27891 7ff76daf1fa0 31 API calls 27890->27891 27894 7ff76db1f6d5 27891->27894 27892 7ff76db1f742 ShellExecuteExW 27893 7ff76db1f846 27892->27893 27898 7ff76db1f755 27892->27898 27893->27895 27900 7ff76db1f8fb 27893->27900 27894->27892 27896 7ff76daf129c 33 API calls 27894->27896 27895->27881 27899 7ff76db1f717 27896->27899 27897 7ff76db1f78e 27972 7ff76db1fe24 PeekMessageW GetMessageW TranslateMessage DispatchMessageW WaitForSingleObject 27897->27972 27898->27897 27901 7ff76db1f7e3 CloseHandle 27898->27901 27906 7ff76db1f781 ShowWindow 27898->27906 27971 7ff76db05b60 53 API calls 2 library calls 27899->27971 27903 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27900->27903 27904 7ff76db1f7f2 27901->27904 27905 7ff76db1f801 27901->27905 27909 7ff76db1f900 27903->27909 27973 7ff76db113c4 CompareStringW 27904->27973 27905->27893 27913 7ff76db1f837 ShowWindow 27905->27913 27906->27897 27908 7ff76db1f725 27912 7ff76daf1fa0 31 API calls 27908->27912 27911 7ff76db1f7a6 27911->27901 27915 7ff76db1f7b4 GetExitCodeProcess 27911->27915 27914 7ff76db1f72f 27912->27914 27913->27893 27914->27892 27915->27901 27916 7ff76db1f7c7 27915->27916 27916->27901 27917->27596 27918->27596 27919->27596 27920->27596 27921->27596 27922->27596 27923->27596 27924->27596 27925->27596 27926->27596 27928 7ff76db072ea 27927->27928 27974 7ff76dafb3a8 27928->27974 27932 7ff76db031e4 27931->27932 27933 7ff76db031e7 DeleteFileW 27931->27933 27932->27933 27934 7ff76db031fd 27933->27934 27941 7ff76db0327c 27933->27941 27936 7ff76db06a0c 49 API calls 27934->27936 27935 7ff76db22320 _handle_error 8 API calls 27937 7ff76db03291 27935->27937 27938 7ff76db03222 27936->27938 27937->27596 27939 7ff76db03226 DeleteFileW 27938->27939 27940 7ff76db03243 27938->27940 27939->27940 27940->27941 27942 7ff76db032a1 27940->27942 27941->27935 27943 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27942->27943 27944 7ff76db032a6 27943->27944 27946->27596 27947->27596 27948->27596 27949->27596 27950->27596 27951->27596 27953 7ff76db0d25e 27952->27953 27954 7ff76db0d292 27953->27954 27955 7ff76daf1744 33 API calls 27953->27955 27954->27649 27955->27953 27956->27548 27957->27536 27959->27517 27960->27520 27961->27522 27962->27576 27963->27566 27965->27571 27967->27846 27968->27858 27969->27875 27970->27885 27971->27908 27972->27911 27973->27905 27977 7ff76dafb3f2 memcpy_s 27974->27977 27975 7ff76db22320 _handle_error 8 API calls 27976 7ff76dafb4b6 27975->27976 27976->27596 27977->27975 28034 7ff76db086ec 27978->28034 27980 7ff76dafe3c4 28040 7ff76dafe600 27980->28040 27982 7ff76dafe4d4 27985 7ff76db221d0 33 API calls 27982->27985 27983 7ff76dafe549 27986 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27983->27986 27984 7ff76dafe454 27984->27982 27984->27983 27987 7ff76dafe4f0 27985->27987 27995 7ff76dafe54e 27986->27995 28046 7ff76db13148 102 API calls 27987->28046 27989 7ff76dafe51d 27990 7ff76db22320 _handle_error 8 API calls 27989->27990 27991 7ff76dafe52d 27990->27991 27991->27666 27992 7ff76db018c2 27993 7ff76db0190d 27992->27993 27996 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 27992->27996 27993->27666 27994 7ff76daf1fa0 31 API calls 27994->27995 27995->27992 27995->27993 27995->27994 27997 7ff76db0193b 27996->27997 27999 7ff76dafe7ea 27998->27999 28000 7ff76dafe864 27999->28000 28002 7ff76dafe8a1 27999->28002 28047 7ff76db03ec8 27999->28047 28000->28002 28003 7ff76dafe993 28000->28003 28010 7ff76dafe900 28002->28010 28054 7ff76daff578 28002->28054 28004 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 28003->28004 28007 7ff76dafe998 28004->28007 28005 7ff76dafe955 28006 7ff76db22320 _handle_error 8 API calls 28005->28006 28009 7ff76dafe97e 28006->28009 28012 7ff76dafe578 28009->28012 28010->28005 28090 7ff76daf28a4 82 API calls 2 library calls 28010->28090 29004 7ff76db015d8 28012->29004 28015 7ff76dafe59e 28016 7ff76daf1fa0 31 API calls 28015->28016 28018 7ff76dafe5b7 28016->28018 28017 7ff76db11870 108 API calls 28017->28015 28019 7ff76daf1fa0 31 API calls 28018->28019 28020 7ff76dafe5c3 28019->28020 28021 7ff76daf1fa0 31 API calls 28020->28021 28022 7ff76dafe5cf 28021->28022 28023 7ff76db0878c 108 API calls 28022->28023 28024 7ff76dafe5db 28023->28024 28025 7ff76daf1fa0 31 API calls 28024->28025 28026 7ff76dafe5e4 28025->28026 28027 7ff76daf1fa0 31 API calls 28026->28027 28031 7ff76dafe5ed 28027->28031 28028 7ff76db018c2 28029 7ff76db0190d 28028->28029 28032 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 28028->28032 28029->27670 28030 7ff76daf1fa0 31 API calls 28030->28031 28031->28028 28031->28029 28031->28030 28033 7ff76db0193b 28032->28033 28035 7ff76db0870a 28034->28035 28036 7ff76db221d0 33 API calls 28035->28036 28037 7ff76db0872f 28036->28037 28038 7ff76db221d0 33 API calls 28037->28038 28039 7ff76db08759 28038->28039 28039->27980 28041 7ff76dafe627 28040->28041 28043 7ff76dafe62c memcpy_s 28040->28043 28042 7ff76daf1fa0 31 API calls 28041->28042 28042->28043 28044 7ff76daf1fa0 31 API calls 28043->28044 28045 7ff76dafe668 memcpy_s 28043->28045 28044->28045 28045->27984 28046->27989 28048 7ff76db072cc 8 API calls 28047->28048 28049 7ff76db03ee1 28048->28049 28053 7ff76db03f0f 28049->28053 28091 7ff76db040bc 28049->28091 28052 7ff76db03efa FindClose 28052->28053 28053->27999 28055 7ff76daff598 _snwprintf 28054->28055 28117 7ff76daf2950 28055->28117 28058 7ff76daff5cc 28062 7ff76daff5fc 28058->28062 28132 7ff76daf33e4 28058->28132 28061 7ff76daff5f8 28061->28062 28164 7ff76daf3ad8 28061->28164 28383 7ff76daf2c54 28062->28383 28069 7ff76daff7cb 28174 7ff76daff8a4 28069->28174 28071 7ff76daf8d04 33 API calls 28072 7ff76daff662 28071->28072 28403 7ff76db07918 48 API calls 2 library calls 28072->28403 28074 7ff76daff677 28075 7ff76db03ec8 55 API calls 28074->28075 28080 7ff76daff6ad 28075->28080 28076 7ff76daff842 28076->28062 28195 7ff76daf69f8 28076->28195 28206 7ff76daff930 28076->28206 28083 7ff76daff74d 28080->28083 28084 7ff76daff89a 28080->28084 28086 7ff76db03ec8 55 API calls 28080->28086 28404 7ff76db07918 48 API calls 2 library calls 28080->28404 28083->28069 28083->28084 28085 7ff76daff895 28083->28085 28087 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 28084->28087 28089 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 28085->28089 28086->28080 28088 7ff76daff8a0 28087->28088 28089->28084 28090->28005 28092 7ff76db041d2 FindNextFileW 28091->28092 28093 7ff76db040f9 FindFirstFileW 28091->28093 28095 7ff76db041f3 28092->28095 28096 7ff76db041e1 GetLastError 28092->28096 28093->28095 28097 7ff76db0411e 28093->28097 28099 7ff76db04211 28095->28099 28102 7ff76daf20b0 33 API calls 28095->28102 28098 7ff76db041c0 28096->28098 28100 7ff76db06a0c 49 API calls 28097->28100 28103 7ff76db22320 _handle_error 8 API calls 28098->28103 28107 7ff76daf129c 33 API calls 28099->28107 28101 7ff76db04144 28100->28101 28104 7ff76db04148 FindFirstFileW 28101->28104 28105 7ff76db04167 28101->28105 28102->28099 28106 7ff76db03ef4 28103->28106 28104->28105 28105->28095 28109 7ff76db041af GetLastError 28105->28109 28116 7ff76db04314 28105->28116 28106->28052 28106->28053 28108 7ff76db0423b 28107->28108 28110 7ff76db08090 47 API calls 28108->28110 28109->28098 28111 7ff76db04249 28110->28111 28111->28098 28114 7ff76db0430f 28111->28114 28112 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 28113 7ff76db0431a 28112->28113 28115 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 28114->28115 28115->28116 28116->28112 28118 7ff76daf296c 28117->28118 28119 7ff76db086ec 33 API calls 28118->28119 28120 7ff76daf298d 28119->28120 28121 7ff76db221d0 33 API calls 28120->28121 28124 7ff76daf2ac2 28120->28124 28122 7ff76daf2ab0 28121->28122 28122->28124 28126 7ff76daf91c8 35 API calls 28122->28126 28405 7ff76db04d04 28124->28405 28126->28124 28127 7ff76db02ca8 28131 7ff76db024c0 54 API calls 28127->28131 28128 7ff76db02cc1 28129 7ff76db02cc5 28128->28129 28419 7ff76dafb7e8 99 API calls 2 library calls 28128->28419 28129->28058 28131->28128 28159 7ff76db028d0 104 API calls 28132->28159 28133 7ff76daf3674 28420 7ff76daf28a4 82 API calls 2 library calls 28133->28420 28134 7ff76daf3431 memcpy_s 28141 7ff76daf344e 28134->28141 28144 7ff76daf3601 28134->28144 28156 7ff76db02bb0 101 API calls 28134->28156 28136 7ff76daf69f8 132 API calls 28138 7ff76daf3682 28136->28138 28137 7ff76daf34cc 28160 7ff76db028d0 104 API calls 28137->28160 28138->28136 28139 7ff76daf370c 28138->28139 28138->28144 28161 7ff76db02aa0 101 API calls 28138->28161 28143 7ff76daf3740 28139->28143 28139->28144 28421 7ff76daf28a4 82 API calls 2 library calls 28139->28421 28141->28133 28141->28138 28142 7ff76daf35cb 28142->28141 28145 7ff76daf35d7 28142->28145 28143->28144 28148 7ff76daf384d 28143->28148 28162 7ff76db02bb0 101 API calls 28143->28162 28144->28061 28145->28144 28146 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 28145->28146 28149 7ff76daf3891 28146->28149 28147 7ff76daf34eb 28147->28142 28158 7ff76db02aa0 101 API calls 28147->28158 28148->28144 28150 7ff76daf20b0 33 API calls 28148->28150 28149->28061 28150->28144 28151 7ff76daf69f8 132 API calls 28153 7ff76daf378e 28151->28153 28152 7ff76daf35a7 28152->28142 28163 7ff76db028d0 104 API calls 28152->28163 28153->28151 28154 7ff76daf3803 28153->28154 28155 7ff76db02aa0 101 API calls 28153->28155 28157 7ff76db02aa0 101 API calls 28154->28157 28155->28153 28156->28137 28157->28148 28158->28152 28159->28134 28160->28147 28161->28138 28162->28153 28163->28142 28165 7ff76daf3af9 28164->28165 28170 7ff76daf3b55 28164->28170 28422 7ff76daf3378 28165->28422 28167 7ff76db22320 _handle_error 8 API calls 28169 7ff76daf3b67 28167->28169 28169->28069 28169->28071 28170->28167 28171 7ff76daf3b6c 28172 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 28171->28172 28173 7ff76daf3b71 28172->28173 28647 7ff76db0886c 28174->28647 28176 7ff76daff8ba 28651 7ff76db0ef60 GetSystemTime SystemTimeToFileTime 28176->28651 28179 7ff76db10994 28180 7ff76db20340 28179->28180 28181 7ff76db07df4 47 API calls 28180->28181 28182 7ff76db20373 28181->28182 28183 7ff76db0aae0 48 API calls 28182->28183 28184 7ff76db20387 28183->28184 28185 7ff76db0da98 48 API calls 28184->28185 28186 7ff76db20397 28185->28186 28187 7ff76daf1fa0 31 API calls 28186->28187 28188 7ff76db203a2 28187->28188 28660 7ff76db1fc68 28188->28660 28196 7ff76daf6a0e 28195->28196 28204 7ff76daf6a0a 28195->28204 28205 7ff76db02bb0 101 API calls 28196->28205 28197 7ff76daf6a1b 28198 7ff76daf6a2f 28197->28198 28199 7ff76daf6a3e 28197->28199 28198->28204 28672 7ff76daf5e24 28198->28672 28734 7ff76daf5130 130 API calls 2 library calls 28199->28734 28202 7ff76daf6a3c 28202->28204 28735 7ff76daf466c 82 API calls 28202->28735 28204->28076 28205->28197 28207 7ff76daff978 28206->28207 28210 7ff76daff9b0 28207->28210 28264 7ff76daffa34 28207->28264 28849 7ff76db1612c 137 API calls 3 library calls 28207->28849 28209 7ff76db01189 28211 7ff76db011e1 28209->28211 28212 7ff76db0118e 28209->28212 28210->28209 28217 7ff76daff9d0 28210->28217 28210->28264 28211->28264 28898 7ff76db1612c 137 API calls 3 library calls 28211->28898 28212->28264 28897 7ff76dafdd08 179 API calls 28212->28897 28213 7ff76db22320 _handle_error 8 API calls 28214 7ff76db011c4 28213->28214 28214->28076 28217->28264 28764 7ff76daf9bb0 28217->28764 28219 7ff76daffad6 28777 7ff76db05ef8 28219->28777 28222 7ff76daffb7a 28382 7ff76db02aa0 101 API calls 28222->28382 28224 7ff76daffb5e 28224->28222 28851 7ff76db07c94 47 API calls 2 library calls 28224->28851 28264->28213 28384 7ff76daf2c88 28383->28384 28385 7ff76daf2c74 28383->28385 28386 7ff76daf1fa0 31 API calls 28384->28386 28385->28384 28983 7ff76daf2d80 108 API calls _invalid_parameter_noinfo_noreturn 28385->28983 28388 7ff76daf2ca1 28386->28388 28390 7ff76daf2d64 28388->28390 28984 7ff76daf3090 31 API calls _invalid_parameter_noinfo_noreturn 28388->28984 28392 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 28390->28392 28391 7ff76daf2d08 28985 7ff76daf3090 31 API calls _invalid_parameter_noinfo_noreturn 28391->28985 28394 7ff76daf2d7c 28392->28394 28395 7ff76daf2d14 28396 7ff76daf1fa0 31 API calls 28395->28396 28397 7ff76daf2d20 28396->28397 28986 7ff76db0878c 28397->28986 28403->28074 28404->28080 28406 7ff76db04d32 memcpy_s 28405->28406 28415 7ff76db04bac 28406->28415 28408 7ff76db04d54 28409 7ff76db04d90 28408->28409 28411 7ff76db04dae 28408->28411 28410 7ff76db22320 _handle_error 8 API calls 28409->28410 28412 7ff76daf2b32 28410->28412 28413 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 28411->28413 28412->28058 28412->28127 28414 7ff76db04db3 28413->28414 28416 7ff76db04c2f memcpy_s 28415->28416 28417 7ff76db04c27 28415->28417 28416->28408 28418 7ff76daf1fa0 31 API calls 28417->28418 28418->28416 28419->28129 28420->28144 28421->28143 28423 7ff76daf339a 28422->28423 28424 7ff76daf3396 28422->28424 28428 7ff76daf3294 28423->28428 28424->28170 28424->28171 28427 7ff76db02aa0 101 API calls 28427->28424 28429 7ff76daf32f6 28428->28429 28430 7ff76daf32bb 28428->28430 28436 7ff76daf6e74 28429->28436 28431 7ff76daf69f8 132 API calls 28430->28431 28434 7ff76daf32db 28431->28434 28434->28427 28438 7ff76daf6e95 28436->28438 28437 7ff76daf69f8 132 API calls 28437->28438 28438->28437 28440 7ff76daf331d 28438->28440 28468 7ff76db0e808 28438->28468 28440->28434 28441 7ff76daf3904 28440->28441 28476 7ff76daf6a7c 28441->28476 28444 7ff76daf396a 28447 7ff76daf3989 28444->28447 28448 7ff76daf399a 28444->28448 28445 7ff76daf3a8a 28449 7ff76db22320 _handle_error 8 API calls 28445->28449 28508 7ff76db10d54 28447->28508 28452 7ff76daf39a3 28448->28452 28456 7ff76daf39ec 28448->28456 28451 7ff76daf3a9e 28449->28451 28451->28434 28513 7ff76db10c80 33 API calls 28452->28513 28453 7ff76daf3ab3 28454 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 28453->28454 28457 7ff76daf3ab8 28454->28457 28514 7ff76daf26b4 33 API calls memcpy_s 28456->28514 28461 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 28457->28461 28458 7ff76daf39b0 28462 7ff76daf1fa0 31 API calls 28458->28462 28466 7ff76daf39c0 memcpy_s 28458->28466 28460 7ff76daf3a13 28515 7ff76db10ae8 34 API calls _invalid_parameter_noinfo_noreturn 28460->28515 28465 7ff76daf3abe 28461->28465 28462->28466 28463 7ff76daf1fa0 31 API calls 28467 7ff76daf394f 28463->28467 28466->28463 28467->28445 28467->28453 28467->28457 28469 7ff76db0e811 28468->28469 28470 7ff76db0e82b 28469->28470 28474 7ff76dafb664 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task 28469->28474 28471 7ff76db0e845 SetThreadExecutionState 28470->28471 28475 7ff76dafb664 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task 28470->28475 28474->28470 28475->28471 28477 7ff76daf6a96 _snwprintf 28476->28477 28478 7ff76daf6ae4 28477->28478 28479 7ff76daf6ac4 28477->28479 28481 7ff76daf6d4d 28478->28481 28484 7ff76daf6b0f 28478->28484 28554 7ff76daf28a4 82 API calls 2 library calls 28479->28554 28583 7ff76daf28a4 82 API calls 2 library calls 28481->28583 28483 7ff76daf6ad0 28485 7ff76db22320 _handle_error 8 API calls 28483->28485 28484->28483 28516 7ff76db11f94 28484->28516 28486 7ff76daf394b 28485->28486 28486->28444 28486->28467 28512 7ff76daf2794 33 API calls __std_swap_ranges_trivially_swappable 28486->28512 28489 7ff76daf6b85 28490 7ff76daf6c2a 28489->28490 28507 7ff76daf6b7b 28489->28507 28560 7ff76db08968 109 API calls 28489->28560 28525 7ff76db04760 28490->28525 28491 7ff76daf6b80 28491->28489 28556 7ff76daf40b0 28491->28556 28492 7ff76daf6b6e 28555 7ff76daf28a4 82 API calls 2 library calls 28492->28555 28498 7ff76daf6c52 28499 7ff76daf6cd1 28498->28499 28500 7ff76daf6cc7 28498->28500 28561 7ff76db11f20 28499->28561 28529 7ff76db01794 28500->28529 28503 7ff76daf6ccf 28581 7ff76db04700 8 API calls _handle_error 28503->28581 28505 7ff76daf6cfd 28505->28507 28582 7ff76daf433c 82 API calls 2 library calls 28505->28582 28544 7ff76db11870 28507->28544 28509 7ff76db10d8c 28508->28509 28510 7ff76db10f48 28509->28510 28511 7ff76daf1744 33 API calls 28509->28511 28510->28467 28511->28509 28512->28444 28513->28458 28514->28460 28515->28467 28517 7ff76db11fc5 std::bad_alloc::bad_alloc 28516->28517 28518 7ff76db12056 std::bad_alloc::bad_alloc 28516->28518 28520 7ff76db24078 Concurrency::cancel_current_task 2 API calls 28517->28520 28521 7ff76db1200f std::bad_alloc::bad_alloc 28517->28521 28522 7ff76daf6b59 28517->28522 28519 7ff76db24078 Concurrency::cancel_current_task 2 API calls 28518->28519 28519->28517 28520->28521 28521->28522 28523 7ff76db24078 Concurrency::cancel_current_task 2 API calls 28521->28523 28522->28489 28522->28491 28522->28492 28524 7ff76db120a9 28523->28524 28526 7ff76db04780 28525->28526 28528 7ff76db0478a 28525->28528 28527 7ff76db221d0 33 API calls 28526->28527 28527->28528 28528->28498 28530 7ff76db017be memcpy_s 28529->28530 28584 7ff76db08a48 28530->28584 28533 7ff76db017f2 28535 7ff76db08a48 146 API calls 28533->28535 28536 7ff76db01830 28533->28536 28594 7ff76db08c4c 28533->28594 28535->28533 28545 7ff76db1188e 28544->28545 28547 7ff76db118a1 28545->28547 28604 7ff76db0e948 28545->28604 28551 7ff76db118d8 28547->28551 28600 7ff76db2236c 28547->28600 28549 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 28550 7ff76db11ad0 28549->28550 28553 7ff76db11a37 28551->28553 28611 7ff76db0a984 31 API calls _invalid_parameter_noinfo_noreturn 28551->28611 28553->28549 28554->28483 28555->28507 28557 7ff76daf40dd 28556->28557 28558 7ff76daf40d7 memcpy_s 28556->28558 28557->28558 28612 7ff76daf4120 33 API calls 2 library calls 28557->28612 28558->28489 28560->28490 28562 7ff76db11f29 28561->28562 28563 7ff76db11f5d 28562->28563 28564 7ff76db11f55 28562->28564 28565 7ff76db11f49 28562->28565 28563->28503 28643 7ff76db13964 151 API calls 28564->28643 28613 7ff76db120ac 28565->28613 28568 7ff76db14733 memcpy_s 28568->28568 28569 7ff76db08a48 146 API calls 28568->28569 28569->28568 28581->28505 28582->28507 28583->28483 28586 7ff76db08bcd 28584->28586 28590 7ff76db08a91 memcpy_s 28584->28590 28585 7ff76db08c1a 28587 7ff76db0e808 SetThreadExecutionState RtlPcToFileHeader RaiseException 28585->28587 28586->28585 28588 7ff76dafa174 8 API calls 28586->28588 28591 7ff76db08c1f 28587->28591 28588->28585 28589 7ff76db1612c 137 API calls 28589->28590 28590->28586 28590->28589 28590->28591 28592 7ff76db04888 108 API calls 28590->28592 28593 7ff76db028d0 104 API calls 28590->28593 28591->28533 28592->28590 28593->28590 28595 7ff76db08c8b 28594->28595 28596 7ff76db08c72 memcpy_s 28594->28596 28595->28596 28601 7ff76db2239f 28600->28601 28602 7ff76db223c8 28601->28602 28603 7ff76db11870 108 API calls 28601->28603 28602->28551 28603->28601 28605 7ff76db0ecd8 103 API calls 28604->28605 28606 7ff76db0e95f ReleaseSemaphore 28605->28606 28607 7ff76db0e9a3 DeleteCriticalSection CloseHandle CloseHandle 28606->28607 28608 7ff76db0e984 28606->28608 28609 7ff76db0ea5c 101 API calls 28608->28609 28610 7ff76db0e98e CloseHandle 28609->28610 28610->28607 28610->28608 28611->28553 28615 7ff76db120c8 memcpy_s 28613->28615 28614 7ff76db121ba 28614->28568 28615->28614 28616 7ff76dafb75c 82 API calls 28615->28616 28616->28615 28643->28563 28648 7ff76db08892 28647->28648 28649 7ff76db08882 28647->28649 28648->28176 28654 7ff76db023f0 28649->28654 28652 7ff76db22320 _handle_error 8 API calls 28651->28652 28653 7ff76daff7dc 28652->28653 28653->28076 28653->28179 28655 7ff76db0240f 28654->28655 28658 7ff76db02aa0 101 API calls 28655->28658 28656 7ff76db02428 28659 7ff76db02bb0 101 API calls 28656->28659 28657 7ff76db02438 28657->28648 28658->28656 28659->28657 28661 7ff76db1fc94 28660->28661 28662 7ff76daf129c 33 API calls 28661->28662 28663 7ff76db1fca4 28662->28663 28664 7ff76db1f0a4 24 API calls 28663->28664 28665 7ff76db1fcb1 28664->28665 28666 7ff76db1fceb 28665->28666 28668 7ff76db1fd03 28665->28668 28667 7ff76db22320 _handle_error 8 API calls 28666->28667 28670 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 28668->28670 28673 7ff76daf5e67 28672->28673 28736 7ff76db085f0 28673->28736 28675 7ff76daf6134 28746 7ff76daf6fcc 82 API calls 28675->28746 28677 7ff76daf613c 28678 7ff76daf69af 28677->28678 28680 7ff76daf69e4 28677->28680 28690 7ff76daf69ef 28677->28690 28679 7ff76db22320 _handle_error 8 API calls 28678->28679 28682 7ff76daf69c3 28679->28682 28685 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 28680->28685 28681 7ff76daf6973 28758 7ff76daf466c 82 API calls 28681->28758 28682->28202 28684 7ff76daf612e 28684->28675 28684->28681 28687 7ff76db085f0 104 API calls 28684->28687 28686 7ff76daf69e9 28685->28686 28688 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 28686->28688 28689 7ff76daf61a4 28687->28689 28688->28690 28689->28675 28693 7ff76daf61ac 28689->28693 28691 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 28690->28691 28692 7ff76daf69f5 28691->28692 28694 7ff76daf623f 28693->28694 28747 7ff76daf466c 82 API calls 28693->28747 28694->28681 28696 7ff76daf6266 28694->28696 28699 7ff76daf68b7 28696->28699 28702 7ff76daf62ce 28696->28702 28734->28202 28737 7ff76db0869a 28736->28737 28738 7ff76db08614 28736->28738 28740 7ff76daf40b0 33 API calls 28737->28740 28743 7ff76db0867c 28737->28743 28739 7ff76daf40b0 33 API calls 28738->28739 28738->28743 28741 7ff76db0864d 28739->28741 28742 7ff76db086b3 28740->28742 28759 7ff76dafa174 28741->28759 28745 7ff76db028d0 104 API calls 28742->28745 28743->28684 28745->28743 28746->28677 28760 7ff76dafa185 28759->28760 28762 7ff76dafa19a 28760->28762 28763 7ff76db0af18 8 API calls 2 library calls 28760->28763 28762->28743 28763->28762 28770 7ff76daf9be7 28764->28770 28765 7ff76daf9c1b 28766 7ff76db22320 _handle_error 8 API calls 28765->28766 28767 7ff76daf9c9d 28766->28767 28767->28219 28769 7ff76daf9c83 28772 7ff76daf1fa0 31 API calls 28769->28772 28770->28765 28770->28769 28773 7ff76daf9cae 28770->28773 28899 7ff76db05294 28770->28899 28917 7ff76db0db60 28770->28917 28772->28765 28774 7ff76daf9cbf 28773->28774 28921 7ff76db0da48 CompareStringW 28773->28921 28774->28769 28776 7ff76daf20b0 33 API calls 28774->28776 28776->28769 28787 7ff76db05f3a 28777->28787 28778 7ff76db0619b 28779 7ff76db22320 _handle_error 8 API calls 28778->28779 28781 7ff76daffb29 28779->28781 28780 7ff76db061ce 28925 7ff76daf704c 47 API calls memcpy_s 28780->28925 28781->28222 28850 7ff76db07c94 47 API calls 2 library calls 28781->28850 28783 7ff76daf129c 33 API calls 28785 7ff76db06129 28783->28785 28784 7ff76db061d4 28786 7ff76daf1fa0 31 API calls 28785->28786 28788 7ff76db0613b memcpy_s 28785->28788 28786->28788 28787->28778 28787->28780 28787->28783 28788->28778 28789 7ff76db061c9 28788->28789 28790 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 28789->28790 28790->28780 28849->28210 28850->28224 28851->28222 28897->28264 28898->28264 28900 7ff76db052d4 28899->28900 28905 7ff76db05312 __vcrt_FlsAlloc 28900->28905 28911 7ff76db05339 __vcrt_FlsAlloc 28900->28911 28922 7ff76db113f4 CompareStringW 28900->28922 28901 7ff76db22320 _handle_error 8 API calls 28903 7ff76db05503 28901->28903 28903->28770 28906 7ff76db05382 __vcrt_FlsAlloc 28905->28906 28905->28911 28923 7ff76db113f4 CompareStringW 28905->28923 28907 7ff76db05439 28906->28907 28908 7ff76daf129c 33 API calls 28906->28908 28906->28911 28910 7ff76db0551b 28907->28910 28912 7ff76db05489 28907->28912 28909 7ff76db05426 28908->28909 28913 7ff76db072cc 8 API calls 28909->28913 28915 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 28910->28915 28911->28901 28912->28911 28924 7ff76db113f4 CompareStringW 28912->28924 28913->28907 28916 7ff76db05520 28915->28916 28918 7ff76db0db73 28917->28918 28919 7ff76daf20b0 33 API calls 28918->28919 28920 7ff76db0db91 28918->28920 28919->28920 28920->28770 28921->28774 28922->28905 28923->28906 28924->28911 28925->28784 28983->28384 28984->28391 28985->28395 28987 7ff76db087af 28986->28987 28989 7ff76db087df 28986->28989 28988 7ff76db2236c 108 API calls 28987->28988 28990 7ff76db087ca 28988->28990 28991 7ff76db2236c 108 API calls 28989->28991 28999 7ff76db0882b 28989->28999 28993 7ff76db2236c 108 API calls 28990->28993 28994 7ff76db08814 28991->28994 28993->28989 28996 7ff76db2236c 108 API calls 28994->28996 28995 7ff76db08845 28997 7ff76db0461c 108 API calls 28995->28997 28996->28999 28998 7ff76db08851 28997->28998 29000 7ff76db0461c 28999->29000 29001 7ff76db04632 29000->29001 29003 7ff76db0463a 29000->29003 29002 7ff76db0e948 108 API calls 29001->29002 29002->29003 29003->28995 29005 7ff76db0163e 29004->29005 29008 7ff76db01681 29004->29008 29005->29008 29009 7ff76db031bc 51 API calls 29005->29009 29006 7ff76daf1fa0 31 API calls 29006->29008 29007 7ff76dafe600 31 API calls 29014 7ff76db016de 29007->29014 29008->29006 29012 7ff76db016a0 29008->29012 29009->29005 29010 7ff76db0175b 29011 7ff76db22320 _handle_error 8 API calls 29010->29011 29015 7ff76dafe58a 29011->29015 29012->29007 29013 7ff76db0178d 29016 7ff76db27904 _invalid_parameter_noinfo_noreturn 31 API calls 29013->29016 29014->29010 29014->29013 29015->28015 29015->28017 29017 7ff76db01792 29016->29017 29018->27683 29019->27689 29020->27692 29021 7ff76db211cf 29022 7ff76db21102 29021->29022 29023 7ff76db21900 _com_raise_error 14 API calls 29022->29023 29024 7ff76db21141 29023->29024 29025 7ff76db21491 29026 7ff76db213c9 29025->29026 29027 7ff76db21900 _com_raise_error 14 API calls 29026->29027 29027->29026
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Item$Message$_invalid_parameter_noinfo_noreturn$Send$DialogText$File$ErrorLast$CloseFindFocusLoadStringViewWindow$CommandConcurrency::cancel_current_taskCountCreateDispatchEnableExecuteFirstHandleLineMappingParamShellSleepTickTranslateUnmap
      • String ID: %s %s$-el -s2 "-d%s" "-sp%s"$@$LICENSEDLG$REPLACEFILEDLG$STARTDLG$__tmp_rar_sfx_access_check_$p$runas$winrarsfxmappingfile.tmp
      • API String ID: 255727823-2702805183
      • Opcode ID: b06a604dd1e1a1014e6e042a78463e585c17e51e9bce1e84f9241aa3d162bcb5
      • Instruction ID: 7803298c24c5dc4da1c63e6cf4bc78aff20ef8a5a8569c7463d40ca4dda920ff
      • Opcode Fuzzy Hash: b06a604dd1e1a1014e6e042a78463e585c17e51e9bce1e84f9241aa3d162bcb5
      • Instruction Fuzzy Hash: 62D27262A2C682C1EA21FB25E8546F9E361EF8A780FD04135D94D466EDFE7CE944C720
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task$FileMessageMoveSend$DialogItemPathTemp
      • String ID: .lnk$.tmp$<br>$@set:user$HIDE$MAX$MIN$ProgramFilesDir$Software\Microsoft\Windows\CurrentVersion$lnk
      • API String ID: 3007431893-3916287355
      • Opcode ID: ade84c13a5dc0a923d4b23a7709a57b38a9eab8197af02a88ef7afa6ef055700
      • Instruction ID: e7e9c4e0f1a67e599037fc17226c357f5a65f511af62441db85950b81df67c20
      • Opcode Fuzzy Hash: ade84c13a5dc0a923d4b23a7709a57b38a9eab8197af02a88ef7afa6ef055700
      • Instruction Fuzzy Hash: 1A139062B2C782D5EB11EF64D8402EC67A2EB48798FD00536DA1D57ADDEF38E584C360

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 1466 7ff76db20754-7ff76db20829 call 7ff76db0dfd0 call 7ff76db062dc call 7ff76db1946c call 7ff76db23cf0 call 7ff76db19a14 1477 7ff76db2082b-7ff76db20840 1466->1477 1478 7ff76db20860-7ff76db20883 1466->1478 1481 7ff76db2085b call 7ff76db2220c 1477->1481 1482 7ff76db20842-7ff76db20855 1477->1482 1479 7ff76db208ba-7ff76db208dd 1478->1479 1480 7ff76db20885-7ff76db2089a 1478->1480 1485 7ff76db208df-7ff76db208f4 1479->1485 1486 7ff76db20914-7ff76db20937 1479->1486 1483 7ff76db2089c-7ff76db208af 1480->1483 1484 7ff76db208b5 call 7ff76db2220c 1480->1484 1481->1478 1482->1481 1487 7ff76db20ddd-7ff76db20de2 call 7ff76db27904 1482->1487 1483->1484 1483->1487 1484->1479 1490 7ff76db2090f call 7ff76db2220c 1485->1490 1491 7ff76db208f6-7ff76db20909 1485->1491 1492 7ff76db20939-7ff76db2094e 1486->1492 1493 7ff76db2096e-7ff76db2097a GetCommandLineW 1486->1493 1501 7ff76db20de3-7ff76db20df0 call 7ff76db27904 1487->1501 1490->1486 1491->1487 1491->1490 1498 7ff76db20969 call 7ff76db2220c 1492->1498 1499 7ff76db20950-7ff76db20963 1492->1499 1495 7ff76db20b47-7ff76db20b5e call 7ff76db06454 1493->1495 1496 7ff76db20980-7ff76db209b7 call 7ff76db2797c call 7ff76daf129c call 7ff76db1cad0 1493->1496 1510 7ff76db20b89-7ff76db20ce4 call 7ff76daf1fa0 SetEnvironmentVariableW GetLocalTime call 7ff76db03e28 SetEnvironmentVariableW GetModuleHandleW LoadIconW call 7ff76db1b014 call 7ff76db098ac call 7ff76db167b4 * 2 DialogBoxParamW call 7ff76db168a8 * 2 1495->1510 1511 7ff76db20b60-7ff76db20b85 call 7ff76daf1fa0 call 7ff76db23640 1495->1511 1526 7ff76db209b9-7ff76db209cc 1496->1526 1527 7ff76db209ec-7ff76db209f3 1496->1527 1498->1493 1499->1487 1499->1498 1512 7ff76db20df5-7ff76db20e2f call 7ff76db21900 1501->1512 1573 7ff76db20cec-7ff76db20cf3 1510->1573 1574 7ff76db20ce6 Sleep 1510->1574 1511->1510 1521 7ff76db20e34-7ff76db20ee1 1512->1521 1521->1512 1530 7ff76db209e7 call 7ff76db2220c 1526->1530 1531 7ff76db209ce-7ff76db209e1 1526->1531 1532 7ff76db209f9-7ff76db20a13 OpenFileMappingW 1527->1532 1533 7ff76db20adb-7ff76db20b12 call 7ff76db2797c call 7ff76daf129c call 7ff76db1fd0c 1527->1533 1530->1527 1531->1501 1531->1530 1538 7ff76db20a19-7ff76db20a39 MapViewOfFile 1532->1538 1539 7ff76db20ad0-7ff76db20ad9 CloseHandle 1532->1539 1533->1495 1555 7ff76db20b14-7ff76db20b27 1533->1555 1538->1539 1542 7ff76db20a3f-7ff76db20a6f UnmapViewOfFile MapViewOfFile 1538->1542 1539->1495 1542->1539 1545 7ff76db20a71-7ff76db20aca call 7ff76db1a190 call 7ff76db1fd0c call 7ff76db0b9b4 call 7ff76db0bb00 call 7ff76db0bb70 UnmapViewOfFile 1542->1545 1545->1539 1558 7ff76db20b29-7ff76db20b3c 1555->1558 1559 7ff76db20b42 call 7ff76db2220c 1555->1559 1558->1559 1562 7ff76db20dd7-7ff76db20ddc call 7ff76db27904 1558->1562 1559->1495 1562->1487 1575 7ff76db20cfa-7ff76db20d1d call 7ff76db0b8e0 DeleteObject 1573->1575 1576 7ff76db20cf5 call 7ff76db19f4c 1573->1576 1574->1573 1581 7ff76db20d1f DeleteObject 1575->1581 1582 7ff76db20d25-7ff76db20d2c 1575->1582 1576->1575 1581->1582 1583 7ff76db20d48-7ff76db20d59 1582->1583 1584 7ff76db20d2e-7ff76db20d35 1582->1584 1586 7ff76db20d5b-7ff76db20d67 call 7ff76db1fe24 CloseHandle 1583->1586 1587 7ff76db20d6d-7ff76db20d7a 1583->1587 1584->1583 1585 7ff76db20d37-7ff76db20d43 call 7ff76dafba0c 1584->1585 1585->1583 1586->1587 1588 7ff76db20d7c-7ff76db20d89 1587->1588 1589 7ff76db20d9f-7ff76db20da4 call 7ff76db194e4 1587->1589 1592 7ff76db20d99-7ff76db20d9b 1588->1592 1593 7ff76db20d8b-7ff76db20d93 1588->1593 1598 7ff76db20da9-7ff76db20dd6 call 7ff76db22320 1589->1598 1592->1589 1597 7ff76db20d9d 1592->1597 1593->1589 1596 7ff76db20d95-7ff76db20d97 1593->1596 1596->1589 1597->1589
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: File$EnvironmentHandleVariableView$_invalid_parameter_noinfo_noreturn$AddressCloseCurrentDeleteDirectoryModuleObjectProcUnmap$CommandDialogIconInitializeLineLoadLocalMallocMappingOpenParamSleepTimeswprintf
      • String ID: %4d-%02d-%02d-%02d-%02d-%02d-%03d$STARTDLG$sfxname$sfxstime$winrarsfxmappingfile.tmp
      • API String ID: 1048086575-3710569615
      • Opcode ID: 5a0cbdb8d1f0485109b3182adadad79a05d95305e578c214513e8b8f27ec5f32
      • Instruction ID: 78882203a30877c7fcb288195f0688c2f4a13a5d3d59edb255fb4b120d987ba8
      • Opcode Fuzzy Hash: 5a0cbdb8d1f0485109b3182adadad79a05d95305e578c214513e8b8f27ec5f32
      • Instruction Fuzzy Hash: A7126662E2C782C1EB10AF25E8552B9A361FF8D784F804235DA5D46AADFF7CE544C720

      Control-flow Graph

      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Window$Rect$Text$ByteCharClientItemLongMetricsMultiSystemWideswprintf
      • String ID: $%s:$CAPTION
      • API String ID: 2100155373-404845831
      • Opcode ID: 1224945cd41bf140f0dcf37f1b002595631e4f701a4b658f84a72e9da714e3d9
      • Instruction ID: 145190f1ea3e40a07ecd3de3857bef1d6f7ff474017247dcf97ada4d37b79358
      • Opcode Fuzzy Hash: 1224945cd41bf140f0dcf37f1b002595631e4f701a4b658f84a72e9da714e3d9
      • Instruction Fuzzy Hash: B391D632B2C641C6E714EF29E804A6EA7A1FB88784F845535EE4D57B5CEE3DE805CB10

      Control-flow Graph

      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Global$Resource$AllocCreateGdipLock$BitmapFindFreeFromLoadSizeofStreamUnlock
      • String ID: PNG
      • API String ID: 211097158-364855578
      • Opcode ID: c8606208415c3a11eb94d5df8c8f8595ea54109f2541637b646828bce78d4013
      • Instruction ID: ba26915fb8a23958c3352d3d445d4a8f56dbcc4e19950f630ef307fc4cc2c6c1
      • Opcode Fuzzy Hash: c8606208415c3a11eb94d5df8c8f8595ea54109f2541637b646828bce78d4013
      • Instruction Fuzzy Hash: 64413D29A2DB42D1EE15AB16D854379E3A1BF8CB90F880535CE0D87768FF7CE4489720
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: __tmp_reference_source_
      • API String ID: 3668304517-685763994
      • Opcode ID: 288aadb9850286666244f589a7a65127607e522c818528ab99dbe7041c3f50d5
      • Instruction ID: 700e5424733f7fed5502bca2309565ed53fbc6fffa487920e44c148f284941f4
      • Opcode Fuzzy Hash: 288aadb9850286666244f589a7a65127607e522c818528ab99dbe7041c3f50d5
      • Instruction Fuzzy Hash: 72E2C662A2C6C2D2EA64EB25D0407FEE761FB89784F844136DB9D436A9EF3CE454C710
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: CMT
      • API String ID: 3668304517-2756464174
      • Opcode ID: 7d1c6c22bd83c666423e6e8ace876ca52384bc33d34e44693625b0213485e245
      • Instruction ID: 59917cd4d95c10d4081a72695850cf02215c06212d4b7e110c0446df6b02fda6
      • Opcode Fuzzy Hash: 7d1c6c22bd83c666423e6e8ace876ca52384bc33d34e44693625b0213485e245
      • Instruction Fuzzy Hash: 03E20622B2C682C6EB14EB75D150AFDA7A1FB49384F884032DA5E47796EF7CE954C310

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 3712 7ff76db040bc-7ff76db040f3 3713 7ff76db041d2-7ff76db041df FindNextFileW 3712->3713 3714 7ff76db040f9-7ff76db04101 3712->3714 3717 7ff76db041f3-7ff76db041f6 3713->3717 3718 7ff76db041e1-7ff76db041f1 GetLastError 3713->3718 3715 7ff76db04106-7ff76db04118 FindFirstFileW 3714->3715 3716 7ff76db04103 3714->3716 3715->3717 3719 7ff76db0411e-7ff76db04146 call 7ff76db06a0c 3715->3719 3716->3715 3721 7ff76db04211-7ff76db04253 call 7ff76db2797c call 7ff76daf129c call 7ff76db08090 3717->3721 3722 7ff76db041f8-7ff76db04200 3717->3722 3720 7ff76db041ca-7ff76db041cd 3718->3720 3732 7ff76db04148-7ff76db04164 FindFirstFileW 3719->3732 3733 7ff76db04167-7ff76db04170 3719->3733 3723 7ff76db042eb-7ff76db0430e call 7ff76db22320 3720->3723 3748 7ff76db04255-7ff76db0426c 3721->3748 3749 7ff76db0428c-7ff76db042e6 call 7ff76db0f168 * 3 3721->3749 3725 7ff76db04205-7ff76db0420c call 7ff76daf20b0 3722->3725 3726 7ff76db04202 3722->3726 3725->3721 3726->3725 3732->3733 3736 7ff76db04172-7ff76db04189 3733->3736 3737 7ff76db041a9-7ff76db041ad 3733->3737 3739 7ff76db041a4 call 7ff76db2220c 3736->3739 3740 7ff76db0418b-7ff76db0419e 3736->3740 3737->3717 3741 7ff76db041af-7ff76db041be GetLastError 3737->3741 3739->3737 3740->3739 3743 7ff76db04315-7ff76db0431b call 7ff76db27904 3740->3743 3745 7ff76db041c0-7ff76db041c6 3741->3745 3746 7ff76db041c8 3741->3746 3745->3720 3745->3746 3746->3720 3753 7ff76db0426e-7ff76db04281 3748->3753 3754 7ff76db04287 call 7ff76db2220c 3748->3754 3749->3723 3753->3754 3755 7ff76db0430f-7ff76db04314 call 7ff76db27904 3753->3755 3754->3749 3755->3743
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: FileFind$ErrorFirstLast_invalid_parameter_noinfo_noreturn$Next
      • String ID:
      • API String ID: 474548282-0
      • Opcode ID: 302a779ab95c7aaca0ba1f13af6e7309770b234b011da9b93882c2eb88fdf2be
      • Instruction ID: 41fdd2a1173c4987afa6e096342996f6f70accd2c2d6223ddc2b775c1156a21e
      • Opcode Fuzzy Hash: 302a779ab95c7aaca0ba1f13af6e7309770b234b011da9b93882c2eb88fdf2be
      • Instruction Fuzzy Hash: F561B362A2CA46C1EA10AB24E84067DA361FF9D7A4F905331EAAD43ADDEF7CD544C710

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 3823 7ff76daf5e24-7ff76daf6129 call 7ff76db0833c call 7ff76db085f0 3829 7ff76daf612e-7ff76daf6132 3823->3829 3830 7ff76daf6134-7ff76daf613c call 7ff76daf6fcc 3829->3830 3831 7ff76daf6141-7ff76daf6171 call 7ff76db083d8 call 7ff76db08570 call 7ff76db08528 3829->3831 3836 7ff76daf697b 3830->3836 3849 7ff76daf6973-7ff76daf6976 call 7ff76daf466c 3831->3849 3850 7ff76daf6177-7ff76daf6179 3831->3850 3838 7ff76daf697e-7ff76daf6985 3836->3838 3840 7ff76daf69b4-7ff76daf69e3 call 7ff76db22320 3838->3840 3841 7ff76daf6987-7ff76daf6998 3838->3841 3843 7ff76daf69af call 7ff76db2220c 3841->3843 3844 7ff76daf699a-7ff76daf69ad 3841->3844 3843->3840 3844->3843 3847 7ff76daf69e4-7ff76daf69e9 call 7ff76db27904 3844->3847 3858 7ff76daf69ea-7ff76daf69ef call 7ff76db27904 3847->3858 3849->3836 3850->3849 3853 7ff76daf617f-7ff76daf6189 3850->3853 3853->3849 3855 7ff76daf618f-7ff76daf6192 3853->3855 3855->3849 3857 7ff76daf6198-7ff76daf61aa call 7ff76db085f0 3855->3857 3857->3830 3864 7ff76daf61ac-7ff76daf61fd call 7ff76db084f8 call 7ff76db08528 * 2 3857->3864 3863 7ff76daf69f0-7ff76daf69f7 call 7ff76db27904 3858->3863 3873 7ff76daf623f-7ff76daf6249 3864->3873 3874 7ff76daf61ff-7ff76daf6222 call 7ff76daf466c call 7ff76dafba0c 3864->3874 3876 7ff76daf6266-7ff76daf6270 3873->3876 3877 7ff76daf624b-7ff76daf6260 call 7ff76db08528 3873->3877 3874->3873 3891 7ff76daf6224-7ff76daf622e call 7ff76daf433c 3874->3891 3878 7ff76daf6272-7ff76daf627b call 7ff76db08528 3876->3878 3879 7ff76daf627e-7ff76daf6296 call 7ff76daf334c 3876->3879 3877->3849 3877->3876 3878->3879 3889 7ff76daf62b3 3879->3889 3890 7ff76daf6298-7ff76daf629b 3879->3890 3893 7ff76daf62b6-7ff76daf62c8 3889->3893 3890->3889 3892 7ff76daf629d-7ff76daf62b1 3890->3892 3891->3873 3892->3889 3892->3893 3895 7ff76daf62ce-7ff76daf62d1 3893->3895 3896 7ff76daf68b7-7ff76daf6929 call 7ff76db04d04 call 7ff76db08528 3893->3896 3898 7ff76daf6481-7ff76daf64f4 call 7ff76db04c74 call 7ff76db08528 * 2 3895->3898 3899 7ff76daf62d7-7ff76daf62da 3895->3899 3914 7ff76daf6936 3896->3914 3915 7ff76daf692b-7ff76daf6934 call 7ff76db08528 3896->3915 3929 7ff76daf64f6-7ff76daf6500 3898->3929 3930 7ff76daf6507-7ff76daf6533 call 7ff76db08528 3898->3930 3899->3898 3901 7ff76daf62e0-7ff76daf62e3 3899->3901 3904 7ff76daf62e5-7ff76daf62e8 3901->3904 3905 7ff76daf632e-7ff76daf6353 call 7ff76db08528 3901->3905 3910 7ff76daf696d-7ff76daf6971 3904->3910 3911 7ff76daf62ee-7ff76daf6329 call 7ff76db08528 3904->3911 3920 7ff76daf6355-7ff76daf638f call 7ff76daf4228 call 7ff76daf3c84 call 7ff76daf701c call 7ff76daf1fa0 3905->3920 3921 7ff76daf639e-7ff76daf63c5 call 7ff76db08528 call 7ff76db08384 3905->3921 3910->3838 3911->3910 3922 7ff76daf6939-7ff76daf6946 3914->3922 3915->3922 3970 7ff76daf6390-7ff76daf6399 call 7ff76daf1fa0 3920->3970 3942 7ff76daf6402-7ff76daf641f call 7ff76db08444 3921->3942 3943 7ff76daf63c7-7ff76daf6400 call 7ff76daf4228 call 7ff76daf3c84 call 7ff76daf701c call 7ff76daf1fa0 3921->3943 3927 7ff76daf694c 3922->3927 3928 7ff76daf6948-7ff76daf694a 3922->3928 3933 7ff76daf694f-7ff76daf6959 3927->3933 3928->3927 3928->3933 3929->3930 3944 7ff76daf6535-7ff76daf6544 call 7ff76db083d8 call 7ff76db0f134 3930->3944 3945 7ff76daf6549-7ff76daf6557 3930->3945 3933->3910 3937 7ff76daf695b-7ff76daf6968 call 7ff76daf4840 3933->3937 3937->3910 3960 7ff76daf6475-7ff76daf647c 3942->3960 3961 7ff76daf6421-7ff76daf646f call 7ff76db08444 * 2 call 7ff76db0c800 call 7ff76db24a70 3942->3961 3943->3970 3944->3945 3951 7ff76daf6572-7ff76daf6595 call 7ff76db08528 3945->3951 3952 7ff76daf6559-7ff76daf656c call 7ff76db083d8 3945->3952 3966 7ff76daf65a0-7ff76daf65b0 3951->3966 3967 7ff76daf6597-7ff76daf659e 3951->3967 3952->3951 3960->3910 3961->3960 3971 7ff76daf65b3-7ff76daf65eb call 7ff76db08528 * 2 3966->3971 3967->3971 3970->3921 3987 7ff76daf65f6-7ff76daf65fa 3971->3987 3988 7ff76daf65ed-7ff76daf65f4 3971->3988 3990 7ff76daf6603-7ff76daf6632 3987->3990 3992 7ff76daf65fc 3987->3992 3988->3990 3993 7ff76daf6634-7ff76daf6638 3990->3993 3994 7ff76daf663f 3990->3994 3992->3990 3993->3994 3996 7ff76daf663a-7ff76daf663d 3993->3996 3995 7ff76daf6641-7ff76daf6656 3994->3995 3997 7ff76daf66ca 3995->3997 3998 7ff76daf6658-7ff76daf665b 3995->3998 3996->3995 4000 7ff76daf66d2-7ff76daf6731 call 7ff76daf3d00 call 7ff76db08444 call 7ff76db10d54 3997->4000 3998->3997 3999 7ff76daf665d-7ff76daf6683 3998->3999 3999->4000 4001 7ff76daf6685-7ff76daf66a9 3999->4001 4011 7ff76daf6745-7ff76daf6749 4000->4011 4012 7ff76daf6733-7ff76daf6740 call 7ff76daf4840 4000->4012 4003 7ff76daf66b2-7ff76daf66bf 4001->4003 4004 7ff76daf66ab 4001->4004 4003->4000 4006 7ff76daf66c1-7ff76daf66c8 4003->4006 4004->4003 4006->4000 4014 7ff76daf675b-7ff76daf6772 call 7ff76db2797c 4011->4014 4015 7ff76daf674b-7ff76daf6756 call 7ff76daf473c 4011->4015 4012->4011 4021 7ff76daf6774 4014->4021 4022 7ff76daf6777-7ff76daf677e 4014->4022 4020 7ff76daf6859-7ff76daf6860 4015->4020 4023 7ff76daf6873-7ff76daf687b 4020->4023 4024 7ff76daf6862-7ff76daf6872 call 7ff76daf433c 4020->4024 4021->4022 4025 7ff76daf67a3-7ff76daf67ba call 7ff76db2797c 4022->4025 4026 7ff76daf6780-7ff76daf6783 4022->4026 4023->3910 4029 7ff76daf6881-7ff76daf6892 4023->4029 4024->4023 4037 7ff76daf67bf-7ff76daf67c6 4025->4037 4038 7ff76daf67bc 4025->4038 4030 7ff76daf6785 4026->4030 4031 7ff76daf679c 4026->4031 4034 7ff76daf6894-7ff76daf68a7 4029->4034 4035 7ff76daf68ad-7ff76daf68b2 call 7ff76db2220c 4029->4035 4036 7ff76daf6788-7ff76daf6791 4030->4036 4031->4025 4034->3863 4034->4035 4035->3910 4036->4025 4040 7ff76daf6793-7ff76daf679a 4036->4040 4037->4020 4041 7ff76daf67cc-7ff76daf67cf 4037->4041 4038->4037 4040->4031 4040->4036 4043 7ff76daf67d1 4041->4043 4044 7ff76daf67e8-7ff76daf67f0 4041->4044 4045 7ff76daf67d4-7ff76daf67dd 4043->4045 4044->4020 4046 7ff76daf67f2-7ff76daf6826 call 7ff76db08360 call 7ff76db08598 call 7ff76db08528 4044->4046 4045->4020 4047 7ff76daf67df-7ff76daf67e6 4045->4047 4046->4020 4054 7ff76daf6828-7ff76daf6839 4046->4054 4047->4044 4047->4045 4055 7ff76daf6854 call 7ff76db2220c 4054->4055 4056 7ff76daf683b-7ff76daf684e 4054->4056 4055->4020 4056->3858 4056->4055
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID:
      • String ID: CMT
      • API String ID: 0-2756464174
      • Opcode ID: 920946c3a46788dbc14b960d280913d1087d646ed99960bedbc598b6726ca41f
      • Instruction ID: 2aa83eb56e7bd934acae2bc947f415b0c6ca9167017039fee652feb165e186c0
      • Opcode Fuzzy Hash: 920946c3a46788dbc14b960d280913d1087d646ed99960bedbc598b6726ca41f
      • Instruction Fuzzy Hash: 9542FF22B2C682D6EB18EB74C1506FDB7A1EB15344F880176DB5E53796EF38E918C360
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 00cc9b5d49baee892d39d1da46008d2b4229947a5b0a2c39888c4d08721f4c94
      • Instruction ID: bcc6315be46deeb5c03434c8daa23f0126a4c0c3c70bb8f4f889afb71af80d72
      • Opcode Fuzzy Hash: 00cc9b5d49baee892d39d1da46008d2b4229947a5b0a2c39888c4d08721f4c94
      • Instruction Fuzzy Hash: FBE11722A2C2C2CAEB61EF28A84427DB792FB4D78CF454135DB4E87749EE3CE5458714
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 27e1d97200dc275f03108a64776f1fd30e61297024d66dcfdcf317728c87068d
      • Instruction ID: 0b0908e59adfefaab742b2a57e182c85295f71d08826d920ce25fcf9ddc6aad3
      • Opcode Fuzzy Hash: 27e1d97200dc275f03108a64776f1fd30e61297024d66dcfdcf317728c87068d
      • Instruction Fuzzy Hash: 54B1C2A2B196C992DE5AEB65D908AE9A392B709FC4F848036DE0D07749FF3CE155C310
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Create$CriticalEventInitializeSectionSemaphore
      • String ID:
      • API String ID: 3340455307-0
      • Opcode ID: 388497648aa7178462f46e8a8cb48851b3eb3f46bbabbbefb59410a44eea80d8
      • Instruction ID: cbcd7424181c76624d226ef20aae0690c88870c3b7e8822dd3d2c7778abfe589
      • Opcode Fuzzy Hash: 388497648aa7178462f46e8a8cb48851b3eb3f46bbabbbefb59410a44eea80d8
      • Instruction Fuzzy Hash: 94411922B2D656CAFB64EF11A900B7AA252FBDC784F844030DE4D07798EE3CE4468714

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 0 7ff76db0dfd0-7ff76db0e024 call 7ff76db22450 GetModuleHandleW 3 7ff76db0e07b-7ff76db0e3a5 0->3 4 7ff76db0e026-7ff76db0e039 GetProcAddress 0->4 5 7ff76db0e3ab-7ff76db0e3b4 call 7ff76db2b788 3->5 6 7ff76db0e503-7ff76db0e521 call 7ff76db06454 call 7ff76db07df4 3->6 7 7ff76db0e03b-7ff76db0e04a 4->7 8 7ff76db0e053-7ff76db0e066 GetProcAddress 4->8 5->6 15 7ff76db0e3ba-7ff76db0e3fd call 7ff76db06454 CreateFileW 5->15 19 7ff76db0e525-7ff76db0e52f call 7ff76db051a4 6->19 7->8 8->3 11 7ff76db0e068-7ff76db0e078 8->11 11->3 22 7ff76db0e4f0-7ff76db0e4fe CloseHandle call 7ff76daf1fa0 15->22 23 7ff76db0e403-7ff76db0e416 SetFilePointer 15->23 27 7ff76db0e531-7ff76db0e53c call 7ff76db0dd88 19->27 28 7ff76db0e564-7ff76db0e5ac call 7ff76db2797c call 7ff76daf129c call 7ff76db08090 call 7ff76daf1fa0 call 7ff76db032bc 19->28 22->6 23->22 25 7ff76db0e41c-7ff76db0e43e ReadFile 23->25 25->22 29 7ff76db0e444-7ff76db0e452 25->29 27->28 39 7ff76db0e53e-7ff76db0e562 CompareStringW 27->39 66 7ff76db0e5b1-7ff76db0e5b4 28->66 32 7ff76db0e458-7ff76db0e4ac call 7ff76db2797c call 7ff76daf129c 29->32 33 7ff76db0e800-7ff76db0e807 call 7ff76db22624 29->33 48 7ff76db0e4c3-7ff76db0e4d9 call 7ff76db0d0a0 32->48 39->28 42 7ff76db0e5bd-7ff76db0e5c6 39->42 42->19 45 7ff76db0e5cc 42->45 49 7ff76db0e5d1-7ff76db0e5d4 45->49 61 7ff76db0e4db-7ff76db0e4eb call 7ff76daf1fa0 * 2 48->61 62 7ff76db0e4ae-7ff76db0e4be call 7ff76db0dd88 48->62 52 7ff76db0e63f-7ff76db0e642 49->52 53 7ff76db0e5d6-7ff76db0e5d9 49->53 56 7ff76db0e648-7ff76db0e65b call 7ff76db07eb0 call 7ff76db051a4 52->56 57 7ff76db0e7c2-7ff76db0e7ff call 7ff76daf1fa0 * 2 call 7ff76db22320 52->57 58 7ff76db0e5dd-7ff76db0e62d call 7ff76db2797c call 7ff76daf129c call 7ff76db08090 call 7ff76daf1fa0 call 7ff76db032bc 53->58 82 7ff76db0e661-7ff76db0e701 call 7ff76db0dd88 * 2 call 7ff76db0aae0 call 7ff76db0da98 call 7ff76db0aae0 call 7ff76db0dc2c call 7ff76db187ac call 7ff76daf19e0 56->82 83 7ff76db0e706-7ff76db0e753 call 7ff76db0da98 AllocConsole 56->83 107 7ff76db0e63c 58->107 108 7ff76db0e62f-7ff76db0e638 58->108 61->22 62->48 72 7ff76db0e5ce 66->72 73 7ff76db0e5b6 66->73 72->49 73->42 100 7ff76db0e7b4-7ff76db0e7bb call 7ff76daf19e0 ExitProcess 82->100 93 7ff76db0e7b0 83->93 94 7ff76db0e755-7ff76db0e7aa GetCurrentProcessId AttachConsole call 7ff76db0e868 call 7ff76db0e858 GetStdHandle WriteConsoleW Sleep FreeConsole 83->94 93->100 94->93 107->52 108->58 112 7ff76db0e63a 108->112 112->52
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$Console$FileHandle$AddressProcProcess$AllocAttachCloseCompareCreateCurrentDirectoryExitFreeLibraryLoadModulePointerReadSleepStringSystemVersionWrite
      • String ID: DXGIDebug.dll$Please remove %s from %s folder. It is unsecure to run %s until it is done.$RpcRtRemote.dll$SSPICLI.DLL$SetDefaultDllDirectories$SetDllDirectoryW$UXTheme.dll$WINNSI.DLL$WindowsCodecs.dll$XmlLite.dll$aclui.dll$apphelp.dll$atl.dll$browcli.dll$cabinet.dll$clbcatq.dll$comres.dll$crypt32.dll$cryptbase.dll$cryptsp.dll$cryptui.dll$cscapi.dll$devrtl.dll$dfscli.dll$dhcpcsvc.dll$dhcpcsvc6.dll$dnsapi.DLL$dsrole.dll$dwmapi.dll$ieframe.dll$imageres.dll$iphlpapi.DLL$kernel32$linkinfo.dll$lpk.dll$mlang.dll$mpr.dll$msasn1.dll$netapi32.dll$netutils.dll$ntmarta.dll$ntshrui.dll$oleaccrc.dll$peerdist.dll$profapi.dll$propsys.dll$psapi.dll$rasadhlp.dll$rsaenh.dll$samcli.dll$samlib.dll$secur32.dll$setupapi.dll$sfc_os.dll$shdocvw.dll$shell32.dll$slc.dll$srvcli.dll$userenv.dll$usp10.dll$uxtheme.dll$version.dll$wintrust.dll$wkscli.dll$ws2_32.dll$ws2help.dll
      • API String ID: 1496594111-2013832382
      • Opcode ID: 652c747d7e630e86415ee3ad066f254a367a94a472fe2acd263d178260856de2
      • Instruction ID: ae0f320c16891c86e521ef51f4168120da06dcf25602287661acf1e29e33863e
      • Opcode Fuzzy Hash: 652c747d7e630e86415ee3ad066f254a367a94a472fe2acd263d178260856de2
      • Instruction Fuzzy Hash: 6E323C35A2DB82D5EB21AF20E8405E9B3A4FF48354F810236DA4D46BA9FF7CD254D350
      APIs
        • Part of subcall function 00007FF76DB08E58: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF76DB08F8D
      • _snwprintf.LEGACY_STDIO_DEFINITIONS ref: 00007FF76DB09F75
      • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF76DB0A42F
      • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF76DB0A435
        • Part of subcall function 00007FF76DB10BBC: MultiByteToWideChar.KERNEL32(?,?,?,?,?,00007FF76DB10B44), ref: 00007FF76DB10BE9
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$ByteCharConcurrency::cancel_current_taskMultiWide_snwprintf
      • String ID: $ ,$$%s:$*messages***$*messages***$@%s:$DIALOG$DIRECTION$MENU$RTL$STRINGS
      • API String ID: 3629253777-3268106645
      • Opcode ID: c449468cbcdcc3f584a662d802def55668ac00cfe72deb88729f3f670db9afdb
      • Instruction ID: b8fed4fac491a311764754281a2c4bf4b0f440c4cb20b164780333121ea433ca
      • Opcode Fuzzy Hash: c449468cbcdcc3f584a662d802def55668ac00cfe72deb88729f3f670db9afdb
      • Instruction Fuzzy Hash: BF62BD22A2DA82C5EB20EB24D444ABDA365FB48784FC48536DA4D476DDFF3CE944C760

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 1911 7ff76db21900-7ff76db21989 call 7ff76db21558 1914 7ff76db2198b-7ff76db219af call 7ff76db21868 RaiseException 1911->1914 1915 7ff76db219b4-7ff76db219d1 1911->1915 1923 7ff76db21bb8-7ff76db21bd5 1914->1923 1917 7ff76db219d3-7ff76db219e4 1915->1917 1918 7ff76db219e6-7ff76db219ea 1915->1918 1919 7ff76db219ed-7ff76db219f9 1917->1919 1918->1919 1921 7ff76db21a1a-7ff76db21a1d 1919->1921 1922 7ff76db219fb-7ff76db21a0d 1919->1922 1924 7ff76db21ac4-7ff76db21acb 1921->1924 1925 7ff76db21a23-7ff76db21a26 1921->1925 1931 7ff76db21b89-7ff76db21b93 1922->1931 1932 7ff76db21a13 1922->1932 1927 7ff76db21acd-7ff76db21adc 1924->1927 1928 7ff76db21adf-7ff76db21ae2 1924->1928 1929 7ff76db21a28-7ff76db21a3b 1925->1929 1930 7ff76db21a3d-7ff76db21a52 LoadLibraryExA 1925->1930 1927->1928 1933 7ff76db21ae8-7ff76db21aec 1928->1933 1934 7ff76db21b85 1928->1934 1929->1930 1935 7ff76db21aa9-7ff76db21ab2 1929->1935 1930->1935 1936 7ff76db21a54-7ff76db21a67 GetLastError 1930->1936 1943 7ff76db21bb0 call 7ff76db21868 1931->1943 1944 7ff76db21b95-7ff76db21ba6 1931->1944 1932->1921 1941 7ff76db21b1b-7ff76db21b2e GetProcAddress 1933->1941 1942 7ff76db21aee-7ff76db21af2 1933->1942 1934->1931 1937 7ff76db21abd 1935->1937 1938 7ff76db21ab4-7ff76db21ab7 FreeLibrary 1935->1938 1945 7ff76db21a69-7ff76db21a7c 1936->1945 1946 7ff76db21a7e-7ff76db21aa4 call 7ff76db21868 RaiseException 1936->1946 1937->1924 1938->1937 1941->1934 1948 7ff76db21b30-7ff76db21b43 GetLastError 1941->1948 1942->1941 1949 7ff76db21af4-7ff76db21aff 1942->1949 1951 7ff76db21bb5 1943->1951 1944->1943 1945->1935 1945->1946 1946->1923 1953 7ff76db21b5a-7ff76db21b81 call 7ff76db21868 RaiseException call 7ff76db21558 1948->1953 1954 7ff76db21b45-7ff76db21b58 1948->1954 1949->1941 1955 7ff76db21b01-7ff76db21b08 1949->1955 1951->1923 1953->1934 1954->1934 1954->1953 1955->1941 1958 7ff76db21b0a-7ff76db21b0f 1955->1958 1958->1941 1961 7ff76db21b11-7ff76db21b19 1958->1961 1961->1934 1961->1941
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: DloadSection$AccessExceptionProtectRaiseReleaseWrite$ErrorLastLibraryLoad
      • String ID: H
      • API String ID: 3432403771-2852464175
      • Opcode ID: cf3fc932a6b7fb7fc9ef8320b4dd67bfc8d7ec91281715f792326570f1d4a57f
      • Instruction ID: 76f668cc70b58042c60f31fcdb793942adbe815c35cbe1b12f900522928264dc
      • Opcode Fuzzy Hash: cf3fc932a6b7fb7fc9ef8320b4dd67bfc8d7ec91281715f792326570f1d4a57f
      • Instruction Fuzzy Hash: CF915C26A29B91CAEB10DF65D8846B8B3B1FB0CB94B894435DE0D17B58FF79E445C320

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 1989 7ff76db1f4e0-7ff76db1f523 1990 7ff76db1f529-7ff76db1f565 call 7ff76db23cf0 1989->1990 1991 7ff76db1f894-7ff76db1f8b9 call 7ff76daf1fa0 call 7ff76db22320 1989->1991 1996 7ff76db1f567 1990->1996 1997 7ff76db1f56a-7ff76db1f571 1990->1997 1996->1997 1999 7ff76db1f582-7ff76db1f586 1997->1999 2000 7ff76db1f573-7ff76db1f577 1997->2000 2004 7ff76db1f588 1999->2004 2005 7ff76db1f58b-7ff76db1f596 1999->2005 2002 7ff76db1f579 2000->2002 2003 7ff76db1f57c-7ff76db1f580 2000->2003 2002->2003 2003->2005 2004->2005 2006 7ff76db1f628 2005->2006 2007 7ff76db1f59c 2005->2007 2009 7ff76db1f62c-7ff76db1f62f 2006->2009 2008 7ff76db1f5a2-7ff76db1f5a9 2007->2008 2010 7ff76db1f5ab 2008->2010 2011 7ff76db1f5ae-7ff76db1f5b3 2008->2011 2012 7ff76db1f637-7ff76db1f63a 2009->2012 2013 7ff76db1f631-7ff76db1f635 2009->2013 2010->2011 2016 7ff76db1f5e5-7ff76db1f5f0 2011->2016 2017 7ff76db1f5b5 2011->2017 2014 7ff76db1f63c-7ff76db1f643 2012->2014 2015 7ff76db1f660-7ff76db1f673 call 7ff76db063ac 2012->2015 2013->2012 2013->2015 2014->2015 2018 7ff76db1f645-7ff76db1f65c 2014->2018 2030 7ff76db1f698-7ff76db1f6ed call 7ff76db2797c call 7ff76daf129c call 7ff76db032a8 call 7ff76daf1fa0 2015->2030 2031 7ff76db1f675-7ff76db1f693 call 7ff76db113c4 2015->2031 2020 7ff76db1f5f2 2016->2020 2021 7ff76db1f5f5-7ff76db1f5fa 2016->2021 2022 7ff76db1f5ca-7ff76db1f5d0 2017->2022 2018->2015 2020->2021 2026 7ff76db1f8ba-7ff76db1f8c1 2021->2026 2027 7ff76db1f600-7ff76db1f607 2021->2027 2023 7ff76db1f5b7-7ff76db1f5be 2022->2023 2024 7ff76db1f5d2 2022->2024 2034 7ff76db1f5c0 2023->2034 2035 7ff76db1f5c3-7ff76db1f5c8 2023->2035 2024->2016 2028 7ff76db1f8c3 2026->2028 2029 7ff76db1f8c6-7ff76db1f8cb 2026->2029 2032 7ff76db1f609 2027->2032 2033 7ff76db1f60c-7ff76db1f612 2027->2033 2028->2029 2037 7ff76db1f8de-7ff76db1f8e6 2029->2037 2038 7ff76db1f8cd-7ff76db1f8d4 2029->2038 2056 7ff76db1f6ef-7ff76db1f73d call 7ff76db2797c call 7ff76daf129c call 7ff76db05b60 call 7ff76daf1fa0 2030->2056 2057 7ff76db1f742-7ff76db1f74f ShellExecuteExW 2030->2057 2031->2030 2032->2033 2033->2026 2041 7ff76db1f618-7ff76db1f622 2033->2041 2034->2035 2035->2022 2036 7ff76db1f5d4-7ff76db1f5db 2035->2036 2042 7ff76db1f5dd 2036->2042 2043 7ff76db1f5e0 2036->2043 2046 7ff76db1f8e8 2037->2046 2047 7ff76db1f8eb-7ff76db1f8f6 2037->2047 2044 7ff76db1f8d9 2038->2044 2045 7ff76db1f8d6 2038->2045 2041->2006 2041->2008 2042->2043 2043->2016 2044->2037 2045->2044 2046->2047 2047->2009 2056->2057 2059 7ff76db1f846-7ff76db1f84e 2057->2059 2060 7ff76db1f755-7ff76db1f75f 2057->2060 2062 7ff76db1f850-7ff76db1f866 2059->2062 2063 7ff76db1f882-7ff76db1f88f 2059->2063 2064 7ff76db1f76f-7ff76db1f772 2060->2064 2065 7ff76db1f761-7ff76db1f764 2060->2065 2067 7ff76db1f868-7ff76db1f87b 2062->2067 2068 7ff76db1f87d call 7ff76db2220c 2062->2068 2063->1991 2070 7ff76db1f78e-7ff76db1f7ad call 7ff76db5e1b8 call 7ff76db1fe24 2064->2070 2071 7ff76db1f774-7ff76db1f77f call 7ff76db5e188 2064->2071 2065->2064 2069 7ff76db1f766-7ff76db1f76d 2065->2069 2067->2068 2075 7ff76db1f8fb-7ff76db1f903 call 7ff76db27904 2067->2075 2068->2063 2069->2064 2077 7ff76db1f7e3-7ff76db1f7f0 CloseHandle 2069->2077 2070->2077 2097 7ff76db1f7af-7ff76db1f7b2 2070->2097 2071->2070 2086 7ff76db1f781-7ff76db1f78c ShowWindow 2071->2086 2082 7ff76db1f7f2-7ff76db1f803 call 7ff76db113c4 2077->2082 2083 7ff76db1f805-7ff76db1f80c 2077->2083 2082->2083 2084 7ff76db1f82e-7ff76db1f830 2082->2084 2083->2084 2085 7ff76db1f80e-7ff76db1f811 2083->2085 2084->2059 2092 7ff76db1f832-7ff76db1f835 2084->2092 2085->2084 2091 7ff76db1f813-7ff76db1f828 2085->2091 2086->2070 2091->2084 2092->2059 2096 7ff76db1f837-7ff76db1f845 ShowWindow 2092->2096 2096->2059 2097->2077 2099 7ff76db1f7b4-7ff76db1f7c5 GetExitCodeProcess 2097->2099 2099->2077 2100 7ff76db1f7c7-7ff76db1f7dc 2099->2100 2100->2077
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ShowWindow$CloseCodeExecuteExitHandleProcessShell_invalid_parameter_noinfo_noreturn
      • String ID: .exe$.inf$Install$p
      • API String ID: 1054546013-3607691742
      • Opcode ID: 48140b0d21dce65f81d100c807e52341a8602df26a51c2eeeaab42c3cb1b7ebd
      • Instruction ID: 2402fdd531d21fe0a42fc7fc6077588ec1d1b2f268ab2e125b601288b42688c9
      • Opcode Fuzzy Hash: 48140b0d21dce65f81d100c807e52341a8602df26a51c2eeeaab42c3cb1b7ebd
      • Instruction Fuzzy Hash: DFC16D62F2C602D5FB11EB65D94027DA3A2AF8DB84F844131DA4D47AA9FF7CE855C320

      Control-flow Graph

      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Message$Send$DialogDispatchItemPeekShowTranslateWindow
      • String ID:
      • API String ID: 3569833718-0
      • Opcode ID: 6d17268858d6b6aed380ad60cc2cf8b16547cb3a0c40a3112c59011326a33119
      • Instruction ID: ee477364f1235bcdcbb936c56ffd7913d54cbaa95d16ec8a9adaeef4baaf5ca8
      • Opcode Fuzzy Hash: 6d17268858d6b6aed380ad60cc2cf8b16547cb3a0c40a3112c59011326a33119
      • Instruction Fuzzy Hash: 1341D432B28642C6F300EF61E800BAD6360EB8DB88F840135DD0D47B9CDE7DD8498764
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3668304517-0
      • Opcode ID: 809eb512f13192bff50bcfd52d504cde0913946dec18b9405ddbe5e6ea7d9c14
      • Instruction ID: b8184999ef1c2b379f70869ec9e68ba718aa77e24428f811fddea7ec3bdbd39f
      • Opcode Fuzzy Hash: 809eb512f13192bff50bcfd52d504cde0913946dec18b9405ddbe5e6ea7d9c14
      • Instruction Fuzzy Hash: D212C062F2CB42C4EA20EB64D4446FDA371EB457A8F840276DA5C17AD9EF3CD989C310

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 3763 7ff76db024c0-7ff76db024fb 3764 7ff76db02506 3763->3764 3765 7ff76db024fd-7ff76db02504 3763->3765 3766 7ff76db02509-7ff76db02578 3764->3766 3765->3764 3765->3766 3767 7ff76db0257d-7ff76db025a8 CreateFileW 3766->3767 3768 7ff76db0257a 3766->3768 3769 7ff76db025ae-7ff76db025de GetLastError call 7ff76db06a0c 3767->3769 3770 7ff76db02688-7ff76db0268d 3767->3770 3768->3767 3779 7ff76db025e0-7ff76db0262a CreateFileW GetLastError 3769->3779 3780 7ff76db0262c 3769->3780 3771 7ff76db02693-7ff76db02697 3770->3771 3773 7ff76db026a5-7ff76db026a9 3771->3773 3774 7ff76db02699-7ff76db0269c 3771->3774 3777 7ff76db026cf-7ff76db026e3 3773->3777 3778 7ff76db026ab-7ff76db026af 3773->3778 3774->3773 3776 7ff76db0269e 3774->3776 3776->3773 3782 7ff76db026e5-7ff76db026f0 3777->3782 3783 7ff76db0270c-7ff76db02735 call 7ff76db22320 3777->3783 3778->3777 3781 7ff76db026b1-7ff76db026c9 SetFileTime 3778->3781 3784 7ff76db02632-7ff76db0263a 3779->3784 3780->3784 3781->3777 3786 7ff76db026f2-7ff76db026fa 3782->3786 3787 7ff76db02708 3782->3787 3788 7ff76db02673-7ff76db02686 3784->3788 3789 7ff76db0263c-7ff76db02653 3784->3789 3791 7ff76db026ff-7ff76db02703 call 7ff76daf20b0 3786->3791 3792 7ff76db026fc 3786->3792 3787->3783 3788->3771 3793 7ff76db02655-7ff76db02668 3789->3793 3794 7ff76db0266e call 7ff76db2220c 3789->3794 3791->3787 3792->3791 3793->3794 3797 7ff76db02736-7ff76db0273b call 7ff76db27904 3793->3797 3794->3788
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: File$CreateErrorLast$Time_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3536497005-0
      • Opcode ID: 33f6b48159d5b7d750ef9f2960fa93fa1ced6f4fdcb3bbf877704cc21e72eec3
      • Instruction ID: 00f2fdff30aeb3d09c26d0ac8b7e68fa3b991b34cca5e2ceee5023d76f933c1e
      • Opcode Fuzzy Hash: 33f6b48159d5b7d750ef9f2960fa93fa1ced6f4fdcb3bbf877704cc21e72eec3
      • Instruction Fuzzy Hash: 2261E366A2C681C5E7209B29E54076EA7B1FB887A8F501334DFAD03ADCEF3DD4588714

      Control-flow Graph

      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Global$Resource$Object$AllocBitmapCreateDeleteGdipLoadLock$FindFreeFromSizeofStreamUnlock
      • String ID: ]
      • API String ID: 3561356813-3352871620
      • Opcode ID: 2f79d63664e457f963bfbd157e1c525b341384e02eb8e860e1f42d2dee528bbf
      • Instruction ID: 53bec2ebfc137fcaab81dcfe7b7838d2544a37d32c6755d9af814a8184aeb34d
      • Opcode Fuzzy Hash: 2f79d63664e457f963bfbd157e1c525b341384e02eb8e860e1f42d2dee528bbf
      • Instruction Fuzzy Hash: 2C115425B1D643C1FA65BB119A55279D393AF8DBC4F880038D95D47B9DFE2CE8048614

      Control-flow Graph

      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Message$DialogDispatchPeekTranslate
      • String ID:
      • API String ID: 1266772231-0
      • Opcode ID: 8f901ab8bb575df3ccfb48a5cb3294f091b017f84468599a2020223c8e70b7dc
      • Instruction ID: d91a0bb074895c126ecbd37e89f0f266e87f1a490c952d32e1ebec825c639667
      • Opcode Fuzzy Hash: 8f901ab8bb575df3ccfb48a5cb3294f091b017f84468599a2020223c8e70b7dc
      • Instruction Fuzzy Hash: 35F09126B3C552C2FB50AF25E855E7AA361BF98B45FD05431E54E81858EF2CD509CB10

      Control-flow Graph

      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: AutoClassCompareCompleteFindNameStringWindow
      • String ID: EDIT
      • API String ID: 4243998846-3080729518
      • Opcode ID: 5198dd27efd6ef2cfe81d4e1a42d30dc263c523227a297f5f4c02164b2b5e029
      • Instruction ID: 5bfcedf53e8f06dc32d94c63d92bd47e65395eab0cc1cd20353842c1d7f3f0e5
      • Opcode Fuzzy Hash: 5198dd27efd6ef2cfe81d4e1a42d30dc263c523227a297f5f4c02164b2b5e029
      • Instruction Fuzzy Hash: F3016D21B3CA83C1FE20AB21EC107BAA391AF9C740FC80031C95D4B65CFE6CE549CA60

      Control-flow Graph

      • Executed
      • Not Executed
      control_flow_graph 4073 7ff76db02ce0-7ff76db02d0a 4074 7ff76db02d13-7ff76db02d1b 4073->4074 4075 7ff76db02d0c-7ff76db02d0e 4073->4075 4077 7ff76db02d1d-7ff76db02d28 GetStdHandle 4074->4077 4078 7ff76db02d2b 4074->4078 4076 7ff76db02ea9-7ff76db02ec4 call 7ff76db22320 4075->4076 4077->4078 4080 7ff76db02d31-7ff76db02d3d 4078->4080 4082 7ff76db02d86-7ff76db02da2 WriteFile 4080->4082 4083 7ff76db02d3f-7ff76db02d44 4080->4083 4086 7ff76db02da6-7ff76db02da9 4082->4086 4084 7ff76db02d46-7ff76db02d7a WriteFile 4083->4084 4085 7ff76db02daf-7ff76db02db3 4083->4085 4084->4086 4087 7ff76db02d7c-7ff76db02d82 4084->4087 4088 7ff76db02ea2-7ff76db02ea6 4085->4088 4089 7ff76db02db9-7ff76db02dbd 4085->4089 4086->4085 4086->4088 4087->4084 4090 7ff76db02d84 4087->4090 4088->4076 4089->4088 4091 7ff76db02dc3-7ff76db02dd8 call 7ff76dafb4f8 4089->4091 4090->4086 4094 7ff76db02e1e-7ff76db02e6d call 7ff76db2797c call 7ff76daf129c call 7ff76dafbca8 4091->4094 4095 7ff76db02dda-7ff76db02de1 4091->4095 4094->4088 4106 7ff76db02e6f-7ff76db02e86 4094->4106 4095->4080 4097 7ff76db02de7-7ff76db02de9 4095->4097 4097->4080 4099 7ff76db02def-7ff76db02e19 4097->4099 4099->4080 4107 7ff76db02e9d call 7ff76db2220c 4106->4107 4108 7ff76db02e88-7ff76db02e9b 4106->4108 4107->4088 4108->4107 4109 7ff76db02ec5-7ff76db02ecb call 7ff76db27904 4108->4109
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: FileWrite$Handle
      • String ID:
      • API String ID: 4209713984-0
      • Opcode ID: 0e24b38da4911ce84cd1995b05bc76a48cdbb6549566894b7731c3bd6f5b2069
      • Instruction ID: b515a32f15037976b8007df4349da10b902a905e9fe1cbcdfdd7b7e70004ded4
      • Opcode Fuzzy Hash: 0e24b38da4911ce84cd1995b05bc76a48cdbb6549566894b7731c3bd6f5b2069
      • Instruction Fuzzy Hash: 8751E822A3D642D2FA20AB15D444B7AA360FF49794FC41231DB0D46A98FF7CE889C350

      Control-flow Graph

      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$TextWindow
      • String ID:
      • API String ID: 2912839123-0
      • Opcode ID: ddbc6463633b4561293e059f1e2bc995c27909e3b92e1583c4456597393468a2
      • Instruction ID: 55ba759824bbd2c820326d1e9e16bb3b60c50a11e5646d3454afc057651543f6
      • Opcode Fuzzy Hash: ddbc6463633b4561293e059f1e2bc995c27909e3b92e1583c4456597393468a2
      • Instruction Fuzzy Hash: 31518F63F38692C4FB00ABA5D8542BDA322AB49B94FC04636DA5C16BD9FE6CD440C320
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: CreateDirectory$ErrorLast_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 2359106489-0
      • Opcode ID: c692564d5d1c2d87129f870fd8c4aa882645ff23391cbc0b7309d447f995f5b9
      • Instruction ID: f000a739bbe79a3810c4782f7994b7a8430ea3c8731dc160abcbee29ccc8bad9
      • Opcode Fuzzy Hash: c692564d5d1c2d87129f870fd8c4aa882645ff23391cbc0b7309d447f995f5b9
      • Instruction Fuzzy Hash: E131B566A2C682C1EA20BB25A458E7DE351FF8C7A0FD44231EE9D827DDEF3CD4458610
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: __scrt_acquire_startup_lock__scrt_dllmain_crt_thread_attach__scrt_get_show_window_mode__scrt_initialize_crt__scrt_release_startup_lock
      • String ID:
      • API String ID: 1452418845-0
      • Opcode ID: f380b52e8f95e6a0f24ce785192d8cb773bc143ddf3d62aee805abe4fb8ed354
      • Instruction ID: 94f2275f465c25b64c990bfbb1a8ae769a325621d8251e5128b6705af3b4c69f
      • Opcode Fuzzy Hash: f380b52e8f95e6a0f24ce785192d8cb773bc143ddf3d62aee805abe4fb8ed354
      • Instruction Fuzzy Hash: 0F313026A3C183C1FA64BB65D4113B99291AF4D784FC41438D94D8B6EFFE2CE8049271
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ErrorLast$FileHandleRead
      • String ID:
      • API String ID: 2244327787-0
      • Opcode ID: 5dece825d5be91adec6864fa12bb564f4e3b5809c08bfde6ef0babe01e3581d0
      • Instruction ID: e7e39c9f8bb866c7c1cb32cec18b79bc669e9f1327ec02c9c9c3049880295251
      • Opcode Fuzzy Hash: 5dece825d5be91adec6864fa12bb564f4e3b5809c08bfde6ef0babe01e3581d0
      • Instruction Fuzzy Hash: 52219521A2C642C9EA706B11E400A3DE368FF49B94F944534DA5D4E78CEF7CD8898761
      APIs
        • Part of subcall function 00007FF76DB0ECD8: ResetEvent.KERNEL32 ref: 00007FF76DB0ECF1
        • Part of subcall function 00007FF76DB0ECD8: ReleaseSemaphore.KERNEL32 ref: 00007FF76DB0ED07
      • ReleaseSemaphore.KERNEL32 ref: 00007FF76DB0E974
      • CloseHandle.KERNELBASE ref: 00007FF76DB0E993
      • DeleteCriticalSection.KERNEL32 ref: 00007FF76DB0E9AA
      • CloseHandle.KERNEL32 ref: 00007FF76DB0E9B7
        • Part of subcall function 00007FF76DB0EA5C: WaitForSingleObject.KERNEL32(?,?,?,?,?,?,?,?,00007FF76DB0E95F,?,?,?,00007FF76DB0463A,?,?,?), ref: 00007FF76DB0EA63
        • Part of subcall function 00007FF76DB0EA5C: GetLastError.KERNEL32(?,?,?,?,?,?,?,?,00007FF76DB0E95F,?,?,?,00007FF76DB0463A,?,?,?), ref: 00007FF76DB0EA6E
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: CloseHandleReleaseSemaphore$CriticalDeleteErrorEventLastObjectResetSectionSingleWait
      • String ID:
      • API String ID: 502429940-0
      • Opcode ID: 7c4c69b688bb09167c3d8ec6f4195a818a409db0987586a56ae23aa503e7e0cd
      • Instruction ID: 0c208e0593075f28d7f1f81e908fe344851f75c56058c7a5f44c849f648f824b
      • Opcode Fuzzy Hash: 7c4c69b688bb09167c3d8ec6f4195a818a409db0987586a56ae23aa503e7e0cd
      • Instruction Fuzzy Hash: 2D012D36A28A81D2E648AB21E58466DE331FB8CB90F404031DB6D43629DF79E4B4C754
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Thread$CreatePriority
      • String ID: CreateThread failed
      • API String ID: 2610526550-3849766595
      • Opcode ID: cf4f3858e1c5421656891f758a667cd72a6f2059ba57d4f8d940dbc9b5e0f540
      • Instruction ID: f3e015822f2101a7dec5697a117ae1bca23e7d67b9cdd28408896b17d6316a28
      • Opcode Fuzzy Hash: cf4f3858e1c5421656891f758a667cd72a6f2059ba57d4f8d940dbc9b5e0f540
      • Instruction Fuzzy Hash: F0115E31A2CA42C2EB10EB15E8416A9F361FB88784F984231D64D4266CFF7CE981C760
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: DirectoryInitializeMallocSystem
      • String ID: riched20.dll
      • API String ID: 174490985-3360196438
      • Opcode ID: 0d85db053d286d1bd0fa19ead2840fc3f5149c6ee0f027e6ed6c33eb2c824e37
      • Instruction ID: 36fbc84c4048a9ad02a2f0a5c69ad89a1458b36b9ce81baa2840b27f7f395ca0
      • Opcode Fuzzy Hash: 0d85db053d286d1bd0fa19ead2840fc3f5149c6ee0f027e6ed6c33eb2c824e37
      • Instruction Fuzzy Hash: 53F03C71A2CA81C2EB11AF20F45556EB3A0FB88754F840135E98D82B58EFBCD5498B20
      APIs
        • Part of subcall function 00007FF76DB1853C: GlobalMemoryStatusEx.KERNEL32 ref: 00007FF76DB1856C
        • Part of subcall function 00007FF76DB0AAE0: LoadStringW.USER32 ref: 00007FF76DB0AB67
        • Part of subcall function 00007FF76DB0AAE0: LoadStringW.USER32 ref: 00007FF76DB0AB80
        • Part of subcall function 00007FF76DAF1FA0: _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF76DAF1FFB
        • Part of subcall function 00007FF76DAF129C: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF76DAF1396
      • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF76DB201BB
      • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF76DB201C1
      • SendDlgItemMessageW.USER32 ref: 00007FF76DB201F2
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$LoadString$Concurrency::cancel_current_taskGlobalItemMemoryMessageSendStatus
      • String ID:
      • API String ID: 3106221260-0
      • Opcode ID: c331156a73b0a66eb66e79d0130550220cf0b56257511766079ec54958d0214b
      • Instruction ID: 6cd9289998daf79d39aa79e0144d95d27f94bdedfadf49798e6c6008bff60f3e
      • Opcode Fuzzy Hash: c331156a73b0a66eb66e79d0130550220cf0b56257511766079ec54958d0214b
      • Instruction Fuzzy Hash: C851B262F2D682D6FB10ABA5D4516FDA322AB89784F800236DA0D577DEFE6CD500C360
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Concurrency::cancel_current_task__std_exception_copy_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 2371198981-0
      • Opcode ID: 311d9ade44a112f174f5058e8ed5e9daeb1f31e852fd979eace312b941542748
      • Instruction ID: 054226b50e55bfd4d697e7e39823d8afba691d04284e55a6be9fb1d87bf82caa
      • Opcode Fuzzy Hash: 311d9ade44a112f174f5058e8ed5e9daeb1f31e852fd979eace312b941542748
      • Instruction Fuzzy Hash: EE4115A2B2C685C1EA14EF12E6405B9E355EB04BE0F884632DE6C07BD9FF7CE4918314
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: CreateFile$_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 2272807158-0
      • Opcode ID: c0a24921bb432fc979f0151b166e22e2d4d2ab91ccee52ff8beeeb5fa3cca71f
      • Instruction ID: 91d2d010de71d0aac7c78946de55b6ea5decd75851fb430c7148c8f250732f7e
      • Opcode Fuzzy Hash: c0a24921bb432fc979f0151b166e22e2d4d2ab91ccee52ff8beeeb5fa3cca71f
      • Instruction Fuzzy Hash: 3541D673A2C781C2EB20AB15E444669A3A1FB897B4F905334DFAD07AD9EF7CD4948710
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: TextWindow$Length_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 2176759853-0
      • Opcode ID: 41410b057bf1bfc832f9111b5635005432e9644e209f963b7c0d07f0c95fee55
      • Instruction ID: 07d50b4ee15061f5f43dc54771c31a22674d87bca5919547f0240d0cf3ac2c72
      • Opcode Fuzzy Hash: 41410b057bf1bfc832f9111b5635005432e9644e209f963b7c0d07f0c95fee55
      • Instruction Fuzzy Hash: 37219362A2CB8181EA209B65A44057EA364FB8DBD0F945236EB9D43B99EF7CD541C700
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: std::bad_alloc::bad_alloc
      • String ID:
      • API String ID: 1875163511-0
      • Opcode ID: 65d8091f10f06cce83768fe095ce433e052fa83f4fe25a8c85fad3cbd40ccd0d
      • Instruction ID: fcd8c356187fe417ad4cba1c7e8a635529cbd53e1f47e21f422fe1f0c9fe9210
      • Opcode Fuzzy Hash: 65d8091f10f06cce83768fe095ce433e052fa83f4fe25a8c85fad3cbd40ccd0d
      • Instruction Fuzzy Hash: F031D412A2C687D5FB25B710E8493B9A3A1FB59B84F944135D24C029ADFF7CD946C311
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: AttributesFile$_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 1203560049-0
      • Opcode ID: a1f7dc1dbaba3642fc9690cddce522cfa30acb7a6fd15afbd6a0ae69969149b0
      • Instruction ID: cd144a3bffaf5ee236f1f5eca38c68587ad55349c4850271a0db6d2e7d5264bc
      • Opcode Fuzzy Hash: a1f7dc1dbaba3642fc9690cddce522cfa30acb7a6fd15afbd6a0ae69969149b0
      • Instruction Fuzzy Hash: 5221F822A2C781C1EA20AF25E44567EA360FF8CB94F805330EA9D4679CFF3DD540C650
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: DeleteFile$_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3118131910-0
      • Opcode ID: 69d2c27007a20e930861445e234d5951a1cf09c7b93575dd70fe51422861bc3e
      • Instruction ID: 9e3da84e984512932762b12d1145c3048efb4227e3d9adc7e036b6023603a1a1
      • Opcode Fuzzy Hash: 69d2c27007a20e930861445e234d5951a1cf09c7b93575dd70fe51422861bc3e
      • Instruction Fuzzy Hash: 22218622A2C781C1EA10AB25E44566EA360FF8DB94F905234EA9E46B9DFF3CD541C650
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: AttributesFile$_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 1203560049-0
      • Opcode ID: 07782a0afab47d92a22bff3076416a7edfcd43da74ab10a948eda14518e6746e
      • Instruction ID: 5b9b42d867b832ad163c0eb95dbb785a8dcf1e040e9a6b93c74e9a97ef251373
      • Opcode Fuzzy Hash: 07782a0afab47d92a22bff3076416a7edfcd43da74ab10a948eda14518e6746e
      • Instruction Fuzzy Hash: 89217422A2C781C1EA20AB29E48452DA371FBCD7A4F905331EA9D47BEDEF7CD541C614
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Process$CurrentExitTerminate
      • String ID:
      • API String ID: 1703294689-0
      • Opcode ID: 44b3a526fe0d15710854bc957cc7a82f9edee4cc7420f0560de4bec5ea2a17a0
      • Instruction ID: 4f14d586afebc6c5f953336dc2cd215c5a046e84be9051a7c310168991bf678e
      • Opcode Fuzzy Hash: 44b3a526fe0d15710854bc957cc7a82f9edee4cc7420f0560de4bec5ea2a17a0
      • Instruction Fuzzy Hash: 1DE09A2AE2C745C2EB447B218890379A352AF8C741F400038C80E0339EFE7CA4088722
      APIs
      • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF76DAFF895
      • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF76DAFF89B
        • Part of subcall function 00007FF76DB03EC8: FindClose.KERNELBASE(?,?,00000000,00007FF76DB10811), ref: 00007FF76DB03EFD
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$CloseFind
      • String ID:
      • API String ID: 3587649625-0
      • Opcode ID: 1dab662a9ca4cd49b80cf28d58332847119bc68e87dbe30dfd54b4e2fad17f15
      • Instruction ID: a2aeba43c7c5aca6f831ef69651768d26a00e90fbe9e9c1282f16167a82c1734
      • Opcode Fuzzy Hash: 1dab662a9ca4cd49b80cf28d58332847119bc68e87dbe30dfd54b4e2fad17f15
      • Instruction Fuzzy Hash: BB919F73A2C681D0EB10EF24D8446EDA361FB84B98FD44536EA4C07AE9EF78D949C350
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3668304517-0
      • Opcode ID: e528197958c249f96fae0a8177de4e8d77b9f71d72b6948629aa37281091aefa
      • Instruction ID: f490b31c8e91b15acf49519dca7de3b8853539e62b2cf8e2bbe8fb5c610aeec6
      • Opcode Fuzzy Hash: e528197958c249f96fae0a8177de4e8d77b9f71d72b6948629aa37281091aefa
      • Instruction Fuzzy Hash: 8741A262F2D652C4FB10FB71D4506FDA321AF44B94F981136DE5D27A99EE38D8828210
      APIs
      • SetFilePointer.KERNELBASE(00000000,00000002,?,00000F99,?,00007FF76DB0274D), ref: 00007FF76DB028A9
      • GetLastError.KERNEL32(?,00007FF76DB0274D), ref: 00007FF76DB028B8
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ErrorFileLastPointer
      • String ID:
      • API String ID: 2976181284-0
      • Opcode ID: 043a82e8aff847b2e282b78885e55c7214a93c585b530bdf19c19deffc600893
      • Instruction ID: e02c78dc099d93707ea5b0f7c8e627cb2c41a48640bc62a4c31d92ebf1f0cb17
      • Opcode Fuzzy Hash: 043a82e8aff847b2e282b78885e55c7214a93c585b530bdf19c19deffc600893
      • Instruction Fuzzy Hash: D031B626B3D752C2EE746B2AD580A7DA350AF08BD4F940131DE1D47B98FE3CD8499660
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Item_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 1746051919-0
      • Opcode ID: 8d40ccc84b580f33f3dafee36447434fcdf79cb76bf08fc935a239d44bb79c76
      • Instruction ID: 180baf892e1f7433171beb1f3e1442b7f2a22d56f506b99b754ae1079c6898d5
      • Opcode Fuzzy Hash: 8d40ccc84b580f33f3dafee36447434fcdf79cb76bf08fc935a239d44bb79c76
      • Instruction Fuzzy Hash: D531F662A2C781C1EA20AF15E4443BEF360EB84790F845232E79C4BB99FF3CE5448714
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: File$BuffersFlushTime
      • String ID:
      • API String ID: 1392018926-0
      • Opcode ID: 1f7bfd0f82637a6abdcd08aef8b442a865f6f50d97ba3a1fa7ef62b0e093425a
      • Instruction ID: debea80a831a1b0145c590366c707a0ec899d3153c24a3ef9a62df1e2e1f13ac
      • Opcode Fuzzy Hash: 1f7bfd0f82637a6abdcd08aef8b442a865f6f50d97ba3a1fa7ef62b0e093425a
      • Instruction Fuzzy Hash: 3E21C462F1DB42D9FA76AE11D444BBAD790AF09794F954031DE4C062A9FE3CE48EC310
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: LoadString
      • String ID:
      • API String ID: 2948472770-0
      • Opcode ID: efc1550bd5bba1d5ac9face2304fa075ed5e4cb94ffc19493764f318ca00d951
      • Instruction ID: ccb1d13a7e344816565a5ed7a5c1686e78526328973817433f3d586972e08976
      • Opcode Fuzzy Hash: efc1550bd5bba1d5ac9face2304fa075ed5e4cb94ffc19493764f318ca00d951
      • Instruction Fuzzy Hash: 89119D71B2C601C6EA40AF1AA844968F7A1BF8DFC0F944435CE0DA3B28EF7CE9418754
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ErrorFileLastPointer
      • String ID:
      • API String ID: 2976181284-0
      • Opcode ID: 5eda2cbf1ce6837a88d649c872729f31e823bc49095d59e5e9b193bf7b9166cd
      • Instruction ID: 72a9622c3434092795b83428bc286cf9091cab082ac8d9e965fedf1614a7794d
      • Opcode Fuzzy Hash: 5eda2cbf1ce6837a88d649c872729f31e823bc49095d59e5e9b193bf7b9166cd
      • Instruction Fuzzy Hash: EC119D21A2C641C1FB70AB25E480679A360FB59778F944331DA7D566DCEF3CD586C310
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ItemRectTextWindow$Clientswprintf
      • String ID:
      • API String ID: 3322643685-0
      • Opcode ID: ad94589889145b650e3461eb84003e845283bd92425fc2a9221c8100a4e27e71
      • Instruction ID: 949027cbaff123dc84c904f41d66e07a3e867e6f433956907a6b5f2e2a7b65f9
      • Opcode Fuzzy Hash: ad94589889145b650e3461eb84003e845283bd92425fc2a9221c8100a4e27e71
      • Instruction Fuzzy Hash: 09017510A2D28AC1FF657F52A454AB9D7519F49748FCC4075C84D466DDFE2CEC85C320
      APIs
      • GetCurrentProcess.KERNEL32(?,?,?,?,00007FF76DB0EBAD,?,?,?,?,00007FF76DB05752,?,?,?,00007FF76DB056DE), ref: 00007FF76DB0EB5C
      • GetProcessAffinityMask.KERNEL32 ref: 00007FF76DB0EB6F
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Process$AffinityCurrentMask
      • String ID:
      • API String ID: 1231390398-0
      • Opcode ID: 444071b75e142e51b736d9fa504759652bc9944b894df1f8101a797a07211085
      • Instruction ID: fc39bd837abb03a4c3d7e944a475ce5106530445980e5e1b7c2219f72fcfb55e
      • Opcode Fuzzy Hash: 444071b75e142e51b736d9fa504759652bc9944b894df1f8101a797a07211085
      • Instruction Fuzzy Hash: 86E06565B2894686DB599B55C4519A9A392BF8CB40FC48035D60FC3A18EE2CE5458B50
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Concurrency::cancel_current_task$std::bad_alloc::bad_alloc
      • String ID:
      • API String ID: 1173176844-0
      • Opcode ID: ac554a43d54612151bc7e480101717375080be3004ee5b366f50feb51e7139dd
      • Instruction ID: ef0aedd32490d2b9f4a5e9b4525cf050f3c0868e1ef434082e8d8fc4fce51661
      • Opcode Fuzzy Hash: ac554a43d54612151bc7e480101717375080be3004ee5b366f50feb51e7139dd
      • Instruction Fuzzy Hash: D5E0EC42E3E187C5F938366158265B580504F2D771EDC1730DE3E842DEBD1CA5928530
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ErrorFreeHeapLast
      • String ID:
      • API String ID: 485612231-0
      • Opcode ID: 7829e02dcbd74b51c5e196648e5aad52518f68633834b7095f7e5950a32ae739
      • Instruction ID: 04e2b524abd4aa41ea43a078b247595a2b06b145ecdd3278846e9784e6086a7c
      • Opcode Fuzzy Hash: 7829e02dcbd74b51c5e196648e5aad52518f68633834b7095f7e5950a32ae739
      • Instruction Fuzzy Hash: 24E08651E2D183C2FF057BB2B8452B892915FDCB50F840034D90D8625AFE7C94818660
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3668304517-0
      • Opcode ID: bdd91355d2d85a11a0457ea89a247bcc926dc6e93a1eb2f33b56411797ecd77f
      • Instruction ID: 8de493be7e75f18d4886211414d7c66ebaaf5450cca28d15f8407a6de1cf3715
      • Opcode Fuzzy Hash: bdd91355d2d85a11a0457ea89a247bcc926dc6e93a1eb2f33b56411797ecd77f
      • Instruction Fuzzy Hash: 16D1CA62B2C681D5EF68AB25C5406F9F7A1FB05B84F880476CB9D477A5DF3CE8608321
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: CompareString_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 1017591355-0
      • Opcode ID: d592eabcbe9af83a373b8b16b8cc449c2e49e9c4d9704c8b20a1f27e4dd7bd8a
      • Instruction ID: fc2ce590185a1fb4912851ef4a070a2612c762843fdc415775337574d2062ef8
      • Opcode Fuzzy Hash: d592eabcbe9af83a373b8b16b8cc449c2e49e9c4d9704c8b20a1f27e4dd7bd8a
      • Instruction Fuzzy Hash: F861EE51A2C647C1FA64BA254814ABED2D5AF4DBD0F940531EE4E06ECDFEACE8408238
      APIs
        • Part of subcall function 00007FF76DB0E948: ReleaseSemaphore.KERNEL32 ref: 00007FF76DB0E974
        • Part of subcall function 00007FF76DB0E948: CloseHandle.KERNELBASE ref: 00007FF76DB0E993
        • Part of subcall function 00007FF76DB0E948: DeleteCriticalSection.KERNEL32 ref: 00007FF76DB0E9AA
        • Part of subcall function 00007FF76DB0E948: CloseHandle.KERNEL32 ref: 00007FF76DB0E9B7
      • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF76DB11ACB
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: CloseHandle$CriticalDeleteReleaseSectionSemaphore_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 904680172-0
      • Opcode ID: d0ac03a7bcf372d2f09e5791c3f93ba946dfab79c47e876fabcf93b187fb1f6c
      • Instruction ID: dbfbe491f7e84261b2de171eb3e2deb662fa50d8c00be642caa6e434f8f38bd5
      • Opcode Fuzzy Hash: d0ac03a7bcf372d2f09e5791c3f93ba946dfab79c47e876fabcf93b187fb1f6c
      • Instruction Fuzzy Hash: AD61C062B39685D2EE08EF65D5541BCB365FB58FC0F984132D72D07AC9EF28E4658310
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3668304517-0
      • Opcode ID: f25d7cbdbd4b6051481d9dea9bfabb1fe63e2ef918cd70fdc00b4907c2d0f41a
      • Instruction ID: 2da3da13946a58ff8f6d876ea9c3ba044cf79eab499c711c25742f6c33300bcc
      • Opcode Fuzzy Hash: f25d7cbdbd4b6051481d9dea9bfabb1fe63e2ef918cd70fdc00b4907c2d0f41a
      • Instruction Fuzzy Hash: EF51D652A2C681D0EA14AF15E444BFDA751FB89BC4F880173EE4D47796EE3DE985C320
      APIs
        • Part of subcall function 00007FF76DB03EC8: FindClose.KERNELBASE(?,?,00000000,00007FF76DB10811), ref: 00007FF76DB03EFD
      • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF76DAFE993
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: CloseFind_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 1011579015-0
      • Opcode ID: 1ed87b38f53b3cf50e1c2200cac218cce737f4e527dde5fbd83d50be022e59e1
      • Instruction ID: 3c9b13792bb3f936ff0fb37f14b6aae926a3ebfda568f596bcdd8f16e2f487d6
      • Opcode Fuzzy Hash: 1ed87b38f53b3cf50e1c2200cac218cce737f4e527dde5fbd83d50be022e59e1
      • Instruction Fuzzy Hash: 1351A322A2C785C1FB60AF24D4847BDA361FF84B84F880576DA9D476A9EF2CD941C360
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3668304517-0
      • Opcode ID: edbd1a57a037b29b8a92448ef74654e9c5fa8602ea7b4a83cea3799d4ce57b1a
      • Instruction ID: da79c3b57c39d4868a944dcfd2b1be3ca388253468d46c779081916fb22cdcdd
      • Opcode Fuzzy Hash: edbd1a57a037b29b8a92448ef74654e9c5fa8602ea7b4a83cea3799d4ce57b1a
      • Instruction Fuzzy Hash: 6541CA62B2C79181EA18AB17A544779E251FB88FC4F888535EE4C47F5EEF7CD5518300
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3668304517-0
      • Opcode ID: 56fb8cc9aabd16c687145b8809587fd2b26f3257f780f8e7ed96006f2e57f286
      • Instruction ID: 43c7cd005f81d45209fdf40e2e853b568776491519e4ebd37151560b135a699a
      • Opcode Fuzzy Hash: 56fb8cc9aabd16c687145b8809587fd2b26f3257f780f8e7ed96006f2e57f286
      • Instruction Fuzzy Hash: B4411762A2DB41C0EE10AB25E549B7DA361EB8DBD4F845139EA4D0779DFF3DE4808320
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: HandleModule$AddressFreeLibraryProc
      • String ID:
      • API String ID: 3947729631-0
      • Opcode ID: 5b4d6432c9ab27f48bf344f41163fa66ca8822e5b5ed34cf2c0174bd429b5c6d
      • Instruction ID: ac08cc31aa92c2fcee06964bf6dd0f3d31f255fe0c3d4ee7a50fd9f538f0fdab
      • Opcode Fuzzy Hash: 5b4d6432c9ab27f48bf344f41163fa66ca8822e5b5ed34cf2c0174bd429b5c6d
      • Instruction Fuzzy Hash: 8E419123E3C682C2FA14BB11D490178A2A1AF5CB50FC4483ADA0D47AADFF7DE8418765
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Concurrency::cancel_current_taskstd::bad_alloc::bad_alloc
      • String ID:
      • API String ID: 680105476-0
      • Opcode ID: 6f88c17e658a7e6a764477403b9247f1d27f5880b65831beeeee99c6ba04093e
      • Instruction ID: c0d5523d81428962b6269ce66aa486ea3f75665d71ec60c94642b0481653a8ab
      • Opcode Fuzzy Hash: 6f88c17e658a7e6a764477403b9247f1d27f5880b65831beeeee99c6ba04093e
      • Instruction Fuzzy Hash: A621A362A1C651C5EA64AF91A4006B9A250EB04BF0F9C0732DF3D47BC5FE7CE8518350
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo
      • String ID:
      • API String ID: 3215553584-0
      • Opcode ID: 9dd5a9e84c18447e56e2265fa04046f11d37b96b7f5b774ce3305aa6458b3f00
      • Instruction ID: ae6d1af5f330b188bd52971263153f7356dea2250eb7160b32a4200033c3fe2d
      • Opcode Fuzzy Hash: 9dd5a9e84c18447e56e2265fa04046f11d37b96b7f5b774ce3305aa6458b3f00
      • Instruction Fuzzy Hash: 6D11513292C682C6F710AF55E840579F2A9FB4C380FDA0135EA4D87A99FF6CE8109764
      APIs
        • Part of subcall function 00007FF76DB1F0A4: GetDlgItem.USER32 ref: 00007FF76DB1F0E3
        • Part of subcall function 00007FF76DB1F0A4: ShowWindow.USER32 ref: 00007FF76DB1F109
        • Part of subcall function 00007FF76DB1F0A4: SendMessageW.USER32 ref: 00007FF76DB1F11E
        • Part of subcall function 00007FF76DB1F0A4: SendMessageW.USER32 ref: 00007FF76DB1F136
        • Part of subcall function 00007FF76DB1F0A4: SendMessageW.USER32 ref: 00007FF76DB1F157
        • Part of subcall function 00007FF76DB1F0A4: SendMessageW.USER32 ref: 00007FF76DB1F173
        • Part of subcall function 00007FF76DB1F0A4: SendMessageW.USER32 ref: 00007FF76DB1F1B6
        • Part of subcall function 00007FF76DB1F0A4: SendMessageW.USER32 ref: 00007FF76DB1F1D4
        • Part of subcall function 00007FF76DB1F0A4: SendMessageW.USER32 ref: 00007FF76DB1F1E8
        • Part of subcall function 00007FF76DB1F0A4: SendMessageW.USER32 ref: 00007FF76DB1F212
        • Part of subcall function 00007FF76DB1F0A4: SendMessageW.USER32 ref: 00007FF76DB1F22A
      • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF76DB1FD03
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: MessageSend$ItemShowWindow_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 1587882848-0
      • Opcode ID: 7989e94252765e26adec07c6a490604036e5cdaaff5fd5deefe014bb99c4005d
      • Instruction ID: c0cb1b9146b113611f731d7ce2d9bb51b74da25056dc1bbd53393ffe2f99bfb8
      • Opcode Fuzzy Hash: 7989e94252765e26adec07c6a490604036e5cdaaff5fd5deefe014bb99c4005d
      • Instruction Fuzzy Hash: A701C8A3A3C68581E920A765D44537EA312EFCD794FD01331EA9C466DEFE2CE140C614
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3668304517-0
      • Opcode ID: 58579bce4bc1021bb98a03ef504395245509186ce5efb4717343b6b5f18682a3
      • Instruction ID: b911ac0a91be1fd51f4fa952bb1e5297994259997eecc7300db07442244973a4
      • Opcode Fuzzy Hash: 58579bce4bc1021bb98a03ef504395245509186ce5efb4717343b6b5f18682a3
      • Instruction Fuzzy Hash: 3601A162E3C6C5C1EA21A728E445269B361FF89790FC05332E6DC07AA9FF6CD5408615
      APIs
        • Part of subcall function 00007FF76DB21604: GetModuleHandleW.KERNEL32(?,?,?,00007FF76DB21573,?,?,?,00007FF76DB2192A), ref: 00007FF76DB2162B
      • DloadProtectSection.DELAYIMP ref: 00007FF76DB215C9
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: DloadHandleModuleProtectSection
      • String ID:
      • API String ID: 2883838935-0
      • Opcode ID: 908f49ac33541a8240f4269ada82e733cc5c0c647bda27ab8868a2cee9a60ef3
      • Instruction ID: f2bf5b608a11fa5d54e2c32965cfa0392c0d10001e671acf59917be0c1a99251
      • Opcode Fuzzy Hash: 908f49ac33541a8240f4269ada82e733cc5c0c647bda27ab8868a2cee9a60ef3
      • Instruction Fuzzy Hash: C711BA65D3D647C1FB61BF05E842374A350AF1C388F980075C90E862B9FE2DA8958661
      APIs
        • Part of subcall function 00007FF76DB040BC: FindFirstFileW.KERNELBASE ref: 00007FF76DB0410B
        • Part of subcall function 00007FF76DB040BC: FindFirstFileW.KERNEL32 ref: 00007FF76DB0415E
        • Part of subcall function 00007FF76DB040BC: GetLastError.KERNEL32 ref: 00007FF76DB041AF
      • FindClose.KERNELBASE(?,?,00000000,00007FF76DB10811), ref: 00007FF76DB03EFD
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Find$FileFirst$CloseErrorLast
      • String ID:
      • API String ID: 1464966427-0
      • Opcode ID: 18fe74ab7ca813274cb64c08179860cc48efc587ad39327f0b25563dc18ddab5
      • Instruction ID: ae8aa0648f7f480b12efa4aefa4287848279e714a800d9149e28ee9cf91fc08b
      • Opcode Fuzzy Hash: 18fe74ab7ca813274cb64c08179860cc48efc587ad39327f0b25563dc18ddab5
      • Instruction Fuzzy Hash: 04F0F46291C241C1EA10BB70A148979B3609F1EBB4F541338EA3D073CFDE2CD4448760
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: File
      • String ID:
      • API String ID: 749574446-0
      • Opcode ID: 7793d0dfaf1bed477703e517dfb550f1e48d00439aedf8bd4eeb9f79e866bcb3
      • Instruction ID: ba7d2757f57350c3c48e5b8b4138fd9b4ae2664e9f04654557b7a4508f6d0962
      • Opcode Fuzzy Hash: 7793d0dfaf1bed477703e517dfb550f1e48d00439aedf8bd4eeb9f79e866bcb3
      • Instruction Fuzzy Hash: 74E08C16E38615C2EF20BB2AC852A289320AF8CB84F895030CE0C47729DE2CC8858A10
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: FileType
      • String ID:
      • API String ID: 3081899298-0
      • Opcode ID: df9a28314c6b6fddfb177ebf539387614dcb0363737e1ba4f38fe55c4f903e1a
      • Instruction ID: 2be9b3efc0851beba05160e86685b6afef2d36f04cd3df8b2bd5fee0412fd473
      • Opcode Fuzzy Hash: df9a28314c6b6fddfb177ebf539387614dcb0363737e1ba4f38fe55c4f903e1a
      • Instruction Fuzzy Hash: 0ED0121AD1D441C2ED20A736D89143C6350AF9BB35FE40770D73EC16E5DE5D949AA321
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: CurrentDirectory
      • String ID:
      • API String ID: 1611563598-0
      • Opcode ID: 176ab68ebee512dad0278907058cd855c5c44f8615b79807412a7d406b36e525
      • Instruction ID: 7f4d7c436eeb6227bb0e0f03a82dd962dbc24853d07f1365ca2e09d21f6a1b34
      • Opcode Fuzzy Hash: 176ab68ebee512dad0278907058cd855c5c44f8615b79807412a7d406b36e525
      • Instruction Fuzzy Hash: 52C08C20F29542C1DA086B26C8C981853A5BB48B04FA14038C10CC1120EE2CC8FAA396
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: AllocHeap
      • String ID:
      • API String ID: 4292702814-0
      • Opcode ID: c4d23aaef5024e3722ccbb242168b3e22d65bf63548bcaacbbf61b8d0a3ba7a1
      • Instruction ID: 04a3e2033552d063e819a774e0fbb9fab9c1c79132ecb540366413d4573a38bd
      • Opcode Fuzzy Hash: c4d23aaef5024e3722ccbb242168b3e22d65bf63548bcaacbbf61b8d0a3ba7a1
      • Instruction Fuzzy Hash: 23F06256B2D287C5FE557BA699113B592A09FCEB80FC85430C90E863C9FD1CE5814230
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: CloseHandle
      • String ID:
      • API String ID: 2962429428-0
      • Opcode ID: ccbd9008d2c4ce7168f8d058ff2f34620ae6bf54bfe45a0cbca9d6a6f1a7c065
      • Instruction ID: 8b2980f74ab724d18605cb21e7786cc6939056df96c2d6d007a8c1cb97b0167b
      • Opcode Fuzzy Hash: ccbd9008d2c4ce7168f8d058ff2f34620ae6bf54bfe45a0cbca9d6a6f1a7c065
      • Instruction Fuzzy Hash: ABF0AF22A2C682C5FB349B20E085779A660EB18B78F894335DB3D011DCEF68D8998320
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: AllocHeap
      • String ID:
      • API String ID: 4292702814-0
      • Opcode ID: 5fa632deebd8181b9f3ea37834cf4eccbda839d7d0d6f948310c23224b4a93e7
      • Instruction ID: 467c68043c7e1f819432bcd4e5a4d08d8328babee25b6a3b7f200470c16101e2
      • Opcode Fuzzy Hash: 5fa632deebd8181b9f3ea37834cf4eccbda839d7d0d6f948310c23224b4a93e7
      • Instruction Fuzzy Hash: BFF05E52B2D287C4FF14777168403B592905FCC7A0FC81A30ED2E862C9FE1CE44081B0
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$CloseErrorFileHandleLastwcscpy$ControlCreateCurrentDeleteDeviceDirectoryProcessRemove
      • String ID: SeCreateSymbolicLinkPrivilege$SeRestorePrivilege$UNC\$\??\
      • API String ID: 2659423929-3508440684
      • Opcode ID: ba0fc76c453fe0fc40a0c4e7d0d05333b86268085c20e76f46298bccd8a5c1a2
      • Instruction ID: a97bb2fa51739051e77e55a7dbc835b384e7d8a8deebd2bca9ab0a075e22f5a1
      • Opcode Fuzzy Hash: ba0fc76c453fe0fc40a0c4e7d0d05333b86268085c20e76f46298bccd8a5c1a2
      • Instruction Fuzzy Hash: E562C062F2C682C5FB00EB75D4846FDA361AB897A4F944232DA6C53AD9FE7CD584C310
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$ErrorLastLoadString$Concurrency::cancel_current_taskInit_thread_footer
      • String ID: %ls$%s: %s
      • API String ID: 2539828978-2259941744
      • Opcode ID: eef6348a9063751b6e9008af8d2ebfd6cfbeec8057516790c7af88f51b0d5763
      • Instruction ID: e0efa44a671f355be4203870e2d11a1af6d0c874e273e524291d292b7a72fdb5
      • Opcode Fuzzy Hash: eef6348a9063751b6e9008af8d2ebfd6cfbeec8057516790c7af88f51b0d5763
      • Instruction Fuzzy Hash: 6EB2A862A3C682C1EA11BB25D8545BAE321EFCE790F904236E69D43BDEFE6CD540C714
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfomemcpy_s
      • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
      • API String ID: 1759834784-2761157908
      • Opcode ID: c1568b5568d689d261f1f0b975b9c1104ab10acfc5286cd5346a40821ab4f9bc
      • Instruction ID: c98ef4051e0cebaa55916c1fb1b346bbf6ca82064ea214d735af23f852b0d48b
      • Opcode Fuzzy Hash: c1568b5568d689d261f1f0b975b9c1104ab10acfc5286cd5346a40821ab4f9bc
      • Instruction Fuzzy Hash: 16B2F672A2C282CBE7359E29D4406FEA791FB48788F815135DA0E57F8CEF78E5049B50
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: NamePath$File_invalid_parameter_noinfo_noreturn$LongMoveShort$CompareCreateString
      • String ID: rtmp
      • API String ID: 3587137053-870060881
      • Opcode ID: 4f136222ae8c555ed678084566c827b4cbf2143fff5110646e5a632cefb97133
      • Instruction ID: 6447005f21d60b2931f7bdc36455c0a40684c21bed763aa2d05a7da112c80f8e
      • Opcode Fuzzy Hash: 4f136222ae8c555ed678084566c827b4cbf2143fff5110646e5a632cefb97133
      • Instruction Fuzzy Hash: B1F1D422F2CA82D5EB10EB65D4405FDA761EB893C8F941136EA4D87AADEF3CD584C350
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: FullNamePath_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 1693479884-0
      • Opcode ID: 1e7c5ac9d18d4859634b67c516166c1ae8f0dcc4e332a300e03a2fc1b19988e3
      • Instruction ID: da2b9f379a7d9394ed52cfe6b1d197d7f0b7767bfd483b57d5cb234c2f577b47
      • Opcode Fuzzy Hash: 1e7c5ac9d18d4859634b67c516166c1ae8f0dcc4e332a300e03a2fc1b19988e3
      • Instruction Fuzzy Hash: FFA1B362F28B51C4FF10EB7988449BCA361AB49BA4F945231DE5D17FCCEE7CE4818214
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ExceptionFilterPresentUnhandled$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
      • String ID:
      • API String ID: 3140674995-0
      • Opcode ID: eb4060bcbbf6947450414bc0ac192b8da1feec02df413969c5a674799d26ef14
      • Instruction ID: e12c7bedef22f32b3aaa4442d0dd0d37d0a69d6349cedc172797afdfe1691b5a
      • Opcode Fuzzy Hash: eb4060bcbbf6947450414bc0ac192b8da1feec02df413969c5a674799d26ef14
      • Instruction Fuzzy Hash: 67314D76618B81CAEB64AF60E8507FDB360FB88744F84443ADA4D47B98EF78D548C720
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
      • String ID:
      • API String ID: 1239891234-0
      • Opcode ID: 5940ef1d6d2c32beaf7af9e8e0892e721e3d30544378453b8f42f9f5775f8da8
      • Instruction ID: 1ae4377c50429e92392bd0c07eb7c5bbdda2e42989b217bfe2c32fc27c07fa96
      • Opcode Fuzzy Hash: 5940ef1d6d2c32beaf7af9e8e0892e721e3d30544378453b8f42f9f5775f8da8
      • Instruction Fuzzy Hash: 14317F36628B81C5EB249F25E8406AEB3A0FB88754F900135EA8D43B58EF7CC545CB10
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3668304517-0
      • Opcode ID: 2a322e159852dab68bb665a72e630183d686e9f0b395d04b86c8934c1a7a8b0d
      • Instruction ID: 4e54a8ba9c13c80fd897e3d0c469c9259b9dcfa894a22543ed9de495347cfd46
      • Opcode Fuzzy Hash: 2a322e159852dab68bb665a72e630183d686e9f0b395d04b86c8934c1a7a8b0d
      • Instruction Fuzzy Hash: 1AB1CFA2B2C786C5EA10AB65D8446FDA361FB89794F841236EA4C47BD9FF3CD940C310
      APIs
      • _invalid_parameter_noinfo.LIBCMT ref: 00007FF76DB2FAC4
        • Part of subcall function 00007FF76DB27934: GetCurrentProcess.KERNEL32(00007FF76DB30CCD), ref: 00007FF76DB27961
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: CurrentProcess_invalid_parameter_noinfo
      • String ID: *?$.
      • API String ID: 2518042432-3972193922
      • Opcode ID: f96344909874f118cd7fc652812aee2de17a0b901a5c412331694f6fbd6e8fc4
      • Instruction ID: 168f1daba5b1f8a977fbc18ee969baf1391d071ec87f08fe52c037a9e69fce7f
      • Opcode Fuzzy Hash: f96344909874f118cd7fc652812aee2de17a0b901a5c412331694f6fbd6e8fc4
      • Instruction Fuzzy Hash: 1451C363B29AD5C5EF10EFA298145B9A7A4FB4CBD8B844531DE1D17B89FE3CD0428310
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: memcpy_s
      • String ID:
      • API String ID: 1502251526-0
      • Opcode ID: b531b63a04a12e36dec63d06dc2411054f876835da8b044adf2bb9f605172619
      • Instruction ID: 6f4b258e44143020a8db41995b31bbada6d0de1a272e311220f4200a43a421df
      • Opcode Fuzzy Hash: b531b63a04a12e36dec63d06dc2411054f876835da8b044adf2bb9f605172619
      • Instruction Fuzzy Hash: D6D1D332B2C686C7DB34DF15E58466AB7A1FB88784F858134CB4E57B48EA3CE941DB40
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ErrorFormatFreeLastLocalMessage
      • String ID:
      • API String ID: 1365068426-0
      • Opcode ID: c27e05edbcf0c556cf9f4b9f4aa6354f64d9dc72ff0f252d3a2ededa039666af
      • Instruction ID: 29651a884015a0906b4d12c2103a144478db5ac47bc542945f79c06c1d8d52bc
      • Opcode Fuzzy Hash: c27e05edbcf0c556cf9f4b9f4aa6354f64d9dc72ff0f252d3a2ededa039666af
      • Instruction Fuzzy Hash: 5201F47571C781C2E710AF12F4905BAA365FB897C0F884135DA8D87B49EF3CD9059715
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID:
      • String ID: .
      • API String ID: 0-248832578
      • Opcode ID: 7c9d8364e7b62915daf92aecf888b4814fe01b6aae5fc02ec6e7aa2f3019df5b
      • Instruction ID: 3e6a27e97da1f1bb557b32893f975bea0fe482ae3c387bb882f7ef6b023a9f6b
      • Opcode Fuzzy Hash: 7c9d8364e7b62915daf92aecf888b4814fe01b6aae5fc02ec6e7aa2f3019df5b
      • Instruction Fuzzy Hash: 8E310A23B2C6D585F720AA2798047B9AA91AB9DBE4F848235DE5C47BC9FE3CD5018300
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ExceptionRaise_clrfp
      • String ID:
      • API String ID: 15204871-0
      • Opcode ID: 131550a8e914c8a4384a7255cc8ec53066b4dff0b7ecc1394be8dfb6b4310eca
      • Instruction ID: 181310be264211ca89f98f05ece7a6f04776b6cc427eba01f5b3dba986d9adfa
      • Opcode Fuzzy Hash: 131550a8e914c8a4384a7255cc8ec53066b4dff0b7ecc1394be8dfb6b4310eca
      • Instruction Fuzzy Hash: 1FB17A73618B88CBEB15CF2AC8463687BE0F748B48F568831DA5D83BA8DB79D451C714
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ObjectRelease$CapsDevice
      • String ID:
      • API String ID: 1061551593-0
      • Opcode ID: 68dbe16693602acb82a0a9c061fd0d735b77194d41f4ab9e90264308bb487059
      • Instruction ID: 580f52b2a066cfefa94ba0dd162161c40067bdcfc9e178091f47a25bf7c06b33
      • Opcode Fuzzy Hash: 68dbe16693602acb82a0a9c061fd0d735b77194d41f4ab9e90264308bb487059
      • Instruction Fuzzy Hash: 9781392AB28A05C6EB119F6AD8406ACB371FB88B88F814132DE0D57B28EF38D545C350
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: FormatInfoLocaleNumber
      • String ID:
      • API String ID: 2169056816-0
      • Opcode ID: a0c8fcaef59427837b2a7c7753e3d717a8442860a15e47712294eddcbb527c28
      • Instruction ID: e2c2eda1c74549810dd1edd43ab388c86004cc2018d84522f325020eb2d08258
      • Opcode Fuzzy Hash: a0c8fcaef59427837b2a7c7753e3d717a8442860a15e47712294eddcbb527c28
      • Instruction Fuzzy Hash: 46112762A2CB81D5E661AF21E8006AAB360FF88B44F844135DA4D42A68EF3CA549C658
      APIs
        • Part of subcall function 00007FF76DB024C0: CreateFileW.KERNELBASE ref: 00007FF76DB0259B
        • Part of subcall function 00007FF76DB024C0: GetLastError.KERNEL32 ref: 00007FF76DB025AE
        • Part of subcall function 00007FF76DB024C0: CreateFileW.KERNEL32 ref: 00007FF76DB0260E
        • Part of subcall function 00007FF76DB024C0: GetLastError.KERNEL32 ref: 00007FF76DB02617
      • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF76DB015D0
        • Part of subcall function 00007FF76DB03980: MoveFileW.KERNEL32 ref: 00007FF76DB039BD
        • Part of subcall function 00007FF76DB03980: MoveFileW.KERNEL32 ref: 00007FF76DB03A34
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: File$CreateErrorLastMove$_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 34527147-0
      • Opcode ID: ff8db0b7e6220f8763dd011d447b107dd9c9988147a577c1b56b2c29d4da8d2e
      • Instruction ID: 1ecf9daba967df8abbae2c4d929849e2886385a241619be1e53d69664fc2caa5
      • Opcode Fuzzy Hash: ff8db0b7e6220f8763dd011d447b107dd9c9988147a577c1b56b2c29d4da8d2e
      • Instruction Fuzzy Hash: 6E91C622B3CA41D2EB14EB66D444ABDA361FB58BC8F844036EE0D97B99EE3CD545C710
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Version
      • String ID:
      • API String ID: 1889659487-0
      • Opcode ID: 5e1f820920c456f15e44ae9d5f0cc3b6f822566f542002a6e47536c5256bfc9c
      • Instruction ID: 430d54fc636415be61a4e4fc3563b21a8c09a17b9d0b47840671bc86711b782d
      • Opcode Fuzzy Hash: 5e1f820920c456f15e44ae9d5f0cc3b6f822566f542002a6e47536c5256bfc9c
      • Instruction Fuzzy Hash: 1D018F71D6D5C2C9FA31BB21A4147B6E390AFBE309FC40134D59C062ADFE3CA4888A34
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo
      • String ID: 0
      • API String ID: 3215553584-4108050209
      • Opcode ID: 0fbd957179d89af9e1d3453d65279f22830f04fe064c784c04e338e6c7bf3646
      • Instruction ID: d65bb873fb37c32126ba6f9b534ac76d0dfddd37bade645b41590e26d4d2c267
      • Opcode Fuzzy Hash: 0fbd957179d89af9e1d3453d65279f22830f04fe064c784c04e338e6c7bf3646
      • Instruction Fuzzy Hash: 77811A1BA3C1C2C2EA68BA16904057DA390EF58784FD41635DD0D87A9DFF3DE84AC761
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo
      • String ID: 0
      • API String ID: 3215553584-4108050209
      • Opcode ID: a261a21fa45f21d734edfefcd2ffe271b1157111beaf653bc061adca1a26389c
      • Instruction ID: d39e7151c0890c916b47fdca89ea6a10ab3b903dd67e4a9f25365e0f70f04ea1
      • Opcode Fuzzy Hash: a261a21fa45f21d734edfefcd2ffe271b1157111beaf653bc061adca1a26389c
      • Instruction Fuzzy Hash: ED715A2BA3C2C2C6FB68AA2444442BDE3909F4A744F945535CD0D876DEFE2EE8468771
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID:
      • String ID: gj
      • API String ID: 0-4203073231
      • Opcode ID: 226aa63bfce789330e15763d8953fb7d553c3450d9c1aa6f260de1088bdface5
      • Instruction ID: fd2f45bf35f84642f9c12f5637dd46a7ca8c3f6b03345dbef07e2974f1ba9260
      • Opcode Fuzzy Hash: 226aa63bfce789330e15763d8953fb7d553c3450d9c1aa6f260de1088bdface5
      • Instruction Fuzzy Hash: 865190377286908BD724CF25E404A9EB3A5F388758F455126EF8A93B09DB3DE945CF40
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID:
      • String ID: @
      • API String ID: 0-2766056989
      • Opcode ID: 49e7fa989fc271adaa8e130b28d1cae0d9f82f392019a5f874cdac11a507a941
      • Instruction ID: 1b56474348d66c7ce4cae04f083b2fb81fdfea3008e04c4c12dfc498a1fb9d86
      • Opcode Fuzzy Hash: 49e7fa989fc271adaa8e130b28d1cae0d9f82f392019a5f874cdac11a507a941
      • Instruction Fuzzy Hash: 4B41B023728A44C6EA04DF2AE4182A9B3A1A75CFD0B899036DF4D87758FE3CD446C300
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: HeapProcess
      • String ID:
      • API String ID: 54951025-0
      • Opcode ID: 4ce929ddb23f73c0a8458b43b9ad49d4d7e2a2f746430c3d48bba7e89996d797
      • Instruction ID: 9abba5af6afe0934e64d2cccb2755ff42019c651fad957f8b8f4e1c33eb5cb79
      • Opcode Fuzzy Hash: 4ce929ddb23f73c0a8458b43b9ad49d4d7e2a2f746430c3d48bba7e89996d797
      • Instruction Fuzzy Hash: F8B09224E2BA02C2EA093F11AC8229462A4BF4C700FD58039D14C82324EE6C24A55B21
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 1df1e6e81a57214c8643d36be1bb9cde3812740f73d4ab830297bee2ffae98a2
      • Instruction ID: aaf35787b3ad64d81b2c303eab78a269ee08332d605bf92331a8f4c9743c5aa5
      • Opcode Fuzzy Hash: 1df1e6e81a57214c8643d36be1bb9cde3812740f73d4ab830297bee2ffae98a2
      • Instruction Fuzzy Hash: 2B820663A2D6C1C6D716EF24D8446BCBB62E759B88F59813ACA4E07389FE3CD445C320
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: fb6bb4a62616f0bcd3e2e2126cd32946fe2ad160a7c0dbd4e5bd03ed1428d6a6
      • Instruction ID: f8736a2c7283acb3edd8fdf9fee09917ab904bfef06e21d97105c364e38abcaf
      • Opcode Fuzzy Hash: fb6bb4a62616f0bcd3e2e2126cd32946fe2ad160a7c0dbd4e5bd03ed1428d6a6
      • Instruction Fuzzy Hash: 85627D9AD3AF9A1EE303A53954131D2E35C0EF74C9551E31BFCE431E66EB92A6832314
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 83a45c88a368d7276059de07aefbbc35b61cea5d64746511b72f3674958eea04
      • Instruction ID: 8eed238c346d73ec7b0d99a7b9dc465f55082d0955b60534d91554afa58005f0
      • Opcode Fuzzy Hash: 83a45c88a368d7276059de07aefbbc35b61cea5d64746511b72f3674958eea04
      • Instruction Fuzzy Hash: 8E8200B3A1D6C18AD716DE28C8446FCBBB2F759B48F588136CA4D07789EA38D485C724
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: ffdf8f5a64276e3eb417e3b9ae5b43350349d41efb04db03fca9f8ba9e24336f
      • Instruction ID: 1089aaf30c582fae8fb8b0c52f20c0b1a43ab962814d4e49e4a0bedc2947852b
      • Opcode Fuzzy Hash: ffdf8f5a64276e3eb417e3b9ae5b43350349d41efb04db03fca9f8ba9e24336f
      • Instruction Fuzzy Hash: 7F22E573B246508BD728CF15C89AE5E3766F799744B4B8228DF0ACB789EB38D505CB40
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 21143e83615dcc23e36b64f0d60848ac948cba63854c17a605a1a3ec217f9251
      • Instruction ID: f2c44547e598d092118a0b23b9b305f7396824af69cabc5e3b5c1cc31d4a6cb3
      • Opcode Fuzzy Hash: 21143e83615dcc23e36b64f0d60848ac948cba63854c17a605a1a3ec217f9251
      • Instruction Fuzzy Hash: 6B32D173A28191CBE719DF24D950ABC77A2F758708F458139DA4E87B88EB3CE860C750
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 063370d9e2e9571dc593e8358d008e0ec5385ad0435e9f2f5019d46da215c13b
      • Instruction ID: 8bd9f93afa4754560292713b3175c16498d2e39b1ae5c9e391947456d079ca0e
      • Opcode Fuzzy Hash: 063370d9e2e9571dc593e8358d008e0ec5385ad0435e9f2f5019d46da215c13b
      • Instruction Fuzzy Hash: B8C1ACB7B281908FE350CF7AE400A9D7BB1F39878CB515125DF59A3B09D639E605CB40
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 602477e063b5c1ca901f2159ae3c7fc010244aaa433e93e1960e83d539d05e76
      • Instruction ID: 9fe42d7b4de0b18421ad8af676dd062c30f7c215f21efd9181d15a5198f814b5
      • Opcode Fuzzy Hash: 602477e063b5c1ca901f2159ae3c7fc010244aaa433e93e1960e83d539d05e76
      • Instruction Fuzzy Hash: B4A13773E1C186C6EB26EA24D8057BDA792EBA9784FC54135DA4D47789FE3CD841C320
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: e3f156a61251d3696a660eff3e2c5499dd818c979554cbf7ea7c30eccab92618
      • Instruction ID: f27b24dc413a70ac8b99a3a2608ae1886644396c0480f6edb12f2ea5810e496b
      • Opcode Fuzzy Hash: e3f156a61251d3696a660eff3e2c5499dd818c979554cbf7ea7c30eccab92618
      • Instruction Fuzzy Hash: 39C10673A292E08DE302CBB5A4248FD3FB5E71D34DB4A4152EFA656B4ED6285201DF70
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: AddressProc
      • String ID:
      • API String ID: 190572456-0
      • Opcode ID: ba0d91b71a6ba36ace61fab0c0f7d4922daa1e3f8d028e3e8b3457ff5b2a4fa0
      • Instruction ID: 180ff80e60117ebda100846b6d9bceb8e72ed5f300f9c7f23b59cfa2996f4482
      • Opcode Fuzzy Hash: ba0d91b71a6ba36ace61fab0c0f7d4922daa1e3f8d028e3e8b3457ff5b2a4fa0
      • Instruction Fuzzy Hash: 5491F063B2C58196EB11EF29D451AFDA721FB99788F841132EF4E07749EE38DA46C310
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: cfd80b8924012b3a81ce264cde7180753b201b1e387c519ebd9873ce58afa85e
      • Instruction ID: 43c06133e714b8ed7c7a24f35225044020b64828d49a5bc97b7bcc7e97e34f13
      • Opcode Fuzzy Hash: cfd80b8924012b3a81ce264cde7180753b201b1e387c519ebd9873ce58afa85e
      • Instruction Fuzzy Hash: BB611223B2C1D189EB11DF7585148FDBFA1A71D784B868032CF9E5764AEA3CE506CB24
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 8137a9b05b05aada6fbcd6bbdda66db02b1ef4637fe403d2df7c72722ebbdea5
      • Instruction ID: a0ab4497e092ae486ecf4ea93c88378f6e0198e74405fe3b87bb352359dc9eac
      • Opcode Fuzzy Hash: 8137a9b05b05aada6fbcd6bbdda66db02b1ef4637fe403d2df7c72722ebbdea5
      • Instruction Fuzzy Hash: 85511273A2C1918BE32A9F28A405B7DB752F798B44F844134DB4D4B68CEE3DE541CB50
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 525267a7f117e2089c634eae81b531c40420bccc1aa688f1dd99d62513960580
      • Instruction ID: 843ee3e7b715db562d4071eebb595631f2b0f611b338ac631d12e6213c93d16a
      • Opcode Fuzzy Hash: 525267a7f117e2089c634eae81b531c40420bccc1aa688f1dd99d62513960580
      • Instruction Fuzzy Hash: 423126B2A2C5818BD719EF16D96167EBBD1F759380F409038DB4A83B85EA3CE045C710
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: 6a4fac86f8f1a6b9d8c17b4c2881c5c96027003405599c7815143c772f625e0d
      • Instruction ID: 55642a10f092749edee653da8131a71e52bd7c1d522488125786302d34f964b8
      • Opcode Fuzzy Hash: 6a4fac86f8f1a6b9d8c17b4c2881c5c96027003405599c7815143c772f625e0d
      • Instruction Fuzzy Hash: 23F0FE61F3C003C2FB7820287819B39A0569B99310FD44935E11FC6ACDFDADE8811129
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID:
      • String ID:
      • API String ID:
      • Opcode ID: e57e15d0ab639cfe726454a8769b7378f2b682ff734fe90589bfb13db1bf513a
      • Instruction ID: 01562c2d36a9f3c34739ed7c47318393a6ac68f4a3c9ff2632059517001e9aa5
      • Opcode Fuzzy Hash: e57e15d0ab639cfe726454a8769b7378f2b682ff734fe90589bfb13db1bf513a
      • Instruction Fuzzy Hash: 4DA0026692CC82D0E749AB10E8608B0A330FB58300BD10035F00D817BCFF7CA601D321
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: :$EFS:$LOGGED_UTILITY_STREAM$:$I30:$INDEX_ALLOCATION$:$TXF_DATA:$LOGGED_UTILITY_STREAM$::$ATTRIBUTE_LIST$::$BITMAP$::$DATA$::$EA$::$EA_INFORMATION$::$FILE_NAME$::$INDEX_ALLOCATION$::$INDEX_ROOT$::$LOGGED_UTILITY_STREAM$::$OBJECT_ID$::$REPARSE_POINT
      • API String ID: 3668304517-727060406
      • Opcode ID: fc44dbfd106e66ad26630d810067bee7702886ae7b68d41755c36eb4d41d7e9a
      • Instruction ID: 39ebf160a0776197e6d39eead2459df3de7a8e2ad1cf134f4959730c4d3e4936
      • Opcode Fuzzy Hash: fc44dbfd106e66ad26630d810067bee7702886ae7b68d41755c36eb4d41d7e9a
      • Instruction Fuzzy Hash: 4D411836B29F01D8EB01AB64E4803E873B5FB48798F850236DA4C43B68FE78D555C390
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Handle$AddressCriticalModuleProcSection$CloseCountCreateDeleteEventInitializeSpin
      • String ID: SleepConditionVariableCS$WakeAllConditionVariable$api-ms-win-core-synch-l1-2-0.dll$kernel32.dll
      • API String ID: 2565136772-3242537097
      • Opcode ID: 6e1e709f092c3aabc6fb1c9db3d7c09c3ef1a4a7bf2af41e7ac9402dec2f511f
      • Instruction ID: 9022f654de8ff5f1c29558e7e55d5a2f5da9de89a85263932b9925ce351b7aec
      • Opcode Fuzzy Hash: 6e1e709f092c3aabc6fb1c9db3d7c09c3ef1a4a7bf2af41e7ac9402dec2f511f
      • Instruction Fuzzy Hash: 35212A69E3DA43D1FE69BB51E855574A3A0AF4D780FC50034C90E86BACFE7CE4459321
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$Xinvalid_argumentstd::_
      • String ID: DXGIDebug.dll$UNC$\\?\
      • API String ID: 4097890229-4048004291
      • Opcode ID: 679bcbf7d584aa38b2e22764c1af6e01fe464e1a33c10589402711c3c672582b
      • Instruction ID: 8f5737c9028de07fcb0925349bb73d7de1c87be32aa7fd571fb4d4ed5eb84e0b
      • Opcode Fuzzy Hash: 679bcbf7d584aa38b2e22764c1af6e01fe464e1a33c10589402711c3c672582b
      • Instruction Fuzzy Hash: 1A12CE62A2CB42C1EB10EB65D4405BDA371EB49B88F904236DB5D07AA9EE7CD589C350
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_taskDialog
      • String ID: GETPASSWORD1$Software\WinRAR SFX
      • API String ID: 431506467-1315819833
      • Opcode ID: d20c2f114c9109beee27ce5cf2a2d2fb90c2edf5e9b936924732424cb653f975
      • Instruction ID: 0399642f27522586fe5399cac1c580fdc9b150712a06e32f884841e1cf079668
      • Opcode Fuzzy Hash: d20c2f114c9109beee27ce5cf2a2d2fb90c2edf5e9b936924732424cb653f975
      • Instruction Fuzzy Hash: C8B1B762F2D782C5FB00EB64D8446BC6372AB49394F904235DA5C26ADDFE7CE54AC314
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$Global$AllocCreateStream
      • String ID: </html>$<html>$<html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"></head>$<style>body{font-family:"Arial";font-size:12;}</style>
      • API String ID: 2868844859-1533471033
      • Opcode ID: 7d5a2165bcb14269ce88758dc811b505d41036279ac82267a240c61270d62392
      • Instruction ID: 8ea027417120e638f77ec02b84b56915978fd17caa76816ab811766507f16e8c
      • Opcode Fuzzy Hash: 7d5a2165bcb14269ce88758dc811b505d41036279ac82267a240c61270d62392
      • Instruction Fuzzy Hash: F1818F62F2CA42D5FB01EBA5D8402FDA372AB49784F800135DE1D57A9DFE78E50AC364
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo
      • String ID: INF$NAN$NAN(IND)$NAN(SNAN)$inf$nan$nan(ind)$nan(snan)
      • API String ID: 3215553584-2617248754
      • Opcode ID: ca8329083cbd7a022b2adefca7a3bb58d0ae1dff90efa4c28dbe4d3f14657870
      • Instruction ID: 0902e3f6300090554bf5921eba8d5000189465d86a11622f7c1876c1d765c63b
      • Opcode Fuzzy Hash: ca8329083cbd7a022b2adefca7a3bb58d0ae1dff90efa4c28dbe4d3f14657870
      • Instruction Fuzzy Hash: F241CF32A19B85C9E701DF65E8417ED73A4EB18394F824636EE4C47B58EE3CD025C354
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Window$MessageObjectSend$ClassDeleteLongName
      • String ID: STATIC
      • API String ID: 2845197485-1882779555
      • Opcode ID: 028936735c5caa7e1c5955390d3996a5d13f8d6e72d7f98742e6e6c768b0ab82
      • Instruction ID: 8f8e736da902cad3290539c3565d933cd6013383cec49327a5f0350bfe58844b
      • Opcode Fuzzy Hash: 028936735c5caa7e1c5955390d3996a5d13f8d6e72d7f98742e6e6c768b0ab82
      • Instruction Fuzzy Hash: 01315226B2C652C6FA61BB12A9547B9A392BB8DBD0F840430DD4D47B5DEE3CD806C760
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ItemTextWindow
      • String ID: LICENSEDLG
      • API String ID: 2478532303-2177901306
      • Opcode ID: 35fefc179f922e98870b8a3b257cf5e504c5ed53f195972dc606f5139ed8380b
      • Instruction ID: 493bb756683c0f502fa6c34353b3ae233f261bbb9c96957f2e81e0adefd7b5ee
      • Opcode Fuzzy Hash: 35fefc179f922e98870b8a3b257cf5e504c5ed53f195972dc606f5139ed8380b
      • Instruction Fuzzy Hash: DA418121E2C652C2FB55AF16A814B7DA361AF8CB84FD44035D90D43B9CEF7CE94A8724
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: AddressProc$CurrentDirectoryProcessSystem
      • String ID: Crypt32.dll$CryptProtectMemory$CryptProtectMemory failed$CryptUnprotectMemory$CryptUnprotectMemory failed
      • API String ID: 2915667086-2207617598
      • Opcode ID: d2e93635ec338890dfe438c4789fcaf7e26687fbfe6c7ce53d5981307f2d6baa
      • Instruction ID: 845770ef7aca00ec23b7416c6b00cb661f3b9add0ff75b42dc77b1d9fd3fa0eb
      • Opcode Fuzzy Hash: d2e93635ec338890dfe438c4789fcaf7e26687fbfe6c7ce53d5981307f2d6baa
      • Instruction Fuzzy Hash: B2314C24F2DB06C1FE14AB16E960975A7A0AF4CB90FC54135C85E437ACFEBCE9419324
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: $
      • API String ID: 3668304517-227171996
      • Opcode ID: ab3e1cf375e14aa7788add7031566744a4a2a58747ae13a7e3943128d7c57d22
      • Instruction ID: ba46468eeeff14be08dccea9291b6eee9e6f7be67b8eff983f7c0dfe5b2055f8
      • Opcode Fuzzy Hash: ab3e1cf375e14aa7788add7031566744a4a2a58747ae13a7e3943128d7c57d22
      • Instruction Fuzzy Hash: A3F1CF66F2CB46E0EE11AB65D8441BDA362BB48B98F905235CA1D177DDFF7CE1808360
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Is_bad_exception_allowedabortstd::bad_alloc::bad_alloc
      • String ID: csm$csm$csm
      • API String ID: 2940173790-393685449
      • Opcode ID: 65edb01f61f21fff02eaccc9a46b43a233fa456fccf40e480b66f774ee54b1a7
      • Instruction ID: d2e8d7e5095ce76d487ced04bcd44d6ca4b82b3fae2d19a15c60edd7e39ba4d2
      • Opcode Fuzzy Hash: 65edb01f61f21fff02eaccc9a46b43a233fa456fccf40e480b66f774ee54b1a7
      • Instruction Fuzzy Hash: 69E18C7392C6C2CAE710AB24D4803BDB7A0FB49758F944135DA8D5769EFE38E485C714
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: AllocClearStringVariant
      • String ID: Name$ROOT\CIMV2$SELECT * FROM Win32_OperatingSystem$WQL$Windows 10
      • API String ID: 1959693985-3505469590
      • Opcode ID: a8b35b7bcd37d82ee4aaa20c3b876beaab518b1de9e1ce59ea14af8b32f1fe8d
      • Instruction ID: 44c6f05aa9d61386a0c48742e2860045017bd04761e2f47b4a29cf176bd61911
      • Opcode Fuzzy Hash: a8b35b7bcd37d82ee4aaa20c3b876beaab518b1de9e1ce59ea14af8b32f1fe8d
      • Instruction Fuzzy Hash: 0A713A36A28B05C5EB10EF25D8905ADB7B4FB88B98F815136DA4D43B68EF7CD544C350
      APIs
      • LoadLibraryExW.KERNEL32(?,?,00000000,00007FF76DB274F3,?,?,?,00007FF76DB2525E,?,?,?,00007FF76DB25219), ref: 00007FF76DB27371
      • GetLastError.KERNEL32(?,?,00000000,00007FF76DB274F3,?,?,?,00007FF76DB2525E,?,?,?,00007FF76DB25219), ref: 00007FF76DB2737F
      • LoadLibraryExW.KERNEL32(?,?,00000000,00007FF76DB274F3,?,?,?,00007FF76DB2525E,?,?,?,00007FF76DB25219), ref: 00007FF76DB273A9
      • FreeLibrary.KERNEL32(?,?,00000000,00007FF76DB274F3,?,?,?,00007FF76DB2525E,?,?,?,00007FF76DB25219), ref: 00007FF76DB273EF
      • GetProcAddress.KERNEL32(?,?,00000000,00007FF76DB274F3,?,?,?,00007FF76DB2525E,?,?,?,00007FF76DB25219), ref: 00007FF76DB273FB
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Library$Load$AddressErrorFreeLastProc
      • String ID: api-ms-
      • API String ID: 2559590344-2084034818
      • Opcode ID: eedfc97f7024c66fbeb39a7219499b253e22696fd1fdab2c5f769bf1fd383016
      • Instruction ID: 5c48cde4d4d8927faecae13f318fd97069b09aad76c3b778b94599211f38c620
      • Opcode Fuzzy Hash: eedfc97f7024c66fbeb39a7219499b253e22696fd1fdab2c5f769bf1fd383016
      • Instruction Fuzzy Hash: 9B31C422E3E682C1EE11BB06A800A75A294FF0CBA0F994535DD5D4B788FFBCE4418734
      APIs
      • GetModuleHandleW.KERNEL32(?,?,?,00007FF76DB21573,?,?,?,00007FF76DB2192A), ref: 00007FF76DB2162B
      • GetProcAddress.KERNEL32(?,?,?,00007FF76DB21573,?,?,?,00007FF76DB2192A), ref: 00007FF76DB21648
      • GetProcAddress.KERNEL32(?,?,?,00007FF76DB21573,?,?,?,00007FF76DB2192A), ref: 00007FF76DB21664
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: AddressProc$HandleModule
      • String ID: AcquireSRWLockExclusive$KERNEL32.DLL$ReleaseSRWLockExclusive
      • API String ID: 667068680-1718035505
      • Opcode ID: 4fe35f58cd4175722fa2f4edd42b7d77b08fa8d78ae8e9bf73ccac7c2071e7f8
      • Instruction ID: bc6aa59c33c84ff108eba856be1e1059e248c4fe073488e6dce1d7fe5f753e1e
      • Opcode Fuzzy Hash: 4fe35f58cd4175722fa2f4edd42b7d77b08fa8d78ae8e9bf73ccac7c2071e7f8
      • Instruction Fuzzy Hash: A9112A26A3DB82C1EE56AF00E94027DA2916F0C7D0FCD4435C81E0A75CFE7DA8449630
      APIs
        • Part of subcall function 00007FF76DB051A4: GetVersionExW.KERNEL32 ref: 00007FF76DB051D5
      • FileTimeToLocalFileTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FF76DAF5AB4), ref: 00007FF76DB0ED8C
      • FileTimeToSystemTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FF76DAF5AB4), ref: 00007FF76DB0ED98
      • SystemTimeToTzSpecificLocalTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FF76DAF5AB4), ref: 00007FF76DB0EDA8
      • SystemTimeToFileTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FF76DAF5AB4), ref: 00007FF76DB0EDB6
      • SystemTimeToFileTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FF76DAF5AB4), ref: 00007FF76DB0EDC4
      • FileTimeToSystemTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FF76DAF5AB4), ref: 00007FF76DB0EE05
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Time$File$System$Local$SpecificVersion
      • String ID:
      • API String ID: 2092733347-0
      • Opcode ID: 197518eb8103cda2bd6b54f1f5e99fa721289ee203340eaf45d2c62117a67569
      • Instruction ID: 9fedfcb0c15f4905c6e302d9669f29b65db3d51eef6a3ea0dac35cb965dd7fcf
      • Opcode Fuzzy Hash: 197518eb8103cda2bd6b54f1f5e99fa721289ee203340eaf45d2c62117a67569
      • Instruction Fuzzy Hash: 12518DB2B24651CAEB14DF65D8404AC77B1F74C788BA0403ADE0D97B58EF38D546C710
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Time$File$System$Local$SpecificVersion
      • String ID:
      • API String ID: 2092733347-0
      • Opcode ID: 93bf5fe4be91675a5f4cba4a2df0f2c5ed0bd126a165fd4d88c3e7d5e64543a6
      • Instruction ID: 74b644b7722a9143fd917112034b01affce026c1e6133130094120a74cf0e322
      • Opcode Fuzzy Hash: 93bf5fe4be91675a5f4cba4a2df0f2c5ed0bd126a165fd4d88c3e7d5e64543a6
      • Instruction Fuzzy Hash: 51314766B24A51CEEB00DFB5E8801AC7370FB0C758B94503AEE0E97A58EF78D895C315
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: .rar$exe$rar$sfx
      • API String ID: 3668304517-630704357
      • Opcode ID: 2782df0ac0d906a6dfd4afc5fd13043494203347564149d90fad9f6fe0172506
      • Instruction ID: 744799f54324f5d6eec2662e3dfd11953a6d87c1af1e0813e2520b4ac365148a
      • Opcode Fuzzy Hash: 2782df0ac0d906a6dfd4afc5fd13043494203347564149d90fad9f6fe0172506
      • Instruction Fuzzy Hash: D0A1C262E2CA46D0EB10AB25D4546BCA361BF48B98FD41235CD1D076EDEFBCE585C360
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: abort$CallEncodePointerTranslator
      • String ID: MOC$RCC
      • API String ID: 2889003569-2084237596
      • Opcode ID: 0f4c2d06ef2d655583c55900dbb020dcf620b12558a4295111afe460be181df6
      • Instruction ID: 9c98fb941550a0fb49bdbbb78f46bfe51d8186a3d3569174d45c8ea288d63860
      • Opcode Fuzzy Hash: 0f4c2d06ef2d655583c55900dbb020dcf620b12558a4295111afe460be181df6
      • Instruction Fuzzy Hash: 05917E73A18B81CAE710EB65D4802BDB7A0F758788F94413AEA8D17B5DEF38D195CB10
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: CurrentImageNonwritableUnwind__except_validate_context_record
      • String ID: csm$f
      • API String ID: 2395640692-629598281
      • Opcode ID: a7c39da158025e753bf36dfb1e051fd0b17def11f5f8def40396cbfe1c046983
      • Instruction ID: d852ea3846284bb204075943aa0d80ad307d1540f4a08a6e33cb304f113f3dbb
      • Opcode Fuzzy Hash: a7c39da158025e753bf36dfb1e051fd0b17def11f5f8def40396cbfe1c046983
      • Instruction Fuzzy Hash: 6651A033A2D682C6EB14EB15E844A39B795FB48B98F918034DA1E4774CFF78E8418758
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ErrorLast_invalid_parameter_noinfo_noreturn$CloseCurrentHandleProcess
      • String ID: SeRestorePrivilege$SeSecurityPrivilege
      • API String ID: 2102711378-639343689
      • Opcode ID: 8e19f0960acccde70cdb6f4ae44bfdba7dde49cd3aecb391576d39059d5aab7f
      • Instruction ID: 6b3d9e71028b7e8d2c8f06d1aa497227e42ff04d0832adf79ce8582a07a4a2ed
      • Opcode Fuzzy Hash: 8e19f0960acccde70cdb6f4ae44bfdba7dde49cd3aecb391576d39059d5aab7f
      • Instruction Fuzzy Hash: 2251D362E2C742C5FB11FB65D8415BDA370AF897A4F880176DE1D1769AFE3CA885C220
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Window$Show$Rect
      • String ID: RarHtmlClassName
      • API String ID: 2396740005-1658105358
      • Opcode ID: 7f8a0b662af83a4f47b362c37f36e9414f73daccdb18f375bc1ce0a7ee57f15d
      • Instruction ID: c93b1d2a92d34dbbbce056639530f20cdb2b7c68367ab36db69d560e31bf9888
      • Opcode Fuzzy Hash: 7f8a0b662af83a4f47b362c37f36e9414f73daccdb18f375bc1ce0a7ee57f15d
      • Instruction Fuzzy Hash: 3F519322A2C781C6EA25AF21E85477AE361FB8C780F844435DE4E47B5CEF7CE4458710
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: EnvironmentVariable$_invalid_parameter_noinfo_noreturn
      • String ID: sfxcmd$sfxpar
      • API String ID: 3540648995-3493335439
      • Opcode ID: ce72e9bcdfddcf2667ebe4c513ec0d1727c59f1d3b739ca42450d660fec21911
      • Instruction ID: 26dd70beaaa12d7d4d3f926923044fe99aff85c31ccd1e14d6a82a92d9c2e287
      • Opcode Fuzzy Hash: ce72e9bcdfddcf2667ebe4c513ec0d1727c59f1d3b739ca42450d660fec21911
      • Instruction Fuzzy Hash: 49318132A28A05C4EF00EB6AE8841BCA372FB4CB98F941131DE5D57BADEE78D141C354
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID:
      • String ID: RENAMEDLG$REPLACEFILEDLG
      • API String ID: 0-56093855
      • Opcode ID: 98f895654b64cd1d2f90e97d30244ed9b67d31cc2014a88c355cd353264df31a
      • Instruction ID: ba715d6b7a3b305b2c6be6ef852f5898c51ff2d0cce0ce08ae3350e6ad5f0dcd
      • Opcode Fuzzy Hash: 98f895654b64cd1d2f90e97d30244ed9b67d31cc2014a88c355cd353264df31a
      • Instruction Fuzzy Hash: F1210C66E2DA47C0FA12AF15F844574E361AB4D788FD44036D94D4326CEEBCE485C760
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: AddressFreeHandleLibraryModuleProc
      • String ID: CorExitProcess$mscoree.dll
      • API String ID: 4061214504-1276376045
      • Opcode ID: 42a4ca90c7c49dddb16080121233970ff8583544d2054868cb5f0899d871e2db
      • Instruction ID: 68de0e6ef72640d1c8741726e87499543d6a155e944b465252e2b972fed8f579
      • Opcode Fuzzy Hash: 42a4ca90c7c49dddb16080121233970ff8583544d2054868cb5f0899d871e2db
      • Instruction Fuzzy Hash: A0F06866A3DA42C1EF44AB51F850379A360EF8C790F851039D94F46A58FE7CD484D710
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo
      • String ID:
      • API String ID: 3215553584-0
      • Opcode ID: cf462e6f26ae3af6f96c078c51b53c82231ed120809331cf2f591469c69a5a17
      • Instruction ID: 3d0936d96f1bebbaf82035ebb08a7ec42ef6756c4bfd41110f202b901b4c5f85
      • Opcode Fuzzy Hash: cf462e6f26ae3af6f96c078c51b53c82231ed120809331cf2f591469c69a5a17
      • Instruction Fuzzy Hash: 6C81CF22E3C642C5F710AF65D8406BDA6A1BB4DB88F824135CD0E53B9DEFBDA445E320
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: File$Create$CloseHandleTime_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 2398171386-0
      • Opcode ID: ed02a809717236ee1ed586c7e858dbefa1ed7ae72bbe3c8719455611c93ecd51
      • Instruction ID: c4481d07cf52dcb06c56f05fe188a9bc9403b7fd66a9298cad1fa6747218451a
      • Opcode Fuzzy Hash: ed02a809717236ee1ed586c7e858dbefa1ed7ae72bbe3c8719455611c93ecd51
      • Instruction Fuzzy Hash: 5651A122B2CB4299FB60EB65E444BBDA371AB4C7A8F804635DE1D867DCFE38D4458310
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: FileWrite$ByteCharConsoleErrorLastMultiWide
      • String ID:
      • API String ID: 3659116390-0
      • Opcode ID: 8f90b3f8899b92826fb288bc35eb601c263b89b4fb676f823db5d062d6f6b41f
      • Instruction ID: dc56928fa98b81ead44e51e7c0b7732d8c5060b93973e2855728f40716d6f544
      • Opcode Fuzzy Hash: 8f90b3f8899b92826fb288bc35eb601c263b89b4fb676f823db5d062d6f6b41f
      • Instruction Fuzzy Hash: BC51CE32A28A51C9E710DB25E8443ACBBB0FB4C798F858135DE4E57B98EF79D145C720
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ByteCharMultiWide$AllocString
      • String ID:
      • API String ID: 262959230-0
      • Opcode ID: 7e9601d2247a13adf5892490d0984888a090eff7ba9d3fa4ff308a8b8e371313
      • Instruction ID: efc28cf00b45acfb681b39c5950e6cc4565524cd2aded52ee7fd405085717a1e
      • Opcode Fuzzy Hash: 7e9601d2247a13adf5892490d0984888a090eff7ba9d3fa4ff308a8b8e371313
      • Instruction Fuzzy Hash: 81419622A2D685C5EB14BF219850279A291EF0CBE4FD84634EA6D87BDDFF7DD1418320
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: AddressProc
      • String ID:
      • API String ID: 190572456-0
      • Opcode ID: d8da239e760e4119be076ce5ae60c5d71a4e7276355522d8061e2664917ecd9d
      • Instruction ID: dbd88efc9f2a3a2966ce4c304be37cd79275778aa9fe24228bce948d6aec4f7d
      • Opcode Fuzzy Hash: d8da239e760e4119be076ce5ae60c5d71a4e7276355522d8061e2664917ecd9d
      • Instruction Fuzzy Hash: 06410622B2DA82C1FA15AF13A814675A395BF4CBD0F894535DE5E4BB4CFE7CE4408320
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _set_statfp
      • String ID:
      • API String ID: 1156100317-0
      • Opcode ID: f3bd3298a46f29c998dca386ec4adc9bd6d7efdfabb851da102e47160911a3a1
      • Instruction ID: 68fef63d04940238e428c7cd50e33fd9faf632965d676650c13a2c1c51a4f27a
      • Opcode Fuzzy Hash: f3bd3298a46f29c998dca386ec4adc9bd6d7efdfabb851da102e47160911a3a1
      • Instruction Fuzzy Hash: 52119D76E3CA17D1F6543124E54237991C16F4C3A0ECA4230EA7E0AEDEBEACA440622D
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Message$DispatchObjectPeekSingleTranslateWait
      • String ID:
      • API String ID: 3621893840-0
      • Opcode ID: eb57a341668d454e4e6cd52f39bb1811463ddcab187ea95c48cb89abc8d18535
      • Instruction ID: 4847d567e479d37ab14284986ddbde28961284dc71fa549d1703d21bd6341736
      • Opcode Fuzzy Hash: eb57a341668d454e4e6cd52f39bb1811463ddcab187ea95c48cb89abc8d18535
      • Instruction Fuzzy Hash: B4F01222B3C546C2FB50AB30E855B7AA251FFECB05FC41030E54E81998EE2CD549C720
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: __except_validate_context_recordabort
      • String ID: csm$csm
      • API String ID: 746414643-3733052814
      • Opcode ID: 91fc108a1c492767e4bb41002f60c2920875b1ec76e01922ab372504797a4c8e
      • Instruction ID: b87734ab9b811d980aba195483d4ae423ea19daf315125a28c064ec2566e5c58
      • Opcode Fuzzy Hash: 91fc108a1c492767e4bb41002f60c2920875b1ec76e01922ab372504797a4c8e
      • Instruction Fuzzy Hash: CA71AF7361C6C1C6D760AB25945077DBBA0EB09F88F948236DA9C07A8DFB2CD591C790
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo
      • String ID: $*
      • API String ID: 3215553584-3982473090
      • Opcode ID: 42643a1ee39b50d27a50b926b179a62c0cdc4d381fe14b17104e750277292b9f
      • Instruction ID: d6f1b19e900bd44dee3a03e2efbc460d89cd1ec360f698f3b1fa77a3f6d548b9
      • Opcode Fuzzy Hash: 42643a1ee39b50d27a50b926b179a62c0cdc4d381fe14b17104e750277292b9f
      • Instruction Fuzzy Hash: D7517F7B92CA82CAE765AE28845537CBBB1FB0DB09F941135C64E412DDFF2CE481C625
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ByteCharMultiWide$StringType
      • String ID: $%s
      • API String ID: 3586891840-3791308623
      • Opcode ID: 8174e861c2faa6f2f7f5292a0ee7474812abc1109b8acb2517e9a7bc716d8d39
      • Instruction ID: 7271627e2a9f21ddb93d6cda04f524da17fd2969afed063816742b780cf9e1e7
      • Opcode Fuzzy Hash: 8174e861c2faa6f2f7f5292a0ee7474812abc1109b8acb2517e9a7bc716d8d39
      • Instruction Fuzzy Hash: C0419822B29781C6EB109F25D8003A9A295FB58BE8F894635DE1D47BC8FF7CE4458314
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: CreateFrameInfo__except_validate_context_recordabort
      • String ID: csm
      • API String ID: 2466640111-1018135373
      • Opcode ID: ef48871438151390fa300b301edbe87f2aaf35895cd4fd9de5e2d21b12dcaab2
      • Instruction ID: 9da3858651a2984dd017500a512d2767f22aa18ff72da6bfc1b793c28e63c613
      • Opcode Fuzzy Hash: ef48871438151390fa300b301edbe87f2aaf35895cd4fd9de5e2d21b12dcaab2
      • Instruction Fuzzy Hash: 9D514B73A2C781C7D620AB15A04027EB7B4FB8DB90F940135EA8D47B9AEF38E450CB50
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ByteCharErrorFileLastMultiWideWrite
      • String ID: U
      • API String ID: 2456169464-4171548499
      • Opcode ID: a3c4996b5397ae7c68c43f4944c85cd830f0b958292ccb38960a62bfe152ddee
      • Instruction ID: 070d6d3d906aad1b751e952c246111b196fe8321bffe4f3da6093d5b0a267f5a
      • Opcode Fuzzy Hash: a3c4996b5397ae7c68c43f4944c85cd830f0b958292ccb38960a62bfe152ddee
      • Instruction Fuzzy Hash: 8741B32262DA85C2D7209F25E8447BAB760FB8CB94F854131EE4D87B48EF7DD445C710
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ObjectRelease
      • String ID:
      • API String ID: 1429681911-3916222277
      • Opcode ID: 0b5772d91688d342ea342be5c9c3c9ea07a5ad9e93d570546deb1a9808731c40
      • Instruction ID: d7d4f64dd51dd2c0a49f3393b027cfbc3cd114d0dcfd65f6111e125aace7d6c1
      • Opcode Fuzzy Hash: 0b5772d91688d342ea342be5c9c3c9ea07a5ad9e93d570546deb1a9808731c40
      • Instruction Fuzzy Hash: E9313C3561874186EA04AF12B81962AB760F78DFD1F844539ED4E83B58DE3CE849CB10
      APIs
      • InitializeCriticalSection.KERNEL32(?,?,?,00007FF76DB1317F,?,?,00001000,00007FF76DAFE51D), ref: 00007FF76DB0E8BB
      • CreateSemaphoreW.KERNEL32(?,?,?,00007FF76DB1317F,?,?,00001000,00007FF76DAFE51D), ref: 00007FF76DB0E8CB
      • CreateEventW.KERNEL32(?,?,?,00007FF76DB1317F,?,?,00001000,00007FF76DAFE51D), ref: 00007FF76DB0E8E4
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: Create$CriticalEventInitializeSectionSemaphore
      • String ID: Thread pool initialization failed.
      • API String ID: 3340455307-2182114853
      • Opcode ID: 6610cce2f1ff4f40d78c24fcbab0d777ace7136147ab701da82aad1b7a389e44
      • Instruction ID: 4e90d9277c8961b473f9b26691c27a207be0bd0adb548d13ff50e90087609224
      • Opcode Fuzzy Hash: 6610cce2f1ff4f40d78c24fcbab0d777ace7136147ab701da82aad1b7a389e44
      • Instruction Fuzzy Hash: FB21E732E2D601C6F750AF24D4447AD72A2EB9CB0CF588134CA0D4A699EFBE9845C7A0
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: CapsDeviceRelease
      • String ID:
      • API String ID: 127614599-3916222277
      • Opcode ID: a42f7bf34e2550c06df92b4c4441a28b155cc5d7cfc3f2a0da00e80f490195b4
      • Instruction ID: 1a9aafccecc54c4f2dc561666341dbdb1aa9269e9cc5b42f64036ae1c2eecd2f
      • Opcode Fuzzy Hash: a42f7bf34e2550c06df92b4c4441a28b155cc5d7cfc3f2a0da00e80f490195b4
      • Instruction Fuzzy Hash: 8AE0CD20B1C641C2FB086F75B58903E5251974CBD0F554035D91F8375CDD3DC8C44310
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$FileTime
      • String ID:
      • API String ID: 1137671866-0
      • Opcode ID: 2d452471b7d5dd184fe666455331b196c35d21b330d78aced89ac185778723fc
      • Instruction ID: 931b47f6eb6d2338834a30d3640224916abecd981cdbdeda9f360c5bf994014d
      • Opcode Fuzzy Hash: 2d452471b7d5dd184fe666455331b196c35d21b330d78aced89ac185778723fc
      • Instruction Fuzzy Hash: DBA19062A2CA82C1EE11EB65D8445EDA371FFC5784F845232EA8D03A99EF3CE944C710
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ErrorLast
      • String ID:
      • API String ID: 1452528299-0
      • Opcode ID: 5aa82b6364e12ec5417afa2caacf8d198bf7c475976c756bafdf9cf489c7b7c1
      • Instruction ID: 4f1e67dec26a9c3a6c905061d1f11dc650e779ab2501a02bf31dc7c2b2cec007
      • Opcode Fuzzy Hash: 5aa82b6364e12ec5417afa2caacf8d198bf7c475976c756bafdf9cf489c7b7c1
      • Instruction Fuzzy Hash: 8A51A462B28A42D5FB00AF65D8452FCA322EB89B98F804232DA5C57BDDFE7CD544C350
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: CreateCurrentDirectoryErrorFreeLastLocalProcess
      • String ID:
      • API String ID: 1077098981-0
      • Opcode ID: decc2da6846149065e747433b686ffe20880dedc2611ac47de6390cb5f5191d4
      • Instruction ID: 0c4563ab30ae394d271b84d5d600f8a8ec21ae2e3b00ee2f4098081ffb53f367
      • Opcode Fuzzy Hash: decc2da6846149065e747433b686ffe20880dedc2611ac47de6390cb5f5191d4
      • Instruction Fuzzy Hash: A9516232A2CB82C6EB509F21E84476EB375FB88B84F941139EA4D57A58EF3CD504CB10
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo$ByteCharErrorLastMultiWide
      • String ID:
      • API String ID: 4141327611-0
      • Opcode ID: fdb879c7c344a6dcddabd48f24568e2f5e84c2dc3f6ceef9c32cec135b3ccbbf
      • Instruction ID: 611f548f9cbfe013c2cc86d12e70bf30e12248d45bdfb093f3b59518b54e7f36
      • Opcode Fuzzy Hash: fdb879c7c344a6dcddabd48f24568e2f5e84c2dc3f6ceef9c32cec135b3ccbbf
      • Instruction Fuzzy Hash: 45419333A2C6C2C6F761AA10A4443B9E290EFD8BA0F948531DA4D46ADDFF7CD8418660
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: FileMove_invalid_parameter_noinfo_noreturn
      • String ID:
      • API String ID: 3823481717-0
      • Opcode ID: 1e191b709e62ef26e60e8f1d0cc24d6cdbe4e9a67f5d62f6318cd10f240089dc
      • Instruction ID: 5f9c2930020ff14e6ffcf1c10603ff2b26507dd1b32917ddd334f740dd4ea9ef
      • Opcode Fuzzy Hash: 1e191b709e62ef26e60e8f1d0cc24d6cdbe4e9a67f5d62f6318cd10f240089dc
      • Instruction Fuzzy Hash: A441BE62F38B91C4FB00EB75D8489AC6371BB48BA8F805235DE5D66B9DEF78D045C210
      APIs
      • GetEnvironmentStringsW.KERNEL32(?,?,?,?,?,?,?,00007FF76DB2C45B), ref: 00007FF76DB30B91
      • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,00007FF76DB2C45B), ref: 00007FF76DB30BF3
      • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,00007FF76DB2C45B), ref: 00007FF76DB30C2D
      • FreeEnvironmentStringsW.KERNEL32(?,?,?,?,?,?,?,00007FF76DB2C45B), ref: 00007FF76DB30C57
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ByteCharEnvironmentMultiStringsWide$Free
      • String ID:
      • API String ID: 1557788787-0
      • Opcode ID: 23704c5f87cc5d65a6a85ab0da0438508b9fc27f2b888927c3d6011bf25654c1
      • Instruction ID: 1578e7cb469302a70595848261c3e54534b206715924f1dea2954ae8e10aec86
      • Opcode Fuzzy Hash: 23704c5f87cc5d65a6a85ab0da0438508b9fc27f2b888927c3d6011bf25654c1
      • Instruction Fuzzy Hash: D5215221A2CB51C1E624AF16A440129E6A4FF98BD0B894134DE8E63FD8EF7CE4529314
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ErrorLast$abort
      • String ID:
      • API String ID: 1447195878-0
      • Opcode ID: df247b5a3948333368795c339682862bf84e23f7c025c70b8dad3e7beb060077
      • Instruction ID: 228f565894c6f9bb8b7d770f3f6ad014a47e03144065a1c3ef4e0ff83af9ee24
      • Opcode Fuzzy Hash: df247b5a3948333368795c339682862bf84e23f7c025c70b8dad3e7beb060077
      • Instruction Fuzzy Hash: BC019216B2C682C2FA59B762B65523DD1615FCCB90FC40938D96E42BDEFD2CB8048270
      APIs
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: CapsDevice$Release
      • String ID:
      • API String ID: 1035833867-0
      • Opcode ID: de15d0a72ac65e47349a1b4cc9ca260558533dfe27db70e7b1e031f833f09c6c
      • Instruction ID: 28b5094714ba0cac2b161e177cc853697d99375609739349857d3c0d2b610a70
      • Opcode Fuzzy Hash: de15d0a72ac65e47349a1b4cc9ca260558533dfe27db70e7b1e031f833f09c6c
      • Instruction Fuzzy Hash: 0AE01260F2D702C2FF09BF75685913AA291AF4C741F888579D81F86358FD3DA885C720
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn
      • String ID: DXGIDebug.dll
      • API String ID: 3668304517-540382549
      • Opcode ID: 6f2cc4c21ac84bf77e587620cb9a44cf3404ae28cc3e8307b621819abafd7d0e
      • Instruction ID: 046eaad76931192e97c02518a7104356da4f46a79ae50ce6f82e2cd68b18c0dd
      • Opcode Fuzzy Hash: 6f2cc4c21ac84bf77e587620cb9a44cf3404ae28cc3e8307b621819abafd7d0e
      • Instruction Fuzzy Hash: 1071AC72A28B81C2EB14DB25E8406ADB3A4FB587D4F844236DBAC47B99EF78D551C300
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo
      • String ID: e+000$gfff
      • API String ID: 3215553584-3030954782
      • Opcode ID: ffbcb58cc87a1110f60409a8afde5d08377aab6ce8cf060c3284a5669936e3c2
      • Instruction ID: 797baa3b104e6213a66002109d28657d96ca2f78a99a8a0e7dbd534af2a0950e
      • Opcode Fuzzy Hash: ffbcb58cc87a1110f60409a8afde5d08377aab6ce8cf060c3284a5669936e3c2
      • Instruction Fuzzy Hash: 44511663B2C7C1C6E7259B36984077DAB91EB89B90F888235C69D87BD9FE2CD444C710
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: _invalid_parameter_noinfo_noreturn$swprintf
      • String ID: SIZE
      • API String ID: 449872665-3243624926
      • Opcode ID: e0bc738575b9dfc7518a9e38475377609f14f4f1dbbb3954c7928ccc9b577437
      • Instruction ID: bb4f1c0621dacf3d1fe7c88bd5b7a222aeebbbdc83479dc96a67dadb63231699
      • Opcode Fuzzy Hash: e0bc738575b9dfc7518a9e38475377609f14f4f1dbbb3954c7928ccc9b577437
      • Instruction Fuzzy Hash: B541BF62A3C782D5EE10AB19E4457BDE360AF99790F848231EA9D426DEFE7CD540C710
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: FileModuleName_invalid_parameter_noinfo
      • String ID: C:\Users\user\Desktop\file.exe
      • API String ID: 3307058713-4010620828
      • Opcode ID: 2b307fc7043d57580c2760bc14d10e66149d3294dbd6a1f00798eb6953a6f573
      • Instruction ID: 791ddd8f48895da79f583b6bdcf12a94154f6bd221915ad4eefc5afb1c96ae40
      • Opcode Fuzzy Hash: 2b307fc7043d57580c2760bc14d10e66149d3294dbd6a1f00798eb6953a6f573
      • Instruction Fuzzy Hash: 13419073A2CA82C6EB15AF21A4401BDB7A4EF8CB94B844435E94D47B49FF3DE441C360
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ItemText$DialogWindow
      • String ID: ASKNEXTVOL
      • API String ID: 445417207-3402441367
      • Opcode ID: 75a4ef6a6cdb84fc8c98b7401f85638b76a9530d4b428818baa7d4c6ec3066de
      • Instruction ID: 39d49f6657b8dfebdf2964d702f4b31a0faf46895df53c4c3f930c1173764316
      • Opcode Fuzzy Hash: 75a4ef6a6cdb84fc8c98b7401f85638b76a9530d4b428818baa7d4c6ec3066de
      • Instruction Fuzzy Hash: A9419362E2C682C1FA11BF12E9401BAA391AF8DBC0F944035DE4D4779DEF3DE8458760
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ByteCharMultiWide_snwprintf
      • String ID: $%s$@%s
      • API String ID: 2650857296-834177443
      • Opcode ID: 68d6d98aec82f67e7f26d78b4367655257a27e60e60eb814561ac576190adeba
      • Instruction ID: 68a48ed2e1c0e0206c74c6ff29327cee2e3377286c39bb21a1dc1e9c1d616045
      • Opcode Fuzzy Hash: 68d6d98aec82f67e7f26d78b4367655257a27e60e60eb814561ac576190adeba
      • Instruction Fuzzy Hash: B7318F72B2DA46D5EE10AF66E440AA9A3A0AB4C784F841032EE4D17B9DFE3DE505C750
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: FileHandleType
      • String ID: @
      • API String ID: 3000768030-2766056989
      • Opcode ID: 01c4e23626c5bd34e0d32a71787dfe5976e9b76bf070a7e2fa99837352baeece
      • Instruction ID: 819df9cc466f92b81fee645565599f326efe41a6b2475055c56a9a2bf8a5f775
      • Opcode Fuzzy Hash: 01c4e23626c5bd34e0d32a71787dfe5976e9b76bf070a7e2fa99837352baeece
      • Instruction Fuzzy Hash: 8A216F23A2C6C2C1EB649B3698D413DA651EB49774F680335D66F467DCFE38D881D321
      APIs
      • RtlPcToFileHeader.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF76DB21D3E), ref: 00007FF76DB240BC
      • RaiseException.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF76DB21D3E), ref: 00007FF76DB24102
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ExceptionFileHeaderRaise
      • String ID: csm
      • API String ID: 2573137834-1018135373
      • Opcode ID: 995ce70781ed1107fbe35a2df86b6ab92d82f2488d4e31342cdb9a65d606da21
      • Instruction ID: 3f4341a80e85357aa1ecfdf7f68820145071a12d57a09ff17945fa60d4e07e1e
      • Opcode Fuzzy Hash: 995ce70781ed1107fbe35a2df86b6ab92d82f2488d4e31342cdb9a65d606da21
      • Instruction Fuzzy Hash: AD115B32618B81C2EB209B15E44026AB7A1FB9CB84F584234DE8C07B58EF3CC591C700
      APIs
      • WaitForSingleObject.KERNEL32(?,?,?,?,?,?,?,?,00007FF76DB0E95F,?,?,?,00007FF76DB0463A,?,?,?), ref: 00007FF76DB0EA63
      • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,00007FF76DB0E95F,?,?,?,00007FF76DB0463A,?,?,?), ref: 00007FF76DB0EA6E
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: ErrorLastObjectSingleWait
      • String ID: WaitForMultipleObjects error %d, GetLastError %d
      • API String ID: 1211598281-2248577382
      • Opcode ID: 98ce5a6e9b01a49333d4d7b683bb298ff4a8e953ba0927a3bf2f7aa8eb90df55
      • Instruction ID: b727ba76167a0668b7a2be7cb4e526d0f2d40fb4df4544b459645df71a424e81
      • Opcode Fuzzy Hash: 98ce5a6e9b01a49333d4d7b683bb298ff4a8e953ba0927a3bf2f7aa8eb90df55
      • Instruction Fuzzy Hash: 36E01A65E3D842C2F640B725DC828B8A2217F6D774FD40331D03E819E9BF6CA9459321
      APIs
      Strings
      Memory Dump Source
      • Source File: 00000000.00000002.1455500039.00007FF76DAF1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF76DAF0000, based on PE: true
      • Associated: 00000000.00000002.1455480631.00007FF76DAF0000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455550821.00007FF76DB38000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB4B000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455582251.00007FF76DB54000.00000004.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5A000.00000002.00000001.01000000.00000003.sdmpDownload File
      • Associated: 00000000.00000002.1455646543.00007FF76DB5E000.00000002.00000001.01000000.00000003.sdmpDownload File
      Joe Sandbox IDA Plugin
      • Snapshot File: hcaresult_0_2_7ff76daf0000_file.jbxd
      Similarity
      • API ID: FindHandleModuleResource
      • String ID: RTL
      • API String ID: 3537982541-834975271
      • Opcode ID: e39cf6139d6c3c808756c827088780cb49cd2dd94430b396554b51375d39015a
      • Instruction ID: 5791f1107a0da9c55e5a8d7ec80e773d38cc7588bd2195d559b88723e2d5a90e
      • Opcode Fuzzy Hash: e39cf6139d6c3c808756c827088780cb49cd2dd94430b396554b51375d39015a
      • Instruction Fuzzy Hash: BBD05E99F2DA02C2FF196B75E44973452505F1CF41FC94038C84E4A798FEACD088C762